Today's issue is supported by Chartsy

Chartsy turns your Stripe or Paddle data into answers. Ask "show MRR by plan" or "why did churn spike" in plain English and get the chart instantly - no spreadsheets, no pivot tables. Built for founders who'd rather read their numbers than wrestle them.

For two years, America's plan was simple: keep its most powerful AI chips away from China. Whoever controls the chips controls the frontier. Ban the sale, slow the rival.

China found the one gap the ban left open, and it's almost insultingly simple. The rules block selling China the physical chip. They say nothing about China renting one from far away. And for training a model, renting is nearly as good as owning.

So Chinese firms booked time on Nvidia servers sitting in data centers in Thailand, Singapore, and Malaysia, just outside America's reach. They never touched the hardware. They logged in from Beijing. The wall still stood. They walked around it.

The clearest way to see it: three years, three different ways China kept getting the compute the ban was supposed to deny.

How China kept getting frontier compute despite the ban

2024  Smuggling      ████████████████  $1B+ chips slipped in
2025  Capped sales   ████████          H200s, quota-limited
2026  Cloud renting  ██████████████████████  near-unlimited

Bars show the relative scale/openness of each route, not identical units. Smuggling: FT estimate of $1B+ in three months. Renting is the hardest to cap nothing crosses a border.

None of these routes are small. By one Epoch AI estimate, somewhere between 290,000 and 1.6 million high-end chip-equivalents were smuggled into China through 2025 and the midpoint of that range alone is roughly a third of all the AI compute China is thought to have. The wall was never watertight. Renting just made climbing it unnecessary.

The ban stops a chip from crossing the border. It says nothing about a Chinese engineer logging into a chip that never moves. America guarded the door. China used the cloud.

Smuggling is a crime. Renting is a login.

Last week we covered the smuggling side of this nine people indicted in Taiwan, including Nvidia and Supermicro insiders, for sneaking 74 banned B300 servers into China with forged documents and a faked website.

It's dramatic. It's also expensive and risky: Chinese buyers reportedly pay around a million dollars per B300 server on the grey market, nearly double the US price, and a CSIS analyst has noted the profit margins on smuggled AI chips rival those in narcotics trafficking.

So the smartest Chinese firms mostly didn't bother. Why smuggle a chip through Indonesia, risk prison, and pay a narco-market premium when you can just rent the same chip legally and log in? Put the two routes side by side and it's obvious why the money moved to the cloud.

Smuggling

Legal status

A crime insiders now indicted in Taiwan and the US

Cost

~$1M per server, roughly double the US price

Risk

Seizures at the border, forgery charges, prison

Traceable?

Yes, a physical chip crosses a border and can be caught

Renting

Legal status

Legal, the ban doesn't mention remote access

Cost

Standard cloud rates, no smuggler's markup

Risk

None yet, no law broken

Traceable?

No, nothing crosses a border to catch

That's the whole reason this loophole matters more than the smuggling rings grabbing headlines. Smuggling can be policed with customs and indictments. Renting can't - not with the rules as written.

A near-frontier model, trained on rented American machines

Then US officials spotted something alarming. A Chinese startup called Moonshot AI had trained a giant model, Kimi K3, a 2.8-trillion-parameter system that came dangerously close to America's best. According to a senior White House official, it ran on rented Nvidia GB300 servers in Thailand.

The ban had held. Not one banned chip was sold to China. And China caught up anyway.

Then came the twist that makes this bigger than one company. Kimi K3 launched July 16, and around July 27 Moonshot posted its weights to Hugging Face meaning a near-frontier model, allegedly trained on rented American chips, is now free for anyone on earth to download and run.

The loophole didn't just help one Chinese lab catch up. It produced an open model the whole world now holds, including every US startup that quietly builds on it.

3

Countries hosting the rented chips: Thailand, Singapore, Malaysia

2.8T

Parameters in Moonshot's Kimi K3, near the US frontier

369–22

House vote to close the loophole - then the Senate stalled it

Sept

When Washington's new anti-renting rule could reach industry

Keep this honest

The Moonshot claim is a US-government allegation, not an independently confirmed fact. Renting offshore compute is, for now, legal. So the accurate read isn't "China cheated", it's "China found a legal route the ban never covered, and Washington is furious it left the door open."

America opened this door itself

Here's what turns this from a China story into a self-inflicted one. The US had a rule in the works to track who rents these chips overseas, a "know-your-customer" requirement for cloud compute.

Commerce scrapped it. Then Congress tried to close the gap directly: the Remote Access Security Act passed the House 369 to 22. It reached the Senate Banking Committee, and stalled.

What the ban covers

Selling or shipping a physical chip to China - tightly controlled

What it misses

Renting remote access to a chip that stays in Thailand -untouched

The rule that would've caught it

Commerce's "know-your-customer" tracking - scrapped before it took effect

The law that would've closed it

Remote Access Security Act - passed the House 369–22, stalled in the Senate

What's happening now

Trump's Commerce Dept drafting a rule to block renting; draft could land in September

So the loophole didn't just exist. America looked straight at it, had two chances to close it, and left it open anyway. Now the Trump administration is racing to draft a fresh rule one that blocks renting, not just buying.

But here's why that's genuinely hard, and why it kept stalling. Blocking a sale means stopping an object at a border, customs officers, shipping manifests, a chip you can physically seize.

Blocking a rental means policing how compute gets used, everywhere, continuously tracking who logs into which data center in which country, forever. That's not a customs problem. It's a global surveillance problem, and nobody has built the machinery for it.

Every month Washington spends designing that machinery, the models keep training. The chip war moved from the factory to the cloud, and the cloud is a much harder place to build a wall.

🔮 The Bottom Line

America spent two years walling off its best AI chips. China didn't climb the wall, it rented a room on the other side and logged in, and trained a near-frontier model on machines America was happy to sell to Thailand.

The ban wasn't wrong. It was aimed at the wrong thing: it controlled the hardware and assumed that controlled the power. In an age when compute is something you rent by the minute from anywhere, what you own matters far less than what you can reach.

That's this week. If you saw the reel and want more like it, our Instagram is @unseen_ainews - breakdowns hit there first, full stories land here. And hit reply with your read: can export controls ever really contain AI, or is this a game Washington can't win?

- hiPreneurs

📧 Forward this to 3 entrepreneur friends who need to see this opportunity