Report Says Chinese AI Firms Tap Southeast Asian Nvidia Clouds

Chinese artificial intelligence firms have reportedly accessed advanced Nvidia compute by connecting remotely to data centers located in Thailand, Malaysia, and Japan. That pattern appears in a CNBC report that describes how cross-border cloud use intersects with a United States system that policy experts say has focused on the movement of physical chips rather than the use of hardware hosted abroad. CNBC reported the cross-border cloud-access allegations.

According to CNBC, policy experts indicate that remote compute access has generally not been controlled in the same way as exports of physical processors. In this account, the focus of the current system is on shipment and transfer of hardware, while remote connections to infrastructure outside China present a different kind of scenario for compliance and oversight.

Why remote GPU access is difficult to police

CNBC reports that a White House official accused Moonshot AI of accessing GB300 compute through a facility in Thailand. The account characterizes this as a reported allegation and not proof that Moonshot owned restricted chips. Within the framework described by CNBC, the allegation concerns use of powerful compute that was not said to be located inside China, and it centers on how companies may reach that compute from afar.

The allegation involving Moonshot AI is presented in the report as an example of the kinds of claims that can arise when remote sessions are used to reach high-performance chips. In the CNBC account, the issue is not framed as a transfer of ownership but as access to capabilities through infrastructure situated outside Chinese territory. The distinction is consistent with the broader theme noted by policy experts in the report, which highlights the difference between physical exports and access mediated by networks.

As described by CNBC, the pattern of Chinese AI firms reportedly tapping compute in Thailand, Malaysia, and Japan raises questions that map to how the current system is organized. If the controls are centered on physical chip exports, reported use of offshore data centers by Chinese organizations illustrates how remote usage can occur alongside rules that are keyed to where hardware sits and how it is shipped.

That policy uncertainty is part of a wider debate over how Washington responds to Chinese firms’ use of AI models.

RASA would extend control to cloud-based access

The CNBC report references legal commentary that speaks to this distinction. Freshfields explains that United States export rules do not generally prohibit remote access where it does not export a controlled item, while also noting that other compliance risks can arise. That explanation aligns with the view, reported by CNBC from policy experts, that remote access has generally not been treated the same way as a physical export of advanced chips.

Freshfields’ note about other compliance risks indicates that circumstances can matter to how rules are interpreted and applied. While the firm’s explanation points to a general principle about what constitutes an export, it also underscores that additional obligations or restrictions may still be relevant depending on the facts. Taken together with the CNBC reporting, this framing helps clarify why remote connections to offshore compute have become a focal point for discussions that involve both technology development and compliance practices.

For readers seeking additional policy context around efforts to address cross-border AI activity, a previous EastFrontier analysis provides background on proposals and enforcement conversations that have emerged alongside export controls. That broader view situates the CNBC reporting within an evolving set of ideas about how access to advanced compute may be governed across jurisdictions.

Southeast Asia becomes a strategic compute corridor

CNBC notes that the Remote Access Security Act passed the House in January 2026 but had not passed the Senate at that time. If enacted, the measure could authorize controls over remote access. This prospective authority is relevant to the scenarios described in the report, where the user and the hardware are in different countries and the linkage is a remote session rather than a shipment.

Because the bill had not cleared the Senate at the time referenced by CNBC, any change to oversight would depend on final passage and the specifics of how any new rules are written. The possibility outlined in the report points to a mechanism that could, if it becomes law, address activity that experts say has generally not been controlled in the same way as exports of physical chips. It also suggests that the policy environment may continue to evolve as lawmakers and agencies consider how remote access fits within existing authorities.

Within the boundaries of what CNBC reports, the current picture combines three elements. First, Chinese AI firms have reportedly accessed advanced Nvidia compute via data centers in Thailand, Malaysia, and Japan. Second, policy experts cited in the report say the United States system has focused on physical chip exports and that remote compute access is generally not controlled the same way. Third, Freshfields explains that export rules do not generally prohibit remote access where it does not export a controlled item, while emphasizing that other compliance risks can arise. Together, those elements frame how companies, cloud operators, and policymakers may view remote use of compute that is hosted beyond national borders.

The specific allegation about Moonshot AI, as described by CNBC, is notable because it illustrates how questions about remote access can intersect with high-profile organizations and advanced chips like the GB300. The report states that a White House official accused the company of accessing GB300 compute through a Thai facility, but that this was a reported allegation and not proof that Moonshot owned restricted chips. That detail underscores the difference between possession of hardware and the act of connecting to it from another jurisdiction.

If the Remote Access Security Act ultimately becomes law, it could create a basis for addressing remote access in a more direct way. If it does not, the distinction highlighted by policy experts in the CNBC report between physical exports and remote use would remain a central feature of the landscape as described. In either case, the facts presented by CNBC and the explanation from Freshfields indicate that any assessment of remote compute access involves understanding both the current structure of export controls and the potential for new authorities that may target specific kinds of cross-border connections.

In the near term, the reported use of data centers in Thailand, Malaysia, and Japan by Chinese AI firms, as described by CNBC, places attention on where advanced compute resides and how it is reached. The legal and policy context summarized above shows why remote access has become a topic for further scrutiny, and why proposed legislation has focused on that mode of activity. As developments proceed, the combination of reported practices, existing rules, and possible new controls will shape how access to advanced Nvidia compute is evaluated across regions.