How the U.S. is Moving to Block Remote Access to AI Compute via Third Countries
The U.S. government is drafting new regulations to close the "cloud loophole," extending export controls from physical AI chips to remote network access.
- National Security Advocates
- Argue that closing the cloud loophole is essential to prevent adversaries from training military AI models on American hardware.
- Tech Industry & Cloud Providers
- Warn that overly broad remote access rules create massive compliance burdens and push global customers to non-U.S. cloud ecosystems.
- AI Researchers & Academics
- Highlight the risk of collateral damage to international research collaboration and open-source development.
At a glance
- The U.S. is shifting export controls from physical AI chips to remote cloud access.
- Foreign developers currently bypass hardware bans by renting compute in third-country data centers.
- New regulations would treat remote access to advanced AI compute as a licensable export.
- Cloud providers will face complex new compliance burdens to verify the geographic origin of workloads.
- The House passed the Remote Access Security Act to explicitly authorize these digital export controls.
The physical blockade on artificial intelligence hardware is rapidly evolving into a digital one. Since 2022, the United States has relied on strict export controls to prevent advanced AI chips from reaching geopolitical rivals, aiming to slow the development of adversarial military and surveillance capabilities.[3]
But physical borders mean little in the era of cloud computing. A structural gap in U.S. trade policy—widely known as the "cloud loophole"—has allowed foreign entities to rent the exact computing power they are forbidden from purchasing outright.[1][2]
Now, the U.S. government is moving to close that gap. The Trump administration is drafting new regulations that would treat remote access to advanced AI compute as a licensable export, fundamentally shifting how cloud infrastructure is governed globally.[1][6]
The mechanism of the cloud loophole is straightforward but highly effective. Instead of attempting to smuggle restricted hardware like Nvidia's H100 or B200 GPUs across heavily monitored borders, a foreign AI developer simply leases server time from a data center located in a third country.[2][3]
Southeast Asia has emerged as the primary hub for this workaround. Nations like Malaysia, Thailand, and Singapore are not subject to the same stringent export bans as China, allowing data centers in those jurisdictions to legally import advanced American chips.[1][2]
Once the hardware is installed in a server rack in Kuala Lumpur or Bangkok, engineers in Beijing or Shenzhen can log in remotely. They upload their datasets, train their models on the restricted GPUs, and download the finished weights—all without a single physical chip ever crossing into Chinese territory.[6]
This dynamic has driven a massive surge in AI infrastructure investment across Southeast Asia, with customs data revealing exponential increases in GPU shipments to the region over the past year.[2]
For U.S. policymakers, this remote access route undermines the core objective of the original export controls. If a foreign military can train an autonomous system via the cloud, the physical ban on the processor is effectively meaningless.[3][4]
policymakers, this remote access route undermines the core objective of the original export controls.
The legislative response is already in motion. In early 2026, the House of Representatives overwhelmingly passed the Remote Access Security Act (H.R. 2683), a bipartisan bill designed to modernize the Export Control Reform Act of 2018.[4][5]
The bill explicitly extends federal authority to restrict foreign adversaries' ability to access controlled technologies through network connections and cloud computing services, closing the statutory gap that left remote access unregulated.[4][5]
Parallel to the legislative effort, the Trump administration is preparing executive rules to replace the previous administration's "AI diffusion" framework. The new approach pivots from a map-based system of country tiers to an access-based system focused entirely on the end-user.[1][2]
This shift imposes a significant new compliance burden on the tech industry. U.S. cloud providers and data center operators will effectively be deputized to enforce national security policy at the server level.[2][6]
To comply, cloud platforms will need to implement rigorous "Know Your Customer" protocols for compute access. They must verify not just the billing address of a client, but the actual geographic origin of the workloads and the ultimate beneficiaries of the trained models.[2]
Industry analysts warn that this level of surveillance is technically challenging and commercially risky. The layers of intermediaries, shell companies, and virtual private networks that separate a cloud provider from an end-user make attribution notoriously difficult.[3][6]
Furthermore, overly aggressive remote access controls risk driving global customers away from American cloud ecosystems. If renting compute from a U.S. provider requires navigating a labyrinth of export licenses, international developers may migrate to emerging sovereign AI clouds in Europe or the Middle East.[3]
Academic institutions also face collateral damage. Cross-border research collaborations rely heavily on shared cloud infrastructure, and broad restrictions could isolate U.S. universities from the global scientific community.[3]
Despite these concerns, the trajectory of U.S. policy is clear: the definition of an "export" is expanding from the shipment of a physical good to the provision of a digital capability.[6]
As artificial intelligence becomes increasingly central to national power, the infrastructure that enables it will face the same level of scrutiny traditionally reserved for weapons systems and nuclear materials.[6]
Terms to know
- Cloud Loophole
- The practice of accessing restricted computing power remotely via cloud servers located in countries not subject to export bans.
- Remote Access Security Act (RASA)
- A 2026 U.S. bill designed to extend export controls to the remote use of American technology through network connections.
- Compute
- The raw processing power, typically provided by advanced GPUs, required to train and run large artificial intelligence models.
- Export Control Reform Act (ECRA)
- The 2018 U.S. law that grants the Executive Branch authority to regulate the export of sensitive dual-use technologies.
- Know Your Customer (KYC)
- Compliance protocols used to verify the identity and location of a client, now being adapted for cloud computing access.
Sources
[1]The InformationTech Industry & Cloud ProvidersTrump Administration Working on AI Rule to Curb China's Remote Access to Chips
Read on The Information →
[2]ExplainXTech Industry & Cloud ProvidersTrump Replaces Biden AI Chip Rules to Block China's Remote GPU Access
Read on ExplainX →
[3]Brookings InstitutionAI Researchers & AcademicsThe tension between AI export control and U.S. AI innovation
Read on Brookings Institution →
[4]U.S. Government Publishing OfficeNational Security AdvocatesH.R. 2683 - Remote Access Security Act
Read on U.S. Government Publishing Office →
[5]Congress.govNational Security AdvocatesH.R.2683 - Remote Access Security Act
Read on Congress.gov →
[6]Factlen Editorial TeamAI Researchers & AcademicsSynthesis by Factlen editorial team
Read on Factlen Editorial Team →
Comments
Every angle. Every day.
Get ai stories with full source coverage and perspective breakdowns delivered to your inbox.

