The investigation Washington just widened

The Bureau of Industry and Security, the Commerce Department division that enforces US chip export rules, has opened a formal review into how Chinese AI companies are obtaining access to Nvidia's most advanced processors without buying them outright. The trigger was Moonshot AI's release of Kimi K3, a 2.8 trillion parameter model whose performance drew immediate comparisons to frontier systems from Anthropic and OpenAI. Days later, on 22 July, White House Office of Science and Technology Policy director Michael Kratsios said publicly that Moonshot had acquired Nvidia GB300 servers, part of the export-restricted Blackwell generation, and had run training workloads through infrastructure based in Thailand rather than importing the chips into China.

Reporting on the review, drawing on people familiar with the matter, describes the Commerce Department as now formally investigating whether Chinese firms reached export-controlled American AI chips this way as a matter of course, not an isolated case. Treasury Secretary Scott Bessent has said sanctions and placement on the Entity List, the US blacklist that cuts a company off from American suppliers, 'will be on the table' for firms confirmed to have used the practice at scale.

Renting was the workaround, not the ban

Chip export controls were built around a physical transaction: a chip ships from a US or allied factory, crosses a border, and lands in a buyer's data center. Every rule Washington has written for five years has tightened that chokepoint, restricting which chips can be sold to which buyers and requiring export licenses for the most capable hardware. What those rules did not clearly reach is a Chinese firm renting compute by the hour from a data center in Thailand, Malaysia, or another third country that never itself imported the chip in violation of anything. The hardware stays put; only the workload crosses a border, invisibly, over a network connection.

That gap is exactly what a bill already moving through Congress, the Remote Access Security Act, is designed to close, by extending export-control obligations to remote and cloud access rather than physical shipment alone. The bill and the BIS review point at the same problem from two directions, legislative and enforcement, which is itself a signal that Washington now treats offshore rental as the live edge of the export-control fight, not a footnote to it.

Why a European compute buyer should care

Most owners will read this as a US-China story with no European angle. It has one, and it is not about which AI model you use. For five years, an EU or UK company doing AI vendor due diligence has asked one question about hardware: who did you buy the chip from. That question is becoming the wrong one. The question a compliance-minded buyer needs now is where the physical hardware behind a rented GPU contract actually sits, and who else is renting time on the same cluster, because a reseller offering cheap GPU-hours through a chain of subsidiaries can be sitting on exactly the kind of offshore, multi-tenant capacity this review is built to catch.

The exposure is not that a European firm gets accused of anything. It is that a shared cluster named in a future BIS enforcement action, or a reseller placed on the Entity List, can strand a European customer's workloads with no warning and no easy fallback, and can turn a routine vendor relationship into a compliance incident a board has to explain. That is a new line item for AI supply-chain risk, sitting next to the model-provenance and data-residency questions most compliance teams already track.

The provenance check to add before your next GPU contract

Add one question to every cloud GPU procurement from now on: ask the vendor, in writing, which jurisdiction physically hosts the hardware behind your contract, and whether the cluster is shared with tenants outside your own compliance perimeter. A reseller who cannot answer that cleanly is telling you something. Document the answer the same way you already document model provenance and data-residency choices under the EU AI Act's vendor-risk expectations, so a change in a supplier's status shows up as a decision you made on purpose, not a surprise an auditor finds first.

None of this is settled law yet. The BIS review is a review, and the Remote Access Security Act is a bill in progress, not an enacted rule, so nothing forces a vendor switch today. What it does force is the habit of asking the location question before signing the next contract, while it still costs nothing to ask and everything to have skipped.