Insights Business| SaaS| Technology Why US AI Chip Export Controls Keep Failing Against Chinese Demand
Business
|
SaaS
|
Technology
Jul 16, 2026

Why US AI Chip Export Controls Keep Failing Against Chinese Demand

AUTHOR

James A. Wondrasek James A. Wondrasek
Why US AI Chip Export Controls Keep Failing Against Chinese Demand

The US export control regime for AI chips is a careful piece of regulatory architecture. The Bureau of Industry and Security classifies chips by performance thresholds and blocks sales above them to China. The entity list stops specific organisations. On paper, complete.

Then you encounter the numbers. Epoch AI estimates that between 290,000 and 1.6 million H100-equivalent GPUs have reached China despite the controls, with a median of 660,000. Roughly 3% of the global compute stockpile.

The gap between the architecture and the outcome is what matters. The system is an adaptive three-body problem where the US, China, and intermediaries each evolve faster than the others can anticipate. It is one dimension of the Taiwan-China semiconductor crackdown, a story that runs from California sales offices through Southeast Asian transshipment hubs to mainland Chinese data centres.

How Does the US Export Control Licensing System Work for AI Chips — and Where Are the Enforcement Gaps?

The BIS framework under the Export Control Reform Act classifies chips, requires licences, and restricts Hopper (H100, H200) and Blackwell B200 architectures above performance thresholds. The H800 was Nvidia’s gimped China variant, later banned. The H20 was banned in April 2025.

Classification is the easy part. The gap opens after a licence is issued. The architecture is designed for pre-sale gatekeeping but structurally incapable of post-sale verification. Enforcement gaps exploit this asymmetry: ghost data centres where replica servers pass inspection while real hardware is diverted, franken-cards pairing restricted GPU dies with unrestricted components to fall outside classification thresholds. These are the structural gaps that the smuggling pipeline that moves silicon from California to Shenzhen was built to exploit.

The December 2025 relaxation repealed the AI Diffusion Rule just as Chinese demand accelerated, a timing problem as much as a design one. When regulatory positions shift faster than supply chains can adjust, the gaps become structural.

The Chip Security Act proposes hardware-level serial-number tracking in silicon, replacing sticker-based tracking with location verification built into the chip. Not yet law, facing industry resistance on cost and complexity.

The practical dimensions under assessment include country of origin for GPU components, distributor compliance history, serial-number traceability, and secondary-market purchase risks. BIS penalties totalled nearly $420 million in 12 months, and enforcement is headed in one direction.

What Role Do Southeast Asian Intermediaries Play in Chip Diversion Networks?

Singapore and Malaysia are the operational infrastructure for the parent-company loophole, the cloud compute loophole, and multi-hop obfuscation.

The Affiliates Rule extended entity-list restrictions to subsidiaries of blacklisted entities. Its suspension let Chinese firms procure through Singaporean and Malaysian subsidiaries not themselves listed. During the May 2025 to May 2026 regulatory gap, Chinese firms established subsidiaries in Singapore and Malaysia to purchase Blackwell and H100 chips without licences. BIS “clarified” in May 2026 that licences were required, but hundreds of thousands of banned Nvidia chips may already have reached Chinese-owned subsidiaries through the year-long window.

The Megaspeed case makes the scale concrete. A Singapore cloud provider imported $4.6 billion in Nvidia hardware with at least 136,000 GPUs. Nvidia catalogued only 86,000. Tens of thousands are unaccounted for. The office went dark after investigations began. If you were mapping chip diversion networks, Megaspeed is the template: a legitimate-appearing data centre operator serving as a pass-through.

ByteDance and Alibaba access restricted Nvidia chips remotely via offshore data centres, generally permitted under current controls. The standard diversion path creates four jurisdictional layers. As one tightens, routing shifts to the UAE, Turkey, and Vietnam.

If the physical diversion happens in Southeast Asia, the enforcement response increasingly depends on partner countries, and none matters more than Taiwan.

How Does Taiwan’s Approach to AI Chip Export Enforcement Compare to the US Approach?

The US approach is licensing-based: chips classified by thresholds, licences required, enforcement primarily pre-sale with post-sale investigative capacity through BIS and the DOJ. Taiwan’s approach is prosecution-based: no standalone licensing framework; enforcement relies on fraud and forgery statutes, triggered by specific cases.

Each model has structural limits. The US has broad scope but is thin at the physical border. Taiwan is narrower legally but closer to the enforcement point: prosecutors can raid offices and seize servers before they leave the island.

The interaction is where the architecture functions. The US creates the legal framework. Partner-country enforcement provides operational capacity. Taiwanese prosecutions feed intelligence into US investigations. Congress approved export control officer positions in Taiwan, formalising the island as an enforcement frontline where most US chip companies ship through. Taiwan’s transformation from transshipment hub to enforcement frontline is the product of converging pressures: a concrete prosecution target, a harder-line administration, and sustained US engagement.

While enforcement tightens at the supply end, the demand side reveals an equally complex picture, starting with who is buying and how.

Why Are Chinese Military-Linked Universities Pursuing H200 Chips Through Procurement Networks?

At least seven Chinese military-linked universities are actively pursuing H200 chips. The H200 offers higher memory bandwidth (4.8 TB/s via HBM3e) and improved inference performance over the H100, valuable for large-model workloads military AI requires.

The procurement method exploits the civilian-military boundary. Universities use research budgets and academic channels, working through trading companies, exchange programmes, and joint research initiatives. A chip procured for natural language processing research at a military-linked university can contribute to defence AI without ever being classified as a military end-use. Cadence Design Systems pleaded guilty in July 2025 to transferring sensitive chip design technology to a Chinese university the US believes uses it for supercomputers supporting nuclear explosive and military simulation.

If you were mapping Chinese AI chip demand, military-linked universities would be the category hardest to place on either side of the civilian-military line. They are one segment of a larger picture spanning cloud providers, state AI labs, and defence-industrial entities. The universities are the most ambiguous category: neither clearly civilian nor clearly military, hardest to regulate.

Why Did China Block Imports of Nvidia H200 Chips After the US Approved Them for Sale?

In December 2025, the Trump administration approved H200 sales to 10 Chinese companies. By mid-May 2026, not a single H200 had been sold. Beijing blocked the imports.

The approval came with conditions: end-use monitoring, audit rights, entity-level restrictions. Beijing treated these as sovereignty-compromising. Chinese authorities had learned from the H20 experience: when DeepSeek‘s models ran on H20s, the US cut off access. Allowing H200s would recreate the same dependency.

Huawei’s Ascend 920 reportedly matches H20 performance. DeepSeek V4 runs on Huawei Ascend. Huawei’s “LogicFolding” architecture targets 1.4nm-equivalent performance by 2031 without ASML’s EUV tools. The Brookings Institution concludes US chip companies have zero share of the AI chip market in China.

Rejecting H200s also pressures ByteDance, Alibaba, and Tencent onto Huawei Ascend rather than Nvidia’s CUDA ecosystem. Beijing is using the rejection to force domestic cloud providers onto domestic hardware, accelerating the chip ecosystem whether those providers want it or not.

If Beijing is now rejecting chips the US approved, the question for anyone watching this unfold shifts from “what is happening” to “how do we measure whether any of this is working.”

How Can Companies Assess Whether US Export Controls Are Actually Slowing Chinese AI Development?

The only honest way to answer is on a gradient rather than as a binary yes or no.

The evidence that controls constrain legitimate access is unambiguous. Nvidia’s forward guidance assumes zero data centre compute revenue from China. DeepSeek has acknowledged compute constraints. Domestic alternatives remain behind on both manufacturing process and software ecosystem maturity. CUDA lock-in is real.

Evidence the black market offsets the constraint is equally clear. The Epoch AI median estimate of 660,000 smuggled H100-equivalents represents a substantial countervailing force. B200 racks command a 50% black-market premium. Evasion methods proliferate. Domestic capability advances on its own trajectory.

Three questions matter more than “are the controls working.” How much slower is Chinese AI relative to an uncontrolled baseline? Is the gap widening or narrowing? When does domestic capability cross the threshold where controls become irrelevant?

The control regime is permanent. The implication for supply-chain strategy is that escalating enforcement, not relaxation, is the baseline to plan against.

The US licensing architecture is elegant. The black market is resourceful. Beijing’s calculus has shifted from dependency to self-sufficiency. All three are true at once. The right question is how the system is reshaping itself, and whether your assessment accounts for all three moving parts — which the full enforcement and demand-side picture maps across the operational pipeline, Taiwan’s enforcement pivot, and the control architecture’s structural limits.

Frequently Asked Questions

What makes the H100 and H200 so important that they warrant export controls?

The H100 and H200 are the industrial engines of modern AI training. The H100 delivers the compute density needed to train large language models at scale, and the H200 adds HBM3e memory with 4.8 TB/s bandwidth, which dramatically accelerates inference workloads. The chips sit at the intersection of commercial AI capability and strategic military application because the same silicon that trains a chatbot also trains targeting algorithms, making them dual-use technologies that export controls were designed to restrict.

Is Nvidia losing money from these export controls?

Nvidia’s forward guidance now assumes zero data centre compute revenue from China, which represented roughly 20 to 25 percent of that segment before the controls tightened. The company has offset the loss through surging demand from US hyperscalers and other unrestricted markets, but the strategic cost is arguably larger than the financial one: every restricted sale pushes Chinese cloud providers toward Huawei’s Ascend ecosystem, which erodes Nvidia’s long-term market position in the world’s second-largest economy.

Can China just manufacture its own advanced AI chips?

China can manufacture capable AI chips, but not at parity with Nvidia’s leading silicon. Huawei’s Ascend 920 reportedly matches the H20 on certain benchmarks, and SMIC has advanced its 7nm process despite lacking ASML’s EUV tools. The real gap is the software ecosystem: Nvidia’s CUDA platform has two decades of library accumulation and developer familiarity that Huawei cannot replicate quickly. China is closing the hardware gap faster than the software one, but both are narrowing.

What happens if a company unknowingly sells chips that end up in China?

Unknowing involvement does not guarantee immunity from liability. BIS and DOJ have pursued penalties against companies whose compliance programs failed to catch red flags, even where intent was not proven. The Supermicro case demonstrates the risk: dummy equipment audits and falsified end-user certifications can make a legitimate transaction look clean to a reasonable compliance check. Companies are expected to know their customers, verify end-use, and flag anomalies. The standard is negligence, not knowledge.

Why doesn’t the US impose a blanket ban on all chip exports to China?

A blanket ban would be both diplomatically unsustainable and operationally unenforceable. It would sever relationships with allies whose cooperation is essential for enforcement, trigger immediate WTO challenges, and accelerate domestic Chinese chip development by removing any ambiguity about the need for self-sufficiency. The tiered licensing approach preserves leverage by keeping some Chinese entities dependent on US technology while denying the most advanced capabilities. It is a scalpel by design, not a sledgehammer that was never considered.

How do ghost data centres actually operate?

Ghost data centres are facilities that appear legitimate at the paper-trail level but functionally do not exist as operational computing sites. The operator registers a business address, installs non-functional or dummy server racks for compliance inspections, and lists GPU purchases against that facility, while the actual hardware is diverted to unregistered locations. The model works because BIS enforcement relies on end-user certification and declared addresses. There is no routine physical verification of every listed data centre across every jurisdiction that receives US chip exports.

Are other countries beyond Singapore and Taiwan involved in chip diversion?

Yes. The United Arab Emirates, Turkey, and Vietnam have all been identified as nodes in multi-hop diversion networks. The UAE in particular has drawn attention because its AI ambitions create legitimate demand that can mask diversion activity, and its proximity to Iran adds a second proliferation risk. BIS has announced plans to station enforcement agents in the UAE and Turkey specifically to address this geographic expansion. The pattern is consistent: as one jurisdiction tightens, the routing shifts to the next softest point.

What is CUDA and why does it matter in the export control debate?

CUDA is Nvidia’s proprietary parallel computing platform and programming model that allows developers to write software that runs directly on GPU hardware. It matters because nearly the entire modern AI software stack, from PyTorch to model training pipelines, is built on top of CUDA. Switching to alternative hardware such as Huawei’s Ascend requires rewriting or porting that software, which is costly, slow, and introduces performance regressions. CUDA lock-in is the single largest barrier to Chinese adoption of domestic chips, and it is a structural advantage the export controls reinforce.

How do Chinese AI labs like DeepSeek keep building advanced models despite chip restrictions?

DeepSeek and similar labs work within the constraint rather than pretending it does not exist. DeepSeek V4 was optimised to run on Huawei Ascend hardware, and the lab has publicly acknowledged that compute limitations forced architectural innovations they might not have pursued with unrestricted access to Nvidia silicon. They also benefit from chips acquired before the controls tightened and from the grey-market supply chain documented in the Epoch AI estimates. The outcome is not “unaffected” but “adapted,” and the quality of that adaptation is the variable worth tracking.

Could export controls backfire by accelerating China’s domestic chip industry?

They already are. Huawei’s “LogicFolding” architecture targets 1.4nm-equivalent performance by 2031 without ASML’s EUV tools, a research direction that would have been economically irrational when Nvidia chips were freely available. Beijing’s H200 rejection converts a US policy lever into a Chinese industrial-policy accelerant by forcing ByteDance, Alibaba, and Tencent onto domestic hardware. The Brookings Institution’s argument that the US has “already lost” the China AI chip market may be premature, but the mechanism it identifies is real: restrictions create the demand certainty that domestic chip investment requires.

AUTHOR

James A. Wondrasek James A. Wondrasek

SHARE ARTICLE

Share
Copy Link

Related Articles

Need a reliable team to help achieve your software goals?

Drop us a line! We'd love to discuss your project.

Offices Dots
Offices

BUSINESS HOURS

Monday - Friday
9 AM - 9 PM (Sydney Time)
9 AM - 5 PM (Yogyakarta Time)

Monday - Friday
9 AM - 9 PM (Sydney Time)
9 AM - 5 PM (Yogyakarta Time)

Sydney

SYDNEY

55 Pyrmont Bridge Road
Pyrmont, NSW, 2009
Australia

55 Pyrmont Bridge Road, Pyrmont, NSW, 2009, Australia

+61 2-8123-0997

Yogyakarta

YOGYAKARTA

Unit A & B
Jl. Prof. Herman Yohanes No.1125, Terban, Gondokusuman, Yogyakarta,
Daerah Istimewa Yogyakarta 55223
Indonesia

Unit A & B Jl. Prof. Herman Yohanes No.1125, Yogyakarta, Daerah Istimewa Yogyakarta 55223, Indonesia

+62 274-4539660
Bandung

BANDUNG

JL. Banda No. 30
Bandung 40115
Indonesia

JL. Banda No. 30, Bandung 40115, Indonesia

+62 858-6514-9577

Subscribe to our newsletter