A Nvidia chip subject to export controls for China may never step foot on Chinese territory and yet still end up providing artificial intelligence capabilities to a company in the country. The growth of data centers with US GPUs in Malaysia, Singapore, and other Southeast Asian markets is forcing Washington to grapple with a difficult-to-control issue: how to limit Chinese access to advanced computing when the hardware remains physically in another country.
The keys to Chinese access to Nvidia GPUs in 30 seconds
- The US has been restricting the export of certain advanced Nvidia GPUs to China since 2022 and has expanded controls multiple times.
- Megaspeed is under scrutiny for its purchases of servers with GPUs and its operations in Southeast Asia.
- An investigation by Culper Research attributes to its Malaysian subsidiary imports worth $4.6 billion between December 2024 and January 2026.
- The issue is no longer just where the chip ends up, but who funds the infrastructure and who uses its capacity remotely.
- Nvidia acknowledges that controls and diversion attempts increasingly complicate its international business.
The Megaspeed case helps to understand a transformation that traditional export controls do not easily address. For decades, it was relatively simple to think of restricted technology as an object: a machine, component, or semiconductor crossing a border.
Cloud computing changes that logic. The customer no longer needs to own the GPU. They don’t even need to be in the same country. They can purchase processing hours thousands of kilometers away and send data, code, or models to the server via the internet.
The GPU doesn’t travel. The computing does.
Megaspeed and an operation that grew at an extraordinary speed
Megaspeed is a Singapore-based company initially linked to 7Road, a Chinese company focused on video games and technology services. Its subsequent expansion into AI infrastructure has drawn attention due to its rapid growth and the volume of hardware acquired.
An investigation published by Culper Research in May 2026, which should be read considering that the firm declared a short position on Nvidia, analyzed Singapore and Malaysian corporate and commercial records.
According to its estimates, Speedmatrix, Megaspeed’s Malaysian subsidiary, imported products worth about $4.6 billion between December 2024 and January 2026. Approximately $4 billion of this came from Aivres Systems, a server manufacturer and former Nvidia partner known as Inspur Systems.
Culper also suggests that certain financial structures would indirectly connect the operation to Alibaba. This relationship is presented as an inference based on corporate and financial documents, not as a legal conclusion.
This is precisely one of the more delicate aspects of the case: purchasing servers in Malaysia to operate a data center there does not by itself demonstrate a violation of US controls.
The relevant question is who controls, finances, and ultimately uses that capacity.
In July, reports indicated that US and Singaporean authorities were examining Megaspeed’s activities and the possible use of data centers in Malaysia and Indonesia to remotely serve Chinese clients.
This significantly changes the nature of the problem.
The US can control a chip, but controlling an hour of GPU time is more difficult
Washington began tightening controls over advanced accelerators destined for China in 2022. Since then, restrictions have been expanded and modified several times.
Nvidia itself explains in documents filed with the US Securities and Exchange Commission (SEC) that controls affect products exceeding certain performance, density, interconnect bandwidth, or memory limits.
Affected products have included A100, H100, H200, and systems based on Blackwell such as B200 and GB200. The specific conditions depend on the product, destination, customer, and current regulation.
But cloud introduces a fundamental difference.
A Chinese company might need 1,000 GPUs for weeks to train or tune a model. Technically, it doesn’t need to buy them. An overseas provider could host them in Kuala Lumpur, Jakarta, or other permitted locations and sell remote capacity.
For the user, the experience is much like hiring any Infrastructure as a Service (IaaS) provider.
And here is one of the most challenging frontiers of US tech policy: regulating computing capacity beyond the physical movement of semiconductors.
This isn’t entirely new. The US Department of Justice has documented much more conventional schemes where intermediaries purchased GPUs and then exported them physically to China via third countries.
In a procedure announced in December 2025, US authorities accused several individuals of conspiring to export advanced GPUs to China using Malaysia and Thailand as intermediate points.
Remote leasing presents another scenario. The component can remain legitimately installed in the country to which it was sold.
Malaysia and Singapore are in the spotlight
Southeast Asia has also become one of the most attractive markets for data centers among international operators.
Singapore has long been one of Asia’s major digital hubs. Land and energy constraints have shifted new projects toward Malaysia, especially Johor.
But it’s important to avoid overly simplistic conclusions: the growth of data centers in these countries does not automatically mean an operation to evade sanctions.
Singapore has publicly defended its controls and states it will investigate potential deceptive practices aimed at avoiding international restrictions. Its Ministry of Trade and Industry also noted that less than 1% of Nvidia’s revenue from Singaporean entities comes from products physically delivered there, a reflection of the country’s role as a corporate and administrative hub for many international companies.
Malaysia has also tightened oversight of servers and advanced chips.
For regulators and providers, the challenge is to distinguish legitimate growth in Asian cloud infrastructure from schemes specifically designed to give certain entities access to technologies they couldn’t acquire directly.
Nvidia also acknowledges diversion risks
This situation puts Nvidia in a tricky position.
The company states that it aims to comply with applicable controls and cooperate with authorities regarding potential diversion attempts. At the same time, it recognizes an obvious limitation: once the product is sold, Nvidia no longer has physical control over it.
In its 2026 financial filings, the manufacturer notes that it also relies on customer and partner compliance programs.
Regulation also has direct economic consequences for Nvidia. Restrictions on the H20 once led to a charge of $4.5 billion related to inventory and purchase commitments.
Subsequently, the situation has evolved. Nvidia’s latest filings indicate that since February 2026 the US has issued licenses to send small quantities of H200 to certain Chinese customers, though the company reported at the close of its first fiscal quarter 2027 that it had not yet generated revenue under this program and was unsure if China would ultimately approve the imports.
This makes it too simplistic to portray US policy as a permanent ban on any advanced GPU. Restrictions vary depending on product, generation, customer, and regulatory timing.
The next export control might be in the cloud
The Megaspeed case raises an issue likely to recur.
Controlling the destination of a semiconductor makes sense when the technological value travels inside a box. It’s much less effective when what the customer truly needs are tokens per second, GPU hours, or temporary access to a cluster.
The cloud model separates hardware ownership from its use.
This could force the US and other governments to pay more attention to the identity of the end customer, parent companies, financing, ultimate beneficiaries, and remote access to large pools of computing capacity.
For data center operators and cloud providers, compliance work also increases. Knowing the customer may no longer suffice if a chain of intermediaries, financing, and end-users in other jurisdictions is involved.
And for companies buying GPUs in Asia-Pacific, another consideration arises. The location of the data center no longer tells the whole story of the provider.
It’s important to understand who controls the company, where its funding comes from, who supplies the servers, and what guarantees exist regarding the origin and regulatory compliance of the infrastructure.
The risk isn’t just that Washington cuts off a supply route. A provider under investigation, subject to new export restrictions, or facing issues with manufacturers can quickly become a continuity risk for its clients.
Megaspeed exemplifies this precisely. Not because it alone proves US controls have failed—which investigations will determine—but because it exposes an increasingly clear contradiction: in the cloud era, controlling where a GPU is and controlling who can use it are two different things.
Frequently Asked Questions
Can a Chinese company use an Nvidia GPU installed in Malaysia?
Technically, they can remotely access infrastructure located in another country if a provider offers it. The regulatory question depends on the chip, the provider, the end customer, and applicable US regulations at any given time.
What is being investigated in the Megaspeed case?
Available information points to the volume and financing of its Nvidia infrastructure acquisitions and the possible remote access from China to capacity deployed in other Asian countries. Some of its most detailed allegations come from Culper Research and should not be confused with legal conclusions.
Does the US prohibit all Nvidia GPUs in China?
No. Controls target specific products and technical features and have changed multiple times since 2022. The US has also established licensing mechanisms for particular products, including the H200 in 2026.
Why is GPU rental important for export controls?
Because it physically separates the hardware from its usage. A GPU can remain in an authorized data center while its processing capacity is consumed remotely from another country.
Sources:
- Bugtraq Solutions, Nvidia Chips, triangulation, and China: the new gap in export controls, 08/10/2026.

