AI Chip Leasing Export Controls and the Tencent Deal

Tencent has reportedly agreed to pay about $7 billion over five years for access to roughly 100,000 advanced AI chips it is not permitted to buy. The chips sit in Oracle data centres in South-East Asia. They will stay there.

The Financial Times reported the arrangement on September 30. Neither company has confirmed it. If it is accurate, it describes something export-control law was not originally built to analyse: the hardware never moves toward the restricted destination, but the capability the hardware produces becomes available to a company inside it.

That is a genuinely difficult question, and most coverage has answered it too quickly in both directions. Calling it a loophole assumes the rules ignore remote access, which is not quite right. Calling it obviously lawful assumes physical location settles the analysis, which is also not right.

The useful question is narrower: what exactly is the export-control system regulating — the chip, or what the chip can do for whom?

Key takeaways
  • The FT reported on September 30 that Tencent signed a five-year lease worth about $7 billion for access to roughly 100,000 advanced AI chips in Oracle data centres in South-East Asia, with about 30% paid upfront. Neither company has confirmed it.
  • Under longstanding BIS practice, remote access to computing power is generally not treated as an export of the underlying chip. That is the basis of the gap argument, and it is only part of the picture.
  • BIS’s January 2026 rule conditions licences for China-destined advanced chips on KYC screening of remote users and, for IaaS providers, identification of remote end users in countries of concern. The rules already reach past the hardware.
  • End-use and end-user prohibitions under EAR Part 744 apply regardless of where hardware physically sits.
  • The contrast case is physical: DOJ alleges a California man routed more than $300 million in export-controlled GPU servers to China through Malaysia and Singapore. That conduct sits squarely within the existing framework. Offshore compute leasing is a different mechanism.
  • As compute becomes a financeable, leasable asset — NVIDIA’s $500 billion financing push treats chips as collateral — the distinction between owning hardware and buying its output becomes commercially central as well as legally awkward.
  • Nothing here is legal advice, and nothing in this article concludes that the reported arrangement is lawful or unlawful.

Quick Navigation


The Chip Stayed Put. The Compute Didn’t.

Seven arrangements get flattened into “getting chips,” and they are not legally equivalent. Separating them is the single most useful thing an article on this subject can do.

Table: scroll sideways to view all columns when needed.

ArrangementWhat movesWho holds the hardware
Physical exportA controlled item crosses a borderThe recipient
Ownership transferTitle changes handsThe buyer, wherever it sits
Hardware leasePossession and use of physical serversThe lessee, physically
Compute leasingContractual access to capacityThe operator keeps the hardware
Cloud / GPU-as-a-serviceRemote consumption of cyclesThe provider
Offshore data-centre accessRemote use from another jurisdictionThe third-country operator
Diversion / transshipmentHardware routed to a prohibited destinationUltimately the prohibited end user
AI Chip Leasing Export Controls

The first three and the last involve physical items changing location or control. The middle three do not. Export-control law was built mainly around the first category and has been extended, through end-use and end-user rules, toward the others.

The important distinction is this: an export-control analysis asks what item went where, to whom, and for what use. A compute lease changes the answer to the first question without necessarily changing the answers to the other three.

What Export Controls Actually Control

The US framework for advanced AI chips runs through the Export Administration Regulations, administered by the Bureau of Industry and Security at the Commerce Department. Four mechanisms do most of the work.

  • Item-based controls. Advanced computing integrated circuits above performance thresholds are classified under specific ECCNs and require licences for certain destinations. This is the hardware layer.
  • Destination controls. Licence requirements and review policies vary by country, with China and Macau subject to the most restrictive treatment.
  • End-user controls. The Entity List and related restrictions attach to named parties regardless of where a transaction occurs. A listed party cannot receive controlled items anywhere.
  • End-use controls. EAR Part 744 prohibits certain uses — military, military-intelligence, WMD-related — and these prohibitions apply with knowledge, irrespective of geography.

Two further features matter for this story. The Foreign Direct Product Rule extends US jurisdiction to certain foreign-produced items made with US technology, which is how controls reach chips fabricated outside the United States. And the Data Center Validated End User framework, introduced in October 2024 and expanded in the January 2025 AI Diffusion Rule, created a route for approved operators to receive controlled chips for data centres abroad, with per-company and per-country computing-power limits. The Diffusion Rule itself was rescinded, but several of its structural ideas persist in current licence conditions.

In practical terms: the chip has to be licensed to get into the data centre in the first place. Whatever happens afterwards, the hardware entered under US authority and conditions.

Where AI Chip Leasing Export Controls Get Complicated

Start with the point everyone cites, stated precisely: under longstanding BIS practice, providing remote access to computing power is generally not treated as an export of the chips themselves. The item does not move. No licence requirement attaches merely because a foreign user runs a job on a US-origin GPU located abroad.

That principle is real, it is not a drafting oversight, and it exists for a defensible reason. Treating remote access as an export would mean every cloud login from a foreign IP address became a licensable event, which would be unenforceable and would damage US cloud providers more than it would constrain anyone else.

Now the complications, each of which is documented.

  • Licence conditions already reach remote users. BIS’s final rule effective January 15, 2026 moved China and Macau-destined advanced computing exports to case-by-case review, conditioned on certifications. Those conditions include rigorous KYC procedures by the ultimate consignee to screen and prevent unauthorized remote access by prohibited end users, and where the consignee provides IaaS, identification of intended remote end users in countries of concern plus controls against illicit access. Law-firm analysis of the rule described it as a notable departure from the practice that remote access alone is not an export.
  • End-user prohibitions do not care about geography. If a party is on the Entity List, supplying it with controlled items is prohibited wherever that happens. Whether a compute lease constitutes supplying an item is exactly the hard question, but the prohibition is not switched off by the hardware staying put.
  • End-use prohibitions travel. Military-intelligence and WMD-related end uses trigger requirements with knowledge, regardless of location. BIS has warned that exports to foreign cloud providers can trigger licence requirements under catch-all controls where there is knowledge of a prohibited end use.
  • Model weights are separately controlled. The January 2025 framework brought the most advanced model weights into scope, and IaaS commitments in current licence conditions address the transfer of weights trained on controlled chips. Compute leases produce weights; that output has its own treatment.

So the honest formulation is not “export controls do not cover this.” It is that hardware controls and compute access operate on different regulatory dimensions. The hardware layer is licensed, located and countable. The access layer is contractual, remote and attributed through the operator’s own diligence. The rules reach into the second layer mainly through conditions imposed at the first.

The South-East Asia Model

What the FT reported, stripped to verified elements: a five-year agreement signed this year, roughly $7 billion in value, about 30% paid upfront, access to approximately 100,000 advanced AI chips across multiple Oracle data centres in South-East Asia, for use in developing Tencent’s AI models and agentic tools.

What has not been reported: the chip generations, the host countries, the ownership structure, the contractual form, or any licensing position taken by either party. Those unknowns matter, because each would change an export-control analysis. The article’s analysis is therefore about the model, not about this transaction’s legality.

The pattern is not new. Reporting has described Tencent accessing NVIDIA Blackwell capacity through a data centre near Osaka in December 2025, and ByteDance’s Singapore subsidiary accessing B200 GPUs through a UK provider’s facility in Norway. What is new is scale: a nine-figure chip count and a ten-figure contract with a major US cloud provider.

Why this structure is commercially attractive is not mysterious:

  • Speed. Capacity exists now. Building domestic alternatives takes years.
  • Capability. The chips are generations ahead of what is available inside China.
  • Financial form. An operating expense with 30% upfront, rather than a capital purchase requiring import approval.
  • Regulatory posture. It avoids the question of importing hardware entirely, on both the US and Chinese sides.

For Oracle, the attraction is equally plain: a five-year anchor tenant with a large upfront payment underwriting South-East Asian capacity.

The analytical point: this is what happens when the regulated object is scarce but the service it produces is fungible and remotely deliverable. Demand routes to wherever the capability can be lawfully consumed.

A Server in Malaysia Is Not a GPU in China

On October 1, 2026, the Justice Department announced the arrest of Greg Lui, 38, also known as Yiu Kong Lui, of San Gabriel, California, owner of Earthmade Computer. A grand jury returned a three-count indictment on September 29 charging conspiracy to violate the Export Control Reform Act and the EAR, outbound smuggling, and conspiracy to commit money laundering.

Prosecutors allege that between 2023 and 2024 Lui and co-conspirators bought export-controlled servers containing US-made GPUs from American suppliers and shipped them through freight forwarders to countries including Malaysia and Singapore, using false paperwork, while knowing the true end users were in China. The release describes one January 2024 shipment of 27 servers sent from Los Angeles to Kuala Lumpur, allegedly forwarded to a buyer in China.

These are allegations. Lui is presumed innocent unless and until proven guilty.

Place that next to a compute lease and the difference is structural rather than moral:

Table: scroll sideways to view all columns when needed.

Alleged diversionOffshore compute access
What movesPhysical serversNetwork traffic
Where the hardware ends upAllegedly ChinaStays in the third country
Evidence trailShipping records, invoices, customs filings, emailsContracts, access logs, billing records
Who investigatesBIS Export Enforcement, DOJ, customsPrimarily the operator’s own compliance function
Legal theoryEstablished: unlicensed export, smugglingDepends on end user, end use and licence conditions

The first column describes conduct the existing system was designed to catch, and it caught it. Physical goods generate documents, and documents generate cases.

The second column produces almost none of that. There is no shipment, no customs entry, no freight forwarder. There is a commercial contract between a cloud provider and a customer, and the record of who ran what is held by the provider.

For an enforcement agency, this means the investigative starting point moves from the border to the data centre’s customer list. That is a different kind of work, requiring different access, and it is the practical sense in which something has changed — not that the law is silent, but that the evidence lives somewhere else and belongs to someone else.

The Law Was Written Around Hardware. AI Is Becoming a Service.

Export controls assume a world of discrete items with owners and locations. That assumption is weakening on the commercial side faster than on the legal side.

NVIDIA announced partnerships in August 2026 with Apollo, BlackRock, Blackstone, Brookfield, Goldman Sachs and KKR around financing platforms intended to mobilise more than $500 billion for AI infrastructure. Jensen Huang told CNBC that this is the first time technology chips have become an investable asset class, arguing that because the hardware is broadly adopted and transferable, lenders can underwrite compute as a revenue-generating asset. NVIDIA has indicated it may provide residual-value support of up to 25% on some projects.

The structure is ordinary equipment finance applied to accelerators: a financing vehicle buys the hardware, an operator leases it, customer contracts produce the cash flows, and the debt is secured against both. CoreWeave’s $8.5 billion GPU-backed facility earlier this year is the proof of concept.

Reuters reported in early October that bankers and asset managers want more guarantees before treating these chips as long-term collateral, with one portfolio manager noting that Wall Street is more conservative than NVIDIA’s decade-long revenue claim implies. That scepticism is about residual value, which is the same obsolescence problem we worked through in our analysis of AI accelerator depreciation.

Here is why this belongs in an export-control article. The financing model deliberately separates three things that used to travel together: who owns the chip, who operates it, and who consumes its output. A financing vehicle may own it, an operator may run it, and a customer in a third jurisdiction may use it. Every one of those can be a different legal person in a different country.

Export-control analysis has to pick one of those relationships to attach to. Historically it attached to ownership and location. The commercial structure is moving the economic substance toward consumption.

China’s Two Paths to Compute

Chinese AI developers have two routes to frontier-scale compute, and they operate on completely different timescales.

  1. Domestic silicon is the sovereign answer and the slow one. Alibaba’s T-Head unveiled its Zhenwu V900 accelerator in September, claiming clusters scaling to 500,000 cards, and Huawei continues to iterate its Ascend line. The constraint is not design talent. It is manufacturing, advanced packaging and high-bandwidth memory supply, all of which are themselves export-controlled or capacity-limited — the chain we examined in our piece on the memory wall behind a 500,000-card cluster.
  2. Offshore leased compute is the fast answer. It delivers current-generation capability immediately, with no fabrication, no packaging and no domestic approval process for imported hardware.

The two are complements rather than alternatives, and the comparison should not be overstated. Offshore capacity cannot serve latency-sensitive domestic products well, cannot be used for workloads with data-residency constraints, and leaves the customer dependent on a foreign provider and a foreign regulator. It buys training capability, not infrastructure sovereignty.

The analytical read: domestic silicon addresses the long-run strategic problem; offshore leasing addresses the immediate capability gap. A company pursuing both is behaving rationally, and the existence of the second does not reduce the urgency of the first.

The Enforcement Problem

Even where rules clearly apply, applying them to compute access is harder than applying them to cargo. Five reasons, none of which is a legal gap as such.

  1. Attribution. A shipment has a consignee. A compute workload has an account, which may belong to a subsidiary, a joint venture or a reseller. Determining who is actually running a job is a diligence exercise, not a customs check.
  2. Beneficial ownership. End-user rules attach to parties, and corporate structures can obscure which party a customer ultimately belongs to. This is why current licence conditions push KYC obligations onto the consignee — the operator is better placed than the regulator to know its own customers.
  3. Jurisdiction. The chips are US-origin and subject to the EAR. The data centre sits in a third country under that country’s law. The customer is in a fourth. US authority reaches the hardware; reaching the commercial relationship around it depends on the conditions attached when the hardware was licensed.
  4. Visibility. Access records belong to the operator. There is no equivalent of a customs declaration that a government sees by default.
  5. Fungibility. Compute is not a widget. The same cluster serves many customers and many workloads, which makes a per-job determination about end use far harder than a per-shipment one.

To be explicit about what this article will not do: none of the above is a description of how to structure an arrangement to avoid controls, and nothing here recommends jurisdictions, structures or practices for that purpose. The point is the opposite — these are the features that make compliance and oversight demanding for everyone operating legitimately.

The Bear Case: Why the Gap May Be Smaller Than It Looks

The loophole framing assumes a static rulebook. Several things cut against it.

  • The hardware was licensed under conditions. Those chips reached a South-East Asian data centre through the US export-control system. Conditions imposed at that point — KYC, remote-user identification, IaaS commitments, prohibitions on serving restricted end users — travel with them.
  • BIS has already moved. The January 2026 rule conditions China-destined licences on exactly the remote-access questions this article is about. Analysts described it as a departure from the position that remote access alone is not an export, and as a possible precursor to broader reconsideration.
  • Legislation is pending. The Remote Access Security Act, if enacted, would make cloud access to controlled computing explicitly subject to controls. It has not passed, and the article does not assume it will.
  • Cloud providers have strong incentives. A major US provider risks its licences, its reputation and potential enforcement exposure. Compliance functions at that level are not nominal.
  • Diligence guidance already exists. BIS has published due-diligence expectations for parties dealing with advanced computing ICs, including evaluating data centres and IaaS providers, which assumes the compute-service layer is within the regulatory field of view.
  • The policy scenario worth watching: if policymakers conclude that access to compute is strategically equivalent to possession of chips, the regulatory object changes from an item to a service. That would mean licensing compute capacity by customer and country, mandatory KYC for AI-scale workloads, reporting of large training runs, and possibly technical attestation of what runs where. Each is conceivable. Each would land hardest on compliant US providers, which is the central argument against doing it, and the reason it remains a scenario rather than a forecast.

What AI Infrastructure Buyers Should Watch

Different parties face different exposure here, and the practical implications diverge.

  • Cloud and data-centre operators carry the heaviest load. Licence conditions push KYC and remote-user identification onto the consignee, which means the operator is the compliance perimeter. Worth confirming: what your licences actually require, whether customer screening extends to affiliates and ultimate parents, how remote-user records are retained, and whether your contracts let you terminate access on a compliance determination.
  • Enterprises buying compute should know where their capacity physically sits and under what authorisation. A capacity contract with an offshore provider carries counterparty risk that is regulatory as well as commercial. If rules tighten, access can be curtailed by someone else’s licence condition.
  • Investors in AI infrastructure should treat regulatory exposure as part of the asset analysis. A facility whose economics depend on a single large customer from a sensitive jurisdiction has a concentration risk that no residual-value guarantee covers.
  • Chip financiers face a version of the same problem. If compute access becomes licensable, the cash flows securing a GPU-backed facility become dependent on continued regulatory permission for specific customers.

The indicators worth tracking over the next year:

  • Whether BIS issues guidance or rulemaking addressing remote access directly
  • Whether the Remote Access Security Act or similar legislation advances
  • Enforcement actions involving cloud access rather than physical diversion
  • New licence conditions attached to data-centre exports
  • Whether allied jurisdictions hosting this capacity adopt parallel requirements
  • Public confirmations or denials from Oracle or Tencent
  • The pace of Chinese domestic accelerator deployment, which determines how long offshore demand persists

The Two Objects

The physical chip and the computing capability it produces are becoming two different economic objects, and the regulatory system currently has a mature apparatus for one of them.

For the chip, there are classifications, licences, thresholds, destination rules, customs records and prosecutions. The Lui indictment shows that machinery working as intended: documents, shipments, a paper trail, charges.

For the capability, there is a growing set of conditions attached to the hardware’s export and a heavy reliance on operators to police their own customer lists. That is not nothing. It is a different kind of control, enforced at a different point, with evidence held by private parties.

Whether that constitutes a gap depends on what you think controls are for. If the objective is preventing controlled hardware from reaching restricted destinations, the current system is working and the Tencent arrangement does not defeat it. If the objective is preventing restricted parties from obtaining frontier AI capability, hardware location is an increasingly indirect proxy for the thing being controlled.

That is the question policymakers have not yet answered out loud, and every structure described in this article is a bet on which answer arrives first.

FAQ

This section is informational analysis, not legal advice. Anyone with a live transaction should take export-control counsel.

What are AI chip leasing export controls?

The term describes how US export rules apply when a customer leases access to advanced AI chips rather than buying them. The chips themselves are controlled under the Export Administration Regulations and require licences for certain destinations and end users. Leasing arrangements raise a separate question: whether providing remote access to those chips’ computing power is itself a controlled activity.

Can companies legally lease AI compute from another country?

Generally yes, subject to the applicable rules. Remote access to computing power is not ordinarily treated as an export of the underlying chip under longstanding BIS practice. That does not make any particular arrangement lawful: end-user restrictions, end-use prohibitions and conditions attached to the chips’ original export licences all continue to apply.

Do US export controls apply to offshore GPU cloud services?

In several ways. The chips must be lawfully exported to the data centre. Licence conditions issued since January 2026 for China-destined advanced chips require the consignee to apply KYC screening to prevent unauthorized remote access and, where it provides IaaS, to identify remote end users in countries of concern. Prohibitions on supplying listed parties or prohibited end uses apply regardless of location.

Is renting GPU compute the same as importing AI chips?

No. Importing involves a physical item crossing a border with an identifiable consignee and customs record. Renting compute involves a contractual right to run workloads on hardware that stays where it is. The export-control analysis differs because the regulated item does not move, though end-user and end-use rules still apply.

Why are companies using offshore AI compute?

Speed and capability. Capacity exists now, the hardware is generations ahead of what is available inside China, and the arrangement is an operating expense rather than a capital import requiring approval on both sides.

Can China access advanced AI chips through overseas data centres?

Chinese companies have accessed overseas compute capacity, as reported in the Oracle-Tencent case and earlier arrangements in Japan and Norway. Whether a specific arrangement complies with US controls depends on the end user, the end use, and the conditions attached to the chips’ export. No public determination has been made about the reported Oracle arrangement.

What is the difference between the DOJ smuggling case and offshore compute leasing?

In the DOJ case, prosecutors allege physical servers were routed to China through third countries using false paperwork. Those are allegations and the defendant is presumed innocent. In offshore leasing, the hardware stays in the third country and only network traffic crosses borders. The first is a classic export-control violation theory; the second turns on different questions.

Will export controls eventually cover AI compute access?

Possibly. The Remote Access Security Act would make cloud access to controlled computing explicitly subject to controls, but it has not been enacted. Current licence conditions already impose KYC and IaaS obligations that reach remote users indirectly. Whether that extends into direct regulation of compute access is a policy choice that has not yet been made.


Keep reading

AI Chip Leasing Export Controls

AI Chip Leasing Export Controls and the Tencent Deal

Tencent has reportedly agreed to pay about $7 billion over five years for access to roughly 100,000 advanced AI chips it is not permitted to …
Misaligned Agent Activity

Misaligned Agent Activity: Who Pays When an Agent Strays

More than a hundred organisations received a notice from OpenAI they did not ask for and could not act on in advance. The company had …
Hybrid AI TCO

AMD’s Hybrid AI Math: What the 40–60% Savings Model Assumes

AMD says a fleet of 500 AI PCs running half their AI work locally can cost 40 to 60% less over three years than doing …
Gemini Free Plan

Gemini Free Plan Drops to Flash-Lite Only on October 9

If you use Gemini without paying, the model picker is about to get shorter. On October 9, 2026, the Gemini Free Plan stops offering Flash …
Advertisement

Leave a Comment