Several recent studies indicate that amidst the ongoing restrictions on the export of advanced artificial intelligence (AI) chips to China from the United States, certain controlled NVIDIA chips and servers with high-end GPUs may be entering China through third countries in Southeast Asia. Research institutions point out that existing public data only reveal partial transactions but already reflect enforcement challenges regarding transshipment in third countries, verification of end users, and corporate ownership.
Epoch AI, an AI research institution, released a special report on September 17 titled “Trade Data: Trade Value Over $3 Billion in Chips Smuggled into China via Malaysia.” It revealed that between April 2024 and June 2025, Chinese customs records showed servers imported from Malaysia valued at approximately $3.75 billion, while Malaysia declared exports to China at around $600 million. The declared quantities of equipment from both countries were quite similar, with Malaysia reporting exports of about 36,700 units and China recording imports of around 35,500 units; the main discrepancy lies in the declared values, which average about $17,000 per unit in Malaysia and approximately $106,000 in China.
Epoch AI indicated that this anomaly aligns with known cases of transshipment involving AI servers, where middlemen reroute servers with high-end GPUs through locales like Malaysia and potentially declare them under the guise of ordinary servers.
The institution estimated that this trade flow could potentially represent the transfer of computational power equivalent to around 150,000 units of NVIDIA H100 or H100-equivalent (H100e) performance. The H100 is a data center-grade chip introduced by NVIDIA in 2022.
This related trade flow emerged after the US expanded export controls on advanced computing chips in October 2023. At that time, the US Department of Commerce implemented new licensing requirements for advanced chips, including NVIDIA A800 and H800, further restricting their exports to China. A800 and H800 are NVIDIA’s data center GPUs targeted at the Chinese market, based on the A100 and H100 architectures (primarily used for AI training and high-performance computing), and they had reduced certain capabilities to comply with the prevailing US export control requirements.
By July 2025, Malaysia further mandated a 30-day advance notification and permission for the export, transshipment, or transit of high-performance, US-origin AI chips. Data from Epoch AI showed a significant decrease in related high-value server traffic after the implementation of this measure.
The non-profit research organization Center for Advanced Defense Studies (C4ADS) released the “Covert Compute” report in September, analyzing channels through which restricted NVIDIA chips might enter China based on Chinese government procurement documents, Southeast Asian trade data, and corporate information.
C4ADS pointed out that from July 2025 to January 2026, Chinese universities and research institutions purchased at least 56 restricted NVIDIA chips valued at around $1.7 million. These chips were included in comprehensive procurement contracts worth hundreds of millions of dollars and acquired through companies lacking the necessary qualifications. C4ADS stated that many relevant universities and research institutions have affiliations with the Chinese government or defense industrial complex.
The second channel involves transshipment through Southeast Asia. In trade data from 2022 to 2025, C4ADS identified 50 batches of restricted NVIDIA GPUs transited through Vietnam, India, and Malaysia to Hong Kong and China, involving around $13.4 million. The report suggested that some transactions may constitute violations of export controls.
The third channel involves complex corporate ownership structures. C4ADS noted that some businesses utilize multi-layered corporate frameworks and different jurisdictions to increase the difficulty of tracing ultimate beneficiaries and end users. Using the case of Singaporean company Megaspeed International from 2023-2025, the report highlighted that the total value of NVIDIA hardware import transactions amounted to around $4.6 billion, but uncertainties remained regarding its ultimate ownership.
C4ADS emphasized that its research covered a limited six-month period and publicly available government and trade data only; it solely accounted for transactions explicitly mentioning restricted NVIDIA products, hence couldn’t fully capture the actual scale of chip transshipment and control evasion. The discovery of these cases in public data already suggests that the actual extent of the issue might surpass the bounds of current public records.
C4ADS primarily focuses on international security issues and illicit networks. Leveraging open-source intelligence (OSINT), publicly available information (PAI), and data analysis such as corporate registrations, trade records, satellite imagery, shipping data, etc., the organization intertwines dispersed data to track illicit trade, sanction evasion, arms flows, smuggling, and other transnational networks.
Citing another study by Epoch AI, the organization estimated that by the end of 2025, approximately 290,000 to 1.6 million units of NVIDIA H100 or H100-equivalent computational power might have clandestinely entered China, with a 90% confidence level towards this estimation. The median estimated value from Epoch AI is roughly equivalent to one-third of China’s existing AI computing capability.
Nevertheless, this is a model estimation, not a confirmed count of detected chips. C4ADS highlighted that the wide range of estimations stemmed from uncertainties regarding the undiscovered volume of illicit activities and whether the chips redirected for transshipment indeed made it to China in the end.
US restrictions on advanced AI chips have gradually evolved in recent years from “direct export limitations,” extending to end users, third-country transshipment, and corporate ownership – shifting towards managing the entire cross-border supply chain.
In January 2026, the US Department of Commerce’s Bureau of Industry and Security (BIS) announced a change in the export applications for NVIDIA H200, AMD MI325X, and similar products to China, now subjected to a “case-by-case review” when meeting specific security conditions. Applicants must demonstrate that exports won’t diminish the global semiconductor capacity accessible to current US customers, Chinese buyers need to establish customer screening and export compliance procedures, and products must undergo testing by an independent third party in the US.
Moreover, on May 31, 2026, BIS released guidelines reaffirming that if controlled advanced computing products’ ultimate entities are located in third countries but their headquarters or ultimate parent company headquarters fall in countries listed under “Country Group D:5” (nations and regions like Russia, China, Iran, North Korea, and Cuba subject to US arms embargoes) or Macau, they might still require BIS approval. This signifies that where companies are registered isn’t the sole determinant of export control applicability.
Previously, BIS had already demanded enhanced end-user and end-use investigations by enterprises, including confirming customer ownership structures, final delivery or installation addresses, and whether data centers possess the required infrastructure for actual operation of advanced AI chips like power, cooling, and space.
From a corporate perspective, it was reported that NVIDIA enhanced its scrutiny of Asian customers in 2026. Reuters cited a Financial Times report in July, stating that NVIDIA had intensified due diligence in Singapore, Malaysia, and Japan, establishing a new “whitelist” system (where customers undergo a pre-approval assessment to purchase chips), reducing over half of its Asian customers previously permitted to buy AI chips. The report noted that company employees also conducted on-site inspections of data centers, verified contracts, and interviewed end users.
Simultaneously, the US is promoting the “Pax Silica” initiative to bolster cooperation with allies and partners on semiconductor, crucial minerals, and AI infrastructure supply chains. Launched at the end of 2025, the core goal of the initiative is to establish a more secure and resilient global semiconductor supply chain in the AI era.
In Southeast Asia, Singapore was among the early signatory countries, while the Philippines officially joined in April 2026. The Philippines and the US concurrently announced plans to establish a 4,000-acre economic security zone and an AI industry acceleration center in the Luzon Economic Corridor, forming part of the semiconductor, AI, and advanced manufacturing supply chains.
This integration of third-country export control compliance becomes a critical aspect of supply chain collaboration: the US aims to fortify semiconductor and AI supply chains through regions like Southeast Asia, but these countries might also act as nodes for transshipment of controlled chips, necessitating stringent end-user checks and tracking of goods flow.
A report released on September 21 by the Center for Strategic and International Studies (CSIS) addressed export controls from a broader technological competition perspective, highlighting that export controls might delay China’s access to specific advanced technologies but cannot supplant the US’s own technology innovation policies.
The report advocated for export controls focusing on explicit national security “chokepoints,” coupled with long-term semiconductor R&D, talent cultivation, advanced manufacturing, and commercial investments.
This implies that the US restrictions on limited AI chips towards China encompass not only thwarting third-country transshipment but also entail managing export controls, ally cooperation, and domestic technological industry competitiveness in the global supply chain.
Meanwhile, Southeast Asian countries are also seeking their own space for AI development. Using Malaysia as an example, a Bloomberg report in September mentioned that Malaysia is evaluating various technological supply solutions, including adopting Huawei’s Ascend AI chips, as the basis for a sovereign AI initiative amounting to around 2 billion Malaysian ringgit (approximately $494 million).
The country seeks to avoid solely relying on the NVIDIA ecosystem for its national AI development. However, this presents tangible challenges as Huawei’s current chips and software ecosystem face limitations concerning performance, supply, compatibility with CUDA, and using Huawei’s Ascend could potentially raise concerns regarding US export controls. CUDA is NVIDIA’s GPU software platform, and many AI frameworks, models, and development tools revolve around CUDA.
The Malaysian case is currently in the evaluation phase, and the quantity of chips to be procured remains undetermined.
