US House Passed Remote Access Security Act 369-22 to Close Cloud GPU Loophole as Senate and White House Move in Parallel
Physically shipping an Nvidia H200 to China requires a Bureau of Industry and Security license. Renting time on that same chip from a Singapore data center does not. The Remote Access Security Act targets that gap directly, and three separate enforcement tracks are now converging around it.
What RASA does
The House passed H.R. 2683 (Remote Access Security Act, or RASA) by 369-22 on January 12, 2026, per analysis from Latham & Watkins citing the congressional record. The bill amends the Export Control Reform Act to give BIS explicit authority over remote access to items subject to the Export Administration Regulations (EAR), covering cloud-based and internet-mediated access, not just physical shipments.
The underlying legal gap is well-documented. BIS issued advisory opinions in 2009, 2011, and 2014 establishing that cloud providers are not "exporters" when foreign customers rent compute on their networks. A Chinese AI company that sends training data to a Malaysia-hosted cluster, runs it on US-made H100s there, and retrieves model weights never triggers the standard export-control mechanism because the chips never cross a border. RASA would change that.
Select Committee Chairman John Moolenaar (R-Mich.) said after the House vote that "the CCP's AI ambitions are being fueled by its access to American chips housed in data centers located outside of China," per Vision Times.
Why it matters now
The Senate companion bill, S. 3519, is pending before the Senate Banking, Housing, and Urban Affairs Committee per the Institute for AI Policy and Strategy. Separately, a small group within the Commerce Department has been drafting a Trump administration rule targeting the same remote-access gap, and that rule could be circulated to AI companies and industry groups as early as September 2026, per The Information (via Vision Times).
Both tracks matter because the enforcement pressure predates either outcome. BIS has begun examining whether legally structured offshore compute-rental arrangements, specifically Chinese AI firms renting GPU capacity in third-country data centers, violate the intent of US export law even when they comply with its current letter, per TechTimes citing Bloomberg. That is a meaningful shift: prior BIS enforcement targeted smuggling and diversion, not legally advised cloud transactions.
The scale of the gap adds urgency. The Institute for AI Policy and Strategy estimates offshore cloud compute arrangements could boost China's effective access to advanced US compute by at least 60 percent in 2026 relative to what chip export controls alone would permit, per IAPS.
What to watch next
If the Senate passes S. 3519, cloud providers serving cross-border customers on controlled hardware face a structural compliance shift: customer vetting and licensing procedures, not just hardware export controls. Major cloud operators with GPU capacity in Malaysia, Singapore, Japan, and the UAE have the most direct exposure. A Commerce Department rule arriving before Senate action could establish an interim enforcement framework without waiting for legislation.
The breadth of the House vote (369-22, bipartisan) signals political consensus on the principle. The question for AI-tool operators and cloud infrastructure buyers is timing: whether Senate passage or an executive rule comes first, and which of the two carries more precise carve-outs for low-risk compute services.
Sources
- What the Remote Access Security Act Means for Export Controls Compliance Programs: Latham and Watkins, March 2026
- BIS Targets Legal Cloud Compute as China AI Firms Bypass Export Controls: TechTimes, August 7, 2026
- China Finds New Routes Around US AI Chip Controls as Washington Moves to Close Cloud Loophole: Vision Times, August 31, 2026
- GPU Export Controls 2026: What It Means for Cloud Pricing: Spheron Network
- Remote Access Security Act (RASA) Issue Brief: Institute for AI Policy and Strategy, July 2026
