Onpode
Cover art for Nvidia's A100 and H100 chips designed for AI ended up in PLA procurement despite restrictions

Nvidia's A100 and H100 chips designed for AI ended up in PLA procurement despite restrictions

July 27, 2026 · 10 min

Ryan Castillo & Jordan Hale

Approximately one in five of Nvidia's authorized China partners were supplying U.S.-blacklisted entities tied to the People's Liberation Army, according to Wire China. Moonshot AI allegedly routed banned Blackwell GB300 servers through Thailand to train Kimi K3, a 2.8-trillion-parameter model — yet Nvidia's stock rose 3.26% the day the White House accused them.

U.S. export controls imposed in October 2022 explicitly restricted shipment of Nvidia's A100 and H100 GPUs to China, citing national security concerns about their capacity to accelerate AI training for military applications. Nvidia responded by engineering reduced-capability variants—the A800 and H800 with lower NVLink bandwidth—and later the H20, L20, and L2 as China-market Hopper derivatives.

0:009:53
Get the next episode on Nvidia

Follow it free — new episodes land in your feed.

Or make your own — any topic, in minutes

More Onpode episodes on Nvidia

About this episode

On July 22nd, 2026, the White House's science and technology director publicly accused Moonshot AI of routing Nvidia GB300 Blackwell servers through Thailand to train Kimi K3 — a 2.8-trillion-parameter open-source model that dropped five days earlier and reportedly benchmarked above American frontier models. Nvidia's stock closed up 3.26% that day. This episode starts there and doesn't let go. The story isn't really about one Chinese AI company evading one export rule. It's about what happens when enforcement is designed to catch a shipment, not a network. An Nvidia-authorized reseller in China — Shanghai Pusai — held People's Liberation Army contracts while advertising compatibility with export-controlled A100 and H100 chips. Wire China found roughly one in five of Nvidia's China partners were supplying U.S.-blacklisted PLA-linked entities. Each individual actor stayed inside the legal lines. The aggregate outcome was something else. The episode also gets into the Chip Security Act — the proposed fix that cleared committee 42-0 and would embed location-verification technology directly into export-controlled hardware. The structural logic is sound. But six tracking-technology vendors publicly backed the bill in June 2026 while noting it would unlock chip markets currently off-limits to them. And separately, BIS and a House committee couldn't agree on whether a Huawei acquisition loophole even existed. You can't close a gap when one arm of the government denies it's there. The real deadline isn't regulatory. It's whether any of this matters before China's domestic chip industry makes the question moot.

Frequently asked

How did Nvidia chips get to PLA-linked entities despite U.S. export controls?

Nvidia's authorized Chinese resellers operated in a legal gray zone: marketing servers compatible with export-controlled A100 and H100 chips while holding PLA contracts was not the same legal act as shipping restricted hardware. Wire China found roughly one in five of Nvidia's China partners were supplying U.S.-blacklisted PLA-linked entities.

Did Moonshot AI use banned Nvidia chips to train Kimi K3?

White House OSTP director Michael Kratsios publicly accused Moonshot AI on July 22, 2026 of routing Nvidia GB300 Blackwell servers through Thailand to train Kimi K3, a 2.8-trillion-parameter model released July 17, 2026 that reportedly benchmarked above GPT-5.6 Sol. Moonshot engineers allegedly accessed the hardware remotely from Beijing.

What is the Chip Security Act and would it stop chip smuggling to China?

The Chip Security Act proposes embedding location-verification technology into every U.S. export-controlled chip within 180 days of enactment. It cleared committee 42-0 in March 2026. Critics note that six tracking-technology firms publicly backed the bill in June 2026 citing new revenue, and firmware spoofing could undermine hardware-level enforcement.

Were DeepSeek and Kimi K3 both built on restricted Nvidia chips?

A congressional report found DeepSeek was reportedly built on approximately 60,000 restricted Nvidia chips. Kimi K3, released July 17, 2026, allegedly used smuggled Blackwell GB300 servers routed through Thailand. Both cases illustrate the same reseller-arbitrage pattern applied to successive chip generations.

Why did Nvidia stock rise after the Moonshot AI smuggling accusation?

Nvidia's stock rose 3.26% to $205.39 on July 22, 2026 — the same day a White House official named Moonshot AI, banned Blackwell chips, and Thailand as a smuggling route. The market reaction suggests investors either doubted enforcement would follow, or had already priced in that export-control violations rarely produce lasting commercial consequences for Nvidia.

Grounded in 8 sources
White House official says Moonshot AI accessed Nvidia’s chips despite Chinese export ban - CNBC · cnbc.com
China's Moonshot AI accessed banned Nvidia chips, U.S. official says · cnbc.com
Export Controls Without Borders: How Foreign-Made Products Trigger U.S. Criminal Liability - Forbes · forbes.com
Moonshot's GB300 Alert: Export-Control Leak or Nvidia's Next Headline Risk? · ainvest.com
Nvidia circumvents restrictions: a strategic relaunch of AI chips in the Chinese market - aivancity blog · aivancity.ai
Z.ai and Huawei aren't defeating US export controls · blog.peterwildeford.com
US Chip Security Act Mandates Location Tracking on Export-Controlled AI Accelerators | BotBeat · botbeat.news
Nvidia Rose 3.26% as White House Accused Moonshot AI of Chip Smuggling · businesstech.news
Read transcript

Ryan Castillo: Jordan, quick — if someone told you the White House named a specific Chinese AI company, a specific banned chip, a specific country used to smuggle it, all in one press statement, what would you expect Nvidia's stock to do?

Jordan Hale: I mean... probably sell off? Like, that sounds like the kind of headline that spooks people.

Ryan Castillo: Up 3.26%. $205.39. July 22nd, 2026.

Jordan Hale: No way — that same day?

Ryan Castillo: Same day. Michael Kratsios goes on record — White House OSTP director — accuses Moonshot AI of routing GB300 Blackwell servers through Thailand to train Kimi K3, which is a 2.8-trillion-parameter model that dropped five days earlier and reportedly beat GPT-5.6 Sol. And Nvidia... gains. That's what we're digging into today.

Jordan Hale: Because if that's not a sell signal — a sitting White House official naming your chips in a smuggling accusation — you have to ask what the market actually thinks these export controls are for. Like, is this enforcement, or is it just... a narrative the government tells itself?

Ryan Castillo: And the controls aren't new — A100s and H100s have been restricted since October 2022. Four years. Kimi K3 apparently came out anyway, allegedly on banned Blackwell hardware, open-source, benchmarking above American frontier models. So the question isn't whether controls exist. It's whether they do anything.

Jordan Hale: And you know what gets me — the accusation is specific enough to be credible but Nvidia still goes up, which means either the market doesn't believe Kratsios, or it's already priced in that nobody follows through. Those are really different problems.

Ryan Castillo: But pump the brakes on 'the controls failed' — because that framing already assumes they were designed to hold at the reseller layer. They weren't.

Jordan Hale: Wait — what do you mean, not designed to?

Ryan Castillo: Think about it this way. A licensed gun shop takes in a trade-in from someone who turns out to be connected to a gang. The shop didn't sell the gang a gun. Did it break the law? Maybe not. That's Shanghai Pusai — an Nvidia-authorized solution provider, advertising AI servers compatible with export-controlled A100 and H100 chips, while simultaneously holding PLA contracts. Two facts that are each legal on their own.

Jordan Hale: Right — but the part that doesn't fit is, like... advertising compatibility isn't the same as shipping the chip. And that gap is actually doing a lot of work here, legally.

Ryan Castillo: That's the exact ambiguity that made Pusai's position defensible. Marketing compatibility with a controlled chip is not the same legal act as shipping it. BIS enforces the shipment. Nobody owns the advertisement.

Jordan Hale: And you know what makes this feel less like an anomaly and more like... structural baseline? Wire China found approximately one in five of Nvidia's China partners were supplying U.S.-blacklisted entities tied to the People's Liberation Army. One in five — that's not an edge case, that's a distribution.

Ryan Castillo: And the number that matters — Nvidia still cut over half its Asian AI chip buyers when BIS widened the compliance net. Which tells you the liability math shifted, not the underlying network.

Jordan Hale: So the controls were never, I mean — they were never trying to catch a company like Pusai. They were trying to catch a shipment. And Pusai just... existed in the space between those two things.

Ryan Castillo: Exactly — and that gap isn't a bug somebody missed. It's what distributed accountability produces when no single actor holds enough risk to change behavior. The Chip Security Act's location-verification proposal — which cleared committee 42-0 in March 2026 — only closes it if someone actually faces consequences for breaching it. Which brings us back to: does anyone?

Jordan Hale: And that gap just... keeps moving outward, right? Like, Pusai was the reseller layer. Thailand is the geographic layer. It's the same arbitrage, one passport further.

Ryan Castillo: That's exactly where Moonshot closes the argument. Picture a compliance officer at a mid-tier Nvidia distributor in Singapore getting a purchase order — GB300 servers, marked 'enterprise AI infrastructure,' shipping to a Thailand data center. Legal language, legal destination. They ship it.

Jordan Hale: And then Moonshot engineers just... remote in from Beijing.

Ryan Castillo: BIS jurisdiction ends at the U.S. border. Thailand is outside it. There's no enforcement move available. Kratsios calls it out July 22nd, Scott Bessent follows with a warning that the U.S. could sanction Chinese AI models built through IP theft — and Nvidia's response is to cut over half its Asian chip buyers. After the fact.

Jordan Hale: Wait — Bessent's threat is specifically about IP theft? Not the hardware smuggling?

Ryan Castillo: Both, actually. Kratsios also alleged Moonshot built an internal platform for large-scale distillation against U.S. frontier models. So it's not just 'they got the chips' — it's 'they used the chips to clone the models.' That's the part that pulled Treasury in.

Jordan Hale: And this isn't, I mean — it's not Moonshot inventing something novel. A congressional report found DeepSeek was reportedly built on roughly 60,000 restricted Nvidia chips. So Kimi K3 on banned Blackwell hardware is just... the same playbook, newer generation.

Ryan Castillo: That's the partial win for the hot take — the kernel that survives scrutiny. The reseller arbitrage didn't break down with Moonshot. It graduated. And the proposed fix, the Chip Security Act's location-verification technology — which, by the way, six tracking-technology firms publicly backed in June 2026, which is not the same thing as good policy — that's a whole other layer we need to get into.

Jordan Hale: Yeah — six firms that profit from mandatory hardware embedding just happen to back the bill. That's the part I want to pull on.

Ryan Castillo: The six firms thing is — look, it's not disqualifying on its own. A GPS company lobbying for GPS mandates doesn't make GPS wrong. But 42-0 in committee with zero public dissent while six tracking vendors are literally on record in June 2026 saying this unlocks larger chip deals for them — that's not bipartisan clarity, that's a commercial interest wearing a security badge.

Jordan Hale: Wait — they actually said it unlocks deals? That's not even subtle.

Ryan Castillo: Their public argument was that mandatory location verification creates enough trust to sell into markets currently off-limits. Which is a revenue pitch dressed as a security argument.

Jordan Hale: Okay but — and I want to push on this — does that make the architecture wrong? Because the actual proposal, embedding location verification into every export-controlled chip within 180 days of enactment, that does attack it at the right layer. Like, Shanghai Pusai and Thailand both slipped through the reseller layer. This moves enforcement to the chip itself.

Ryan Castillo: It's the right intervention. I'll grant that. But the enforcement question doesn't disappear — it just migrates. Firmware, physical interception — somebody figures out how to spoof the location signal, now you've got a 42-0 bill that created a false ceiling.

Jordan Hale: And meanwhile Nvidia's already been doing their own version of threshold-hugging — I mean, the H20 was formally licensed for China in 2025, right alongside the A800 and H800. All engineered to stay just below the control line.

Ryan Castillo: Which is legal. That's the part that's maddening. And then separately, the House Select Committee sends a letter about a Huawei loophole enabling third-party acquisition — BIS just flatly denies the loophole exists. Same government, irreconcilable disagreement. That's not enforcement ambiguity, that's institutional fracture.

Jordan Hale: No, that's — yeah, that's actually the most damning part. You can't close a loophole when one arm of the government won't admit it's there.

Ryan Castillo: So the calibrated take is this: the Chip Security Act is structurally correct. Hardware-embedded verification is where enforcement has to go. But it's being sold by people who profit from it, passed without a single dissenting vote, into an enforcement environment where BIS and the House can't agree on what's currently broken. Whether the evasion just moves to firmware is an open question — but the alternative, leaving it at the reseller layer, already failed.

Jordan Hale: And that's — Kimi K3 specifically. It dropped July 17th. The accusation came July 22nd. The chips are already in Thailand. The distillation platform already ran. Like, the enforcement conversation is happening entirely in the past tense.

Ryan Castillo: That's the real clock. Not BIS versus Moonshot AI. It's whether location verification gets embedded in every export-controlled chip before China doesn't need Nvidia's chips at all. Huawei's already building domestically. If the next version of Kimi trains on hardware that was never subject to U.S. controls — the whole argument collapses from underneath.

Jordan Hale: And then the Chip Security Act is just... six companies billing for a ventilator on a patient who already left the building.

Ryan Castillo: Okay — 'dead' was too strong when I said it earlier. 'On life support with six companies billing for the ventilator' is probably more precise.

Jordan Hale: I'll take it. That's a genuinely uncomfortable place to end, but I think it's the honest one. Thanks for walking through all of it — this was worth the time.