
The US Banned Selling AI Chips to China. So China Rented Them Back for $7 Billion.
Mahmud Hasan
October 4, 2026
The deal, as reported
On September 30, the Financial Times reported, citing people familiar with the matter, that Tencent had signed its largest overseas deal ever: a five-year lease with Oracle, estimated at about $7 billion, giving it access to roughly 100,000 advanced AI chips sitting in Oracle data centers across Southeast Asia. Around 30 percent is paid upfront — roughly $2.1 billion changing hands before a single model finishes training.
Two things the reporting does not say: whose chips they are (the accounts describe them only as "advanced AI chips"; neither company names a vendor), and whether the deal is even real. Reuters covered the FT's reporting but said it could not independently verify it. Neither Tencent nor Oracle has commented. Oracle's own September 10 earnings materials never mention Tencent. So treat this as reported, not confirmed — and then notice how much of the underlying pattern holds either way.
Renting the chips you can't buy
The reason the arrangement exists is a legal distinction most people outside export-control law have never thought about. America's semiconductor restrictions cover the physical chip. They control what can be shipped to China. They do not cover remote access to a chip that legally landed somewhere else.
That isn't a loophole anyone discovered by accident. Bureau of Industry and Security advisory opinions from 2009, 2011, and 2014 all say the same thing: cloud providers are not "exporters" under the Export Administration Regulations, and making computing capacity available remotely is not an export event. When BIS issued guidance on May 31, 2026 closing a related loophole — Chinese-headquartered subsidiaries buying restricted chips through offshore entities — it explicitly stated that data centers already operating under prior rental arrangements were not required to stop. A data center in Malaysia renting Nvidia-grade compute to a Chinese AI lab is, under current rules, a legal gray zone the regulations cannot clearly reach.
Tencent is not the first to notice. Industry reporting has tracked Chinese AI labs routing training work through Southeast Asia for over a year; ByteDance and Alibaba remain even bigger customers of the region's data centers than Tencent. What makes this deal different is the price tag and the structure: five years, locked in, with a $2.1 billion down payment. This isn't a spot purchase of cloud hours. It's a bet that the gray zone lasts half a decade.
The math of a sanctions premium
Run the division: $7 billion divided by 100,000 chips is $70,000 per chip over five years — $14,000 per chip per year, before you factor in that the figure also covers power, networking, hosting, and Oracle's margin. That is not what compute is supposed to cost when you rent it. It is what compute costs when the buyer is legally barred from the alternative.
You can see the same pressure in Tencent's own books. The company reported a 176 percent year-over-year jump in second-quarter capital expenditure — to 53 billion yuan, about $7.5 billion — driven mostly by advance payments for AI computing and data center infrastructure. Its Hunyuan models have reportedly narrowed the gap with domestic rivals like Alibaba's Qwen, and the company is pushing AI agents across its ecosystem: Xiaowei, an agent embedded in WeChat with its 1.4 billion users, and WorkBuddy, which reportedly leads China's PC-based office agent market. Compute is the constraint on all of it, and when the direct channel is closed, the workaround channel charges a premium.
Washington is already chasing this deal
Here is the part that should worry anyone signing long-term cloud contracts in Southeast Asia. The US government knows about the gray zone and is drafting the rule to close it. The Information reported in August that the Commerce Department is preparing regulations that would bar Chinese AI firms from renting GPU compute through third-country data centers in Thailand, Singapore, and elsewhere.
The catch: export-control lawyers widely acknowledge that BIS probably lacks the statutory authority to enforce it. The Remote Access Security Act — the bill that would add "remote access" to the activities BIS can regulate — passed the House 369–22 back in January 2026 and has been sitting in the Senate Banking Committee ever since. An attorney at Baker McKenzie told The Information it is "widely acknowledged" in the export-control bar that Commerce cannot reach remote access under existing law.
The proximate case the administration cites is Moonshot AI. The White House's science and technology director has publicly alleged that Moonshot ran Nvidia GB300 servers in Thailand to help train its Kimi K3 model — a claim presented without public evidence. Whether or not that specific allegation holds up, the pattern is established: the chips don't cross the border; the work does. Even Nvidia's CEO has reportedly told Congress the export controls were "a failure" — not because they failed to bite, but because the bite landed on American sellers while the buyers kept shopping.
What this actually teaches
Strip away the geopolitics and this is a story about a category error. The controls were designed for a world where computing power was inseparable from the hardware it ran on. Cloud computing ended that world a decade ago. You can now buy the output of a restricted chip — trained models, inference capacity, GPU hours — without the chip ever entering your jurisdiction, and the law has no clean vocabulary for that transaction.
Two honest predictions. First, the loophole will narrow, but slowly and messily: without the Senate act, any BIS rule on remote access is legally fragile, and cloud providers will fight it. Second, the premium is the point. Every billion dollars spent renting around restrictions is a billion dollars of incentive to build the domestic alternative — which is exactly what Huawei's chip division, SMIC, and China's national neurotech-style industrial policy are already doing. The controls bought time. They did not buy control.
For the rest of us, the practical takeaway is narrower but real. If you build anything that trains or runs models on rented GPUs — especially in Southeast Asia — your cloud region just became a policy variable, not just a latency one. Watch the Senate's Remote Access Security Act. If it passes, cloud providers worldwide become licensing gatekeepers for GPU compute, and "where the servers are" becomes a compliance question for every AI company renting capacity abroad. The $7 billion question is how long the gray zone survives. Tencent just bet it lasts five years.
References
- Financial Times, via The Business Times: "China's Tencent leases 100,000 chips from Oracle to accelerate AI push" (Oct 1, 2026) — businesstimes.com.sg
- ChinaTechNews: "Tencent Secures $7 Billion Oracle Cloud Deal to Access AI Chips" (Oct 5, 2026) — chinatechnews.com
- Reuters, via ET CIO: deal details and verification status (Oct 1, 2026) — cio.economictimes.indiatimes.com
- AI Weekly: "Commerce drafts rule to shut China's remote AI-chip access" — aiweekly.co
- TechTimes: "Commerce Drafts AI Chip Rule for Loophole" — FAQ on current legality of GPU rental — techtimes.com
- Reuters Practical Law: "What's the latest with semiconductor export controls?" (Sep 23, 2026) — reuters.com
- Gadgets Now: "Tencent Partners With Oracle for $7 Billion AI Chip Lease" — Tencent AI push details — gadgetsnow.indiatimes.com
- NineTwoThree: "Why did US chip export controls fail to stop China's AI?" — ninetwothree.co
Comments
More in Technology

GitHub Copilot Can Now Operate Your Computer. Don't Touch "Always Allow" Yet.
GitHub Copilot can now click through desktop apps like you do. It is disabled by default and asks for approval per app — and the "always allow" button is the one setting worth reading about before you touch it.
Read more
Your BIG-IP's OAuth Server Has a 9.8 Hole, and Hiding the Admin UI Won't Help
A 9.8 unauthenticated RCE on F5 BIG-IP's OAuth path is under active attack — and hiding the admin UI won't help. Here's the configuration check that decides your week.
Read more
WhatsApp's New Parental Controls Watch the Groups, Not the Messages
WhatsApp's optional teen parental controls give parents a PIN-protected dashboard over group activity, privacy, and Meta AI — while end-to-end encryption stays untouched. The design tradeoff, and the opt-in problem.
Read more