On 22 July Michael Kratsios, director of the White House Office of Science and Technology Policy, laid out three accusations against Moonshot AI. The Chinese company allegedly distilled Fable, Anthropic's most advanced model, to develop Kimi K3; allegedly purchased servers equipped with Nvidia GB300s; and allegedly accessed additional GB300s in Thailand, "probably to train its models." Distillation, in this context, means the systematic use of a model's outputs to train or improve another model.
Six days earlier, on 16 July, Moonshot had unveiled Kimi K3: a multimodal model with 2.8 trillion parameters, native visual capabilities, and a context window of up to one million tokens. The company announced it as the first open model approaching the three-trillion-parameter threshold, though the full weight release is scheduled for 27 July.
Kratsios's accusations, however, are not all framed in the same way. The distillation of Fable is explicitly tied to the development of K3. The sentence about the GB300s refers instead, more generically, to the training of Moonshot's "models." The public statements reviewed name no Thai data centre, no operator, no system ownership, no period of use, no workload executed. It is not even clear whether the hardware was physically moved through Thailand or whether Moonshot remotely accessed machines already installed in the country. Reuters reported that the company had not immediately responded to a request for comment; the Chinese embassy in Washington called the accusations "entirely groundless."
That distinction matters. The GB300s belong to Nvidia's Blackwell Ultra platform: data-centre systems that, in the NVL72 configuration, link 72 GPUs and 36 Grace CPUs within a single rack-scale architecture. US rules require export licences for products exceeding certain thresholds of performance, density, memory and interconnect when shipped to China, or to companies headquartered or controlled in Group D:5 countries. But tracking where a machine ends up is simpler than tracking everyone who may use it once it is installed.
A server can sit in Thailand and work for a customer located somewhere else. It can be purchased, leased, reserved for a few weeks, or reached through a cloud infrastructure. If compute is sold as a service, knowing where the box was delivered is no longer enough: you need to know who obtained the credentials, who paid for the workload, and on whose behalf it was run.
The US regulatory machinery is already trying to follow that chain. In a guidance document published on 13 May 2025, the Bureau of Industry and Security listed as a risk indicator the case of an Infrastructure-as-a-Service provider unable to certify that its users are not based in China. It also recommended detailed end-user certifications, checks on parent companies, and written attestations from data centres. Sites capable of powering infrastructure above ten megawatts, according to the BIS, warrant additional scrutiny because they can provide access to large quantities of advanced chips for model training.
The guidance does, however, draw a distinction between due diligence and outright restrictions. Exports to foreign IaaS providers, changes of end user, and even services provided by US citizens or companies can trigger a licence requirement when there is knowledge that the infrastructure will be used to train models on behalf of entities based in China and that the activity could support military, intelligence or weapons-of-mass-destruction-related uses. Without that qualification, the guidance risks being read as broader in scope than the BIS declared it to be.
The centre of gravity of controls has not, therefore, simply shifted from chip to cloud. It is expanding. Oversight of the semiconductor as an object is being joined by oversight of compute as a service: rack owners, colocation companies, regional clouds, access logs, parent-company identities and contractual attestations. All the compliance work that looks like bureaucracy until it becomes foreign policy.
The United States still holds enormous power over the global semiconductor supply chain. The Moonshot episode reveals, however, the operational limit of that power, even if the American accusations are never substantiated: knowing where the hardware is does not amount to knowing who is consuming its capacity.
In this story, Thailand matters — at least for now — more as a possible geography of access than as a geography of shipment. The next time someone frames AI controls as a matter of boxes stopped at customs, it is worth asking who signs the end-user attestation and who administers the data centre. The new map starts there.
The available sources define the perimeter of the accusation. Kratsios referred to servers with Nvidia GB300 GPUs and to access to GB300s in Thailand. The sources reviewed contain no public details about any physical transit of chips through Thailand, nor about the data centre, its operator, system ownership or the exact workload. The direct link to Kimi K3 has not been publicly documented either: as reported by Reuters and The New Stack, Kratsios spoke more generally of models probably trained with that compute. The distinction matters. If compute is rented or accessed remotely, control over the shipped box counts for less than control over the capacity actually consumed.
Here the regulatory signal precedes the case. In the BIS guidance of 13 May 2025 on advanced chip diversion, the Commerce Department's Bureau of Industry and Security had already put in black and white that IaaS providers and foreign data centres can become the vehicle through which entities based in Group D:5 countries, China included, obtain training capacity. The same guidance recommends end-user certifications. It asks for information on headquarters and parent company. It asks for data-centre attestations and greater scrutiny for sites above 10 megawatts, precisely because they can provide access to large quantities of advanced chips for training. The US regulatory machinery is already trying to follow the end user beyond the physical destination of the shipment.
The centre of gravity of controls is shifting from the chip as object to compute as service. If Washington decides to tighten its grip on this terrain in earnest, the pressure will fall not only on Nvidia or on direct importers. It will fall on rack owners and colocation providers. Then on regional clouds, their access logs, their contractual attestations, and on the compliance work that looks like bureaucracy until it becomes foreign policy. The BIS guidance already anticipates this: exports to foreign IaaS providers, in-country transfers and even support provided by US persons can enter the scope of controls when there is knowledge of use on behalf of entities based in countries like China.
The United States still holds a great deal of power over the semiconductor supply chain. But episodes like this one, even when they remain at the stage of public accusation, reveal the operational limit of that power: knowing where the hardware arrives does not automatically mean knowing who is consuming the compute. In this story, Thailand matters more as a geography of access than as a geography of shipment. The next time someone tells you AI controls are a matter of boxes stopped at customs, ask them who signs the end-user attestation and who administers the data centre. The map starts there.



