The Take — The chip ban's biggest hole is a rental agreement
Nscale's IPO filing has done what export controls could not: it put a number on the loophole. According to Financial Times reporting built on the company's US SEC filings, ByteDance accounted for 73% of Nscale's $33 million in 2025 revenue — and its access route was a rental agreement. Spring, a Singaporean subsidiary, contracted for 2,304 of Nvidia's B200 chips in a data center in Glomfjord, Norway, hardware that TikTok's parent cannot lawfully buy under US export controls. The company rents those chips by the GPU-hour, and the 192-page prospectus pitched to stock-market investors never names ByteDance at all. I think this is the moment to stop calling what happened a leak. A leak gets smuggled, hidden, interdicted. This was transacted in plain sight, by the hour, with an Nvidia-backed cloud company — and the correct conclusion is uncomfortable: the chip ban is not being circumvented. It is being obeyed, and that is the problem.
The distinction matters because Washington's regime was engineered for a specific instrument: the sale. The October 2022 controls and their successors sweep in advanced chips, the machines that make them, and — since January 2025 — the intermediaries who move them. What that architecture never priced in was the cloud, because a rental changes the noun. In a sale, the regime can trace a controlled object across borders; in a rental, the object stays in the United States' regulatory orbit — the Norwegian racks sit comfortably outside Chinese jurisdiction — while the compute crosses. There is no export declaration for "30 million tokens, apiece, to a Singaporean entity acting for a Chinese parent." The B200s never left Glomfjord. The thing the controls exist to withhold — frontier training compute — left anyway.

And the market has already priced this in. The Singapore angle did not come out of nowhere: in August, Bloomberg reported the US was probing Singapore-based Apex Logistics over its suspected role in smuggling servers with Nvidia chips to China, and Singapore's own government has said most of the servers that transited the country this year were bound elsewhere. Taipei has indicted nine people over AI servers smuggled to the mainland, and Washington has trained its sights on the freight middlemen. The enforcement model, in other words, treats the cloud as a shipping lane: find the container, count it, stop it. But ByteDance's arrangement wasn't a container at all — it was a lease, executed by a subsidiary in a jurisdiction happy to host it, at an Nvidia-backed company with a public listing on the line. When your enforcement model assumes contraband moves and the real contraband stays put, you are not enforcing a regime, you are decorating one.
The strongest version of the counter-case runs through the letter of the law — and it is not a weak case. Nothing in the current US framework clearly prohibits a Chinese company from renting controlled chips located outside China. The controls govern exports and certain transfers, not remote access; the Commerce Department has moved on GDP, on model weights, and on intermediaries, but there is no rule that says a data center in Norway must check the ultimate parent of the entity signing the lease. On the letter, Nscale did nothing wrong. On the incentives, the picture darkens: Nscale is a private company courting public money, and it filed a 192-page prospectus in which its dominant customer is never named. That is not the behavior of a party that believes disclosure is safe. It is the behavior of a party that believes disclosure is expensive — and it is precisely the gap between legal and safe where disclosure stops happening and enforcement starts playing catch-up.
Here is why I think the take holds anyway. The regime's defenders lean on the one number that does not scare them — $33 million, a rounding error against Nvidia's data-center revenue — and the number is doing a lot of quiet work. The whole logic of export controls is that compute converts to capability, and the regime's own unit of account was never dollars, it was GPU-hours. ByteDance's 2,304 B200s running in Norway produce exactly the same tokens as 2,304 B200s in Shenzhen — the machine does not care where its operator sits, or which flag flies over the building. If compute is the controlled substance, then controlling the object while leaving the substance on the table is not enforcement, it is a formality. And formality gets more expensive by the quarter: Washington spent 2026 chasing containers through Singapore while the substance of the policy was transacted by the GPU-hour in Norway.
What would change my mind is narrow, and worth writing down because the rebuttal matters. First: if the Commerce Department or Treasury publishes enforcement guidance that reaches remote access to US-origin chips located abroad — a theory of compute that treats where the operator sits, not where the machine sits, as the regulated event — the loophole becomes a violation, and this argument collapses into a compliance story. Second: if ByteDance's Norwegian rentals prove isolated — one customer, one facility, no replication by Alibaba, Tencent, or the frontier labs — then this is an anecdote, not a pattern, and a Take on an anecdote is just a blog post. Both tests are live, and the next quarters will run them. But the core claim here is narrower than it looks: not that the regime has failed, but that the regime's instrument — the sale — is no longer the instrument being used. ByteDance did not break the chip ban. It read it, found the noun it regulates, and rented around it.
Should a data center abroad be allowed to rent frontier chips to a company the US bars from buying them? Tell us in the comments.
Sources: Financial Times · The Decoder · Bloomberg via Techmeme