On September 9, 2026, a Washington-based research organization called C4ADS published a study that did not rely on anonymous sources, whistleblowers, or classified intelligence. It relied on public records.

The organization cross-referenced Chinese government procurement documents, Southeast Asian trade data, and corporate filings. What emerged was a detailed map of how restricted Nvidia GPUs — the A100, H100, and Blackwell series — continue to reach users in China despite U.S. export controls that have been tightening since 2022.

The study's central finding is not that the controls are being evaded. It is that the evidence of evasion is sitting in publicly available records, waiting to be read.

Route One: Universities and Research Institutions

The first pathway runs through China's university system.

Between July 2025 and January 2026, C4ADS identified 56 restricted Nvidia GPUs purchased by Chinese universities and research institutions, with a total value of 11.9 million renminbi (approximately $1.7 million). According to corporate and open-source records, many of the buyer institutions have reported ties to China's defense industrial base, and several have been linked to entities associated with China's intelligence community.

The method of acquisition is what makes the transactions difficult to flag. The GPUs were bundled inside larger, multi-vendor procurement contracts. A single university contract might include laboratory equipment, software licenses, and other hardware — with a handful of restricted GPUs embedded somewhere in the line items. The chip appears as one component of a much larger purchase, making it harder for export control screening to identify.

C4ADS noted that these contracts cover only a small portion of such activity. The organization used only the most recent records and included only contracts that explicitly named Nvidia products that remained controlled as of January 2026. Larger contracts involving private and military buyers did not appear in the public Chinese government documents it reviewed.

Route Two: The Southeast Asian Transit Network

The second pathway exploits the inherent complexity of the semiconductor supply chain.

C4ADS identified 50 shipments of restricted GPUs, valued at approximately $13.4 million, that passed through Vietnam, India, and Malaysia before continuing to Hong Kong or mainland China between 2023 and 2025.

Transit through multiple countries is not inherently irregular. Chip manufacturing, testing, assembly, and distribution routinely involve multiple jurisdictions. A GPU designed in California, fabricated in Taiwan, packaged in Malaysia, and tested in Vietnam has a legitimate international footprint.

That same footprint creates opportunities for the final destination to change somewhere along the chain. For enforcement agencies, the challenge is not identifying who initially purchased the chip. It is identifying who ultimately received it. The more hands a product passes through, the harder that becomes.

Route Three: Opaque Corporate Structures

The third pathway involves corporate ownership structures that are difficult to trace.

The primary example in the C4ADS report is Megaspeed International, described as a major importer of Nvidia hardware in Southeast Asia. Data analyzed by C4ADS indicates $4.6 billion in imports between 2022 and 2025.

The report notes that this figure requires a caveat. Not all of those imports were restricted chips. But the structure of Megaspeed's ownership — spanning multiple jurisdictions, including secrecy-friendly locations such as the Cayman Islands — makes it difficult to determine who ultimately controlled the entity and where the hardware went.

Reporting by Bloomberg and The New York Times has indicated that Megaspeed obtained chips from Nvidia's Blackwell lineup, which remains restricted under U.S. export controls. The central unanswered question, as C4ADS puts it, is: "Who actually controls Megaspeed?"

The Entity List Loophole

The C4ADS report was published against the backdrop of a separate investigation that illustrated a different kind of gap in the export control system.

On September 6, 2026, The New York Times published a report on Aivres, a California-based server maker. Aivres is the U.S.-based subsidiary of Inspur Group, a Chinese server manufacturer that was added to the U.S. Entity List in 2023.

Aivres itself does not appear on the Entity List.

Between April 2024 and February 2026, Aivres exported at least $5.6 billion in advanced technology to Southeast Asia, including more than $3 billion in computers equipped with Nvidia's most advanced Blackwell chips. Those servers ultimately served Chinese customers, including ByteDance and Alibaba, according to the Times.

The gap is structural. The Entity List prohibits U.S. companies from selling to listed entities. It does not automatically prohibit U.S.-based subsidiaries of listed entities from operating, provided the subsidiary itself is not listed. Inspur was listed. Aivres was not.

When the Times report was published, Inspur's Shenzhen-listed unit fell 3.8%. A financial columnist quoted by Eastmoney noted: "Aivres has been legally purchasing Nvidia's Blackwell chips as a US entity for some time. If it were sanctioned, that channel would be shut off."

The Trump administration had previously acknowledged this gap. In June 2026, officials expressed concern that a loophole in U.S. rules allowed Chinese companies to acquire banned chips through overseas subsidiaries. New guidance was issued to close it — after the chips may have already moved.

The Enforcement Gap

The common thread across these three routes is not sophistication. It is the difficulty of enforcing export controls after the hardware leaves the point of sale.

The Institute for Security and Technology, a think tank that tracks export control policy, published a report in early 2026 assessing the Bureau of Industry and Security's H200 licensing rules. The researchers concluded that verifying end uses in China is "structurally very difficult and will be challenging to implement." Their assessment was blunt: "The effectiveness of these controls will hinge less on their formal stringency and more on how credibly they can be audited and enforced once chips and end users are located in China, where U.S. leverage is inherently limited."

The report identified specific mechanisms that complicate enforcement. Chips can be redirected after import. Restricted entities can use shell companies to make purchases. China's military-civil fusion blurs the distinction between commercial and military use. And in the absence of a dedicated controls regime for cloud services, platforms have become a path of least resistance — with China-linked actors accessing cloud service providers by obscuring their identities through intermediaries.

C4ADS itself was careful to note the limits of its findings. "Public records capture only a fraction of illicit transfers," the organization wrote, "and these investigations almost certainly understate the true volume of diverted chips."

What the Records Show

The export control debate in Washington has focused on tightening the rules. New licensing requirements, new Entity List additions, new congressional bills — each designed to close a gap identified by the last enforcement action.

The C4ADS study suggests that the gaps are not always in the rules. They are in the enforcement. The records it analyzed were not secret. They were Chinese government procurement documents, Southeast Asian trade filings, and corporate registrations. They were available to anyone willing to cross-reference them.

What the records show is a system in which restricted hardware continues to move through channels that are visible in retrospect but difficult to police in real time. A university bundles a GPU into a larger contract. A shipment transits through three countries. A company with an opaque ownership structure imports billions of dollars in hardware.

Each individual step has a legitimate explanation. The pattern, viewed as a whole, does not.

The export control system is not failing because the rules are weak. It is failing because the enforcement mechanisms were not designed to track hardware after it leaves the point of sale. The evidence of that failure is not classified. It is in the public record.

Sources: C4ADS "Covert Compute" report (September 9, 2026); Hardware.com.br (September 21, 2026); Asia Times (September 7, 2026); The New York Times (September 6, 2026); The Hill (September 23, 2026); Institute for Security and Technology report via Export Compliance Daily (March 3, 2026); The Next Web (June 5, 2026); Nvidia Q2 FY2027 earnings via Yahoo Finance (September 22, 2026).

Disclaimer

The information provided in this article is for general informational and educational purposes only. It does not constitute legal, financial, or professional advice. The author and publisher are not responsible for any actions taken based on the content of this article. Readers should consult qualified professionals for advice specific to their situation. All trademarks and references to third-party products, services, or organizations are the property of their respective owners. The performance data and benchmarks discussed are based on specific research studies and may not generalize to all use cases or environments. As of the publication date, the AI landscape continues to evolve rapidly, and readers should verify current information independently.

Limitations

This analysis is based on reporting and public data available as of the article date; figures may be revised as sources update.

Forecasts from third-party analysts can change with market conditions.

Cost and pricing examples are point-in-time estimates; actual rates vary.

Country and company comparisons rely on public reporting, not operational data.

This sector moves fast; timelines and deal terms may be updated later.

Company deals and regulatory rulings may evolve; verify current status.

AI infrastructure is changing quickly; claims can become outdated soon.


Sources

  1. C4ADS "Covert Compute" report (September 9, 2026)
  2. Hardware.com.br (September 21, 2026)
  3. Asia Times (September 7, 2026)
  4. The New York Times (September 6, 2026)
  5. The Hill (September 23, 2026)
  6. Institute for Security and Technology report via Export Compliance Daily (March 3, 2026)
  7. The Next Web (June 5, 2026)
  8. Nvidia Q2 FY2027 earnings via Yahoo Finance (September 22, 2026).

The information provided in this article is for general informational and educational purposes only. It does not constitute legal, financial, or professional advice. The author and publisher are not responsible for any actions taken based on the content of this article. Readers should consult qualified professionals for advice specific to their situation. All trademarks and references to third-party products, services, or organizations are the property of their respective owners. The performance data and benchmarks discussed are based on specific research studies and may not generalize to all use cases or environments. As of the publication date, the AI landscape continues to evolve rapidly, and readers should verify current information independently.

Limitations: This analysis is based on reporting and public data available as of the article date; figures may be revised as sources update.; Forecasts from third-party analysts can change with market conditions.; Cost and pricing examples are point-in-time estimates; actual rates vary.; Country and company comparisons rely on public reporting, not operational data.; This sector moves fast; timelines and deal terms may be updated later.; Company deals and regulatory rulings may evolve; verify current status.; AI infrastructure is changing quickly; claims can become outdated soon.