Markets 16 September 2026 12 min read

Less Than 1% Against $5.6bn (September 2026): The Licensed Route Into China Is a Rounding Error — and Nvidia's Own Geography Table Disclaims the Rest

Licensed H200 sales are under 1% of Nvidia's Data Center revenue while $5.6bn moved through one US subsidiary. The enforcement mechanism, explained.

Less Than 1% Against $5.6bn (September 2026): The Licensed Route Into China Is a Rounding Error — and Nvidia's Own Geography Table Disclaims the Rest
Photo: public domain, via Wikimedia Commons.

Less Than 1% Against $5.6bn (September 2026): The Licensed Route Into China Is a Rounding Error — and Nvidia's Own Geography Table Disclaims the Rest

Two numbers published within a fortnight of each other describe the same subject and refuse to sit in the same sentence. Nvidia's 10-Q for the quarter ended 26 July 2026 says that shipments made under the US government's H200 licensing programme — the legal, permitted, politically negotiated route into China — account for less than 1% of Data Center revenue, against $89.0 billion of Data Center revenue in the quarter. On 6 September the New York Times reported that one California server maker, the renamed US operation of a blacklisted Chinese parent, exported at least $5.6 billion of advanced technology to Southeast Asia over twenty-two months, more than $3 billion of it Blackwell-based systems ultimately serving Chinese customers. With Xi Jinping due at the White House on 24 September and a first bilateral AI dialogue tentatively pencilled in, the question worth understanding is not who is guilty. It is why a control regime that works on boxes keeps missing a product that is sold by the hour.

Key takeaways
  • The licensed channel is a rounding error. Nvidia's 10-Q states H200 licensing-programme shipments were less than 1% of Data Center revenue in the July quarter, after a $0.4bn excess-inventory charge in the first half as demand for the part diminished.
  • The contested channel is not. The New York Times reported $5.6bn of advanced technology exported to Southeast Asia between April 2024 and February 2026, over $3bn of it Blackwell systems. No charge has been brought; the reporting does not establish a breach.
  • Control law counts ownership, not usage. Renting accelerator-hours in a third country sits outside the regime as written — a point made on the record in August 2026 by a compute-policy researcher, not a claim invented here.
  • The geography table is not a destination map. Nvidia books revenue by direct customer headquarters and says in the same paragraph that end customer and shipping location may differ. Taiwan: $26,985m in the quarter, from $8,902m a year earlier.
  • The fix is drafted but not law. The Remote Access Security Act passed the House 369–22 on 12 January 2026 and is still sitting in the Senate; even enacted, BIS would have to write the rule.
  • Sizing matters. Twenty-two months of the disputed channel is about 5.8% of a single Nvidia quarter. This is a legal and diplomatic risk, not a revenue-line one — unless a remote-access rule reaches demand that the China line never contained.
  • See how the rate, risk and growth factors are scoring the eight majors right now on the live meter.

The two numbers, and why they belong to different systems

Start with the filing, because it is the least contested document in the story. Nvidia disclosed that the US government granted licences allowing it to ship small amounts of H200 products to specific China-based customers, that those sales were then restricted by the PRC government, and that the company has been unable to sell all the product for which it holds licences. It took a $0.4 billion charge in the first half of fiscal 2027 for excess H200 inventory and purchase obligations as demand for the part diminished. The licences require each unit to pass a US inspection before shipment, which attracts a 25% tariff on importation into the United States, a cost the company says it has been unable to pass to customers.

That is what a fully legal, bilaterally sanctioned trade channel looks like after two years of negotiation: under 1% of Data Center revenue, a write-down attached, a tariff on the way through, and a buyer's own government discouraging the purchase.

Now set the other number beside it. Twenty-two months, $5.6 billion, more than half of it Blackwell-based systems. Divide it out and the run rate is roughly $255 million a month of hardware following a path the rules did not contemplate — not smuggled in a suitcase, but exported through ordinary channels to ordinary destinations and then, per the reporting, ending up serving customers the controls were written to exclude.

Channel Verified figure Source
H200 licensed shipments to China <1% of Data Center revenue, Q2 FY2027 Nvidia 10-Q, quarter ended 26 Jul 2026
Data Center revenue, same quarter $89,023m Nvidia 10-Q
H200 excess-inventory charge, H1 FY2027 $0.4bn Nvidia 10-Q
Reported Aivres exports to SE Asia, Apr 2024–Feb 2026 $5.6bn (>$3bn Blackwell systems) New York Times, 6 Sep 2026
Revenue booked to Taiwan-HQ customers, Q2 FY2027 $26,985m (28.0% of total) Nvidia 10-Q
Revenue booked to China/HK-HQ customers, Q2 FY2027 $7,880m (8.2% of total) Nvidia 10-Q
Remote Access Security Act, House vote 369–22, 12 Jan 2026 H.R.2683

What the rule actually controls: an owner, a box, a border

Export control is a property regime. It attaches to an item, asks who owns or controls it, and asks which border it crosses. Everything in the architecture follows from that, and so does everything that leaks out of it.

Inspur Group was added to the Entity List in March 2023; six of its subsidiaries were added in March 2025. In September 2025 BIS introduced its affiliates rule, extending listings down through ownership chains rather than name by name — an admission in policy design that the entity-by-entity approach was being outrun by corporate restructuring. Then on 31 May 2026 Commerce issued guidance confirming that licence requirements for advanced AI chips apply to all businesses with headquarters or a parent company in China, wherever the business is physically located. Asked whether it was enforcing pre-existing licence requirements after the previous administration's diffusion framework was scrapped, BIS replied: "The answer is yes." Nvidia's response at the time was that the guidance reaffirmed its existing approach — licences are required to ship controlled products to PRC-headquartered companies.

Read those three steps as one motion. Each closes the previous gap by extending the ownership test: from the parent, to the subsidiaries, to the headquarters. Every extension is a tighter answer to the question "whose box is this?" None of them touches the question of who is using it.

Why "legal" and "intended" are different words hereAn export-control regime is a list of prohibitions, not a statement of purpose, and the difference is where every one of these stories lives. A server assembled by a Taiwanese contract manufacturer, sold to a US-incorporated company that is not itself listed, exported under licence to a Malaysian data-centre operator and then rented by the hour to a customer in Shenzhen may involve no prohibited transaction at any single step, while producing exactly the outcome the policy exists to prevent. That is not a loophole in the pejorative sense; it is what happens when a rule written for an object is applied to a service. The corollary is the useful half. When a gap is definitional rather than criminal, prosecutions do not close it and enforcement announcements do not either — only a new definition does, which is why the legislative calendar rather than the indictment docket is the thing to watch. The primary documents are public: entity listings and guidance from the Bureau of Industry and Security, and the filings themselves at SEC EDGAR.

The second gap: renting the chip instead of owning it

The diversion story is the visible one because it leaves shipping records. The larger one leaves almost nothing.

CNBC reported in August 2026 that Chinese hyperscalers including ByteDance, Alibaba and Tencent have accessed Nvidia compute remotely via facilities in Thailand, Malaysia and Japan. Michael Kratsios, the White House science and technology adviser, accused Moonshot AI of using GB300 chips through a Thai facility less than a week after the company released a new model in July. ByteDance's reported arrangement runs through Aolani, a Singapore-headquartered cloud provider with Nvidia hardware in Malaysia; Aolani told CNBC that the companies it serves have no ownership, future claim or physical access to the chips powering its solutions, and that permitted access is fully compliant with applicable regulations.

That statement is worth reading twice, because it is almost certainly accurate and it is also the entire problem. Non-ownership is the compliance argument. Non-ownership is also irrelevant to model capability, which depends on accelerator-hours consumed, not on title held.

Fab and assemblyChips made in Taiwan, systems built by Taiwan-HQ ODMs
Licensed exportShipped to a third-country data-centre operator
Compute rentalCapacity sold by the hour; title never moves
Model weightsTrained abroad, returned as a file over the network

The infrastructure making this possible is being built for reasons that have nothing to do with export control. Real-estate firm JLL estimates global data-centre capacity could roughly double to 200GW by 2030, and DC Byte counts 31 planned 100MW-plus facilities across Malaysia, Indonesia and Thailand against just two today. That build-out would be happening if no export control existed. It simply creates, as a by-product, a large pool of advanced compute inside jurisdictions that are neither the exporter nor the destination the rules are aimed at.

Why the geography table cannot settle the argument

Here is where the market's favourite shortcut breaks. When people want to know where the chips went, they reach for Nvidia's revenue-by-geography disclosure. That disclosure explicitly tells you it cannot answer the question.

Nvidia states that revenue by geographic region is designated based on the location of the headquarters of direct customers, and that the end customer and shipping location may be different from that headquarters location. Direct customers are add-in-board makers, distributors, ODMs, OEMs, cloud providers, model developers and system integrators — the buyers of record, not the operators of the buildings.

For the quarter ended 26 July 2026: United States $60,074m, Taiwan $26,985m, China including Hong Kong $7,880m, other $1,282m, on total revenue of $96,221m. The Taiwan line alone is 28.0% of company revenue and has come from $8,902m a year earlier — roughly a tripling. That is not a statement about demand in Taiwan. It is a statement about where the contract manufacturers that assemble AI systems keep their headquarters, and those systems ship onward to whoever ordered them.

So the most-cited public dataset on chip destinations resolves, on inspection, into a dataset about corporate registration. Anyone building a view on how much advanced compute sits within reach of Chinese developers is working from an input whose own publisher has disclaimed that use. Keeping that straight is the same discipline that applies to reading a compute target without its precision attached, which is the trap examined in China's 9,800 EFLOPS five-year target.

See how the rate, risk and growth factors are scoring the eight majors right now.Open the live meter →

What would actually close it, and what closing it would cost

The drafted answer is the Remote Access Security Act, H.R.2683, which would extend BIS authority to remote access of items subject to the Export Administration Regulations. The House passed it 369–22 on 12 January 2026 — a margin that tells you the political question is settled even though the legal one is not. The Senate companion, S.3519, has not moved.

Two things follow. First, enactment would be a beginning rather than an end: BIS would still have to write a rule specifying which compute is covered, who may not reach it and what customer-verification scheme providers must operate. King's assessment was that BIS could move quickly with White House backing, and that the difficulty lies in drafting something enforceable. Second, the cost lands on cloud providers, who would carry the know-your-customer burden — which is why industry pushback is expected, and why the timeline is a function of lobbying as much as of drafting.

This is the point where politics becomes a price input rather than a subject. Xi is due at the White House on 24 September. Reuters reported that a first bilateral AI dialogue under this administration, led on the US side by Treasury Secretary Scott Bessent, was tentatively planned for mid-September, while a White House official said there was no planned AI-related meeting in that window. Whatever the venue, chip access is the highest-value item on the table, and a negotiated outcome pushes in the opposite direction to a tightening rule. Anyone reading headlines out of that summit should keep the two tracks separate: a diplomatic loosening changes the licensed channel currently worth under 1% of Data Center revenue, while a remote-access rule would change something considerably larger that does not appear in the China line at all.

Where this reaches the instruments people trade, and where it does not

Be precise about the transmission, because the loose version of this story is wrong in both directions.

The revenue at stake in the diversion narrative is small. Twenty-two months at $5.6 billion is about 5.8% of one Nvidia quarter, and the hardware in question was sold and recognised already. Enforcement against a diverter does not claw back a past sale; it removes a future buyer. A market that already marks the licensed China channel at approximately zero cannot be surprised much further down that particular line — a point developed in the quarter preview.

The revenue at stake in a remote-access rule is potentially larger and sits somewhere nobody is currently counting. Demand from third-country cloud operators is booked to whichever entity signs the purchase order, and it is part of the same flow that has driven the Taiwan line to 28% of revenue. A rule requiring those operators to vet and exclude end users adds compliance friction to a fast-growing buyer segment. That is an index-level consideration rather than a single-name one, because the concentration of a handful of AI-complex names in US500 and NAS100 means a policy shift affecting their order books reaches the index through its largest weights.

The currency channel is the honest place to stop short. There is no clean FX trade in an export-control rulemaking, and pretending otherwise would be the same category error as reading a headquarters table as a shipping manifest. What exists is second-order: chip policy is one input into the risk-sentiment factor, and a summit outcome read as de-escalation is mildly risk-positive in the way that usually flatters the growth-linked currencies and takes a little of the haven bid out of the dollar. That is a small, conditional, easily-swamped effect, and the live read on it belongs on the USD factor page rather than in a forecast here. The reasoning behind separating factors that way is set out on the about page.

What would change the picture

Four things, in rough order of how much they would move:

Senate action on S.3519. A committee vote would convert a settled political question into a live legal one and start the BIS rulemaking clock.

A BIS rule on remote access, with or without the statute. Watch for the definition of covered compute and the customer-verification standard; the enforceability of those two clauses is the whole rule.

An outcome from the 24 September summit that touches chips explicitly. A licensing expansion and a remote-access crackdown are opposite signals and can arrive in the same week.

Any enforcement action naming an entity in the third-country chain. Not because the penalty would matter financially, but because it would signal that Commerce believes existing authority already reaches the conduct — which would remove the need for the statute and accelerate everything above.

Until one of those lands, the gap stays open because it is definitional, and the most reliable thing to do with the story is to stop treating published geography as geography. The related question of what happens to prices when policy reroutes physical supply is traced in mature-node chip pricing.

Educational macro context only — not investment advice.

Advertisement

Frequently asked

How do Chinese companies still get access to Nvidia's most advanced chips?
Through two gaps that work differently, and only one of them involves a chip physically entering China. The first is diversion — hardware is exported lawfully to a third country and its ownership or control ends up somewhere the rules did not intend. The second, and the harder one, is remote access, where a Chinese firm never buys or owns the hardware at all and instead rents compute time on machines sitting in a data centre elsewhere in Asia. Cassia King, senior researcher on the compute policy team at the Institute for AI Policy and Strategy, told CNBC in August 2026 that such an arrangement was legal so long as the Chinese customer is not actually buying and owning the physical hardware directly, because the US export-control regime, in her words, controls physical AI chips and does not cover remote access to those chips. That is not a claim about who is breaking the law. It is a description of what the law counts — a box, an owner and a border crossing. Training a frontier model consumes none of those things; it consumes accelerator-hours, which cross borders as a network session.
What is the Aivres and Inspur export-control story?
On 6 September 2026 the New York Times published an investigation reporting that Aivres, a California-based server maker, exported at least $5.6 billion of advanced technology to Southeast Asia between April 2024 and February 2026, including more than $3 billion of computers built around Nvidia's Blackwell chips, and that the servers ultimately served Chinese customers including ByteDance and Alibaba. Aivres is the renamed US operation of Inspur Group, which the US Commerce Department added to the Entity List in March 2023; six further Inspur subsidiaries were added in March 2025, and Aivres was not among them. No charge has been brought and the reporting does not establish that any law was broken — which is precisely what makes it a policy story rather than a criminal one. Nvidia's stated position is that it does not support diversion of its products and sells to established partners that work with it to comply with US export rules.
What is the Remote Access Security Act and has it become law?
The Remote Access Security Act, H.R.2683, sponsored by Representative Michael Lawler, would give the Commerce Department's Bureau of Industry and Security authority to regulate remote access to items subject to the Export Administration Regulations — extending export control beyond the shipment of hardware to the renting of it. The House passed it on 12 January 2026 by 369 votes to 22. It has not become law; a Senate companion, S.3519, introduced in December 2025 by Senators Dave McCormick and Ron Wyden with Tom Cotton and Chris Coons, sits with the Senate Banking Committee. Passage alone would not close anything either. Michelle Nie of the Center for a New American Security told CNBC the bill would grant the authority to regulate remote access but that BIS would still need to write a rule — deciding which compute is covered, who is barred from reaching it, and what know-your-customer scheme cloud providers must run. King's estimate was that BIS could move in a matter of days with White House support; the hard part is writing something enforceable.
How much revenue does Nvidia actually make from China right now?
Far less than the political temperature implies, and the company's own filing says so in unusually plain language. In its 10-Q for the quarter ended 26 July 2026, Nvidia disclosed that the US government granted licences allowing it to ship small amounts of H200 products to specific China-based customers, that those sales were restricted by the PRC government, and that it has been unable to sell all the products for which it holds licences. It took a $0.4 billion charge in the first half of fiscal 2027 for excess H200 inventory and purchase obligations as demand for the part diminished, and states that shipments made under the licensing programme account for less than 1% of Data Center revenue in the most recent quarter. Data Center revenue that quarter was $89.0 billion. The licences also require the H200s to pass a US inspection before shipment, which subjects them to a 25% tariff on importation into the United States — a cost Nvidia says it has been unable to pass on.
Why can't Nvidia's geographic revenue table tell you where the chips ended up?
Because it was never designed to, and the filing says so directly above the numbers. Nvidia states that revenue by geographic region is designated based on the location of the headquarters of direct customers, and that the end customer and shipping location may be different from that headquarters location. A direct customer is typically an original design manufacturer, distributor, system integrator or cloud provider, not the operator of the building the machine finally runs in. That is why the Taiwan line was $26,985 million in the quarter to 26 July 2026, against $8,902 million a year earlier — Taiwan-headquartered contract manufacturers assemble the systems and ship them onward to whoever ordered them. Reading that line as a statement about where compute is installed is a category error, and the company's own footnote is the warning label.
PT
Pip Theory desk

We build the tools we write about. Educational macro context only — never investment advice.

About the desk