Three of China's largest technology companies sit on a Pentagon blacklist. All three can still reach some of America's most advanced artificial intelligence. The trick, according to a Financial Times investigation confirmed this week by the companies involved, is not a smuggling route or a stolen password. It is a business address. OpenAI and Google have both been supplying advanced AI services to Singapore-registered subsidiaries of Alibaba, Baidu and Tencent, whose parent companies appear on the Pentagon's "1260H" list of firms Washington accuses of ties to the Chinese military.
The sales are legal. That is precisely what has rattled Washington.
American export controls are built on two categories: named entities and named places. Mainland China is restricted. Singapore is not. A Chinese firm on the 1260H list can register a subsidiary in Singapore, and on paper that unit becomes a Singaporean business, free to sign contracts its parent in Hangzhou or Shenzhen cannot. Current rules block direct access to a handful of frontier systems, including OpenAI's GPT-5.6 and Anthropic's Mythos and Fable, but they stop well short of barring Chinese-headquartered companies from using cutting-edge AI software through overseas arms. The gap is wide enough to drive a cloud contract through.
What makes this more than a paperwork story is that the same pattern already played out in hardware. Trump officials have spent months warning that loopholes let Chinese firms reach Nvidia's Blackwell chips, and Nvidia's Vera CPU has been cast by critics as another way back into China. The software layer was supposed to be the easier one to control, because a model is not a physical object that has to cross a border in a crate. It turns out that being weightless does not make it easier to stop. It just moves the choke point from customs to a login screen.
The two companies caught in the story are not defending themselves in the same way. OpenAI says it blocks direct access from mainland China but permits some Chinese-owned companies to use its services in jurisdictions where it can enforce safeguards and monitor for misuse. It also points to its own enforcement record: last month it suspended API access for Alibaba-linked users after detecting suspected "distillation", the practice of using a leading model's outputs to train a rival system, and reported the activity to the US government. "We don't think nationality alone should decide access," the company told the FT, arguing it would rather the world run on AI shaped by democratic values than on AI controlled by autocratic ones. Google says its services are available in Singapore and Hong Kong under policies that forbid distillation, while conceding the obvious limit of the approach: a line on a map does little to stop a sophisticated actor determined to route around it.
Anthropic has drawn the hardest line of the three, barring Chinese companies and the foreign entities they own from its frontier models, and lobbying Washington for broader software export controls. It has also named names, telling Congress it believed Alibaba created roughly 25,000 fake accounts to run more than 28 million interactions with Claude in breach of its terms. Alibaba, for its part, rejects the whole premise, and has asked a US court to strike it from the 1260H list, calling the designation arbitrary and capricious.
Underneath the corporate positioning sits a real policy question that nobody in Washington has answered. Should access to frontier AI be governed by who a company is, or by where it happens to be logged in? Chris McGuire, a former Biden administration official now at the Council on Foreign Relations, argues for the former: the most advanced models should stay out of Chinese firms' hands wherever those firms sign in from. The counter-argument, which OpenAI is effectively making, is that a rule written around corporate nationality would push the rest of the world toward Chinese models rather than American ones, and lose the influence that comes with being the default.
Both arguments cannot be satisfied at once, and the current rules split the difference in a way that satisfies neither. The export regime the United States spent years building around chips is now being tested on software, where the product ships instantly, the border is a terms-of-service page, and a subsidiary in the right city is all it takes to become, legally speaking, somebody else.