Analysis: Chinese data centres may shape ASEAN's AI norms

A report in The Diplomat argues that Chinese-built data centres could shape ASEAN's AI and privacy norms. Alibaba Cloud opened two centres in Johor in June, taking its Malaysian total to five. Chinese providers operating abroad must comply with China's cybersecurity, data security and national intelligence laws. Huawei has formed training partnerships in Indonesia. The author urges ASEAN to diversify providers, demand full visibility into data flows and retain audit powers.

Source

The Diplomat (Asia) · read the original report ↗

#asean#data centers#ai governance#china#cloud computing

Desk check · some claims need care

What the desk checked (5)
  • Alibaba Cloud opened two data centres in Johor in June, taking its Malaysian total to five. — Figure appears in source; no external document cited, attributed to the author's reporting.
  • ASEAN endorsed a Malaysia-led cross-border cloud computing framework four months before the Johor openings. — Stated in source without a named document or date; timing is relative only.
  • Chinese cloud providers operating abroad must comply with China's Cybersecurity, Data Security and National Intelligence Laws. — Laws are named in source; interpretation of compelled data access is the author's analysis.
  • Financial Times reported in November 2025 that Alibaba and ByteDance trained advanced models in Southeast Asian data centres to access Nvidia chips. — Attributed to the Financial Times; source acknowledges no independent verification.
  • Apple provided the FBI with Xu Yanjun's iCloud data under a December 2017 warrant, aiding his arrest and extradition. — Specific dated claim in source; presented as established case history without a cited court record.

Analysts’ view opinion

AI Strategic Affairs Analyst

Data centres are no longer just industrial policy — they are standards-setting strategic infrastructure. The core argument here is that ASEAN states may keep the formal authority to write their own AI and privacy rules while quietly losing the practical ability to enforce them, if the underlying infrastructure concentrates around a narrow set of providers. The fact that Chinese firms must comply with China's cybersecurity, data security and national intelligence laws even when operating abroad makes it harder to treat that dependency as purely commercial.

  • Platform lock-in is the real strategic exposure: once government agencies and regulated industries build around one provider, switching to different privacy or security standards means redesign, retraining and migration costs that can make change practically unaffordable.
  • Training is a norms channel as much as a commercial one — Alibaba Cloud's certification courses in Malaysia and Huawei's partnerships in Indonesia can shape professional habits; not inherently malicious, but durable in effect.
  • This is not a one-sided problem: the US PATRIOT Act, CLOUD Act and FISA 702 also create state pathways to data, so the question for ASEAN is whose law governs the stack, not whether any law does.
  • Reports that Alibaba and ByteDance have trained advanced models in Southeast Asian facilities to access Nvidia chips unavailable at home suggest Beijing could come to see these sites as strategic assets rather than ordinary overseas investments.
  • Because China's Data Security Law allows countermeasures against countries restricting data-technology investment or trade, tougher ASEAN audit or access rules could themselves become a friction point.

What to watch — Watch whether the Malaysia-led cross-border cloud framework ASEAN endorsed in February stays a set of principles or hardens into enforceable conditions — data-flow visibility, audit rights and genuine provider diversification.

The story offers no definitive proof that Beijing directs Chinese data centres abroad; this is a risk assessment based on legal obligations and dependency, not a demonstrated case of misuse.

Deep dive

Research brief · 8 facts · 8 dates · exam-ready

The brief

Context

Southeast Asia is attracting large-scale data centre investment as ASEAN countries push to become digital economy hubs. Much of the capital, capacity and expertise comes from Chinese cloud providers such as Alibaba Cloud and Huawei, which have embedded themselves in Malaysian and Indonesian digital infrastructure through government and business partnerships. An analysis in The Diplomat argues that because Chinese providers remain bound by China's Cybersecurity, Data Security and National Intelligence laws even when operating abroad, the technical standards and operating practices in their facilities could quietly shape ASEAN's AI and privacy norms. The author frames data centre investment as a matter of AI governance and digital sovereignty, not merely industrial policy.

Key facts

  • In June, Alibaba Cloud opened two data centres in Johor, taking Alibaba's Malaysian facilities to five — its largest data centre presence in Southeast Asia.
  • The Johor opening came four months after ASEAN endorsed a Malaysia-led framework on cross-border cloud computing covering data protection, regulatory access and cross-border data hosting.
  • Chinese cloud providers operating abroad must still comply with China's Cybersecurity Law, Data Security Law and National Intelligence Law.
  • The source compares these Chinese laws to the USA PATRIOT Act, CLOUD Act and FISA 702 as pathways for state access to data.
  • Under a warrant issued in December 2017, Apple gave the FBI iCloud data on Chinese intelligence officer Xu Yanjun, aiding his arrest in Belgium and extradition to the US the following year.
  • In 2025, Selangor state recognised Alibaba Cloud as a provider under its Multi Cloud Services initiative; Alibaba also partnered with the Malaysia Digital Economy Corporation to train SMEs.
  • In Indonesia, Huawei has partnered with the National Cyber and Crypto Agency and Institut Teknologi Del, set up a Huawei Academy, and trained the Indonesian Air Force.
  • The Financial Times reported in November 2025 that Alibaba and ByteDance were training advanced models in Southeast Asian data centres to access Nvidia chips unavailable in China.

Timeline

  1. December 2017A warrant leads Apple to provide the FBI with iCloud data on Chinese intelligence officer Xu Yanjun.
  2. The following year (after the 2017 warrant)Xu Yanjun is arrested in Belgium and extradited to the United States.
  3. 2022Indonesia enacts its data protection law.
  4. 2024A study finds vague definitions and limited enforcement weaken implementation of Indonesia's data protection law.
  5. February (four months before June opening)ASEAN endorses a Malaysia-led framework governing cross-border cloud computing.
  6. JuneAlibaba Cloud opens two data centres in Johor, Malaysia, raising its Malaysian total to five.
  7. 2025Selangor recognises Alibaba Cloud under its Multi Cloud Services initiative; Alibaba offers AI Toolkit training and certification.
  8. November 2025Financial Times reports Alibaba and ByteDance training advanced AI models in Southeast Asian data centres to access Nvidia chips.

Who has a stake

  • ASEAN governments — Risk retaining formal authority to write AI and privacy rules while losing practical ability to enforce them; need diversification, visibility and audit powers.
  • Malaysia — Led ASEAN's cross-border cloud framework while hosting Alibaba's largest Southeast Asian data centre footprint; proposed safeguards may be undercut by provider lock-in.
  • Indonesia — Huawei partnerships with the National Cyber and Crypto Agency, Institut Teknologi Del and the Air Force shape professional cybersecurity norms amid weak enforcement of its 2022 law.
  • Alibaba Cloud — Expanding facilities, AI Toolkit training and certification across Malaysian agencies, educators, students and SMEs.
  • Huawei — Positions its tools and expertise as cybersecurity "best practices" through academies and training programmes in Indonesia.
  • Beijing / Chinese state — May view Chinese-operated ASEAN data centres as strategic assets; Data Security Law authorises countermeasures against states restricting Chinese data-tech investment or trade.
  • United States — Intensifying U.S.-China AI competition makes ASEAN an increasing focus of U.S. law enforcement action; US laws also enable data access.
  • Local firms, agencies and workers — Platform lock-in makes switching providers costly, requiring ecosystem redesign, retraining and migration expenses.

Why it matters

Whoever builds and operates the data centres sets the technical specifications, security configurations and training practices that everything running on top of them must follow, so infrastructure choices become de facto governance choices. If ASEAN's digital economy is built on systems governed by another country's laws, member states could keep the formal power to write AI and privacy rules but lose the practical ability to enforce them. The stakes widen as ASEAN facilities become central to Chinese firms' access to Nvidia chips and advanced model training amid U.S.-China AI competition.

UPSC angle

Prelims pointers

  • Alibaba Cloud opened two data centres in Johor in June, taking its Malaysia total to five — its largest in Southeast Asia.
  • ASEAN endorsed a Malaysia-led cross-border cloud computing framework covering data protection, regulatory access and cross-border data hosting.
  • China's three relevant laws: Cybersecurity Law, Data Security Law, National Intelligence Law; US counterparts cited: PATRIOT Act, CLOUD Act, FISA 702.
  • Malaysia Digital Economy Corporation is the agency under the Ministry of Digital leading Malaysia's technological transformation.
  • Selangor's Multi Cloud Services initiative recognised Alibaba Cloud as a provider in 2025.
  • Indonesia's partners for Huawei programmes: National Cyber and Crypto Agency, Institut Teknologi Del, and the Indonesian Air Force.

Mains framing

Data centres are increasingly instruments of norm-setting rather than neutral industrial assets. Because only a few firms can supply data centres, compute and full cloud-AI stacks at scale, their technical specifications and operating practices propagate to every agency and business building on them; once governments and regulated industries commit, platform lock-in makes alternative privacy or security standards prohibitively costly, requiring ecosystem redesign, retraining and migration. In ASEAN this matters because Chinese providers must comply with China's Cybersecurity, Data Security and National Intelligence laws even abroad, mirroring US instruments like the CLOUD Act and FISA 702, while regional enforcement is uneven \u2014 a 2024 study found Indonesia's 2022 data protection law weakened by vague definitions and thin AI and big-data provisions, and GDPR-inspired laws have not delivered uniform standards. The strategic layer deepened after the Financial Times reported in November 2025 that Alibaba and ByteDance were training advanced models in Southeast Asian facilities to reach Nvidia chips barred in China, raising the prospect that Beijing treats these sites as strategic assets, with the Data Security Law authorising countermeasures against restrictions on Chinese data technology investment. The author's way forward is not rejection of foreign capital but diversification of providers, clarity on foreign data access obligations, building domestic AI capacity, full visibility into data flows, and preserved powers to audit and intervene against unauthorised access or foreign interference.

Key terms

ASEAN cross-border cloud framework
A Malaysia-led framework endorsed by ASEAN setting regional principles for data protection, regulatory access and cross-border data hosting.
Platform lock-in
Dependence on one provider that makes switching standards or vendors costly, requiring system redesign, retraining and migration expenses.
China's Data Security Law
Chinese law governing data handling that also authorises countermeasures against countries restricting Chinese data-technology investment or trade.
CLOUD Act / FISA 702
US legal instruments cited as enabling government access to data held by providers, comparable in effect to China's access pathways.
Malaysia Digital Economy Corporation
Agency under Malaysia's Ministry of Digital leading the economy's technological transformation; partnered with Alibaba to train SMEs.
Digital sovereignty
A state's practical ability to control and enforce rules over the digital systems and data its economy and government depend on.

Practice questions

  1. "Data centre investment is a form of AI governance, not merely industrial policy." Critically examine this claim with reference to ASEAN's reliance on Chinese cloud providers.
  2. How does platform lock-in in cloud and AI infrastructure erode a state's practical regulatory authority even when its formal legal powers remain intact? Suggest safeguards.
  3. Discuss how extraterritorial data access laws in both China and the United States complicate digital sovereignty for developing digital economies, using examples from the source.

Grounded only in the source report — figures and dates are the source's, not inferred.

Next storyDelhi CM Rekha Gupta attends Nair Summit 2026 in New Delhi →
← All stories