Skip to main content
AI Supply ChainPolicy Explainer· event dated Jun 1, 2026· 4 min read· in Artificial Intelligence

Bipartisan 'Cloud Security Act' Targets Major Loophole Allowing Adversaries to Rent Restricted AI Compute

New legislation aims to close a critical gap in U.S. export controls by giving cloud providers the legal cover to report foreign adversaries renting advanced AI computing power.

By Nicolas Laurent

National Security Advocates 45%Cloud Infrastructure Providers 35%Global Trade Analysts 20%
National Security Advocates
Lawmakers and defense officials focused on preventing adversaries from training military AI.
Cloud Infrastructure Providers
Tech giants seeking legal clarity to protect their platforms without violating privacy laws.
Global Trade Analysts
Economists and trade experts warning about the long-term market consequences of cloud restrictions.

Perspectives this story doesn't cover

  • Privacy Advocates
  • International Cloud Customers

For the past three years, the United States has waged a quiet, high-stakes campaign to restrict foreign adversaries from acquiring the physical hardware necessary to build frontier artificial intelligence.[4]

Through a series of escalating export controls, the Department of Commerce effectively banned the shipment of advanced semiconductors—like Nvidia’s highly coveted H100 and Blackwell chips—to nations deemed national security risks, primarily China.[4]

The strategy relied on a 20th-century model of trade enforcement: if you can stop the physical box from crossing a border, you can stop the technology from proliferating.

But the artificial intelligence boom is inherently a 21st-century phenomenon, built not just on physical hardware, but on the cloud.

While physical chip exports are heavily restricted, adversaries have historically bypassed bans by renting compute remotely.

A glaring loophole quickly emerged in the regulatory framework. While a Chinese tech firm or military contractor could no longer purchase and import a server rack of advanced American AI chips, they could simply log onto the internet and rent that exact same computing power by the hour.

Major American cloud providers—Amazon Web Services, Microsoft Azure, and Google Cloud—maintain massive data centers packed with restricted silicon. Because renting cloud compute does not involve the physical export of a good, it fell outside the traditional boundaries of export control laws.[1]

On June 26, 2026, a bipartisan coalition in the U.S. House of Representatives introduced the "Cloud Security Act" to finally close this digital backdoor.[2]

Co-led by Rep. Josh Gottheimer (D-NJ) and Rep. John Moolenaar (R-MI), Chairman of the Select Committee on China, the legislation represents a fundamental shift in how the U.S. views technology exports.[1]

"We can't let our adversaries—especially China—dodge our export controls by simply renting what they can't buy," Gottheimer stated upon the bill's introduction, highlighting the absurdity of the current enforcement gap.

Bipartisan lawmakers are pushing to modernize export controls for the digital age.

The core mechanism of the Cloud Security Act is designed to solve a complex legal bind that has paralyzed American cloud providers.

The core mechanism of the Cloud Security Act is designed to solve a complex legal bind that has paralyzed American cloud providers.

Under existing U.S. privacy laws, cloud companies are generally prohibited from disclosing customer content, usage records, or server activity to the government without a subpoena or warrant.

This created a chilling effect: even if a cloud provider's internal security team noticed a foreign entity spinning up massive clusters of AI compute for suspicious model training, alerting the Department of Commerce exposed the provider to severe legal liability.

The Cloud Security Act establishes a legal "safe harbor," amending current law to allow cloud compute providers to voluntarily report suspected misuse of their services by customers associated with U.S. adversaries.[1][2]

Furthermore, the legislation pushes for robust "Know Your Customer" (KYC) protocols for the cloud industry, mirroring the identity verification standards long required in the banking and financial sectors.[2]

The legislation provides legal cover for cloud providers to report suspicious activity without violating privacy laws.

Cloud providers will be expected to verify the true identity and geographic origin of entities renting massive swaths of AI compute, stripping away the anonymity provided by shell companies and VPNs.

This new bill acts as the enforcement mechanism for the "Remote Access Security Act," a related piece of legislation passed overwhelmingly by the House in January 2026.[3]

While the January bill gave the Commerce Department the statutory authority to regulate remote access to controlled technology, the Cloud Security Act gives the industry the actual tools and legal cover to report the violations.

For the cloud computing industry, the transition will require significant investment in compliance infrastructure, shifting their operational model from frictionless, self-serve compute to a more vetted, security-conscious onboarding process.[4]

The push to secure remote AI access has garnered sweeping bipartisan support in the House.

However, the clarity provided by the safe harbor provision is largely welcomed by an industry that has found itself caught between maximizing global revenue and inadvertently powering the military AI ambitions of foreign states.

By modernizing export controls for the cloud era, the United States is acknowledging that in the artificial intelligence race, computing power is the ultimate strategic resource—whether it sits in a server room in Beijing or is accessed remotely from a data center in Virginia.[2]

The stakes

As artificial intelligence becomes a critical national security asset, controlling who can build frontier models is just as important as controlling physical weapons. This legislation fundamentally rewrites the rules of the global tech trade, shifting the battleground from shipping containers to cloud data centers.

The essentials

  • U.S. export controls currently ban the physical sale of advanced AI chips to foreign adversaries like China.
  • A major loophole allows these adversaries to simply rent the same computing power from U.S. cloud providers.
  • The bipartisan Cloud Security Act aims to close this gap by establishing 'Know Your Customer' rules for cloud companies.
  • The bill creates a legal 'safe harbor' so providers can report suspicious activity without violating privacy laws.
  • The legislation acts as the enforcement mechanism for the previously passed Remote Access Security Act.

Open questions

  • How strictly the Department of Commerce will define the 'Know Your Customer' requirements for cloud providers.
  • Whether foreign adversaries will simply use layers of international shell companies to bypass the new identity verification checks.
  • How quickly the Senate will take up the companion legislation to move the bill to the President's desk.

Glossary

Export Controls
Federal regulations that restrict the shipment of certain sensitive technologies or goods to foreign countries for national security reasons.
Cloud Compute
The delivery of computing services—including servers, storage, and processing power—over the internet, allowing users to rent hardware rather than own it.
Safe Harbor
A legal provision that protects a company from liability or penalty as long as certain conditions are met, such as voluntarily reporting a security threat in good faith.
Know Your Customer (KYC)
A mandatory process of identifying and verifying the identity of a client, traditionally used in finance but now being proposed for digital infrastructure.

Sources

Source coverage

4 outlets

3 viewpoints surfaced

National Security Advocates 45%Cloud Infrastructure Providers 35%Global Trade Analysts 20%
  1. [1]NextgovNational Security Advocates

    Preventing AI chip access via cloud computing

    Read on Nextgov
  2. [2]The Ripon AdvanceNational Security Advocates

    Moolenaar's bipartisan bill would protect U.S. export controls for AI chips

    Read on The Ripon Advance
  3. [3]China Economic ReviewGlobal Trade Analysts

    US passes bill to prevent Chinese access to AI chips via cloud services

    Read on China Economic Review
  4. [4]QuartzCloud Infrastructure Providers

    The Commerce Department is cracking down on AI chip exports to Chinese firms abroad

    Read on Quartz

Comments

Stay informed

Every angle. Every day.

Get Artificial Intelligence stories with full source coverage and perspective breakdowns delivered to your inbox.