Bipartisan 'Cloud Security Act' Targets Major Loophole Allowing Adversaries to Rent Restricted AI Compute
New legislation aims to close a critical gap in U.S. export controls by giving cloud providers the legal cover to report foreign adversaries renting advanced AI computing power.
- National Security Advocates
- Lawmakers and defense officials focused on preventing adversaries from training military AI.
- Cloud Infrastructure Providers
- Tech giants seeking legal clarity to protect their platforms without violating privacy laws.
- Global Trade Analysts
- Economists and trade experts warning about the long-term market consequences of cloud restrictions.
Perspectives this story doesn't cover
- Privacy Advocates
- International Cloud Customers
For the past three years, the United States has waged a quiet, high-stakes campaign to restrict foreign adversaries from acquiring the physical hardware necessary to build frontier artificial intelligence.[4]
Through a series of escalating export controls, the Department of Commerce effectively banned the shipment of advanced semiconductors—like Nvidia’s highly coveted H100 and Blackwell chips—to nations deemed national security risks, primarily China.[4]
The strategy relied on a 20th-century model of trade enforcement: if you can stop the physical box from crossing a border, you can stop the technology from proliferating.
But the artificial intelligence boom is inherently a 21st-century phenomenon, built not just on physical hardware, but on the cloud.
A glaring loophole quickly emerged in the regulatory framework. While a Chinese tech firm or military contractor could no longer purchase and import a server rack of advanced American AI chips, they could simply log onto the internet and rent that exact same computing power by the hour.
Major American cloud providers—Amazon Web Services, Microsoft Azure, and Google Cloud—maintain massive data centers packed with restricted silicon. Because renting cloud compute does not involve the physical export of a good, it fell outside the traditional boundaries of export control laws.[1]
On June 26, 2026, a bipartisan coalition in the U.S. House of Representatives introduced the "Cloud Security Act" to finally close this digital backdoor.[2]
Co-led by Rep. Josh Gottheimer (D-NJ) and Rep. John Moolenaar (R-MI), Chairman of the Select Committee on China, the legislation represents a fundamental shift in how the U.S. views technology exports.[1]
"We can't let our adversaries—especially China—dodge our export controls by simply renting what they can't buy," Gottheimer stated upon the bill's introduction, highlighting the absurdity of the current enforcement gap.
The core mechanism of the Cloud Security Act is designed to solve a complex legal bind that has paralyzed American cloud providers.
The core mechanism of the Cloud Security Act is designed to solve a complex legal bind that has paralyzed American cloud providers.
Under existing U.S. privacy laws, cloud companies are generally prohibited from disclosing customer content, usage records, or server activity to the government without a subpoena or warrant.
This created a chilling effect: even if a cloud provider's internal security team noticed a foreign entity spinning up massive clusters of AI compute for suspicious model training, alerting the Department of Commerce exposed the provider to severe legal liability.
The Cloud Security Act establishes a legal "safe harbor," amending current law to allow cloud compute providers to voluntarily report suspected misuse of their services by customers associated with U.S. adversaries.[1][2]
Furthermore, the legislation pushes for robust "Know Your Customer" (KYC) protocols for the cloud industry, mirroring the identity verification standards long required in the banking and financial sectors.[2]
Cloud providers will be expected to verify the true identity and geographic origin of entities renting massive swaths of AI compute, stripping away the anonymity provided by shell companies and VPNs.
This new bill acts as the enforcement mechanism for the "Remote Access Security Act," a related piece of legislation passed overwhelmingly by the House in January 2026.[3]
While the January bill gave the Commerce Department the statutory authority to regulate remote access to controlled technology, the Cloud Security Act gives the industry the actual tools and legal cover to report the violations.
For the cloud computing industry, the transition will require significant investment in compliance infrastructure, shifting their operational model from frictionless, self-serve compute to a more vetted, security-conscious onboarding process.[4]
However, the clarity provided by the safe harbor provision is largely welcomed by an industry that has found itself caught between maximizing global revenue and inadvertently powering the military AI ambitions of foreign states.
By modernizing export controls for the cloud era, the United States is acknowledging that in the artificial intelligence race, computing power is the ultimate strategic resource—whether it sits in a server room in Beijing or is accessed remotely from a data center in Virginia.[2]
The stakes
As artificial intelligence becomes a critical national security asset, controlling who can build frontier models is just as important as controlling physical weapons. This legislation fundamentally rewrites the rules of the global tech trade, shifting the battleground from shipping containers to cloud data centers.
The essentials
- U.S. export controls currently ban the physical sale of advanced AI chips to foreign adversaries like China.
- A major loophole allows these adversaries to simply rent the same computing power from U.S. cloud providers.
- The bipartisan Cloud Security Act aims to close this gap by establishing 'Know Your Customer' rules for cloud companies.
- The bill creates a legal 'safe harbor' so providers can report suspicious activity without violating privacy laws.
- The legislation acts as the enforcement mechanism for the previously passed Remote Access Security Act.
Open questions
- How strictly the Department of Commerce will define the 'Know Your Customer' requirements for cloud providers.
- Whether foreign adversaries will simply use layers of international shell companies to bypass the new identity verification checks.
- How quickly the Senate will take up the companion legislation to move the bill to the President's desk.
Glossary
- Export Controls
- Federal regulations that restrict the shipment of certain sensitive technologies or goods to foreign countries for national security reasons.
- Cloud Compute
- The delivery of computing services—including servers, storage, and processing power—over the internet, allowing users to rent hardware rather than own it.
- Safe Harbor
- A legal provision that protects a company from liability or penalty as long as certain conditions are met, such as voluntarily reporting a security threat in good faith.
- Know Your Customer (KYC)
- A mandatory process of identifying and verifying the identity of a client, traditionally used in finance but now being proposed for digital infrastructure.
Sources
[1]NextgovNational Security AdvocatesPreventing AI chip access via cloud computing
Read on Nextgov →
[2]The Ripon AdvanceNational Security AdvocatesMoolenaar's bipartisan bill would protect U.S. export controls for AI chips
Read on The Ripon Advance →
[3]China Economic ReviewGlobal Trade AnalystsUS passes bill to prevent Chinese access to AI chips via cloud services
Read on China Economic Review →
[4]QuartzCloud Infrastructure ProvidersThe Commerce Department is cracking down on AI chip exports to Chinese firms abroad
Read on Quartz →
Comments
More in Artificial Intelligence
See all →AI Infrastructure
How FlashAttention Bypasses the GPU Memory Bottleneck to Enable Long-Context AI
5 sources
Open Source Standards
How the Open Source Initiative's 1.0 Definition Excludes the Most Downloaded Open-Weight AI Models
7 sources
Generative Adversarial Networks
How a Generator and a Discriminator Compete to Create Realistic AI Output
8 sources
Machine Learning
How Generative AI Maps the Joint Probability Distribution of Data
5 sources
Every angle. Every day.
Get Artificial Intelligence stories with full source coverage and perspective breakdowns delivered to your inbox.




