Bipartisan 'Cloud Security Act' Targets Major Loophole Allowing Adversaries to Rent Restricted AI Compute
New legislation aims to close a critical gap in U.S. export controls by giving cloud providers the legal cover to report foreign adversaries renting advanced AI computing power.
By Factlen Editorial Team
- National Security Advocates
- Lawmakers and defense officials focused on preventing adversaries from training military AI.
- Cloud Infrastructure Providers
- Tech giants seeking legal clarity to protect their platforms without violating privacy laws.
- Global Trade Analysts
- Economists and trade experts warning about the long-term market consequences of cloud restrictions.
What's not represented
- · Privacy Advocates
- · International Cloud Customers
Why this matters
As artificial intelligence becomes a critical national security asset, controlling who can build frontier models is just as important as controlling physical weapons. This legislation fundamentally rewrites the rules of the global tech trade, shifting the battleground from shipping containers to cloud data centers.
Key points
- U.S. export controls currently ban the physical sale of advanced AI chips to foreign adversaries like China.
- A major loophole allows these adversaries to simply rent the same computing power from U.S. cloud providers.
- The bipartisan Cloud Security Act aims to close this gap by establishing 'Know Your Customer' rules for cloud companies.
- The bill creates a legal 'safe harbor' so providers can report suspicious activity without violating privacy laws.
- The legislation acts as the enforcement mechanism for the previously passed Remote Access Security Act.
For the past three years, the United States has waged a quiet, high-stakes campaign to restrict foreign adversaries from acquiring the physical hardware necessary to build frontier artificial intelligence.[4]
Through a series of escalating export controls, the Department of Commerce effectively banned the shipment of advanced semiconductors—like Nvidia’s highly coveted H100 and Blackwell chips—to nations deemed national security risks, primarily China.[4]
The strategy relied on a 20th-century model of trade enforcement: if you can stop the physical box from crossing a border, you can stop the technology from proliferating.
But the artificial intelligence boom is inherently a 21st-century phenomenon, built not just on physical hardware, but on the cloud.

A glaring loophole quickly emerged in the regulatory framework. While a Chinese tech firm or military contractor could no longer purchase and import a server rack of advanced American AI chips, they could simply log onto the internet and rent that exact same computing power by the hour.
Major American cloud providers—Amazon Web Services, Microsoft Azure, and Google Cloud—maintain massive data centers packed with restricted silicon. Because renting cloud compute does not involve the physical export of a good, it fell outside the traditional boundaries of export control laws.[1]
On June 26, 2026, a bipartisan coalition in the U.S. House of Representatives introduced the "Cloud Security Act" to finally close this digital backdoor.[2]
Co-led by Rep. Josh Gottheimer (D-NJ) and Rep. John Moolenaar (R-MI), Chairman of the Select Committee on China, the legislation represents a fundamental shift in how the U.S. views technology exports.[1]
"We can't let our adversaries—especially China—dodge our export controls by simply renting what they can't buy," Gottheimer stated upon the bill's introduction, highlighting the absurdity of the current enforcement gap.

The core mechanism of the Cloud Security Act is designed to solve a complex legal bind that has paralyzed American cloud providers.
The core mechanism of the Cloud Security Act is designed to solve a complex legal bind that has paralyzed American cloud providers.
Under existing U.S. privacy laws, cloud companies are generally prohibited from disclosing customer content, usage records, or server activity to the government without a subpoena or warrant.
This created a chilling effect: even if a cloud provider's internal security team noticed a foreign entity spinning up massive clusters of AI compute for suspicious model training, alerting the Department of Commerce exposed the provider to severe legal liability.
The Cloud Security Act establishes a legal "safe harbor," amending current law to allow cloud compute providers to voluntarily report suspected misuse of their services by customers associated with U.S. adversaries.[1][2]
Furthermore, the legislation pushes for robust "Know Your Customer" (KYC) protocols for the cloud industry, mirroring the identity verification standards long required in the banking and financial sectors.[2]

Cloud providers will be expected to verify the true identity and geographic origin of entities renting massive swaths of AI compute, stripping away the anonymity provided by shell companies and VPNs.
This new bill acts as the enforcement mechanism for the "Remote Access Security Act," a related piece of legislation passed overwhelmingly by the House in January 2026.[3]
While the January bill gave the Commerce Department the statutory authority to regulate remote access to controlled technology, the Cloud Security Act gives the industry the actual tools and legal cover to report the violations.
For the cloud computing industry, the transition will require significant investment in compliance infrastructure, shifting their operational model from frictionless, self-serve compute to a more vetted, security-conscious onboarding process.[4]

However, the clarity provided by the safe harbor provision is largely welcomed by an industry that has found itself caught between maximizing global revenue and inadvertently powering the military AI ambitions of foreign states.
By modernizing export controls for the cloud era, the United States is acknowledging that in the artificial intelligence race, computing power is the ultimate strategic resource—whether it sits in a server room in Beijing or is accessed remotely from a data center in Virginia.[2]
How we got here
October 2023
The Department of Commerce significantly tightens export controls on the physical shipment of advanced AI chips to China.
January 2026
The U.S. House passes the Remote Access Security Act, giving Commerce the authority to regulate remote access to controlled technology.
June 2026
Lawmakers introduce the Cloud Security Act to provide reporting tools and legal safe harbor for cloud providers.
Viewpoints in depth
National Security Advocates
Lawmakers and defense officials focused on preventing adversaries from training military AI.
This camp argues that the physical export ban on AI chips is meaningless if adversaries can simply rent the exact same computing power from American companies over the internet. They view the 'cloud loophole' as a critical national security vulnerability that allows foreign militaries to train advanced AI models for cyber warfare, surveillance, and autonomous weapons using U.S. infrastructure. For these advocates, implementing 'Know Your Customer' rules in the cloud is a long-overdue modernization of trade law.
Cloud Infrastructure Providers
Tech giants seeking legal clarity to protect their platforms without violating privacy laws.
Major cloud providers like AWS, Azure, and Google Cloud have found themselves in a difficult legal bind. Prior to this legislation, strict privacy laws like the Electronic Communications Privacy Act (ECPA) made it legally perilous for them to voluntarily hand over customer usage data to the government, even if they suspected a foreign adversary was using their servers. This camp welcomes the 'safe harbor' provisions of the Cloud Security Act, which gives them the legal cover to report suspicious activity, though they remain cautious about the operational burden of verifying the identity of every global customer.
Global Trade Analysts
Economists and trade experts warning about the long-term market consequences of cloud restrictions.
While acknowledging the security risks, trade analysts warn that heavily restricting access to American cloud infrastructure could accelerate the bifurcation of the global tech ecosystem. They argue that if Chinese and other foreign firms are entirely cut off from U.S. cloud services, it will massively incentivize the rapid development of domestic, state-backed cloud infrastructure and indigenous silicon in those countries. In the long run, this camp cautions, the U.S. could lose its visibility into global AI development if adversaries move entirely to closed, non-Western networks.
What we don't know
- How strictly the Department of Commerce will define the 'Know Your Customer' requirements for cloud providers.
- Whether foreign adversaries will simply use layers of international shell companies to bypass the new identity verification checks.
- How quickly the Senate will take up the companion legislation to move the bill to the President's desk.
Key terms
- Export Controls
- Federal regulations that restrict the shipment of certain sensitive technologies or goods to foreign countries for national security reasons.
- Cloud Compute
- The delivery of computing services—including servers, storage, and processing power—over the internet, allowing users to rent hardware rather than own it.
- Safe Harbor
- A legal provision that protects a company from liability or penalty as long as certain conditions are met, such as voluntarily reporting a security threat in good faith.
- Know Your Customer (KYC)
- A mandatory process of identifying and verifying the identity of a client, traditionally used in finance but now being proposed for digital infrastructure.
Frequently asked
What is the 'cloud loophole' in AI?
It is the ability for foreign entities to rent advanced AI computing power from U.S. cloud providers over the internet, effectively bypassing federal bans on purchasing and importing the physical AI chips.
Why didn't cloud providers just report this activity before?
Existing privacy laws prohibited cloud companies from sharing customer data or usage records with the government without a warrant, creating severe legal liability if they voluntarily reported suspicious behavior.
What does 'Know Your Customer' mean for the cloud?
It means cloud providers will have to rigorously verify the true identity, corporate structure, and geographic location of the businesses renting massive amounts of computing power, similar to how banks verify account holders.
Sources
[1]NextgovNational Security Advocates
Preventing AI chip access via cloud computing
Read on Nextgov →[2]The Ripon AdvanceNational Security Advocates
Moolenaar's bipartisan bill would protect U.S. export controls for AI chips
Read on The Ripon Advance →[3]China Economic ReviewGlobal Trade Analysts
US passes bill to prevent Chinese access to AI chips via cloud services
Read on China Economic Review →[4]QuartzCloud Infrastructure Providers
The Commerce Department is cracking down on AI chip exports to Chinese firms abroad
Read on Quartz →
More in ai
See all 5 stories →AI Regulation
How 42 State Attorneys General Are Using Consumer Law to Regulate OpenAI
6 sources
Silicon Sovereignty
$1 Trillion AI Chip Selloff Follows Wave of Custom Silicon Shipments, Reshaping Compute Market
7 sources
Macroeconomics
Federal Reserve Raises US Growth Forecast, Citing Surging AI Infrastructure Investment
4 sources
Every angle. Every day.
Get ai stories with full source coverage and perspective breakdowns delivered to your inbox.







