# Bipartisan House bill would let cloud providers report suspected foreign use of advanced AI compute

> Source: <https://mlq.ai/news/bipartisan-house-bill-would-let-cloud-providers-report-suspected-foreign-use-of-advanced-ai-compute/>
> Published: 2026-08-19 17:57:58.334650+00:00

# Bipartisan House bill would let cloud providers report suspected foreign use of advanced AI compute

- H.R. 9546, the Cloud Security Act, would amend the Stored Communications Act to permit qualifying disclosures to Commerce when a provider believes a specified foreign entity is using a covered cloud product.
[[1]](https://www.govinfo.gov/content/pkg/BILLS-119hr9546ih/pdf/BILLS-119hr9546ih.pdf) - The proposal covers infrastructure-as-a-service, platform-as-a-service and software-as-a-service products that provide substantially equivalent computing resources, along with advanced chips and systems meeting specified export-control thresholds.
[[1]](https://www.govinfo.gov/content/pkg/BILLS-119hr9546ih/pdf/BILLS-119hr9546ih.pdf) - The bill is not an enacted cloud-access restriction. It was introduced June 30, 2026, and referred to the House Judiciary Committee.
[[2]](https://www.govinfo.gov/app/details/BILLS-119hr9546ih) - Existing BIS guidance separately requires licenses for advanced computing items exported to China- or Macau-headquartered entities, including qualifying overseas subsidiaries, while allowing compliant data centers to continue using and servicing already-installed equipment.
[[3]](https://media.bis.gov/media/documents/bis-guidance-may-31-2026.pdf)

A bipartisan House bill would give U.S. cloud providers a legal path to report suspected use of advanced AI computing by certain foreign entities to the Commerce Department, targeting a remote-access gap in chip export controls. [[1]](https://www.govinfo.gov/content/pkg/BILLS-119hr9546ih/pdf/BILLS-119hr9546ih.pdf)[[4]](https://www.axios.com/2026/06/26/gottheimer-moolenaar-ai-cloud-security-bill)

The Cloud Security Act is a proposal, not a new ban. H.R. 9546 was introduced by Representatives Josh Gottheimer, Democrat of New Jersey, and John Moolenaar, Republican of Michigan, on June 30, 2026, and referred to the House Judiciary Committee. [[2]](https://www.govinfo.gov/app/details/BILLS-119hr9546ih)

## What the bill would change

The bill would amend sections of the Stored Communications Act that govern voluntary disclosure of customer communications and records. It would create exceptions for disclosures to the Commerce secretary, or designated government officials, when a provider in good faith believes the information relates to a covered cloud product used by a specified foreign entity or by an entity acting for its benefit. [[1]](https://www.govinfo.gov/content/pkg/BILLS-119hr9546ih/pdf/BILLS-119hr9546ih.pdf)

The disclosure would have to be limited to information reasonably necessary to verify, notify, refer or report activity under the Export Control Reform Act. The text does not require providers to report every customer from China or another covered country, and it does not directly prohibit those customers from using U.S. cloud services. Its immediate mechanism is a legal permission to share narrowly tailored information. [[1]](https://www.govinfo.gov/content/pkg/BILLS-119hr9546ih/pdf/BILLS-119hr9546ih.pdf)

The bill defines a covered cloud product broadly. It includes infrastructure-as-a-service used to develop or deploy an advanced AI model, plus platform-as-a-service and software-as-a-service products that provide substantially equivalent computing resources or functionality. [[1]](https://www.govinfo.gov/content/pkg/BILLS-119hr9546ih/pdf/BILLS-119hr9546ih.pdf)

## Which services and customers could be covered

The bill defines an AI model as one trained on broad data, generally using self-supervision, with at least 1 billion parameters and applicability across a wide range of contexts. Its covered-integrated-circuit definition includes products classified under export-control categories 3A090 and 4A090, related classifications and functionally equivalent products. It also includes chips meeting specified processing-performance, performance-density, DRAM-bandwidth or interconnect-bandwidth thresholds. [[1]](https://www.govinfo.gov/content/pkg/BILLS-119hr9546ih/pdf/BILLS-119hr9546ih.pdf)

The proposal incorporates the existing tax-code definition of a specified foreign entity. That category includes foreign entities of concern, entities identified as Chinese military companies operating in the United States, entities on specified government lists and foreign-controlled entities. The definition of foreign-controlled entity reaches governments, agencies, certain citizens and companies incorporated or principally based in a covered nation, along with controlled subsidiaries. [[5]](https://uscode.house.gov/view.xhtml?req=%28title%3A26+section%3A7701+edition%3Aprelim%29)

The sponsors identified Amazon Web Services, Microsoft Azure and Google Cloud as examples of providers whose platforms can offer access to advanced chips without transferring ownership of the hardware. Those companies are commercial examples, not named subjects of an enforcement action, and the bill does not list providers or Chinese customers by name. [[4]](https://www.axios.com/2026/06/26/gottheimer-moolenaar-ai-cloud-security-bill)

## What is already in force

The proposal follows a regulatory gap created after the Commerce Department announced in May 2025 that it would rescind the Biden administration’s AI Diffusion Rule and instructed officials not to enforce its new compliance requirements. The department said it planned a replacement rule. [[6]](https://www.bis.gov/press-release/department-commerce-announces-rescission-biden-era-artificial-intelligence-diffusion-rule-strengthens)

On May 31, 2026, the Bureau of Industry and Security clarified that a license is required to export advanced computing items to entities headquartered in China or Macau, or to entities whose ultimate parent is headquartered there, even when the recipient is located elsewhere. The guidance covers advanced computing items in categories including 3A090.a, 4A090.a and related products. [[3]](https://media.bis.gov/media/documents/bis-guidance-may-31-2026.pdf)

That action addresses export transactions involving chips and other controlled items, not every subsequent use of computing capacity. BIS said bona fide data-center operators do not have to stop the ongoing use, storage, disposal or servicing of covered equipment because of the guidance. [[3]](https://media.bis.gov/media/documents/bis-guidance-may-31-2026.pdf)

BIS’s May 2025 diversion guidance separately advises companies to examine IaaS customers, ownership structures, end uses and data-center infrastructure. It warns that transactions involving knowledge that advanced chips will support AI-model training for China-headquartered parties may trigger licensing requirements and potential civil or criminal enforcement under the Export Administration Regulations. [[7]](https://www.bis.gov/media/documents/ai-counter-diversion-industry-guidance-may-13-2025.pdf)

## The policy argument

David Feith, a former State Department official, told the Senate Banking Committee in June that export controls traditionally focus on whether a physical chip crosses a border. He said Chinese companies can instead rent access to chips located in Southeast Asia, the Middle East or the United States, leaving the hardware outside China while allowing computing benefits to flow to Chinese users. [[8]](https://www.banking.senate.gov/imo/media/doc/feith_testimony_6-11-26.pdf)

Gottheimer and Moolenaar argue that cloud providers need clearer authority to verify users and notify Commerce when a qualifying foreign entity appears to be using U.S. infrastructure to develop advanced AI models. The bill, however, does not establish a new Commerce inspection regime, a universal know-your-customer requirement or a dedicated penalty schedule. Any resulting export-control case would rely on existing authorities under the Export Control Reform Act and the Export Administration Regulations. [[1]](https://www.govinfo.gov/content/pkg/BILLS-119hr9546ih/pdf/BILLS-119hr9546ih.pdf)[[4]](https://www.axios.com/2026/06/26/gottheimer-moolenaar-ai-cloud-security-bill)

As of August 19, 2026, the GovInfo record lists H.R. 9546 as an introduced bill referred to Judiciary, with no enacted compliance date. The May 2026 BIS guidance remains the operative control for exports of covered advanced-computing items to China- or Macau-headquartered entities overseas. [[2]](https://www.govinfo.gov/app/details/BILLS-119hr9546ih)[[3]](https://media.bis.gov/media/documents/bis-guidance-may-31-2026.pdf)

## Companies mentioned

## Further sources

[[1] H.R. 9546, the Cloud Security Act: disclosure exceptions, covered cloud product… ↗](https://www.govinfo.gov/content/pkg/BILLS-119hr9546ih/pdf/BILLS-119hr9546ih.pdf)

[[2] GovInfo record showing H.R. 9546 was introduced June 30, 2026, sponsored by Jos… ↗](https://www.govinfo.gov/app/details/BILLS-119hr9546ih)

[[3] BIS May 31, 2026 guidance on license requirements for advanced-computing items … ↗](https://media.bis.gov/media/documents/bis-guidance-may-31-2026.pdf)

[[4] Axios reporting on the bill’s sponsors, its intended cloud-disclosure mechanism… ↗](https://www.axios.com/2026/06/26/gottheimer-moolenaar-ai-cloud-security-bill)

[[5] 26 U.S.C. § 7701(a)(51), the definition of specified foreign entity and foreign… ↗](https://uscode.house.gov/view.xhtml?req=%28title%3A26+section%3A7701+edition%3Aprelim%29)

[[6] BIS announcement that the Commerce Department initiated rescission of the Biden… ↗](https://www.bis.gov/press-release/department-commerce-announces-rescission-biden-era-artificial-intelligence-diffusion-rule-strengthens)+2 more

The stories that matter, in one email. Free — unsubscribe anytime.
