By Donald Pearce, Sentinel LLC
ECTI Core Instructor
Export controls have traditionally revolved around a simple concept: when goods or technology cross a border, physically or electronically, that transfer is an export that may be regulated by the government. Under current U.S. policy, an export can include shipping a controlled product overseas, sending controlled software abroad, or releasing controlled technology to a foreign person, even inside the United States. That framework has served America well when sensitive capabilities or components were in a machine, a file, or technical know-how that could be transferred by shipping, emailing, or even showing and telling.
Consider the cloud computing model: a foreign user can log in to a U.S.-hosted software platform, run advanced analytics, or rent access to powerful computing infrastructure without ever receiving the underlying source code, technical data, or hardware. In most cloud arrangements, the customer accesses functionality rather than taking possession of the controlled item itself. Historically, that distinction has meant that providing login credentials to a Software-as-a-Service (SaaS) tool or allowing remote use of Infrastructure-as-a-Service (IaaS) resources was not automatically treated as an export, so long as the user could not download controlled technology. This describes what many consider to be the “cloud loophole.”
The concern is obvious from a national security perspective.A foreign adversary may not need to buy or import restricted computing hardware if it can simply rent access to comparable capability through a cloud provider. Likewise, a user may not need to obtain controlled software if a cloud-hosted application provides the same sensitive functionality through a browser. Nothing is exported in the traditional sense, but the capability is still delivered.
A recent threat intelligence report from Anthropic outlined examples of what they assess as the “most notable and novel threat activity” discovered between December 2025 and August 2026, and it reads like an export compliance nightmare. The report logs disrupted attempts to use the company’s popular AI models for malicious activities like “conventional weapons development” and “biological misuse.”
The Remote Access Security Act (RASA) is Congress’s most direct attempt to close that gap. The bill would amend the Export Control Reform Act of 2018 to give the Bureau of Industry and Security (BIS) explicit statutory authority to regulate “remote access” by foreign persons to items subject to the Export Administration Regulations (EAR). In practical terms, the trigger would no longer be limited to shipment, download, or release of controlled technology. If BIS determined that use of an item through a network connection could pose a serious national security or foreign policy risk, in that case the remote access itself could become licensable.
That would be a major shift for cloud providers and their customers. A foreign user logging into a cloud-hosted software platform, spinning up compute instances, or accessing advanced chips through a data center could potentially create an export-control issue even if no code, data sheet, chip, or model file changes hands. The compliance analysis would move closer to an access-control model: Who is the user? Where are they located? What are they using? What can the service enable?
RASA has already shown substantial political momentum. The House passed the bill by a vote of 369–22 in January 2026, signaling strong bipartisan interest in modernizing export controls for cloud-based access. The Senate companion bill, S. 3519, was introduced in December 2025 and referred to the Senate Banking, Housing, and Urban Affairs Committee, where it has remained as of this writing. That delay is not surprising; the bill would place significant operational burdens on cloud platforms, including more intensive know-your-customer procedures, screening for restricted parties, geolocation controls, and potentially blocking or licensing access based on nationality, location, or end use.
Major cloud providers have a strong incentive to resist rules that turn subscription onboarding into an export-control gatekeeping function. For hyperscale platforms, the challenge is architectural more than legal. Export-control compliance would need to be a central pillar in account creation, requiring identity verification, IP-based access controls, usage monitoring, contracting, and escalation workflows. That is far more complex than screening a physical shipment or reviewing a one-time technology transfer.
Although the bill is still in committee for now, stalled does not mean dead. Standalone export control bills often struggle in the Senate, but RASA’s supporters may look to attach its language to the National Defense Authorization Act (NDAA) during fall conference negotiations. The NDAA, the annual bill that primarily funds the military is considered must-pass legislation, and national security-focused members of Congress may view it as the most viable vehicle for remote-access controls. For compliance professionals, the key point is that the bill’s current procedural status should not be mistaken for legislative defeat.
Even if Congress does not enact RASA, BIS may continue stretching existing authority to address remote access in high-risk contexts. The Export Control Reform Act already gives BIS broad power to regulate items subject to the EAR when national security or foreign policy concerns are in play. BIS has also shown increasing willingness to use end-use and end-user controls, advisory guidance, and targeted regulatory actions such as “is informed” letters to regulate transactions involving advanced computing and artificial intelligence.
The IaaS precedent is especially important. BIS has warned that access to advanced computing integrated circuits and related commodities for training AI models may trigger license requirements where there is knowledge of military-intelligence or weapons of mass destruction end uses involving certain high-risk destinations. Separately, the policy debate over requiring U.S. IaaS providers to verify the identity of foreign customers training large AI models demonstrates that regulators are increasingly focused on cloud access, customer identity, and compute-enabled capability—not merely the movement of physical chips.
This means the direction of travel is already visible. The government may not yet have a fully settled remote-access rulebook, but the compliance risk is there and rising. Businesses that assume remote access is categorically outside export controls may find themselves behind the curve if BIS issues new rules, targeted notices, or enforcement theories before Congress acts.
The practical takeaway is straightforward: SaaS and IaaS providers can no longer assume they are outside the export-control perimeter simply because they do not ship product or hand over source code. Cloud-based access can deliver strategic capability, and that makes it a regulatory target.