REGULATORY ORDERv1.0
CASE 02

The Remote Access Security Act

The treatment of remote access to controlled compute, and the legislative attempt to bring it inside export authority.

LayerWhatWhen
Object held Remote use of controlled compute, an act of access, not a chip crossing a border. 2009, when remote use of compute first came up
Where it started to move BIS's own 2009 to 2014 advisories said remote use did not fit export, reexport, or transfer. Only Congress can add a fourth category. same moment: BIS's advisory said it didn't fit
Where cost arrives first Cloud and infrastructure providers, if the statute lands: licensing, due diligence, and knowing who is actually using the compute. if RASA clears the Senate, for cloud and infrastructure providers
Difference carried The line Congress has the authority to redraw has passed the House twice and is still not law. The 2009 reading remains the one in force. after two House passages, with the Senate still not moved

Where the 2009 line stopped reaching

Congress writes ECRA's operative categories (export, reexport, transfer) in general terms; BIS can only rule on whether a new situation fits inside them, not add one of its own. Three advisories in a row could only say remote access didn't fit. Only Congress could write it in as a fourth category, which is exactly what RASA does.

WhatWhat actually counted as regulated
Old reading (2009 to 2014)BIS's own repeated ruling that remote use doesn't fit inside "export," "reexport," or "transfer." Not a new category, just a negative answer inside the existing ones.
The gapA chip can sit in a data center overseas and still be reached, and used, from anywhere. Nothing here fits Congress's existing categories, and nothing BIS alone can add one to cover.
RASA (proposed)Amends ECRA itself to add "remote access" as a fourth category alongside export, reexport, and transfer.

Three separate advisories (2009, 2011, 2014) reaffirmed the old reading rather than revisiting it. Only once BIS's own 2023 rule flagged the gap did Congress move: first a bill that stalled in 2024, then a reintroduced version that passed the House 369 to 22 in January 2026 and now sits with the Senate.

Timeline

January 2009BIS rules, by advisory, that providing computational capacity isn't an export.
January 2011BIS reaffirms that reading for deemed-export purposes.
November 2014BIS reaffirms it again, this time for cloud-based storefronts.
October 2023BIS's own Advanced Computing rule flags the cloud/IaaS gap itself and says it's evaluating a response.
January 2024Industry comment letters push BIS to leave the reading alone.
September 2024The House passes an earlier version, H.R. 8152; it stalls in the Senate.
April 2025Rep. Michael Lawler reintroduces it as H.R. 2683; the Foreign Affairs Committee approves it unanimously, 51-0, two days later.
December 17, 2025A Senate companion bill, S. 3519, is introduced by McCormick, with Wyden, Cotton, and Coons; it is referred to the Banking Committee, where it still sits.
January 12, 2026The House passes its version again, 369-22; the Senate companion, S. 3519, remains parked in committee.
August 2026BIS drafts a rule to close the same gap on its own (one it helped create by letting a prior Know-Your-Customer requirement lapse), even as its own lawyers reportedly doubt it can enforce that without the Senate acting first.

Who meant what, and what happened instead

The old reading passed only a light duty into the value chain. When that left too much uncovered, the answer wasn't to reinterpret the boundary. It was to try rewriting it, in statute.

ActorAuthority heldWhat happened instead
BIS (2009 to 2023) Keep the 2009 reading stable through advisory opinions, reaffirming it rather than revisiting it. By 2023, had to publicly flag the gap itself in its own rule instead of patching it by advisory again.
Cloud & infrastructure providers Preserve the existing reading: 2024 comment letters argued for keeping the lighter, non-exporter duty they'd operated under for over a decade. If RASA clears the Senate, absorb new licensing, due-diligence, and liability obligations instead, now the party expected to know who's actually using the compute.
Congress (Lawler, McCormick, Wyden, Cotton, Coons) Close the gap by statute, moving the trigger from the chip to the act of accessing it. Passed the bill twice (stalled in 2024, then 369 to 22 through the House in 2026) and it's still not law; the old reading remains in force while the Senate sits on S. 3519.
BIS (2026) Close the same gap on its own, by rule, rather than wait on Congress (a gap it helped widen by letting a prior Know-Your-Customer requirement lapse). Drafted the rule anyway, even as its own lawyers reportedly doubt it has enforcement authority without the statute RASA would provide.