The Remote Access Security Act
The treatment of remote access to controlled compute, and the legislative attempt to bring it inside export authority.
| Layer | What | When |
|---|---|---|
| Object held | Remote use of controlled compute, an act of access, not a chip crossing a border. | 2009, when remote use of compute first came up |
| Where it started to move | BIS's own 2009 to 2014 advisories said remote use did not fit export, reexport, or transfer. Only Congress can add a fourth category. | same moment: BIS's advisory said it didn't fit |
| Where cost arrives first | Cloud and infrastructure providers, if the statute lands: licensing, due diligence, and knowing who is actually using the compute. | if RASA clears the Senate, for cloud and infrastructure providers |
| Difference carried | The line Congress has the authority to redraw has passed the House twice and is still not law. The 2009 reading remains the one in force. | after two House passages, with the Senate still not moved |
Where the 2009 line stopped reaching
Congress writes ECRA's operative categories (export, reexport, transfer) in general terms; BIS can only rule on whether a new situation fits inside them, not add one of its own. Three advisories in a row could only say remote access didn't fit. Only Congress could write it in as a fourth category, which is exactly what RASA does.
| What | What actually counted as regulated |
|---|---|
| Old reading (2009 to 2014) | BIS's own repeated ruling that remote use doesn't fit inside "export," "reexport," or "transfer." Not a new category, just a negative answer inside the existing ones. |
| The gap | A chip can sit in a data center overseas and still be reached, and used, from anywhere. Nothing here fits Congress's existing categories, and nothing BIS alone can add one to cover. |
| RASA (proposed) | Amends ECRA itself to add "remote access" as a fourth category alongside export, reexport, and transfer. |
Three separate advisories (2009, 2011, 2014) reaffirmed the old reading rather than revisiting it. Only once BIS's own 2023 rule flagged the gap did Congress move: first a bill that stalled in 2024, then a reintroduced version that passed the House 369 to 22 in January 2026 and now sits with the Senate.
Timeline
| January 2009 | BIS rules, by advisory, that providing computational capacity isn't an export. |
|---|---|
| January 2011 | BIS reaffirms that reading for deemed-export purposes. |
| November 2014 | BIS reaffirms it again, this time for cloud-based storefronts. |
| October 2023 | BIS's own Advanced Computing rule flags the cloud/IaaS gap itself and says it's evaluating a response. |
| January 2024 | Industry comment letters push BIS to leave the reading alone. |
| September 2024 | The House passes an earlier version, H.R. 8152; it stalls in the Senate. |
| April 2025 | Rep. Michael Lawler reintroduces it as H.R. 2683; the Foreign Affairs Committee approves it unanimously, 51-0, two days later. |
| December 17, 2025 | A Senate companion bill, S. 3519, is introduced by McCormick, with Wyden, Cotton, and Coons; it is referred to the Banking Committee, where it still sits. |
| January 12, 2026 | The House passes its version again, 369-22; the Senate companion, S. 3519, remains parked in committee. |
| August 2026 | BIS drafts a rule to close the same gap on its own (one it helped create by letting a prior Know-Your-Customer requirement lapse), even as its own lawyers reportedly doubt it can enforce that without the Senate acting first. |
Who meant what, and what happened instead
The old reading passed only a light duty into the value chain. When that left too much uncovered, the answer wasn't to reinterpret the boundary. It was to try rewriting it, in statute.
| Actor | Authority held | What happened instead |
|---|---|---|
| BIS (2009 to 2023) | Keep the 2009 reading stable through advisory opinions, reaffirming it rather than revisiting it. | By 2023, had to publicly flag the gap itself in its own rule instead of patching it by advisory again. |
| Cloud & infrastructure providers | Preserve the existing reading: 2024 comment letters argued for keeping the lighter, non-exporter duty they'd operated under for over a decade. | If RASA clears the Senate, absorb new licensing, due-diligence, and liability obligations instead, now the party expected to know who's actually using the compute. |
| Congress (Lawler, McCormick, Wyden, Cotton, Coons) | Close the gap by statute, moving the trigger from the chip to the act of accessing it. | Passed the bill twice (stalled in 2024, then 369 to 22 through the House in 2026) and it's still not law; the old reading remains in force while the Senate sits on S. 3519. |
| BIS (2026) | Close the same gap on its own, by rule, rather than wait on Congress (a gap it helped widen by letting a prior Know-Your-Customer requirement lapse). | Drafted the rule anyway, even as its own lawyers reportedly doubt it has enforcement authority without the statute RASA would provide. |
Sources
| Primary | H.R. 2683, Remote Access Security Act, GovTrack (passed House Jan. 12, 2026) |
|---|---|
| Primary | Roll Call 13, 119th Congress, Office of the Clerk (369 to 22, Jan. 12, 2026) |
| Reporting | Baker McKenzie, "US House Passes Remote Access Security Act" |
| Reporting | Crowell & Moring, "House Passes Remote Access Security Act..." (Jan. 14, 2026) |
| Analysis | Latham & Watkins, "What the Remote Access Security Act Means for Export Controls Compliance Programs" |
| Reporting | Tech Times, "Commerce Drafts AI Chip Rule for Loophole It Created by Rescinding Biden Know-Your-Customer" (Aug. 29, 2026) |