Find a lawyerOur capabilitiesYour career
Locations
Our capabilities
News

Select language:

Locations
Our capabilities
News

Select language:

hamburger menu showcase image
  1. Our thinking
  2. Blogs
  3. A Fresh Take
  4. Remote Access or Remote Possibility? RASA and the Future of Cloud Export Controls
4MIN

Remote Access or Remote Possibility? RASA and the Future of Cloud Export Controls

Subscribe
Jul 30 2026

For a number of years there have been concerns across the US political aisle about the ability of certain “countries of concern,” such as China and Russia, to lawfully access the compute capabilities of advanced semiconductor chips by way of remote or cloud access – in particular to train AI models. 

To close this so-called “cloud loophole,” a bill called the Remote Access Security Act (RASA) is moving through Congress. RASA would authorize restrictions on remote access to controlled items, such as advanced chips. This could have significant consequences for data centers and their customers across the globe. 

Companies operating remote access data center models, and their customers, should carefully monitor whether RASA passes and in what form. They should also consider the steps that can be taken now to mitigate compliance, enforcement, business continuity, and other commercial risks.

Current US Export Control Restrictions on Remote Access to Datacenters and Compute 

US export controls do not generally prohibit data centers from selling remote access to semiconductors or cloud compute to customers in jurisdictions to which the export of the underlying GPUs themselves would require a license. 

The primary statutory basis for US dual-use export controls is the Export Control Reform Act of 2018 (ECRA; 50 USC 4801 et seq), which authorizes the President to control the “export, re-export, and in-country transfer” of items—commodities, software, and technology—that are subject to US jurisdiction. The export of these items to specific destinations, or for designated end uses or end users, is controlled under the US Export Administration Regulations (EAR). The President delegated this authority to the Commerce Department’s Bureau of Industry and Security (BIS), which administers EAR. 

The EAR does not generally control remote access if that access does not involve the export of a controlled item. As a result, data centers have generally not been restricted from operating in relatively less-restricted jurisdictions—such as certain countries in Southeast Asia and the Middle East—and providing remote access to advanced semiconductors for companies in destinations like China. This has driven the growth of various “GPUaaS” business models, whereby data center operators provide customers based in jurisdictions that are targeted by the most restrictive US export controls on GPUs and advanced semiconductors with remote access to the computing power that utilizes such items (without exporting the chips themselves to those jurisdictions).

Importantly, even without RASA there are existing compliance risks that need to be considered by those operating remote access business models. For example, remote access to controlled technology can constitute an export to the destination country. Moreover, US persons supporting or facilitating certain activities may require a BIS export license or a Treasury Department Office of Foreign Assets Control (OFAC) specific license. In practice, these restrictions can limit the permissible offerings of data centers and/or US involvement.

RASA Would Introduce the Authority to Limit Remote Access to Data Centers Via Export Controls 

If enacted, RASA would extend BIS’s authority under the ECRA to control or regulate “remote access” to items that are subject to the EAR where BIS deems it necessary for national security reasons. 

As presently defined in RASA, remote access occurs when a foreign person accesses an item subject to US jurisdiction from a location other than where the item is physically located. The access must be through a network connection, including the internet or a cloud computing service, and requires a negligent (or higher) level of knowledge that the item is being remotely accessed.

RASA does not specify the jurisdictions or items that should be subject to controls or which controls or license requirements should apply. Instead, if RASA becomes law, then BIS would be responsible for setting out these details in further regulations implementing the law. BIS could decide to regulate remote access to a wide range of items subject to the EAR, or it could choose to control a narrower subset of items, or access for certain end uses and end users only. However, the bill’s sponsors have made it clear that the proposed law is intended to restrict remote access to computing resources for AI, especially by Chinese companies.

RASA’s Prospects of Becoming Law

RASA passed the US House of Representatives with bipartisan support in January 2026, and a companion measure is pending a vote in the Senate, where the bill has been sponsored by a bipartisan group of senators. A prior version of the bill was introduced in September 2024 but stalled in the Senate. If RASA passes the Senate this time, and is not vetoed by the President or has enough bipartisan support, it will become law. 

The bill has a meaningful chance of becoming law in light of the breadth of House support, its bipartisan Senate sponsorship, its enduring legislative attention, and its general alignment with the Trump administration’s technology competition agenda. RASA could become law in its current form, as amended by the Senate, or as part of a larger “must-pass” bill like the National Defense Authorization Act for Fiscal Year 2027. 

Implications for Data Center Companies

If RASA becomes law, data center businesses offering remote access to advanced chips, and their customers, could be exposed to a significant new dimension of export control risk. 

Ultimately, the nature of the risk, and the extent to which the EAR’s “cloud loophole” will close, will need to be further assessed once BIS issues its regulations implementing RASA. The stated objective of the bill’s sponsors strongly suggests that remote access to advanced chips, particularly by Chinese entities, will be targeted at some level.

Companies that could be impacted by the restrictions should continue to monitor whether RASA passes. In addition, it would be prudent to consider the impact of RASA on: (i) technical and operational frameworks; (ii) counterparty due diligence; and (iii) existing and future commercial contracting arrangements, and the steps that can be taken to mitigate the potential compliance, enforcement, business continuity and other commercial risks.

To receive the latest insights on US legal developments, subscribe to the Freshfields A Fresh Take Blog.

Tags

sanctions and tradeusartificial intelligenceinternational tradenational securityregulatory and compliance advisory

Authors

Washington, DC

Nabeel Yousef

Partner
New York

Stephanie Brown Cripps

Partner
New York

Noah Lipkowitz

Senior Associate
New York

Mitchell Levinson

Law Clerk
Latest Insights

Latest Insights

NAVIGATE TO
About usLocations and officesYour careerOur thinkingOur capabilitiesNews
CONNECT
Find a lawyerAlumniContact us
NEED HELP
Fraud and scamsComplaintsTerms and conditions
LEGAL
AccessibilityCookiesLegal noticesTransparency in supply chains statementResponsible procurementPrivacy

Select language:
Select language:
© 2026 Freshfields. Attorney Advertising: prior results do not guarantee a similar outcome