PolicyBrief
H.R. 9546
119th CongressJun 30th 2026
Cloud Security Act
IN COMMITTEE

The Cloud Security Act authorizes cloud service providers to disclose customer data to the Department of Commerce to ensure compliance with export control regulations regarding advanced AI models and integrated circuits.

Josh Gottheimer
D

Josh Gottheimer

Representative

NJ-5

LEGISLATION

Cloud Security Act Grants New Data Sharing Powers to Government for AI and Export Oversight

The Cloud Security Act introduces a significant shift in how cloud providers handle your data when high-level national security is on the line. Specifically, it amends the U.S. Code (Sections 2702 and 2711) to allow companies like Amazon, Google, or Microsoft to hand over customer communications and records to the Department of Commerce without a warrant. This isn't for every user, though; it’s specifically triggered when a provider believes 'in good faith' that a 'specified foreign entity' is using their cloud services to develop advanced AI or use high-end hardware that violates export laws. Under Section 2, these disclosures are permitted as long as the provider deems the information 'reasonably necessary' to comply with the Export Control Reform Act of 2018.

The AI Hardware Crackdown

The bill focuses heavily on the 'brains' behind modern tech, specifically what it calls 'covered integrated circuits.' These aren't your average laptop chips; we're talking about high-performance hardware with a total processing performance of 4,800 or more, or massive DRAM bandwidth exceeding 1,400 gigabytes per second. For a software developer at a startup or a researcher at a university, this means the infrastructure you use to train large-scale AI models (defined here as having at least 1 billion parameters) is now under much stricter federal observation. If the government suspects these powerful tools are being funneled to restricted foreign groups, the cloud provider can bypass typical privacy hurdles to flag that activity directly to the Secretary of Commerce.

Privacy in the 'Good Faith' Zone

One of the more complex parts of this bill is the 'good faith' standard for disclosure. In plain English, if a cloud company thinks a user is acting on behalf of a restricted foreign entity, they can turn over records to the government proactively. While this is aimed at stopping bad actors from using U.S. tech for advanced weaponry or surveillance, it creates a gray area for legitimate international businesses. For example, a consultant working with overseas clients might find their communications shared if their activity matches a certain profile, even if they haven't actually broken a law. Because the bill allows the Secretary of Commerce to rewrite the technical definitions of 'covered circuits' every 24 months, the goalposts for what triggers a report could move frequently.

Who Feels the Impact?

This legislation puts cloud giants in the role of digital border agents. For the average person scrolling social media, life stays the same. But for tech companies building 'Platform as a Service' (PaaS) tools or anyone managing data centers, the compliance burden just got heavier. The bill specifically targets products designed for data centers, meaning high-end enterprise tech is the primary focus. While the goal is to keep American AI breakthroughs from being used against the country, the trade-off is a new, direct pipeline between private cloud servers and federal regulators that bypasses the traditional court-ordered subpoena process.