The bill strengthens U.S. export-control enforcement for covered chips and cloud products by allowing targeted provider reporting and clarifying covered categories, but does so at the cost of expanded privacy exceptions, potential erroneous data disclosures, compliance costs, and regulatory uncertainty.
Cloud providers and Commerce Department: providers can share limited, relevant data with Commerce to detect and report possible use of covered cloud products by specified foreign entities, enabling enforcement of export-control rules.
Tech providers and manufacturers: the bill clarifies key definitions (e.g., 'AI model', 'covered cloud product', 'covered integrated circuit'), making it easier for suppliers to identify what hardware/software is subject to reporting and compliance.
Small businesses and customers using cloud services: disclosures to Commerce are limited to the contents reasonably necessary to substantiate compliance reports, which reduces unnecessary data sharing compared with broader disclosure approaches.
Small businesses, individual customers, and financial institutions: providers may disclose customer communications or records to Commerce based on a 'good faith' belief, which can result in erroneous sharing of private data without prior judicial oversight.
Customers and small businesses: the bill expands exceptions to existing wiretap/customer-record privacy protections (18 U.S.C. §2702), weakening long-standing privacy safeguards for stored communications and records.
Cloud providers and hardware manufacturers: implementing detection, verification, and reporting systems for covered cloud products and integrated circuits will impose compliance costs that could be passed on to customers or reduce investment elsewhere.
Based on analysis of 2 sections of legislative text.
Creates a limited exception to electronic-communications privacy law allowing providers to share data with Commerce for export-control verification about covered cloud products and specified foreign entities.
Official title: To provide for exceptions for notifications to the United States Government relating to specified foreign entities.
Introduced June 30, 2026 by Josh S. Gottheimer · Last progress June 30, 2026
Allows cloud service providers to share customer communications and records with the Commerce Department (or Commerce-designated U.S. personnel) when the provider reasonably believes the data relates to use of certain cloud products by specified foreign entities and the disclosure is needed to meet verification, notification, referral, or reporting requirements under export-control rules. The bill also adds definitions for covered cloud products, covered integrated circuits (with technical thresholds and ECCN references), and AI models, and it narrows the allowed disclosure to the minimum content reasonably necessary. The change creates a statutory exception to federal electronic-communications privacy rules so providers can assist Commerce with enforcing export-control and related reporting obligations for high-performance chips, cloud offerings, and AI-related products used by targeted foreign entities. It includes technical thresholds for integrated circuits and a mechanism for Commerce to update those thresholds after two years.