Congress quietly expands export controls to remote access—with lower criminal thresholds.
H.R. 2683 — Remote Access Security Act · Filed by Michael Lawler (R-NY) · 17 cosponsors · Introduced Apr 7, 2025 · Passed chamber
Your members of Congress
Enter a ZIP to see where your representative and both senators stood on this bill.
Looked up on this device — your ZIP is never stored on our servers.
What it does
This bill amends the Export Control Reform Act of 2018 to extend U.S. export controls to include remote access of controlled items by foreign persons over the internet or cloud services, not just physical export. It defines remote access as purposeful, knowing, reckless, or negligent access to controlled technology from abroad, and requires the Secretary of Commerce to regulate such access when it poses a serious national security or foreign policy risk. The bill requires the Commerce Department to consult Congress on anticipated remote-access regulations but does not require congressional approval before implementing them.
Why we flagged it
The bill's core function is to extend U.S. export control jurisdiction from physical shipment to remote digital access of controlled technology, closing a regulatory gap identified in national security policy. It is not a carve-out or subsidy but a regulatory expansion with legitimate security rationale.
What the text implies
- The definition of remote access includes 'negligent' access, meaning a U.S. company or researcher could face criminal liability for failing to prevent unauthorized foreign access to controlled technology—shifting liability from the foreign actor to the U.S. entity, even absent intent.
- The bill grants the Secretary of Commerce unilateral authority to regulate remote access with only post-hoc congressional notification (not approval), creating a regulatory blank check for defining what constitutes a 'serious risk' to national security.
The full analysis lists 5 implications of this text.
Who stands to gain
Cybersecurity and export-compliance software vendors; Defense contractors and aerospace firms (reduced foreign competition risk); Semiconductor manufacturers (protection of advanced chip designs)