QuorumCivic. Hidden in plain sight Get the app
Bill intelligence

U.S. tightens cloud-access rules for foreign governments and entities

S. 3519 — Remote Access Security Act · Filed by Dave McCormick (R-PA) · 6 cosponsors · Introduced Dec 17, 2025 · Referred to committee

72%
Transparency
Typical bill: 82%
15/100
Hidden-provision risk
Typical bill: 15/100
National Security Export Control Expansion

Your members of Congress

Enter a ZIP to see where your representative and both senators stood on this bill.

Looked up on this device — your ZIP is never stored on our servers.

What it does

This bill amends the Export Control Reform Act of 2018 to add new restrictions on remote access to sensitive U.S. technology by foreign governments and entities of concern. It defines 'remote access' as cloud-based access to controlled items by foreign persons, and prohibits such access when it poses national security risks—specifically for training AI weapons, conducting offensive cyberattacks, or enabling human-rights-violating surveillance. The bill gives the Secretary of Commerce authority to regulate and license remote access, with a 10-year sunset. It requires the Commerce Department to consult Congress and report on implementation, economic impact, and licensing efficiency.

Why we flagged it

The bill's core mechanism is a regulatory expansion of export controls to cover remote (cloud-based) access to sensitive technology, driven by national security concerns around AI weapons, offensive cyber tools, and surveillance. It is not a deregulation, tax measure, or commemorative act—it is a straightforward (if complex) addition to the existing export-control regime.

What the text implies

  • The definition of 'foreign person of concern' includes residents of Hong Kong and Macau as separate entities, potentially restricting legitimate academic and commercial collaboration with researchers and companies in those regions regardless of their political affiliation.
  • Compliance costs for U.S. cloud-service providers (AWS, Microsoft Azure, Google Cloud) will likely be substantial, as they must implement access controls, licensing workflows, and audit trails—costs that may be passed to all customers, not just foreign ones.
  • The 10-year sunset creates regulatory uncertainty: companies must invest in compliance infrastructure knowing the rules expire, potentially discouraging long-term investment in export-control compliance.
  • The bill requires Commerce to consult Congress on 'impact on competitiveness of United States industry in cloud services,' signaling awareness that the restrictions may harm U.S. tech companies' global market share relative to non-restricted competitors.

Section numbers refer to the bill text the analysis read — linked under Primary records below.

Who it affects

Citizens gain national security protections against hostile foreign access to dual-use AI, cyberattack tools, and surveillance technology. However, compliance costs imposed on U.S. cloud-service providers may be passed to consumers through higher prices, and the broad definition of 'foreign persons of concern' (including Hong Kong and Macau residents) may restrict legitimate business and research collaboration, creating economic friction.

Who stands to gain

  • U.S. defense and national security contractors (beneficiaries of reduced foreign access to dual-use
  • Compliance software and consulting firms (new licensing, audit, and monitoring services)

Named in the bill

Secretary of Commerce, Export Control Reform Act of 2018, Commerce Control List, Foreign persons of concern, Cloud infrastructure service providers (AWS, Microsoft, Google, etc.), National Institute of Standards and Technology (NIST), Senate Committee on Banking, Housing, and Urban Affairs

Where it stands

6 cosponsors: 3 Democrats, 3 Republicans.

  • Dec 17, 2025 — Introduced · Congress.gov: “Introduced in Senate”
  • Dec 17, 2025 — Referred to Senate Committee on Banking, Housing, and Urban Affairs · Congress.gov: “Read twice and referred to the Committee on Banking, Housing, and Urban Affairs”

Dates and quoted wording are Congress.gov's action record; the timeline shows status changes, not every procedural step.

Money around this bill

14 lobbying clients named this bill on 15 disclosure filings across 3 quarters, Dec 2025 to Jun 2026. Those filings disclosed $9,338,894 in lobbying spend. A filing names 8 bills on average, so that figure is what each filing reported, not a share belonging to this bill.

More lobbying clients named this bill than 94% of bills with at least one filing.

Dave McCormick, the sponsor, reported $684,750 in PAC receipts in the 2026 cycle. $5,000 of that came from 1 PAC tied to these lobbying clients.

  • Oracle Corporation — $2,000,000 on 1 filing
  • Sap America, Inc. — $1,590,000 on 1 filing
  • Information Technology Industry Council — $1,440,000 on 2 filings
  • Nvidia Corporation — $1,250,000 on 1 filing
  • Medtronic Inc — $1,180,000 on 1 filing

Lobbying Disclosure Act filings through Jul 21, 2026. A filing shows who paid to lobby on a bill it names, not what changed.

How this was measured

Analysis — Quorum's AI read the bill text published by Congress.gov (10,609 characters) on Sep 23, 2026. Section numbers in the findings refer to that text, linked below; transparency and hidden-provision scores are compared against the median of 14,707 analysed bills.

Status and sponsors — Congress.gov's bill record — actions, committee referrals and cosponsors — loaded nightly. The timeline shows status changes, not every procedural action.

Money — Senate Lobbying Disclosure Act filings whose specific-issue field names this bill for quarters ending Dec 2025 to Jun 2026. A filing's amount is reported whole beside the median number of bills a filing names; it is never divided across them. PAC receipts are FEC-reported contributions to the sponsor's candidate committee in the 2026 cycle.

As of — lobbying records through Jul 21, 2026 · page rendered 2026-09-23.

“U.S. tightens cloud-access rules for foreign governments and entities” QuorumCivic. https://share.quorumcivic.app/bill/119/s3519 Report an error

Correlative observation from public records — not evidence of coordination or wrongdoing, and not financial advice.
This page is the record as of today. The app tells you when it changes.
Quorum analysis of the full bill text · 119th Congress · public record