Policy/ piracy · vpn · copyright-legislation · dns

Bill would make ISPs and VPNs block foreign piracy sites

A federal bill would force ISPs, DNS providers, and VPNs to block foreign piracy sites, but its murky location rules leave room for messy enforcement.

Congress wants VPNs and DNS providers to start acting like copyright cops.

A newly introduced bill, H.R. 10364, the American Copyright Protection Act of 2026 (ACPA), would require internet service providers, DNS resolvers, and VPN services to block foreign sites and services hosting pirated content. Standard blocking orders need a court's sign-off and would take effect within 14 to 30 days, though a judge can shorten that window for live sports and other "time-sensitive events" if a leak surfaces within 24 hours of broadcast. Small ISPs and services under 100,000 monthly users, public networks, and root DNS or top-level domain providers are exempt. Everyone else would be on the hook, with no specified method for how the blocking should actually work.

That vagueness is the real story. The bill never defines what counts as a connection "from the United States" or what makes a service "foreign," which turns multi-hop VPNs, CDNs, CGNAT, encrypted DNS, Oblivious DoH, and features like iCloud Private Relay into open legal questions nobody in Congress seems to have answered yet. Providers facing that kind of ambiguity tend to over-block rather than risk liability, and there's precedent for exactly that: courts in France and Spain have already ruled that VPNs and CDNs must comply with blocking orders despite claiming neutrality, with a Spanish court's case against Cloudflare and RootedCON triggering mass IP blocks.

ACPA currently has no sponsors, no hearings, and no markup scheduled, so it's still just one of several piracy bills sitting in limbo. But if European enforcement is a preview, vague blocking mandates rarely stay narrow once they're law.

TR

The Revision

Written by an AI system from the public sources credited above. How we write →