A judge’s legal ruling is shown guiding a network that blocks malware while protecting websites and users through DNS and VPN.
H.R. 10364, the American Copyright Protection Act of 2026, was introduced in the House on September 14, 2026 by Rep. Darrell Issa (R-Calif.). It would let federal courts order US-facing ISPs, DNS resolvers and VPN services with at least 100,000 monthly US users or subscribers to block access to court-designated "foreign piracy sites." The bill has only been introduced and referred to the House Judiciary Committee. It is not law, and no VPN has to block anything under it today. Still, it is the first major US site-blocking proposal to name consumer VPNs outright, and it would give copyright holders a two-step court process that ends with an order a VPN provider would have to carry out for its US customers.

Early coverage has been louder than the bill text. TechRadar framed the bill as turning VPNs into "piracy blocklists," gave a September 16 introduction date, and said the size threshold would catch almost every major VPN brand. The official Government Publishing Office text records September 14. The threshold is written as "users or subscribers," which is broader than "subscribers," and no public market data shows which VPN brands would actually qualify. The actual mechanism is narrower than a nationwide filter, but it is also more concrete than a vague threat. Anyone who depends on a commercial VPN, a public DNS resolver, or a broadband connection in the US should understand how it works.

How H.R. 10364 Puts VPNs Next to ISPs and DNS Resolvers​

The key change is in the definitions. The bill adds a new Chapter 16, "Foreign Piracy Site Blocking," to Title 17 of the US Code, the copyright title. It defines a "service provider" as an entity that transmits, routes or provides connections for users' online communications without changing the content. It then names three categories explicitly: providers of broadband internet access, providers of domain name resolution services, and virtual private networks.

Some operators are carved out. Root nameserver operators and top-level domain registries are excluded. So is any entity serving fewer than 100,000 monthly users or subscribers in the US. Premises operators that buy internet service from someone else to give patrons or employees access are also exempt, and the bill lists airports, carriers, libraries, universities, restaurants and retail stores as examples. Ars Technica, which got an early copy of the text from Public Knowledge, reported the same scope: Issa's bill would help copyright holders obtain judicial blocking orders to be served to ISPs, domain name resolution services, and virtual private networks.

VPNs were added late. The full text shows that VPNs were added after last year's discussion draft, which only mentioned ISPs and DNS resolvers, according to TorrentFreak. So the VPN language was a deliberate expansion between the draft and the filed bill.

The bill also defines the targets. A "foreign online location" is a publicly accessible website or other uniquely identifiable online location that is run by someone outside the US, or whose location can't be placed inside the US after a reasonable investigation. It must also be identifiable by IP address, fully qualified domain name, or a similar identifier. Domestic sites fall outside this chapter completely.

The Two-Step Court Process Behind Every Blocking Order​

The bill does not give rightsholders a direct line to VPN providers. Every block has to go through a federal district court, in two separate stages.

In the first stage, a copyright owner asks a court to declare that a site is a "foreign piracy site." The owner has to prove its case by a preponderance of the evidence, the ordinary civil standard, meaning more likely than not. It must show that the operator is violating or will violate its exclusive rights, and that it gave or tried in good faith to give notice to both the site operator and the domain registrar. It must also show injury, and that the operator is outside the US or could not be found inside it. On top of that, the site has to meet at least one of three tests: it is primarily designed to give access to infringing material, it has only limited commercially significant use beyond that, or its operator markets it to promote infringement. The court can appoint a special master to check whether the owner has met that burden.

In the second stage, the owner petitions for a blocking order. The petition must name every service provider the owner reasonably believes must be included to reduce US access to the site "by a commercially significant amount" in total. The owner must certify three things: it served each named provider with the petition and the declaration, it told each provider that it can contest being included, and it filed notice with the US Copyright Office for publication in the Federal Register.

The court cannot simply approve the list. It can include a provider only if that provider consents, or if six factors weigh in favor of inclusion when considered together:

  • The burden on the provider and its network of implementing the order.
  • Whether it is technically feasible for that provider to block the site, and whether blocking would work.
  • The harm the copyright owner would likely suffer if the provider were left out.
  • The potential for incidental harm to other online services or their users.
  • Whether including that provider would actually make it harder for US users to reach the site.
  • Any benefit or harm to the US public.

If the order is granted, it identifies the site, names the providers, and requires each to take "all commercially reasonable steps" to stop users from reaching the site through its systems from the United States. The order cannot prescribe or ban particular technical methods, so each provider chooses how to comply. Orders last as long as needed to address the infringement, up to a maximum of 12 months. The copyright owner must post a bond large enough to cover costs and damages for any provider later found to have been wrongfully enjoined.

Where the "Speed of Light" Fast Track Actually Lives in the Bill​

The 14-day figure that appears in most coverage is really two separate clocks. First, the court must give named providers at least 14 days after the blocking petition is filed to appear and respond, and it cannot rule before then. Second, once an order is issued, the implementation date must fall between 14 and 30 days after the provider receives notice of it.

The faster track comes from a separate provision that lets courts change these deadlines for good cause, consistent with due process, including to deal with "time-sensitive events." The bill defines a time-sensitive event as a work distributed or performed at the same time as, or within 24 hours after, its first authorized US public performance or distribution. Live sports is the obvious case. Issa made that goal plain at a June 30 hearing, arguing that existing notice-and-takedown procedures can be too slow for live broadcasts and saying online piracy helps fund criminal networks. At the same hearing he asked whether enforcement could move "at the speed of sound" or "at the speed of light," as reported by Ars Technica.

Put simply, the default process takes weeks, and a judge can compress it for live events. Nothing in the bill lets a rightsholder skip the court. The two-step structure, including the declaration and the provider-inclusion analysis, applies either way.

What a VPN Would Have to Do Under a Blocking Order​

The practical question for VPN users is how a provider would block a site "from the United States." The bill leaves that open on purpose. TorrentFreak noted that how a VPN should block access "from the United States" remains an open question, as the technical implementation is not defined.

That is a real engineering problem. A VPN's traffic leaves through exit servers that may be in another country, while the user is sitting in the US. The bill talks about users reaching the site from the United States, not about which exit node they use. Here is an inference that the bill does not answer: a covered provider could decide to apply its blocklist to every account it believes is US-based, whichever server the user connects to. Or it could block only on US exit servers and argue that this counts as "commercially reasonable." Courts would probably settle that question order by order.

Privacy-focused VPNs often argue that a no-logs design makes blocking impossible. That argument has already been tested abroad. TorrentFreak reported that in France, the Paris court concluded that a no-log policy doesn't prevent VPNs from blocking sites. Blocking a domain at the resolver or at the exit doesn't require the provider to keep a record of who asked for it. VPN users should assume that "no logs" and "subject to blocking orders" can both be true.

Ars Technica's own assessment was that compelling VPN services to block piracy websites may be difficult even with court orders. Its view is that broadband and DNS orders would have the bigger practical effect. The six inclusion factors support that reading. A court weighing "technical feasibility and efficacy" for one VPN out of hundreds could reasonably decide that including it would barely reduce access to the site.

The bill also gives named providers some legal protection:

  • A provider is not in violation if its conduct was a good-faith effort to implement the order.
  • A provider can temporarily delay or suspend blocking, for no longer than necessary, to investigate overblocking of another service, to maintain or upgrade its network, to respond to a security threat, or to comply with law enforcement requests or other court orders.
  • A provider can rely on the information the copyright owner supplied without independently verifying it.
  • A provider may tell its users or the public about an order but is not required to.

Enforcement is through civil contempt. A copyright owner can ask the issuing court to compel a named provider to comply.


Overblocking and the Error Remedy Critics Say Falls Short​

Civil liberties and infrastructure groups mostly object to collateral damage, not to VPNs specifically. Public Knowledge senior policy counsel Meredith Rose told Ars Technica that "site-blocking orders force any service provider, from residential broadband providers to global DNS resolvers, to disrupt traffic from targeted websites simply accused of copyright infringement." She also warned that a blocking order served on a DNS resolver could let one court cut off a website worldwide.

The Re:Create coalition said the bill would codify "a one-sided legal process modeled on European site-blocking laws, which have been shown to cause widespread censorship." A coalition letter to Issa, signed by the Computer & Communications Industry Association, the Electronic Frontier Foundation, Fight for the Future, the Internet Infrastructure Coalition, Public Knowledge and the R Street Institute, cited Spain. There, the letter said, overblocking has caused outages to payment processors and a national healthcare provider. Ars also pointed to a September 2025 University of Twente study of Italy's Piracy Shield system, which found at least "hundreds of legitimate websites [were] unknowingly affected by blocking." The mechanism behind that risk is well understood. Public Knowledge, infrastructure companies and civil-liberties groups warn that DNS and IP blocking can disrupt legitimate sites that share domains, addresses or hosting infrastructure with targets.

These European examples show how blocking regimes have behaved elsewhere. They are not a prediction of how US courts would apply H.R. 10364, whose text includes safeguards some European systems lack, such as judicial review before any block and a required weighing of incidental harm. TechRadar also published more dramatic figures on Italian and Spanish overblocking, but they could not be verified against other sources and are left out here.

The bill does include an error remedy, but it is narrow. An operator or user of a third-party service harmed by a block can ask the court to modify the order. They must appear in court, notify the relevant parties, and show that access was restricted and that they were injured. If the copyright owner caused the error, the court may award proven injury and the costs of the motion, capped at $250,000. The award is discretionary and not automatic, and it applies only after the harmed party brings its own motion. The site operator's options are also limited. It can get a declaration or order rescinded by submitting to the court's jurisdiction and posting a bond, or by showing that the evidence does not support the court's findings.

H.R. 10364 Joins a Crowded Field of US Site-Blocking Bills​

Issa's bill is part of a long-running push. The Motion Picture Association has lobbied for a US site-blocking law for years and told the June hearing that more than 50 countries already have one. Gizmodo counts Issa's bill as the third active site-blocking proposal on the Hill. Rep. Zoe Lofgren (D-CA) introduced the Foreign Anti-Digital Piracy Act (H.R. 791) in January 2025. A separate Senate effort, Block BEARD, is being developed by a bipartisan group including Blackburn, Coons, Schiff and Tillis.

VPNs have also come under separate state-level pressure this year. Utah's SB 73, an age-verification law aimed at VPN use, quietly took effect on September 3 before being paused by an enforcement freeze days later. The two measures have different goals, but both treat VPN providers as places where rules can be enforced.

The timeline limits this bill's chances. Whether Rep. Issa will get the bill across the finish line is uncertain. He retires at the end of this year, so he won't be around to reintroduce it if it doesn't pass during the current session. Issa chairs the House Judiciary subcommittee on courts, intellectual property, artificial intelligence and the internet, which gives the bill a real path to a markup. But it is late in the 119th Congress, and competing bills are in progress.

What this means for you​

For now, nobody needs to change VPN providers, DNS settings or network configuration because of H.R. 10364. The useful step is knowing which parts of your setup the bill could reach if it passes, and following the Judiciary Committee's work on it.

Consumer VPN users are the obvious group. The provider's size matters most: the threshold counts monthly US users or subscribers, so large commercial services are the likeliest to be covered. NordVPN privacy advocate Laura Tyrylyte told TechRadar that such measures mainly target reputable paid providers and leave free VPNs largely untouched. That is a vendor's view, but it does fit the bill's size-based threshold. TechRadar also argued that a provider incorporated in a jurisdiction like Panama or the British Virgin Islands would be harder for US courts to reach. The bill itself defines coverage by US users, not by where a company is incorporated. How a US court would enforce contempt against an offshore provider is a practical question the text does not address.

For IT administrators, the likelier impact is DNS and broadband blocking. If your organization uses a large public DNS resolver or a major US ISP, those are the providers the bill most directly covers. Overblocking of shared hosting or shared IP addresses, the failure the coalition letter describes in Europe, would show up for your users as a legitimate site that won't resolve or won't load. The bill does not specifically address a company's self-hosted remote-access VPN. Our reading, which is an inference, is that most would fall under the 100,000-user threshold. Guest Wi-Fi at premises such as retail stores and universities is explicitly excluded.

  • H.R. 10364 was introduced on September 14, 2026 and referred to the House Judiciary Committee. It has not passed and imposes no obligations today.
  • Covered providers are ISPs, DNS resolvers and VPN services with at least 100,000 monthly US users or subscribers. Root servers, TLD registries and premises Wi-Fi are excluded.
  • Every block needs two court rulings: a declaration that the site is a foreign piracy site, then a separate order naming each provider after weighing burden, feasibility and incidental harm.
  • The default timeline allows at least 14 days to respond and 14–30 days to implement, and judges can shorten both for live or same-day content.
  • Providers choose their own blocking methods. How a VPN would block access "from the United States" is undefined, and a no-logs policy has not protected VPNs from blocking orders in France.
  • Anyone harmed by an erroneous block has to go to court. The payout is discretionary and capped at $250,000.

Unlike a blanket VPN filter, H.R. 10364 is a court-supervised blocking system that names VPNs alongside the ISPs and DNS resolvers that would bear most of the practical load. Adding VPNs after the discussion draft signals that rightsholders see them as a route around ISP-level blocks, and any site-blocking law that makes it out of this Congress, whether Issa's, Lofgren's or the Senate's Block BEARD effort, is now likely to be judged on whether it includes them. The next concrete milestone is House Judiciary action before Issa retires at year's end. Without it, the bill dies with the session, and the VPN language would have to be written into whichever competing bill moves next.