The US Bill That Wants to Make VPNs Enforce Blocklists
H.R. 10364 would require VPN services with 100,000+ US users to block court-designated sites. Here's what the bill actually says and why it matters.
A bill introduced in the US House of Representatives in September 2026 has attracted serious attention from digital rights groups and VPN users alike—not because it has passed, but because of what it explicitly proposes. For the first time in a major federal legislative effort, consumer VPN services are named outright as entities that must comply with court-ordered website blocks.
The bill is H.R. 10364, officially called the American Copyright Protection Act of 2026, or ACPA. It was introduced on 14 September 2026 by Representative Darrell Issa (R-CA) and has been referred to the House Judiciary Committee. It is not law. It imposes no obligations today. But its framing of VPNs as infrastructure that copyright enforcement can reach through the courts represents a meaningful shift in how legislators are thinking about these tools—and it is worth understanding clearly.
This article sets out what the bill actually proposes, where its logic is contested, and what the practical implications might be if legislation along these lines were ever enacted.
What the Bill Proposes
ACPA would create a mechanism allowing copyright holders to obtain fast-track court orders requiring certain online intermediaries to block access to designated "foreign piracy sites." The category of intermediaries covered is broad: internet service providers, DNS resolvers, and—crucially—VPN services.
The inclusion of VPN providers is not implied or incidental. The bill's operative text names them explicitly. That is the detail that distinguishes ACPA from earlier site-blocking proposals in the US, which focused almost entirely on ISPs and DNS operators.
The blocking obligation would not apply universally. The bill sets a threshold: a VPN service must have at least 100,000 monthly active users in the United States before it falls within scope. The intent, presumably, is to focus enforcement on services with meaningful reach rather than burdening tiny operators. Critics, however, point out that this threshold effectively captures the entire paid VPN market while leaving a large population of free VPN applications—many of which are owned and operated by companies outside the United States—completely beyond the law's reach.
How the Blocking Mechanism Would Work
Under the proposed framework, a copyright holder that believes a foreign website is primarily engaged in copyright infringement could apply to a federal court for a blocking order. The process is described as fast-track, meaning it is designed to move quickly, without the full adversarial proceedings that characterise ordinary civil litigation.
If a court grants the order, named intermediaries—including VPN providers that meet the user threshold—would be required to prevent their users from accessing the designated site. The technical means of enforcement are not prescribed in detail by the bill itself, which is typical of this kind of legislation: it establishes the legal obligation and leaves implementation specifics to the covered services.
For a VPN provider, compliance could mean blocking at the DNS level, routing-level filtering, or some combination. Each approach carries its own technical complications and raises questions about what it means for a service that is architecturally designed to route traffic without inspecting or filtering its content.
Why VPNs Are Architecturally Awkward Targets
A VPN's core function is to create an encrypted tunnel between a user's device and a server, then forward that traffic to its destination. The tunnel hides the user's origin IP from the destination site and, depending on configuration, hides the destination from the user's ISP. Understanding what a VPN actually does at a technical level makes clear why compelling one to act as a content filter is not straightforward.
Unlike an ISP, which sits between a user and the entire internet and can implement DNS-based or IP-based blocks with relatively predictable results, a VPN service encrypts traffic before it exits to the wider network. If a VPN enforces a block, it must do so either before the tunnel (at the DNS resolution stage) or within its own infrastructure after traffic has been decrypted for forwarding. Either approach requires the VPN to actively inspect or redirect traffic in ways that are contrary to the privacy guarantees many users rely on.
There is also a practical circumvention problem. A site-blocking order that targets domain names can be bypassed by accessing the site via its IP address directly. An order targeting IP addresses can be bypassed if the blocked site moves to new infrastructure. These limitations are well-documented from the experience of European countries that have operated site-blocking regimes for years.
The Threshold Problem
The 100,000 monthly US user threshold is one of the bill's most-discussed features, and not because it seems strict. Critics argue it achieves the opposite of what a neutral enforcement threshold should do.
Paid VPN services that are incorporated in the US or do substantial business there tend to be larger, more visible, and more legally accountable. They are also the services most likely to have robust privacy policies, clear logging practices, and legal teams capable of contesting an overreaching court order. These are the services the threshold captures.
Free VPN applications with large user bases but opaque ownership structures—some of which have been documented by security researchers as harvesting user data—frequently operate through corporate structures outside US jurisdiction. A 100,000-user threshold does not automatically exclude them, but enforcement against a company with no US presence or assets is a different matter entirely from enforcing against a regulated UK-based service.
The result, as critics have noted, is a law that reaches the most accountable services most easily while leaving less accountable ones practically untouched.
Due Process and First Amendment Concerns
Digital rights organisation Public Knowledge has raised concerns about both the due-process implications of the fast-track court order mechanism and potential First Amendment issues. These are not frivolous objections.
Site-blocking orders issued without full adversarial proceedings risk capturing lawful content. A domain hosting a mixture of infringing and non-infringing material could be blocked entirely, affecting users and publishers who have no connection to any infringement. US courts have historically been cautious about prior restraints on speech—blocking access to a website before any finding of infringement on the merits sits uncomfortably close to that territory.
The fast-track design is also a due process concern for the intermediaries themselves. A VPN provider served with a blocking order would need to comply quickly, potentially before it has had a meaningful opportunity to contest the order's scope or accuracy.
Whether these concerns would ultimately persuade courts that ACPA is unconstitutional is a different question—and one that would only arise if the bill became law and was challenged. For now, they represent substantive objections that the bill's sponsors have not publicly addressed.
What This Means for Users Outside the US
ACPA, if enacted, would apply to VPN services operating within US jurisdiction or serving US users above the threshold. It would not directly govern what a UK-incorporated VPN provider does for its non-US users. A user in the United Kingdom connecting to a UK-based server would not be subject to a US court order requiring blocks on a list of US-designated sites.
The more relevant question is what a VPN provider's US-facing infrastructure would be required to do. A service that routes US users through servers in the United States, or that has significant US user numbers, could face obligations regardless of where the company is headquartered—though enforcement against a company with no US assets or presence is practically difficult.
For users concerned about network-level filtering in general, it is worth understanding the difference between VPN architectures and what they can and cannot protect against. Our comparison of VPNs, proxies, and Tor covers how these tools differ in their approach to routing and filtering.
Where the Bill Stands
H.R. 10364 has been referred to the House Judiciary Committee. That is the beginning of the legislative process, not the end. Bills referred to committee face several further hurdles: committee markup, a committee vote, a full House vote, Senate consideration, and presidential signature. The majority of bills introduced in Congress do not become law.
ACPA's significance at this stage is not legal but political and conceptual. It establishes, formally, that legislators are willing to treat VPN services as content enforcement infrastructure—a framing that would have been unusual in a major federal bill even a few years ago. Whether this bill advances, stalls, or is incorporated into broader legislation, that framing is now part of the legislative record.
Digital rights groups will continue to monitor the bill's progress through committee. Users who want to follow developments should look to organisations like Public Knowledge, which has already engaged publicly with the bill's implications.
A Note on PremierVPN's Position
PremierVPN is a UK-based, independent VPN provider. Our no-logs policy means we do not record which sites users visit or what they do online. We are not subject to US law in the way a US-incorporated service would be, and H.R. 10364—even if it became law—would not automatically govern our operations for non-US users.
We do not design our service to inspect or filter user traffic, and any obligation to do so would be fundamentally incompatible with what a VPN is for. We will continue to monitor legislative developments in the US, UK, and elsewhere that affect the privacy and usability of VPN services, and we will report on them honestly—including when the picture is uncertain, as it is here.
If you are evaluating a VPN in the context of questions like these, the most useful things to look at are where a provider is incorporated, what its logging practices actually say, and how its infrastructure is architected. Our IP leak test is a practical starting point for checking whether your current setup is behaving as expected.
ACPA is a proposal, not a law. But it is a proposal worth watching—because the question of whether VPNs can be compelled to act as enforcement infrastructure will not disappear from legislative agendas on either side of the Atlantic.
Share this article
Protect your privacy with PremierVPN
Fast, secure, and truly private VPN service with servers in 12+ countries.
Get Started