In the U.S. Congress, two bills aimed at blocking "pirate" websites were introduced about ten days apart. Both grant copyright holders the same right: to compel providers through the courts to block American access to foreign resources. However, they differ in a way that is crucial for our audience. The American Copyright Protection Act (ACPA) explicitly names VPN services among those required to block for the first time in U.S. history. In contrast, the competing DEFEND IP Act explicitly excludes VPNs. On October 2, the EFF released an analysis of the ACPA, and the topic spread across specialized media. Below is what is stated in both texts, where proxies fit in, and what should be done by those who parse or manage accounts through American IPs.
What was introduced and who is behind it
ACPA (H.R. 10364) — Darrell Issa's bill
The text is dated September 14, 2026, authored by Republican Darrell Issa from California, and the document has been submitted to the House Judiciary Committee. The mechanics are as follows:
- The copyright holder requests a federal court to recognize the site as a "foreign piracy site"; the standard of proof is "preponderance of evidence";
- Then the court issues a blocking order, and providers must take "commercially reasonable measures" to prevent users in the U.S. from accessing the resource;
- The recipients of the order have 14 days to respond, but the court may expedite the process — for example, for live sports broadcasts;
- The accused site is not required to participate in the process: recognition can occur without it. The appointment of a special master is at the court's discretion, not a requirement;
- The copyright holder posts a bond for potential damages; a party harmed by an erroneous block can seek compensation, but with a cap of $250,000 and only if they prove the copyright holder's error.
The key point is the definition of "service provider." The text states that it "includes broadband providers, domain name resolution providers, and virtual private networks." The threshold is 100,000 users or subscribers in the U.S. per month. Root DNS servers and domain registries are excluded, as are those who provide internet access to visitors and employees: airports, libraries, universities, cafes.
Additionally, the EFF highlights the expanded definition of "pirate site": it includes resources that, besides violations, have only "limited commercially significant" legal use. This means that a site with legitimate commerce could also end up on the list.
DEFEND IP Act — a joint project by Lofgren and Tillis
On September 24, it was introduced in the House by Zoe Lofgren (Democrat) and Ben Cline (Republican), and in the Senate by Thom Tillis, Chris Coons, Marsha Blackburn, and Adam Schiff (Senate number S. 5529). This merges two initiatives from last year: Lofgren's FADPA (February 2025) and Tillis's Block BEARD (July 2025).
- The obligation to block falls on providers with 50,000 subscribers and above, as well as public DNS resolvers with revenues of $100 million per year — effectively targeting Google and Cloudflare;
- The procedure is two-step: the court recognizes the site as pirate, then issues an order if the blocking is "technically feasible and effective"; the order is valid for one year with the possibility of extension;
- Parties have 20 days to respond, ex parte orders are allowed — without the participation of the other side;
- VPNs are explicitly excluded: the law does not apply to "an organization that solely provides virtual private network services or a similar service that encrypts and routes user traffic through intermediary servers."
ACPA vs. DEFEND IP: the main points in one table
| Parameter | ACPA (H.R. 10364) | DEFEND IP (H.R. 10575 / S. 5529) |
|---|---|---|
| Author | Darrell Issa | Lofgren, Cline, Tillis, Coons, Blackburn, Schiff |
| VPN | Explicitly included | Explicitly excluded (if the service is "solely" a VPN) |
| Threshold for ISPs | 100,000 users in the U.S. per month | 50,000 subscribers |
| Threshold for DNS | Included in the general definition | Revenue of $100 million per year |
| Response time | 14 days | 20 days, ex parte possible |
| Provider protection from piracy lawsuits | Broad immunity after the site is recognized as pirate | No, DMCA provisions remain |
| Compensation for providers' expenses | Court "must," including overhead | At the court's discretion, without overhead and capital expenditures |
Where proxies fit in
The word "proxy" does not appear in any of the discussed fragments. However, this does not mean that the topic of the proxy market is not relevant. Let's analyze both texts.
In ACPA, the definition is open
The wording "includes" in American legal terminology typically sets examples rather than a closed list. Currently, ISPs, DNS, and VPNs are named. No one can predict how broadly courts will interpret "service provider." The risk for proxy services is theoretical, but it arises precisely from the open structure. The threshold of 100,000 users per month from the U.S. is high for B2B providers that sell traffic to companies rather than millions of individuals.
In DEFEND IP, the exclusion is broader than it seems
Note the tail of the wording: "or a similar service that encrypts and routes traffic through intermediary servers." Proxies do direct traffic through an intermediary node. However, two words create uncertainty:
- "solely" — TorrentFreak notes that it is unclear how to treat companies for which VPN is just one of the services;
- "encrypts" — HTTP proxies without TLS do not encrypt traffic by themselves. Whether they fall under "similar service" is a matter of interpretation.
A detail that is overlooked: residential exits are with ISPs
Even if proxy services are not affected, blocks will still impact their users. A residential IP from the U.S. is a home connection with an American provider. If this provider blocks a site on its side (via DNS or IP) through a court order, traffic through such an exit will hit the same block. How exactly this occurs depends on where the domain is resolved: at the proxy gateway or at the resolver of the provider to which the device is connected. Mobile exits are the same case: a mobile operator is also an ISP. Datacenter IPs behave differently — their networks typically do not serve retail subscribers, but hosting also has its own backbone provider.
Why this matters even for those who do not deal with pirate content
The main risk for parsing and multi-accounting is not the blocking of a specific pirate site, but overblocking. The EFF provides European examples: in Italy, 510 harmless sites were blocked, and in Spain, over 550,000 domains. According to Reclaim The Net, among those affected in Europe were sites of Harvard University and Greenpeace. The mechanics are clear: a pirate resource sits behind a shared IP address of a CDN, block the IP — and hundreds of legitimate sites on the same infrastructure drop off together.
For someone collecting prices, reviews, or search results through American exits, this manifests as sudden timeouts and connection errors on some target sites, and only from one geo. Without monitoring by countries, this can easily be mistaken for a ban by the site itself, leading to "treating" the wrong issue: changing fingerprints, reducing speed, buying more IPs.
What are the chances this will become law
- Both texts have just been introduced and are sitting in committees — there have been no hearings or votes yet;
- TorrentFreak points out the timelines: Issa is leaving Congress at the end of the year, and Tillis's term ends in January 2027. Unfinished bills, according to Congressional rules, die with the session and must be reintroduced;
- The Motion Picture Association (MPA) publicly supports DEFEND IP: according to its representatives, the law will provide the country with a "highly effective tool" against foreign piracy;
- Opposition comes from the EFF, Public Knowledge, and the Re:Create coalition. In 2012, similar SOPA and PIPA were dropped by Congress after mass protests.
A realistic scenario is a negotiation between the two versions. Since DEFEND IP is backed by a bipartisan group from both chambers, the chances of a compromise without VPNs seem higher than those for ACPA in its current form. This is an assessment, not a prediction: the history of SOPA shows that such laws can get stuck even at the finish line.
What to do right now: a checklist for parsing and multi-accounting
- Log errors by geo. Record not only the response code but also the country of exit. A sudden increase in timeouts in one geo while others remain normal is a sign of network blocking, not anti-bot measures.
- Keep a backup geo. If the task does not require a strictly American IP (for example, checking site availability rather than prices for the U.S.), set up a switch to Canada, the UK, or the EU in advance. For residential pools, this is just one country setting in residential proxies from ProxyCove.
- Resolve DNS on the proxy side. Use socks5h:// instead of socks5:// or HTTP proxies with CONNECT, so the domain resolves at the gateway rather than at your local resolver. This does not bypass IP blocking at the exit ISP, but it removes an unnecessary point of failure and request leakage.
- Separate tasks by IP type. For mass technical collection, where "home" reputation is not needed, check how the target behaves through datacenter proxies: they have a different path to the site than retail ISPs.
- Do not confuse piracy laws with VPN access laws. These are different regulatory lines. We discussed how the state of Utah mandated sites to recognize VPNs and proxies by IP in the analysis of Utah SB 73 and IP blocking — there, the user of the proxy, not the pirate site, is already under threat.
Conclusion
Neither ACPA nor DEFEND IP is law yet, and neither directly mentions proxies. However, the direction is clear: the U.S. is moving towards judicial blocking of sites at the provider and DNS level, which, according to MPA estimates, already affects over fifty countries. For proxy businesses, the consequences will not come through a ban on proxies, but through infrastructure: residential and mobile exits in the U.S. will inherit their ISPs' blocks, and overblocking on shared IPs will affect legitimate sites. Preparing for this is inexpensive: monitoring errors by countries, having a backup geo, and resolving DNS at the gateway. It is important to keep an eye on which version passes the committee, especially the fate of the words "includes" in ACPA and "solely" in DEFEND IP.
