Instrument

Cloud and compute-access denial

Cloud and compute-access denial restricts a target's use of infrastructure-as-a-service, hosted software or high-performance computing. The instrument operates through several separate legal and commercial channels. It is not a general rule that every service of a United States cloud provider is subject to one global denial authority.

Export controls can apply to items, software, technology, destinations, end users or end uses under the Export Administration Regulations (EAR). The January 2025 AI Diffusion interim final rule took effect on 13 January 2025 and set out a global architecture for advanced computing and model weights, with a general compliance date of 15 May 2025. Commerce announced universal non-enforcement and planned formal rescission on 13 May 2025. Government Accountability Office analysis later confirmed that the announcement did not itself erase the codified rule. BIS issued additional advanced-computing guidance in May 2026. The resulting legal state remains date-sensitive.

A second channel is customer identification and reporting. Commerce proposed an infrastructure-as-a-service rule in January 2024 that would implement customer-identification programmes and reporting for specified foreign malicious cyber activity and large AI-model training. The cited Federal Register record remained a proposal when checked on 29 July 2026; no final rule was located in the publication-day search. Executive Order 14110, one source of the AI reporting policy, was revoked in January 2025.

A third channel is sanctions on defined services. Under Executive Order 14071, the Treasury determined that specified information-technology consultancy and design services, and certain IT support and cloud-based services for covered enterprise-management and design or manufacturing software, could not be supplied from the United States or by United States persons to persons in Russia from 12 September 2024, subject to exclusions. OFAC's guidance does not create a general ban on all cloud services to Russia.

Private providers can also withdraw service under contract or risk policy. That is commercial conduct unless law or government direction is proved separately.

Assessment

Compute denial can raise costs where advanced accelerators and hyperscale infrastructure are concentrated. It can also drive intermediated access, shell customers, domestic-cloud investment and alternative hardware. The outcome depends on the exact service, customer, workload, jurisdiction and enforcement route. A publication-ready account must keep export licensing, proposed customer identification, sanctions services restrictions and private withdrawal separate.

See also

Economic statecraft · AI-chip and compute export control · Hyperscale cloud infrastructure · Compute clusters and AI datacentres (sovereign AI compute) · AI-model and training-data export control · Software and cloud-service denial

Sources

  1. United States Department of Commerce, proposed infrastructure-as-a-service customer-identification rule, 29 January 2024.
  2. United States Department of Commerce, Bureau of Industry and Security, Framework for Artificial Intelligence Diffusion, 15 January 2025.
  3. United States Department of Commerce, Bureau of Industry and Security, announcement of non-enforcement and planned rescission, 13 May 2025.
  4. United States Government Accountability Office, *Applicability of the Congressional Review Act to the Rescission of the Artificial Intelligence Diffusion Rule*, B-337935, 12 May 2026.
  5. Office of Foreign Assets Control, determination concerning information-technology services to Russia, 12 June 2024.
  6. Office of Foreign Assets Control, FAQs 1186, 1187 and 1192, checked 29 July 2026.
  7. President of the United States, Executive Order 14148, 20 January 2025.

Recommended citation

Cite this entry

Tennant, James J., ed. 'Cloud and compute-access denial.' The Encyclopedia of Economic Statecraft, version 2.0.1, last reviewed 12 August 2026. https://jamesjtennant.com/entries/cloud-and-compute-access-denial/.

Suggest an edit