The VPN debate is about filtering, not a federal ban
Two copyright proposals in the U.S. House of Representatives offer very different answers to an important privacy question: should VPN providers be required to help block access to websites accused of large-scale piracy?
H.R. 10364, the American Copyright Protection Act, would include qualifying VPN providers within a proposed court-supervised blocking system. H.R. 10575, known as the DEFEND IP Act, would expressly exclude companies that exclusively provide VPN services. Both bills have been introduced and referred to the House Judiciary Committee, but neither is law.
The issue received renewed attention after digital-rights organization Fight for the Future reported on October 6 that thousands of people had participated in its September 25 Defend VPNs Day of Action. That organization opposes VPN restrictions, so its broader warnings should be understood as advocacy. Nevertheless, the competing bills confirm that the role of VPNs in online enforcement is now an active policy question.
For users, the immediate message is straightforward: there is no blanket federal VPN ban to respond to, and no reason to cancel a subscription because of these proposals. The longer-term debate concerns whether privacy and network services should become legally mandated filtering points.
Defend VPNs Day of Action 2026 drives action for privacy online · www.govinfo.gov · www.govinfo.gov
H.R. 10364 would include larger VPN services
Introduced on September 14, H.R. 10364 defines covered service providers to include broadband companies, DNS-resolution services and virtual private networks. Its provisions would not apply to a service with fewer than 100,000 monthly users or subscribers in the United States.
Under the proposed process, a federal court could designate a foreign online service as primarily engaged in copyright infringement. A copyright owner could then ask the court to order named providers to take commercially reasonable steps to prevent U.S. users from accessing that service. The bill does not impose one universal blocking technology, leaving room for different providers to implement an order in different ways.
Orders would generally expire within 12 months, although extensions could be requested. Those limits and the involvement of a court distinguish the proposal from an unrestricted administrative blocking system. Even so, the bill would make qualifying VPN providers part of the enforcement chain.
That does not mean a VPN would stop encrypting a customer’s connection. Encryption and destination availability are separate. Traffic between a device and a VPN server could remain encrypted while the provider blocks a named destination, refuses the connection or presents a notice in response to a valid order.
www.govinfo.gov
The DEFEND IP Act takes a different route
H.R. 10575, introduced on September 24, also proposes court-authorized action against foreign piracy sites, but its definition of a covered provider is narrower. The bill expressly excludes an entity that exclusively provides VPN services or a similar service that encrypts and routes traffic through intermediary servers. It also excludes entities providing DNS resolution exclusively through encrypted DNS protocols.
Instead, the bill would cover broadband providers with at least 50,000 subscribers and public DNS-resolution providers reporting more than $100 million in annual revenue. This makes its treatment of dedicated VPN services materially different from that of H.R. 10364.
One word deserves particular attention: exclusively. A company devoted solely to VPN service appears to fall within the exemption. The text does not provide the same unambiguous protection to a diversified company that sells a VPN alongside other potentially covered network services. That is an inference from the wording, not a settled legal interpretation. No court has interpreted the provision, and Congress could amend it before any vote.
This distinction is why readers should follow the bill numbers rather than headlines referring vaguely to “the site-blocking bill.” One proposal includes qualifying VPNs; the other attempts to leave VPN-only providers outside the system.
www.govinfo.gov
Why infrastructure-level blocking raises privacy concerns
Website blocking sounds simple, but implementation can affect more than the intended target. DNS, for example, works like an addressing system that translates a domain name into information a device can use to reach an online service. DNS blocking changes or withholds that answer; it does not remove the disputed material from its original server.
The Internet Society has warned that mandated DNS blocking can restrict lawful material when unrelated content shares a domain or supporting infrastructure. It may also interfere with security mechanisms and create effects beyond the jurisdiction that issued an order. The organization recommends directing enforcement toward responsible operators or hosting sources where practical rather than altering core Internet infrastructure.
These concerns do not establish that every blocking order will cause widespread disruption. The result depends on the target, technical method and safeguards used. They do explain why transparency, appeal procedures and narrowly drawn orders matter.
Encrypted DNS is not a universal solution. It can protect DNS queries from some local monitoring or manipulation, but it does not provide anonymity and cannot guarantee access when restrictions are applied by an ISP, VPN server, hosting company or another layer of the connection.
DNS Blocking: Mind the Unintended Consequences - Internet Society · www.internetsociety.org
What VPN users should do now
No immediate technical change is required because neither proposal currently imposes obligations on providers or customers. Users can, however, use the debate as a reason to review how their privacy tools handle legal demands.
- Read the provider’s transparency material. Look for clear explanations of court orders, legal requests, domain blocking and whether affected users receive notice. A broad “no logs” statement does not answer every question about filtering.
- Separate encryption from access. A VPN may protect data travelling to its server without promising that every destination will remain reachable. Blocking can happen after the encrypted tunnel has been established.
- Avoid opportunistic “anti-blocking” apps. Political controversy often creates an opening for hastily promoted tools. Check ownership, update history, permissions, privacy terms and independent security assessments before installing unfamiliar software.
- Track H.R. 10364 and H.R. 10575 separately. Legislative text can be amended, combined, delayed or abandoned. Viral posts that omit the bill number may mix provisions from competing proposals.
- Do not treat encrypted DNS as a substitute for a VPN. The technologies address different parts of a connection. Encrypted DNS conceals DNS requests from some observers, while a VPN generally encrypts and routes a broader portion of device traffic to a VPN server.
- Keep the policy issue in focus. The privacy concern is not about presenting VPNs as piracy tools. It is whether neutral communications infrastructure should be redesigned as a copyright-enforcement layer and what safeguards would limit collateral blocking.
www.govinfo.gov · DNS Blocking: Mind the Unintended Consequences - Internet Society · www.govinfo.gov
The consequential choice is still ahead
These bills do not eliminate VPN access, and their introduction does not predict which approach—if either—Congress will adopt. Their contrasting language nevertheless establishes a significant policy choice.
H.R. 10364 would place sufficiently large VPN providers inside a court-ordered blocking framework. H.R. 10575 would exempt VPN-only services while relying more heavily on broadband and large public DNS providers. The practical differences could affect product design, legal compliance and the information providers disclose to customers.
Users do not need to panic, switch services solely because of a proposal or install questionable circumvention software. They should instead monitor the official texts, demand understandable transparency policies and remain alert to amendments. The central question is not whether VPNs disappear tomorrow, but whether services built to protect and route private communications should also be required to decide which destinations their users may reach.
Defend VPNs Day of Action 2026 drives action for privacy online · www.govinfo.gov · www.govinfo.gov