The introduction of the DEFEND IP Act by Senator Thom Tillis and Rep. Zoe Lofgren marks a shift in how Congress approaches content removal at scale. Unlike earlier proposals that cast a wider net, this bill contains a deliberate carve-out: VPN providers are explicitly exempt from court-ordered blocking requirements. That distinction is worth examining not for political theatre, but for what it reveals about the technical and jurisdictional boundaries regulators are beginning to recognise.
Where the bill targets, and where it stops
The DEFEND IP Act grants copyright holders a mechanism to obtain court orders requiring Internet Service Providers and large DNS resolvers to block access to foreign sites deemed to host infringing content. ISPs sit at a natural chokepoint—they control the last-mile connection for most residential and business users. DNS resolvers, too, handle queries from millions of devices daily. Blocking at either layer affects broad traffic flows.
VPN providers, by design, sit outside this infrastructure hierarchy. A VPN client encrypts traffic and tunnels it to a remote server controlled by the VPN operator, typically in a different jurisdiction. The ISP or DNS resolver upstream cannot see the destination—only that encrypted traffic is flowing to a VPN endpoint. Blocking the VPN provider's IP address would require a court order against the operator directly, which is impractical when the operator is incorporated overseas or deliberately maintains infrastructure across multiple jurisdictions.
By exempting VPN providers, the bill acknowledges this technical reality. It also sidesteps the question of whether a US court can compel a foreign entity to comply with domestic blocking orders—a question that remains unsettled in international law.
Jurisdiction and the limits of court orders
The explicit exemption also reflects a deeper jurisdictional problem. ISPs are heavily regulated entities in the US, often licensed by state and federal authorities. They have clear domestic assets, staff, and infrastructure that a court can threaten to seize or fine. DNS resolvers like Cloudflare and Google Public DNS operate servers in US territory and are subject to US subpoena and injunction.
VPN operators are different. Many deliberately incorporate in jurisdictions—the British Virgin Islands, Panama, Romania—that lack extradition treaties with the US or have laws that shield them from foreign copyright orders. Even US-based VPN operators often route traffic through overseas infrastructure or use business structures that limit domestic assets available for seizure. A court order becomes difficult to enforce when the defendant's material resources are beyond US reach.
This gap in enforcement authority is not new. The same jurisdictional problem has long frustrated copyright holders attempting to shut down Torrent sites, streaming platforms, and DNS blocklists hosted in countries indifferent to US copyright law. The DEFEND IP Act does not solve that problem—it simply acknowledges that VPN operators exist in a grey zone where compulsion is unreliable.
What this means for privacy and offshore infrastructure
The exemption carries implications for how privacy services position themselves. Operators running no-logs VPN services, anonymous hosting, or privacy-focused infrastructure now have a clearer signal: as long as they do not themselves host infringing content or directly operate DNS services, they are unlikely to face mandatory blocking orders under this bill. That does not mean they are risk-free—future legislation could change the calculus, and criminal liability is separate from civil copyright enforcement—but it is a recognition that the technical architecture of VPN encryption makes blocking impractical without targeting the operator's physical infrastructure or assets.
For hosting providers and infrastructure operators in offshore jurisdictions, the bill's structure reinforces an existing incentive: decentralise operational dependencies, avoid centralised DNS or routing points that a court can easily seize, and maintain assets outside US legal reach. None of this is controversial from a technical standpoint; it is standard practice for any infrastructure operator seeking resilience against jurisdictional risk.
The pattern beneath the exemption
Taken alongside earlier blocking proposals and EU moves toward mandatory content filtering, the VPN exemption suggests regulators are learning to distinguish between scalable technical enforcement and jurisdictional theatre. You can order an ISP to block a domain. You cannot easily order an operator in a foreign country to decrypt their users' traffic or reveal their destination.
Rather than treat that gap as a problem to solve through stronger laws, this bill accepts it. That acceptance is pragmatic, but it also signals something important: the more critical infrastructure moves away from centralised chokepoints—DNS resolvers, large ISPs, backbone routers—the harder compulsory blocking becomes. The DEFEND IP Act does not eliminate that dynamic. It simply operates within the boundaries it sets.

