In late September 2026, Congress got two competing site-blocking bills within about two weeks. Rep. Darrell Issa's American Copyright Protection Act (ACPA, H.R. 10364) came first. The bipartisan DEFEND IP Act from Sen. Thom Tillis and Rep. Zoe Lofgren followed. DEFEND IP is the more careful of the two, and it deserves to be judged on its own terms. Even so, it builds a blocking mechanism with no real penalty for getting it wrong.
The strongest case for the bill
Piracy of live sports and newly released films is a real harm, and the operators are often overseas and beyond the reach of US courts. Rightsholders have a fair complaint that notice-and-takedown does little against a site that ignores notices. Many democracies already use judicial site blocking. A bill that requires a federal court, a response period, and a look at less burdensome alternatives is not SOPA. Lofgren has long positioned herself as a skeptic of the 2012 approach. Her office described her earlier Foreign Anti-Digital Piracy Act (H.R. 791, introduced January 29, 2025) as a bill that targets only large-scale, foreign-run piracy sites, requires court orders, and has courts verify that blocking will not interfere with lawful content (Lofgren).
What DEFEND IP actually does
DEFEND IP merges Lofgren's FADPA with Tillis's Block BEARD draft. The Senate version is S. 5529, and Sens. Chris Coons, Marsha Blackburn and Adam Schiff are co-sponsors. According to TorrentFreak's reading of the text, it covers broadband providers with 50,000 or more subscribers and public DNS resolvers with $100 million or more in revenue. A federal court first designates a site as a "foreign digital piracy site" after a 20-day response window. A rightsholder then asks for a blocking order, and the court weighs feasibility and less burdensome alternatives. Orders last one year and can be renewed when a site migrates. The bill covers live events flagged before transmission begins. Orders cannot dictate the technical method, providers get immunity for good-faith compliance, and they can seek cost-sharing from rightsholders. VPNs that exclusively provide VPN services are carved out, and so are DNS resolvers operating exclusively through encrypted protocols.
The VPN carve-out matters. ACPA, by contrast, drops the earlier protections and expressly lists VPNs among covered intermediaries, according to EFF. Forcing privacy tools to enforce geographic copyright restrictions would be a serious step, and the sponsors of DEFEND IP were right to refuse it.
Where the design still fails
Whole-site blocking is blunt. A court order against a domain cannot distinguish infringing files from lawful speech hosted alongside them. EFF argues that "there is no way to create a mechanism for blocking access to an entire website that does not invite both deliberate abuse and lots of collateral harm to free and lawful speech" (EFF). The foreign examples EFF cites are sobering. Italy's system blocked 510 benign sites, and Spain's blocked more than 550,000 domains (EFF on ACPA). I have not independently verified those counts, and they come from systems that differ from the US proposals. They still show how enforcement tends to drift once the infrastructure exists.
The error costs fall on the wrong party. TorrentFreak reports that DEFEND IP offers no compensation for mistaken blocks, while ACPA at least requires copyright owners to post bonds, a point EFF also notes. Under DEFEND IP, a rightsholder who wins an overbroad order bears little of the cost. The site owner, who may be a small publisher or a foreign newsroom, must litigate in a US court to be unblocked. EFF notes the bill has "no punishments for getting a website blocked for protected speech." A system that rewards aggressive filing and does not penalize error will, over time, get more aggressive filings.
Orders that renew by default are hard to audit. One-year orders that can be extended when a site changes domain are practical for rightsholders. They are also an invitation to scope creep. The more a blocking order follows a site across mirrors, the more it works like a standing injunction against a publisher who never appeared. Neither bill requires the designating court to hear from the site operator first, and EFF notes that ACPA's initial designation can still be made without the operator appearing.
DNS resolvers are the wrong chokepoint. The $100 million revenue threshold sweeps in a handful of public resolvers that were built to be neutral infrastructure. Making resolvers part of the enforcement chain pushes copyright policy into the plumbing of the open internet. Public Knowledge, per TorrentFreak, warns that this builds "expansive infrastructure for censorship" instead of going after overseas operators directly.
A proportionate alternative
If Congress insists on site blocking, the minimum safeguards should be:
- Fee-shifting or damages for blocks later found wrongful, as ACPA's bond requirement partly contemplates.
- A requirement that the court make a specific finding that the site's infringing content is the overwhelming majority of what it hosts, rather than a lesser standard.
- Mandatory notice to the site operator, with a real chance to appear before a designation.
- Public, searchable dockets for every designation and order, so overblocking is measurable.
- A sunset and reporting requirement that forces Congress to look at actual collateral damage.
These add cost for rightsholders, but a legal tool that can remove lawful speech from view should cost something to use badly.
Bottom line
DEFEND IP is a real improvement over ACPA on VPNs, and its sponsors have clearly tried to avoid SOPA's mistakes. But the central design choice is unchanged. It gives courts the power to order the network layer to cut off whole sites, and it leaves no consequence for wrongful use. Congress should weigh the promised protection against the collateral harm before moving a bill through the Judiciary Committee.