Congress should fight piracy, not make ISPs internet police
Online piracy is a serious problem for content creators and rightsholders. Studies estimate that unauthorized streaming and downloads cost the US economy billions in lost revenue each year. But mandating that internet service providers (ISPs) block alleged piracy websites would shift responsibility from the bad actors to innocent ISPs while creating risks of overblocking, perpetual compliance obligations, and free speech concerns.
There have been a series of legislative proposals (either formally introduced or disseminated as discussion drafts) to address content piracy, including the Foreign Anti-Digital Piracy Act, American Copyright Protection Act, and Block BEARD Act. While the proposals differ procedurally, all would authorize courts to order ISPs and DNS resolvers (the internet’s equivalent to a phone book) to block access to foreign piracy websites.
Rather than targeting piracy operators, site-blocking proposals enlist ISPs as anti-piracy police.
These efforts have advanced even as the Supreme Court has grown more skeptical of holding intermediaries responsible for the behavior of users. In March 2026, in Cox Communications v. Sony Music, the Court held that an ISP is not liable for copyright infringement merely because it provides a general-purpose service that it knows some customers will use to infringe (contributory liability requires intent). From Sony v. Universal in 1984 to Cox this year, the Court has been consistently reluctant to regard general-purpose services as responsible for misuse by a few wrongdoers. Congress should be equally reluctant.
The most significant risk involved in ISP site-blocking is overblocking. IP address and DNS-level blocking is a blunt tool. Shared IP addresses, content delivery networks, and cloud hosting put many unrelated, lawful sites behind a single IP address. Accordingly, blocking such addresses will harm bystanders. IP address recycling compounds this problem, as an address tied to a pirate site today may be reassigned to a legitimate user tomorrow.
Though the proposals include certain safeguards (such as reaching only foreign sites and only then via an order from a federal court), none of them reach the reason bystanders get blocked in the first place. The sites caught alongside a pirate domain share its infrastructure, not its purpose, so a court reviewing the named target never hears from the thousands that go dark with it.
Recent examples in Europe demonstrate the risks of overblocking. Since 2025, Spain’s top football league, La Liga, has obligated the country’s largest ISPs to block Cloudflare IP addresses during match times. A June 2026 study by the Open Observatory of Network Interference found that blocking as few as four to twenty IP addresses in a single match window knocked more than 400,000 unrelated sites offline. Blocked sites included banking apps, a national health operator, and ironically Freedom.gov, a US government online portal designed to help people evade censorship. In a similar fashion, a September 2025 University of Twente study found that Italy’s Piracy Shield has indiscriminately blocked hundreds of legitimate, non-streaming sites. Piracy Shield even knocked Google Drive offline temporarily.
Overblocking is not the only problem. Maintaining site-blocking infrastructure incurs significant recurring compliance costs. Even with carve-outs for the smallest providers, mid-sized and regional ISPs would incur continuing engineering, legal, and compliance obligations that major national providers can better absorb. Also, because the proposed site-blocking regimes involve dynamic injunctions that extend to new domains as targets move, the obligation is never-ending, becoming a perpetual and open-ended policing duty.
A clear sign that the proposed legislation is misdirected is that the proposals also reach public DNS resolvers. A resolver fulfills a specific purpose: it translates a domain name into a numerical address (the way a phone book turns a name into a number). Cloudflare’s public resolver alone answers hundreds of billions of queries a day, the vast majority of which have nothing to do with pirated content. The legislation’s requirement of filtering here is both overinclusive and ineffective. It is overinclusive because it degrades a global service to reach a handful of targets. It is ineffective because bad actors can evade the filtering with a simple settings change to use encrypted DNS and a different resolver.
The proposed site-blocking regime also raises serious First Amendment concerns. Overblocking censors lawful expression that happens to share infrastructure with a piracy site but has nothing to do with online piracy. No-fault and ex-parte procedures compound this problem by cutting off access before the affected parties are heard.
Despite all of the costs and impositions on free expression, the underlying offense is left untouched. That is so because ISP site-blocking regimes are easy to evade. A VPN routes around both IP and DNS blocks with a few taps, and encrypted resolvers and proxies offer lower-effort routes around DNS filtering. These are tools that determined users can deploy in minutes. Blocked sites reappear at new domains and mirrors faster than orders can follow. Additionally, much infringing material can now move through decentralized peer-to-peer networks that have no central website or server for an order to reach. The block lands on infrastructure, but the demand simply moves. La Liga, for instance, concedes it stops only about 60 percent of the streams it targets. It has responded by chasing VPNs rather than reconsidering the tool.
Considering that demand persists, the more promising path targets the operators who profit from piracy, rather than the ISPs that merely carry the traffic. Following the money by disrupting pirate operators’ payment processing, advertising revenue, merchant accounts, hosting arrangements, and international distribution networks directly targets the business model that sustains large-scale piracy.
Piracy is a serious problem deserving serious solutions. But site-blocking shifts responsibility from the bad actors to ISPs, even though the Supreme Court has declined to assign ISPs the role of piracy police. Site-blocking is a costly answer to a real problem, and one that can be sidestepped via a dropdown menu.
Congress should pursue the pirates, not deputize ISPs.