Trump signs an executive order that seeks to thwart foreign use of cloud computing products or services for malicious cyber operations against the US
Netflix content ‘turning point’, Jack's back, Samsung robots Joel Khalili / TechRadar : Trump looks to block foreign actors from US cloud computing services Tweets: Annie Apple / @survivinamerica : One of the best thing about today is that Donald Trump can't tweet, can't Facebook and can't post on Instagram. Black women literally threw his ass out of the White House and banished him to the 1980s. I love us. Joe Uchill / @joeuchill : The new know-your-foreign-customer EO for cloud infrastructure is going to get some pushback. Get your nicest pushback outfit ready. https://www.whitehouse.gov/... Real GrrrGraphics Cartoons / @rrrgthe : .Executive Order on Taking Additional Steps to Address the National Emergency with Respect to Significant Malicious Cyber-Enabled Activities https://www.whitehouse.gov/... @malwaretechblog : Wait till he finds out cybercriminals don't actually sign up for AWS with the real name. Most are using forged or stolen identity documents. https://www.whitehouse.gov/... Jake Williams / @malwarejake : Anyone else following the new EO on IaaS? I'm trying to decode this and trying to figure out why it needed to be issued today. Knowing the personality involved, it seems that either: 1. This hurts Biden 2. This helps Tump Anyone have theories for how? https://www.whitehouse.gov/...
Context & Ripple Effects
This order extends a line of Trump-era moves that treat digital infrastructure as a national-security chokepoint. It follows his [[a:941719|order blocking US companies from doing business with ICT firms owned or controlled by foreign adversaries]] in 2019, which targeted hardware supply chains; this one targets the compute layer instead, applying a know-your-foreign-customer model to cloud services.
It also lands on top of an earlier government-wide cybersecurity review from 2017 that largely kept prior administrations' policy path — meaning this is less a new doctrine than a new enforcement surface. The later EO scrapping or revising several Biden- and Obama-era cybersecurity programs shows how quickly these orders become contested terrain between administrations.
First-order effects
- US cloud providers such as AWS now face know-your-customer obligations for foreign accounts, shifting verification cost and liability onto IaaS operators rather than leaving abuse detection purely to them.
- Foreign actors who relied on anonymous sign-up to rent US compute for attacks lose that channel immediately, pushing hostile reconnaissance and staging workloads elsewhere.
Second-order effects
- Expect industry pushback over compliance burden and privacy-style objections — the reporting itself flags that the know-your-foreign-customer requirement 'is going to get some pushback' — plus revenue risk as legitimate foreign customers weigh friction against non-US alternatives.
- The move pressures rival cloud jurisdictions: providers outside US reach gain a selling point for customers who fear being cut off by American policy, echoing the supplier-decoupling dynamic set off by the 2019 ICT adversary order.
Third-order effects
- If the pattern holds, access to US compute becomes an explicitly regulated export-like good, with cloud capacity treated as strategic leverage alongside chips and software — a structural shift from open utility to permissioned infrastructure.
- Successive administrations rewriting each other's cyber EOs points to executive orders hardening into the default instrument of US cyber policy, leaving providers to navigate rules that flip with each White House.
The trend: US policy is moving from securing networks to controlling who may rent American compute at all, making cloud access a lever of national security rather than a neutral commodity.