
The Federal Communications Commission has added foreign-produced advanced robotic devices to its Covered List, preventing new models from receiving the equipment authorization required for importation, marketing and sale in the U.S. The action follows national security determinations that the products pose unacceptable supply chain and cybersecurity risks.
According to the FCC, network-connected robots could be exploited to manipulate physical operations, collect sensitive data, conduct surveillance or be remotely commandeered, while connected power inverters could create vulnerabilities affecting critical infrastructure. The restrictions apply only to new device models and do not affect previously authorized products already in the U.S. market.
While this is not the first time robotics have raised cybersecurity concerns, the steps taken by the FCC to specifically call out these machines and components raised the brow of several industry experts.
Matt Wyckhouse, Founder & CEO, Finite State
“Supply chain resilience and onshoring of critical technology manufacturing matters to U.S. national security, and the risks documented in the government's determinations, remote commandeering, surveillance and pre-installed backdoors, are real, not hypothetical.
"The additional measure we'd advocate is objectivity: pairing these steps with true security assessment of the devices themselves.
"From analyzing the firmware inside thousands of connected products, we see the same pattern everywhere. Security is a property of engineering, not geography. There is rigorously engineered, secure software coming out of foreign countries, and there is deeply insecure software shipping from U.S. companies.
"Country of origin is an important input to the risk analysis, particularly where software provenance is hard to establish, but an objective assessment of what's actually in a device is what separates the secure from the vulnerable.
"That's why the FCC's proposed software and hardware bill-of-materials requirements are an encouraging step, and why pairing them with the substantive security requirements already developed under the Cyber Trust Mark, much as the EU is doing through the Cyber Resilience Act, would give the U.S. an approach that is both resilient and objective: one that strengthens the supply chain while raising the security bar for every device sold here, wherever it's built.”
Seemant Sehgal, Founder & CEO, BreachLock:
"The FCC drew a line at the import stage, which is the wrong place to draw it if the goal is reducing risk. There are already authorized devices operating in U.S. networks that carry the same trust relationships, the same firmware update dependencies, and the same remote access capabilities as anything on the new restricted list.
"Blocking future imports without a plan for what is already inside the perimeter is a procurement policy dressed up as a security measure."
Donald McFarlane, Advisory Board Member, Xcape, Inc.
“Taken together with recent guidance from the Five Eyes and other federal agencies, this decision reflects a growing emphasis on the cybersecurity of cyber-physical systems and the resilience of the critical infrastructure that depends on them. We should pay close attention to these signals. They are likely indicative of how governments assess the evolving threat environment and where they see strategic risk increasing.
“Industrial robots are increasingly more than just machines, they are connected computers capable of sensing, deciding, and acting in the physical world. Many of today’s advanced robots have significant operational dependencies on cloud connectivity, AI services, remote management, identity systems, and vendor-operated infrastructure.
"The security question is not simply whether someone can hack the robot; it’s also what happens if the cloud, the vendor, or the communications path the robot depends on is compromised or unavailable.”
John Strand, Owner, Black Hills Information Security, Inc.
“I think these technology-specific bans feel very arbitrary. The security concerns people raise about robotics are the same concerns we’ve had with automobiles, drones, industrial control systems, smartphones, and just about every other connected technology. If it has software, it will have vulnerabilities. That’s simply the reality of modern computing.
“If the standard is that a technology could someday be exploited by a foreign adversary, then almost every technology would qualify. That’s why these policies can feel less like a coherent cybersecurity strategy and more like market protectionism wrapped in the language of national security.
"The focus should be on building resilient systems, validating software and hardware, and reducing risk regardless of who manufactures the technology, instead of singling out one category while ignoring the fact that the same security challenges exist across the entire technology ecosystem.”
Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs
“Nation-state attackers have spent a decade moving up the supply chain. Software exploits get patched. Firmware backdoors get caught in audits. Hardware is where verification breaks down, because you cannot audit a fabrication line you do not control.
“That is the security argument behind the FCC adding foreign-produced robots and power inverters to its Covered List this week. Network-connected humanoid robots carry cameras, LiDAR, and persistent connectivity. Inverters sit between solar panels, batteries, data center equipment, and the grid. Both create attack surface that defenders can monitor but cannot fully inspect when the hardware ships from a geopolitical competitor.
"I've done enough embedded-device assessments to know that firmware review catches what you can reach, and on hardware imported from an adversary nation, there are layers you simply cannot reach. Software backdoors exist in every copy, find one and you've found them all. Hardware is different.
“One unit gets pulled off the line or intercepted in shipping, altered with a modified chip, and put back. Intelligence agencies, including ours, have been doing this for years. You can tear down a sample unit, certify it clean, and have no way of knowing the next unit off the same line hasn't been touched.
“The FCC has banned three product categories in seven months using the same Secure Networks Act written in 2019 for Huawei and ZTE. Drones in December, routers in March, now robots and power inverters. A White House interagency body issues a National Security Determination, the FCC updates its list, and the ban takes effect without new legislation.
“Watch the Conditional Approval list over the next 90 days. Fifteen non-Chinese UAS vendors cleared approval within months of the drones ban. Netgear and eero passed the router review within a month. Zero Chinese manufacturers have received approval in either category, and that ratio will hold for robots and inverters.”





















