Could your robotic vacuum or four-legged robot dog be a covert agent for China or another country? The Federal Communications Commission (FCC) seemed to think so. This week, the agency called for a ban on new foreign-made humanoid robots and quadrupeds, as well as power inverters that are deployed to connect solar energy to the electric grid, citing national security risks.

The move is the latest from the White House to counter Chinese competition in artificial intelligence (AI) and to slow the adoption of clean energy, a technology that China now dominates globally.

“Relying on foreign-produced advanced robotic devices presents unacceptable supply chain and cybersecurity vulnerabilities,” the FCC warned, adding, “When advanced robotic devices and their critical components are sourced from foreign countries, U.S. stakeholders have limited visibility into the development practices and software provenance of the device. This magnifies the risk that vulnerabilities remain unaddressed, updates are withheld, or functionality is altered in ways that degrade the device.”

Beijing quickly accused the U.S. of protectionism, but security experts have warned that these devices can gather data without the owner’s knowledge or approval.

“We’re supportive of the FCC’s direction here,” said Matt Wyckhouse, founder and CEO at cybersecurity provider Finite State.

Wyckhouse told ClearanceJobs that supply chain resilience and onshoring of critical technology manufacturing matter deeply to U.S. national security, and the risks documented in the government’s determinations that there could be remote commandeering, surveillance, and pre-installed backdoors are real and not hypothetical.

“The additional measure we’d advocate is objectivity: pairing these steps with true security assessment of the devices themselves,” added Wyckhouse. “Country of origin is an important input to the risk analysis, particularly where software provenance is hard to establish, but an objective assessment of what’s actually in a device is what separates the secure from the vulnerable.”

Drawing a Line

The FCC’s call to ban robots and power inverters comes as each technology is still in its infancy, yet has the potential to gain wider adoption very quickly. For once, the United States seems to be ahead of the curve, instead of playing catch-up afterward.

That has been an issue with artificial intelligence (AI), where the U.S. didn’t attempt to control access to the technology for foreign companies or governments until well after the proverbial “Genie” was out of the bottle. Likewise, Washington is still actively weighing how to implement restrictions targeting Chinese AI and related hardware.

The same was true of certain social media platforms, notably TikTok, where it became practically too big to ban. The U.S. isn’t taking any chances this time.

Instead, with the robots and inverters, the FCC has been quick to warn that these forms of technology pose very real cybersecurity risks that could threaten critical infrastructure.

“The FCC drew a line at the import stage, which is the wrong place to draw it if the goal is reducing risk,” said Seemant Sehgal, founder and CEO at cybersecurity provider BreachLock.

“There are already authorized devices operating in U.S. networks that carry the same trust relationships, the same firmware update dependencies, and the same remote access capabilities as anything on the new restricted list,” Sehgal told ClearanceJobs. “Blocking future imports without a plan for what is already inside the perimeter is a procurement policy dressed up as a security measure.”

Additional products could also face a similar ban, some more established than others.

“The FCC has banned three product categories in seven months using the same Secure Networks Act written in 2019 for Huawei and ZTE. Drones in December, routers in March, now robots and power inverters. A White House interagency body issues a National Security Determination, the FCC updates its list, and the ban takes effect without new legislation,” explained Jacob Krell, senior director for Secure AI Solutions & Cybersecurity at Suzu Labs.

The ban on robots and inverters did seem to come somewhat out of the blue, and other bans likely also arrive with little warning.

Although the FCC is now banning foreign-made robots and inverters, some could eventually get the green light for import; just perhaps not those coming from China.

“Watch the Conditional Approval list over the next 90 days,” Krell told ClearanceJobs, noting that 15 non-Chinese UAS vendors cleared approval within months of the drones ban.

“Netgear and eero passed the router review within a month,” Krell added. “Zero Chinese manufacturers have received approval in either category, and that ratio will hold for robots and inverters.”

Is It Too Arbitrary?

Given that so many products are sourced from foreign companies, not every cybersecurity expert suggested that the bans were necessary. Robots and inverters are just two examples of literally dozens of products that are now imported, and could have similar or even greater security risks.

“These technology-specific bans feel very arbitrary,” said John Strand, owner of Black Hills Information Security, Inc.

Strand told ClearanceJobs that the security concerns people raise about robotics are the same concerns that had been seen with automobiles, drones, industrial control systems, smartphones, and just about every other connected technology.

“If it has software, it will have vulnerabilities,” acknowledged Strand. “That’s simply the reality of modern computing.”

He added that if the standard is that a foreign adversary could someday exploit a technology, then almost every technology would qualify.

“That’s why these policies can feel less like a coherent cybersecurity strategy and more like market protectionism wrapped in the language of national security,” Strand continued. “The focus should be on building resilient systems, validating software and hardware, and reducing risk regardless of who manufactures the technology, instead of singling out one category while ignoring the fact that the same security challenges exist across the entire technology ecosystem.”

The Industrial Machines

The United States clearly isn’t taking any chances with robots, and it isn’t just the robot vacuum or quadrupeds that are the main concern for Washington. The bigger concern, or at least it should be, is industrial robots that could provide an unexpected backdoor into a company’s network.

“Industrial robots are increasingly more than just machines; they are connected computers capable of sensing, deciding, and acting in the physical world,” suggested Donald McFarlane, advisory board member at Xcape, Inc.

McFarlane told ClearanceJobs that we shouldn’t think of these as being the same robots that have been on assembly lines since the 1970s and 1980s. These are far more advanced in terms of hardware and software.

“Many of today’s advanced robots have significant operational dependencies on cloud connectivity, AI services, remote management, identity systems, and vendor-operated infrastructure,” warned McFarlane. “The security question is not simply whether someone can hack the robot; it’s also what happens if the cloud, the vendor, or the communications path the robot depends on is compromised or unavailable.”

The danger is that nation-state attackers have also spent a decade moving up the supply chain, understanding that these robots could be a very easy weak point to exploit.

“Software exploits get patched. Firmware backdoors get caught in audits. Hardware is where verification breaks down, because you cannot audit a fabrication line you do not control,” added Krell.

“One unit gets pulled off the line or intercepted in shipping, altered with a modified chip, and put back. Intelligence agencies, including ours, have been doing this for years,” Krell continued. “You can tear down a sample unit, certify it clean, and have no way of knowing the next unit off the same line hasn’t been touched.”

Related News

Peter Suciu is a freelance writer who covers business technology and cyber security. He currently lives in Michigan and can be reached at petersuciu@gmail.com. You can follow him on Twitter: @PeterSuciu.