FCC Restricts New Foreign Robots and Inverters Over Security Risks

Wait 5 sec.

The FCC added foreign robots and power inverters to its Covered List, while allowing security updates for existing authorized devices until 2029.The FCC just widened its Covered List again, this time adding foreign-produced advanced robotic devices and power inverters. In plain terms, that means new models in those categories generally can’t get the equipment authorization they need for import, marketing, or sale in the US, although already authorized devices can still be sold and used.“The Federal Communications Commission’s Office of Engineering and Technology (OET) announces that certain prohibitions contained in 47 CFR §§ 2.932(b) and 2.1043(b) will not apply for now to certain foreign-produced advanced robotic devices and power inverters. All advanced robotic devices and power inverters authorized for use in the United States may continue to receive software and firmware updates that mitigate harm to U.S. consumers at least until January 1, 2029.” reads the FCC public notice. “These include all software and firmware updates to ensure the continued functionality of the devices, such as those that patch vulnerabilities and facilitate compatibility with different operating systems.”The FCC Covered List is a registry of communications equipment and services considered potential national security or public safety risks in the United States. Created under the Secure and Trusted Communications Networks Act of 2019, it targets foreign-produced technologies that may raise concerns over espionage, cyber vulnerabilities, foreign influence, or supply-chain risks. Devices added to the list may face restrictions, including limits on FCC authorization for new products, additional approval requirements for hardware or software changes, and greater scrutiny for companies using these technologies.That waiver matters because the FCC’s default rules would otherwise block permissive changes on covered equipment, including software and firmware updates that fix vulnerabilities or keep devices working with different operating systems. The agency is trying to avoid a stupid outcome where security updates get trapped behind a rule meant to cut off risky gear.“OET finds that special circumstances warrant a deviation from the general rules and the public interest would be better served by waiving prohibitions on these Class I and Class II permissive changes in these circumstances.” continues the notice.The notice is narrow, though. It only covers already authorized devices, and grantees still have to follow the rest of the FCC’s rules, including the normal requirements for Class II permissive changes, test results, minimum performance, and certification statements. So this is relief, not a free pass.The FCC also drew a line around what counts as covered hardware. For robots, the definition is broader than just “mobile robots” and excludes connected road vehicles, rail-only equipment, uncrewed aircraft, underwater vehicles, FDA-regulated medical and mobility devices, and fixed industrial arms like SCARA, gantry, and delta systems. For inverters, the rule covers systems that convert DC to AC or the reverse and include remote communication, control, sensing, data collection, or monitoring features.“OET believes that analogous concerns regarding the continued safe operation of existing models of UAS, UAS critical components, and routers that OET described in the prior UAS Waiver and Router Waiver also apply equally to foreign-produced power inverters and advanced robotic devices.” states FCC. “Therefore, OET concludes that waiving our prohibitions with regard to software and firmware Class I and II permissive changes that mitigate harm to U.S. consumers for Covered Power Inverters and Covered Advanced Robotic Devices through at least January 1, 2029, is warranted and in the public interest.”The FCC’s move is preventive, not reactive. It doesn’t name a confirmed active campaign against deployed robots or inverters, but it does rely on prior security research and supply-chain concerns to justify the action. That includes cases where researchers found exposure of camera feeds, microphone audio, maps, BLE attack paths, API-driven remote control, and inverter risks tied to remote access and grid instability.“We clarify that this waiver only applies to the prohibitions on Class I or Class II permissive changes for already-authorized devices. Grantees whose devices are subject to this waiver must still comply with other relevant FCC rules.” concludes the notice.The agency is also making clear that this is part of a wider pattern. The action follows earlier Covered List moves on foreign-produced drones and consumer routers, so the FCC is steadily using the same national-security framework across more device classes. The message is simple: if the device can be reached, updated, or remotely controlled, the supply chain is now part of the threat model.Follow me on Twitter: @securityaffairs and Facebook and MastodonPierluigi Paganini(SecurityAffairs – hacking, Covered List)