FCC Adds Foreign-Produced Robots and Power Inverters to Covered List, Citing National Security Risks
The Federal Communications Commission (**FCC**) has expanded its Covered List to include certain foreign-produced mobile robots and networked power inverters. This move, effective July 28, aims to prevent new models from obtaining the necessary equipment authorization for import, marketing, or sale in the U.S., addressing potential national security and critical infrastructure vulnerabilities.
The **FCC** recently announced a significant expansion of its Covered List, targeting specific categories of foreign-produced mobile robots and networked power inverters. This action, implemented on July 28, largely prohibits new models within these categories from receiving the equipment authorization required for their import, marketing, or sale within the United States.
Existing authorized models can continue to be sold, and devices already owned by consumers remain unaffected. Federal government purchases and use are also exempt from this new **FCC** directive.
### Maintaining Security and Compatibility
Previously authorized hardware can still receive qualifying security and compatibility updates. The **FCC** has granted a waiver, valid until at least January 1, 2029, specifically for software and firmware changes that "patch vulnerabilities and facilitate compatibility with different operating systems." Manufacturers can also apply for Conditional Approval through the **FCC**, with the Department of War (**DoW**) potentially approving robotic devices and the **DoW** or Department of Homeland Security (**DHS**) approving power inverters. Applications for conditional approval must be submitted by January 1, 2028.
### Defining "Foreign-Produced"
Neither the robot nor the inverter categories are defined by brand or country of origin. Instead, "foreign-produced" is determined by whether an article qualifies as a "domestic end product" under the Buy American standard, as outlined in 48 CFR 25.101(a). This distinction is based on two national security determinations sent to the **FCC** on July 27.
### Robotic Devices Under Scrutiny
The robot definition encompasses mechanical mobile devices capable of ground locomotion, obstacle avoidance, or navigation that can operate remotely from a human operator using commands or sensor data. Key criteria include weighing more than 4.4 lbs (including any dock or ground station), carrying an environmental sensor, and supporting wired or wireless communications at 200 kbps or faster in either direction. Crucially, these devices must also run software locally or remotely to control movement, perception, data collection, or remote command and control, including firmware and artificial intelligence or machine-learning model weights.
The **FCC**'s fact sheet broadly refers to the category as "mobile robots, such as humanoids and quadrupeds," though the underlying determination is wider. Excluded from this definition are connected road vehicles, rail-only equipment, uncrewed aircraft, unmanned underwater vehicles, **FDA**-regulated medical and mobility devices, and fixed industrial arms (like SCARA, gantry, and delta designs).
Supporting the robot determination, the **FCC** cited three published security reports. One detailed a 2026 finding where a researcher could access camera feeds, microphone audio, and floor-plan maps from thousands of household robots. Another referenced **UniPwn** research, which documented four **Bluetooth Low Energy**-related **CVEs**, including **CVE-2025-35027**. This exploit chain provided root command execution on **Go2**, **B2**, **G1**, and **H1** units and could spread to nearby devices via **Bluetooth Low Energy** (**BLE**). The third cited vulnerability is **CVE-2025-2894**, which could grant full remote control of **Unitree Go1** quadrupeds through the **CloudSail** service with the correct **API** key.
### Power Inverters and Critical Infrastructure Concerns
The inverter definition covers systems that convert direct current to alternating current (or vice versa) and contain components for remote communication, control, sensing, data collection, or monitoring. The determination highlights that remote access to these devices could be leveraged to shut down systems, exfiltrate data, enable surveillance, or facilitate cyberattacks against critical infrastructure.
**Forescout**'s **SUN:DOWN** research, which reported 46 flaws across **Sungrow**, **SMA**, and **Growatt** products, is cited as evidence, describing potential fleet manipulation and grid instability, though no observed disruption. The determination also references **Idaho National Laboratory** on supply-chain and remote-connectivity risks, **ERCOT** on the potential for rapid grid collapse in a worst-case scenario, and one instance where a foreign manufacturer remotely disabled inverters following a dispute with a U.S. distributor (though the company was not named).
### A Proactive Supply Chain Measure
This **FCC** action is framed as a preventive supply-chain measure, rather than a response to a confirmed active exploitation campaign against deployed robots or inverters. This marks the third category-wide addition to the Covered List, following foreign-produced drones in December 2025 and consumer routers in March 2026.