Resources · Blog

It's not just routers anymore — and that's exactly the point

The FCC added humanoid robots and connected power inverters to its Covered List. It's the right call — and proof that a ban alone cannot finish the job.

Rows of solar panels in a field with grid-connected power inverters in the foreground
← Blog
Blog · Policy

This week the FCC added two new categories of foreign-made hardware to its Covered List — the federal government's register of technology that poses "unacceptable risks to the national security of the United States." Not routers this time. Networked smart machines — the humanoids and quadrupeds now moving into warehouses, factory floors, and job sites, carrying cameras and sensors and taking direction remotely. And connected power inverters — the devices that tie solar arrays, battery storage, and EV charging into the electrical grid.

I support this action. It's the right call, and it's overdue. But if you've read our earlier briefings and posts, you already know why I'm not calling it a solution: the FCC cannot achieve the sea change that is required on its own. What this action signals is that the tide for that sea change is finally coming in — and starting to flow in the right direction.

The pattern I described is now on the record

When the FCC placed foreign-made routers on the Covered List back in March, I said plainly that routers were the opening move, not the endgame. The underlying vulnerability was never confined to the box that routes your traffic. It runs through the entire ecosystem of internet-connected "smart hardware" that American homes, businesses, and infrastructure depend on — cameras, uninterruptible power supplies, printers, industrial sensors, medical equipment, building controls, EV chargers, and more — the vast majority manufactured in, or with key components from, nations that run active espionage campaigns against the United States and whose companies are compelled by law to cooperate with the state.

This week the list widened to smart machines and inverters. That is the pattern advancing exactly as I said it would, and it deserves to be recognized for what it is: the policy world catching up, category by category, to a threat the security community documented years ago.

The robots get the headlines but the inverters are the bigger risk

The humanoids and quadrupeds are what has gotten all the attention in the media. They are new, visible, and easy to picture walking across a warehouse floor. They are also, for now, comparatively few and mostly still arriving. The connected power inverter is the opposite story, and it is the one that should worry you more.

Inverters, together with the broader family of smart batteries, energy-storage controllers, EV chargers, and connected power devices, are already implanted at enormous scale — and already trusted inside of networks — across our critical infrastructure, factories, businesses, and homes. They sit at the seam between solar arrays, battery storage, the building, and the grid; the vast majority are networked and remotely manageable; and a large share are built, or built with key components, in nations that have engaged in systematic espionage and sabotage for the last decade. This is what former NSA Cybersecurity Director Rob Joyce is pointing to in his recent paper: "China's cyber explosives are in place".

A compromised inverter is not a privacy problem: it can be shut down remotely, driven to destabilize the circuit it feeds, and manipulated in concert across a whole fleet of identical units. Multiply one remotely reachable device by millions of near-identical deployments and you have a systemic vulnerability sitting quietly inside the power layer of the economy. And that power layer is highly distributed today, so it is inside your factories, businesses and homes too.

Why a ban, by itself, cannot finish this

A Covered List addition does one thing well: it stops the next bad device at the border. It is a necessary instrument. But it leaves three gaps that no single agency can close.

First, it addresses new equipment authorizations only. It does nothing about the millions of inverters, smart machines, cameras, and routers already deployed and already trusted the moment they were switched on. Nothing you own today is removed, recalled, or made safe by this action.

Second, it stops at the finished good and leaves the components inside untouched. The CHIPS Act mobilized advanced semiconductors for AI and defense but skipped the commodity memory, microcontrollers, and wireless chipsets inside every router, camera, inverter, and smart machine. Regulation has reached the device level and stopped at the component level.

Third — and this is the one policymakers most often miss — a ban creates demand for trusted domestic alternatives that American industry is not yet positioned to supply. Consider what happened a month before the router ban: Micron, America's leading memory maker, wound down its consumer Crucial brand entirely, redirecting capacity to AI data centers, and warned that the resulting memory drought could run to 2028. At the exact moment national-security policy began demanding American-made hardware, a critical component supplier was walking away from the market that hardware depends on. A ban without an industrial strategy behind it is a declaration without a delivery mechanism.

Sticks need carrots — and this needs more than the FCC

Good industrial policy requires both halves. The "sticks" — Covered List designations, CMMC requirements for the defense supply chain, the ROUTERS Act (which passed the House unanimously in September 2025 and still awaits the Senate, and which needs to do more than commission further study), Commerce Department authority over supply-chain chokepoints, and a Conditional Approval pathway that is fast and fair to American producers — create the market signal. They tell the market what is no longer acceptable.

But the sticks alone create a vacuum, not a solution. The "carrots" are what make the transition economically viable and not merely patriotically desirable: manufacturing incentives modeled on the CHIPS Act; seed and scaling capital through the DoD Office of Strategic Capital; direct CISA and NIST support for the small businesses most exposed; cyber-insurance incentives that reward good hardware hygiene; and transition subsidies that help businesses and consumers replace compromised devices without absorbing the full cost alone. And this cannot be a federal effort only. States are major purchasers — of hardware for their own agencies, schools, hospitals, and utilities — and are often positioned to move faster; state procurement mandates and workforce programs at community colleges and state universities belong in the same strategy.

The FCC did its part this week. Congress, Commerce, CISA, NIST, DoD, DHS, and the states now have to do theirs — together, and with urgency. Individual agency actions, however well-intentioned, cannot substitute for an integrated national strategy.

What you can do while the policy catches up

None of this requires you to wait. The realistic question for any operator is not how fast you can rip out and replace this hardware — you can't, and neither can anyone else — but how fast you can contain it.

That is the gap we built Faction to close. Our Pods and Portals sit behind your existing infrastructure and place your critical devices — the inverter, the power controller, the camera, the legacy controller — inside an owner-controlled network that is invisible and unreachable from the public internet, with every packet encrypted under keys only you hold. A compromised device can no longer reach, observe, or exfiltrate the traffic that matters, and continuous monitoring verifies it stays that way. No rip and replace. No specialist IT team required.

We are not the only answer, and we have never claimed to be — America needs many companies answering this call. But we are proof it can be done, and done now.

The tide is turning. This week's action is real evidence of it. Let's make sure it carries us all the way to where "Made in America and cyber-assured" is not the exception for critical hardware, but the standard.

Own your trust. Keep your peace of mind.

The new threat environment calls for a new Zero Trust model. We'd welcome the chance to show you how Faction puts you in control and secures your critical systems and assets rapidly with low cost and IT overhead.