It's not just routers anymore: the FCC just flagged robots and power inverters
The Covered List has crossed from the hardware that carries your data to the hardware that operates in your physical space
On July 28, 2026, the FCC added two new categories of foreign-made hardware to its Covered List — the federal government's register of technology that poses "unacceptable risks to the national security of the United States." Not routers this time. Networked smart machines — humanoids and quadrupeds with onboard sensors that can see, move, and be controlled remotely — and connected power inverters, the devices that tie solar arrays, battery storage, and EV charging to the grid.
We support this action. It's the right call, and it's overdue. But if you've read our earlier briefings and posts, you already know why we're not calling it a solution: the FCC cannot achieve the sea change that is required on its own. But this action signals that the tide for that sea change is indeed happening, and starting to flow in the right direction.
Why these devices, and why now
The logic is identical to the router determination. This is hardware, largely manufactured in or with key components from nations operating active espionage campaigns against the United States, that sits inside American operations with remote connectivity and the ability to act on the physical world. A compromised inverter can be disabled remotely or used to destabilize the grid it feeds. A compromised smart machine carries cameras, microphones, and mobility into the middle of a factory floor, a warehouse, or a hospital. The risk is no longer just data exfiltration. It is surveillance, sabotage, and the remote commandeering of machines that move.
That is the escalation worth noticing: the Covered List has crossed from the hardware that carries your data to the hardware that operates in your physical space.
The robots get the headlines but the inverters are the bigger risk
The humanoids and quadrupeds are what has gotten all the attention in the media. They are new, visible, and easy to picture walking across a warehouse floor. They are also, for now, comparatively few and mostly still arriving. The connected power inverter is the opposite story, and it is the one that should worry you more.
Inverters, together with the broader family of smart batteries, energy-storage controllers, EV chargers, and connected power devices, are already implanted at enormous scale — and already trusted inside of networks — across our critical infrastructure, factories, businesses, and homes. They sit at the seam between solar arrays, battery storage, the building, and the grid; the vast majority are networked and remotely manageable; and a large share are built, or built with key components, in nations that have engaged in systematic espionage and sabotage for the last decade. This is what former NSA Cybersecurity Director Rob Joyce is pointing to in his recent paper: "China's cyber explosives are in place".
A compromised inverter is not a privacy problem: it can be shut down remotely, driven to destabilize the circuit it feeds, and manipulated in concert across a whole fleet of identical units. Multiply one remotely reachable device by millions of near-identical deployments and you have a systemic vulnerability sitting quietly inside the power layer of the economy. And that power layer is highly distributed today, so it is inside your factories, businesses and homes too.
What it means for you
Read the fine print. Like the router action, this applies to new equipment authorizations — not to the millions of devices already deployed and already trusted the moment they were switched on. Nothing you own today is removed, recalled, or rendered safe by this. And this is not a critical-infrastructure problem you can wave off: the same inverters sit behind ordinary solar installs, and the same networked machines are arriving in mid-sized manufacturers, distribution centers, and clinics that will never staff a security team.
You cannot rip and replace your way out of that. The realistic question is not how fast you can remove this hardware — it's how fast you can contain it.
Why the FCC alone can't finish this
A ban stops the next bad device at the border. It does nothing about the installed base, and it stops at the finished good — leaving the silicon and components inside every one of these products untouched. It also creates demand for trusted domestic alternatives that American industry is not yet positioned to supply at scale. Closing this gap takes more than one agency: coherent action from Congress, Commerce, CISA and NIST, and DoD and DHS, matched at the state level — the regulatory "sticks" paired with the manufacturing and transition "carrots" that make trusted hardware viable, not just mandated. The FCC did its part this week. The rest of the response has to follow.
What you can do now
You don't have to wait for that policy to catch up to protect what's already inside your network — and this is where the two new categories part ways. An autonomous robot often needs security engineered into its own embedded components. A smart inverter, battery system, EV charger, or power controller does not: it sits on your network, behind your infrastructure, which is exactly where Faction's Pods and Portals contain it. They place your critical devices — the inverter, the power controller, the camera, the legacy controller — inside an owner-controlled network that is invisible and unreachable from the public internet, with every packet encrypted under keys only you hold. A compromised device can no longer reach, observe, or exfiltrate the traffic that matters, and OSec's continuous monitoring verifies it stays that way. No rip and replace, no waiting for a recall or a redesign, no specialist IT team. Now, not after the next budget cycle.
Own your trust. Keep your peace of mind.
The new threat environment calls for a new Zero Trust model. We'd welcome the chance to show you how Faction puts you in control and secures your critical systems and assets rapidly with low cost and IT overhead.