
The United States Commerce Department proposed in September 2024 to prohibit specified Chinese- and Russian-linked software and hardware in connected vehicles, citing risks of surveillance, remote disruption and dependence on foreign-adversary supply chains. The measure was a proposed rule, not an immediate ban on every foreign-made vehicle component.
The rule targeted connected systems
It focused on vehicle connectivity-system hardware and software and software used in automated-driving systems. These technologies communicate externally or help control vehicle behaviour, making compromise potentially more consequential than an ordinary component defect.
Parts outside the defined systems were not automatically covered merely because they were made in China.
China and Russia were named countries of concern
The proposal covered technology with a sufficient nexus to people owned, controlled by or subject to those governments’ jurisdiction or direction. It also restricted connected-vehicle manufacturers tied to those countries, even for some vehicles assembled in the United States.
Detailed definitions were necessary to determine corporate and supply-chain relationships.
Officials described data and disruption risks
Modern vehicles can collect location, infrastructure and driver information while receiving software updates and commands. Commerce Secretary Gina Raimondo argued that a hostile actor could exploit widespread access to gather intelligence or disrupt many vehicles.
The rule addressed a projected systemic risk; officials did not claim that all covered products contained active malware.
Implementation was designed to be phased
Covered software restrictions were proposed for model year 2027, while hardware restrictions would begin around 2029 or model year 2030. Longer lead time recognized the difficulty of tracing and replacing embedded supply chains.
Automakers still warned that compliance would require extensive mapping and engineering.
The process allowed public comment
A notice of proposed rulemaking invited industry, security experts and the public to challenge definitions, costs and feasibility before a final rule. Agencies were required to consider that record.
Reporting should separate the September proposal from later final requirements and effective dates.
Security and trade policy overlapped
The Biden administration had also increased tariffs on Chinese electric vehicles. China criticized the connected-vehicle plan as protectionist, while US officials framed it as a narrow national-security action.
Both effects can coexist: a security rule may also reshape competition and domestic manufacturing.
Privacy concerns are not limited to foreign suppliers
American and allied vehicles also collect sensitive data. Restricting adversary access does not substitute for strong privacy rules, secure software development, vulnerability reporting and limits on commercial data use across the industry.
Consumers need protection regardless of where a manufacturer is headquartered.
Effectiveness depends on precise, auditable rules
Broad exclusions could raise costs without reducing meaningful risk, while loopholes through third countries could defeat the purpose. Compliance needs component inventories, attestations, testing and penalties proportionate to violations.
The proposal marked a shift from reacting to cyber incidents toward limiting strategically risky technology before it became widespread. Its merits should be judged by evidence of reduced access and resilient supply chains, not by treating every Chinese product as malicious or every domestic product as safe.
Regulators should publish guidance early enough for suppliers to correct uncertain classifications and should preserve narrowly tailored procedures for legitimate research or low-risk uses. Periodic review is necessary because vehicle architecture and geopolitical risks will change faster than a static component list.



