WASHINGTON — The robot patrolling a warehouse floor or crawling on four legs through a logistics hub may now carry a designation that once belonged to Huawei routers and ZTE base stations: national security threat.
The Federal Communications Commission on Monday updated its Covered List — the agency’s register of equipment determined to pose an unacceptable risk to U.S. communications infrastructure — to include humanoid robots, quadruped robots, and connected power inverters manufactured in foreign adversary nations. A White House interagency body formally declared all three categories to represent unacceptable risks before the FCC’s listing took effect. New models of those devices will no longer be eligible for the equipment authorization required to be imported, marketed, or sold in the United States.
The practical consequence is harder to overstate than it might first appear. Hundreds of companies and research institutions across the country have acquired Chinese-made quadruped robots over the past several years — machines that walk warehouse floors, assist on factory lines, and have become fixtures in university robotics programs. The existing fleet is not retroactively banned. But the supply chain for replacing, upgrading, or expanding it has narrowed sharply, and every business running a foreign-made robot now has a policy question sitting alongside whatever technical ones they may already have.
The move extends Washington’s hardware security perimeter from telecommunications equipment, where it has been focused since 2019, into physical machines that see, hear, and move through facilities where sensitive work happens. For the manufacturing sector, logistics companies, and academic institutions that have embraced affordable Chinese robotics, the FCC’s action means that whatever cost advantage they captured now carries a new kind of liability — one that parallels enforcement actions already playing out across the semiconductor supply chain.
A known, unpatched exploit made the Covered List expansion easier to justify. Researchers disclosed a critical flaw in Unitree’s hardware in September 2025, documented publicly on GitHub under the name UniPwn, that the company had not remediated by Monday. The vulnerability sits in the Bluetooth Low Energy interface these robots use for Wi-Fi configuration and relies on a hardcoded AES encryption key — identical across every Go2, B2, G1, and H1 unit ever manufactured — meaning any attacker within Bluetooth range can achieve root-level control without authentication. The exploit is wormable: a compromised robot can silently scan for other Unitree units nearby and take them over, building what researchers described as a robot botnet that spreads through proximity alone. The House Select Committee on the Chinese Communist Party confirmed those machines were running inside networks at MIT, Princeton, Carnegie Mellon, and the University of Waterloo before Monday’s listing.
Rep. John Moolenaar, the Michigan Republican who chairs that committee, had been pushing toward precisely this outcome. Along with Rep. Jay Obernolte and Rep. Morgan McClellan, Moolenaar introduced the GUARD Act on June 3 — legislation that would extend the Covered List framework specifically to robotics, and that now stands to advance considerably faster than its sponsors had planned. “Keep out Chinese robots with backdoors that share sensitive data with the CCP,” Moolenaar said in a statement from the committee. The bipartisan nature of the bill reflects how thoroughly the framing of Chinese technology as a hardware risk — a concern that extends to Chinese AI systems, not just physical devices — has become a fixture in Washington.
The Covered List has existed in its current form since the Secure and Trusted Communications Networks Act of 2019, which directed the FCC to identify equipment posing national security risks and restrict its use in subsidized networks. The list began with Huawei and ZTE, expanded to surveillance camera manufacturers Hikvision and Dahua, then incorporated Kaspersky software. Monday’s update is the most significant expansion of the list’s scope since its creation — moving from passive communications and surveillance hardware to machines that physically navigate space, collect environmental data, and interact with their surroundings.
Connected power inverters, which convert output from solar panels and battery storage systems into grid-ready electricity, were added for related but distinct reasons. European regulators had flagged Chinese-manufactured inverters months earlier, citing concerns about malware installation during maintenance windows and the potential to disrupt grid operations remotely. American energy developers and data center operators that have installed Chinese-made inverters face a question the FCC left unanswered Monday: what, if anything, the Covered List designation requires of equipment that was legally purchased and federally authorized before the listing arrived.
Exemptions exist through a Conditional Approval mechanism operated by the Department of Energy and the Department of Homeland Security, under which specific devices can continue operating after satisfying additional security requirements. The FCC has not published the criteria for which robot models or inverter systems qualify for that pathway, or when that guidance might arrive.
The announcement did not name a single manufacturer. It did not name China. And it offered no framework for the questions that follow most directly from the listing: what happens to existing authorized units as they age, whether software updates for hardware already in the field will require additional agency review, and how broadly the inverter designation reaches into solar installations that have been generating power for years. The scope question is the one Washington has opened without answering. For anyone currently operating a foreign-made robot — or reconsidering whether to — that gap is where the policy actually lives.

