The Trump administration is recruiting private security firms to conduct federal government-authorized operations, including cyberattacks, against overseas-based criminal organizations that commit hacks on US persons, organizations, or government entities.
In a National Security Presidential Memorandum issued Thursday, US President Donald Trump directed the National Coordination Center (NCC), which operates under the Homeland Security Task Force, to develop a program for conducting specific cyber operations that combat foreign transnational criminal organizations (TCOs). The Departments of Justice and Homeland Security will provide oversight. The lynchpin of that program is bringing in private sector companies to participate.
Devil will be in the still-undefined details
A fact sheet that accompanied Thursday’s memo listed ransomware, sextortion schemes, phishing campaigns, financial fraud, and impersonation scams as activities eligible for private-sector security firms to target. The memo said such firms could “conduct Cyber Surveillance Operations and Cyber Effects Operations” against “cyber-enabled” TCOs. Such groups are defined as “any foreign group that conducts cyber-enabled crime against the United States Government, a United States person, or United States interests, and that is not an institutional part of a foreign government or wholly operated under a foreign government’s direction.”
The U.S. Federal Communications Commission (FCC) “Covered List,” originally published in 2021, identifies communications equipment and services that it says pose a threat to national security. On 28 July, the FCC added mobile, communicating robots weighing more than 2 kilograms and power inverters commonly used in solar panels to the list, meaning that new products from any foreign country in these categories are no longer eligible for import.
The move is a Department of Defense–driven expansion of scattered federal efforts to further limit U.S. exposure to potentially sensitive Chinese technology, but it may impose major changes on the robotics industry in allied countries, too.
All foreign-produced advanced robotic devices pose an unacceptable risk to the national security of the United States and to the safety and security of U.S. persons…unless the [Department of Defense determines that] a given foreign-produced advanced robotic device, or a class of such devices, does not pose such risks.
There are two important definitions here. The first is what an “advanced robotic device” is, and the second is what “unacceptable risk” means. Drones already went through their own round of this sort of regulation, so they’re exempt from this particular restriction, as are connected vehicles and medical devices. As far as the FCC is concerned, “advanced robotic devices” are mobile systems that incorporate on-board sensing and communications and have some amount of autonomy. There are a couple of loopholes, including systems weighing under 2 kilograms and any system that communicates at less than 200 kilobits per second, which opens up some creative possibilities. It’s important to note that this applies to new devices; those already certified are not restricted for sale or use.
As to the risks, the U.S. government says that foreign advanced robotic devices represent “a cybersecurity risk that threatens the security of critical infrastructure and thus the safety and security of U.S. persons.” There seem to be two main points to the justification, found in Appendix C. The first is that mobile robots are important to both the economy and the military, so the United States needs its own supply chain and industrial base rather than relying on foreign manufacturers. And second, mobile robots monitor critical infrastructure in sensitive locations, making them a security risk.
The Country That Must Not Be Named
As part of its justification for why foreign robots are a security risk, the DOD cites IEEE Spectrum’s article on a critical vulnerability in robots from Unitree, based in Hangzhou, China, along with several other news articles and reports about Chinese robotics. And despite the FCC swearing up and down that this action is “country neutral” and “not targeted at any country or countries,” U.S. national security sources told Spectrum that the perceived threat is obviously China. That’s how China feels about it, too, per a Chinese Ministry of Commerce 29 July press conference (translation of the first quote here):
On the surface, the FCC’s measures fly the banner of “non-discrimination,” but in substance they discriminate against and suppress Chinese enterprises and products…
China firmly opposes the U.S. overstretching the concept of national security and going after Chinese companies. Protectionism does not make the U.S. more competitive and will only hurt the interests of U.S. companies and consumers. China will continue to do what is necessary to firmly defend the legitimate and lawful rights and interests of Chinese companies.
It’s unclear what China is going to do about this—but how about the rest of the world? How can foreign companies that make advanced robotic devices get them cleared for FCC authorization? Among many, many other things, you’ll need to provide “a detailed, time-bound plan to establish or expand manufacturing in the United States for the advanced robotic device.”
Because China also produces a large fraction of robot components, even for robots assembled in the United States, it will have strong leverage in any related negotiations until U.S. robotics companies further diversify their supply chains.
Applicants must also submit their applications to the DOD and FCC by 1 January 2028, which is unfortunate for anyone who wants to develop an advanced robotic device after that point.
Robotics Industry Reactions
This is all very new, and reactions from the robotics community have been mixed.
Some American robotics companies may benefit in the local market from the newfound lack of competition in the commercial market. Brendan Schulman,Boston Dynamics’ vice president of policy, wrote an enthusiastic endorsement of the ban on LinkedIn: “I sense that this is just the first round in a series of policies that will define the success and growth of the industry for decades to come.” On the other hand, third-country buyers may just stick to Chinese products, as they generally have for drones and electric cars.
But not all companies expect major changes from the new regulation. American customers “need to know they can audit the technology, get support quickly, and keep the system operating without depending on a fragile overseas supply chain,” Nic Radford, the CEO of the U.S. humanoid robotics company Persona, tells IEEE Spectrum. In other words, he figures some customers wouldn’t have wanted Chinese humanoids anyway.
Philipp Frey, vice president of strategy for the Swiss quadruped company ANYbotics, agrees. He says their enterprise customers in the United States “increasingly evaluate robots on long-term reliability, cybersecurity, software capability, safety certification, serviceability, and ecosystem integration, not on hardware cost alone.”
ANYbotics also plans to apply for conditional approval of future products, Frey says. That will involve a national-security review by the DOD or the Department of Homeland Security, disclosing company beneficial ownership, supply-chain risks, and declaring a plan for establishing a significant manufacturing presence in the United States.
Gavin Kenneally, CEO of the U.S. quadruped company Ghost Robotics, is more explicit about the risks that Chinese robot strategy poses to the United States. “Active and purposeful spyware is deployed inside the U.S. on Chinese robots. Examples of predatory pricing abound. And this isn’t just a competition between U.S. and Chinese robotics companies; it’s between private U.S. companies and China’s coordinated national strategy,” Kenneally tells Spectrum. “If today’s announcement encourages stronger cybersecurity and a more level competitive environment, that’s good for customers and good for the robotics industry.”
So is an industry-wide ban the best way to guard against threats? American approaches to Chinese technology security risks have been “ad hoc and fragmented,” wrote the Brookings Institution sociologist Kyle Chan in a report published 9 July. Chan called for the Bureau of Industry and Security, part of the Department of Commerce, to centralize federal information gathering and decision-making on how to handle risky foreign devices. He also called for better public input mechanisms for these issues, and a continuous, proportionate process that tightened or relaxed targeted import restrictions in response to well-defined risks.
That would allow American industry to continue benefiting from partnerships with Chinese manufacturers in less sensitive links of the supply chain, Chan argues. Those links will evolve over time, requiring continued assessment, but without those partnerships, crude bans “could make it more difficult for American startups and researchers to develop new software and end up slowing innovation across the U.S. robotics ecosystem,” he writes.
China has threatened to retaliate against new US restrictions on foreign-produced humanoid robots, warning that the measures will damage economic and trade relations between the world’s two largest economies. The response comes after the US Federal Communications Commission (FCC) added foreign-produced advanced robotic devices, including humanoids and quadrupeds, to its Covered List, preventing new models […]
“It’s not an argument with two sides, it’s an argument with 10 sides,” one senior administration official tells WIRED about how US AI policy is being shaped.
As access to Anthropic’s and OpenAI’s frontier models becomes more restricted, Chinese labs are pitching their open-source alternatives as stable, accessible, and increasingly capable.
Last week, thousands of SamKnows routers were bricked after a government program ran its course.
In 2020, as part of a program conducted by the Australian Competition & Consumer Commission (ACCC), the Australian government's chief competition regulator, thousands of volunteers received routers to help test and report on the typical speed and performance of broadband plans in Australia. (More specifically, the Measuring Broadband Australia (MBA) program targeted fixed-line broadband services provided over the NBN, Australia's government-owned wholesale open-access broadband network, as well as services delivered over other access networks.)
According to the final report that the ACCC distributed, the routers are whiteboxes that were “supplied by SamKnows” and that “perform tests to measure internet performance using test servers maintained by SamKnows and hosted in Australia.”
International authorities and a raft of private technology companies say they have disrupted a cybercrime “assembly line” that allowed crooks to collect millions of login credentials and steal more than $47 million in ransom payments and by other fraudulent means.
The crux of the operation was the simultaneous targeting of two unrelated tools that are widely used in various online scams. The first is Amadey, a malware-as-a-service platform for compromising devices and delivering malicious payloads for ransomware and other scams. Amadey has been observed in the wild since at least 2018 and was seen last year abusing GitHub as it collected system information from infected devices and installed customized payloads. The second tool was StealC, an infostealer-as-a-service platform that collects credentials, authentication cookies, cryptocurrency wallets, browser extensions, and files whose names match customer-defined patterns.
Severing a critical link in the cybercrime chain
Amadey and StealC are separate tools that are run independently of each other. Given their widespread use, however, many customers use both in their individual cybercrime activities. The tools also, it turns out, relied on some of the same underlying infrastructure to run. Microsoft said it made this determination after analyzing the tools using AI. This insight allowed Microsoft attorneys to seek an order disrupting both at the same time.
The White House is drastically shortening the deadline for government agencies and organizations to adopt new quantum-resistant encryption systems that will withstand attacks that use quantum computers, as the federal government seeks to protect decades’ worth of secrets belonging to militaries, banks, governments, and most individuals on Earth.
The executive order, titled Securing the Nation against Advanced Cryptographic Attacks, requires computing systems for “high-value assets” and “high-impact systems” to transition to post-quantum cryptographic key establishment schemes by December 31, 2030, and to quantum-safe digital signature schemes by December 31, 2031.
Heading off a significant threat
The new deadline, which for many organizations is about five years sooner than the previous one, comes on the heels of recent research showing that the resources and cost for building a cryptographically relevant quantum computer are far less than previous consensus estimates. In response, Google, Cloudflare, and other companies recently tightened their timelines for moving off vulnerable systems to 2029.
Certain U.S. firms, such as Ghost Robotics, may benefit, because they are among the few companies that can handle demand for ground robots from U.S. government buyers. Ground robots are finished products at the top of the chain of added value, unlike semiconductors, which are “lower” down the value chain since they are always components of other products. If the proposed ground robot ban were to move lower down the value chain, preventing American robot makers from buying Chinese-made components, those companies might have a harder time fulfilling U.S. demand. The U.S. robotics industry is in a pickle: Companies would benefit from eliminating Chinese competitors at their level of the value chain, so long as they can retain their Chinese suppliers.
The U.S. does not have a serious, overarching strategy to guiding its approach to the U.S.-China techno-economic competition.” —Stephen Ezell, Information Technology & Innovation Foundation
It’s still early for the ground robotics industry in the U.S. Adoption is not yet that high, nor are the supply chains mature yet. South Korea and Japan make many crucial robot components, for example, so if they or other countries the U.S. considers friendly can replace Chinese components the U.S. government declares unsafe, the U.S. robotics industry may be able to adapt and build its competitiveness.
For other technologies, it’s Chinese tech all the way down the chain. The UAS market, for example, is dominated by Chinese producers. The U.S. Department of Commerce has sought to ban them for more than a year, and in December, the FCC added UAS’s to its import ban list, called the Covered List.
“That was a problem with the drone ban,” Chan says. “Rather than thinking about how you would ramp up domestic production and then have this tapering off of dependence on Chinese drones, it was a sharp and fast switch, which left industry in the lurch.”
Many Supply Chains Already Extend Beyond China
The FCC’s March ban on new foreign-made routers was a surprise to that industry. In 2025, the U.S. imported nearly US $ 31 billion of routers, according to the Global Electronics Association. Yet China produced only 1.1 percent of that, by value, down from around 20.5 percent of the U.S. market share in 2019. In 2025, the top three sources of routers in the U.S. by value were Vietnam, Mexico, and Thailand, together accounting for 68.4 percent of the market.
“A lot of this is more nuanced than the regulatory approaches suggest. The real vulnerabilities are outdated software, patches that haven’t been installed, unchanged default passwords,” says Global Electronics Association economist Shawn DuBravac, one of the authors of the association’s report.
On 14 April, the FCC issued conditional approvals for U.S. distribution of certain Netgear and Adtran routers, along with Sees.ai UAS’s. U.S.-headquartered Netgear manufactures routers in Vietnam and Taiwan, according to Consumer Reports. DuBravac says the fact that the FCC took only about three weeks to exempt those imports is positive, but that since the exemptions last only 18 months, manufacturers must still contend with a lot of uncertainty.
“If you’re a company you’re going to have to have clear visibility into your suppliers and into your suppliers’ suppliers,” DuBravac says. “There’s much, much more scrutiny.”
The last several U.S. administrations have restricted a growing list of Chinese tech, across both political parties. “I see this as bipartisan,” Chan says, “and I would expect continued scrutiny.”
Companies building technology subject to security controls should also prepare for speed. A White House interagency task force determined that foreign routers were a security risk, leading to the FCC’s Public Safety and Homeland Security Bureau announcing first the UAS ban and later the router ban. Because UAS’s use radio to communicate, they are subject to FCC oversight. Both security-related determinations, unlike conventional FCC rule making, did not require public notice or a commenting period.
“There hasn’t been much of a back and forth process into [the UAS] rule,” Chan says.
The electronics industry is also accustomed to more dialogue with trade-related changes, DuBravac says. “When you see a problem, you open an investigation and stakeholders can submit input into that investigation so it feels a little more like a two-way conversation, so you’re actually hearing from industry on this.” So far, that has not happened.
Instead, even analysts that welcome U.S. security scrutiny of Chinese technology are finding the fits and starts of the associated policymaking jarring, says Stephen Ezell of the Information Technology and Innovation Foundation, a think tank in Washington, D.C.: “The U.S. does not have a serious, overarching strategy guiding its approach to the U.S.-China techno-economic competition.”