A procurement ban is not a security control, and the space between the two is where the risk now sits. In late July 2026, the Federal Communications Commission added two device classes to its Covered List: networked power inverters and advanced mobile robots. New foreign-produced models in those categories lose the authorization they need to be imported or sold in the United States. That is a lever aimed at what gets bought next year. It does nothing for the inverters and robots already wired into networks today, and those are the ones a defender has to answer for.
The distinction matters because the FCC was explicit about it. Devices that already hold an authorization are not pulled from service, and they keep receiving firmware and security updates through January 1, 2029, per the order. So this is a forward-looking market signal, not a recall. The installed base stays exactly where it is: on your network, doing its job, reachable by whatever remote plane the vendor built into it.
What the FCC flagged, and why it fits our beat
Two categories, both defined broadly. A networked power inverter is any system that converts between direct and alternating current and carries components for remote communication, control, sensing, or monitoring. An advanced mobile robot is a machine that moves on its own, carries sensors, talks over a wireless link, and runs software to steer itself. The common thread is not the physical form. It is that each one is a sensor package bolted to a remote command channel.
The evidence the agency cited reads like a threat model. It pointed to research that pulled video from onboard cameras, audio from microphones, and maps of building interiors off household robots. Reporting on the decision tied documented Bluetooth flaws, tracked as CVE-2025-35027, to root-level command execution on several commercial robot models. For inverters, the concern is blunter: remote access that can switch a unit off, drain data from it, or be aimed at grid stability at scale. None of that needs a novel exploit. It needs a device that answers to someone outside your walls.
| Device class added | Remote capability the FCC cited | What it means on your network |
|---|---|---|
| Networked power inverters | Remote shutdown, data collection, and monitoring of DC/AC conversion; access that could affect grid stability | A power-conversion unit with an outward-facing control plane, often tied to a vendor cloud, sitting in facilities infrastructure |
| Advanced mobile robots | Access to camera and microphone feeds and interior maps; documented Bluetooth flaws (CVE-2025-35027) enabling root command execution on some models | A mobile sensor that maps your site and answers to an external command channel, usually filed under operations, not IT |
The Covered List keeps describing the same shape
Step back and the pattern is consistent. The list has named telecommunications gear from Huawei and ZTE, then video-surveillance equipment from Hikvision and Dahua, and now robots and inverters. In each case the FCC's rationale points to the same recurring property: a networked device with a vendor-controlled remote plane the operator cannot fully audit. Each addition is the regulator catching up to a class of hardware that was already deployed and, once reachable, one weak credential away from being conscripted into a botnet.
That lag is the part worth internalizing, and it is not new. We saw the same beat with export controls: policy trails the technical reality by design. By the time a device category lands on the Covered List, the security decision has already reached you, because the risky units are the ones you bought before anyone flagged them. Many also run embedded firmware that ships with known flaws and no clear patch path. The ban shapes next year's procurement. It leaves this year's exposure to whoever owns the asset. For most organizations that is not the security team, which is the problem.
Treat them as untrusted endpoints, starting with the inventory
The first action is boring and it is the one almost nobody has done: put every networked inverter and robot on the asset inventory as a remote-controllable endpoint. These devices hide in plain sight because they are filed under the wrong department. A rooftop solar inverter is "facilities." A warehouse picking robot is "operations." A cleaning robot is a line item on a maintenance contract. None of them show up on the list the security team actually watches, so nobody is monitoring the network link they all carry.
Once they are on the inventory, the rest follows the logic you apply to any device you do not control. Put them on a segment of their own, with no lateral path to systems that matter, so a compromised inverter or robot cannot become a foothold. Watch their outbound traffic and treat the vendor cloud connection as an untrusted channel: baseline where each device normally talks, then alert when it reaches a destination it has never used. That egress and lateral-movement monitoring is the layer that tells you something changed before the vendor's next advisory does, and it is exactly what a managed detection service is built to run.
Patching still applies. The 2029 update window is real, and firmware fixes should be taken as they ship. But a patch closes a specific hole; it does not remove the architectural fact that these devices carry a remote command plane by design. You manage that with segmentation and monitoring, not with a version bump. The FCC has made the buying decision easier for the next cycle. The one in front of you, the fleet already running inside the perimeter, is still yours to secure.