On July 28, the Federal Communications Commission added foreign-produced advanced robotic devices to its Covered List after national security agencies warned that networked robots could support surveillance, foreign intelligence collection, or remote manipulation. On Aug. 6, FCC Chairman Brendan Carr defended the broader campaign against Chinese technology as a way to reduce security risks before millions of vulnerable devices become embedded in American life.
The direction is sensible, but Washington is still using the wrong unit of analysis.
Recommended Stories
Washington has spent years confronting connected technology by category. Commerce has restricted connected-vehicle hardware and software tied to China and Russia. The FCC has moved against foreign-made drones, routers, robots, and connected power inverters. Each action addresses a real exposure. Intelligence collection can cross all of those product boundaries.
The latest FCC action mainly blocks new equipment authorizations. Previously approved devices remain in homes, businesses, and networks. That makes the harder question immediate: What intelligence value is created by the devices already surrounding sensitive people and places?
A connected vehicle can reveal movement around a military base or government office. A domestic robot can map a home and generate cloud telemetry about activity inside it. A smart television can record detailed viewing behavior. The Federal Trade Commission’s Vizio case showed that internet-connected televisions could collect second-by-second viewing information and associate it with household demographic data.
The counterintelligence risk grows when those streams describe the same person or place.
Consider a cleared defense employee. A vehicle contributes location and movement. A robot contributes interior spatial information and household routines. A television contributes information-consumption patterns. Cameras, wearables, routers, and other connected devices add more observations. None has to contain a classified document to create intelligence value. Persistent correlation can expose routines, relationships, absences, interests, and physical layouts that become useful for targeting, recruitment, social engineering, or surveillance.
The risk does not depend on every Chinese-made device being malicious. Ordinary cloud telemetry, insecure backend services, software updates, or access to vendor-controlled systems can each create exposure. Counterintelligence should assess the aggregate sensor field rather than wait for one mechanism to become the headline.
The Trump administration is right to make supply chain security a national security priority. President Donald Trump’s July order on defense supply chains calls for deeper mapping of critical dependencies and protection against physical, cyber, and economic subversion. The same discipline should extend to the commercial sensor environment surrounding cleared personnel and sensitive facilities.
Current policy still tends to ask whether a particular product, manufacturer, or component is safe enough to permit. Counterintelligence should also ask what the total sensor field can reveal after ordinary telemetry is combined across products. Device security, supply chain review, personnel security, and facility protection often live in different bureaucratic lanes. The accumulated exposure can fall between them.
That requires an aggregation-aware review for high-risk populations and locations. Security offices should map concentrations of connected sensors around sensitive facilities and personnel, identify where their data is processed, and reassess the exposure when ownership, firmware, cloud routing, or software-development kits change. Where mission conditions justify it, agencies should favor local processing, data minimization, and devices that remain useful when external cloud services are removed.
RUSSIA DOESN’T NEED PROPAGANDA. IT JUST NEEDS A DEEPFAKE OF YOUR PASTOR
The National Institute of Standards and Technology already treats IoT security as a lifecycle and system-risk problem, with attention to device data protection, software updates, configuration, and ongoing support. Counterintelligence policy should add one more question: What can an adversary learn from the collection of devices even when each device is behaving as designed?
The FCC’s robot decision is a useful step. Washington now needs to move faster than the product cycle. Chinese surveillance exposure can emerge quietly from the sensor field Americans assemble for themselves, one convenient device at a time.
Burak Oktenli is an independent researcher based in Washington, D.C. He holds a bachelor’s degree in computer science and engineering from the University of South Florida and an MBA, and is completing a master of professional studies in applied intelligence at Georgetown University.
