On 28 July 2026, the U.S. Federal Communications Commission added foreign-produced advanced robotic devices (humanoids, quadrupeds, and other mobile robots) to its Covered List under the Secure and Trusted Communications Networks Act. The action followed a National Security Determination by a White House-convened interagency body, which found that the networked capabilities of advanced robotic systems create vectors for attacks that can manipulate both the data and the physical operation of the machine. New models are now ineligible for the FCC equipment authorization required to import, market, or sell in the United States unless the Department of War grants a Conditional Approval.
The Intercognitive Foundation acknowledges the stated concern. A robot is not a phone. It has actuators. It occupies space alongside people. When a fleet of networked machines can be remotely commanded, the security of the control path is a legitimate public safety question, not a trade irritant. Anyone who has worked on remote actuation knows how thin the line is between a stale credential and a moving mass.
Our concern is not that the United States is asking the question. It is that the instrument chosen reveals how little we can currently answer it.
THE BAN IS A DIAGNOSIS
Category-wide exclusion is what a regulator reaches for when individual assessment is not possible. Today, it isn't. There is no common way for a robot to declare what it exposes, what may be commanded through it, under whose authority, for how long, or what actually happened afterward. ROS gives the ecosystem shared message patterns and tooling, but it does not give every robot a uniform control contract. Two machines can both "support ROS" while exposing entirely different control surfaces, timing assumptions, arbitration rules, and safety behavior.
That leaves a regulator with no evidence on which to make a device-level judgment, and little choice but to judge the category as a whole. The Determination's own reasoning proves the point: it describes a class-wide vulnerability precisely because the class offers nothing more specific to evaluate.
This is a standards gap presenting as a trade dispute.
THREE STRUCTURAL PROBLEMS
1. The measure is nationality-neutral in text but not in effect.
The Covered List entry reads "produced in a foreign country, regardless of the nationality of the producer." As written, it reaches allied manufacturers, joint ventures, and offshore production by U.S. firms. If the risk is adversary control of a machine, country of assembly is a poor proxy for it. It's a poor proxy in both directions, catching partners while missing threats that route through software, updates, and cloud dependencies rather than through a bill of lading.
2. The burden of proof runs the wrong way, against no published standard.
Conditional Approval is the right idea. But exclusion is the default, the applicant bears the burden, and no technical criteria, evidentiary standard, or decision timeline has been published. A discretionary licensing regime without criteria is not a security control. It's an invitation to litigate, lobby, and wait.
Vendors cannot engineer toward a standard that does not exist.
3. Interdependence cuts both ways.
The U.S. robotics industry is not insulated from this. In June, Nvidia unveiled a humanoid reference design built on a Chinese chassis (@UnitreeRobotics) with Singaporean hands (@SharpaRobotics).
American developers depend on foreign actuators, reducers, sensors, and platforms, and the fastest route to a competitive domestic industry runs through access to the best available hardware (vetted, instrumented, and understood), not around it.
WHAT WE SUPPORT
We support vetting suppliers, excluding bad actors, and defending genuine national security interests. We do not believe those aims require categorical exclusion, and we hold that they are better served by making machines legible than by making them absent.
Concretely, a robot should be able to declare, in machine-readable form:
• Which capabilities it exposes.
• Which of those accept commands.
• The frame, units, and valid range of each command surface.
• Whether a live authenticated session and current epoch are required.
• The arbitration model for that capability—shared, leased, or exclusive.
• Command expiry and deadman timeouts.
• Where the outcome of a command can be observed and reconciled against independently measured state.
Access should be layered rather than binary:
• A durable grant establishing who may ask.
• A live session establishing who is presently recognized.
• A short-lived capability lease establishing who may act right now.
Locomotion and manipulation should be exclusive and time-bounded. Local safety systems must always retain final authority. No remote grant should clear an E-stop or exceed a locally enforced operating envelope.
Declarations are claims, not proofs.
They do not establish that a machine is safe, calibrated, or honest. But without them there is not even a claim to evaluate. And evaluation is exactly what a Conditional Approval process requires.
Work in this direction already exists. VDA 5050 standardizes fleet-to-robot communication, the MassRobotics AMR Interoperability Standard addresses coexistence and shared status, and OPC UA Robotics defines industrial information models. None of them yet specifies a control and authority contract of the kind an equipment authorization regime would need.
OUR COMMITMENT
The Intercognitive Foundation will publish open declaration and control profiles for advanced robotic devices, developed with our founding members and open to any manufacturer, regulator, or research institution. We invite governments and standards bodies to treat these profiles as candidate evaluation criteria, and to tell us what we have missed.
Openness is not a request for leniency. A machine that can prove what it will and will not do is a stronger security posture than a border.
Build the standard, and vetting becomes possible.
Without it, exclusion is the only tool anyone has.

