FCC restricts authorization of new foreign-produced robots and networked power inverters

On July 28, 2026, the Federal Communications Commission added foreign-produced mobile robots and networked power inverters to its Covered List. New models generally can no longer obtain the equipment authorization required for import, marketing or sale in the United States.
Why the restrictions matter
The measure targets supply-chain exposure in connected hardware that can collect environmental data, receive remote commands or affect energy infrastructure. It is preventive: the FCC did not identify an active exploitation campaign against deployed robots or inverters.
Previously authorized models may still be sold, while equipment already owned remains unaffected. Federal procurement and use are also outside this action. The restrictions are based on production and technical criteria rather than a list of brands or countries.
Technical scope and exceptions
Covered robots weigh more than 4.4 lb, include an environmental sensor, communicate at 200 kbps or faster and use local or remote software for movement, perception or control. Connected vehicles, aircraft, underwater systems, regulated medical devices and fixed industrial arms are excluded.
The FCC granted a waiver through at least January 1, 2029, for software and firmware changes that:
“patch vulnerabilities and facilitate compatibility with different operating systems.”
Manufacturers may seek Conditional Approval by January 1, 2028. The Department of War may approve robotic devices; it or the Department of Homeland Security may approve inverters.
The supporting record cites UniPwn flaws affecting Unitree Go2, B2, G1 and H1 devices, remote-control risk involving Go1 robots and CloudSail, and 46 inverter vulnerabilities reported by Forescout across Sungrow, SMA and Growatt products. Potential consequences include surveillance, data theft, fleet manipulation and grid instability.
Practical implications for buyers
Businesses planning robotics or distributed-energy deployments should verify US authorization before procurement, document product origin and assess remote-access controls. Contracts should also preserve access to security updates, clarify vendor support and provide alternatives if a future model becomes ineligible.

