On Tuesday the FCC stopped granting equipment authorization to new foreign-made humanoid and quadruped robots. National security, critical infrastructure, cybersecurity risk. China holds something like 85% of the global humanoid market, so nobody had to squint at who the order was about. Beijing called it protectionism within a day.
That got the headlines, and I understand why. Robot dogs photograph well.
The same action also stopped authorization for new foreign-produced power inverters, the kind used in solar and battery storage. Effective immediately.
I work in small commercial buildings. Sump pumps, air handlers, walk-in coolers, the machinery whose failure ruins somebody's week. Here is the entire relevance of Tuesday's order to that world, sorted honestly:
| Device class | How many are in the buildings I work in |
|---|---|
| Humanoid robots | Zero |
| Quadruped robots | Zero |
| Power inverters | Some, and they're already on the wall |
The half of the order nobody wrote about is the only half that touches an actual building.
Grandfathering is the entire story
If you own a building with solar or storage in it, the useful thing to understand about Tuesday is what the order does not do.
It does not make anything you own illegal. Devices already purchased are unaffected. Models that already carry FCC equipment authorization are unaffected. Older inverter models can still be imported. Federal purchase and use is exempt, systems conditionally approved by the Department of War or DHS are exempt, and there is a waiver path for pushing software updates to foreign-supplied equipment.
What changed is the path to the next one. New models now need conditional approval before they can enter the market.
Nothing in your building broke on Tuesday. What got narrower is what you're allowed to replace it with in 2029.
That reframes this from a security story into a procurement story, which is much less dramatic and much more likely to actually cost somebody money. If a client's inverter dies four years from now, the question won't be whether it was legal. It was, and it stays legal. The question will be whether the equivalent model still holds authorization, how long the approval queue is, and what the domestic option costs by then.
That's not a reason to do anything today. It is a reason to know what you have, which most building owners don't, and which takes about twenty minutes to find out.
The part of the record that complicates the story
I want to be even-handed here, because the security concern is not manufactured and the counterevidence is not nothing.
On the security side: researchers found a backdoor in Unitree robots, and found models transmitting data to Chinese servers without their owners' knowledge. That was raised in the industry reaction to this order by Robert Little, formerly a robotics strategist at Novanta, and it is a real finding about real shipped hardware. Standard Bots CEO Evan Beard called the FCC action one of the strongest technology-security moves in modern U.S. history. People who build robots for a living are not uniformly against this.
On the other side, three things are also in the record.
A Department of Energy investigation six months ago sampled Chinese-manufactured inverters and found no malicious software in them. That is worth stating plainly rather than skipping past. The inverter half of this order rests on a thinner evidentiary base than the robot half.
The scope may be wider than China. Henrik Christensen at UC San Diego pointed out that "foreign-made" and "Chinese-made" are not the same category, and that Canadian and European equipment could land inside the same line.
And the components are untouched. This is the one I keep coming back to. Georg Stieler made the point that the upstream dependency on Chinese actuators, magnets, and sensors is unaddressed by any of this. You can ban the finished robot and still find that every meaningful part inside its domestic replacement was made in the same place. The order regulates the assembly. It does not regulate the bill of materials.
Now the uncomfortable question about my own equipment
Here's where I should stop talking about other people's supply chains.
The monitoring I install runs on inexpensive, widely available parts. ESP32-class microcontrollers are made by Espressif, a Shanghai company. The capable non-NVIDIA edge processor that's become a standard part this year, the RK3588, is Rockchip, in Fuzhou. That is not a secret and it is not unusual. It is most of the sensor industry.
So let me be exact, because this is precisely the kind of thing that gets stated loosely to make a point.
Neither company is on the FCC's Covered List. Nothing in Tuesday's order touches either one. There is no restriction on any part in any system I've installed, and I'm not going to imply there is in order to sound prescient.
What I'll say instead is narrower and I think more useful: "not restricted" is a status, not a property. It describes this week. The honest position isn't to reassure a customer that the category is safe, because I can't know that. It's to build so that the answer doesn't matter much either way.
Three design choices that happen to answer this
None of these were made in anticipation of a regulatory action. All three came from reliability arguments I've been making for two years. They just turn out to be the same answers.
1. Read-only, not actuation
What makes a connected device a genuine security concern is that it can do something. Change a setpoint. Open a valve. Move a joint. Turn an inverter off, which is exactly the scenario the FCC described. A device that can only observe has a categorically smaller attack surface than a device that can act, and that difference is architectural. It survives a change in the paperwork, because it isn't a claim about a vendor's trustworthiness. It's a claim about what the thing is physically capable of.
My monitors watch. They are not on the control network, they don't command equipment, and the worst realistic outcome of one being compromised is that somebody learns how often a sump pump in Watertown cycles.
2. Detection stays in the building
The sensing, the baseline, the drift detection, and the decision to raise an alarm all happen on a small box on a shelf. There's an outbound path for notifications, and I've written before about being precise on that point: that path touches services I don't own, and if one of them triples its price, that's my cost to absorb rather than a surprise on my customer's invoice. But nothing about deciding that something is wrong requires a round trip to anybody's cloud, in any jurisdiction.
I didn't build it that way for geopolitical reasons. I built it that way because the storm that floods the basement is the same storm that takes the internet down, and a water alarm that needs a cloud connection is statistically most likely to be offline in exactly the hour it exists for.
3. Substitutable parts
This is the one I've never put on the website, and after this week I'm going to.
The software doesn't know what sensor it's talking to. It learns how one specific machine behaves from a physical signal, then watches for the drift that shows up before a failure. Swap the vibration sensor for a different manufacturer's and the baseline re-learns. Nothing in the system is keyed to a part number.
That's the actual hedge against supply-chain policy, and it's worth designing for on purpose. Not "my parts will never be restricted," which nobody can promise, but "if any part becomes unavailable for any reason, tariff, ban, shortage, or a vendor simply going out of business, the replacement is a purchase order and not a rebuild."
Two weeks, one pattern
Last week I wrote about Samsung starting to charge for SmartThings API access, and the small contractor who has to explain a new recurring fee on a job that was finished and paid for in June.
This week a regulator reclassified two device categories with no notice.
These are completely unrelated events with completely different causes, and I don't want to build a grand theory out of two data points. But they rhyme in a specific way that's worth naming: in both cases, an input to an already-installed system changed after the installation, for reasons entirely outside the installer's control and entirely invisible in the original proposal.
You can't forecast which input changes next. Nobody had "FCC bans inverters" on a July calendar. What you can do is reduce the number of inputs that can change on you, and make sure the ones that remain are swappable rather than structural.
That's the difference between a system you own and a system you're renting a piece of without quite realizing it.
If you have solar or storage, four questions
Nothing here is urgent. This is the twenty minutes I'd spend, in this order:
- What inverter model is actually installed, and when was it authorized? Write it down somewhere that isn't the installer's filing cabinet. Existing authorizations are unaffected, so this is inventory, not a fire drill.
- What's the expected service life, and what's the replacement? If the answer is more than five years out, this order is genuinely not your problem. If it's two, ask your installer now what they'd put in and whether that model is authorized.
- Does anything else in the building phone home to a platform you didn't choose? This is the Samsung question, and it's still the higher-probability one. Ask for an itemized list of every external service the system needs. Any competent installer can produce it in an hour.
- For anything monitoring your equipment: can it change equipment state, or only observe? If a vendor can't answer that clearly, that's the answer.
My systems are deliberately boring. Read-only, local detection, ordinary parts with ordinary substitutes, and a written list of everything they touch. That has never once impressed anybody in a sales meeting. What it means is that a headline about a device class getting reclassified is something I can read with interest rather than with a knot in my stomach, and that when a customer asks me what's inside the box, I don't have to go find out.
Monitoring with no part you can't replace.
One off-the-shelf sensor per critical asset and a small box on a shelf that learns how that specific machine behaves, then watches for the drift that shows up before a failure. Read-only, never on your control network. Detection runs in your building, so it keeps working when the internet doesn't. Every part has a substitute, and you get a written list of every external service it touches. Start with the one machine whose failure would ruin your week.
See how it worksSources: FCC restrictions on equipment authorization for new foreign-made humanoid and quadruped robots and new foreign-produced power inverters, announced by Chairman Brendan Carr on July 28, 2026, including immediate effect, the exemption of devices already purchased and models holding prior authorization, the continued importability of older inverter models, Department of War and DHS conditional-approval and federal-use exemptions, and the waiver path for software updates to foreign-supplied systems, via The Robot Report, The Washington Post, NBC News, Forbes, The Hill, The Washington Times, and Solar Power World (July 28–29, 2026). The estimated 85% Chinese share of the global humanoid robot market and Beijing's protectionism response via NBC News and the Baltimore Sun. Industry reaction including Evan Beard of Standard Bots, Robert Little formerly of Novanta on researcher findings of a backdoor in Unitree robots and undisclosed data transmission to Chinese servers, Henrik Christensen of UC San Diego on the scope extending beyond China to Canadian and European equipment, and Georg Stieler on unaddressed upstream dependencies in actuators, magnets, and sensors, via The Robot Report. The Department of Energy investigation finding no malicious software in sampled Chinese-manufactured inverters approximately six months prior, via Solar Power World. The FCC Covered List, maintained by the Public Safety and Homeland Security Bureau under Section 2 of the Secure Networks Act, names Huawei, ZTE, Hytera, Hikvision, Dahua, Kaspersky, China Mobile International USA, China Telecom (Americas), China Unicom (Americas), Pacific Networks Corp, and ComNet (USA); neither Espressif nor Rockchip appears on it. Via FCC supply chain materials, Nemko, and the Congressional Research Service (LSB10895). Samsung SmartThings API paid access beginning October 2026 via Hackaday (July 28, 2026). Field deployments at The Intersecto Watertown sump-pump site and Northampton 40-device building.