The ‘Covered List’: A Fraud Claimed ‘National Security’
A tool built to block Huawei and Hikvision now bans drones, routers, and solar inverters—undermining the security it was meant to protect.
In 2021, President Biden signed the Secure Equipment Act. This act created the Federal Communications Commission’s (FCC’s) covered list, a list of equipment that the FCC would no longer approve (and therefore effectively ban) based on an effectively unchallengeable assertion that the device would “pose an unacceptable risk to the national security of the United States or the security and safety of United States persons.”
The covered list was both a well-conceived and well-implemented system under the Biden administration, identifying and mitigating significant security risks from Chinese telecommunications and network-connected cameras and, later, Russian connected antivirus software. But it also relied on a significant amount of deference to the administration in making decisions that actually enhance our national security.
This broad discretion, especially in light of how Slaughter has weakened the idea of a rulemaking agency insulated from political direction, has created one of the most destructive tools in the Trump administration’s campaign against the existing global trade order: banning effectively all foreign network equipment, drones, solar inverters, and even robot vacuums. Each of these bans is questionable, but the solar-inverter ban is the most troubling: It works against one of the U.S.’s more promising long-term responses to the Iranian threat.
This is a significant piece of a larger pattern of economic self-injury, and one with direct implications for national security. And if Congress wishes to fix the problem, it needs to eliminate the notion of deference, providing a mechanism where those affected can require the executive to prove in court that there is a security risk.
The covered list wasn’t created in a vacuum. It was passed by Congress in response to real concerns about Huawei and ZTE telecommunications equipment finding its way into U.S. networks. Indeed, in 2019 I was strongly in favor of prohibitions on Huawei 5G equipment based on my risk analysis published in Lawfare. Telecommunications devices and most cloud services are designed to enable wiretapping, and allowing wiretapping equipment provided by a potentially hostile party is a significant vulnerability. Or, as I colloquially put it, bans are appropriate where “Blind-Carbon-Copy the Chinese Communist Party” (BCC-the-CCP)—is not an acceptable feature.
The FCC will simply not authorize any new device on the covered list under the normal FCC product registration process. Since one can’t sell devices without FCC authorization, this acts as a complete ban on new products. Existing designs may still be sold, but the FCC considers even software updates as design changes—so a device that remains on the market cannot be patched or improved.
The initial covered list involved just five companies: Huawei, ZTE, Hytera, Hikvision, and Dahua—all Chinese telecommunications and network-connected camera companies. And although the telecommunications bans were absolute, the camera restrictions were limited to those “used for the purpose of public safety, security of government facilities, physical security surveillance of critical infrastructure, and other national security purposes, including telecommunications or video surveillance services.”
Due to the nature and sensitivity of networks or of connected cameras, this was a reasonable list of equipment vendors and there was an honest national security justification. The only additions during the Biden administration were Kaspersky antivirus and telecommunications services from China Mobile, China Telecom, and Pacific Networks.
This is how the covered list was supposed to work. The FCC would identify and articulate particular threats, involving particular companies and geopolitical risks involving the companies’ headquarters, and only then add a company to the list. Independent experts could nod along and agree.
Then the administration changed. Give the Trump administration a tool where they can claim “national security” and they will run roughshod.
The first target, released on Dec. 21, 2025, targeted drones. Rather than just targeting specific companies (such as DJI or Autel) or even specific countries, it imposed a blanket ban on drones or critical components (including batteries, flight controllers, and remote controls) from all other countries. The terms have changed slightly since (notably exempting “toy drones” and allowing a temporary reprieve for foreign components already explicitly approved by the Department of Defense).
Additionally, the December ban includes specific bans against DJI and Autel, two major Chinese manufacturers, although it does this not by actually making a determination that the two manufacturers are general threats (rather than targeted threats like Hikvision cameras), but by simply taking the default inaction option that covers those companies and that was added in the 2025 National Defense Authorization Act’s (NDAA’s) Section 1709(a)1.
The next target, on March 13, 2026, was routers (including home WiFi routers), again with no regard to the country of origin or even country of design: It applies the same set of rules to U.S.-designed components, with U.S. software, that are simply manufactured outside the United States.
And most recently, on July 28, similar blanket bans were added for both foreign power inverters and “advanced robotic devices.” The former is the key component in a solar system that allows the solar panel to connect to the larger power grid while the latter definition of “advanced robotics” includes almost any mobile robot weighing more than 4.4 pounds, a threshold that even picks up most robotic vacuums.
Of course, friends of the administration are not affected because they can apply to either the Department of Defense or the Department of Homeland Security (depending on the product) for an exemption. So SpaceX, for example, which builds its satellite receivers in Vietnam, is free to continue to do so. Apparently it is not a national security issue for Elon Musk to make his routers overseas.
A common premise runs through these bans: that trade is largely zero-sum. The security argument for them turns on whether a domestic-only supply chain for these devices would meaningfully reduce risk, or whether it mainly shifts costs onto the U.S. economy. Indeed these restrictions apply equally to devices made in China and in allied countries such as Canada. The unfortunate reality is that these bans reduce, not enhance, U.S. national security.
Take both the drone and inverter bans. Restricting the drone market to overpriced U.S. products (for example, a NDAA-compliant radio controller is $300 compared with a similarly capable—albeit different protocol—Chinese-made controller for $90) damages both the talent supply chain necessary for the military and leaves the U.S. bereft of tools available to the rest of the world.
For example, if the U.S. military wants recruits already familiar with first-person view drones, it needs a civilian population that can buy the latest (Chinese-made) drones at Costco—that is how you get service members who understand the technology before they enlist. And for the vast majority of drone flights, the data exposure is trivial: The CCP is welcome to watch me inspect my roof for fallen leaves with my DJI mini; in this case, BCC-the-CCP is an acceptable (and for me indeed explicitly articulated) feature I tolerate in return for a quality drone that costs far less.
The uses where exposure genuinely matters are already covered by existing bans on Chinese-made drones such as the 2020 NDAA’s Section 848, which restricted the Defense Department from using drones or drone components from China or other covered countries. And if those bans were insufficient, the FCC already showed, with Hikvision, that they can use the covered list to ban uses only in a public safety or other sensitive context.
Indeed the FCC’s ban on drones and drone components is so severe that, once a temporary exemption expires in 2028, foreign components explicitly approved by the Defense Department for U.S. military use are nevertheless considered a “security vulnerability” by the FCC.
Of even greater security concern is the new ban on all foreign-made solar inverters. A solar inverter is the component that allows a solar panel to integrate with the power grid in the home or in a power utility. Restricting installations to use only U.S.-made inverters will effectively prevent the installation of more solar panels because the U.S. manufacturing base for these critical devices is small compared to the rest of the world.
The economics of switching to solar are favorable even in ordinary times—solar-plus-battery storage is already more cost-effective than natural gas—and the Iranian war makes it even more critical. For all the administration’s months of bluster, threats, and claims of ceasefires, the reality is NACHO: Not a Chance Hormuz Opens.
The only reason oil prices remain remotely stable (for now) is that the U.S. and Chinese strategic petroleum reserves are being rapidly depleted in the hope the situation somehow resolves itself. The U.S. Strategic Petroleum Reserve is draining at roughly 10 million barrels a week with absolute zero a little more than six months away. And nobody outside the Chinese government knows the true state of China’s reserves or the rate at which they are depleting (or even if they’ve switched to stockpiling).
The viable long-term strategy to defeat Iran is not through bluster or bombing campaigns, but by removing the U.S. and the world’s dependence on oil through the mass deployment of solar, wind, batteries, and battery-electric vehicles. Eliminating a substantial amount of the demand for crude oil would render Iran and the entire strait economically inconsequential, eliminating Iran’s ability to finance itself.
Read that way, a policy that limits U.S. solar capacity works directly against U.S. national security. Limiting solar deployments (and, relatedly, spending $4 billion of taxpayer money to terminate the development of previously approved offshore wind farms) is, at best, reckless.
Congress should address this, along with many other statutes that defer to the “judgment” of the executive branch. Simple deference is more difficult to justify now that Slaughter has narrowed Congress’s ability to create credibly independent agencies such as the FCC. Any law granting such deference should instead require that, when challenged, the executive be able to demonstrate in open court probable cause to justify its decision.
The United States needs a legal escape valve—one that lets those affected by executive decisions challenge the substance of the rationale in court, not merely its compliance with the Administrative Procedures Act. The FCC complied with the letter of the law: It created statements alleging a national security case for these decisions. But these statements don’t hold up well under independent scrutiny and judgment.
It is time for Congress to narrow executive deference considerably. The executive must be able to make these decisions, but Congress should ensure the reasoning behind them can be tested in court. Otherwise, invocations of national security and executive deference will keep putting U.S. long-term security at risk.
