
New US restrictions on foreign-produced connected robots extend beyond humanoid machines. They could also affect autonomous mobile robots and guided vehicles used in warehouses, factories and other IoT-enabled environments.
A robot does not need a human-shaped body to raise national-security concerns. It only needs to move, sense its surroundings, run software and connect to a network.
That is the reasoning behind the latest expansion of the US Federal Communications Commission’s Covered List. On July 28, 2026, the FCC added foreign-produced “advanced robotic devices” to the equipment categories considered an unacceptable risk to US national security or the safety of US persons.
The immediate consequence is regulatory. Newly covered models cannot obtain the FCC equipment authorisation generally required before radio-frequency devices can be imported, marketed or sold in the United States. Previously authorised products are not automatically removed from the market.
What makes the decision particularly relevant to the IoT industry is its scope. It is not limited to humanoid robots or military systems. It can apply to connected mobile machines used in logistics, manufacturing, inspection, cleaning and other commercial environments.
The Definition Extends Beyond Humanoids
The FCC defines an advanced robotic device as a mobile mechanical system—including autonomous mobile robots, humanoids and quadrupeds—that meets several conditions.
The machine must be capable of locomotion, obstacle avoidance, navigation or other movement on the ground. It must operate at a distance from its human supervisor in response to commands, sensor data or both. Its combined weight, including any dock or ground station, must exceed 4.4 pounds, or approximately two kilograms.
It must also contain:
- A sensor capable of perceiving its environment
- Wired or wireless network connectivity of at least 200 kilobits per second
- Software controlling navigation, perception, data collection or remote operation
The software can run locally or remotely and may include firmware, artificial intelligence and machine-learning model weights.
This definition reaches much further than the humanoid robots featured in many headlines. It can include an autonomous mobile robot transporting components through a factory, a quadruped inspecting industrial infrastructure or a connected cleaning machine.
The FCC has also clarified that automated guided vehicles may qualify, even when they follow predefined routes rather than navigating with the flexibility of an AMR. This brings a well-established category of warehouse and factory automation within the measure’s potential scope.
Fixed industrial robots, including articulated arms, delta robots, gantry systems and SCARA machines, are excluded because they are not mobile. The distinction is therefore not whether a robot is industrial or consumer-facing, but whether it combines mobility, environmental sensing, connectivity and autonomous or remote software control.
Connectivity Creates a Physical Attack Surface
An autonomous mobile robot can map a warehouse, identify the location of equipment and employees, communicate with a fleet-management platform and receive instructions from a remote service.
Its sensors may include cameras, microphones, lidar or depth sensors capable of collecting detailed information about the facility in which it operates. Compromising the data layer could expose commercially or strategically sensitive information.
Compromising the control layer creates a more direct risk.
A fleet of mobile robots can influence the movement of goods, access to production lines and the availability of warehouse capacity. An attacker able to redirect, disable or interfere with those machines could disrupt operations without necessarily compromising the facility’s core industrial-control system.
The national-security determination supporting the FCC action identifies risks including data exfiltration, surveillance, remote takeover and disruption of critical infrastructure. It argues that connected robots are inherently networked systems with attack surfaces extending beyond the physical machine.
These vulnerabilities are not unique to foreign-produced equipment. A domestically manufactured robot with weak access controls, insecure cloud APIs or a poorly protected update mechanism can present similar technical risks.
The FCC’s approach addresses the issue through production origin rather than individual cybersecurity assessments. The measure is therefore also an industrial and supply-chain policy—not simply a technical security standard.
Existing Robot Fleets Are Not Immediately Banned
The FCC decision does not require businesses to remove existing foreign-produced robots.
Previously authorised models can generally continue to be sold and operated. The FCC has also issued a temporary waiver allowing certain security, software and firmware updates for authorised equipment until January 1, 2029.
This reduces the immediate disruption for deployed fleets, but it creates uncertainty around future product generations and upgrades.
Robotics platforms increasingly evolve through software. Navigation algorithms, AI models and fleet-management functions can change significantly while the underlying machine remains the same. Manufacturers will need to determine when a modification remains covered by an existing authorisation and when it effectively creates a new model.
Hardware changes could be more consequential. Replacing a wireless module, processor or another logic-bearing component may require a fresh authorisation, potentially bringing an established product line within the restriction.
For operators, grandfathering therefore reduces short-term risk without guaranteeing long-term access to new hardware, functionality or support.
Compliance Does Not Automatically Mean Security
The restrictions may encourage manufacturers to move production, change suppliers or establish US assembly operations. Foreign manufacturers can also request conditional approval from the US Department of War for products determined not to present an unacceptable risk.
However, changing the country of production does not necessarily secure the complete IoT stack.
A robot assembled in the United States may still depend on foreign-developed firmware, externally hosted fleet-management software or cloud services operating across several jurisdictions. Conversely, a foreign-produced platform could use independently audited software, local data processing and tightly restricted remote access.
The security of a connected robot depends on multiple layers:
- Sensors and onboard processors
- Wireless modules and network interfaces
- Firmware and operating systems
- Navigation and perception software
- Cloud and fleet-management platforms
- Software-update infrastructure
- Remote maintenance access
Production origin can affect control and accountability across that chain, but it is not a substitute for security-by-design.
The resulting risk is that regulatory compliance and cybersecurity become conflated. A robot may qualify for US authorisation without being particularly resilient, while another may be excluded because of its origin despite implementing stronger security controls.
Procurement Questions Are Changing
Industrial buyers should now look beyond a robot’s performance and purchase price.
They need to verify whether the exact model already has FCC authorisation, where the system and its critical components are produced, and whether future versions are likely to remain eligible.
Contracts may also need to cover:
- Where mapping and operational data is stored
- Who can access the robot remotely
- How firmware, cloud and component changes are communicated
- How long security updates will remain available
- Whether the robot can operate without its vendor’s cloud platform
- What migration options exist if future models cannot be authorised
These questions matter because mobile robots become embedded in warehouse processes, production workflows and software integrations that are costly to replace.
The FCC decision illustrates a broader change in the regulation of connected equipment. A warehouse robot may still perform a straightforward material-handling task, but its sensors, software and connectivity also make it part of the IoT infrastructure.
Connectivity is therefore no longer simply a product feature. It can determine how a machine is classified, whether it reaches a market and which national-security rules apply to it.