It Worked for Routers

Published:

It Worked for Routers

On March 23, 2026, the Federal Communications Commission stopped approving new consumer-grade routers made outside the United States.

Nobody voted on it. No statute was passed. No committee hearing produced the kind of recorded vote a challenger could run against in November. The Commission added a line to a list. That is the entire formal action: the Covered List updated to include all foreign-made consumer routers.

Read that sentence slowly. All consumer-grade routers produced in foreign countries. Not the defective ones. Not the models with a demonstrated flaw. All of them, sorted by country of manufacture.

In July I argued in The Safety Moat that the biggest AI labs want regulation because regulation is a moat. That piece described the demand side: who wants the rules, and why. This piece is about the supply side. An actual regulator, using an actual authority, removing actual products from the market. The FCC never mentions AI. It does not need to. What matters is that the mechanism works, that it has now been used on a consumer product, and that it can be used again.


What the Commission Actually Did

The Commission’s fact sheet is blunt about the formal step: “the Federal Communications Commission updated its Covered List to include all consumer-grade routers produced in foreign countries.”

It did not stop there. The update “followed a determination by a White House-convened Executive Branch interagency body with appropriate national security expertise that such routers ‘pose unacceptable risks to the national security of the United States or the safety and security of United States persons.’”

Two grounds are stated. First, “a supply chain vulnerability that could disrupt the U.S. economy, critical infrastructure, and national defense.” Second, “a severe cybersecurity risk that could be leveraged to immediately and severely disrupt U.S. critical infrastructure and directly harm U.S. persons.”

The Commission anchored the whole action in the president’s 2025 National Security Strategy:

“the United States must never be dependent on any outside power for core components—from raw materials to parts to finished products—necessary to the nation’s defense or economy. We must re-secure our own independent and reliable access to the goods we need to defend ourselves and preserve our way of life.”

The named adversaries are specific: Volt Typhoon, Flax Typhoon, and Salt Typhoon, all attributed by U.S. authorities to Chinese state-sponsored actors. Flax Typhoon is closest to the question at hand. The FBI disclosed it in September 2024. It took control of internet-connected consumer and small-business devices - cameras, routers, network storage - and stitched them into a botnet. A router ban justified by an attack on consumer routers is not a hypothetical.

Now the limits, stated plainly, because they are the part the coverage skipped.

“the restrictions imposed today apply to new device models.”

And the order “does not impact a consumer’s continued use of routers they previously acquired. Nor does it prevent retailers from continuing to sell, import, or market router models approved previously through the FCC’s equipment authorization process.”

So this is not a recall. Nobody is coming for the router in your hallway. The shelf is not cleared. What changed is the gate for anything new. After March 2026, a router model that has not already been approved faces a country-of-origin test it cannot pass by being good, or cheap.


The Mechanism Is the Story

Here is the sentence to keep. From the FCC’s own FAQ:

“Under the Secure Networks Act, the FCC can update the Covered List only after the direction of a qualifying national security authority. In other words, the Commission cannot update this list on its own and is required to implement determinations that are made by our national security agency experts.”

Everything else follows from that.

The regulator did not decide this. The legislature did not decide it. A determination was made inside the executive branch, by a body the White House convened, and the Commission’s role was to carry it out.

If you want to stop it, you do not call your member of Congress. You do not file a comment in a rulemaking. There is no bill to amend and no tariff schedule to renegotiate. You have to move a national security determination made in the executive branch, and that is not a process the public has a lever in.

Now note where the exit door is. The determination “included an exemption for routers that the Department of War (DoW) or the Department of Homeland Security (DHS) have granted ‘Conditional Approval.’” Producers are “encouraged to submit an application for Conditional Approval.” The applications go to conditional-approvals@fcc.gov.

A determination takes your product off the market. An application, adjudicated by the same branch of government that wrote the determination, can put it back. The gate is guarded by the people who closed it.

That is how you get a market exclusion with no statute, no tariff schedule, no revenue, and no vote. It is also why the lobbying target here was never the legislature. When the gate is an executive determination, the only useful place to stand is next to whoever writes determinations.

This is the machinery the safety moat piece was pointing at, and it is worth noticing that it did not need the AI labs at all. It was already built. The 2019 Secure and Trusted Communications Networks Act created the authorities. The Commission laid the plumbing in 2021. All that was ever missing was a determination, and determinations are cheap.


The Rationale Is Dependency, Not Defect

Read the two stated grounds again and look for what is not there.

Nowhere in the action is there a finding that a specific foreign router is worse than a specific American one. There was no comparative testing. No model was named as failing a security standard. No defect was demonstrated. No recall was ordered.

If the standard were security, that is what you would produce. You would test routers. You would publish the results. You would name the models that failed and explain how they failed. The Commission did none of that, and it did not need to, because the test it used is origin, not performance.

A router made in a country the United States classifies as adversarial is presumptively excluded. A router made at home is not required to be better built. It is required to come from somewhere else. The same product, the same firmware lineage, the same chips, moved across a border, gets a different answer.

That is a flag test. It has been a flag test from the beginning. The independence of the equipment authorization program runs in one direction only.

Let me be fair about the threat, because the threat is real. Volt Typhoon pre-positioned inside U.S. critical infrastructure, in power and water. Salt Typhoon got into U.S. telecoms, and it is widely described as among the most significant cyber espionage campaigns against American infrastructure. Flax Typhoon turned consumer devices into a botnet. A manufacturer that can be compelled by its home government can be compelled to ship a backdoor, and a router is both a listening post and a launchpad that sits in the home.

So the danger is not invented. But the danger does not stop at the border, and that is the part an origin test cannot handle. Any vendor legally obligated to a state is a supply chain risk. American vendors are legally obligated to the American state. They answer to American subpoenas, American courts, and the Foreign Intelligence Surveillance Court. The United States government can compel a domestic router manufacturer in ways it accuses foreign governments of compelling theirs.

That is not an argument against the ban. It is an argument about what the ban actually is. “Foreign” is a proxy for “not ours,” and a proxy is not a security standard. It is a jurisdictional one. It tells you who holds the leverage, not who holds the flaw.


Who Pays

Industry reporting puts roughly 99 percent of consumer routers as manufactured overseas. If that is anywhere close to right, this is not a ban on an edge case. It is a ban on the category.

Now consider how the ban collects.

A tariff raises money. It is ugly, it distorts prices, and it generates revenue a government can spend or rebate. This action raises nothing. No customs receipt, no excise, no auction, no fee schedule. The government removes a product from the market for free.

Which means the entire cost lands somewhere else. In the price of the routers that remain legal, because the supply of new models just got narrower. In the cost of certification, which becomes part of the price of anything that clears the gate. In the years spent waiting for domestic manufacturing to exist at a scale it does not currently have. And in the routers people keep using past their supported life, because replacing a device they never think about now costs more than they are willing to spend on it.

Maybe the price is worth paying. National security is expensive, and cheap security usually is not security. But there is no line in this order that accounts for the cost, and no one is being asked to look at it.

The tariff comparison is not rhetorical. A tariff at least sends money to the treasury and leaves the choice with the buyer. This is a tariff with none of the fiscal upside: the transfer without the receipt, the exclusion without the revenue, and the bill landing on everyone who now pays more for the substitute.


The Precedent Was Expensive

The router action is not the first use of this authority. It is the second.

The Secure and Trusted Communications Networks Act passed in 2019. The Commission adopted remove-and-replace rules in its Second Report and Order in January 2021, effective March 2022, requiring carriers to strip Huawei and ZTE equipment out of their networks. Congress appropriated $1.9 billion in 2021. A further $3.08 billion Treasury loan was authorized in December 2024. Call it $5 billion in total.

As of June 2026, only 42 percent of those projects are complete. Supply chain delays have doubled.

That is the track record of this mechanism in its first application. Five billion dollars, more than four years past the effective date, and the removal is not yet half finished. And that program was aimed at the equipment inside carrier networks - a few hundred sophisticated operators who are paid to comply and staffed to do it.

The new order points the same machinery at the devices in the vast majority of American homes. The Commission has not published a cost estimate, a completion target, or a date by which the gate might come down.

Hold on to the 42 percent. It is what happens when the state is handed the job of deciding which products may exist. It does not have to run the router market to break it. It only has to certify who is allowed to sell into it.


The AI Version, at True Scope

Here is where this connects to July’s argument, and here is where the precision matters, because overstating the case would hand it away.

In February 2025, a bipartisan pair in the House proposed banning DeepSeek from federal devices, explicitly modeled on the TikTok approach. On June 25 and 26, 2025, the “No Adversarial AI Act” was introduced in both houses. It would bar U.S. executive agencies from procuring or deploying AI models developed in China, Russia, Iran, or North Korea, and it names DeepSeek. A parallel Senate proposal extends the bar to federal contractors.

Those are real proposals with real scope. Here is that scope stated exactly: they ban government use. They do not ban the models. Nothing stops you from downloading DeepSeek’s weights, running them on your own hardware, or using a model trained in Beijing that some American company has wrapped and resold. A procurement ban changes what the federal government buys. It does not change what exists.

That gap is precisely why the router route matters.

If the lesson taken from March 2026 is that a security determination can remove a product from the consumer market with no statute, no tariff, and no vote, then the thing to watch is not the next procurement bill. It is the next determination.

A determination covering foreign-developed model weights, or the accelerators they run on, or the APIs that serve them, would reach past anything Congress has proposed, because it would regulate the market instead of the government’s own purchasing. Whether it would need new legislation is the part nobody has tested. The Covered List is a list of communications equipment and services, and an API that serves a model sits closer to that definition than the model weights do. But the pattern is what travels: a national security determination, a list, an approval gate, and an exemption you apply for. The router order proved the pipeline is open and the water runs.

Be exact about what has not happened. No such determination has been issued for AI models. No Chinese model has been banned in the United States. The open question is not whether anyone asked for it. The safety moat piece already showed what the labs are asking for: a single regime with independent testing and a government gate before release. The open question is whether the machinery that just cleared foreign routers gets aimed at foreign AI models, because that would arrive as an administrative step rather than a vote - no appropriation to pass, no hearing to survive, and no debate anyone would have to win.

What the router order hands AI incumbents is not a favor. It is a template. Compliance gates favor whoever can afford to pass them, and the labs are the ones who can. The FCC never had to mention them.


The Seven Questions

Apply the framework this site uses on every policy - the one laid out in The Seven Questions - and this order does worse than most.

Question 1: What problem are you solving? The order names three threat actors and a condition. It does not name a number. There is no measured baseline of router compromise, no target for reducing it, and no attempt to separate the supply chain risk from patching, configuration, and user behavior. Dependency is a condition, not a metric. You cannot tell whether this order reduces dependency, because dependency was never quantified in the first place.

Question 2: Who wins and who loses? The winners are domestic manufacturers and the compliance industry, and they are easy to name because they are the policy’s authors in every practical sense. The losers are every household that buys a router, and every small foreign manufacturer that cannot absorb the cost of a Conditional Approval application. They are not named. They never are.

Question 3: How will this be implemented? This is the order’s strongest answer, and it deserves to be said. The Covered List exists. The equipment authorization program exists. The Conditional Approval route exists. Implementation here is not a promise. It is a schedule. The order will be carried out.

Question 4: How will you measure the effects? It will not, and the failure has a shape worth seeing. The action bans new models while explicitly permitting continued sale of previously approved ones. The attack that justified the ban, Flax Typhoon, used consumer devices that were already in the field. So the models that remain legal to sell are drawn from the same population that was compromised, while the models facing the new gate are the ones nobody has attacked, because they do not exist yet. Nothing in the order measures whether any of this changes the risk. There is no baseline, no metric, and no report. Failing Question 4 this completely is not an oversight. It is the design.

Question 5: How will you report the results? There is no reporting requirement. No annual scorecard, no cost disclosure, no plain-language accounting of what the gate cost the people it holds back. What exists is a fact sheet, which is a press document, not a measurement.

Question 6: What does success look like? Undefined. There is no stated threshold at which the restriction lifts. Every router in the rest of the world will still be manufactured in the same countries, by the same firms, under the same governments. The dependency does not end at the American border, so there is no condition under which the risk is fully addressed. A measure with no terminating condition cannot succeed. It can only continue.

Question 7: What is the sunset clause? There is none. The Covered List has only ever grown. Nothing has ever been taken off it.

Five of the seven questions have no answer at all. The two that do - how it will be implemented, and who wins - are the two that favor the people who wrote it. That is the ordinary result, and it is why the framework exists.


The Question

The order will work, in the narrow sense that matters to the people who wrote it. Foreign consumer router models will stop being approved, and the market will reorder around the gate. That is not a prediction. It is what a certification regime does.

The question is whether you noticed, and whether you understand what has been assembled. A determination you did not vote for. An exemption you apply for from the same branch of government that closed the door. A mechanism tested on carrier equipment in 2021, tested again on the router in your hallway in 2026, and available, at the stroke of a determination, for whatever gets defined as the next dependency.

The labs published their answer to the safety question in July: a regime that decides who can build and ship advanced AI. The Commission has now shown what such a regime looks like when it points outward, at a foreign product, instead of inward at a domestic one. No vote. No bill. No threshold. No sunset. No measurement. A list, a determination, and an email address for the exemption.

It worked for routers. The only open question is which product it works on next.


This is the second in a series on the regulatory moat. Start here: The Safety Moat: How Big AI Wants Regulation.