# Securing the Information and Communications Technology and Services Supply Chain: Connected Vehicles

> Briefs, arguments, decisions, and more.

URL: https://www.frixlaw.com/law-library/documents/fr%3A2025-00592

## Record

- **Collection:** Federal Register
- **Document type:** Rule
- **Published:** January 16, 2025
- **Citation:** 90 FR 5360

## Text

DEPARTMENT OF COMMERCE
Bureau of Industry and Security
15 CFR Part 791
[Docket No. 250107-0005]
RIN 0694-AJ56
Securing the Information and Communications Technology and Services Supply Chain: Connected Vehicles

AGENCY:

Bureau of Industry and Security, Department of Commerce.

ACTION:

Final rule.

SUMMARY:

This final rule, published by the Department of Commerce's (Department) Bureau of Industry and Security (BIS), sets forth regulations and procedures to address undue or unacceptable risks to national security and U.S. persons posed by classes of transactions involving information and communications technology and services (ICTS) that are designed, developed, manufactured, or supplied by persons owned by, controlled by, or subject to the jurisdiction or direction of certain foreign adversaries and that are integral to connected vehicles as defined herein.

DATES:

This final rule goes into effect on March 17, 2025.

FOR FURTHER INFORMATION CONTACT:

Marc Coldiron, U.S. Department of Commerce, telephone: (202) 482-3678. For media inquiries: Office of Congressional and Public Affairs, Bureau of Industry and Security, U.S. Department of Commerce:
OCPA@bis.doc.gov.

SUPPLEMENTARY INFORMATION:

I. Background

In this final rule, BIS prohibits transactions involving Vehicle Connectivity System (VCS) hardware and covered software designed, developed, manufactured, or supplied by persons owned by, controlled by, or subject to the jurisdiction or direction of the People's Republic of China, including the Hong Kong Special Administrative Region and the Macau Special Administrative Region, (PRC); or the Russian Federation (Russia). It follows an advance notice of proposed rulemaking (ANPRM), 89 FR 15066 (March 1, 2024), and a notice of proposed rulemaking (NPRM), 89 FR 79088 (September 26, 2024). In the ANPRM, BIS sought public comment to inform a rulemaking that would address the undue or unacceptable risks, as identified in Executive Order (E.O.) 13873, “Securing the Information and Communications Technology and Services Supply Chain,” 84 FR 22689 (May 17, 2019), posed by a class of transactions that involve ICTS designed, developed, manufactured, or supplied by persons owned by, controlled by, or subject to the jurisdiction or direction of a foreign adversary and integral to connected vehicles. The NPRM proposed a rule to address the undue or unacceptable risks identified in the ANPRM and solicited public comment. BIS has considered the comments received during both rounds of public comment, and is making revisions, from the proposed rule, that address significant portions of that feedback.

In E.O. 13873, the President delegated to the Secretary of Commerce (Secretary), to the extent necessary to implement the Order, the authority granted under the International Emergency Economic Powers Act (IEEPA) (50 U.S.C. 1701,
et seq.
), “to deal with any unusual and extraordinary” foreign threat to the United States' national security, foreign policy, or economy, if the President declares a national emergency with respect to such threat. 50 U.S.C. 1701(a). In E.O. 13873, the President declared a national emergency with respect to the “unusual and extraordinary” foreign threat posed to the ICTS supply chain and has, in accordance with the National Emergencies Act (NEA), extended the declaration of this national emergency in each year since E.O. 13873's publication.
See Continuation of the National Emergency With Respect to Securing the Information and Communications Technology and Services Supply Chain,
85 FR 29321 (May 14, 2020);
Continuation of the National Emergency With Respect to Securing the Information and Communications Technology and Services Supply Chain,
86 FR 26339 (May 13, 2021);
Continuation of the National Emergency With Respect to Securing the Information and Communications Technology and Services Supply Chain,
87 FR 29645 (May 13, 2022);
Continuation of the National Emergency With Respect to Securing the Information and Communications Technology and Services Supply Chain,
88 FR 30635 (May 11, 2023);
Continuation of the National Emergency With Respect to Securing the Information and Communications Technology and Services Supply Chain,
89 FR 40353 (May 9, 2024).

Specifically, the President identified the “unrestricted acquisition or use in the United States of ICTS designed, developed, manufactured, or supplied by persons owned by, controlled by, or subject to the jurisdiction or direction of foreign adversaries” as “an unusual and extraordinary” foreign threat to the national security, foreign policy, and economy of the United States that “exists both in the case of individual acquisitions or uses of such technology or services, and when acquisitions or uses of such technologies are considered as a class.”
See
E.O. 13873,
and
50 U.S.C. 1701(a)-(b).

Once the President declares a national emergency, IEEPA empowers the President to, among other acts, investigate, regulate, prevent, or prohibit, any “acquisition, holding, withholding, use, transfer, withdrawal, transportation, importation or exportation of, or dealing in, or exercising any right, power, or privilege with respect to, or transactions involving, any property in which any foreign country or a national thereof has any interest by any person, or with respect to any property, subject to the jurisdiction of the United States.” 50 U.S.C. 1702(a)(1)(B).

To address the identified risks to national security from ICTS transactions, the President in E.O. 13873 imposed a prohibition on transactions that the Secretary, in consultation with relevant agency heads, has determined involve foreign adversary ICTS and pose certain risks to U.S. national security, including U.S. technology and critical infrastructure, or the security and safety of U.S. persons. Specifically, to fall within the scope of the prohibition, the Secretary must determine that a transaction: (1) “involves [ICTS] designed, developed, manufactured, or supplied, by persons owned by, controlled by, or subject to the jurisdiction or direction of a foreign adversary,” defined in E.O. 13873 as “any foreign government or foreign non-government person engaged in a long-term pattern or serious instances of conduct significantly adverse to the national security of the United States or security and safety of United States persons, which, pursuant to E.O. 13873's implementing regulations at 15 CFR 791.4 are the PRC, Republic of Cuba (Cuba), Islamic Republic of Iran (Iran), Democratic People's Republic of Korea (North Korea), Russia, and Venezuelan politician Nicolás Maduro (Maduro Regime); and (2):

A. “Poses an undue risk of sabotage to or subversion of the design, integrity, manufacturing, production, distribution, installation, operation, or maintenance of information and communications technology or services in the United States;”

B. “Poses an undue risk of catastrophic effects on the security or

resiliency of United States critical infrastructure or the digital economy of the United States;” or

C. “Otherwise poses an unacceptable risk to the national security of the United States or the security and safety of United States persons.”

Factors A through C are collectively referred to as “undue or unacceptable risks.” In addition, section 1(b) of E.O. 13873 grants the Secretary the authority to design or negotiate mitigation measures to allow an otherwise prohibited transaction.

The President also delegated to the Secretary the ability to promulgate regulations that, among other things, establish when transactions involving particular technologies may be categorically prohibited. E.O. 13873 section 2(a)-(b);
see also
3 U.S.C. 301-02. Specifically, the Secretary may issue regulations establishing criteria, consistent with section 1 of E.O. 13873, by which particular technologies or market participants may be categorically included in or categorically excluded from prohibitions established pursuant to E.O. 13873.

II. Introduction

Today's vehicles contain a myriad of connected components that provide greater convenience for consumers and increase road safety for both drivers and pedestrians, such as Wi-Fi, Bluetooth, cellular, and satellite connectivity. However, the incorporation of progressively more complex hardware and software systems that facilitate these features has also increased the attack surfaces through which malign actors and foreign adversaries may exploit vulnerabilities to gain access to a vehicle. As BIS outlined in its March 1, 2024, ANPRM and its September 26, 2024, NPRM, certain ICTS integral to connected vehicles present an undue or unacceptable risk to U.S. national security when those systems are designed, developed, manufactured, or supplied by persons owned by, controlled by, or subject to the jurisdiction or direction of a foreign adversary.

In the
Securing the Information and Communications Technology and Services Supply Chain
interim final rule, 86 FR 4909 (Jan. 19, 2021), the Secretary determined that certain foreign governments or foreign non-government persons—the PRC, Cuba, Iran, North Korea, Russia, and the Maduro Regime—constitute foreign adversaries for purposes of E.O. 13873 and regulations promulgated pursuant to E.O. 13873.
See
15 CFR 791.4 (to the extent that the list of foreign adversaries identified in 15 CFR 791.4 is updated to add or remove governments or non-government persons, this final rule intends to reflect the most up-to-date designations of foreign adversaries). Additionally, section 2(b) of E.O. 13873 provides that the Secretary may issue rules that identify particular technologies or countries with respect to transactions involving ICTS that warrant particular scrutiny. For the purposes of this final rule regarding transactions involving ICTS integral to connected vehicles, BIS is focusing its regulatory efforts on ICTS that are designed, developed, manufactured, or supplied by persons owned by, controlled by, or subject to the jurisdiction or direction of the PRC or Russia. BIS has identified that, for the purposes of addressing the national security risks posed by connected vehicles, these two foreign adversaries pose particular undue and unacceptable risks to U.S. national security because of these adversaries' legal, political, and regulatory regimes, combined with their current and anticipated growth and involvement in the connected vehicles sector.

As discussed below, the PRC and Russia are able to leverage domestic legislation and regulatory regimes to compel companies subject to their jurisdiction, including carmakers and their suppliers, to cooperate with security and intelligence services. Such control over companies and their products and services means that their equipment is easily exploitable by PRC and Russian authorities. The privileged access that the PRC and Russia may gain to connected vehicles through their components, including software and hardware, could enable those foreign adversaries to (1) exfiltrate sensitive data collected by connected vehicles and (2) allow remote access and manipulation of connected vehicles driven by U.S. persons. Pursuant to E.O. 13873, BIS has determined that certain classes of transactions that can facilitate the exfiltration of data and remote manipulation of connected vehicles by the PRC and Russia pose undue or unacceptable risks to U.S. national security and to the safety and security of U.S. persons. These risks, moreover, present an urgent national security risk to the safety and security of technology used in the United States and to U.S. persons.

The PRC has pre-positioned malware on U.S. information technology and critical infrastructure networks. The PRC has also set objectives for the completion of the People's Liberation Army's (PLA) modernization and other military and technology goals by 2027, which—in light of the PLA's military-civil fusion strategy and the growing prevalence of PRC dual-use technologies in U.S. commercial supply chains, including in the auto industry—presents additional risks to U.S. national security. Mounting evidence of threats such as these to U.S. critical infrastructure, data security, and broader national security necessitates this urgent action by the U.S. government to address the risk of foreign adversary supply chains in the connected vehicles sector.

a. Overview of the Advance Notice of Proposed Rulemaking (ANPRM)

BIS issued an ANPRM, 89 FR 15066 (Mar. 1, 2024), seeking public comment to inform a rulemaking that would address the undue or unacceptable risks posed by a class of transactions that involve ICTS designed, developed, manufactured, or supplied by persons owned by, controlled by, or subject to the jurisdiction or direction of a foreign adversary and integral to connected vehicles. In the ANPRM, BIS posed 35 questions to the public for comment and feedback. The questions related to potential definitions used in the rulemaking, the degree of foreign adversary involvement in the connected vehicle supply chain, which systems should be the focus of a potential rulemaking, and what the economic impacts of a potential rulemaking might be, among other questions. BIS identified six systems as the potential focus for a future rule: (1) vehicle operating systems (OS), (2) telematics systems, (3) advanced driver assistance systems (ADAS), (4) automated driving systems (ADS), (5) satellite or cellular telecommunications systems, and (6) battery management systems (BMS). BIS received 57 comment submissions in response to the ANPRM from a variety of parties, including original equipment manufacturers (OEMs), component suppliers, two foreign governments, nonprofit organizations, and individual respondents. Five comments contained Confidential Business Information (CBI), and one comment was retracted at the request of the commenter. The comments generally urged BIS to narrow the scope of a future regulation and to limit the systems to be regulated to only those posing significant national security risks. Commenters also urged BIS to provide industry stakeholders with sufficient lead time to comply. BIS considered each comment in developing the NPRM outlined in the next section.

b. Overview of the Notice of Proposed Rulemaking (NPRM)

BIS then issued an NPRM, 89 FR 79088 (Sept. 26, 2024), that identified a smaller subset of systems in connected

vehicles that pose the most significant undue or unacceptable risk to national security when designed, developed, manufactured, or supplied by persons owned by, controlled by, or subject to the jurisdiction or direction of the PRC or Russia. Below is a summary of the proposed rule.

Regulated Systems

The proposed rule identified (1) VCS, which is composed of the hardware and software that enable a connected vehicle to communicate off-board above 450 MHz, and (2) ADS, as subject to regulation by BIS. This determination was based, in part, on public comments requesting BIS narrow the scope of the rule, as a regulation that impacted all six of the listed automotive systems would be overbroad. The ANPRM listed ADS, operating systems, telematic systems, automated driving assistance systems, satellite and communication systems, and battery management systems as potential automotive systems that could be regulated in the subsequent proposed rule. Public comment as well as BIS's analysis suggested that automotive telematics functions were one of the primary means for a foreign adversary to exploit automotive data and actuation systems. BIS also determined, based on public comment as well as internal analysis, that the term “telematics” generally refers to systems that operate on cellular band protocols. As BIS intended to regulate multiple automotive connectivity systems, not just automotive cellular systems, BIS chose to use the broader term of “VCS” to encompass cellular, Wi-Fi, Bluetooth, and potentially satellite communications. The NPRM proposed to regulate both the hardware and software in VCS and solely the software in ADS.

Prohibited Transactions

The NPRM proposed to (1) prohibit VCS hardware importers from knowingly importing into the United States certain hardware for VCS; (2) prohibit connected vehicle manufacturers from knowingly importing into the United States completed connected vehicles incorporating covered software, which was defined in the NPRM as certain software that supports the function of VCS or ADS; and (3) prohibit connected vehicle manufacturers from knowingly selling within the United States completed connected vehicles that incorporate software that supports the function of VCS or ADS. These prohibitions included in the NPRM applied when such VCS hardware or covered software was designed, developed, manufactured, or supplied by persons owned by, controlled by, or subject to the jurisdiction or direction of the PRC or Russia. The NPRM also proposed to (4) prohibit connected vehicle manufacturers who are owned by, controlled by, or subject to the jurisdiction or direction of the PRC or Russia from knowingly selling in the United States completed connected vehicles that incorporate VCS hardware or covered software, even when that hardware or software did not have a nexus to the PRC or Russia.

Declarations of Conformity

The NPRM proposed that VCS hardware importers and connected vehicle manufacturers would submit to BIS, once per calendar year or model year, Declarations of Conformity attesting that they had not engaged in prohibited transactions involving VCS hardware or covered software. The NPRM would have mandated that VCS hardware importers and connected vehicle manufacturers submit a substantial amount of information with their Declarations of Conformity, including a hardware bill of materials (HBOM) or software bill of materials (SBOM), and a list of external endpoints to which the VCS hardware connected. In the final rule, BIS has changed the Declarations of Conformity requirement to clarify the certification, narrow the information required to be submitted, and add recordkeeping requirements.

Authorizations

The NPRM enumerated general authorizations under which a regulated entity would be permitted to engage in an otherwise prohibited transaction without need to notify BIS. Under the NPRM, general authorizations would have been available to small business VCS hardware importers and connected vehicle manufacturers. Specifically, general authorizations applied if (1) the connected vehicle manufacturer or VCS hardware importer produced fewer than 1,000 connected vehicles or VCS hardware units; (2) the completed connected vehicle was used on public roadways for fewer than 30 calendar days in a year; (3) the completed connected vehicle or VCS hardware was used solely for purposes of display, testing, or research; or (4) the completed connected vehicle was imported solely for repair, alteration, or competition off public roads and would have been exported within one year of import. In the final rule, BIS has revised the general authorizations provision so that the above-mentioned general authorizations are not provided in the rule text itself. Instead, BIS will issue general authorizations through its website and the
Federal Register
.

The NPRM also provided a process for specific authorizations. Following an application to and approval from BIS, a specific authorization granted VCS hardware importers and connected vehicle manufacturers the ability to engage in otherwise prohibited transactions not eligible for a general authorization, subject to certain conditions imposed by BIS.

Exemptions

The NPRM permitted VCS hardware importers to engage in otherwise prohibited transactions involving VCS hardware and exempted them from certain requirements so long as: (1) for VCS hardware not associated with a model year, the import of the VCS hardware had taken place prior to January 1, 2029; or (2) the VCS hardware unit was associated with a vehicle model year prior to 2030 or the VCS hardware was integrated into a connected vehicle (completed or incomplete) with a model year prior to 2030. In the NPRM, connected vehicle manufacturers were permitted to engage in otherwise prohibited transactions involving covered software and exempt from certain requirements so long as the completed connected vehicle that was imported, or sold within the United States, was of a model year prior to 2027. Lastly, connected vehicle manufacturers that are owned by, controlled by, or subject to the jurisdiction or direction of the PRC or Russia were permitted to sell completed connected vehicles with a model year prior to 2027 that incorporated VCS hardware or covered software. The final rule includes new exemptions for parts that are imported for the purpose of warranty or repair of a completed connected vehicle with a model year prior to 2030.

Advisory Opinions, Is-Informed Notices, and Appeals

The NPRM provided an advisory opinion mechanism by which regulated entities could seek guidance from BIS as to whether specific prospective transactions were subject to the proposed rule's prohibitions. The mechanism included in the NPRM applied to actual, as opposed to hypothetical, transactions in which all parties are identified. Additionally, the NPRM permitted BIS to issue certain “Is-Informed” notices to VCS hardware importers and connected vehicle manufacturers to inform them that a specific authorization was required for an activity. The NPRM also included an

appeal process by which any person whose application for a specific authorization was denied, whose specific authorization was suspended or revoked, or who received a written notification of ineligibility for a general authorization could appeal that decision to the Under Secretary for Industry and Security (Under Secretary). In the final rule, BIS has added a 60-day timeline for BIS to respond to advisory opinion requests and clarified procedural requirements of submitting an appeal request.

Recordkeeping and Reporting

The NPRM proposed that regulated entities keep a “full and accurate record” for a period of 10 years after each transaction for which a Declaration of Conformity, general authorization, or specific authorization was required, regardless of whether the transaction was effected pursuant to such an authorization. In the NPRM, VCS hardware importers and connected vehicle manufacturers were required to furnish “complete information” relevant to any transaction involving the import of VCS hardware or covered software, irrespective of any authorization granted by BIS.

Violations

The NPRM additionally outlined the framework by which BIS determined a violation took place, the procedure by which BIS notified an affected party of such a violation (including the party's right to respond or to settle), the specific penalties BIS was permitted to impose on violators, and the administrative collection of those penalties.

c. Overview of Final Rule

The final rule benefits from the responses received during the public comment periods for the ANPRM and the NPRM and incorporates significant portions of that feedback. For example, BIS considered public feedback to define the scope of connected vehicles, identify ICTS integral to connected vehicles, and better understand the effects of any potential prohibition. As stated in the NPRM, determining the scope of the prohibitions required a balancing of the need to address the undue or unacceptable risk posed by foreign adversary involvement in the connected vehicles supply chain with the impact on the public and industry. For a detailed discussion of how the final rule has changed from the NPRM, refer to Section V: Discussion of the Final Rule and Section VI: Revisions from the Proposed Rule and Response to Comments.

III. Comments on the Notice of Proposed Rulemaking

BIS received 101 comments on the NPRM.
1

Many commenters agreed with BIS's risk assessment of foreign adversary connected vehicle technology as described in Section IV of the NPRM and supported the decision to address these risks through supply chain regulation. Commenters' concerns with the NPRM centered on the broad scope of the regulation and the potentially onerous and disruptive nature of the compliance process, particularly the submission of Declarations of Conformity. Some commenters disagreed with the NPRM's inclusion of the commercial vehicle market, arguing that definitions proposed in the NPRM did not as easily apply to this sector compared to the passenger vehicle market. Commenters also warned that the wide scope of the NPRM across the connected vehicle market may have significant economic impact and that the current implementation timeline could not easily be met by industry.

1
This includes four written submissions received after the close of the public comment period, all of which were considered and posted on
regulations.gov.

Commenters requested that BIS implement alternative methods of compliance, such as a self-certification model; provide greater detail on the HBOM and SBOM submission requirements; and describe how BIS intends to protect any submitted data. Commenters also voiced apprehension over any requirement to share proprietary information with customers and the government. For a more thorough discussion of the comment submissions and BIS's responses, please see Section IV: Risks Associated with Vehicle Connectivity Systems and Automated Driving Systems When Designed, Developed, Manufactured, or Supplied by Persons Owned by, Controlled by, or Subject to the Jurisdiction or Direction of the PRC and Russia and Section V: Discussion of the Final Rule.

IV. Risks Associated With Vehicle Connectivity Systems and Automated Driving Systems When Designed, Developed, Manufactured, or Supplied by Persons Owned by, Controlled by, or Subject to the Jurisdiction or Direction of the PRC and Russia

BIS received multiple comments related to the risks stemming from VCS and ADS when designed, developed, manufactured, or supplied by persons owned by, controlled by, or subject to the jurisdiction or direction of the PRC or Russia. Commenters agreed with the risks posed by PRC and Russian involvement in the connected vehicle supply chain as laid out in the NPRM, and BIS reiterates those same risks in this section. For instance, one commenter acknowledged that allowing adversarial suppliers into the automotive supply chain poses direct threats to data integrity, consumer safety, and national security. In contrast, another commenter critiqued the proposed rule as overly broad and characterized the threats as hypothetical in nature, underscoring that PRC and Russian companies are incentivized to avoid exploiting vulnerabilities in connected vehicles in order to avoid conflict. BIS recognizes that many of the risks laid out in the NPRM and final rule are forward-looking, and this rulemaking is an attempt to proactively address these risks before PRC and Russian actors are able to leverage them to harm U.S. national security. Moreover, while BIS agrees that action by the PRC or Russia to leverage vulnerabilities in VCS or ADS could feasibly cause undesired conflict, the strategic benefit of exploiting vulnerabilities may outweigh other types of harm it causes and thus is unlikely to preclude such an action altogether from the perspective of the PRC and Russia. Another commenter highlighted that the rule does not apply retroactively to address any of the data already collected by connected vehicle manufacturers that may have already been legitimately transferred to the PRC or other foreign adversaries and may be informing foreign intelligence analysis. BIS recognizes that some connected vehicle and component manufacturers may already transfer vehicle data abroad, a point that is reiterated later in this final rule. However, BIS believes that retroactive application of this rule would not reduce or alleviate any of the harm that has already occurred as a result of foreign intelligence organizations gaining access to that data. Following consideration of the comments received on the NPRM, and further consideration of the risks and vulnerabilities associated with various ICTS components that are critical to the operation of connected vehicles, BIS has decided to retain the proposed rule's focus on two integral ICTS systems—VCS and ADS—when designed, developed, manufactured, or supplied by persons owned by, controlled by, or subject to the jurisdiction or direction of two foreign adversaries—the PRC and Russia. Below, BIS provides its findings of the undue and unacceptable risks associated with these particular systems, and these particular foreign

adversaries, following this latest round of public comments.

a.
Vulnerabilities Associated With Vehicle Connectivity Systems and Automated Driving Systems

1. Vehicle Connectivity Systems

The term VCS encompasses hardware and software systems—such as the telematics control units (TCU), cellular modems and antennas, and other automotive components—that integrate various radio frequency (RF) communication technologies and enable connected vehicles to access external data sources, facilitate vehicle-to-vehicle communication, and provide enhanced services to users through seamless connectivity options. For example, as the primary automotive VCS component, a TCU acts as the primary interface between the internal network and external communication channels. It collects data from onboard sensors such as Global Positioning Systems (GPS), accelerometers, gyroscopes, BMS, and other Electronic Control Units via wired networks like Controller Area Network (CAN) bus, Local Interconnect Network (LIN), FlexRay, Automotive Ethernet and K-Line, as well as wireless protocols such as Bluetooth and Wi-Fi. Some systems use cameras and microphones to facilitate facial recognition of drivers or to respond to voice commands of drivers. Once gathered, the TCU converts this internal data into radio frequency signals suitable for transmission over the chosen wireless protocol. In other words, as the vast array of sensors on a connected vehicle collect information about a driver's location, speed, voice patterns, battery state of charge, or other vehicle diagnostic and operational information, the TCU converts that data into a format that can be transmitted to systems outside the vehicle and then enables that transmission. Sensing systems, such as radar, audio, video, or Light Detection and Ranging (LiDAR) hardware and software, are not VCS. Based on a number of comments to the proposed rule, BIS recognizes a national security risk posed by LiDAR, but it concludes that focusing this regulation on VCS hardware and software systems, which ultimately enable the external communication of end-point sensors, is an appropriate scope at this time. For a more thorough discussion on the exclusion of PRC or Russian LiDAR from this rule, please see Section VI below.

While the increased degree of vehicle connectivity offers benefits to both consumers and manufacturers, it also increases risks to consumers and manufacturers due to the number of access points into the internal connected vehicle network. Each access point may present multiple new software vulnerabilities for adversaries to exploit.
See
Cabell Hodge, Konrad Hauk, Shivam Gupta, and Jess Bennett, Vehicle Cybersecurity Threats and Mitigation Approaches,
National Renewable Energy Laboratory,
at 4-5 (Aug. 2019),
https://www.nrel.gov/docs/fy19osti/74247.pdf.
Such compromise of VCS software could occur at various points of the software development lifecycle where software functionality can be accessed and altered, including tool development, source code repositories, open-source dependencies, software updates, and shipment interdiction. For instance, Upstream's 2024 Global Automotive Cybersecurity Report documented a case where security researchers installed malicious software on the VCS by performing a simulated jailbreak attack of an OEM's VCS using a voltage fault injection on the chipmaker's processor. This malicious software unlocked features to manipulate the vehicle, such as acceleration and heated seats. Upstream,
2024 Global Automotive Cybersecurity Report,
at 62 (Feb. 2024),
https://upstream.auto/reports/global-automotive-cybersecurity-report.
The software also provided access to private user data and enabled decryption of encrypted Non-Volatile Memory Express (NVMe) storage, manipulation of the car's identity, and extraction of the vehicle-unique credential used for authenticating and authorizing the OEM's internal service network.
See id.
By compromising software or its dependencies, malign actors may surveil, disrupt, damage, or otherwise exploit the data or systems of those who use the software.
See
National Counterintelligence and Security Center,
Software Supply Chain Attacks,
(Mar. 2021),
https://www.dni.gov/files/NCSC/documents/supplychain/Software_Supply_Chain_Attacks.pdf.

The threat of such a cyber operation by malicious actors can grow significantly when firmware or hardware components are intentionally designed with vulnerabilities. Access to the hardware supply chain for VCS provides an avenue for threat actors to manipulate or insert, with malicious intent, hardware, or firmware modules into telematics hardware components such as modems, Systems on Chip (SoC), Printed Circuit Boards (PCB), Central Processing Units, and antennae. Manipulating or modifying hardware and associated firmware in the supply chain could also allow foreign adversaries to insert a backdoor, granting them control over the VCS.
See
Cybersecurity & Infrastructure Security Agency,
Defending Against Software Supply Chain Attacks,
at 6 (Apr. 2021),
https://www.cisa.gov/sites/default/files/publications/defending_against_software_supply_chain_attacks_508.pdf;
National Counterintelligence and Security Center, Software Supply Chain Attacks, (Apr. 2023),
https://www.dni.gov/files/NCSC/documents/supplychain/Software-Supply-Chain-Attacks.pdf.
For instance, cellular and satellite telecommunications transceivers are pivotal connectivity components in the VCS, utilizing radio frequency (RF) energy to facilitate the transmission and reception of data between a vehicle and the external world. If these transceivers are designed, developed, manufactured, or supplied by persons owned by, controlled by, or subject to the jurisdiction or direction of the PRC or Russia, such actors would have the means and capability to introduce vulnerabilities that could be exploited to intercept and/or compromise the information exchanged between the connected vehicle and the external world.

2. Automated Driving Systems

The complexity of ADS software, the large foundation of data sources, and the driving responsibilities inherent to ADS render it a valuable target for exploitation. An ADS encompasses the upper end of the spectrum of autonomy levels that dictate the vehicle's independence, and the extent of driver intervention required. The primary standard setting organization for automotive autonomy is the global mobility standard-setting body SAE International. SAE International sets standards that affect many aspects of automotive production and maintenance, often in concert with the International Standards Organization (ISO). SAE International's
Taxonomy and Definitions for Terms Related to Driving Automation Systems for On-Road Motor Vehicles
(SAE J3016) is the current industry norm for evaluating standard levels of vehicle autonomy. SAE J3016 autonomy levels range from Level 0 (no automation) where the driver controls all aspects of driving, to Level 5 (full automation) where the vehicle can operate independently under all conditions without human intervention. Levels 1 and 2 offer driver assistance through systems that control either steering or acceleration and braking, while Levels 3 through 5 (which generally comprise ADS)

progressively increase the system's responsibility for driving tasks. Level 4 requires the ability to complete all driving functions on a sustained basis within defined operational design domains (ODDs), while Level 5 requires the ability to complete all driving functions unconditionally. As the autonomy level increases, the reliability and safety of the ADS become increasingly reliant on the system's operational performance, safety protocols, and cybersecurity measures.
See
SAE J3016_02104, Taxonomy and Definitions for Terms Related to Driving Automation Systems for On-Road Motor Vehicles,
SAE International,
at 31-32 (Apr. 2021),
https://www.sae.org/standards/content/j3016_202104/.

An ADS must be able to execute Dynamic Driving Tasks (DDTs) within specific ODDs. DDTs include critical tasks such as steering, braking, acceleration, and Object and Event Detection, Classification and Response (OEDCR). OEDCR enables an ADS to perceive and respond to surrounding objects and events, a responsibility that shifts progressively from the driver to the ADS itself as the degree of vehicle autonomy increases.
See id.
at 17; Edward Griffor, David Wollman, and Christopher Greer, Automated Driving System Safety Measures Part 1: Operating Envelope Specification,
NIST Special Publication 1900-301,
at 2 (2021),
https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.1900-301.pdf.

An ADS relies on a large foundation of connected information sources for decisions and outputs which, in turn, could create inherent vulnerabilities. For example, a user of a vehicle, or even an OEM purchaser of ADS likely does not know the sum total of what data the ADS was trained on, or how, specifically, the ADS makes its decisions. It is not possible to find single lines of code that dictate how an ADS responds to specific scenarios in modern ADS systems. Rather, leading ADS are controlled by complex software that can include a neural net that references training data and previous decisions to instantaneously decide on an action in a driving setting. This opacity and lack of understanding of how the system actually reacts is inherently vulnerable to poisoned data injection or specific scenario-based failures. As a result, the complex software systems that drive decisions for an ADS are valuable targets for malicious actors to exploit. Software-based threats to connected vehicles equipped with an ADS include manipulation of sensors to create phantom objects; manipulation of ADS software to detect, capture, and retain information about specific geographic areas or other sensitive data; or other manipulation of sensor fusion processing software that could lead to faulty and dangerous vehicle decision making, to include unauthorized control over the connected vehicle.
See
National Counterintelligence and Security Center,
Autonomous Automotive Vehicle Supply Chain Risk,
(2022),
https://www.dni.gov/files/NCSC/documents/supplychain/autonomous-vehicles-placemat-2022-D9A54B50-.pdf.

A compromised ADS creates opportunities for data exfiltration and unauthorized vehicle manipulation due to the direct access it has to the Internal Vehicle Network (IVN). The IVN controls the communication framework within a connected vehicle, overseeing the electronic control units (ECUs) responsible for engine control, traction control, door locks, climate control, battery management, powertrain, airbags, cameras, and radar functionalities. These ECUs also communicate via overlaid communication networking protocols such as a CAN bus, LIN, and ethernet.
See
Anastasios Giannaros, et al. Autonomous Vehicles: Sophisticated Attacks, Safety Issues, Challenges, Open Topics, Blockchain and Future Directions,
Journal of Cybersecurity and Privacy
3.3, at 508-513, (2023). Because ADS interacts with ECUs through the IVN, a compromised ADS has the capability to execute functions that affect nearly all of a connected vehicle's software and hardware components. For example, an update to an ADS could alter outputs the ADS makes to a Body Control Unit, enabling the ADS to erroneously and dangerously open a vehicle's door while in motion. Moreover, because many connected vehicles maintain their own networks and actively scan their operating environment for other proximate networks, an ADS can also potentially be used to impact the IVN of other vehicles or transportation infrastructure networks through vehicle-to-vehicle communication. This could lead to disablement or compromise of other vehicles or of transportation infrastructure, affecting the movement of goods and the physical safety of drivers.
See
National Counterintelligence and Security Center,
Autonomous Automotive Vehicle Supply Chain Risk
(Apr. 2022),
https://www.dni.gov/files/NCSC/documents/supplychain/autonomous-vehicles-placemat-2022-D9A54B50-.pdf;
Patrick Wagner, Nikolai Puch, and David Emeis, Cybersecurity risk analysis of an automated driving system,
Fraunhofer Institute AISEC
(Oct. 2023),
https://publica.fraunhofer.de/entities/publication/4d66e81e-3570-4c49-9f8c-8c9967a34ca6/details.

Given the significant processing power and complex decision-making capability of an ADS, the risks arising from ADS designed, developed, manufactured, or supplied by persons owned by, controlled by, or subject to the jurisdiction or direction of a foreign adversary extend beyond the IVN itself and include risks to the fidelity and integrity of data that flows to downstream or adjacent transportation infrastructure. Foreign adversaries can corrupt ADS data by exploiting existing vulnerabilities in ADS connectivity environments.
See
subsection IV.b. As such, direct access to an ADS afforded to a malicious actor or foreign adversary through the design, development, manufacture, or supply of ADS software has the potential to cause severe adverse consequences to U.S. national security and U.S. persons.

b. Threats Associated With the PRC and Russia

Several commenters agreed that PRC laws compel compliance with government requests, thereby making some companies subject to the direction of the PRC government. One commenter provided additional detail about the linkages between prominent Chinese companies, the PRC military, and the global automotive industry. Two commenters noted that current investments by Chinese companies in Mexico may allow effective “backdoor” access to the American auto market. One commenter specifically pointed to the risks posed by Chinese-developed buses with connectivity features as posing a particular threat to U.S. national security. While commercial vehicles such as buses are not in the scope of this final rule, BIS intends to propose a new rule specifically tailored to the commercial vehicle sector in order to address substantial national security risks. Another commenter agreed with the Department's actions, specifically as it related to addressing the large amounts of data collected by connected vehicles already being transmitted to the PRC, regardless of the vehicle's physical location. In response to commenters' agreement with the nature of PRC and Russian legal and regulatory landscapes, BIS is reiterating its legal and risk analyses in this final rule. Moreover, BIS thanks commenters for providing additional information that clarifies the linkages between the PRC state, military, and the broader economy. In light of concerns raised by

commenters regarding PRC companies' investments in Mexico, BIS reiterates that PRC investments in Mexico's auto sector risk creating additional potential nexus points between PRC connected vehicle suppliers and U.S. automakers and consumers. Similarly, BIS agrees with commenters' concerns that the PRC-linked entities already collect large amounts of data, including from vehicles which are currently located in the United States. These concerns directly underscore the importance and necessity of this rulemaking.

The design, development, manufacture, or supply of certain VCS and ADS components by persons owned by, controlled by, or subject to the jurisdiction or direction of the PRC or Russia poses undue or unacceptable risks to national security and U.S. persons. As discussed further, the PRC and Russia have adopted political, legal, and regulatory regimes that enable their governments to exercise direct and indirect ownership, control, or influence over entities in the connected vehicle supply chain. In addition, unlike other foreign adversaries, the PRC and Russia have certain current and anticipated industrial capabilities and expertise that uniquely position them within the global automotive market to pose an outsized risk, particularly when paired with the vulnerabilities present within certain connected vehicle systems.

1. PRC

The PRC's role in the U.S. connected vehicle supply chain presents undue and unacceptable risks. The PRC has a large and growing automotive sector that has become increasingly integrated into the ICTS supply chains of global automakers, providing the PRC automotive sector with potential increased access to the U.S. automotive market. Further, the PRC's automotive sector has historical and ongoing links to the PRC military and is influenced by pervasive government intervention, including through legal and regulatory structures that increase government oversight of and control over PRC-based companies and their foreign subsidiaries.
See
Du Xiaoying and Wang Siyi, Dongfeng plays pivotal role in supporting China's military,
China Daily
(Sept. 25, 2015),
https://www.chinadaily.com.cn/cndy/2015-09/25/content_21976945.htm;
Matthew Funaiole, et al., China Accelerates Construction of `Ro-Ro' Vessels, with Potential Military Implications,
Center for Strategic and International Studies
(Oct. 11, 2023),
https://chinapower.csis.org/analysis/china-construct-ro-ro-vessels-military-implications/
(describing the involvement of Chinese automakers in the production of “ro-ro” vessels and the dual-use applications of ro-ro vessels, including clear evidence that the PRC military intends to utilize ro-ros to support military operations). Moreover, the PRC possesses advanced cyber espionage capacities that it exercises through both state and non-state cyber actors, exacerbating such risks.
See
Simon Handler, The 5x5-China's cyber operations,
The Atlantic Council
(Jan. 2023),
https://www.atlanticcouncil.org/content-series/the-5x5/the-5x5-chinas-cyber-operations/.

First, the size and scale of state control in the PRC auto sector poses outsized risks, increasing the vectors by which the national security threats associated with connected vehicles can enter the United States. The PRC automotive sector has played an important role in its domestic industrial policy since 1986, when the sector was first named a “pillar industry” in the Seventh Five-Year Plan. The Fourteenth Five-Year Plan, the latest strategic framework for the PRC, continues to prioritize the technological innovation and sustainable development of the automobile market, including new energy vehicles and connected vehicle software and hardware systems, as key priorities.
See
Ben Murphy, Outline of the People's Republic of China 14th Five-Year Plan for National Economic and Social Development and Long-Range Objectives for 2035,
Center for Security and Emerging Technology,
at 22-23 (May 2021),
https://cset.georgetown.edu/wp-content/uploads/t0284_14th_Five_Year_Plan_EN.pdf.
For many years, the state has pursued policies and practices to further its industrial policy objectives in the automotive sector, including mandatory joint venture requirements, foreign equity restrictions, massive subsidies, and other financial support measures. The PRC automotive sector's growth is also led in part by several prominent state-owned firms, some of which began as military equipment suppliers (
e.g.,
Dongfeng, Sichuan Auto Works, Shanxi Auto Works).
See
Mattias Holweg, Jianxi Luo, and Nick Oliver, The past, present and future of China's automotive industry: a value chain perspective,
International Journal of Technological Learning,
Innovation and Development 2, at 14 (Feb. 2009),
https://www.pure.ed.ac.uk/ws/portalfiles/portal/7765689/Oliver.pdf.
In recent years, this growth and development has led to a massive surge in domestic vehicle production, with Chinese vehicle production increasing by 1.5 times over the 15-year span between 2008 and 2023. Indeed, in 2023, the PRC alone was responsible for nearly 33 percent of global passenger vehicle production.
See
VDA, Global passenger vehicle production in 2023, by country [Graph], (Retrieved July 23, 2024),
https://www.statista.com/statistics/277055/global-market-share-of-regions-on-auto-production/;
OICA & Statista, China's share in global vehicle production from 2008 to 2021 [Graph], (Mar. 17, 2022),
https://www.statista.com/statistics/233942/chinas-share-of-global-production-capacity-of-the-automobile-industry/.

Amid this significant growth in the PRC's domestic auto industry, Chinese automakers, both state-owned and private firms, have leveraged their significant state-backed support, including subsidies, to fuel a global expansion that has seen Chinese automakers establishing foreign operations in countries like South Africa, the Netherlands, Thailand, Japan, and Brazil, among others, increasing the risks stemming from PRC auto manufacturing in third countries.
See
Daisuke Wakabayashi and Claire Fu, China E.V. Makers Rush In and Upend a Country's Entire Auto Market,
The New York Times
(Jul. 30, 2024
), https://www.nytimes.com/2024/07/30/business/chinese-electric-vehicles-thailand.html;
Daniel Leussink, BYD's Global expansion push runs into stiff Japan test,
Reuters
(Sept. 4, 2024),
https://www.reuters.com/business/autos-transportation/byds-global-expansion-push-runs-into-stiff-japan-test-2024-09-05/;
China's BYD starts construction on manufacturing complex in Brazil,
Reuters
(Mar. 5, 2024),
https://www.reuters.com/business/autos-transportation/chinas-byd-starts-construction-manufacturing-complex-brazil-2024-03-06/.

The global expansion of the PRC auto sector's operations in foreign markets and recent foreign investment announcements indicate that Chinese automakers could attempt to enter the U.S. market via exports from third-party countries. Exports from third-party countries of vehicles with Chinese ICTS would expand the scope of the risk that Chinese ICTS poses to U.S. national security.
See
Paul Wiseman, Prospect of low-priced Chinese EVs reaching US from Mexico poses threat to automakers,
The Associated Press
(June 27, 2024),
https://www.ap.org/news-highlights/spotlights/2024/prospect-of-low-priced-chinese-evs-reaching-us-from-mexico-poses-threat-to-automakers/;
Daina Beth Solomon, Chinese automaker BYD looking for Mexico plant location,

executive says,
Reuters
(Feb. 28, 2024),
https://www.reuters.com/business/autos-transportation/chinese-carmaker-byd-launches-low-cost-dolphin-mini-ev-mexico-2024-02-28/.
Some PRC-based companies have announced plans to establish manufacturing facilities in Mexico, which could enable them to receive favorable trade terms contained in the U.S.-Mexico-Canada Agreement (USMCA).
See id.
Therefore, the PRC's growing presence within the global auto sector, particularly via operations in third-party countries, is expected to expand the number of potential nexus points between PRC connected vehicle suppliers and U.S. automakers and consumers, further undermining U.S. national security.

Second, the military linkage between the PRC government and the automotive sector continues to the current day with the PRC's military-civil fusion strategy, which seeks to, among other goals, exploit investment and innovation within the PRC's private sector to achieve military modernization goals. The military-civil fusion strategy prioritizes specific information and communication technologies and services that are integral to connected vehicle supply chains (
e.g.,
telecommunications, artificial intelligence).
See
Ben Murphy, Translation for Outline of the People's Republic of China 14th Five-Year Plan for National Economic and Social Development and Long-Range Objectives for 2035,
Center for Security and Emerging Technology,
at 11 and 36 (May 2021),
https://cset.georgetown.edu/wp-content/uploads/t0284_14th_Five_Year_Plan_EN.pdf.
Strategies to achieve these goals include mandating collaboration between PRC-based companies and the military and establishing public and private firms as vectors to facilitate technology transfer, industrial espionage, and intellectual property (IP) theft that would be advantageous for the PRC military.
See
Office of the Dir. of Nat'l Intelligence,
Annual Threat Assessment of the U.S. Intelligence Community,
at 6-10 (Feb. 6, 2023),
https://www.odni.gov/files/ODNI/documents/assessments/ATA-2023-Unclassified-Report.pdf.

Third, even beyond military-civil fusion, the role of the PRC government in the auto sector has only grown as government intervention in the market increases. For example, the PRC intervenes in the auto market through direct ownership of prominent industry participants, the purchasing of so-called “golden shares” to gain significant levels of influence within otherwise private firms, embedding Chinese Communist Party (CCP) representatives within corporate boards and management, and the forceful application, or threat, of the PRC's expansive security laws, including its digital era legal structure.
See
Lingling Wei, China's New Way to Control Its Biggest Companies: Golden Shares,
Wall Street Journal
(Mar. 2023),
https://www.wsj.com/articles/xi-jinpings-subtle-strategy-to-control-chinas-biggest-companies-ad001a63.
Laws promulgated in recent years provide the PRC government increased oversight and control over PRC-based companies and their foreign subsidiaries, providing a lever for influence over corporate operations that further exacerbates the threat that the PRC poses to U.S. national security. These laws require PRC-based companies, wherever located, to comply with certain access and information requests upon demand from the PRC and therefore could be used by the PRC to obtain business or other data from PRC-based companies involved in the connected vehicle supply chain. Companies operating under these laws frequently highlight the lack of transparency, consistency, clarity, and predictability of the enforcement of these laws, publicly stating that PRC laws relating to cybersecurity, data storage, or cryptography are not subject to the same degree of judicial accountability as they might be in other jurisdictions. In particular, BIS notes the PRC may utilize a suite of national security laws (
e.g., Counter-Espionage Law of the People's Republic of China
[promulgated by the Standing Committee of the National People's Congress, Nov. 1, 2014, amended Apr. 26, 2023, effective July 1, 2023];
National Security Law of the People's Republic of China
[promulgated by the Standing Committee of the National People's Congress, July 1, 2015, effective July 1, 2015];
National Intelligence Law of the People's Republic of China
[promulgated by the Standing Committee of the National People's Congress, June 27, 2017, effective June 28, 2017, amended Apr. 27, 2018];
Anti-Terrorism Law of the People's Republic of China
[promulgated by the Standing Committee of the National People's Congress, Dec. 27, 2015, effective Jan. 1, 2016, amended Apr. 27, 2018]) to compel companies, including those in the connected vehicle supply chain, to support national security efforts—which are more broadly defined in the PRC than in the United States—or military agents upon request. The PRC pursues its broad national security and geopolitical objectives through the creation of backdoors and security vulnerabilities in products sold abroad, and, in many cases, the PRC prohibits companies from disclosing that such a request was made.
See
U.S. Department of Homeland Security,
Data Security Business Advisory: Risks and Considerations for Businesses Using Data Services and Equipment from Firms Linked to the People's Republic of China,
(Dec. 2022),
https://www.dhs.gov/sites/default/files/publications/20_1222_data-security-business-advisory.pdf;
Ministry of Civil Affairs of the People's Republic of China,
National Security Law of the People's Republic of China,
Arts. 25 and 77, promulgated by the 12th National People's Congress on July 1, 2015,
https://www.mca.gov.cn/zt/n2643/n2647/c1662004999979993333/content.html.
Additionally, PRC authorities have established a regulatory system that effectively allows them to stockpile cyber vulnerabilities. Entities subject to these regulations, including automotive systems manufacturers, are required to report vulnerabilities upon discovery to PRC authorities before patching them.
See
Cyberspace Administration of China,
Provisions on the Management of Security Vulnerabilities of Network Products,
(July 2021),
https://www.cac.gov.cn/2021-07/13/c_1627761607640342.htm.
This requirement drastically increases the ability of the PRC government and PRC-backed cyber actors to take action against the United States using connected hardware and its associated software by creating an accessible library of known and potentially unpatched vulnerabilities.

Fourth, the PRC has demonstrated a high level of competency in cyber malfeasance. For instance, PRC state-sponsored cyber group Volt Typhoon has proven capable of infiltrating the IT networks of critical U.S. infrastructure using sophisticated tactics, techniques, and procedures such as Living Off the Land Techniques to pre-position themselves across U.S. critical infrastructure and military assets to carry out advanced reconnaissance in IT systems. At a later point, once advanced reconnaissance is conducted, they are then capable of launching cyberattacks to impede U.S. decision making, induce social panic, and interfere with the deployment of U.S. military forces.
See
Cybersecurity & Infrastructure Security Agency,
PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure,
at 1-5 (Feb. 2024),
https://www.cisa.gov/sites/default/files/2024-03/aa24-038a_csa_prc_state_sponsored_actors_compromise_us_critical_infrastructure_3.pdf.
A 2022 Annual Report to Congress by the U.S.-China Economic and Security Review Commission found that the PRC's ability and willingness to “weaponize” its own industries, particularly its cybersecurity industry, grants the country an asymmetric advantage over the United States. This argument is supported by public reporting detailing the methods by which known government-affiliated cyber threat groups utilize private firms to carry out their attacks.
See
U.S.-China Economic and Security Review Commission,
2022 Annual Report to Congress,
at 11 and 14-15 (Nov. 2022),
https://www.uscc.gov/sites/default/files/2022-11/2022_Annual_Report_to_Congress.pdf;
Christian Shepherd, et al., Leaked files from Chinese firms show vast international hacking efforts,
The Washington Post
(Feb. 22, 2024),
https://www.washingtonpost.com/world/2024/02/21/china-hacking-leak-documents-isoon/.
Additionally, a 2012 report from the United States Senate Permanent Select Committee on Intelligence examining the national security risks posed by the PRC-based companies Huawei and ZTE specifically argued that there are numerous opportunities for PRC-based threat actors to insert malicious hardware or software components into ICTS products throughout the product development stage.
See
Permanent Select Committee on Intelligence,
Investigative Report on the U.S. National Security Issues Posed by Chinese Telecommunications Companies Huawei and ZTE,
at 3 (Oct. 2012),
https://intelligence.house.gov/sites/intelligence.house.gov/files/documents/huawei-zte%20investigative%20report%20(final).pdf.
This risk is further demonstrated by a study of designed vulnerabilities in products conducted by the Georgetown Security Studies Review, which outlines five years of persistent insertion of malicious code by PRC-based threat actors.
See
Ryan Neauhard, Flawed by design electronics with pre-installed malware,
Georgetown Security Studies Review,
at 2 (May 23, 2018),
https://georgetownsecuritystudiesreview.org/2018/05/23/flawed-by-design-electronics-with-pre-installed-malware/.
Given the above, the PRC's access to the U.S. connected vehicle supply chain through its growing automotive sector, military-civil fusion and other corporate governance policies and legal institutions, paired with its development of mature cyber espionage capabilities, present a significant risk that the PRC could alter the systems in or obtain and manipulate data about market participants who use connected vehicle ICTS designed, developed, manufactured, or supplied by persons owned by, controlled by, or subject to the jurisdiction or direction of the PRC.

2. Russia

The Russian state has prioritized the growth of its automotive manufacturing industry, instituted a legal and regulatory framework to compel company data sharing with the state, and maintained a long history of malicious cyber operations against the United States. Under these circumstances, there is an increasing likelihood that Russia emerges as a supplier of connected vehicles technologies for the U.S. market, providing the Russian government a means of exploiting U.S. connected vehicles. Incorporating Russian hardware or software into the U.S. connected vehicle supply chain, therefore, poses undue and unacceptable risks to U.S persons and critical infrastructure.

First, while Russia has historically been less active in the global automotive sector than the PRC, the Russian government has recently sought to revitalize its domestic auto manufacturing industry following the exodus of foreign automakers after the imposition of significant additional sanctions in 2022 in response to the conflict in Ukraine. In 2024 alone, the Russian auto market is projected to experience a 15 percent increase in passenger vehicle sales, marking a notable uptick since the Russian market crashed in 2022 following the imposition of sanctions, and some Russian auto manufacturers have continued introducing new models even amid broader economic headwinds.
See
Russia's 2024 car sales forecast raised to 1.45mln, units, AEB says,
Reuters
(July 3, 2024),
https://www.reuters.com/business/autos-transportation/russias-2024-car-sales-forecast-raised-145-mln-units-aeb-says-2024-07-03.
Russia's domestic auto sector has begun to show signs of resilience, with at least one automaker releasing a new, primarily domestically developed model since the imposition of Western sanctions, even as other domestically sold models are manufactured in the PRC but undergo final assembly in Russia.
See
Gleb Stolyarov and Alexander Marrow, Focus: Made in Russia? Chinese cars drive a revival of Russia's auto factories,
Reuters
(July 20, 2023),
https://www.reuters.com/business/autos-transportation/made-russia-chinese-cars-drive-revival-russias-auto-factories-2023-07-20/.
In Russia, the revitalization of the domestic economy, particularly the domestic auto sector, has become a key focus of the Russian government since the imposition of sanctions in recent years. The Russian government has released several plans that prioritize the development of its domestic automotive market with a particular focus on research and development of new technology, including autonomous vehicles and V2X (“Vehicle to Everything”) vehicle connectivity systems.
See
Russian Federation,
Order of the Government of the Russian Federation of December 28, 2022 No. 4261-r On Approval of the Strategy for the Development of the Automotive Industry of the Russian Federation until 2035
(Jan. 4, 2023),
https://www.garant.ru/products/ipo/prime/doc/405963861/#1000;
Russian Federation,
Order of the Government of the Russian Federation of August 23, 2021 No. 2290-r On Approval of the Concept for the Development of Electric Vehicle Production and the Transport Strategy of 2030
(2023),
http://static.government.ru/media/files/bW9wGZ2rDs3BkeZHf7ZsaxnlbJzQbJJt.pdf.
The development of these interlocking national transportation and automotive industry strategies involves stakeholders from domestic automakers, technology sectors, and the Russian government, illustrating a coordinated effort across the Russian state and its domestic automotive industry. In order to extend the reach of the state into the Russian auto industry, in February 2024, Russia established a state-owned corporation named Rosavto that will act as liaison between government and industry.

Rosavto will develop production plans for vehicles and automotive spare parts, oversee the development of new models and technologies, and manage order distribution, legislative initiatives, and workforce training.
See
Eugene Gerden, New State Corporation to Oversee Russian Auto Industry,
Wards Auto
(Feb. 2024),
https://www.wardsauto.com/regulatory/new-state-corporation-to-oversee-russian-auto-industry.
Further, Russia has demonstrated resilience against Western sanction and export control regimes while also continuing to grow its electric vehicle market. See Carnegie Endowment,
Why Russia Has Been So Resilient to Western Export Controls,
(Mar. 2024),
https://carnegieendowment.org/research/2024/03/why-russia-has-been-so-resilient-to-western-export-controls?lang=en.
According to market reporting, the Russian electric vehicle market has had a robust performance, with double digit growth in output and sales, largely driven by a surge in the sector's exports.
See
Russia Automotive Market Report—Analysing EVE Trends and Car Sales Volume Data,
Global Monitor
(retrieved Nov. 2024),
https://www.globalmonitor.us/product/russia-automotive-market.
Projections suggested that with the support of the government, the electric vehicle subsector is poised for further growth.
See id.
Concerted efforts by the Russian government to develop the domestic Russian automotive industry, a growing electric vehicle market, and resilience to western sanction and export control regimes increase the likelihood that Russia-linked connected vehicle technology, such as VCS hardware or covered software, will enter the U.S. connected vehicle supply chain, which, as described below, presents an undue or unacceptable risk to U.S. national security. Given these factors, BIS is taking proactive measures to mitigate any risk posed by Russia's influence over the U.S. connected vehicle supply chain and to prevent Russia from gaining increasing influence over the U.S. connected vehicle supply chain in the future.

Second, like the PRC, the Russian government employs a suite of laws that enable it to compel domestic companies with overseas operations to provide data gleaned through foreign ventures or to surrender similar operational assets to the Russian state. These laws (
e.g.,
Russian Law Federal Security Service No. 40-FZ, “Operational-Investigative Activity” No. 144-FZ, 2014 Amdt. to No. 97-FZ) allow the Russian government direct control over Russian corporations' activities and facilities, including data or customer information, and mandate that companies assist with counterintelligence actions as requested by the state, including the Federal Security Service of the Russian Federation (FSB). The FSB can, in some cases, mandate that companies allow the FSB to install equipment on their infrastructure or collect data. Firms that are required to facilitate this surveillance or intrusion activity can also be required to actively obfuscate such requests and must provide the state with any information essential to the decryption of any communications captured. Together, these laws enable the Russian state to collect and exploit sensitive data on or about U.S. persons via Russian businesses and, should Russian companies become more prominent in the connected vehicle supply chain, create a pathway through which the Russian government could secure wide-ranging access to the vast amounts of data collected and processed by connected vehicles in the United States.
See
internet Governance,
Report of Peter B. Maggs,
(Dec. 2017),
https://www.internetgovernance.org/wp-content/uploads/12-7-Exhibit-AR-Part-6-Maggs-report.pdf.
Public reports have consistently raised concerns about Russian government laws concerning data collection, citing a lack of appropriate safeguards to prevent misuse, including judicial or public oversight. More broadly, reports have repeatedly documented the uneven application of the rule of law, lack of judicial accountability, recurrent violations of judicial proceedings, and challenges with judicial independence.
See
Justin Sherman, Russia is weaponizing its data laws against foreign organizations,
Brookings
(Sept. 2022),
https://www.brookings.edu/articles/russia-is-weaponizing-its-data-laws-against-foreign-organizations/;
Evegeni Moyakine and A. Tabachnik, Struggling to strike the right balance between interests at stake: The `Yarovaya,' `Fake news,' and `Disrespect' laws as examples of ill-conceived legislation in the age of modern technology,
Computer Law & Security Review,
at 40 (Apr. 2021),
https://www.sciencedirect.com/science/article/pii/S0267364920301175.

Third, apart from the risks presented by the Russian government access as codified in Russia's legal framework, the country has a longstanding pattern of utilizing cyber operations to gain illicit access to systems that advance the strategic ends of Russian authorities. For example, in December 2020, the company SolarWinds announced it was the target of a two-year-long cyber operation perpetrated by Russian hackers in the Russian Foreign Intelligence Services (SVR).
See
U.S. Securities and Exchange Commission,
SEC Charges SolarWinds and Chief Information Security Officer with Fraud, Internal Control Failures,
(Oct. 2023),
https://www.sec.gov/newsroom/press-releases/2023-227.
The perpetrators of the SolarWinds supply chain attack used a software update to deliver malware to the platform's users after Russian intelligence services obtained covert access to the computer systems on which the platform was installed. The attack ultimately impacted more than 18,000 users, including more than 100 companies and nine U.S. Government agencies. This attack credibly demonstrates how Russian actors can infiltrate global enterprise systems via software updates and exemplifies how they could similarly leverage software as a means to exploit connected vehicles in the United States. Additionally, a 2023 Cyber Security Advisory suggests that exploitation of information technology firms and their software will be a persistent tactic leveraged by the Russian government to collect intelligence.
See
Joint Cyber Security Advisory,
Russian Foreign Intelligence Service (SVR) Exploiting JetBrains TeamCity CVE Globally,
at 3 (Dec. 2023),
https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-347a.
BIS has further identified Kaspersky Lab as an example of the risks imposed by Russia's ability to leverage software companies to allow Russia the ability to collect and weaponize the personal information of Americans.
See
Bureau of Industry and Security,
Final Determination: Case No. ICTS-2021-002, Kaspersky Lab, Inc.
(June 2024),
https://www.federalregister.gov/documents/2024/06/24/2024-13532/final-determination-case-no-icts-2021-002-kaspersky-lab-inc.

These political, legal, and regulatory frameworks, combined with the demonstrated capabilities of Russia to exploit ICTS supply chains through malicious cyber activity, exacerbate BIS's concern that the threats posed by Russia could be directed at the U.S. connected vehicle supply chain, including integral systems such as VCS and ADS. The persistent connectivity and software-driven capabilities of VCS and ADS, combined with the vast amounts of data that traverse these systems, make them valuable and likely targets for the Russian government to compromise.

c. Consequences

Taken together, VCS and ADS designed, developed, manufactured, or supplied by persons under the ownership, control, jurisdiction, or direction of the PRC or Russia manifest undue and unacceptable risks to United States national security and to the safety and security of U.S. persons in several ways. If left unaddressed, the interaction of threats and vulnerabilities could result in the exfiltration of sensitive U.S. persons' data to foreign adversaries or the remote or automated manipulation of connected vehicles by the PRC and Russia, among other concerns.

First, the integration of compromised VCS or ADS into a completed vehicle could undermine the reliability of a connected vehicle or its underlying control systems. Compromised components in VCS or ADS could result in increased frequency and severity of connected vehicle malfunctions that could, in turn, detrimentally impact U.S. national security, including the resiliency of U.S. critical infrastructure, or the safety of U.S. persons.

Given the persistent connectivity of VCS and ADS and the essential functions that they serve in the operation of connected vehicles, these systems, if compromised and co-opted by an adversary, could serve as the nodes through which a foreign actor could probe or breach broader ICTS systems within the United States. Remote malicious cyber activities—which rely on network connectivity (
e.g.,
Wi-Fi, Bluetooth, 3/4/5G networks)—have increased significantly in recent years and consistently outnumber malicious cyber activities carried out through physical access to devices since at least 2010, accounting for 95 percent of all malicious cyber activities in 2023.
See
Upstream,
Upstream's 2024 Global Automotive Cybersecurity Report
(2024),
https://upstream.auto/reports/global-automotive-cybersecurity-report/.
Considering the increasingly sophisticated methodologies employed by foreign adversaries to gain access to critical U.S. cyber infrastructure, compromised VCS and ADS, with their inherent connectivity, would easily present another attack surface for foreign adversaries to exploit. As detailed in the previous analysis of vulnerabilities inherent in VCS, adversaries with access to VCS, such as telematics systems, could inject malicious code into a vehicle's operational systems. Additionally, such malware could be developed in such a way as to exploit vehicle connectivity to propagate itself across multiple systems as the vehicle travels and connects to those discrete systems. In this way, not only would the ICTS integral to connected vehicles be compromised, but vehicle systems could be exploited to spread malware with the intent of harming all ICTS systems to which a vehicle connects.
See
Anastasios Giannaros, et al., Autonomous Vehicles: Sophisticated Attacks, Safety Issues, Challenges, Open Topics, Blockchain and Future Directions,
Journal of Cybersecurity and Privacy 3.3,
at 505 (2023).

Second, as discussed, both VCS and ADS have significant control over and access to critical vehicle functions, including steering, braking, speed control, ignition, and almost all other mechanical functions of the vehicle. Such extensive control over vehicle operations could enable a foreign adversary to use a compromised VCS or ADS component to hamper vehicle functions or even to manipulate a connected vehicle for malicious purposes. As VCS and ADS control or link to integral vehicle functions, a foreign adversary could even exploit compromised VCS or ADS components to impair or disable a connected vehicle while in transit. Disabled, impaired, or otherwise improperly functioning vehicles could result in grave damage or impediment to critical infrastructure within the United States or could result in physical harm to U.S. persons. A disabled, impaired, or erratically functioning connected vehicle, or potentially multiple connected vehicles all experiencing problems simultaneously, could cause traffic patterns that would effectively block critical transportation arteries. This scenario could also cause collisions, ultimately damaging transportation features (
e.g.,
roadways, bridges, tunnels), energy, telecommunications, and similar infrastructure situated near transportation systems. The potential consequences of widespread connected vehicle impairment could be particularly acute if the targets were fleet vehicles operating in support of infrastructure vital to transportation, energy, water, waste, telecommunications, and other essential services.

The risks to the resiliency of critical U.S. infrastructure posed by connected vehicle components designed, developed, manufactured, or supplied by persons that are owned by, controlled by, or subject to the jurisdiction or direction of the PRC or Russia are further compounded by the potential for VCS and ADS to collect data on infrastructure. Advances in VCS and ADS necessitate increasingly cutting-edge sensor suites incorporating radar, LiDAR, camera, sonar, and computer vision to gather information on the surrounding environment for both onboard computing and remote cloud computing to process data in informing vehicle operating decisions.
See
Anastasios Giannaros, et al., Autonomous Vehicles: Sophisticated Attacks, Safety Issues, Challenges, Open Topics, Blockchain and Future Directions,
Journal of Cybersecurity and Privacy 3.3,
at 515 (2023); Luis Hernandez, et al., Applications of Cloud Computing in Intelligent Vehicles,
Journal of Artificial Intelligence and Machine Learning in Management,
at 12-13 (2022). This vast wealth of data, collected over time by multiple vehicles, likely contains valuable information such as location data about critical U.S. infrastructure. For example, data gathered from GPS or global navigation satellite systems (GNSS) in a connected vehicle could be cross-referenced and collated with a multitude of other data to produce information about the location, function, and operational trends of various transportation, energy, or other critical infrastructure.
See
Cybersecurity & Infrastructure Security Agency,
Autonomous Ground Vehicle Security Guide: Transportation Sector,
at 1 (2021),
https://www.cisa.gov/sites/default/files/publications/Autonomous%2520Ground%2520Vehicles%2520Security%2520Guide.pdf;
Cybersecurity & Infrastructure Security Agency,
Cybersecurity and Physical Security Convergence,
at 1 (2020),
https://www.cisa.gov/sites/default/files/publications/Cybersecurity%2520and%2520Physical%2520Security%2520Convergence_508_01.05.2021.pdf.
A foreign adversary could extract such critical infrastructure data using its control over designers, developers, manufacturers, or suppliers of VCS and ADS components subject to the foreign adversary's ownership, control, jurisdiction, or direction, thereby increasing the risk and precision of attacks on such critical infrastructure.

Finally, given the volume of information collected by vehicles to support VCS and ADS operation, exploitation of these systems could enable an adversary to cull a tremendous amount of data on vehicle movement across the United States. This information could potentially include data generated on or from fleet vehicles used by emergency response, law enforcement, or the military. This data, and particularly all metadata and

derived data that can be drawn from the raw data, can provide considerable insight into fleet size, composition, and capabilities, as well as information on organizational response times and response procedures. Such information would prove valuable to an adversary seeking to disrupt U.S. emergency response operations. Any potential risks to U.S. national security arising from disrupting emergency response activities are further compounded by the potential for an adversary to exploit access to VCS and ADS to leverage the persistent connectivity required for malign operations, including exploits to trigger improper engine shutdown, brake activation, or electrical system deactivation. Any of these actions would have serious consequences for U.S. persons' health and safety. VCS and ADS, if corrupted by the producer at the direction of a foreign adversary, could improperly access driver mobile devices to collect, exfiltrate, and exploit personally identifiable information (PII) or even protected health information (PHI). It is also possible that a foreign adversary could use covert access to VCS and ADS to provide false or misleading operational information to a driver, causing degraded and dangerous vehicle operation conditions. Such tactics could be used either indiscriminately to sow panic and cause disruption, or to intentionally target specific drivers. Additionally, and as noted by the Office of the Director of National Intelligence in the 2024 National Counterintelligence Strategy, foreign adversaries, like the PRC and Russia, view this kind of PII and PHI as particularly valuable as it provides them “not only economic and R&D benefits, but also useful [counterintelligence] information, as hostile intelligence services can use vulnerabilities gleaned from such data to target and blackmail individuals.”
See
The Director of Nat'l Intelligence,
2024 National Counterintelligence Strategy
(Aug. 2024),
https://www.dni.gov/files/NCSC/documents/features/NCSC_CI_Strategy-pages-20240730.pdf.

Even when such systems are not subject to compromise, companies owned by, controlled by, or subject to the jurisdiction or direction of a foreign adversary, if occupying certain positions within the supply chain, may potentially legally gain access to their users' personal data. For example, one prominent Chinese auto manufacturer with operations in the United States publicly states in its U.S. privacy policy that the personal data it may collect (
e.g.,
identifiers, customer records information, internet or other electronic network activity information, geolocation information, professional or employment-related information) is only stored in the United States in principle, but goes on to note that personal data may be transferred to its headquarters in China for processing and storage. While the incorporation in the U.S. supply chain of VCS hardware and covered software designed, developed, manufactured, or supplied by persons owned by, controlled by, or subject to the jurisdiction or direction of the PRC or Russia poses one type of risk, transactions involving VCS hardware and covered software pose a separate risk when the connected vehicle manufacturer is, itself, owned by, controlled by, or subject to the jurisdiction or direction of the PRC or Russia, even when the connected vehicle manufacturer is located in the United States. Connected vehicle manufacturers have privileged and direct access to all systems in the vehicle, including the VCS hardware and covered software. Not only are VCS hardware and covered software built to the connected vehicle manufacturers' specifications but prior to the sale of a completed connected vehicle, connected vehicle manufacturers are able to exercise significant levels of control over that VCS hardware and covered software with little to no external oversight prior to the sale of the completed connected vehicle. Based on the foregoing, BIS assesses that ICTS transactions involving VCS hardware or covered software designed, developed, manufactured, or supplied by persons owned or controlled by, or subject to the jurisdiction or direction of the PRC or Russia—including transactions to supply the VCS hardware or covered software into the United States market as part of the sale of the completed connected vehicle—present undue or unacceptable risks to the national security of the United States within the meaning of E.O. 13873.

V. Discussion of the Final Rule

This final rule prohibits—absent a general or specific authorization otherwise—(1) VCS hardware importers from knowingly importing into the United States certain hardware for VCS (section 791.302, “Prohibited VCS hardware transactions”), (2) connected vehicle manufacturers from knowingly importing into the United States completed connected vehicles incorporating covered software, and (3) connected vehicle manufacturers from knowingly selling within the United States completed connected vehicles that incorporate covered software (section 791.303, “Prohibited covered software transactions”). These prohibitions apply to transactions when such VCS hardware or covered software is designed, developed, manufactured, or supplied by persons owned by, controlled by, or subject to the jurisdiction or direction of the PRC or Russia. The rule also (4) prohibits connected vehicle manufacturers who are persons owned by, controlled by, or subject to the jurisdiction or direction of the PRC or Russia from knowingly selling in the United States completed connected vehicles that incorporate VCS hardware or covered software (section 791.304, “Related prohibited transactions”), regardless of whether such VCS hardware or covered software is designed, developed, manufactured, or supplied by persons owned by, controlled by, or subject to the jurisdiction or direction of the PRC or Russia (collectively, “prohibited transactions”).

This rule primarily impacts market participants who could be considered VCS hardware importers or connected vehicle manufacturers, such as OEMs and importers of completed connected vehicles, as well as tier one and tier two suppliers of VCS hardware. For these entities, three compliance mechanisms—Declarations of Conformity, general authorizations, and specific authorizations—are available, depending on whether the VCS hardware importer or connected vehicle manufacturer wishes to engage in an otherwise prohibited transaction. Importantly, because VCS hardware importers and connected vehicle manufacturers frequently offer many different types of products, any one of the three mechanisms may not be available for their entire business. Rather, depending on the product, VCS hardware importers and connected vehicle manufacturers could be required to use a combination of these three mechanisms to meet their obligations under the rule.

First, Declarations of Conformity are required to be submitted to BIS by VCS hardware importers and connected vehicle manufacturers prior to importing VCS hardware or importing or selling completed connected vehicles that incorporate covered software, certifying that the VCS hardware or covered software was not designed, developed, manufactured, or supplied by persons owned by, controlled by, or subject to the jurisdiction or direction of the PRC or Russia (section 791.305, “Declaration of Conformity”). The Declarations of Conformity require VCS hardware importers and connected vehicle manufacturers to certify to BIS, once a year or whenever material

changes occur, that they are not engaging in prohibited transactions and provide certain information on the import of VCS hardware and/or the import or sale of completed connected vehicles as relevant.

Second, a general authorization could be available for VCS hardware importers and/or connected vehicle manufacturers seeking to engage in an otherwise prohibited transaction, depending on the circumstances (section 791.306, “General authorizations”). General authorizations are available only in a narrow set of circumstances in which the conditions of the otherwise prohibited transaction appropriately mitigate the level of risk associated with the particular type of transaction. In determining whether to issue a general authorization, BIS may consider any information or material BIS deems relevant and appropriate, classified or unclassified, from any Federal department or agency, or from any other source. BIS will publish general authorizations issued pursuant to this subpart on its website (
https://www.bis.gov/OICTS
) and will also publish them in the
Federal Register
. Those availing themselves of a general authorization are required to continuously monitor their use of the VCS hardware or completed connected vehicles covered by the general authorization to ensure the authorization still applies. If a change renders the transaction ineligible for a general authorization, such as a change in the vehicle's use, the VCS hardware importer or connected vehicle manufacturer is required to apply for a specific authorization and cease engaging in such transaction unless and until a specific authorization is granted.

Lastly, a specific authorization may be permitted for VCS hardware importers and connected vehicle manufacturers who wish to engage in a prohibited transaction, but do not otherwise qualify for a general authorization from BIS (section 791.307, “Specific authorizations”). Such VCS hardware importers and connected vehicle manufacturers are required to pause engaging in these transactions before they may proceed with the prohibited transaction under a specific authorization. A specific authorization will only be available in circumstances where BIS determines, based on the information submitted by the applicant as well as any information or material BIS deems relevant and appropriate, classified or unclassified, from any Federal department or agency, or from any other source, that the otherwise prohibited transaction does not present an undue or unacceptable risk to U.S. national security. However, as a condition of approving the specific authorization, BIS might impose certain requirements and mitigation measures upon the VCS hardware importers and connected vehicles manufacturers seeking to proceed with the prohibited transaction.

VCS hardware importers and connected vehicle manufacturers can appeal any of the following BIS decisions to the Under Secretary: the determination that a VCS hardware importer or connected vehicle manufacturer is ineligible for a general authorization, the denial of an application for a specific authorization, or the suspension or revocation of a previously granted specific authorization (section 791.309, “Appeals”). Further, the regulation establishes a method for VCS hardware importers and connected vehicle manufacturers to seek guidance on prospective transactions that may be prohibited through a BIS advisory opinion (section 791.310, “Advisory opinions”). BIS may also share guidance on its website for VCS hardware importers or connected vehicle manufacturers that certain activities could constitute a prohibited transaction.

In issuing this rule, BIS recognizes that Section 203(b) of IEEPA—
i.e.,
the “Berman Amendment”—limits the scope of the authority to regulate or prohibit transactions relating to “information” or “informational materials.” In relevant part, the Berman Amendment states that the “authority granted to the President by this section does not include the authority to regulate or prohibit, directly or indirectly . . . . the importation from any country, or the exportation to any country, whether commercial or otherwise, regardless of format or medium of transmission, of any information or informational materials, including but not limited to, publications, films, posters, phonograph records, photographs, microfilms, microfiche, tapes, compact disks, CD ROMs, artworks, and newswire feeds.” 50 U.S.C. 1702(b)(3). Consistent with the statute's text and purpose, as demonstrated by legislative history and context as well as judicial interpretations, BIS interprets the phrase “information or informational materials” to be limited to expressive material, consistent with the purpose of 50 U.S.C. 1702(b)(3) to protect materials involving the free exchange of ideas from regulation under IEEPA and with IEEPA's broader purpose to limit material support to adversaries. A broader interpretation of the term would enable adversaries and countries of concern to use non-expressive data to undermine our national security.

In the NPRM, BIS explained this regulation is consistent with the Berman Amendment. BIS sought comment on this issue, including whether and how to address the term “information or informational materials” in the final rule. One commenter claimed that the prohibitions included in the rule could extend beyond IEEPA's intended purpose and result in litigation risk for BIS. Therefore, according to the commenter, BIS should clarify what types of information sharing will be allowed in light of the IEEPA limitations included in the Berman Amendment. One commenter requested clarification on what types of information sharing will be allowed under the rule, including documentation of technology designs. Another commenter asked about “the information/materials—including technology design documentation—that will be permitted or required when the Berman Amendment applies.” In response, BIS notes that this rule does not add any restrictions on the sharing of technology designs, technical documentation, or similar information, nor does it remove any restrictions that may exist under any other regulation (
e.g.,
export controls). Additionally, while this rule requires regulated parties to maintain documentation relevant to their compliance with this rule, it does not prescribe any specific requirements as to what that documentation must consist of. BIS did not receive any comments requesting that specific provisions relating to information or informational materials be added to the rule.

This final rule is consistent with the Berman Amendment. Its purpose is to regulate transactions involving certain hardware and software based on functional capabilities that can be exploited by foreign adversaries, not to restrict the import or export of expressive speech and communicative works and mediums that may be carrying such expressive content. As discussed in Section IV, VCS hardware and covered software process and transmit data such as geolocation information or systems diagnostics reports, which are used to monitor and control the vehicle's safe operation, and that a foreign adversary could manipulate in ways that could impair or disable the vehicle's function, leading to dangerous outcomes that pose a harm to U.S. national security. Similarly, the functional data collected by covered software—such as high-definition mapping data of infrastructure and

roadways—would pose serious risks to that critical infrastructure if collected and exploited by a foreign adversary. This final rule “balances IEEPA's competing purposes” in “restricting material support for hostile regimes while encouraging the robust interchange of information.”
United States
v.
Amirnazmi,
645 F.3d 564, 587 (3d Cir. 2011). Thus, BIS has determined that the prohibitions in this rule are consistent with the Berman Amendment. To the extent that any parties believe that a transaction governed by this rule qualifies as “information or informational materials” that is exempt under 50 U.S.C. 1702(b)(3), they can seek clarification using the administrative processes for seeking an advisory opinion.

VI. Revisions From the Proposed Rule and Response to Comments

Each section of the final rule is discussed below, including BIS's consideration of comments received in response to the NPRM.

a. Definitions

BIS received a variety of comments regarding the definitions listed in the NPRM. In the following sections, BIS summarizes and responds to those comments, outlines the definitions for this final rule, and for some definitions, provides additional interpretation to assist readers in understanding the final definition (see section 791.301, “Definitions”). BIS notes that multiple commenters requested BIS include definitions for terms that are already defined within 15 CFR 791.1, such as U.S. person. In response, BIS emphasizes that definitions contained in 15 CFR 791.1 apply to this subpart, except where the same term is defined differently in this rule.

1. Automated Driving System

In the NPRM, BIS proposed
Automated Driving System (ADS)
to mean hardware and software that, collectively, are capable of performing the entire dynamic driving task for a completed connected vehicle on a sustained basis, regardless of whether it is limited to a specific ODD. After considering commenters' feedback, BIS has chosen to retain this definition in the final rule.

Many commenters requested clarity on the definition of
ADS,
particularly urging BIS to explicitly reference SAE International's J3016 standard in the definition. Commenters also recommended that BIS explicitly exclude Levels 1 and 2 of the SAE J3016 standard or plainly state that the regulation does not capture ADAS in the definition. Similarly, BIS received feedback to incorporate language that excludes hardware and software that are not capable of performing the entire dynamic driving task and to provide examples of these exclusions, such as steering, braking, acceleration, and speed.

BIS declines to include a reference to the current version of SAE J3016 at this time and believes that the current definition adequately covers only those systems that would fall into SAE categorization Level 3 and above. However, this does not preclude BIS from amending this rule in the future to make explicit reference to the current version (April 2021) or any future version of J3016. BIS emphasizes that in enforcing this rule, it will only consider Automated Driving Systems that meet the full definition of this rule to be in scope, and BIS believes that the details regarding the specifics of Levels 3, 4, and 5 systems contained within J3016 are useful guidance for connected vehicle manufacturers to determine if their products fall within scope. Following the effective date of this rule, entities that seek clarification if a specific piece of software is subject to the prohibitions of this rule may submit a request for an advisory opinion from BIS. Further, in response to commenters requesting that BIS explicitly state that ADAS is out of scope, BIS believes this to be unnecessary as the definition aligns with SAE J3016, which differentiates between ADAS and ADS.

Comments contained various positions on the specific exclusion or inclusion of LiDAR and other sensing systems within the prohibitions. Several commenters advised BIS to identify examples of specific components that are outside the scope of the prohibitions, such as radar and camera technology. Others advocated for the inclusion of ADS sensor technology in the prohibitions and explained that BIS should explicitly scope the prohibitions to include cameras, radar, LiDAR, Time of Flight internal sensors, ultrasonic sensors, and microphones. Commenters pointed out that LiDAR is proliferating across critical infrastructure industries and heavily sourced by foreign adversaries, further urging that LiDAR, in particular, should fall in scope of the prohibitions, including LiDAR hardware, software for sensor control, and perception software.

BIS maintains its position from the NPRM that this rulemaking will address only ADS software and not the multiple hardware systems that support or directly enable ADS operation. BIS agrees that proliferation of LiDAR and other sensing technologies from entities with a foreign adversary nexus throughout multiple critical infrastructure sectors may pose a threat to national security. However, within the limited scope of the automotive sector, and with this initial rulemaking, BIS assesses that a prohibition that focuses specifically on transactions that provide ADS software is appropriate at this time to mitigate the national security risks that they present while limiting the supply chain and economic impact. As stated in the NPRM, BIS is proposing to regulate ADS software rather than the hardware components of ADAS and ADS so as to reduce unnecessary economic impacts and supply disruption. The hardware that enables ADAS and ADS varies widely between different OEMs. ADAS and ADS hardware encompasses a wide variety of different sensors, distributed electronic control units (ECUs), centralized computing units, actuators, and signaling units, among others. These sensors and internal vehicle networking hardware rarely have independent connectivity. A rule that coherently and feasibly addresses these varied supply chains would have disproportionate economic and supply chain impacts relative to the reduction of national security risks. Further, focusing on the ADS software supply chain appropriately mitigates the national security risks that they present while limiting the supply chain and economic impact. Commenters should also refer to the discussion below on covered software for greater detail on BIS's decision to omit LiDAR from this rule. BIS's decision not to focus on sensing technologies in this rule does not preclude BIS from addressing them in a subsequent rulemaking.

Commenters recommended providing definitions for terms within the
ADS
definition, such as “operational design domain.” BIS declines to specify a definition for operational design domain as it believes this to be an industry standard term in the autonomous vehicle sector that refers to operating conditions under which an ADS or feature thereof is specifically designed to function. Additionally, BIS hopes to provide industry with additional flexibility to interpret these terms within the contexts of their own technologies, reducing the compliance burden of the rule. However, BIS emphasizes that the related definitions in J3016 are useful guidance for industry and interested entities.

One commenter also advised removing “for a completed connected vehicle” from the definition of
ADS
and adding an “ADS-equipped vehicle” to

the definition to avoid industry confusion because not all connected vehicles will have ADS. BIS maintains that the ADS-related prohibitions of the rule affect only completed connected vehicles that are equipped with ADS by the nature of how the covered software prohibition is crafted, and therefore narrowing the definition of ADS to remove “for a completed connected vehicle” is not necessary.

Commenters noted that the ADS definition includes hardware, while the prohibited transactions do not include ADS hardware. The ADS definition captures the whole of ADS, including hardware, while the regulation prohibits only ADS software and does not prohibit ADS hardware. Commenters advised removing “hardware” from the definition of ADS or providing language that clarifies that the definition of ADS generally describes what an ADS is, but not necessarily what aspects of the system are regulated by this rule. After consideration, BIS declines this suggestion. In the interest of maintaining a harmonized definition that is consistent with other Federal regulations and with industry standards such as NHTSA's Second Amended Standing General Order 2021-01 and SAE J3016, BIS maintains that inclusion of “hardware” in the definition of ADS is appropriate, even though this does not mean that the hardware of an ADS system is regulated. The structure of the covered software definition and the covered software prohibitions are the only instances of a use of the ADS definition and make clear that ADS hardware is not prohibited when designed, developed, manufactured, or supplied by entities owned by, controlled by, or subject to the jurisdiction or direction of the PRC.

One commenter requested that BIS clarify that ADS software that carries out only a single function, such as parking, be excluded from the definition of ADS. While BIS generally believes that systems that are not capable of executing the entire dynamic driving task (as required by the definition of ADS) are not covered by this regulation, BIS declines to amend the definition in this rule as such a determination would be highly fact specific. BIS emphasizes that persons seeking greater clarity may, upon the effective date of this rule, seek an advisory opinion from BIS regarding a specific transaction involving ADS software.

2. Completed Connected Vehicle

In the NPRM, BIS proposed to define
completed connected vehicle
as follows: “a connected vehicle that requires no further manufacturing operations to perform its intended function. For the purposes of this subpart, the integration of an ADS into a connected vehicle constitutes a manufacturing operation for a completed connected vehicle.” BIS chose to retain this definition of
completed connected vehicle
in the final rule based on comments, further research, and other changes to the regulation.

Some commenters, particularly from the commercial vehicle sector, argued that the proposed rule did not provide a clear definition of completed vehicle within the context of the commercial market. As discussed in the following section addressing the definition of connected vehicle, BIS recognizes the substantial compliance concerns associated with the complex commercial vehicle sector and has determined that the commercial vehicle sector will not be covered by this rulemaking. Recognizing there are substantial national security concerns in the commercial vehicle market, BIS intends to issue a new proposed rule specifically tailored to this sector.

One commenter urged BIS to substitute a new definition for “ADS-equipped connected vehicle” instead of “completed connected vehicle” in order to avoid implying that all connected vehicles contain ADS software. BIS recognizes that not all connected vehicles are ADS-equipped. However, BIS declines this suggestion because the prohibitions resulting from the regulation pertain to completed connected vehicles, as defined by the regulation, and BIS does not want to engender confusion or suggest that the prohibitions pertain only to products equipped with ADS. Therefore, BIS chooses not to integrate this recommendation into the final rule.

3. Connected Vehicle

In the NPRM, BIS proposed
connected vehicle
to mean a vehicle driven or drawn by mechanical power and manufactured primarily for use on public streets, roads, and highways, that integrates onboard networked hardware with automotive software systems to communicate via dedicated short-range communication, cellular telecommunications connectivity, satellite communication, or other wireless spectrum connectivity with any other network or device. Vehicles operated only on a rail line are not included in this definition. BIS modified its definition in the final rule based on comments from the public.

A few commenters requested clarifications or refinements for BIS's definition of a “connected vehicle.” Some commenters highlighted that other regulatory bodies, such as National Highway Traffic Safety Administration (NHTSA) and the Environmental Protection Agency (EPA), often implement separate rulemaking efforts for light/passenger vehicles and heavy/commercial vehicles. BIS has opted to exclude commercial vehicles from the final rule. As discussed elsewhere, BIS emphasizes that the national security risks associated with PRC or Russian VCS and ADS in commercial vehicles are grave, and BIS's decision to exclude commercial vehicles from this rulemaking in no way implies that these risks are lesser than in the passenger vehicle market. Rather, BIS intends to propose a separate regulation tailored to the commercial sector in the coming months.

Specifically, BIS has amended the definition of “connected vehicle,” for the purposes of this rule, to exclude vehicles with a gross vehicle weight rating (GVWR) of over 10,000 pounds, which generally aligns with the weight delineation included in definitions used by other government agencies (including the Federal Motor Carrier Safety Administration) and by industry to delineate between passenger and commercial vehicles.

One commenter also requested that BIS clarify that recreational vehicles (RVs) are not included in the definition of a “connected vehicle.” BIS declines to amend the definition as it believes RVs will largely be excluded from the regulation. First, as amended, RVs weighing over 10,000 pounds will not be captured by this rule and will instead be subject to an intended future rule covering commercial vehicles. Second, as the commenter noted, BIS intends to issue a general authorization pertaining to vehicles used on public roads for fewer than 30 days a year, which could capture additional RVs that weigh under 10,001 pounds, if manufacturers are able to verify their RVs are eligible. Manufacturers availing themselves of any future general authorization need not notify BIS of its use nor apply for the authorization, contrary to the comment's suggestion. In the future, BIS may consider whether a general authorization that specifically addresses RVs would be appropriate.

One commenter requested that BIS explicitly exclude agricultural equipment, construction equipment, and mining equipment from the definition of “connected vehicle.” BIS does not believe this modification necessary as it believes the existing definition of “connected vehicle,” which mandates that the vehicle must be manufactured “primarily for use on

public streets, roads, and highways,” and under 10,001 pounds, sufficiently excludes these vehicles from the provisions of the rule. Another commenter urged BIS to clarify that the rule does not apply to entities importing VCS hardware intended for integration into vehicles that are not covered by this rule. BIS believes that modifications to the definition of VCS and VCS hardware address this comment.

Commenters urged BIS to amend the definition of “connected vehicle” to clarify that Personal Delivery Devices (PDDs) and bicycles are not captured by the rule. BIS does not believe this modification is necessary as it does not believe PDDs nor bicycles meet the definition of a connected vehicle. PDDs and bicycles primarily operate in shoulders of roads, bike lanes, and sidewalks, which BIS does not believe meets the definition of “manufactured primarily for use on public streets, roads, and highways.” The exclusion of these devices from this regulation is further in line with Federal and State-level interpretations that have also excluded PDDs from the definition of motor vehicle and related policies.

Commenters asked that BIS clarify whether a “connected vehicle” includes a motorcycle. One commenter offered the definition of motorcycle from 40 CFR 205.151: “[A]ny motor vehicle, other than a tractor, that: (i) [h]as two or three wheels; (ii) [h]as a curb mass less than or equal to 680 kg (1499 lb); and (iii) [i]s capable, with an 80 kg (176 lb) driver, of achieving a maximum speed of at least 24 km/h (15 mph) over a level paved surface.” BIS understands and acknowledges that this definition of motorcycle fits into its definition of “connected vehicle” in this rule, meaning that motorcycles are subject to this regulation, and BIS believes that an additional definition is unnecessary to improve ease of administration of this rule. Further, BIS notes that vehicles such as electric scooters and e-bicycles are not “manufactured primarily for use on public streets, roads, and highways,” given that in most jurisdictions such vehicles cannot be ridden legally on public highways and many roads. Therefore, BIS assesses that the definitions provided are scoped appropriately.

One commenter asked BIS to clarify that the regulation does not apply to VCS hardware importers and connected vehicle manufacturers that import covered hardware intended for assembly into vehicles that are not covered by the definition of connected vehicle. In response, BIS confirms that transactions involving covered software and VCS hardware that are not integrated into a connected vehicle are not subject to this regulation. VCS hardware importers and connected vehicle manufacturers executing covered software and VCS hardware transactions that are intended to be incorporated into a connected vehicle, as defined in the final rule, are subject to this regulation.

BIS has chosen to define “connected vehicle” to mean a vehicle driven or drawn by mechanical power and manufactured primarily for use on public streets, roads, and highways, that integrates onboard networked hardware with automotive software systems to communicate via dedicated short-range communication, cellular telecommunications connectivity, satellite communication, or other wireless spectrum connectivity with any other network or device. Vehicles operated only on a rail line are not included in this definition. For the purposes of this subpart, a connected vehicle with a gross vehicle weight rating of more than 4,536 kilograms or 10,000 pounds is not included in this definition.

The primary change from the definition in the proposed rule is the inclusion of a weight constraint. This final rule has been narrowed to address vehicles under 10,001 pounds (which largely apply to the passenger vehicle market). BIS intends to supplement this rulemaking with an additional rule to address vehicles over 10,000 pounds (which largely applies to the commercial vehicle market), given the national security risks.

4. Connected Vehicle Manufacturer

In the NPRM, BIS proposed “connected vehicle manufacturer” to mean a U.S. person (1) manufacturing or assembling completed connected vehicles in the United States; and/or (2) importing completed connected vehicles for sale in the United States. Based on feedback from commenters, BIS has amended its definition of “connected vehicle manufacturer” in the final rule.

Commenters advised BIS to be more specific about who is responsible for reporting to BIS under this regulation. Commenters recommended that BIS clarify that contracting with another party to manufacture or assemble a completed connected vehicle that integrates one's own ADS or VCS for one's own business is out of scope of the regulation. BIS declines to do so. Through modifications to the
connected vehicle manufacturer
definition, BIS specifies that a person whose sole manufacturing or assembly operation is integrating ADS into an otherwise completed connected vehicle would qualify such a person as being a “connected vehicle manufacturer.” BIS also included changes to the definition of
sale
to ensure that these contracting operations are within scope of the regulation. As discussed further below relating to the modifications to the definition of
sale,
BIS has determined that contracting operations could, but may not necessarily, be a sale under the terms of this rule.

Commenters encouraged BIS to consider whether a person owned by, controlled by, or subject to the jurisdiction or direction of the PRC or Russia, whose sole manufacturing or assembly operation is integrating ADS into an otherwise completed connected vehicle, should be subject to the prohibitions in the rule and need to obtain a specific authorization before importing or selling that completed connected vehicle in the United States. BIS determined that such integration of ADS software into a completed connected vehicle by a person owned by, controlled by, or subject to the jurisdiction or direction of the PRC or Russia is an extension of the national security risk relating to covered software and intended to be restricted. In response, BIS clarifies that ADS integration into an otherwise completed connected vehicle is subject to this regulation and has updated the definition of connected vehicle manufacturer in the final rule to reflect this.

Commenters also encouraged BIS to make third-party manufacturers or assemblers operating on behalf of a U.S. entity, regardless of the origin of the ADS or VCS, exempt from this regulation. BIS rejects this request and has updated the regulation to clarify that third-party manufacturers who are persons owned by, controlled by, or subject to the jurisdiction or direction of the PRC or Russia are subject to this rule. Third-party manufacturers are an integral aspect to a connected vehicle manufacturer's overall manufacturing operations; therefore, if such third parties were persons owned by, controlled by, or subject to the jurisdiction or direction of the PRC or Russia, this would continue to perpetuate the national security risks that this rule is seeking to address.

In the final rule, BIS has chosen to define a
connected vehicle manufacturer
to mean a U.S. person who:

(1) Manufactures or assembles completed connected vehicles in the United States for sale in the United States;

(2) Imports connected vehicles for sale in the United States; and/or

(3) Integrates ADS software on a completed connected vehicle for sale in the United States.

A connected vehicle manufacturer may also be a VCS hardware importer, as defined herein, if VCS hardware has already been installed in a connected vehicle when the connected vehicle manufacturer imports it.

This modified definition clarifies BIS's intention to capture entities who purchase otherwise completed (and compliant) connected vehicles from a third party and then integrate their proprietary ADS on the vehicle to enable autonomous driving. For example, a U.S. person who purchases completed connected vehicles from a U.S. connected vehicle manufacturer (even if those vehicles do not contain PRC or Russian VCS hardware or ADS software) and then integrates its own ADS software on the vehicles would be performing a manufacturing operation and would be explicitly captured as a connected vehicle manufacturer under this amended definition. If that U.S. person is an entity owned by, controlled by, or subject to the jurisdiction or direction of the PRC or Russia, it would require a specific authorization to sell those vehicles in the United States, which includes transferring those vehicles for commercial operations. The modified definition also clarifies that the first paragraph of the definition, which relates to persons who manufacture or assemble completed connected vehicles in the United States, applies only if the vehicles are intended for sale in the United States (not for export and sale abroad).

5. Covered Software

In the NPRM, BIS proposed to define
covered software
as “the software-based components, in which there is a foreign interest, executed by the primary processing unit of the respective systems that are part of an item that supports the function of Vehicle Connectivity Systems or Automated Driving Systems at the vehicle level. Covered software does not include firmware, which is characterized as software specifically programmed for a hardware device with a primary purpose of controlling, configuring, and communicating with that hardware device. Covered software also does not include open-source software that can be freely used, modified, and distributed by anyone, with both access to the source code and the ability to contribute to the software's development and improvement unless that open-source software has been modified for proprietary purposes and not redistributed or shared.” Based on comments, BIS changed its definition of
covered software
to better align with industry practices.

Commenters commonly sought more guidance on the layers of software regulated under the rule. Commenters requested examples regarding how covered software applies to the software stack for VCS and ADS. Common feedback urged BIS to define software-based components that fall in and out of scope of the regulation, such as application, firmware, middleware, and system software. Commenters also encouraged BIS to provide a definition of these layers of software, particularly emphasizing that a definition was needed for firmware. Commenters advocated for the exclusion of embedded software (
e.g.,
middleware and system software) because the application software more directly facilitates external communications, and the embedded software is not divisible or distinguishable from hardware. Commenters also suggested that regulating embedded software would introduce more complex supply chain bottlenecks and prevent many companies from meeting the covered software prohibition within a year's time.

In response to these comments, BIS has added specificity to the
covered software
definition to explicitly include application, middleware, and system software, while continuing to exclude firmware. BIS has also included a description of fir

[Text truncated at 120,000 characters. The full text is on the page linked above.]

---

Source: Frix Law Library, https://www.frixlaw.com/law-library/documents/fr%3A2025-00592. Public record. Not legal advice.
