Skip to content
The ColumnCommentary· No. 1817

COMMENTARY: The FCC bans Huawei, ZTE and Hikvision — America finally closes the door on Trojan horses

On June 26, 2026, the Federal Communications Commission (FCC) of the United States voted to ban the importation of all equipment from

Premium reading
MadMax
Key takeaways
  1. On June 26, 2026, the Federal Communications Commission (FCC) of the United States voted to ban the importation of all equipment from
  2. Introduction: June 26, 2026 — a decision that closes a strategic gap
  3. The FCC and its historic vote
Transparency

Facts, quotes, and cited links remain in the body. Interpretations are framed as analysis or opinion according to the format.

Introduction: June 26, 2026 — a decision that closes a strategic gap

The FCC and its historic vote

On June 26, 2026, the Federal Communications Commission (FCC) of the United States voted to ban the importation of all equipment from companies on its Covered List. This decision closes a critical legal gap: until now, the list prohibited new equipment but allowed the sale of older models, creating a loophole that the affected companies and their distributors were actively exploiting. From now on, the ban is total and applies to all models, old and new.

The companies targeted by this ban are: Huawei, ZTE, Hikvision, Kaspersky, DJI, Autel Robotics, and TP-Link. All are identified as presenting unacceptable risks to U.S. national security. The FCC's decision is analyzed in detail in a report by the Foundation for Defense of Democracies (FDD) published on June 30, 2026. This vote is not a symbolic gesture — it is an operational measure with concrete consequences for American technology supply chains.

Why selling old models was a real problem

The gap that the June 26, 2026 decision closes deserves an explanation. Previous restrictions targeted new installations of Covered List equipment in American networks. But older models of Huawei, ZTE, and similar equipment could still be sold — notably to small rural telecommunications operators who could not afford more expensive alternatives. These operators had therefore continued deploying potentially compromised equipment in regions sometimes located near sensitive military or government installations.

This scenario is not hypothetical. The FCC documented cases of Huawei equipment installed in American rural networks near military bases and Department of Defense sites. The capacity of this equipment to intercept communications or transmit data to servers in China was assessed by U.S. intelligence agencies as a real and documented threat.

Volt Typhoon and the cyberattacks that precipitated the decision

The Volt Typhoon group and its American targets

The FCC explicitly cites repeated Chinese cyberattacks against American networks to justify its June 26, 2026 decision. Among the most documented threats: the hacking group Volt Typhoon, linked to the PLA, which has been identified as pre-positioned in American critical infrastructure — electrical grids, water systems, communications — with a presumed objective of potential sabotage in the event of conflict. This is not ordinary cybercrime: it is military preparation for massive disruption operations.

American cybersecurity agencies — CISA, NSA, and the FBI — published joint alerts on Volt Typhoon in 2023 and 2024, describing how the group had infiltrated critical infrastructure networks and maintained a discreet presence in them for extended periods. Huawei and ZTE equipment in rural networks could theoretically facilitate these operations by providing additional access points for attackers.

The threat to submarine cables carrying financial data

The FCC also cites the threat of sabotage of submarine cables carrying sensitive financial data. This dimension is less publicized than cyberattacks, but its strategic scope is considerable. Submarine cables carry more than 95% of intercontinental digital communications, including global financial transactions representing trillions of dollars daily. Their sabotage or disruption would constitute an economic weapon of extraordinary power.

Recent incidents — including suspicious cable cuts in the Baltic Sea attributed to Russian operations — have made this long-theoretical risk concrete. In the Indo-Pacific context, where China has a rapidly growing navy and documented submarine capabilities, the protection of critical submarine cables is a first-order national security issue for democracies.

Huawei, ZTE, Hikvision: why these specific companies

Documented links with the Chinese security apparatus

Huawei, the largest telecommunications company in China and one of the largest in the world, has been the subject of documented national security concerns for more than a decade. Reports from American and British parliamentary committees established links between Huawei's corporate structure, the Chinese Communist Party, and Chinese military intelligence services. China's 2017 National Intelligence Law obliges Chinese companies to cooperate with intelligence agencies on request — creating a legal obligation that Huawei has never been able or willing to contradict convincingly before Western parliamentary hearings.

ZTE has already faced U.S. sanctions for violating export regulations toward Iran and North Korea. Hikvision, the world's largest surveillance camera manufacturer, was implicated in supplying surveillance systems used in the detention camps of Xinjiang, where the UN documented serious human rights violations against the Uyghur population.

Kaspersky, DJI, and TP-Link: the diversity of threats

The inclusion of Kaspersky — a Russian cybersecurity company — on the Covered List is a reminder that threats do not come only from China. Kaspersky's antivirus and security software has access to the systems it protects — access that Russian intelligence services could theoretically exploit through legal obligations similar to those of China. In 2017, the U.S. government had already banned Kaspersky from government devices. The June 26, 2026 decision extends this approach to the civilian market.

DJI and Autel Robotics, drone manufacturers, present specific risks: their devices transmit location data and imagery to servers, some of which are located in China. DJI drones were used by American police officers and firefighters, potentially collecting data on sensitive infrastructure transmissible to Chinese servers. TP-Link, a consumer router manufacturer, was the subject of investigations for vulnerabilities in its firmware potentially exploitable by state actors.

Implications for American companies and consumers

The transition cost for small rural operators

The FCC's June 26, 2026 decision is not without cost for the American economy. Small rural telecommunications operators that had deployed Huawei or ZTE equipment for cost reasons face significant rip-and-replace expenditures. A federal funding program — the FCC's Secure and Trusted Communications Networks Reimbursement Program — exists to help these operators, but its resources are limited and do not cover all documented needs.

This transition cost is real and deserves to be acknowledged honestly. National security decisions have economic costs that end beneficiaries do not always see directly — they are distributed in phone tariffs, federal funding, and infrastructure costs. The political acceptability of these costs is easier to maintain when the avoided risks are clearly communicated to the public.

Drones, cameras, and routers: a replacement market to build

The ban on DJI, Hikvision, and TP-Link equipment creates a market space for alternatives produced by companies not belonging to countries on the Covered List. American drone manufacturers like Skydio, European camera manufacturers, and router producers based in allied countries will benefit from this opening. The FCC's decision is therefore also an indirect industrial policy — it supports the development of sovereign technological alternatives without direct subsidies.

This process takes time. Alternatives are not always immediately available at the same performance level and price as the banned Chinese products. That is precisely why decisions of this type must be made early — when alternative supply chains can still be built progressively, without the pressure of an immediate crisis.

Europe and the delayed response to Huawei

The American decision versus European hesitation

The European Union treated the Huawei question in 5G networks with a caution that often bordered on complacency. The EU's 5G Toolbox, published in 2020, recommended that member states restrict or exclude high-risk suppliers from their sensitive 5G infrastructure — without imposing a formal ban. Countries like Germany were slow to make firm decisions, partly under the pressure of the telecom operator lobby that had already deployed Huawei equipment.

The American decision of June 26, 2026 puts additional pressure on European governments that have not yet taken comparable measures. In the context of global technological rivalry and growing concerns about critical network security, maintaining Huawei equipment in sensitive networks becomes increasingly difficult to defend politically — especially after such a symbolically powerful decision by the U.S. Congress and the FCC.

The United Kingdom as a positive precedent

The United Kingdom made the decision in 2020 to completely exclude Huawei from its 5G networks by 2027 — after years of debate and hesitation. This decision, difficult economically and diplomatically, demonstrated that a major European democracy could impose firm restrictions on Huawei without the diplomatic and economic consequences being catastrophic. Sino-British relations deteriorated, but the United Kingdom demonstrated its capacity to make firm national security decisions when the evidence demanded it.

This British precedent, combined with the American decision of June 26, 2026, should accelerate similar decisions in European countries that have not yet acted. Coordination among allies is crucial here: a Europe in which some countries maintain Covered List equipment in their sensitive networks represents a weak link in the collective security of the Atlantic Alliance.

What the FDD says in its June 30 analysis

The arguments of the Foundation for Defense of Democracies

The Foundation for Defense of Democracies (FDD), in its June 30, 2026 analysis, welcomes the FCC's decision while highlighting its limits. The analysis notes that the decision closes a real gap — the sale of old models was a problematic inconsistency. But it also points to several implementation challenges: transition timelines for operators dependent on this equipment, risks of circumvention via third countries, and the need to coordinate this decision with allied policies to avoid supply chain leakage.

The FDD is an American conservative think tank whose positions on China are consistently hawkish. Its analyses on technology security deserve to be read with this lens in mind — they may overweight risks and underweight the economic costs of certain measures. But on the specific question of the Covered List, the documented facts generally confirm the concerns it raises.

Unresolved issues after the decision

The June 26, 2026 decision does not solve all the problems. It does not cover equipment already installed in American networks — its replacement remains a long and costly process. It does not apply to equipment produced in third countries by subsidiary companies of these groups. It does not automatically coordinate the American response with that of European and Asian allies, creating potential asymmetries in collective security. These real gaps do not invalidate the decision — they indicate the necessary next steps.

In particular, the risk of circumvention via third countries deserves special attention. Huawei-affiliated entities previously attempted to circumvent American restrictions by producing equipment through subsidiaries in countries not covered by the restrictions. The vigilance of the American export control agencies on this point is a prerequisite for the long-term effectiveness of the decision.

The response to the Russian and Iranian cyber threat

A decision that goes beyond China alone

The FCC included on its Covered List companies associated not only with China, but also with other states presenting risks to U.S. national security. The inclusion of Kaspersky — a Russian cybersecurity company — responds to concerns comparable to those raised for Chinese companies: legal obligations toward an authoritarian state that could demand cooperation with its intelligence services. In 2017, the U.S. government had already banned Kaspersky from government devices. The June 26, 2026 decision extends this approach to the civilian market.

Cyberattacks against water systems, electricity, and telecommunications attributed to state actors — primarily Russian, Chinese, and Iranian — all share one thing: they exploit vulnerabilities in equipment deployed in critical networks. The FCC's decision aims to reduce the attack surface by eliminating equipment whose potential vulnerabilities are tied to their governance rather than their technical architecture alone.

The specific risk to water systems and civilian infrastructure

Recent reports, including one published by Dark Reading in 2026, specifically documented how Iran, Russia, and China target American water distribution systems. These attacks — including compromises of SCADA systems controlling pumps and drinking water chemical treatment — represent a direct threat to public health. Comparable incidents have targeted healthcare facilities, dams, and traffic management systems.

The connection between these cyberattacks and Covered List equipment is not always direct — not all attacks pass through Huawei or ZTE equipment. But this equipment can provide initial access points to networks that are then laterally explored to reach critical systems. That is why eliminating these potential entry points remains a national security priority, even when the specific causal chain cannot always be publicly documented.

Conclusion: a necessary decision, but only a beginning

What the FCC's decision actually accomplishes

The FCC's June 26, 2026 decision accomplishes something real and important: it eliminates a glaring inconsistency in American network security policy. It sends a clear signal to equipment manufacturers that the United States takes seriously the risks posed by companies subject to the Chinese intelligence law. It creates a precedent that allies can cite to justify their own similar decisions. These accomplishments are real and deserve to be recognized.

What it does not accomplish: it does not resolve the question of equipment already deployed. It does not automatically coordinate a coherent allied response. It does not solve the broader problem of Western technological dependence on components manufactured in China in segments not covered by the Covered List. Those are the next challenges on the list.

The urgency of a coordinated allied response

The American decision of June 26, 2026 must be the beginning of allied coordination, not an isolated unilateral action. NATO members, Five Eyes partners, the Quad, and other U.S. technology allies all have an interest in harmonizing their equipment control policies in their critical networks. A collective security chain is only as strong as its weakest link — and as long as some allies maintain Covered List equipment in their infrastructure, collective protection remains incomplete.

The Five Eyes, which just coordinated a public alert on Chinese espionage via LinkedIn, have the existing structure to also coordinate their network equipment security policies. This coordination — technical, political, and diplomatic — is an investment in collective security whose long-term returns far exceed its cost.

Assessment and outlook

A set of decisions sketching a coherent strategy

The FCC's June 26, 2026 decision is part of a broader picture: export controls on chips, surveillance of Chinese embassies, warnings about espionage via LinkedIn, sanctions against Japanese entities by Beijing. These apparently disparate elements sketch a global technological and security competition of which network equipment is only one front among several.

The United States, despite its internal contradictions and hesitations, is progressively building a technology security architecture that takes the rivalry with China seriously. This architecture is incomplete, sometimes incoherent, and often lagging behind the pace of threats — but it exists and it is advancing. That is more than Europe can claim as a whole.

What Europe must do now

The FCC's June 26, 2026 decision is an implicit call to Europe: align with these standards or accept being the weak link in Atlantic collective security. Countries like Germany, Italy, and others that have not yet made firm decisions on Huawei and comparable equipment must accelerate their processes. The window for coordinated action with the American partner is open — it will not remain so indefinitely.

Europe's technological dependence on China in critical sectors is a strategic risk that the Old Continent can no longer afford to minimize. Decisions like the FCC's of June 26, 2026 are incentives to act — but also warnings about the growing cost of inaction.

By Maxime Marquette, columnist

Columnist's transparency note

My biases and my positioning

I am an analyst-columnist with a pro-democracy and pro-collective technology security stance for democracies. I am skeptical of Chinese technology companies operating in critical sectors and subject to the 2017 National Intelligence Law. This bias influences my reading of the FCC's decision — I support it while acknowledging its limits.

I have no financial interest in the technology sectors concerned, no government mandate, and no affiliation with the companies mentioned in this article. My analysis is based exclusively on public sources cited in the Sources section.

What I cannot verify

I do not have access to confidential technical evidence about the specific vulnerabilities of the equipment cited. Precise assessments of the espionage capabilities built into this equipment remain classified. I report the conclusions of American security agencies and publicly accessible parliamentary reports, not a direct technical evaluation of this equipment. The operational reality is probably more precise — and more troubling — than what public sources allow to be documented.

The list of risks linked to Kaspersky, DJI, and TP-Link is based on public reports from security agencies and independent researchers. These risks are probable and documented in broad strokes — but their precise technical implementation in each firmware or software version is not verifiable without analytical resources I do not possess.

Sources

Primary sources

Secondary sources

Get the geopolitics analyses

Conflicts, powers, alliances: the MadMax thread without the noise.

Cite this article

Maxime Marquette (2026). COMMENTARY: The FCC bans Huawei, ZTE and Hikvision — America finally closes the door on Trojan horses. MadMax. https://mad-max.co/en/article/commentaire-la-fcc-bannit-huawei-zte-et-hikvision-l-amerique-ferme-enfin-la-port

How does this piece make you feel?
MM
Maxime Marquette
Independent columnist

Maxime Marquette writes most of the analyses and columns published on MadMax — geopolitics, technology, and current events, no filler.

The Newsletter

Enjoyed this piece? Get the next one.

One chronicle a week, straight to your inbox. No noise.

Comments

0 / 2000

Be the first to weigh in.

This article was generated with AI assistance, under human supervision.

Commentary2840 words4 min read