US automakers are asking Congress to ban Chinese connected vehicles, hardware and software before the current session ends. The request sounds like a demand to build a new wall around the car market. Much of the first wall, however, is already scheduled.
The Commerce Department has a final rule that starts applying to covered software and manufacturers with model year 2027. The proposed Connected Vehicle Security Act would not simply repeat it. The bill would extend the named country list, codify ownership thresholds, set calendar-date prohibitions and make future relaxation more difficult. For manufacturers and suppliers, the investment question is therefore less whether restrictions are coming than which legal definitions will govern a supply chain already being redesigned.
The first barrier is already in force
The Bureau of Industry and Security's final connected-vehicle rule took effect on March 17, 2025. It prohibits certain transactions involving vehicle connectivity system hardware or covered software with a sufficient link to China or Russia. Restrictions on covered software and sales by covered connected-vehicle manufacturers begin with model year 2027. Hardware restrictions begin with model year 2030, or January 1, 2029 for units not associated with a model year.
That distinction matters because headlines about congressional action can imply that Chinese connected vehicles remain unrestricted until a new law passes. They do not. The existing rule already creates a compliance timetable for the systems that communicate outside the vehicle and for automated-driving software. BIS also requires annual declarations of conformity and provides routes for general or specific authorizations.
The current rule is an administrative measure. An administration can amend its definitions, issue authorizations or eventually replace it through another rulemaking. That flexibility can be useful when suppliers prove that a component poses little risk. It also leaves automakers exposed to policy changes over product cycles that often last longer than a presidential term.
The bill changes the legal foundation
S.4429 is still a proposal, not current law. It was introduced on April 29, 2026, and the Senate Commerce Committee said it advanced the measure unanimously on July 22. It would still need to pass Congress and be signed before its prohibitions take effect.
The introduced bill text covers China, Russia, Iran and North Korea. From January 1, 2027, it would prohibit connected vehicles originating in or designed in a covered country, as well as vehicles made by an entity with more than 15% covered-country ownership or control. Covered software would face a 25% developer ownership test from the same date. Connected-vehicle hardware would face a similar 25% manufacturer test from January 1, 2030.
Those percentages turn geopolitical policy into due diligence. A brand name or final assembly location would not answer the question. Manufacturers would need to trace equity, voting rights, board representation and other control indicators through joint ventures and subsidiaries. The proposal also reaches renamed or restructured items intended to evade the restrictions.
Statutory status changes bargaining power. The bill allows Commerce to authorize an otherwise prohibited item after a written risk assessment, consultation with other agencies and 60 days' notice to Congress. Congress could enact a joint resolution of disapproval. That is a higher and more visible process than relying only on agency discretion.
Software arrives before hardware
The staggered dates recognize that replacing code and replacing physical electronics are different industrial tasks. Software provenance can change through developers, updates, managed services and machine-learning models. The bill's definition includes AI components that directly enable automated-driving decisions or control. A vehicle program launching in 2027 therefore needs evidence not only about the software installed at sale but also about how it is maintained.
Hardware redesign requires longer qualification cycles, tooling and safety validation. The 2030 date offers more time, while a repair-and-warranty exception would preserve components for vehicles from before model year 2030. Yet the listed hardware reaches beyond a single modem: it includes networking modules, antennas, signal processors, programmable devices and certain externally communicating battery systems.
For suppliers, that creates two clocks. Software teams face the immediate gate. Purchasing teams must use the intervening years to map component origins and ownership. A company that treats 2030 as a distant purchasing deadline could discover too late that a module cannot be substituted without re-engineering a larger vehicle system.
Security and industrial policy share the same vehicle
Connected cars collect location and operational data and can receive remote commands. The security argument is therefore not hypothetical merely because domestic manufacturers also benefit. Compromised connectivity or driving systems can create surveillance, cyber intrusion and infrastructure risks at a scale unlike ordinary consumer electronics.
The industrial incentive is equally visible. The Alliance for Automotive Innovation, which represents major manufacturers and suppliers, urged Congress to enact a permanent ban on Chinese connected vehicles and high-risk hardware and software. A durable exclusion protects domestic incumbents from both security exposure and formidable Chinese cost competition. The two motives can coexist.
That overlap is the strongest reason to scrutinize scope. If a narrow risk can be addressed through auditable software isolation or a specific authorization, a blanket origin rule may remove a lower-cost supplier without materially improving security. Conversely, a component-by-component test can miss control exerted through updates, data services or corporate ownership. The policy choice is between false positives that raise cost and false negatives that preserve remote access.
Definitions will set the real cost
The proposed law would require declarations of conformity and would set civil penalties at no less than the greater of $1.5 million or five times the transaction value. That would make supplier representations, ownership records and software bills of materials financially material rather than a paperwork exercise. Investors should expect compliance spending to appear well before all hardware prohibitions begin.
Three milestones would change the analysis. First is enacted text: amendments to the 15% and 25% ownership thresholds, the covered-country list or repair exceptions could materially widen or narrow exposure. Second is Commerce guidance on binding rulings and authorizations, which would determine whether low-risk items have a practical route to market. Third is evidence from automakers that alternate suppliers have been qualified without higher warranty costs, launch delays or reduced vehicle features.
The countercase is that BIS already targets the most sensitive systems, making another layer duplicative. The case for legislation is durability and a broader definition of control. Until Congress completes its work, the administrative rule remains the operative barrier. But its 2027 start date means manufacturers cannot wait for the legislative outcome before changing software and supplier decisions.

