HB 4235 creates the “prohibited applications on government-issued devices act,” directing Michigan public employers to block and restrict certain internet applications on government-owned or leased devices issued for work use. The bill defines a prohibited application as one created, maintained, or owned by a “foreign principal” tied to specified foreign countries of concern and that poses security risks such as collecting sensitive data, enabling ransomware, cyber-espionage, surveillance, or misinformation campaigns. It also bars employees and officers from downloading or accessing such applications on government-issued devices, with a specific exception for law enforcement when use is necessary for public safety or an investigation.
The bill requires the Department of Technology, Management, and Budget to compile and maintain a public list of prohibited applications, update that list quarterly, and establish waiver procedures. Public employers may seek waivers for designated employees or officers if they can justify the activity, limit the number of devices and users, set a time limit, and describe mitigation steps to prevent access to sensitive systems. Employees and officers must remove listed prohibited applications from government-issued devices within 15 days after the department issues or updates the list, and the department must adopt rules to implement the act. The bill is scheduled to take effect December 31, 2025.
Its impact on state law is to impose a new cybersecurity and device-use compliance regime across state government, local governments, school districts, community colleges, and public universities. It gives DTMB authority to identify prohibited applications, set waiver procedures, and promulgate rules, while requiring public employers to manage network access, device restrictions, and remote-wipe capabilities. The bill would also create a direct prohibition on use by public employees and officers, subject to limited exceptions.
The general sentiment reflected in the voting history appears strongly supportive, with the bill advancing through committee on unanimous votes and passing the House 79-31. The committee record suggests broad agreement on the need to protect public systems from foreign-linked applications and cybersecurity threats. The bill’s framing as a security measure and its inclusion of waiver and law-enforcement exceptions likely helped build support.
The main points of contention are likely the breadth of the prohibition and the discretion given to the department to determine which applications qualify as prohibited. Potential concerns include whether the definition could sweep in widely used apps, how the foreign-principal standard will be applied, and whether the restrictions could interfere with legitimate government work or research. The waiver process and law-enforcement exception appear designed to address those concerns, but the 31 House no votes indicate some members remained uneasy about the scope or implementation of the restrictions.
HB 4235 would add a new state-level framework governing the use of certain internet applications on government-issued devices by public employers. It would require blocking, access restrictions, remote-wipe capability, employee removal of listed apps, and DTMB rulemaking and list maintenance, affecting state agencies, local governments, schools, colleges, and universities.
The bill appears to have received generally favorable treatment in committee and on the House floor, with unanimous committee votes and a 79-31 House passage. The available record suggests support for the bill’s cybersecurity and foreign-influence rationale, though the floor vote shows meaningful opposition from a minority of members.
The likely areas of disagreement are the scope of the term “prohibited application,” the breadth of the foreign-country-of-concern and foreign-principal definitions, and the degree of administrative discretion given to DTMB to place apps on the list. Critics may also worry about operational burdens on public employers, possible overbreadth affecting legitimate uses, and whether the restrictions could limit access to commonly used platforms. Supporters appear to emphasize security, data protection, and the need to reduce risks from foreign-linked applications.