The Connected Vehicle Security Act of 2026 would prohibit, beginning January 1, 2027, the importation, manufacture, sale, resale, or introduction into interstate commerce of connected vehicles tied to covered foreign countries or controlled by entities with significant ownership or control from those countries. It also bars the integration of covered software into connected vehicles starting in 2027 and extends similar restrictions to connected vehicle hardware beginning in 2030, with a limited repair-and-warranty exception for pre-2030 model-year vehicles. The bill defines connected vehicles, vehicle connectivity systems, covered software, and related hardware broadly, and it expressly includes software updates, data transmission, managed services, and other ongoing transactions within its scope.
The bill gives the Secretary of Commerce, acting through the Bureau of Industry and Security, broad authority to implement the prohibitions, issue binding rulings and advisory opinions, publish lists of authorized items, require declarations of conformity, and impose civil penalties of at least $1.5 million or five times the transaction value for violations. It also allows the Secretary to prohibit additional transactions that pose an undue or unacceptable threat to U.S. economic or national security, and it permits reliance on classified information in enforcement. The measure preserves some existing Commerce Department regulations and exclusions, while directing the Secretary to review whether those exclusions should continue, be modified, or be terminated.
The bill’s stated purpose is to address national security, cybersecurity, and supply-chain risks associated with foreign adversary control over connected vehicles and their software and hardware. Its findings emphasize concerns about data collection, remote access, surveillance, espionage, cyber intrusion, and potential disruption of critical infrastructure, especially with respect to China, Russia, Iran, and North Korea. In practical terms, the bill would affect automakers, importers, suppliers, software developers, resellers, and service providers in the connected vehicle ecosystem, and it would likely require compliance screening and documentation across the automotive supply chain.
Because the bill was only introduced and referred to committee, there is no recorded vote or committee transcript in the provided materials, so no formal legislative sentiment can be measured from debate or roll call. Based on the text alone, the bill appears to be framed as a national security measure rather than a consumer or trade expansion bill, and its structure suggests strong support for restricting foreign-adversary-linked technology. At the same time, the breadth of the definitions and the Commerce Secretary’s discretionary authority indicate likely areas of concern for industry stakeholders, especially regarding compliance burdens, supply-chain disruption, and the treatment of vehicles or components with indirect foreign ownership or legacy regulatory exclusions.
Notable points of contention likely include how broadly the bill defines covered countries, foreign control, connected vehicles, and covered software; whether the ownership thresholds of 15 percent for vehicles and 25 percent for software/hardware are too expansive; and how the repair, warranty, testing, and existing-exclusion provisions will operate in practice. Another likely issue is the bill’s reliance on executive-branch determinations and classified information, which could raise transparency and due-process concerns for affected companies. The delayed implementation schedule for hardware and the authorization process may be intended to soften those concerns, but they also create a complex regulatory regime that could be debated by industry, security, and trade interests.
The bill would add a new federal restriction regime over connected vehicles and related software and hardware associated with covered foreign countries, primarily by directing the Secretary of Commerce to prohibit certain imports, sales, resales, manufacturing, and interstate commerce transactions. It would effectively expand Commerce Department authority over automotive cybersecurity and supply-chain security, while preserving and incorporating existing BIS connected-vehicle regulations and requiring new rulemakings, lists, certifications, and enforcement procedures. The measure would most directly affect automakers, importers, resellers, software developers, hardware suppliers, and service providers dealing in connected vehicle technologies.
The main points of contention are likely to center on the breadth of the prohibitions and the discretion given to the Secretary of Commerce. Industry stakeholders may object to the bill’s expansive definitions of connected vehicles, covered software, and connected vehicle hardware, as well as the ownership and control thresholds that can trigger a ban even when the vehicle or component is not directly sourced from a covered country. Additional concerns may arise over compliance costs, supply-chain disruption, the treatment of repairs and warranties, the use of classified information in enforcement, and whether the bill could sweep in benign or low-risk products that are only indirectly connected to foreign entities.