The Federal Communications Commission (FCC) has embarked on an unprecedented regulatory journey, repurposing its long-standing equipment authorization rules, primarily designed to prevent electromagnetic interference, as a novel mechanism for governing artificial intelligence (AI) in foreign-produced robotic devices. This strategic pivot, detailed in FCC Public Notice DA 26-789, has created a complex compliance landscape that, while seemingly offering a safe harbor for existing products, may in reality be trapping manufacturers in a rapidly evolving technological environment. Kim D. Larsen of Stinson LLP highlights the critical disconnect between the FCC’s traditional technical mandates and the nuanced national security and AI governance objectives it now pursues, creating significant challenges for companies operating in this dynamic sector.

The FCC’s "covered list" initiative, which commenced its public notification phase in late 2023 and formally took effect with the July 28, 2026, deadline, aims to restrict the authorization of new AI-enabled robotic devices manufactured by certain foreign entities deemed to pose national security risks. These risks are broadly understood to encompass potential data exfiltration, surveillance capabilities, and the possibility of remote commandeering of devices. For companies that had secured FCC Part 15 equipment authorization for their foreign-produced AI-enabled robots prior to this deadline, the situation appears to offer a reprieve. Their existing models are effectively "grandfathered," allowing them to continue marketing these products. Furthermore, DA 26-789, issued in August 2026, provides a limited exception, preserving the ability to conduct qualifying software and firmware updates to these already-authorized devices until January 1, 2029. This measure, at first glance, suggests that the regulatory storm has been navigated successfully for these legacy products.

However, this perception of a secure haven is proving to be an illusion. The concept of grandfathering, while providing a temporary shield, inherently locks companies into the specific configuration of their products as approved in 2026. This creates a significant competitive disadvantage as the AI and robotics market is characterized by rapid innovation. Without the limited exceptions provided by DA 26-789, any post-authorization permissive changes, even those that would typically fall under the less stringent Class I or Class II modification categories, would be barred by the covered list prohibitions. This essentially freezes the technological capabilities and operational parameters of these grandfathered devices, while competitors, particularly those with domestic manufacturing and supply chains, are free to develop and deploy more advanced AI models, integrate new services, and implement continuous learning capabilities.

A Structural Mismatch: From EMI to National Security

The core of the issue lies in a fundamental structural mismatch between the FCC’s established Part 15 equipment authorization framework and the complex, multifaceted risks associated with AI-enabled robotics. The Part 15 system was meticulously crafted over decades to address a specific technical challenge: preventing electromagnetic interference (EMI) that could disrupt radio communications. Its rules, such as Sections 2.932 and 2.1043, govern post-authorization changes by focusing on deviations from FCC-authorized technical and radio frequency (RF) characteristics. These regulations are designed to ensure that modifications do not introduce new sources of EMI or degrade the device’s compliance with existing RF emission standards.

The current administration’s decision to leverage this system as a national security chokepoint for AI governance represents a significant repurposing. The goal has shifted from managing RF spectrum integrity to assessing and mitigating potential threats related to data security, privacy, and operational control of advanced robotic systems. This shift has created a critical gap between the risks the FCC now seeks to manage – which are deeply intertwined with AI’s intelligence, autonomy, and data handling capabilities – and the measurement tools its existing rules employ, which are primarily focused on RF emissions.

The Nuances of the DA 26-789 Waiver

To address the immediate concerns of companies with existing authorizations, the FCC’s Office of Engineering and Technology (OET) issued DA 26-789. This public notice provides a waiver of specific provisions within the covered list prohibitions, namely 47 C.F.R. §§ 2.932(b) and 2.1043(b). The waiver is narrowly tailored, applying only to qualifying software and firmware updates for covered advanced robotic devices that received authorization before July 28, 2026. The stated purpose of these permitted updates is to "mitigate harm to US consumers" or to "ensure continued functionality," and this provision is slated to expire on January 1, 2029.

Crucially, DA 26-789 does not waive the underlying FCC requirements entirely, nor does it authorize every conceivable update. The traditional classifications of post-authorization changes remain relevant:

  • Class I Changes: These are modifications that do not degrade the technical and RF characteristics originally reported by the manufacturer and accepted during the certification process. Typically, no formal filing is required for Class I changes, though the manufacturer retains responsibility for ensuring continued compliance.
  • Class II Changes: These modifications are more substantial, potentially degrading reported performance characteristics. However, they must still meet the applicable minimum RF requirements. Class II changes necessitate the submission of complete supporting information and test results to the FCC. The modified equipment cannot be marketed under the existing grant until the FCC acknowledges the acceptability of the Class II change.

The ambiguity arises from the national security rationale versus the FCC’s regulatory tools. The national security concerns revolve around issues like data exfiltration, unauthorized surveillance, and remote manipulation of devices. In contrast, the FCC’s regulatory framework measures effects on FCC-authorized technical and RF characteristics. The critical question is how a change, particularly one that enhances AI capabilities, is categorized.

For instance, an update that significantly improves a robot’s navigation system or collision avoidance capabilities might be considered a Class I change if it does not alter the device’s RF emissions profile. However, whether such an update qualifies under DA 26-789’s criteria for "mitigating harm to US consumers" or "ensuring continued functionality" is left largely undefined. The term "harm" itself is open to interpretation. It could refer to traditional RF-related harm, physical or operational harm (e.g., through improved safety features), or the more contemporary national security and privacy harms arising from sophisticated surveillance, identification, tracking, data exfiltration, or remote control capabilities.

Similarly, "continued functionality" could be interpreted narrowly to mean maintaining the device’s existing operational parameters and compatibility, or more broadly to accommodate the natural evolution of AI performance. The latter interpretation could inadvertently permit materially new capabilities that were not part of the original authorization. While a Class II filing offers the FCC a final opportunity to review and apply its rules, the FCC’s stated objective for these devices is national security, not the incremental improvements in AI performance. Therefore, many AI-centric updates are likely to be categorized as Class I by manufacturers, compelling them to make a judgment call and bear the inherent risk associated with a narrow interpretation of the waiver’s provisions. A feature that enhances a robot’s ability to identify potentially suspicious individuals, for example, while having no RF impact and potentially being classified as Class I, could be seen as either mitigating consumer harm (by improving security) or, conversely, creating the very national security risk that prompted the covered list action.

The AI Update Conundrum: Beyond Discrete Firmware

A significant underlying problem is that the FCC’s regulatory framework, particularly its rules for post-authorization changes, is premised on a model of discrete, versioned updates pushed by a single manufacturer. This model is increasingly inadequate for the dynamic nature of AI-enabled robotics. Modern AI systems often operate with components that are not solely under the direct control of the device manufacturer.

Consider an advanced autonomous warehouse robot. Its core navigation intelligence might reside in the cloud. When the cloud provider updates the AI model, the robot’s behavior changes significantly, even though no software or firmware on the physical device itself has been altered. Similarly, third-party perception services, which provide crucial environmental data to the robot, can be updated independently, outside the direct control of the robot’s manufacturer. Furthermore, some AI systems are designed for continuous learning, adapting their behavior based on operational data without requiring explicit software pushes. Model weights can be refreshed daily, leading to substantial behavioral changes with no discernible impact on RF emissions.

While the FCC’s definition of "covered technology" explicitly includes "software running either locally or remotely," thus bringing cloud-side software into the regulatory scope, the existing update rules were primarily conceived for local, device-centric modifications. This creates a disconnect, as the mechanisms for tracking and authorizing changes do not readily accommodate the distributed and continuous nature of AI model updates.

This presents a strategic challenge for companies relying on grandfathering. By being locked into their 2026 configurations, they are at a significant competitive disadvantage compared to domestic competitors who are not subject to these foreign-produced device restrictions. Domestic companies can freely deploy improved AI models, integrate new third-party services, and implement continuous learning, thereby widening the gap in performance and capability. For AI-enabled robotics, where the primary value proposition hinges on ongoing improvement and adaptation, this situation can effectively represent a competitive "death sentence."

Adding to the concern, the FCC has a history of retroactively narrowing grandfathering provisions for other categories of covered equipment. This precedent signals that current accommodations are likely interim measures, not permanent safe harbors, and could be subject to further restrictions or modifications.

Navigating the Regulatory Labyrinth: A Strategic Imperative

For companies manufacturing or selling foreign-produced AI-enabled robotic devices, the path forward requires a clear-eyed acceptance that grandfathering is a temporary bridge, not a permanent destination. A proactive and strategic approach is essential to navigate the evolving regulatory landscape.

The first step involves a thorough mapping of the company’s AI architecture against the FCC’s definitional boundaries. This includes a detailed understanding of how cloud-based inference, third-party service integrations, and continuous learning mechanisms operate within their systems. Documenting data flows and interdependencies is crucial for demonstrating compliance. Every proposed software or firmware change must undergo a dual assessment: first, evaluating its technical and RF effects under the established Class I/II modification framework, and second, determining whether it qualifies under the ambiguous criteria of DA 26-789’s "consumer-harm mitigation" or "continued functionality" standards. Any modification impacting network connectivity, sensor data processing, or core navigation models should be routed for rigorous legal and compliance review.

The most durable and strategically sound exit from the FCC’s covered list is full compliance with domestic content requirements. A device that meets the specified threshold for domestic content (currently 65%, scheduled to increase to 75% in 2029) is simply not subject to the covered list prohibitions. Companies should therefore treat achieving this domestic content threshold as a primary strategic objective, with grandfathering serving as a transitional measure. The FCC has also established a conditional approval deadline of January 1, 2028, for certain inverters, which may offer a parallel pathway for some AI-enabled robotic devices if domestic content thresholds cannot be met. However, the 16-month window leading up to this deadline is considerably tighter than it might appear, especially given the extensive disclosure requirements involved in demonstrating compliance.

The FCC’s action represents a significant departure, marking perhaps the first instance where US equipment authorization rules have been explicitly deployed as an AI governance mechanism. The regulatory tools it is employing – Part 15 authorization, Class I/II permissive changes, and Supplier’s Declaration of Conformity (SDoC) procedures – were not originally designed for this purpose. This fundamental mismatch between the policy objective of national security AI governance and the inherited regulatory mechanisms creates the very ambiguities that make the grandfathering provisions so precarious.

Ultimately, the "cage" of grandfathering offers temporary shelter, not enduring safety. While companies can establish robust compliance processes to manage the current ambiguities, they must avoid mistaking procedural adherence for a sustainable long-term strategy. The only truly durable exit from this complex regulatory environment lies either in achieving full domestic content compliance or in a fundamental re-evaluation by the FCC of how AI-enabled hardware should be regulated, utilizing tools specifically designed for the unique challenges it presents, rather than adapting legacy frameworks. Until one of these shifts occurs, the walls of the regulatory cage are likely to continue closing in on companies operating in this rapidly evolving technological frontier.

By