Product1 publisher3 min readPublished
Automakers push Congress to ban Chinese vehicle software before adjournment
The Alliance for Automotive Innovation's letter to Congress argues privacy and national security, and the ban it asks for covers software and hardware, which is where the compliance work would actually land.
The Product Desk · Product desk

What happened
- Alliance for Automotive Innovation CEO John Bozzella, in a letter reported by CNBC, urged Congress to enact a ban on Chinese vehicles, software and hardware before adjourning this year.
- He asked for that ban to be permanent and passed in the 119th Congress, covering high-risk hardware and software alongside finished vehicles, as a national security answer to China's manufacturing strategy.
- The same letter states that the dumping of subsidised vehicles with connected software and hardware has not happened inside the United States yet.
- Techdirt argues the industry making the privacy case has some of the worst privacy ratings in America and sells drivers' personal and behavioural data onward.
- Democratic lawmakers in Michigan recently tried to bar Chinese EVs from even visiting the state, also citing consumer privacy.
Compiled by The Product DeskSomething wrong?How this is made
Why it matters
- constraint Scoping a ban to high-risk software and hardware makes sub-tier firmware provenance the deliverable, and most vehicle programmes cannot produce that today for a single telematics module.
- contradiction The threat described is prospective imports, but the remedy requested reaches parts already designed into cars: the part of the ask that's actually enforceable is the provenance requirement on those parts already in vehicles, not the imports that public argument is focused on.
- exposure A rule keyed to supplier nationality leaves the resale path untouched, so any team that cites the ban as its privacy answer is still answering for its own broker contracts.
- precedent If legislators define high-risk software by who owns the supplier rather than by what a module can reach, compliance boundaries end up drawn around ownership charts instead of network paths.
The letter's scoping means a tier-one supplier will spend part of next week on a question that reads like paperwork: which of the modules we ship runs firmware written in China, and can we document that down to the sub-tier. That question exists because of how the request is scoped. John Bozzella's letter, quoted by CNBC, does not ask for a tariff or a case-by-case import review. It asks Congress to ban Chinese vehicles, software and hardware, and to make that permanent in the 119th Congress [2][3].
Teams hearing "Chinese EV ban" picture a customs code and a car that does not arrive, while the letter's own sentence concedes that this "hasn't happened inside the U.S. yet" [4]. Of the three object classes named in the request, two are components rather than finished cars [5]. Vehicles that have not arrived are a border problem, handled at a port by people whose job that is. Software and hardware already designed into North American programmes are a provenance problem, and provenance is where the cost sits, because most bills of materials stop naming names at the first tier.
The thing being pitched is privacy. Techdirt's read is that the pitch and the practice have little to do with each other: US automakers rate among the worst industries in the country on privacy and sell driving, personal and behavioural data onward [6], and with no data broker rules in place, a buyer in China can purchase the same records from any of dozens of existing companies [7]. Nothing in the requested ban changes what a car collects or who may resell it. It changes who is permitted to have written the code that does the collecting. Techdirt's TikTok comparison is the useful part of the analogy: the security framing held while ownership moved, but the data practices went unaddressed [9].
For the person who has to answer for this on a Friday, sort the module inventory on two axes. First: can this part reach the network, or reach a bus that reaches the network. Second: can you name the origin of its firmware, including the sub-tier that supplies the stack inside it. Connected and traceable parts are a filing exercise. The connected-and-untraceable set is the entire exposure, and it's also what a statutory definition written around supplier ownership will catch first. Parts that are unconnected and untraceable can wait for a slower quarter. Unconnected and traceable work is already finished.
Build the connected-and-untraceable list now, before any bill text exists to argue with. This tradeoff costs something concrete: the questionnaire costs procurement goodwill and engineering weeks with suppliers who have no contractual reason to answer, and it will surface a handful of parts you cannot second-source inside a model year. Learning that while the deadline is still hypothetical is worth more than learning it from a compliance date somebody else picked.
What to watch
- Whether any introduced bill text defines high-risk vehicle software by code origin, supplier ownership, or data destination.
- Whether Congress pairs the requested ban with any restriction on selling US driver data to brokers.
- Whether Alliance members can produce sub-tier software provenance for their own telematics stacks.