Cybersecurity Policy Report, Commerce’s Commitment to Connected Car Ban Questioned Following Volvo Deal, (Jun 1, 2026)
The Commerce Department’s decision to allow Volvo, which is majority-owned by China’s Zhejiang Geely Holding Group, to continue selling cars in the U.S. “may signal weaker enforcement” of the department’s import ban on connected cars from manufacturers with ties to China, according to the Foundation for Defense of Democracies (FDD).
The agreement between Volvo and Commerce “is in tension with rising concern over the risks posed by internet-connected vehicles produced by firms connected to foreign adversaries,” Jack Burnham, a senior research analyst in FDD’s China Program, said in a policy brief published Friday.
Final rules published by the Commerce Department last year will ban imports of connected car technologies from China beginning with the 2027 models (CPR, Jan. 14, 2025). Connected cars with a nexus to China could be used to conduct espionage in the U.S., the department said, although the rules allow for “specific authorizations” for automakers that demonstrate that their vehicles are not a threat.
Volvo announced last week that it had received an authorization from the department following “constructive discussions with the US Department of Commerce and other US officials regarding Volvo Cars’ governance, technology and data security.”
“Volvo will be staying in the American market despite concerns that its vehicles may vacuum up data for delivery to the firm’s majority shareholders in China,” Mr. Burnham noted.
“The agreement will allow Volvo, which holds relatively niche market share, to continue selling in the American market without interruption,” he said. “The deal will also reportedly prevent Volvo from transferring data collected by its vehicles to China, though neither the Commerce Department nor Volvo offered detail on these security measures.”
“While the agreement may signal weaker enforcement of Commerce’s new vehicle rule, any security commitments signed by Volvo may present another possible avenue to mitigate the risks posed by connected vehicles produced by firms linked to foreign adversaries. Other national security bans on foreign-produced drones or routers also have waiver programs to allow for regulatory scrutiny without enacting a complete ban,” he noted.
“However, the Commerce Department should ensure that automakers cannot trade rushed mitigation measures for continued market access,” Mr. Burnham added. “In implementing the agreement, Commerce should carefully verify that the data collected by Volvo vehicles is fully insulated from the firm’s Chinese ownership and that its software does not contain significant security vulnerabilities that would allow Geely, or Beijing, to engage in remote access or spy on U.S critical infrastructure.”
News: FederalLegislation DataSecurity DataPrivacy