Abstract:
A competition that has not yet taken place in the United States is prompting a permanent ban. On September 3, 2026, the Alliance for Automotive Innovation (Alliance for Automotive Innovation) sent a letter to leaders of both parties in Congress, requesting legislation before the end of the 119th Congress to permanently ban the sale, import, and manufacturing of Chinese connected cars and related software and hardware in the United States.
The alliance's vehicle members include major automakers such as General Motors, Ford, Toyota, Volkswagen, Hyundai, Honda, Stellantis, BMW, Mercedes-Benz and Volvo. The letter was sent directly to House Speaker Mike Johnson, Senate Majority Leader John Thune, and Democratic leaders in both chambers of Congress, Hakeem Jeffries and Chuck Schumer.
The letter is only two pages long, but the arguments are carefully arranged.
The alliance summarizes its core proposition very clearly: the United States should respond to China's strategy of competing for dominance in the global automobile manufacturing industry with national security policies.
It does not start with a certain car or a certain cybersecurity incident, but first puts China's auto industry policies into a larger set of accusations: unfair trade, government subsidies, intellectual property theft and surveillance. The alliance said these practices were particularly evident as China competes for dominance of global auto manufacturing and key supply chains.
Subsequently, the letter merged industrial competition with cybersecurity. It said Chinese automakers are dumping subsidized vehicles with connected hardware and software into global markets, citing the expansion of Chinese vehicles in Europe, Australia, Southeast Asia, Mexico and South America, saying the vehicles have the ability to collect, process and transmit sensitive vehicle and consumer data to the Chinese Communist Party.
As a result, the alliance expanded its competitors from individual companies to a country. According to the letter, what U.S. car companies face is not normal competition from Chinese companies, but the entire China supported by state-owned enterprises, industrial subsidies and trade policies.
In order to translate this judgment into domestic issues that Congress must deal with, the letter also specifically emphasized that the U.S. auto industry supports 11 million jobs in 50 states and contributes nearly $1.5 trillion to the U.S. economy every year. National security, industrial competition and employment interests are thus squeezed into the same set of arguments.
Then, a sentence appeared in the letter that seemed contradictory but actually best explained the purpose of this lobbying: "This has not happened in the United States yet."
Chinese brands have yet to truly enter the mainstream passenger car market in the United States, and the U.S. Department of Commerce’s administrative ban on connected cars in China has also taken effect. The Alliance for Automotive Innovation remains unconvinced. It requires Congress to upgrade administrative rules into federal law so that the ban is no longer dependent on the policy choices of any one administration.
This is the real news increase of the September 3 letter. What the U.S. auto industry asks Congress to deal with is not a safety incident that has already occurred, but a competitor that has not yet arrived; what it wants to fix is not just today's market barriers, but the government's ability to deal with this barrier in the future.
But the permanent ban first faces a factual issue: the Automotive Innovation Alliance alleged that China's connected cars have the ability to transmit sensitive data to the Chinese government, but did not list specific models, transmission records or technical investigations in the open letter. The materials disclosed by the U.S. Department of Commerce also demonstrate the possibility of data leakage and remote manipulation, rather than the transmission incidents that have been publicly confirmed.
Why is a security threat that has not yet materialized enough to support a permanent ban that is set to span a change of government? To answer this question, we first need to examine the most basic premise of the entire legislation: How far ahead of the evidence are the accusations?
The accusation comes first, the evidence comes later

The letter was written on behalf of the Alliance directly to House Speaker Mike Johnson, Senate Majority Leader John Thune, and Democratic leaders in both chambers of Congress, Hakeem Jeffries and Chuck Schumer, on behalf of the alliance.
The Alliance for Automotive Innovation is one of the major lobbying organizations in the U.S. automotive industry, with members spanning vehicle manufacturing, autonomous driving, components, batteries, and semiconductor companies. Its vehicle members include major automakers such as General Motors, Ford, Toyota, Volkswagen, Hyundai, Honda, Stellantis, BMW, Mercedes-Benz and Volvo.
Objectively speaking, companies such as the Innovation Alliance are at a disadvantage in the competition of modern new energy intelligent connected vehicles.
New energy intelligent connected cars, also known as new cars, constantly generate data such as location, route, driving habits, vehicle status, in-car images and voice, and some functions can also be operated through remote software updates, digital keys and mobile applications.
From the perspective of technical capabilities, connected cars are no longer just traditional means of transportation, but a computing platform that can move, perceive the surrounding environment, and continuously communicate with external servers.
The U.S. Department of Commerce believes that if foreign adversaries are able to enter these software and hardware supply chains, they may be able to extract sensitive data, track vehicle movements, or remotely control vehicles. Massively connected vehicles may also be used to understand the movements of critical infrastructure, military installations and government personnel.
These risks are not entirely without technical basis.
But "being able to collect and transmit data", "may be required to provide data" and "having transmitted data to the Chinese government" are three different factual judgments.
The Automotive Innovation Alliance used the expression "capable" in a two-page letter made public on September 3, saying that China Automobile is able to collect, process and transmit sensitive vehicle and consumer data to the Chinese Communist Party. Strictly speaking, this is a judgment about technical capabilities and potential flows, and does not mean that the alliance has public evidence that a certain car transmits data to the Chinese government.
The letter does not list any specific models, data flows, transmission records, technical appraisals, network security reports or cases that have occurred, nor does it provide footnotes or attachments for this statement. Industrial subsidies, unfair trade and market share expansion can illustrate competitive pressures, but they cannot automatically complete the missing evidence chain for data transfer accusations.
The U.S. Department of Commerce’s public materials mainly use risk-based statements: relevant companies “may be forced” to share data or allow remote access; malicious entry into the supply chain “may” lead to data being extracted or vehicles being manipulated.
So far, what public information can prove is that connected cars have the technical capabilities to collect, process, transmit data and accept remote commands, and that the US government believes that China's legal environment and corporate control relationships may pose national security risks.
Public information cannot prove that a certain Chinese brand passenger car sold overseas has directly transmitted consumer data to the Chinese government.
It cannot be ruled out that the US government has undisclosed or classified information, but in the absence of public evidence, risk assessment cannot be directly written as facts that have already occurred.
The Automotive Innovation Alliance itself admits that the threat posed by China's connected cars "has not yet occurred in the United States."
This sentence defines the nature of this policy: it is not a penalty for a verified behavior, but a market exclusion based on the company's identity, technical capabilities and worst-case scenarios before the fact occurs.
How the first door is closed

The U.S. national security review of China’s connected cars dates back to Trump’s first term.
In May 2019, Trump signed Executive Order 13873, authorizing the Department of Commerce to restrict information and communications technology and service transactions involving "foreign adversaries." At the time, the order did not specifically target cars, but it established a review framework that later became the legal basis for a ban on connected cars.
In March 2024, the Biden administration began investigating the risks that may arise from foreign adversaries’ participation in the U.S. connected car software and hardware supply chain. In September of the same year, the Department of Commerce announced proposed rules to restrict in-vehicle software, communications hardware and automobile manufacturers that have sufficient ties to China or Russia.
In January 2025, the Biden administration officially finalized the "Final Rules for Connected Vehicles", which will take effect on March 17. After Trump returned to power, he did not dismantle this system. The U.S. Department of Commerce's Bureau of Industry and Security continues to enforce the rules and process special authorization, compliance declarations and consultation applications submitted by automakers.
The rules push the regulatory focus from the final assembly site of the car to the interior of the vehicle. Bluetooth, cellular communications, satellite communications, Wi-Fi modules and related software in the vehicle connection system, some software in the autonomous driving system, and the ownership and control relationship behind the manufacturer may all affect whether a car can be sold in the United States.
Restrictions will be implemented in phases.
Starting from the 2027 model year, connected car manufacturers owned, controlled, or subject to their jurisdiction or direction by China or Russia are not allowed to sell new cars equipped with relevant connectivity systems or autonomous driving software in the United States; cars containing restricted Chinese and Russian software are also not allowed to be imported or sold.
Comprehensive restrictions on vehicle connection system hardware will be implemented from the 2030 model year; related equipment without model year concepts will be restricted from January 1, 2029.
Even if a car is produced in the United States, it does not automatically avoid the ban. Vehicles may still be banned from sale as long as the manufacturer itself is deemed to have sufficient ownership, control or jurisdictional ties to China or Russia.
The most important factor in traditional automobile trade, "where it is made," is no longer enough to determine whether a car can enter the United States.
Sealing the next government’s room for maneuver

The current ban on connected cars is based on departmental rules established by a presidential executive order. It is legally binding, but the executive branch still has wide room for interpretation and adjustment.
In the future, the government can change enforcement priorities, adjust the way in which "possessed, controlled or under the direction of" is determined, expand general authorization or special authorization, or modify the existing system through a new rulemaking process.
The Alliance for Automotive Innovation hopes to block this possibility.
Once Congress enacts a ban into statutory law, it will be difficult for future presidents and their Commerce Departments to revoke it simply by executive decision. If policies require fundamental changes, they usually need to be amended again by Congress.
This does not mean that the law can never be changed, but the political threshold for changing a federal law is much higher than adjusting an administrative rule.
For automakers, this is also about product planning certainty. It often takes several years for a new car to go from platform establishment, software development, supplier appointment to formal production. Vehicle communication modules and software systems are deeply embedded in the electronic and electrical architecture of the entire vehicle, making it difficult to temporarily replace the product before it is launched.
As the 2027 model year approaches, administrative rules have changed from principled policies to specific product access issues. Many automakers have begun to re-examine the supply chain of connected modules and software, requiring suppliers to further trace the source of technology and parts.
That’s why the Alliance for Automotive Innovation bypassed the executive branch and wrote directly to four bipartisan leaders in Congress. What it requires is no longer how the Department of Commerce enforces existing rules, but whether Congress can permanently reduce the space for any administration to reinterpret, relax or revoke the rules.
If tariffs can’t stop it, let code do it

The most complete legislative package currently is the Connected Vehicle Security Act of 2026, Senate S.4429 and House of Representatives H.R.8730. S.4429, as revised by the Senate committee, is not an ordinary vehicle import ban.
The "countries of concern" covered by the bill include China, Russia, Iran and North Korea. The review targets the entire vehicle, vehicle connection system hardware, autonomous driving and connection system software, as well as the ownership, voting rights and actual control relationships behind manufacturers and suppliers.
The equity and control thresholds for some vehicle-related companies are more than 15%, and the corresponding thresholds for some software and vehicle connection system hardware companies are more than 25%. A set of 15%-25% tiered thresholds has been embedded in the automobile market access system.
The first person this red line may hit is not even a Chinese car company, but Mercedes-Benz.
According to the shareholder structure disclosed by Mercedes-Benz, BAIC Group holds 9.98% of its voting rights, and Li Shufu holds 9.69% of the equity through Tenaciou3, totaling approximately 19.67%. If the bill calculates interests based on the consolidated calculation of "one or more" concerned country entities, Mercedes-Benz may cross the red line simply because of its shareholding ratio even if its operations, board of directors and data systems are not actually controlled by Chinese shareholders.
A bill in the name of preventing Chinese cars from entering the United States may first block out a German manufacturer that has set up a factory in the United States and employs tens of thousands of employees. This shows that Congress is redefining not just where vehicles come from, but who a multinational company belongs to.
The bill intends to restrict relevant connected cars from January 1, 2027; restrictions on regulated software will begin in the 2027 model year, and restrictions on vehicle connection system hardware will begin in 2030.
The committee’s debate on battery management systems further demonstrates that S.4429 does not simply replicate the Department of Commerce’s current rules. Democratic Senator Tammy Duckworth had proposed an amendment to narrow the definition of "connected vehicle hardware" to the scope of the current rules, but the amendment was rejected by 9 votes in favor and 19 votes against. A majority of the committee members chose to retain the broader definition, which would allow some electronic systems for battery monitoring, management, safety and communication to potentially fall within the scope of regulation.
If a company violates the regulations, it faces a minimum fine of US$1.5 million per transaction, or five times the transaction value; continued violations can also be calculated on a daily basis.
The bill does not completely cancel the special authorization, but it tightens the discretionary space of the Ministry of Commerce. The Secretary of Commerce can only approve authorization after determining that the relevant transaction will not pose inappropriate data leakage, remote control of vehicles, critical infrastructure, or national security risks, and will need to submit a written risk assessment to Congress.
The general authorization or special authorization already obtained under the current rules cannot be extended indefinitely. According to the committee's revised text, these authorizations will terminate at the earlier time between the original expiration date and January 1, 2030.
The bill also requires the Department of Commerce to make public the list of authorizations. Without revealing corporate secrets, the competent authorities should disclose authorized manufacturers, products, and risk judgment bases as much as possible. This will both increase transparency and reduce the space for future governments to relax the ban through case-by-case authorization.
This system restricts not only vehicles produced in China, but also companies that may be touched by Chinese capital, software developed by Chinese teams, and communication hardware manufactured by Chinese suppliers.
Even if the car is offline in the United States, the product may still be excluded as long as the company or core system is deemed to have sufficient ties to China.
Volvo approved: risks can be isolated

Volvo’s experience with Polestar has made the real boundaries of this set of rules concrete.
At the Charleston, South Carolina, plant, Polestar 3 and Volvo EX90 share the SPA2 platform and are assembled in the same production system. The two cars also have extensive connections in technology, software and hardware architecture. However, on May 26, 2026, Volvo received special authorization from the U.S. Department of Commerce to continue importing and selling connected cars in the United States; a month later, on June 24, Polestar's application was rejected. Starting with the 2027 model year, Polestar will no longer be able to sell new vehicles in the United States.
Both companies have close capital ties with Geely, but have received completely different regulatory results.
Geely is still the controlling shareholder of Volvo, and both parties also share technology, industrial collaboration and related transactions. However, Volvo is a listed company operating under Swedish law and has its own management team and governance procedures. Major related transactions involving the Geely system are subject to disclosure, director avoidance and shareholder review procedures.
Neither Volvo nor the Ministry of Commerce has disclosed the complete conditions of the authorization, and the outside world cannot determine which specific measures helped it obtain the release. But the results at least show that Chinese capital holdings do not necessarily mean that Chinese shareholders have direct access to the data, software and remote control systems of U.S. vehicles. Companies can separate capital-level correlations from actual operational risks through corporate governance, technical authority divisions and supply chain arrangements.
The difficulty of Pole Star is precisely here. It is headquartered in Gothenburg, Sweden, and is listed on Nasdaq. Its management and most employees are outside China. However, the company adopts an asset-light model and is highly dependent on the Volvo and Geely systems for vehicle manufacturing, technology platforms, R&D services and parts supply. As of the end of 2025, Li Shufu's relevant shareholders collectively own approximately 52.9% of Polestar's voting rights. Polestar has proposed mitigation plans such as geographical isolation of data, third-party security audits, and restrictions on remote access, but none of them resulted in special authorization.
The problem is that these remedies are aimed at specific behaviors such as "whether data is leaked" and cannot answer the more fundamental question: Polestar's manufacturing, platform and research and development do not operate independently from the Geely system. This kind of bundling at the operational level cannot be compensated for by any technical measures afterwards.
What Polestar has to prove is no longer just the security of vehicle data, but whether its operations are independent of related parties under scrutiny - which is what it is difficult to prove due to its structure as a light-asset enterprise that relies on the manufacturing and R&D systems of Volvo and Geely.
In the end, Polestar did not file a complaint, but instead shrunk its U.S. business and shifted its focus to other markets; multiple media pointed out that Polestar itself had not received a complete explanation of the reasons for the rejection from the Ministry of Commerce. In August 2026, a New Jersey dealer filed a $25 million lawsuit, accusing Polestar of treating the regulatory rejection as "force majeure" and taking the opportunity to voluntarily withdraw from the U.S. market to avoid franchise termination compensation. This statement is currently only an accusation made by one party in the lawsuit. It has not yet received a court ruling or a substantive response from Polestar.
Volvo was approved and Polestar was rejected, which at least shows that the current rules are not based solely on capital ratios. What regulators are more concerned about may be whether the influence of Chinese shareholders can be limited to the capital level, and whether the company can prove that there is an independent boundary that can be verified for its operations - Volvo has this boundary, but Polestar does not.
This also exposes the conflict between permanent legislation and case review: If a company like Volvo, which operates relatively independently and is only related at the capital level, can be evaluated separately, a fixed equity threshold that does not distinguish between capital relatedness and operational bundling is accurately identifying risks, or is it using a one-size-fits-all identity standard to replace what should be a more refined risk judgment?
Build a wall, but also leave a door for yourself

Members of the Alliance for Automotive Innovation cover major vehicle manufacturers in the U.S. market, but the letter issued by the alliance in the name of the organization cannot prove that every member company supports all provisions in the bill.
Public materials show that General Motors clearly praised the "Connected Car Safety Act"; Ford affirmed that members of both parties have promoted the legislation and expressed its hope to continue to participate in the advancement of the bill; Honda supported the goals of the bill, but used the qualifying statement "as the legislation continues to evolve"; Stellantis said that the bill involves important issues and hopes to continue to discuss specific details.
The alliance itself also emphasized in the letter that "details matter" and requested that the final policy allow all its members to continue to develop in the US market while addressing China risks.
This sentence is not routine diplomatic rhetoric. The letter on September 3 clearly listed S.4429, but did not mention the most controversial 15% equity threshold, nor did it explain whether it supported the consolidation of the interests of multiple Chinese investors.
(For details, please refer to "Chinese Entities' Shareholdings Exceed the 15% Red Line, U.S. Legislative Ban on the Sales of Mercedes-Benz Passes the First Level" published by Automotive Business Review on July 23)
This silence carries weight. Mercedes-Benz itself is a member of the Automotive Innovation Alliance, and it may have crossed the 15% red line because of the combined shareholding of two Chinese investors. The league supported the passage of a permanent ban, but did not answer whether it still supported all the provisions of the bill when the ban threatened to lock out its German members.
The so-called industry consensus has a clear distinction between internal and external issues.
Externally, each car company can benefit from preventing Chinese brands from entering the US market; internally, they must ensure that equity thresholds, software traceability and special authorizations do not block their global production and R&D systems.
Ford best illustrates this duality.
On the one hand, Ford supports Congress in restricting Chinese connected cars; on the other hand, it is applying for special authorization for the Lincoln Navigator produced in China. Although the car's software was developed in the United States, it was installed in China, so it may violate existing regulations.
Ford hopes to permanently fix market restrictions on Chinese competitors, but it needs administrative departments to reserve licensing space for its existing products. This is exactly what the alliance means when it says “the details matter”: The industry supports closing the door, but every company doesn’t want its products to be shut out.
GM also has a complex Chinese business system. Its business in China includes long-term cooperation structures such as SAIC-GM, Pan-Asia Automotive Technology Center and Internet of Vehicles services. Publicly available information cannot prove that these technologies are used in GM models sold in the United States, but these cooperations show that the R&D and software relationships between multinational car companies have long transcended national boundaries.
"Where the code belongs", "Who developed it" and "Who has access" are far more difficult to classify than the origin of the vehicle. If Congress adopts an overly broad definition of development sites, suppliers, and related enterprises, U.S. automakers’ own R&D and production relationships in China may also increase compliance burdens.
Therefore, the demands of the Automobile Alliance can be summarized into two levels.
In terms of overall policy, they hope that Congress will keep Chinese competitors out of the U.S. market for a long time; in terms of specific implementation, they hope to retain sufficient authorization channels for their Chinese factories, joint ventures, software development and supply chains.
The later Chinese brands enter, the longer the original participants in the U.S. market will have to adjust; the greater the authorization space left by the bill, the lower the cost of supply chain transformation that existing multinational car companies will have to pay.
What they want is a wall high enough for competitors but still open to themselves.
Three legislative paths, none of which have been successful

The Alliance for Automotive Innovation proposal will not be put directly to a vote. What Congress really needs to deal with are the three legislative paths that are already on the table.
The fastest progress is Senate S.4429. It was proposed by Republican Senator Bernie Moreno and Democratic Senator Elisa Slotkin on April 29, and was approved by the Senate Commerce, Science and Transportation Committee on July 22 to be submitted to the full chamber. The bill adopted revised alternative text at the committee stage but has not yet reached a vote in the full Senate.
The corresponding version of H.R.8730 in the House of Representatives was proposed by Republican Representative John Mueller and Democratic Representative Debbie Dingell on May 11. It is still stuck in the Energy and Commerce Committee, Ways and Means Committee and Foreign Affairs Committee, and has not yet left any committee.
Among the four sponsors, Slotkin, Mullenar and Dingell are from Michigan, and Moreno is from neighboring Ohio. Both states are highly related to the U.S. auto manufacturing industry, and Chinese auto competition is most easily transformed into investment, employment and election issues here.
The third path is H.R.7389, the Motor Vehicle Modernization Act of 2026. The House Energy and Commerce Committee voted 48 to 1 on May 21 to pass the revised bill, which includes restrictions on automakers controlled by foreign adversaries, but it has also yet to receive a vote in the full House of Representatives.
As of the time the Alliance for Automotive Innovation issued its letter on September 3, no permanent ban had passed either house of Congress. Even if S.4429 is passed by the full Senate, the House of Representatives still needs to pass the same or similar version; if the two houses adopt different texts, coordination must be completed before it can be signed by the president.
The 119th Congress will end in January 2027, leaving only a few months for these processes, and the year-end congressional calendar is usually crowded with appropriations, defense authorization and other bills that must be dealt with.
Judging from the procedures, it is not very likely that a complete permanent ban covering complete vehicles, capital, software, hardware and special authorizations will be passed as an independent bill before the end of this Congress. The progress of the supporting bill in the House of Representatives is slow, and the 15% and 25% equity thresholds, authorization termination period, and impact on cross-border supply chains may continue to trigger modifications.
The debate within the Senate committee has brought this resistance into the open. Commission Chairman Ted Cruz supports preventing foreign adversaries from controlling connected cars, but opposes the 15% absolute ownership threshold, arguing that it does not sufficiently distinguish between financial investment and actual control. He once proposed adopting a multi-factor control standard similar to that of the Committee on Foreign Investment in the United States, but later withdrew the amendment in order to let the bill go out of the committee first, while warning that the existing provisions may make it more difficult for the bill to pass the full Senate.
But this legislation cannot therefore be seen as a sideshow. S.4429 has passed the committee, and H.R.7389 also showed a strong cross-party basis with a vote of 48 to 1. A more realistic path is for Congress to extract less controversial core provisions and incorporate them into the comprehensive motor vehicle bill, the National Defense Authorization Act, or other large legislative vehicles at the end of the year.
In other words, the probability that a complete ban will be enacted into law in this Congress is lower than its political momentum, but the probability of partially or phasedly writing the Ministry of Commerce’s administrative rules into law is significantly higher than the probability of an independent bill being passed as it is.
The Automotive Innovation Alliance chose this time to directly put pressure on the top leadership of the two parties precisely to compete for the final agenda window.
Weld the door shut and throw away the key
"Automotive Business Review" believes that even if this lobbying has not spawned a complete permanent ban in this Congress, it has completed an important political advancement: turning the supervision of connected cars, originally controlled by the executive branch, into a national security issue that can be accepted by both parties.
If the legislation fails, the existing administrative ban can still be implemented, but the White House may still modify, relax or even revoke it in the future; if the legislation succeeds, China's connected cars will no longer face just the policy choices of one government, but a long-term market boundary authorized by Congress.
This was never purely a technology and cybersecurity review.
Without announcing specific data transfer cases, the United States is preparing to implement long-term market exclusion based on technical capabilities, corporate identity, and worst-case scenarios; after Volvo proved that capital correlation and operational risks can be distinguished, Congress is still trying to reduce the space for companies to prove their security on a case-by-case basis with fixed equity thresholds, authorization periods, and software source rules.
The permanent ban thus crosses a line: the focus of the review is no longer just whether the risk can be isolated, but who has the qualifications to prove that he is safe, and who has been ruled out before the evidence has been submitted.
When national security becomes the highest-level trade policy tool, the "nationality" of a car is no longer determined by the car logo and factory, but is restructured into a competition around capital, code, data permissions and supply chain dominance.
What the U.S. auto industry wants to block is not a data security incident that has already occurred in the United States, but a competition that has not yet begun but may rearrange the rankings of the U.S. auto market. This is an unbearable burden for the American auto industry.
They are unwilling to leave this result to the market, nor are they willing to leave the power to reopen the door to the next government.
Comments