A bipartisan group of U.S. lawmakers is advancing legislation that would significantly expand restrictions on Chinese connected vehicles, extending scrutiny beyond finished automobiles to encompass software, hardware, critical components, and the broader automotive supply chain.
The proposed Connected Vehicle Security Act of 2026 would prohibit the importation, manufacture, sale, resale, and interstate movement of connected vehicles linked to Chinese companies. The legislation would also apply to vehicles associated with Russia, Iran, and North Korea.
Unlike previous regulations focused primarily on vehicles assembled in China, the bill adopts a broader national-security standard. Vehicles designed, controlled, or equipped with critical technologies supplied by Chinese firms could also face restrictions, regardless of where they are manufactured.
Supporters argue that modern connected vehicles collect vast amounts of sensitive information through cameras, sensors, GPS systems, and wireless communications, making them potential national-security risks if foreign governments gain access to their data or software.
Critics, however, counter that U.S. automakers collect similar volumes of consumer data while Congress has yet to enact comprehensive federal privacy protections for connected vehicles.
Bill expands review to entire supply chain
Success
You are now signed up for our newsletter
Success
Check your email to complete sign up
The Senate bill (S.4429) was introduced by Republican Sen. Bernie Moreno of Ohio and Democratic Sen. Elissa Slotkin of Michigan. Democratic Rep. Debbie Dingell and Republican Rep. John Moolenaar later introduced a companion House measure (H.R.8730). Both remain under congressional consideration.
The proposal would greatly broaden existing connected-vehicle rules by examining vehicle ownership, software, communications systems, and supply chains rather than focusing solely on manufacturing location.
Speaking at the American Enterprise Institute, Moreno described connected vehicles as “TikTok on steroids,” arguing that Chinese law could compel companies to provide user data or technical assistance to Beijing.
Moolenaar said regulators must evaluate not only where vehicles are assembled but also who controls their software and communications systems.
The Associated Press previously reported that former Commerce Secretary Gina Raimondo described connected vehicles as “smartphones on wheels,” warning they collect location, biometric, and personal data while remaining capable of receiving remote software commands. Officials have expressed concern that large numbers of compromised vehicles could threaten transportation networks or other critical infrastructure.

Polestar case illustrates broad reach of rules
The proposed legislation builds on regulations introduced during the final months of the Biden administration, which restricted connected-vehicle hardware and software originating from China or Russia. Those rules have remained in force under the Trump administration.
Their practical impact became clear in June 2026 when the U.S. Commerce Department denied Swedish electric-vehicle maker Polestar an exemption allowing continued U.S. sales beyond the 2027 model year.
Although the Polestar 3 is built in South Carolina and the Polestar 4 is assembled in South Korea, the company remains controlled by China’s Geely Holding Group, bringing it within the scope of U.S. restrictions.
Polestar chose not to appeal the decision and instead shifted greater focus toward Europe, raising concerns among U.S. dealers and customers over resale values, service support, and dealer compensation.
By contrast, Volvo, also controlled by Geely, received approval to continue selling vehicles in the United States, suggesting regulators are evaluating brands individually based on governance structures, software architecture, and data-security practices.
READ MORE:
- EU Fears China’s Growing EV Sector Infrastructure in Morocco Could Circumvent Trade Restrictions
- US Targets Chinese Tech Giants, Adding BYD, Alibaba, Baidu to Pentagon List
- Chinese EV Giant BYD Faces Forced Labor Allegations in Brazil and Hungary
Restrictions could reach U.S. borders
The legislation defines “importation” broadly, potentially allowing authorities to deny entry to Chinese-brand vehicles arriving from Canada or Mexico, even if they are not intended for sale.
Moreno said travelers driving affected vehicles across U.S. land borders could be turned away under the bill.
Slotkin and Rep. Haley Stevens have also introduced separate legislation, the Protecting America from Chinese Cars Act, specifically targeting cross-border vehicle entries, although that measure has attracted fewer congressional supporters.
The issue has gained increasing attention across North America as Chinese automakers rapidly expanded into Mexico through aggressive pricing and feature-rich vehicles. Mexico imposed 50 percent tariffs on some Chinese vehicles in early 2026, sharply reducing imports.
Canada has taken a different approach. After previously imposing 100 percent tariffs on Chinese electric vehicles, Ottawa later negotiated a limited arrangement permitting certain Chinese EV imports at lower tariff rates.
Moreno criticized Canada’s policy, arguing it could create indirect pathways for Chinese vehicles to approach the U.S. market through North American supply chains.

Privacy debate extends beyond China
While national-security concerns have dominated congressional debate, privacy advocates note that extensive data collection is common throughout the global automotive industry.
Modern vehicles routinely gather information on drivers’ locations, speeds, driving behavior, communications, entertainment systems, and in some cases facial, voice, or other biometric data that may be shared with insurers, advertisers, or third parties.
A 2023 review by the Mozilla Foundation found that none of 25 major automobile brands examined met its privacy standards. Separate investigations led by Democratic Sens. Ron Wyden and Ed Markey also identified widespread weaknesses in automotive data protection, including among U.S. manufacturers.
Moolenaar acknowledged that stronger consumer privacy protections remain necessary but argued there is “a fundamental difference” between private-sector data collection in the United States and data potentially accessible to the Chinese government.
Moreno also criticized existing industry practices, arguing that vehicle data collection should require explicit consumer consent rather than forcing owners to navigate complex opt-out procedures.
Congress, however, has repeatedly failed to pass comprehensive federal privacy legislation. The narrower SECURE Data Act, introduced in 2026, remains pending in the House.
Privacy debate extends beyond China
Beyond cybersecurity, the legislation reflects growing bipartisan concern over China’s expanding automotive industry.
Supporters argue Chinese automakers benefit from extensive state subsidies and integrated supply chains, creating competition that extends beyond individual companies to China’s broader industrial policy.
Opponents warn that sweeping restrictions could reduce competition, raise consumer prices, and distract from unresolved privacy weaknesses affecting vehicles regardless of their country of origin.
Ford Executive Chairman Bill Ford recently cautioned that Chinese vehicles cannot be excluded indefinitely, arguing U.S. automakers ultimately must improve their technological capabilities and cost competitiveness rather than relying solely on regulatory barriers.
Both House and Senate versions of the Connected Vehicle Security Act have attracted dozens of bipartisan co-sponsors. Supporters are now considering attaching the legislation to the annual National Defense Authorization Act, a strategy that could substantially improve its chances of becoming law. Although the bill’s final outcome remains uncertain, it reflects Washington’s increasingly expansive approach to national security—one that now extends beyond tariffs and export controls to encompass software, data governance, and the entire automotive supply chain.