No Result
View All Result
SUBSCRIBE | NO FEES, NO PAYWALLS
MANAGE MY SUBSCRIPTION
NEWSLETTER
Corporate Compliance Insights
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • Artificial Intelligence (AI)
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Downloads
    • Download Whitepapers & Reports
    • Download eBooks
  • Research
  • Books
    • CCI Press
    • New: Bribery Beyond Borders: The Story of the Foreign Corrupt Practices Act by Severin Wirz
    • CCI Press & Compliance Bookshelf
    • The Seven Elements Book Club
  • Podcasts
  • Webinars
  • Videos
  • Subscribe
Jump to a Section
  • At the Office
    • Ethics
    • HR Compliance
    • Leadership & Career
    • Well-Being at Work
  • Compliance & Risk
    • Compliance
    • FCPA
    • Fraud
    • Risk
  • Finserv & Audit
    • Financial Services
    • Internal Audit
  • Governance
    • ESG
    • Getting Governance Right
  • Infosec
    • Cybersecurity
    • Data Privacy
  • Opinion
    • Adam Balfour
    • Jim DeLoach
    • Mary Shirley
    • Yan Tougas
No Result
View All Result
Corporate Compliance Insights
Home Risk

The Cage of Grandfathering: Why FCC Protection Won’t Save Foreign-Produced AI Robotics

AI improvements don’t arrive like firmware updates

by Kim D. Larsen
September 18, 2026
in Risk
rusty cage

The FCC is using equipment authorization rules on foreign-produced robotic devices as an AI governance mechanism, a decision that is revealing some cracks. As Kim D. Larsen of Stinson writes, what feels like safe harbor could actually be a prison.

If your company manufactures or sells foreign-produced AI-enabled robots and you had FCC Part 15 authorization before July 28, 2026, you may feel like you’ve reached safe ground. The FCC’s new covered list bars foreign-produced advanced robotic devices from receiving new Part 15 equipment authorization — but your existing model is grandfathered. You can keep selling it. DA 26-789 preserves, at least until Jan. 1, 2029, only qualifying software and firmware updates to already-authorized covered advanced robotic devices. The regulatory storm passed you by.

That feeling is a mirage. Grandfathering sounds like freedom, but it means you are locked into your 2026 configuration while the market moves on. Without DA 26-789’s limited exception, the covered list prohibitions would bar post-authorization permissive changes, even those that might otherwise qualify as Class I or Class II.

The reason lies in a structural mismatch: The FCC’s Part 15 equipment authorization system was designed to prevent electromagnetic interference, not to assess national-security risk. Sections 2.932 and 2.1043 organize post-authorization changes around FCC-authorized technical and radio frequency (RF) characteristics. The administration has repurposed that system as a national-security chokepoint, creating a gap between the risks it seeks to manage and the measurements its rules use.

The waiver that does not fit AI

To address this problem for existing devices, the FCC’s Office of Engineering and Technology issued DA 26-789. It waives only the covered list prohibitions in 47 C.F.R. §§ 2.932(b) and 2.1043(b) for qualifying software and firmware updates to covered advanced robotic devices authorized before July 28, 2026 — updates that mitigate harm to US consumers, including updates that ensure continued functionality — at least until Jan. 1, 2029. It does not waive the underlying FCC requirements or authorize every update. Class I changes do not degrade the characteristics reported by the manufacturer and accepted at certification; no filing is required. Class II changes degrade those reported performance characteristics but must still meet the applicable minimum requirements; they require complete supporting information and test results, and modified equipment may not be marketed under the existing grant until the Class II change has been acknowledged as acceptable.

This is where the mismatch comes into play. The national-security rationale focuses on data exfiltration, surveillance and remote commandeering, while the regulatory tools measure effects on FCC-authorized technical and RF characteristics — not the importance of a change to intelligence, autonomy, data practices or functionality. A capability-enhancing update may therefore be Class I if those characteristics are unchanged. But whether it falls within DA 26-789’s standard for consumer harm mitigation or continued functionality remains unclear.

DA 26-789 does not identify the frame of reference for either “harm to US consumers” or “continued functionality.” “Harm” might refer to RF-related harm within the traditional equipment-authorization regime; physical or operational harm addressed through safer navigation; or national-security and privacy harm arising from surveillance, identification, tracking, data exfiltration or remote control. “Continued functionality” might mean preserving the device’s existing operation and compatibility, or it could be read more broadly to accommodate evolving AI performance, but it should not automatically encompass materially new capabilities. Although a Class II filing gives the FCC a final opportunity to apply its rules, most AI updates will likely be Class I, leaving the manufacturer to make a judgment call and bear the risk under a narrow waiver interpretation. An improvement to navigation or collision avoidance may equally plausibly reduce consumer harm or preserve safe operation or decrease American security and competitiveness; a feature that identifies passersby acting suspiciously, although equally RF-neutral and potentially Class I, may mitigate harm or create the national-security risk that prompted the covered list action. 

cute robots
Compliance

Substantiate Your AI Claims Before They Become AI-Washing Challenges

by Andrew Lustigman and Barry Greenbaum
September 7, 2026

With models, datasets and vendor APIs changing constantly, a claim that was accurate in the past may no longer hold up

Read moreDetails

AI doesn’t update like firmware

An additional problem is that the FCC’s framework assumes discrete, versioned updates pushed by a single manufacturer. AI-enabled robotics has already outgrown that model.

Consider a modern autonomous warehouse robot. Its navigation intelligence may run in the cloud — when the cloud provider updates the model, the robot’s behavior changes, but nothing on the device has been modified. Third-party perception services update independently, outside the manufacturer’s control. Some systems learn continuously from operational data without anyone pushing an update at all. Model weights can be refreshed daily, dramatically changing behavior while having zero RF impact. The FCC’s definition explicitly includes “software running either locally or remotely,” bringing cloud-side software into scope, but the update rules were written for local changes.

And here is the strategic problem: Grandfathering locks you into your 2026 configuration. Competitors with domestic content face no such constraints — they can deploy better models, integrate new services and implement continuous learning. Every improvement they make widens that gap. For AI-enabled robotics, where the value proposition depends on continuous improvement, this is a competitive death sentence.

Worse, the cage may shrink. The FCC has already shown willingness to retroactively narrow grandfathering for other covered equipment categories, signaling that this is an interim accommodation, not a permanent safe harbor.

What should companies do?

The practical path forward requires accepting that grandfathering is a bridge, not a destination. Companies should map their AI architecture against the FCC’s definitional boundaries — especially cloud inference, third-party service and continuous learning — and document the data flows. Every software change should be assessed on dual tracks: its technical and RF effects under Class I/II and whether it qualifies under DA 26-789’s consumer-harm-mitigation/continued-functionality standard. Any change touching network connectivity, sensor data or navigation models should route to legal review.

The only durable exit from the covered list is domestic content compliance, a device meeting the 65% threshold (75% in 2029) is simply not covered. Companies should treat this as the strategic objective, with grandfathering as the bridge. A conditional approval deadline of Jan. 1, 2028, is relevant for those who cannot reach the threshold, but 16 months is tighter than it appears given the disclosure requirements.

The FCC’s action appears to represent the first time that US equipment authorization rules have been deployed as an AI governance mechanism. And the regulatory tools — Part 15 authorization, Class I/II permissive changes, supplier’s declaration of conformity (SDoC) procedures — simply were not designed for this purpose. The mismatch between policy objective and regulatory mechanism creates the ambiguities that make grandfathering so precarious.

The cage of grandfathering offers temporary shelter, not permanent safety. Companies can build defensible compliance processes even in ambiguity, but they should not mistake process for strategy. The only durable exit is domestic content compliance or a fundamental reconsideration by the FCC of how to regulate AI-enabled hardware using tools designed for something else entirely. Until one of those happens, the walls are closing in.

Tags: Artificial Intelligence (AI)
Previous Post

1095-C Season: Where ACA Compliance Actually Goes Wrong

Kim D. Larsen

Kim D. Larsen

Kim D. Larsen is a partner in Stinson’s Washington, D.C. office, where he advises technology and AI companies on regulatory, transactional, and licensing matters. He previously served as general counsel and co-CEO of publicly traded networking companies.

Related Posts

ladder viewed from ground

The First Rung Matters More Than the Ladder

by José Alberro
September 15, 2026

Can organizations preserve the pathways through which entry-level workers become experts in the time of AI?

meeting with attorney

AI in Investigations: What Courts Are Saying (So Far) About Privilege

by Gorev Ahuja
September 15, 2026

Emerging case law shows how easily AI-assisted investigation work can lose attorney-client privilege

stamps and ink pad

Human in the Loop — or Just Another Rubber Stamp?

by Adnan Masood
September 14, 2026

Human involvement doesn’t always mean humans were in control

news roundup green bars

67% of EMEA InfoSec Leaders Say Employees Are Using Shadow Agentic

by Staff and Wire Reports
September 10, 2026

Plus: 1 in 3 UK finserv workers say they’ve gotten bad AI outputs; few UK companies are training on neurodiversity...

GGR sq
No Result
View All Result

Privacy Policy | AI Policy

Founded in 2010, CCI is the web’s premier global independent news source for compliance, ethics, risk and information security. 

Got a news tip? Get in touch. Want a weekly round-up in your inbox? Sign up for free. No subscription fees, no paywalls. 

Follow Us

Browse Topics:

  • CCI Press
  • Compliance
  • Compliance Podcasts
  • Cybersecurity
  • Data Privacy
  • eBooks Published by CCI
  • Ethics
  • FCPA
  • Featured
  • Financial Services
  • Fraud
  • Governance
  • GRC Vendor News
  • HR Compliance
  • Internal Audit
  • Leadership and Career
  • On Demand Webinars
  • Opinion
  • Research
  • Resource Library
  • Risk
  • Uncategorized
  • Videos
  • Webinars
  • Well-Being
  • Whitepapers

© 2026 Corporate Compliance Insights

No Result
View All Result
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • Artificial Intelligence (AI)
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Downloads
    • Download Whitepapers & Reports
    • Download eBooks
  • Research
  • Books
    • CCI Press
    • New: Bribery Beyond Borders: The Story of the Foreign Corrupt Practices Act by Severin Wirz
    • CCI Press & Compliance Bookshelf
    • The Seven Elements Book Club
  • Podcasts
  • Webinars
  • Videos
  • Subscribe

© 2026 Corporate Compliance Insights