" " indicates required fields
Biden’s Proposal to Ban Chinese and Russian Software in Connected Vehicles: What it Means for the Automotive and Mobility Industries
The Biden administration recently announced a proposal aimed at banning Chinese and Russian-developed software in connected vehicles sold in the U.S. This move, outlined as part of the broader national security strategy, is intended “to secure the American people, including our children, from potential surveillance the U.S.”, as outlined by US Commerce Secretary Giana Raimondo on September 22.
Here’s what we know so far – a detailed breakdown of the proposal, its implications, and how car makers should prepare for this (potentially) new rule.
On September 23, 2024, the National Economic Advisor Lael Brainard revealed during a speech at the Detroit Economic Club in Michigan, the Administration’s intent to limit the use of Chinese and Russian software in the American automotive sector. The proposal stems from concerns over safety and security risks in connected cars and ensures that US supply chains are resilient from foreign software threats that could potentially be used for espionage, data breaches, or malicious attacks on U.S. infrastructure.
According to the NYTimes, the proposed rule (pdf) could go into effect before President Biden leaves office in January 2025, leaving car makers with roughly a year to reconfigure their supply chains, software partnerships, and cybersecurity practices to comply with the new law.
A subset of the above rule would ban the sales of vehicles with automated driving (ADAS) components and systems from China or Russia. This proposed rule is farther down the line – 2029-2030, banning self-driving (autonomous) tech made in Russia or China from being used on US Roads, even if the vehicles are made in the US.

If the proposed ban is approved and becomes law, car makers will face significant operational and financial challenges. We’ve outlined four areas of concern:
To comply with the proposed ban and mitigate the risks associated with foreign software, car makers will need to beef up their existing cybersecurity practices, including the generation of audit reports to prove they adhere to the regulation. Three key areas of focus in our opinion are the Software Bill of Materials (SBOM), supply chain security management, and compliance audits.
Schedule an exclusive demo to see firsthand our leading product security platform in action.
1. Why is the US banning Chinese and Russian software?
The US is concerned that software from these countries could be used for cyber espionage or malicious attacks on critical infrastructure, including connected vehicles. The ban aims to enhance national security by mitigating these risks.
2. How will the ban affect car makers?
Car makers will need to overhaul their supply chains, find new software partners, and ensure all software components comply with US regulations. This will likely lead to increased costs and potential delays in vehicle production.
3. What is SBOM, and why is it important?
SBOM is a detailed inventory of all software components used in a vehicle. It helps ensure that automakers can trace the origins of their software and avoid using code from banned sources, thereby complying with national security regulations.
4. What happens if a car maker doesn’t comply?
Non-compliance could result in fines, vehicle recalls, and reputational damage. Car makers must also perform regular audits and ensure strict cybersecurity practices.
Dynamic threat modeling and risk assessment aligned with global regulations
LLM-agnostic generative AI layer powering automation across every module
Aggregated threat feed contextualized against your actual products
Generate, manage, and triage all BOMs and vulnerabilities across the lifecycle
Quantitative optimization of mitigation strategy and security control allocation
Configurable dashboards and reports across every EVSec data layer
Extract software composition and risk from firmware and binaries without source code
Optimized anomaly detection for Ethernet and CAN, plus ECU runtime protection
Quantify and manage cybersecurity risk for products operating in the field
Enrich SOC events with deep product and architecture context
Context-driven test and validation with intelligent fuzzing, integrated into CI/CD
AI-powered static analysis integrated into CI/CD with reduced false positives
Foundational layer: cyber model, workspaces, and integration backbone to DevOps toolchain
Out-of-the-box and customizable workflows for regulatory and security processes
Centralized compliance management with evidence generated from live data