Somewhere in Waymo's Arizona manufacturing facility, a new robotaxi called the Ojai is getting fitted out for San Francisco streets. Strip away the sensors and the badge, and it's a Zeekr minivan underneath, built on a platform from Geely, the Chinese industrial group that also owns Volvo. Waymo says that pedigree doesn't matter, because the software, sensors, and computing that actually make the car drive itself are developed in the US. A bill moving through Congress right now says that distinction won't matter either. If it passes, the Ojai gets banned anyway. Not for what it does. For where it was built.
Garage Deals: Nowell Leather’s Hand-Stitched EDC Gear Belongs in Every Gearhead’s Glovebox
That's the part of this story nobody is leading with. The easy headline is "Congress wants to ban Chinese cars." Washington already did that, more than a year ago, through a rule almost nobody outside a handful of automotive compliance departments has ever heard of. This new bill isn't patching a hole in that rule. It's replacing the idea behind it.
Start with what already exists. In January 2025, the Commerce Department's Bureau of Industry and Security finished a rule two years in the making, using emergency powers built around a 2019 executive order on supply-chain security. The rule took effect that March. It targets two systems: Vehicle Connectivity Systems, defined as anything that lets a car communicate off-board above 450 megahertz, covering cellular, Wi-Fi, Bluetooth, and satellite links, plus Automated Driving System software. Starting with model year 2027, automakers can't sell a car here running Chinese- or Russian-linked connectivity software. Starting with model year 2030, they can't use the hardware either.
Here's the detail that tends to surprise people who think they already know this story: to prove compliance, manufacturers now file an annual Declaration of Conformity backed by a software bill of materials, an ingredient list borrowed from cybersecurity and defense contracting, where it's normally used to track which vulnerable code libraries are buried inside a piece of software. The auto industry never had to produce anything like it before. Now it does, every year, for every connected vehicle sold in the country.
Small operations get a break. Anyone building fewer than 1,000 connected vehicles or hardware units a year is exempt, along with vehicles used on public roads fewer than 30 days annually, or cars imported strictly for testing, display, or racing off public roads. That's a narrow set of carve-outs, built after dozens of rounds of industry comment complaining the first draft was too broad. It reads like a rule written by people who had actually talked to suppliers.
That's the rule already on the books. Here's the bill trying to replace it.
The Connected Vehicle Security Act of 2026, introduced in the Senate as S.4429 by Bernie Moreno (R-OH) and Elissa Slotkin (D-MI), with a House companion from Debbie Dingell (D-MI) and John Moolenaar (R-MI), doesn't stop at connectivity modules and driving software. It would ban the importation, manufacture, sale, resale, or entry into interstate commerce of any connected vehicle designed or made by a company tied to China, Russia, Iran, or North Korea. Not the chip. Not the modem. The car.
"We go way beyond the current connected vehicle rule," Moreno said at a Washington panel, and that's the most honest sentence anyone attached to this bill has offered publicly. The 2025 rule was built around a specific, measurable risk: a foreign government's ability to pull data out of a car or seize remote control of it through its connectivity hardware. This bill doesn't ask whether that risk exists in a given vehicle. It assumes it, permanently, based on who owns the factory.
Which is how you end up with a bill broad enough to ban a car that already passed the test the last rule set up. Waymo's Ojai runs its autonomy stack on hardware installed at an Arizona facility, on what the company describes as a stripped-down, disconnected donor vehicle. Under the 2025 rule, that arrangement was designed to be fine. Under the new bill, it wouldn't matter, because the underlying vehicle traces back to a Chinese platform.
The bill's reach doesn't stop at ports and dealerships, either. It uses a legal definition of "import" broad enough to include any bringing of a product into the country, which means it applies at land borders too. A driver crossing into the US from Canada in a Chinese-made car wouldn't get waved through with a customs form. Based on the sponsors' own description, they'd be told to turn around and buy a different vehicle.
That provision lands at an odd moment. Chinese automakers grabbed an estimated 15 to 19 percent of Mexico's new-vehicle market in 2025 before Mexico imposed a 50 percent tariff this January, and Canada, irritated by its own trade fights with Washington, just cut a deal letting in a limited number of Chinese EVs at a fraction of its old 100 percent tariff. North America's auto market was built for decades on the assumption that parts and cars cross those three borders freely. It's now fracturing into three separate Chinese-car policies at once, and a bill that treats every land crossing like a shipping port doesn't fix that. It adds a fourth policy on top.
None of this is happening in a vacuum. Commerce has already used its narrower, existing authority once, denying Polestar, a company partly owned by Geely, permission to keep selling EVs in the US after the 2026 model year. That decision came under the current rule, the one aimed at specific components. It's a preview of how aggressively an agency can act even without a new statute behind it.
Which is really the point buried under all of this. The old rule asked what a car's electronics could actually do. The new bill only asks where the car was born.
That difference matters more than it sounds like it should. A regulation built around demonstrated risk can be narrowed, waived, or updated as the technology changes; the 2025 rule already includes a process for specific authorizations and advisory opinions for exactly that reason. A statute built around national origin doesn't bend the same way. Writing "companies tied to the PRC are banned, period" into law is a far harder thing to unwind later than an agency deciding, case by case, whether one transaction poses one specific risk. That's not an accident. Moreno wants this attached to the National Defense Authorization Act specifically because NDAA riders are close to unkillable, which tells you the sponsors already expect future administrations, and future Commerce Departments, to want more room to maneuver than this bill allows.
It's also, whatever else it is, an industrial policy wearing the language of cybersecurity. Chinese automakers aren't just cheap anymore, and legacy manufacturers know it; Porsche didn't shut down a battery factory and a chunk of Bugatti's roadmap purely for fun. A bill that walls off the entire American market from that competition solves a business problem at least as much as it solves a security one. Calling China's EV progress a scam, as Moreno did on the same panel, is a way of avoiding that question rather than answering it.
None of that makes the underlying security concern imaginary. Vehicle connectivity really is a plausible attack surface, and Volvo's own over-the-air update history is a useful reminder that even friendly, domestic supply chains can push code to two million cars overnight without much friction. The problem with the 2026 bill isn't that it takes the risk seriously. It's that it stops asking whether the risk is actually present in the specific car in front of it, and starts assuming it's present in every car that shares a birthplace with one that might be a problem.
Whether this specific bill goes anywhere is genuinely unclear. A narrower companion bill explicitly banning Chinese vehicles from crossing US borders has been sitting with only its original two sponsors for months, and Congress hasn't passed a comprehensive data-privacy law in decades despite years of trying. What won't wait for a floor vote is the compliance calendar already running under the existing rule. Software restrictions hit with model year 2027, which in the way the industry actually plans product cycles is basically now. Hardware restrictions land in 2030. Those two dates, not whatever happens to the Connected Vehicle Security Act, are what's actually shaping supplier contracts today, along with platform decisions at every company still racing to expand robotaxi fleets before local governments catch up with rules of their own.
Remember the distinction, not the vote count. The next chapter of this fight won't be decided by whether a car can spy on you. It will be decided by whether anyone in Washington still bothers to ask.
Join our Newsletter, follow our Instagram page, and connect with us on Facebook.