Moreno Connected Vehicle Security Act Bans China Connected Vehicles
- Authority
- U.S. Congress
- Rule type
- statute
- Jurisdiction scope
- US federal
- Source text
- Read primary rule text ↗
Ban on connected vehicles and components from China, Russia, North Korea, Iran; phased software/hardware restrictions.
For the Moreno Connected Vehicle Security Act, “China ban” is too imprecise; the useful record starts with status, scope, dates, and source labels. As of July 30, 2026, this is a regulatory reference record, not a final compliance opinion: S.4429 has cleared the Senate Commerce Committee, but it has not become law, and several important points still depend on final statutory text, floor amendments, and any House-Senate reconciliation.
| Compliance field | Current record |
|---|---|
| Legislative status | S.4429 was introduced by Sens. Bernie Moreno and Elissa Slotkin on April 29, 2026, and advanced out of the Senate Commerce Committee on July 22, 2026; H.R.8730 is the House companion bill. [1][2][3] |
| Covered countries | The Act is reported to cover China, Russia, North Korea, and Iran, expanding beyond the existing BIS connected-vehicle rule’s China-and-Russia frame. [4][5] |
| Software timing | Software prohibitions are reported to begin with model year 2027, broadly tracking the existing BIS rule’s software phase-in. [4][5] |
| Hardware timing | Hardware prohibitions are reported to begin with model year 2030, with a January 1, 2029 date for units not tied to a model year, again broadly tracking the BIS timeline. [4][5] |
| Ownership or control trigger | Roll Call reported a roughly 15% Chinese-ownership threshold discussed during markup, including Sen. Ted Cruz’s Mercedes-Benz example; this should be treated as reported committee-markup information unless confirmed in statutory text. [6] |
| Penalties | The House summary describes civil penalties of at least $1.5 million per violation; that figure should not be assumed to be identical in the Senate bill without checking final text. Existing BIS rule penalties are tied to IEEPA authorities. [3][5] |
| Authorization infrastructure | The Act is reported to add a statutory mandate for Commerce to publish a list of authorized items by January 1, 2032, a feature not currently required by the BIS rule alone. [5] |

What the Act would ban
The Act is aimed at connected vehicles and connected-vehicle components tied to covered foreign-adversary entities. The press framing emphasizes Chinese vehicles and connected components, but the reported coverage is not limited to China: law-firm analysis identifies China, Russia, North Korea, and Iran as covered foreign adversaries for the Act. [1][4]
That matters for screening. A procurement team cannot treat this as a simple “China country of origin” hold. The relevant inquiry may include where the component is made, who developed or controls the software, who owns or controls the supplier, and whether the item falls within the Act’s connected-vehicle hardware or software categories.
The existing BIS Connected Vehicles Rule, effective March 17, 2025, already restricts certain connected-vehicle software and hardware linked to China and Russia. [5] The Act’s practical significance is that it would put a broader statutory layer on top of that rule, rather than merely restating the current Commerce Department framework.
The covered item problem is likely to be more difficult than the country list
A complete diligence file would have to distinguish at least four questions: whether the finished vehicle is covered, whether embedded software is covered, whether hardware is covered, and whether the relevant supplier or upstream entity is owned, controlled, or otherwise captured by a covered foreign adversary rule. The hard cases are unlikely to be cars obviously imported from a Chinese manufacturer. They are more likely to be multi-supplier platforms, telematics modules, connectivity stacks, and components that move across model years.
The Senate Commerce markup makes that point unusually clear. Sen. Tammy Duckworth offered an amendment that, according to Roll Call, would have narrowed the “connected vehicle hardware” definition to match the existing BIS approach; the amendment was rejected 9-19. [6] That is not final statutory language, but it is a meaningful committee signal: at least at markup, the committee was not willing to confine the Act to the narrower BIS hardware definition.
The phase-in schedule: software first, hardware later
For model planning, the effective dates are the first operational checkpoint. The Act is reported to phase in software restrictions for model year 2027 vehicles and hardware restrictions for model year 2030 vehicles. For units that are not assigned a model year, the reported hardware date is January 1, 2029. [4][5]
| Category | Reported Act timing | Compliance consequence |
|---|---|---|
| Covered software | Model year 2027 | Near-term engineering, supplier, and software-origin questionnaires need priority treatment. |
| Covered hardware in model-year vehicles | Model year 2030 | Longer lead time, but platform and sourcing decisions may already be inside design windows. |
| Covered hardware in non-model-year units | January 1, 2029 | Non-passenger or nontraditional vehicle programs need a separate date check rather than relying on model-year shorthand. |
The software date is the tighter one. A 2027 model-year trigger does not leave much room for a supplier to discover, late in validation, that a covered software component is embedded several tiers down. The hardware date gives more time, but it also invites a false sense of safety. Hardware architectures, connectivity modules, and platform-level supplier awards often become difficult to unwind well before the formal model-year cutoff.
The reported schedule also aligns with the BIS rule’s staged approach, which is one reason the Act should be read as an expansion and codification of the existing regulatory framework rather than as a wholly separate compliance universe. [5]

The approximately 15% ownership trigger is the compliance hinge
The most consequential reported detail is not the country list. It is the ownership threshold. Roll Call reported that Sen. Cruz raised concerns during markup about a provision that would treat companies with roughly 15% Chinese ownership as covered, using Mercedes-Benz as an example because of reported Chinese-held stakes approaching 20%. [6]
That example is useful precisely because it is uncomfortable. It shows how the Act could reach a company that is not itself a Chinese automaker and does not fit the simplified public description of a “Chinese vehicle” ban. A threshold of that kind turns the review into a corporate-control and investment-screening exercise. Legal, procurement, finance, and government-affairs teams would need the same cap table facts, but for different decisions: whether to continue sourcing, whether to seek a waiver or authorization, whether to delay a launch, and what to disclose to the board.
The caution is equally important. The roughly 15% figure is sourced here to committee-markup reporting, not to independently reviewed bill text. It should be used as an uncertainty flag in diligence materials: serious enough to trigger ownership review now, but not stable enough to be treated as the final statutory test without verification against the enrolled bill or later committee materials. [6]
The comparison to the existing BIS rule is central. Gibson Dunn describes the BIS rule’s covered-person test as including entities owned by, controlled by, or subject to the jurisdiction or direction of China or Russia, including a 25% or greater ownership threshold for certain covered persons. [5] A reported 15% threshold would materially lower the ownership line and pull more joint ventures, strategic investors, and publicly traded ownership structures into review.
Act versus BIS rule
The BIS rule is already in force, so the practical question is not whether connected vehicles are newly a national-security concern. The question is what the Act would add if Congress enacted it in substantially similar form.
| Issue | Existing BIS Connected Vehicles Rule | Connected Vehicle Security Act as reported |
|---|---|---|
| Issuing authority | Commerce Department/BIS rulemaking under existing authorities. [5] | Congressional statute, if enacted, with Commerce implementation obligations. [1][2] |
| Countries | China and Russia. [5] | China, Russia, North Korea, and Iran. [4] |
| Ownership threshold | Reported in law-firm analysis as including a 25% or greater ownership threshold for certain covered persons. [5] | Roll Call reported a roughly 15% Chinese-ownership threshold discussed during markup; final text must be checked. [6] |
| Software timing | Model year 2027 restrictions. [5] | Reportedly model year 2027 restrictions. [4][5] |
| Hardware timing | Model year 2030 restrictions, with January 1, 2029 timing for non-model-year units. [5] | Reportedly model year 2030 restrictions, with January 1, 2029 timing for non-model-year units. [4][5] |
| Hardware scope | Existing BIS hardware definitions. | Committee rejected an amendment to narrow hardware definitions to the BIS approach, suggesting a broader intended scope at markup. [6] |
| Penalty posture | IEEPA civil penalties up to $377,700 per violation or twice the transaction value, and criminal penalties up to $1 million and 20 years’ imprisonment. [5] | House summary states civil penalties of at least $1.5 million per violation; Senate and final enacted language should be checked. [3] |
| Authorization list | BIS has issued general authorizations, but no statutory requirement to publish the Act-style authorized-items list. | Reported statutory mandate for Commerce to publish a list of authorized items by January 1, 2032. [5] |
The country expansion is straightforward. The ownership threshold and hardware-definition fight are not. Those two points determine whether a company can screen at the level of obvious foreign-origin content or must build a more burdensome review around equity ownership, control rights, software development history, component functionality, and model-year timing.
Penalties: keep the House figure separate until the text is reconciled
The $1.5 million civil-penalty figure should be handled carefully. The House Select Committee’s release for the Moolenaar-Dingell companion bill states that the legislation would impose civil penalties of at least $1.5 million per violation. [3] That is an important planning number, but it is not a substitute for checking the Senate bill text, committee substitute, and any final conference language.
By contrast, the existing BIS rule’s penalty structure is already anchored in IEEPA authorities. Gibson Dunn’s summary identifies civil penalties up to $377,700 per violation or twice the value of the transaction, and criminal penalties up to $1 million and 20 years’ imprisonment. [5] A company preparing a risk memo should not blend those numbers into a single “Act penalty” line. They answer related but different questions: what applies under the current BIS rule, what the House version says, and what the final statute may ultimately provide.
Waivers, authorizations, and the 2032 list
During the Senate Commerce markup, Sen. Moreno responded to concerns about the reach of the bill by pointing to a “robust waiver process” and to the later 2030 hardware effective date. [6] That is relevant legislative history in the ordinary sense, but it is not the same as an operative waiver standard. A compliance team still needs the actual statutory criteria: who may apply, what Commerce must find, whether national-security agencies participate, whether approvals are item-specific or company-specific, and whether authorizations can be revoked.
The authorization-list requirement is more concrete. The Act is reported to require Commerce to publish a list of authorized items by January 1, 2032. [5] That would create a statutory reference point that the BIS rule alone does not currently provide. Gibson Dunn notes that BIS has issued three general authorizations since the final rule, but no specific authorization exemptions. [5]
For near-term planning, that means authorizations should not be treated as a cure-all. They may become central later, especially for legacy platforms or low-risk components, but they do not eliminate the need to classify items, identify covered ownership or control, and preserve evidence of the screening process.
Committee politics and industry support are context, not legal meaning
The bill has bipartisan sponsorship in both chambers: Sens. Moreno and Slotkin in the Senate, and Reps. John Moolenaar and Debbie Dingell in the House. [1][3] It also has support from automotive and transportation constituencies, including public endorsements from AUVSI and NADA. [7][8]
Those facts matter for legislative momentum. They do not resolve the interpretive questions. An industry endorsement does not tell a supplier whether a telematics module is covered hardware, whether a minority investor creates covered ownership, or whether a particular model-year launch falls before or after the operative date.
The failed Duckworth amendment and Cruz’s Mercedes-Benz concern are more useful for compliance planning because they expose the contested edges of the bill. Roll Call reported Cruz warning that the provision could affect Mercedes-Benz because of Chinese ownership stakes and could complicate full Senate passage; the committee nevertheless approved the bill. [6] That sequence does not prove final scope, but it does show where the scope fight is likely to sit.
Related measures: NDAA and vehicle modernization provisions
The Act is not moving in isolation. Holland & Knight notes that Section 353 of the FY2027 Senate NDAA would separately restrict adversary-nation connected vehicles from military installations and Department of War property in two phases beginning July 1, 2027. [4] The same analysis also places the issue alongside Motor Vehicle Modernization Act provisions. [4]
For most commercial supply-chain reviews, those related provisions are not the first screening tool. They are escalation flags. A company selling to federal, defense-adjacent, fleet, or critical-infrastructure customers may need to check whether a vehicle that clears one regime still creates access, installation, or procurement restrictions under another.
What to verify before treating the Act as a compliance rule
The current record is sufficient to begin issue-spotting. It is not sufficient to close a legal opinion. The minimum verification file should include final bill text, any committee substitute or amendment text, House companion language, penalty provisions, ownership and control definitions, waiver or authorization standards, and Commerce implementation guidance if the bill is enacted.
- Check whether the final country list remains China, Russia, North Korea, and Iran.
- Confirm whether the reported approximately 15% ownership threshold appears in final statutory language, and whether it applies only to Chinese ownership or more broadly to covered foreign adversaries.
- Separate software, hardware, model-year, and non-model-year dates in launch calendars.
- Do not import the House $1.5 million civil-penalty figure into a Senate-risk memo without checking the Senate and final enacted text.
- Compare any final hardware definition against the BIS rule, especially because the Senate committee rejected a narrowing amendment.
- Track Commerce authorization guidance separately from statutory waiver authority.
If enacted in substantially similar form, the Connected Vehicle Security Act would codify and expand the current BIS connected-vehicle framework. The expansion would be meaningful: more countries, a potentially lower ownership trigger, a broader hardware fight, a separate authorization-list mandate, and possibly a higher civil-penalty posture. The final compliance answer still depends on the actual statutory text, amendments on the floor, reconciliation with the House bill, and later Commerce guidance.
References
- Moreno, Slotkin Bill to Ban Chinese Vehicles & Connected Components from U.S. Market, Office of Senator Bernie Moreno, April 29, 2026.
- Slotkin-Moreno Bill to Protect National, Economic Security from Chinese Vehicles Advances Unanimously, Office of Senator Elissa Slotkin, July 22, 2026.
- Moolenaar and Dingell Introduce Legislation That Would Ban Chinese Vehicles from U.S. Roads, House Select Committee on the Chinese Communist Party.
- Connected Vehicles Face Growing National Security Scrutiny, Holland & Knight, July 2026.
- BIS Connected Vehicles Rule Effective as of March 17, 2025, Gibson Dunn.
- Bill to ban certain Chinese cars approved by Senate panel, Roll Call, July 22, 2026.
- AUVSI Endorses Connected Vehicle Security Act of 2026, AUVSI.
- NADA Statement on Senate Commerce Committee Advancing Connected Vehicle Security Act, NADA.
Operationalizing workflow
No workflow has been explicitly linked to this obligation yet. See Workflows generally.
Illustrative cases
No illustrative case is currently tracked for this obligation. See Risk Digest for documented incidents generally.
← Back to RegulationReport a correction or tip
Spotted an outdated figure, a misstated fact, or a ruling this regulation entry should reflect? Public comments are disabled for this content given the professional cost of a misreported case outcome, penalty amount, or rule text — use the structured correction channel instead.
Report a correction or tip for this record →