Hello, this is Ryuta Hamamoto from TIMEWELL.
The Wi-Fi router in a US living room and the smart TV next to it are ordinary products. They are also network edge devices that process traffic and, in many designs, viewing data. Over the past year, federal technical regulation, state consumer litigation, and public cyber reporting have all tightened the spotlight on where devices are designed, built, and controlled — and on what data they send off-premises.
I first published this article in February 2026, when Texas state suits were the main public story and a reported Commerce Department track aimed at TP-Link products had been set aside ahead of high-level US–China meetings. Six months later, the federal picture is different. In March 2026, the FCC updated its Covered List to include certain foreign-made consumer Wi-Fi routers, with authorization consequences for new models. The FCC's reading of "produced" looks past final assembly labels toward design and development location. That is a technical-regulatory move, not a criminal verdict against any brand.
This rewrite sticks to public primary and secondary sources, separates allegations from findings, and treats list placement and lawsuits as regulatory and procedural facts — not as moral judgments about the companies named in those records. If you want a quick read on your own export-control and counterparty process, start with our free export-control readiness check.
| Issue | February 2026 (first version) | August 2026 (now) |
|---|---|---|
| Federal track | Reported Commerce action on TP-Link products set aside | FCC adds foreign-made consumer routers to Covered List |
| State track | Texas DTPA suits filed | Suits and related orders continue; multi-state follow-on remains a watch item |
| EAR Affiliates Rule (50%) | Expected return path into late 2026 | Effective once, suspended one year, scheduled return November 10, 2026 |
| Typhoon-linked reporting | Telecom intrusion and long-dwell access | Broader geographic reporting; OT-oriented tradecraft discussed in industry research |
Texas filed five China-linked consumer cases in one week
On Monday, February 17, 2026, Texas Attorney General Ken Paxton announced a suit against TP-Link related to Wi-Fi routers.[1] Subsequent filings the same week named drone seller Anzu Robotics, baby-monitor company Lorex, and e-commerce platforms Temu and Shein.[2] The industries differ. What the AG's office emphasized was alleged ties to the People's Republic of China and data or origin concerns under Texas consumer law.
Paxton's office framed the week as a coordinated series of actions. The legal form is primarily consumer protection under Texas statutes such as the Deceptive Trade Practices Act. National-security vocabulary appears in public statements and complaints; that rhetoric is advocacy, not a federal designation by itself.
Public materials also show longer preparation: investigation activity described from late 2025, and Texas measures affecting state employee use of certain TP-Link products.[1] Treat the suits as pending or ongoing litigation unless a final judgment says otherwise.
Replace siloed classification work with AI.
METI's FY2024 data shows 52% of foreign exchange law violations stem from classification errors. Download the TRAFEED product catalog covering features and rollout.
TP-Link litigation: origin labeling and botnet-related claims
Among the five matters, the TP-Link complaint drew the most attention for its language. Court filings and AG releases describe routers as critical home-network gateways and raise two themes that compliance teams should track as risk signals, not as adjudicated facts:
- Origin and operations — allegations that products labeled with one country of final assembly remain substantially designed, supplied, or operated through China-linked structures.[2]
- Security history — references to public reporting that compromised SOHO routers, including TP-Link models in some campaigns, were used as infrastructure in password-spray and related activity.
On the second theme, Microsoft described Chinese state-linked activity (Storm-0940) using credentials from password spray via a covert network that included compromised routers (Quad7 / related reporting).[4] CISA's Known Exploited Vulnerabilities Catalog has listed multiple TP-Link product CVEs that were observed as exploited in the wild.[5] Those are vulnerability and threat-intel facts. They do not, standing alone, prove company intent or a court finding of liability in the Texas case.
China's National Intelligence Law (2017), Article 7, requires organizations and citizens to support, assist, and cooperate with state intelligence work in accordance with law.[3] Western risk assessments often cite that statute when evaluating PRC-incorporated vendors. Citation of the statute is a legal-environment fact. It is not a finding that any particular company has turned over customer data.
TP-Link has publicly stated that its relevant US-facing entity is headquartered in Singapore and is not under PRC government control.[6] Texas materials emphasize supply-chain and operational substance over legal domicile. Covered List treatment, AG filings, and company rebuttals can all be true as records without any of them being a final judicial determination of wrongdoing.
Smart TV ACR cases: viewing data, not export licenses
In December 2025, Texas sued five TV makers — Sony, Samsung, LG, Hisense, and TCL — over Automatic Content Recognition (ACR) and related viewing-data practices.[7] ACR systems identify content on-screen and collect viewing data. Complaints and privacy reporting describe default-on settings and collection that can extend beyond linear TV to other on-screen sources depending on implementation.[10]
The AG's office obtained temporary court relief limiting certain ACR collection by Hisense in Texas[8] and announced related relief involving Samsung.[9] Those orders are procedural outcomes in consumer privacy litigation. They are not export-control classifications, and they do not establish that every named manufacturer violated a final judgment on the merits. Ownership structures among the five defendants also differ materially; do not collapse them into a single "Chinese TV" category.
Practical takeaway for households and corporate facilities: review ACR and related privacy settings on smart displays. Default-on telemetry is a product design choice that privacy teams should inventory.
On drones and baby monitors, Texas filings allege rebranding and component-origin issues involving parties that appear on various US government lists.[2] Department of Defense "Chinese military company" style listings are regulatory classifications. They are not criminal convictions. Keep that distinction when briefings travel from legal to board level.
| Party (as named in public Texas materials) | Product area | Nature of public claim (allegations unless noted) |
|---|---|---|
| TP-Link | Wi-Fi routers | Origin / China-link disclosures; security history referenced via third-party reporting |
| Hisense, TCL | Smart TVs | ACR data collection; National Intelligence Law cited as environment risk in advocacy |
| Sony, Samsung, LG | Smart TVs | ACR / privacy practices (ownership structures differ from PRC-headquartered peers) |
| Anzu Robotics | Drones | Alleged rebrand relationship to DJI products (unproven in a final merits judgment here) |
| Lorex | Baby monitors | Alleged use of components tied to listed organizations |
| Temu, Shein | E-commerce apps | Alleged aggressive data collection practices |
Salt Typhoon and Volt Typhoon: why edge devices stay on the threat brief
State litigation did not arise in a vacuum. Public US reporting describes long-running cyber operations attributed by the US government and industry to PRC state-sponsored actors.
Salt Typhoon reporting from 2024 onward describes deep access into major US telecommunications providers, including systems associated with lawful intercept processes, and large-scale metadata exposure concentrated around the Washington, D.C. region.[11][12] Later reporting and FBI statements described activity spanning many countries and hundreds of organizations.[13] Separate 2025–2026 reporting discussed further targeting of government-adjacent communications. Treat evolving news as reporting, and use CISA/FBI primary advisories where available for defensive priorities.
Volt Typhoon is described in CISA joint advisories as pre-positioning in critical infrastructure networks — power, water, telecom — with living-off-the-land techniques that abuse legitimate admin tools.[14] The FBI has announced botnet disruption actions against related infrastructure.[15] Industry research in 2025–2026 has discussed movement toward OT-connected environments and long-dwell access that defenders may never fully eradicate.[16]
| Cluster (public naming) | Assessed objective (USG/industry) | Primary environments discussed | Methods highlighted |
|---|---|---|---|
| Salt Typhoon | Intelligence collection | Telecom, high-value communications | Abuse of privileged network functions; large-scale metadata access |
| Volt Typhoon | Pre-positioning for disruption in crisis | Critical infrastructure IT and, increasingly, OT-adjacent systems | Living off the land; long dwell; botnet support infrastructure |
SOHO routers and other always-on edge devices matter in this picture because compromised consumer gear has been documented as relay infrastructure in other campaigns. That is a systems-security reason to care about patching, vendor selection, and network segmentation — separate from any single lawsuit.
Federal action that landed: FCC Covered List and foreign-made routers
Two federal tracks are easy to confuse:
- Commerce / export-trade measures aimed at particular vendors (including reported TP-Link-focused options that were set aside in early 2026 reporting).[17]
- FCC Covered List measures under the Secure and Trusted Communications Networks Act framework — the track that did produce a March 2026 update for foreign-made consumer routers.[18]
Under the Covered List update, new models without required FCC equipment authorization face effective barriers to US import and sale. Devices already in use generally continue to operate. Authorized models can remain available.[19][21] Public coverage noted conditional authorization pathways for some vendors (for example Netgear and Eero through a stated horizon) and that TP-Link did not obtain the same conditional treatment in the materials those outlets described; TP-Link has publicly discussed expanding manufacturing footprint including US capacity.[20] Market-share figures for TP-Link in US retail Wi-Fi vary by source and date; treat any single percentage as estimate, not regulation.[22][6]
Most important for supply-chain teams is the FCC's broad reading of "produced": not only final assembly location, but design and development activity abroad can bring a product into foreign-produced treatment.[19] Labeling "Made in Vietnam" after PRC-centric design and component sourcing may not settle the regulatory question. That is the same substance-over-label instinct state complaints raised — now expressed through federal equipment authorization rules.
What US companies should do with this stack of facts
If you operate networks, sell into regulated sectors, or export items subject to the EAR, the action list is operational:
- Inventory edge devices (routers, cameras, smart displays, industrial IoT gateways) by model, firmware, vendor, and authorization status.
- Separate privacy risk from export risk. ACR settings are a privacy/compliance workstream. Covered List and EAR screening are trade and telecom-security workstreams.
- Verify origin and ownership, not only packing-slip country. Design location, ultimate parent, and listed-party equity stakes all matter under different regimes.
- Patch and segment. KEV-listed vulnerabilities on SOHO gear are a concrete hygiene task regardless of brand politics.
- Prepare for the BIS Affiliates Rule return on November 10, 2026. Ownership of 50% or more by certain listed parties can import license requirements onto unlisted affiliates. Full calculation patterns and Red Flag 29: BIS 50% Rule complete guide. Primary stay text: Federal Register FR Doc 2025-19846.[23]
TRAFEED supports the screening and ownership-mapping side of this problem: multi-list restricted-party checks, capital-relationship context, and classification decision support for dual-use shipments. Final license and procurement decisions stay with your compliance owner. For program design, book a consultation or review the TRAFEED catalog (PDF).
Internal knowledge control is a parallel track when the concern is data exfiltration rather than outbound dual-use licensing. ZEROCK focuses on GraphRAG-based knowledge management so organizations can see who can reach which sensitive materials — useful when supply-chain briefings and design files should not sprawl across unmanaged shares.
The through-line is not "ban every Chinese-branded product tomorrow." It is that US regulators and state AGs are acting on origin, ownership, data practices, and cyber history with more force than packing labels can absorb. Programs that still equate "not on a sanctions list" with "cleared" will under-read Covered List authorization, privacy litigation, and 50% ownership rules that never print the affiliate's name.
References
[1] Texas Attorney General. (2026, February 17). Attorney General Paxton Sues TP Link for Allowing the CCP to Access Americans' Devices. https://www.texasattorneygeneral.gov/news/releases/attorney-general-paxton-sues-tp-link-allowing-ccp-access-americans-devices-first-several-lawsuits
[2] Texas Policy Research. (2026, February 20). Texas Files Four Major Lawsuits Against CCP-Linked Companies. https://www.texaspolicyresearch.com/texas-files-four-major-lawsuits-against-ccp-linked-companies/
[3] China Law Translate. (2017). PRC National Intelligence Law. https://www.chinalawtranslate.com/en/national-intelligence-law-of-the-p-r-c-2017/
[4] Microsoft Security. (2024, October 31). Chinese threat actor Storm-0940 uses credentials from password spray attacks from a covert network. https://www.microsoft.com/en-us/security/blog/2024/10/31/chinese-threat-actor-storm-0940-uses-credentials-from-password-spray-attacks-from-a-covert-network/
[5] CISA. Known Exploited Vulnerabilities Catalog. https://www.cisa.gov/known-exploited-vulnerabilities-catalog
[6] TP-Link. (2025, March 5). TP-Link Systems Inc. Sets the Record Straight Regarding Inaccurate U.S. Market Share Data. https://www.tp-link.com/us/press/news/21656/
[7] Texas Attorney General. (2025, December 15). Attorney General Paxton Sues Five Major TV Companies, Including Some with Ties to the CCP, for Spying on Texans. https://www.texasattorneygeneral.gov/news/releases/attorney-general-paxton-sues-five-major-tv-companies-including-some-ties-ccp-spying-texans
[8] Texas Attorney General. (2025, December 17). Attorney General Ken Paxton Secures Court Order Stopping CCP-Aligned Smart TV Company from Spying on Texans. https://www.texasattorneygeneral.gov/news/releases/attorney-general-ken-paxton-secures-court-order-stopping-ccp-aligned-smart-tv-company-spying-texans
[9] Texas Attorney General. (2026, January 6). Attorney General Ken Paxton Secures Major Win, Stopping Samsung from Using Its Smart TVs to Illegally Spy. https://www.texasattorneygeneral.gov/news/releases/attorney-general-ken-paxton-secures-major-win-stopping-samsung-using-its-smart-tvs-illegally-spy
[10] IAPP. (2026, January 26). Automated content recognition technology takes privacy enforcement spotlight. https://iapp.org/news/a/automated-content-recognition-technology-takes-privacy-enforcement-spotlight
[11] Congress.gov (Congressional Research Service). Salt Typhoon Hacks of Telecommunications Companies and Federal Response Implications (IF12798). https://www.congress.gov/crs-product/IF12798
[12] The Wall Street Journal. (2024, October 5). U.S. Wiretap Systems Targeted in China-Linked Hack. https://www.wsj.com/tech/cybersecurity/u-s-wiretap-systems-targeted-in-china-linked-hack-327fc63b
[13] Nextgov. (2025, August 27). Salt Typhoon hackers targeted over 80 countries, FBI says. https://www.nextgov.com/cybersecurity/2025/08/salt-typhoon-hackers-targeted-over-80-countries-fbi-says/407719/
[14] CISA. (2023, May 24). PRC State-Sponsored Actor, Volt Typhoon, Compromises U.S. Critical Infrastructure (AA23-144a). https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-144a
[15] FBI. (2024, September 18). FBI Director Announces Chinese Botnet Disruption at Aspen Cyber Summit. https://www.fbi.gov/news/stories/fbi-director-announces-chinese-botnet-disruption-exposes-flax-typhoon-hacker-group-s-true-identity-at-aspen-cyber-summit
[16] The Record. (2026, February 19). Researchers warn Volt Typhoon still embedded in US utilities. https://therecord.media/researchers-warn-volt-typhoon-still-active-critical-infrastructure
[17] 9to5Mac. (2026, February 18). Federal ban on TP-Link routers shelved, but Texas fights on. https://9to5mac.com/2026/02/18/federal-ban-on-tp-link-routers-shelved-but-texas-fights-on/
[18] FCC. (2026, March). FCC Updates Covered List to Include Foreign-Made Consumer Routers. https://www.fcc.gov/document/fcc-updates-covered-list-include-foreign-made-consumer-routers
[19] FCC. (2026). FAQs on Recent Updates to FCC Covered List Regarding Routers Produced in Foreign Countries. https://www.fcc.gov/faqs-recent-updates-fcc-covered-list-regarding-routers-produced-foreign-countries
[20] Foundation for Defense of Democracies. (2026, June 30). FCC Introduces New Bans on Chinese-Produced Equipment Linked to Cyber Risks. https://www.fdd.org/analysis/2026/06/30/fcc-introduces-new-bans-on-chinese-produced-equipment-linked-to-cyber-risks/
[21] Consumer Reports. What the FCC Ban on Foreign-Made Routers Means for U.S. Consumers. https://www.consumerreports.org/electronics-computers/wireless-routers/foreign-made-routers-fcc-ban-a1057564057/
[22] The Wall Street Journal. (2024, December 18). U.S. Weighs Ban on Chinese-Made TP-Link Router in Homes. https://www.wsj.com/politics/national-security/us-ban-china-router-tp-link-systems-7d7507e6
[23] Federal Register. (2025, November 12). One Year Suspension of Expansion of End-User Controls for Affiliates of Certain Listed Entities (2025-19846). https://www.federalregister.gov/documents/2025/11/12/2025-19846/one-year-suspension-of-expansion-of-end-user-controls-for-affiliates-of-certain-listed-entities

![[2026 Edition] What Are Research Integrity and Research Security? A Plain-Language Guide to Why Universities and Research Institutions Should Prepare Now](/images/columns/research-integrity-security-basics/cover.png)




