In March 2026, the Federal Communications Commission (FCC) extended its “covered list” of controlled communications equipment and services to include all new foreign-produced, consumer-grade routers, which the administration deemed to pose unacceptable risks to national security. In effect, this extension banned the importation and marketing of these routers in the United States. As discussed in Part I of this series, this move was premised on genuine cybersecurity concerns, with the Volt, Salt, and Flax Typhoon cyberattacks of 2023-2024 cited as justification for the ban. However, the administration’s approach does little to address the underlying vulnerabilities that served as vectors for those attacks. As noted in various after-action reports on these attacks, the threat actors exploited weak password protections and software bugs or targeted older devices no longer receiving security updates. These reports do not blame the place where the devices were manufactured. Indeed, by banning the importation and marketing of new routers, the order not only limits competition in the router marketplace but restricts consumer access to new, safer routers to a handful of companies that secure the administration’s “conditional approval.” In doing so, the order risks increasing vulnerability to cyberattacks. Moreover, there remains some uncertainty as to whether the ban will extend further to include enterprise-grade routers as well.

Industry groups, think tanks, and cybersecurity experts alike have criticized the FCC’s decision, some noting that it received less scrutiny due to pressure from the executive branch. Nevertheless, this influence alone does not explain the router ban. The process established by the administration for producers seeking conditional approval to sell new routers in the United States offers further indication of what is driving this policy. That is, the ban is a form of backdoor mercantilism in the garb of cybersecurity that serves to protect a handful of favored firms while giving bureaucrats and elected officials control over an administered marketplace. Indeed, as one former FCC official put it, the ban seems almost tailor-made to create “a new federal program of conditional approvals” for foreign router companies.

Influencing Policy

As detailed in the FCC’s press release, the router ban decision reflects the Trump administration’s ongoing efforts to strategically decouple the United States from China. It also aims to counteract the real risks of state-backed hacker groups targeting America’s infrastructure. Whatever the merits of these two goals, pursuing them effectively requires that each step along the way be scrutinized to ensure that a) the policy instrument deployed matches the issue and b) that this instrument does not impose an excess burden on citizens. While imperfect, such a technocratic process forces proponents of regulations to show their work and demonstrate that any new regulation delivers at least as much value to society as it destroys. This is why regulatory analysis matters—it serves as at least a partial brake on the volume of regulations imposed on society.

Since 1981, federal agencies have been required to conduct cost-benefit analysis to assess the economic ramifications of new regulations. While regulatory analysis tools are intended to help policymakers quantify and better understand the potential costs of their decisions and avoid harmful new rules, their application and quality varies across agencies and administrations. Research has found that rules or administrative actions that align with or advance an incumbent president’s policy priorities tend to undergo less rigorous analysis before implementation.

The router ban bears the hallmarks of executive influence on agency decision-making. First, the ban emerged from a closed-door process involving an “interagency body with appropriate national security expertise, including appropriate national security agencies.” According to the FCC’s press release, the agencies in question likely consisted of the National Security Agency, the Federal Bureau of Investigation, the Departments of Defense (DOD) and Homeland Security (DHS), and the Office of the Director of National Intelligence. Citing reports from various national security agencies and technology companies on the Salt, Volt, and Flax Typhoon cyberattacks and others, the summary of determination does not prove that the routers’ overseas production was the operative risk factor. Indeed, as noted in Part I of this series, the vulnerabilities revealed by these attacks were unrelated to router hardware or manufacturing location.

Yet the process to create this new ban was rushed. The FCC’s public notice was published March 23 without the usual public rulemaking process. As with cost-benefit analysis, the public comment and input process embodied in the administrative rulemaking process is itself only a slim defense against regulatory overreach by agencies. Nevertheless, had this procedure been followed, it is quite possible that the router ban would at least have been more narrowly scoped. A public comment period would likely have surfaced the instrument mismatch that critics identified immediately upon publication of the order or the logical flaws behind the decision itself. The added scrutiny could have limited the costs imposed on consumers as well as broader disruptions to the marketplace. Instead, the administration seems more concerned with using the ban as a form of mercantilism than promoting cybersecurity. This impression is supported by the national security determination’s emphasis on production location as well as a stipulation in the “conditional approval” guidelines that says companies must outline a plan to reshore manufacturing to the United States.

The Hackers and the Bootleggers

The Trump administration has broken precedent with previous conservative administrations through its explicit embrace of state capitalism. This approach to economic policymaking has carried through from trade and manufacturing into the technological sector. Starting with an August 2025 investment in Intel, the administration has hosted a growing circle of technology companies eager to carve out a share of its largesse. Alongside semiconductor manufacturers, quantum computing developers and potentially artificial intelligence (AI) companies, router manufacturers are only the latest to become entangled with the executive branch.

The near-total absence of domestic router manufacturing capacity in the United States creates a leverage point that could be exploited by an existing firm looking to keep out competitors and dominate the market by political means. Indeed, router manufacturers have been lobbying Congress on issues related to cybersecurity, data privacy, and technology and previously engaged in advocacy for the ROUTERS Act. That bill would have required the National Telecommunications and Information Administration to study the risks associated with routers produced in adversary states. Several of these companies also received conditional approval from the federal government. While these facts do not establish that the ban was instituted for these router manufacturers’ benefit, they do evince the political-economic dynamics that may underlie this policy.

As argued in Part I, a country-of-origin ban is the wrong approach to hardening U.S. cybersecurity; however, it is a useful tool for companies potentially seeking to restrict foreign competition. By blocking the importation of foreign-made routers, the router ban creates an administratively controlled market that limits competition to just those firms that have obtained a waiver. Limiting competition to just those firms approved by the executive branch gives the remaining companies the ability to earn profits above what competitive markets would allow by charging higher prices.

Of course, this would not represent a pure windfall to favored companies. As the conditional approval procedures state, to gain entry into this cartel arrangement, firms must either invest in existing American factories or relocate some of their manufacturing capacity here (or at least create plans to do so). The opacity of the process whereby waivers are granted creates opportunities for members of Congress, particularly those sitting on national security and communications committees, to intercede in the approval process on behalf of an applicant. Firms seeking waivers have every incentive to invest where they can generate political support, effectively sharing their profits with politicians who are well positioned to support their application.

Indeed, of the various constituencies in this arrangement, the politicians and bureaucrats who oversee the administered market will likely be the biggest beneficiaries of this ban. For bureaucrats inside the DOD, DHS, and FCC, the ban increases their regulatory discretion and can be used to justify bigger budgets. Administering a complex approval process requires personnel, legal resources, and technical expertise, all of which provide grounds for agency heads to request increases in their appropriations from Congress. Moreover, the opacity of the actual approval process affords bureaucrats greater discretion in the selection and approval of firms. This creates conditions under which officials might be tempted to use their authority for personal gain, either by enhancing their future career prospects outside of government or by seeking other inducements from firms dependent on their decisions.

Depending on how long the ban persists, companies that obtain a conditional waiver will likely fall victim to the “transitional gains trap,” wherein the value of the advantages conferred by their protected status is priced into their cost structures. Companies with waivers become increasingly dependent on bans to protect them because they would fail in a competitive and free market. This dilemma has the perverse effect of creating opportunities for officials who control access to the administered market to extract favors from incumbent firms in exchange for preserving their protections. Since approvals only last up to 18 months, the waiver process has a built-in mechanism whereby these favors can be routinely extracted if router manufacturers hope to retain their exemptions. This trap would become tighter with each passing approval cycle as companies invest more in maintaining political connections than in new, more secure, or faster routers.

Thus, while certain router companies could benefit temporarily from reduced competition and barriers in the approved router market, any extra profits gained will be used up gradually in lobbying and maintaining the favor of policymakers and regulators. These gains will be reduced further by the inefficiencies that limited competition invites. Indeed, the foreign router ban’s most durable beneficiaries are not American companies, but the bureaucrats and politicians administering the ban.

What Can Be Done?

Cybersecurity is a pressing issue. Novel threats continue to emerge, and with the advent of increasingly advanced AI models, the pace at which threats evolve only seems likely to increase. More precisely, cybersecurity is a complex array of threat vectors that manifest at different governance levels and require a range of policy instruments to be addressed adequately. If policy is to productively enhance American resilience against these threats, then policymakers should consider the full range of policy responses, including no intervention at all. Where government intervention is justified, the policy instrument selected must target the particular issue and must not impose greater costs on society than it creates. The FCC’s router ban fails on both counts—not only is it poorly targeted, it also imposes costs on consumers and businesses that outweigh any demonstrable security benefit. Worse, the ban seems designed to serve the private interests of a handful of firms.

Cybersecurity’s complexity limits the efficacy of general regulation aimed at applying one-size-fits-all policies. Indeed, regulations designed to improve cybersecurity may have the opposite effect of impeding adaptation to novel cyber threats. Moreover, relying solely on the federal government to address cybersecurity ignores the steps already taken by private actors as well as steps that state and local governments can take to harden their own systems to emerging threats or mitigate the after-effects. Part I noted the role played by cyber insurance as both a means to absorb the losses imposed by cyberattacks of any size and to incentivize firms and individuals to improve security procedures. Beyond the financial services industry, similar private market innovations have been developed in the realm of software patching, in authentication protocols, and in the creation of industry-level information-sharing networks. Federal policy should aim to buttress the underlying processes that gave rise to these cooperative institutions and continue to drive society’s adaptation to emerging threats rather than supplanting them through top-down mandates.

To this end, the blanket extension of the FCC’s ban to all new foreign-manufactured routers should be undone. Any such rule should be pursued through the normal notice and comment procedure, allowing for the scrutiny and consultation necessary to help policymakers tailor the instrument to fit the scale of the risk involved. More generally, cybersecurity policy should be polycentric, recognizing where particular threats are better addressed by regional or state governments or by private ordering solutions. Such a multi-stakeholder approach would help right-size policy while preserving the freedom necessary for cybersecurity innovation. As one risk scholar aptly put it, “Relative safety is not static, but is rather a dynamic product of learning from error over time.”  

Our Technology and Innovation program focuses on fostering technological innovation while curbing regulatory impediments that stifle free speech, individual liberty, and economic progress.