Yesterday, following a second National Security Determination from the Department of War (“DoW”), the Federal Communications Commission (“FCC”) clarified the scope of its ban on foreign-produced “power inverters,” a category of devices added to the FCC’s “Covered List” in late July. This new determination revises and narrows the definition of power inverters to more
Continue Reading FCC Narrows Covered List Definition of “Power Inverters” and Clarifies Meaning of “Foreign-Produced”National Security
FCC Restricts Imports of New Foreign-Produced Power Inverters and Advanced Robotic Devices with Additions to its Covered List
On July 28, 2026, the FCC added foreign-produced power inverters and advanced robotic devices to its Covered List, following determinations by an executive branch interagency body that they pose “unacceptable risks” to the national security of the United States. The new additions continue a string of decisions placing entire categories of foreign-produced devices on…
Continue Reading FCC Restricts Imports of New Foreign-Produced Power Inverters and Advanced Robotic Devices with Additions to its Covered ListCJEU Advocate-General indicates that communications network operators can lawfully be required to remove Chinese components, and that compensation is not required
FCC “Covered List” Updated to Include Certain Drones and Related Components, Subject to an Exception
In late December 2025, the FCC updated its “Covered List” to add foreign-produced unmanned aircraft systems (UAS), commonly known as drones, and their critical components after an Executive Branch interagency body determined that they pose “unacceptable risks to the national security of the United States and to the safety and security of U.S. persons.” Subsequently…
Continue Reading FCC “Covered List” Updated to Include Certain Drones and Related Components, Subject to an ExceptionCovington Tech Briefing Spotlight: Impact of Latest Policy Developments on the Tech Industry
On September 24, 2025, Covington’s tech industry experts explored what legal teams, government affairs professionals, and business leaders at tech companies need to know during this pivotal period and offered insights into anticipated challenges and emerging opportunities in the year ahead. Eight Covington attorneys shared their insights during a 60-minute session moderated by Covington partner…
Continue Reading Covington Tech Briefing Spotlight: Impact of Latest Policy Developments on the Tech IndustryFive major changes to the regulation of cybersecurity in the UK under the Cyber Security and Resilience Bill
As the UK Government has recognized, cyber incidents—such as Jaguar Land Rover, Marks and Spencer, Royal Mail and the British Library—are costing UK businesses billions annually and causing severe disruption. The Government recognizes that cybersecurity is a critical enabler of economic growth (“we cannot have growth without stability”), and that the current laws have “fallen out of date and are insufficient to tackle the cyber threats faced by the UK.” Accordingly the UK Government this week published its long-awaited Cyber Security and Resilience Bill (the “Bill”), which will amend the existing Network and Information Systems Regulations 2018 (the “NIS Regulations”), and grant new powers to regulators and the Government in relation to cybersecurity.
The NIS Regulations are the UK’s pre-Brexit implementation of Directive (EU) 2016/1148 (the “NIS Directive”), which established a “horizontal” cybersecurity regulatory framework covering essential services in five sectors (transport, energy, drinking water, health, and digital infrastructure) and some digital services (online marketplaces, online search engines, and cloud computing services). EU legislators replaced NIS Directive in 2022 with the “NIS2” Directive, which Member States were meant to transpose into national law by October of last year (although many are still late in doing so. See our post on NIS2 here for an overview of the requirements of NIS2).
The Bill is the UK’s effort at modernizing the framework originally set out in the NIS Directive. In its current form, the Bill will:
- Significantly expand the scope of the NIS Regulations—to cover, among other things, data centers and managed service providers—and impose additional substantive obligations on covered organizations.
- Increase potential fines—up to GBP 17m or 4% of the worldwide turnover of an undertaking—and extend the powers of competent authorities to share information with one another, issue guidance, and take enforcement action.
- Establish a framework for future changes to the NIS Regulations, mechanisms for competent authorities to impose specific cybersecurity requirements on covered organizations, and greater Government direction of cybersecurity matters.
Below, we set out further detail on five major changes in UK cybersecurity regulation arising from the Bill.
Continue Reading Five major changes to the regulation of cybersecurity in the UK under the Cyber Security and Resilience BillFCC Modifies Equipment Authorization Rules to Address National Security Concerns
Updated December 4, 2025. Originally posted November 26, 2025
On October 29, 2025, the Federal Communications Commission (“FCC”) released its Second Report and Order (the “R&O”) and Second Further Notice of Proposed Rulemaking (“FNPRM”) concerning changes to its equipment authorization rules. The R&O and FNPRM continue the FCC’s ongoing efforts to update the agency’s equipment…
Continue Reading FCC Modifies Equipment Authorization Rules to Address National Security ConcernsFCC Takes Action on Certain “Bad Labs”
Earlier this month on September 8, the Federal Communications Commission (FCC) announced that it was taking an initial set of actions to address threats posed by so-called “bad labs.” “Bad labs” consist of test labs that review and approve radio frequency emitting devices for use in the U.S. but are “ultimately owned or controlled by…
Continue Reading FCC Takes Action on Certain “Bad Labs”European Commission adopts technical standards for the decentralized communication system to be used under the forthcoming e-evidence Regulation
The EU e-evidence Regulation and Directive, which establish a regime for law enforcement authorities (“LEAs”) in one Member State to issue legally-binding demands for data from certain types of providers established in other Member States, will come into effect on 18 August 2026 (our post on the specific requirements of the Regulation and Directive is available here). On 28 July 2025, the European Commission adopted an Implementing Regulation (“IR”) setting out the technical specifications for the decentralized communications system that LEAs and covered service providers must use when, among other things, issuing and responding to European Production Orders (“EPOs”) and European Preservation Orders (“EPrOs”) under the e-evidence Regulation.
Continue Reading European Commission adopts technical standards for the decentralized communication system to be used under the forthcoming e-evidence RegulationTrump Administration Issues AI Action Plan and Series of AI Executive Orders
On July 23, the White House released its AI Action Plan, outlining the key priorities of the Trump Administration’s AI policy agenda. In parallel, President Trump signed three AI executive orders directing the Executive Branch to implement the AI Action Plan’s policies on “Preventing Woke AI in the Federal Government,” “Accelerating Federal Permitting of…
Continue Reading Trump Administration Issues AI Action Plan and Series of AI Executive Orders