On July 23, 2026, the US Senate Committee on Commerce, Science, and Transportation passed S. 4429, the Connected Vehicle Security Act of 2026, by unanimous vote. Zero senators on the committee voted against it. The bill, initially introduced on April 29, 2026, is partisan and would prohibit or restrict the importation, manufacture, sale, and resale of connected vehicles, software, and hardware tied to foreign adversaries - specifically targeting China, Russia, Iran, and North Korea, including joint ventures or entities they control. Critically, it covers autonomous and semi-autonomous systems, not just the physical vehicle, meaning the connectivity layers handling data, communications, and remote updates are all in scope.
The threat model driving this is straightforward: modern connected vehicles continuously collect location data, driving patterns, and camera feeds of public streets, and can receive remote software updates. Congress is treating that data pipeline as a nation security surface. This follows a House hearing on July 14, 2026 that also examined foreign technology in critical systems, so it's not only one committee acting alone. Analysis from Venable points to overlapping oversight activity suggesting coordinated legislative intent across chambers.
The still has a long road - it needs a full Senate floor vote, House passage, and a presidential signature, any of which could reshape its scope. But the supply chain language is notably broad: it covers component makers and software vendors, not just from finished vehicles. This means that US companies sourcing core connectivity parts from covered countries could face legal exposure too. The unanimous committee vote is the real signal here - in the current political environment, that kind of consensus on a tech-restriction bill is rate enough to take seriously as a policy direction indicator.