By adding new connected power inverters and advanced robotic devices manufactured abroad to the Covered List, Washington is turning technological dependence into a matter of national security. Applied consistently, this same criterion forces the European Union to question US control over the platforms and accounts on which its administrations, services and infrastructure depend initially published in Italian by La Repubblica-Italian Tech by Andrea Monti
The ban is not blanket, as exemptions are possible through the ‘conditional approval’ system, under which the Department of Defence or the Department of Homeland Security has the power to decide whether a specific device poses unacceptable risks to national security.
The reasons for the ban
The reasons for this decision are stated in no uncertain terms. With regard to inverters, the document states that the remote control of these devices is a vulnerability that “could allow foreign companies to disable the inverters or use them to collect and steal data, facilitate remote access and surveillance by foreign government actors, or be exploited in other ways through a cyber-attack”; whilst, with regard to robots, the FCC considers that “The network capabilities of advanced robotic systems create numerous vulnerabilities and attack vectors capable of manipulating the data and physical operation of such systems. Relying on foreign-manufactured advanced robotic devices entails unacceptable vulnerabilities in terms of the supply chain and cyber security… Advanced robotic devices collect data that could be exploited by malicious actors to surveil US citizens, enhance the capabilities of foreign intelligence services, or take remote control of the robots.”
From technical vulnerability to strategic dependence
To understand what prompted the FCC to take such a step, it is necessary to examine how the agency uses the term “vulnerability”.
Traditionally, in the technology sector, the concept of vulnerability is associated with flaws in design, manufacture or use that affect products and software (a distinction, incidentally, that is becoming increasingly blurred). Thus, something is ‘vulnerable’ if, when it malfunctions, it causes damage or if someone manages to exploit these flaws to commit unlawful acts.
By contrast, the vulnerability referred to by the FCC does not concern the risk that an inverter might malfunction or that a robot might go out of control due to a fault in the programmes controlling it. On the contrary, the concern is based on diametrically opposed grounds: precisely because these technologies function well and are controllable by other countries, their widespread adoption could undermine the very foundations of strategic sectors of the US economic and industrial system.
So, to summarise the issue in a single sentence, the unacceptable vulnerability identified by the FCC is the loss of autonomy.
National security and economic dependence
The problem is certainly not easy to resolve because, as has become clear from the dossier on tariffs, the intertwining of industrial, financial and political relations between the US and China does not allow either side to adopt rigid positions or cause excessive tensions. It is therefore realistic to assume that, at least in the short term, the pendulum will continue to swing between retaliatory measures and mutual concessions.
The fact remains, however, that the concerns expressed by the US authorities are entirely well-founded, reasonable and evident.
Who could accept – and to what extent – that the functioning of a critical sector, such as the energy sector undoubtedly is, should be dependent on components and materials sourced from ‘unfriendly’ countries? And who could ever allow these components to be managed remotely, from locations other than the US, and by entities whose top priority is not American interests?
The EU’s inert strategy
But if this is true — and it is — then how should we respond if we replace ‘US’ with ‘EU’ and ‘China’ with ‘US’ in this equation?
In other words, if the definition of vulnerability adopted by the FCC holds true, then for the sake of consistency we should ask ourselves how we can accept that ever-larger parts of the administrative structure of the EU and its individual Member States operate solely — to quote the FCC — via software that “collects data that could be exploited by malicious actors to surveil citizens …, enhance the capabilities of foreign intelligence services or take remote control” of systems and infrastructure.
Regardless of the merits of the argument, the strategy of the current US administration is clearly based on the time-honoured yet still relevant and effective Machtpolitik of Prussian origin. It is therefore impossible to rule out entirely that, for example, in response to the sanctions-driven activism of national authorities and the European Commission, in addition to tariffs and other forms of retaliation, the US might decide – even if only for show – to order Big Tech to suspend the accounts that allow various institutions to use platform services.
The account as an instrument of sovereignty
So, if any further proof were needed, the FCC’s decision serves – albeit unwittingly – as a reminder to the EU of the most glaring error that has compromised its ability to achieve genuine technological autonomy: having accepted that the entire technological ecosystem is based on the concept of the ‘account’ – that is, to repeat ad nauseam the points made by the FCC – on a system that allows foreign countries to exercise remote control, to collect data on those who use devices and systems, and to prevent them from functioning.
In such a context, it matters little whether it is China, the US or anyone else.
