Sentinel Vault
← All field notes
Cyber Leadership & Risk · May 15, 2026

Rolling Sensors: What the Connected Vehicle Security Act Says About the Cars in Our Driveways

Rolling Sensors: What the Connected Vehicle Security Act Says About the Cars in Our Driveways

A modern connected vehicle is not a car with software in it. It is a sensor platform with wheels.

A 2024 Tesla Model 3 carries eight cameras, twelve ultrasonic sensors, a forward radar, GPS, an accelerometer, gyroscope, cabin microphones, a cellular modem with always-on connectivity, and an in-cabin camera that watches the driver's face. A BYD Han or a Xiaopeng P7 carries a comparable sensor package. So does a Polestar 3, a Volvo EX90, an MG4. The hardware does not vary much across the global market. What varies is who designs it, who gets the data, and what legal regime applies to the company storing it.

On May 12, 2026, Representative John Moolenaar (R-MI), Chairman of the House Select Committee on the Chinese Communist Party, and Representative Debbie Dingell (D-MI) introduced the Connected Vehicle Security Act. The bill would ban the importation, manufacture, sale, and introduction into U.S. commerce of connected vehicles, software, and hardware originating from or controlled by a covered foreign adversary country. Civil penalties start at $1.5 million per violation. Most provisions take effect January 1, 2027. The hardware ban runs to 2030.

Moolenaar's framing in the announcement was direct: Chinese vehicles and components could capture information on "location, movement, people, and infrastructure in real time."

That framing is operationally accurate, not rhetorical. What follows is what the data harvest looks like when scaled across millions of vehicles, why the legal architecture in Beijing makes a Chinese-origin OEM categorically different from a French or Korean one, and why a Michigan-Ohio coalition spanning both parties is moving on it now.

What a connected vehicle actually collects

The forward-facing cameras on a modern EV operate continuously while the vehicle is in motion. They are doing real work, not waiting for a crash. They read lane markings, traffic signs, brake lights on the car ahead, pedestrian movement, license plates of vehicles in the surrounding traffic, road construction signage, business signage, and storefront branding. The data feeds the driver-assist stack and, depending on the OEM, gets uploaded to cloud infrastructure for fleet-learning and model-training purposes.

The cabin camera, present on most current-model EVs, watches the driver. On Teslas it monitors for inattentive driving. On other platforms it does the same plus biometric driver identification, in-cabin payment authentication, and emotion or fatigue detection.

Cabin microphones are a standard component. Voice assistants need them. So do hands-free calling, in-cabin payment voice prompts, and automatic emergency call dispatch. The microphones do not turn off when the wake word is not spoken. They listen for it.

GPS reports continuous location at one-second granularity or finer. The cellular modem maintains an always-on link to the OEM cloud. Telematics push streams of vehicle state: speed, acceleration, braking force, steering angle, climate settings, occupant count via seat-pressure sensors, charge state, route history, and the addresses of every place the vehicle has been parked.

A modern OEM defends this collection as necessary for over-the-air updates, predictive maintenance, navigation routing, and the user experience. That defense is not wrong. It is also not the whole picture. The same data that enables a software update or a charging-network recommendation also constitutes a complete pattern-of-life profile of the driver, the household, and the routes they travel.

The Department of Commerce, in its January 2025 Final Rule on connected vehicle hardware and software, formally classified vehicle connectivity systems and automated driving systems as critical components subject to national-security review when sourced from foreign adversaries. The rule was the regulatory foundation that the Connected Vehicle Security Act now seeks to codify and extend.

The legal compulsion: PRC National Intelligence Law

The reason the analysis differs for a Chinese-origin OEM is not animus. It is statute.

Article 7 of the PRC National Intelligence Law, enacted in June 2017, reads: "All organizations and citizens shall, in accordance with the law, support, assist, and cooperate with national intelligence efforts, and guard the secrecy of any national intelligence work that they are aware of."

Article 14 obligates intelligence organs to "request that relevant organs, organizations, or citizens provide necessary support, assistance, and cooperation."

The construction is binding, not voluntary. A Chinese-domiciled corporation does not have the option to refuse a lawful request from China's Ministry of State Security or its military intelligence equivalents. There is no equivalent of the U.S. CLOUD Act warrant process, no judicial check, no public docket, no published statistics. The cooperation is mandatory and undisclosed.

This is not a claim that BYD, SAIC, or Geely is currently exfiltrating American driver data on behalf of the MSS. The claim is narrower and more precise: the legal architecture that would compel them to do so on demand already exists, and the company would face criminal liability in China for refusing a lawful order.

Compare to a French OEM under GDPR, a German OEM under BDSG, or a Korean OEM under PIPA. Those regimes constrain government access. The PRC regime requires it.

What the bill actually does

The Connected Vehicle Security Act is structured to address three failure modes the existing rules left open.

First, the bill covers vehicles that are not yet in U.S. commerce. The 2025 Commerce rule restricted hardware and software from foreign adversaries in connected vehicles sold in the U.S. The new bill expands the prohibition to cover importation, manufacture for export, and any introduction into commerce, closing the gap on parallel-market and re-export workarounds.

Second, it sets meaningful penalties. The Commerce rule depended on enforcement through licensing review and could be evaded by entities willing to absorb regulatory friction. A floor of $1.5 million per violation, with multipliers for repeat or willful conduct, makes the math less attractive.

Third, it sets implementation horizons that allow industry to comply. Most provisions take effect January 1, 2027. The hardware-component ban sits further out at 2030. The dates give OEMs time to redesign supply chains and give buyers time to plan replacement cycles.

The Senate version, introduced by Senators Elissa Slotkin (D-MI) and Bernie Moreno (R-OH), codifies the Biden-era Commerce rule in statute so that a future administration cannot rescind it administratively. The two bills are aligned.

The bipartisan signal matters. This is not a partisan litmus test. It is a Michigan-Ohio auto-state coalition responding to two distinct but reinforcing concerns: data security and industrial base.

Pattern-of-life on a national scale

Strip out the geopolitics for a moment and consider what the data harvest looks like operationally.

A single vehicle's location stream over thirty days reveals home address, work address, schools, daycare, gym, place of worship, medical providers, restaurants, friends' homes, and travel patterns. Aggregate across a household and you have the full social graph of the family.

Aggregate across a million vehicles in a metropolitan area and you have the economic activity map of the region: which businesses are growing, which are declining, which neighborhoods are gentrifying, where construction is happening, where crime is concentrated by time of day, and where law enforcement vehicles are deployed.

Aggregate across the country and you have the strategic map: which defense contractors are running at higher capacity than usual based on shift-change parking lot density, which military installations are seeing personnel surges that suggest deployment activity, which government office buildings are operating outside normal business hours, and which ports are receiving unusual traffic.

Forward-facing cameras add a layer. A vehicle parked in the lot of a defense contractor for an hour can capture license plates of every other vehicle in that lot. Cross-referenced over months, that is a roster of the workforce.

In-cabin microphones add another layer. Conversations during a commute are not legally protected the way a phone call is. The OEM owns the data stream by terms-of-service. The driver's own voice provides a biometric template usable for later identification in other contexts.

None of this requires real-time operator control. The data flows continuously to OEM cloud infrastructure as a normal function of the vehicle. A foreign intelligence service that has lawful compulsory access to that infrastructure does not need to compromise anything. It just needs to ask.

The industrial-base playbook

The data threat is the lead, but the industrial threat is the structural reason this fight is happening now.

China is currently the world's largest auto exporter. BYD outsold Tesla globally in EV units for the first time in 2024 and has continued to grow. The pricing model is not commercial. It is industrial policy. The Chinese state subsidizes EV production at every layer: battery materials processing, cell manufacturing, vehicle assembly, export financing, domestic charging infrastructure, and currency intervention to keep the renminbi favorable for export.

A BYD Atto 3 lands in European markets at a sticker price that Ford or GM cannot match at any margin. The American manufacturer is not failing on quality or design. It is being undercut by a state.

This is not a new pattern. The same playbook has been run on solar panels, where China now controls roughly eighty percent of global polysilicon, cell, and module manufacturing. It has been run on commercial shipbuilding, where China builds about half of global tonnage and the U.S. builds less than one percent. It has been run on consumer drones, where DJI captured the global commercial and prosumer market by 2018 and has held it. It was run on 5G telecom switches, where Huawei built dominance until U.S. and allied government action stopped the trajectory.

In each case, the pattern was the same: identify a strategic export sector, subsidize it at scale, capture the global market, and then weaponize the dependency. The dependency takes a different shape in each sector. With solar, it is supply-chain chokepoints on a critical-minerals input layer. With shipbuilding, it is the disappearance of U.S. industrial capacity to surge build during a conflict. With drones, it is data sovereignty over imagery collected by every commercial operator in the country. With 5G, it would have been embedded access to the telecom backplane of every country that adopted it.

With EVs, the dependency is both: data sovereignty over the driving population, and the loss of a manufacturing base that the U.S. needs for military vehicle production, surge capacity, and the blue-collar middle class in Michigan, Ohio, Indiana, and the Carolinas. Auto manufacturing employs about one million workers directly and supports roughly seven million across the broader supplier and dealer ecosystem.

The Connected Vehicle Security Act addresses both layers in one instrument. That is why the coalition behind it spans both parties and both chambers.

American-branded is not American-made

A buyer who wants to act on this analysis runs into a recognition problem.

Volvo Cars is owned by Geely, a Chinese conglomerate. Polestar is a Geely brand. Lotus is Geely. MG, the British heritage marque, is owned by SAIC, a Chinese state-owned enterprise. Smart, the Mercedes-Benz subcompact brand, is now a Geely-Mercedes joint venture with vehicle manufacturing in China.

Components are murkier. CATL, the Chinese battery maker, supplies cells to Tesla, Ford, BMW, Mercedes, and Volkswagen. A "made in America" sticker on a Tesla Model 3 does not change the fact that some battery packs in some configurations contain CATL cells. The vehicle's connected-services stack runs on Tesla's own software, but the cell hardware can still originate from a covered country.

The Connected Vehicle Security Act addresses this by writing the prohibition around control rather than nameplate. A vehicle "originating from or controlled by a covered foreign adversary country" includes brands owned by Chinese parents even when the assembly plant is in Sweden or Mexico. The hardware-component prohibition extending to 2030 allows the supply chain to redesign without immediate disruption.

The practical implication for a buyer in 2026 is that the brand on the badge is not the question. The question is the corporate ownership of the OEM, the location of the cloud infrastructure receiving the telemetry stream, and the legal regime that applies to the company storing the data. None of these are visible at the dealership.

What to do

For individual buyers in 2026, the action is research. Before signing on a connected vehicle, identify the OEM's parent corporation, the country of corporate domicile, and the cloud provider that handles vehicle telematics. The information is in the privacy policy and the parent-company filings, both publicly available.

For fleet operators, including law enforcement agencies, municipal governments, delivery services, and contractor businesses operating near sensitive sites, the analysis is more involved. The General Services Administration and the Department of Defense have begun publishing guidance for federal fleet procurement that excludes vehicles from covered foreign adversaries. State and local agencies do not yet have parallel formal guidance, but the analysis applies the same way.

For small business owners running fleets that operate near defense facilities, federal buildings, ports, utility infrastructure, or other critical sites, the routes your vehicles travel become the data your OEM holds. Ask the OEM what happens to that data, where it is stored, and under what legal regime.

For voters, the Connected Vehicle Security Act is in flight as of this writing. It has bipartisan sponsorship in both chambers. Whether it advances on its merits or gets attached as a rider to a larger vehicle (legislation, not the kind with wheels) will depend on the next several months of committee work.

For policy advocates, the 2027 implementation date for most provisions and the 2030 hardware date are the windows that matter. A vehicle purchased in 2026 will likely still be on the road in 2030 and beyond. The bill addresses the new-sales pipeline. It does not retire the existing fleet.

What comes next

The Connected Vehicle Security Act is one instrument in a longer arc. The next sectors in the same playbook are already visible.

Humanoid robotics is two to three years from mass commercial deployment, with Chinese manufacturers (Unitree, Fourier, Agibot, XPENG) now producing units at price points that American and Japanese competitors cannot match. The same data-sovereignty and industrial-base arguments apply, with the additional concern that a humanoid robot in a home or workplace has even more comprehensive sensor coverage than a vehicle.

Smart-grid infrastructure components, including transformers, inverters, and grid-management software, are increasingly sourced from Chinese manufacturers. The data is less personal than vehicle telematics, but the operational-control implications are higher. A compromise of grid-management infrastructure is a kinetic-effects vector.

Energy storage at the utility scale is already heavily dependent on Chinese cell manufacturing. The Inflation Reduction Act tax credits attempted to onshore some of this; progress has been uneven.

The pattern across all of these is the same one playing out in connected vehicles. The first move is recognition. The second is legislation that addresses both the data and the industrial-base layers. The third is execution: actually shifting supply chains, actually enforcing penalties, actually building the domestic capacity that the legislation assumes will exist.

The car in your driveway is the current case. It will not be the last.

About the author
Pete Hish, Sentinel Vault founder
Taught by Pete Hish · Founder

A working cyber-fraud supervisor, not a vendor consultant.

US Army veteran. Active sergeant supervising a cyber and fraud investigations team at a large Southern California law-enforcement agency. Ten-plus years inside the cases that hit small businesses, families, and public-sector agencies first. The training is shaped by what actually goes wrong, not what vendor decks predict.

Certified Cybersecurity SpecialistCertified Cyber Fraud SpecialistCalifornia POST Certified Instructor
Hacked or Hardened? book cover
Prefer the long-form version?

Hacked or Hardened? covers these patterns end-to-end — the four ways small businesses get hit, what to fix first, and how to lead through an incident.

Related field notes
Next step

Want this kind of analysis for your team?

A 2–4 hour cyber risk briefing: the threats specific to your business, the controls that actually pull their weight, and a 90-day action plan.