Hook
The FCC is about to cross a line it hasn't crossed before. Not with Huawei. Not with ZTE. Those were named entities โ specific companies with documented ties to foreign adversaries. The new proposal targets something far more mundane: optical modules. The transceivers that move data across every network on the planet. Not a company. Not a specific product line. An entire category of components manufactured by dozens of firms across multiple countries.
The Information Technology Industry Council โ the trade group representing Apple, Google, Microsoft, and Amazon โ filed formal opposition. Their argument is precise: focus on entities with clear links to foreign adversaries, not broad coverage of entire technology classes from trusted companies.
This is the moment the Covered List stops being a sanctions tool and becomes something else entirely. Something with a much longer reach.
Context
The Secure Equipment Act of 2021 gave the FCC authority to maintain a list of communications equipment posing national security threats. The first version dropped in 2022, naming specific entities. Huawei. ZTE. The usual suspects. By 2024, the list was expanding. Now the FCC wants to include optical modules as a product category โ regardless of manufacturer.
The optics here matter. Optical modules are commodity components. They sit inside switches, routers, and data center equipment. They're manufactured by Chinese firms like Zhongji Innolight and Eoptolink โ which together control over half the global market โ alongside American companies like Coherent and Lumentum. The supply chain is deeply integrated. A single data center switch might contain modules from three different manufacturers across three different countries.
ITI's opposition isn't about defending Chinese manufacturers. It's about what happens when the FCC starts banning categories instead of entities. If optical modules fall, what's next? Servers? Switches? Fiber optic cable? Power supplies? The precedent is the real issue.
Core
Let me break down what's actually happening here, because the surface narrative โ "FCC bans Chinese optical modules" โ misses the structural shift underneath.
The legal architecture is built on sand. The Secure Equipment Act authorizes the FCC to identify equipment "produced or provided by entities" that pose national security risks. The statutory language is entity-based. The FCC's proposal is category-based. That's not a minor interpretive difference โ it's a potential ultra vires problem. The agency is stretching delegated authority beyond its textual limits. Courts have struck down similar expansions before. R.J. Reynolds v. FDA. West Virginia v. EPA. The Major Questions Doctrine looms.
The chilling effect precedes the rule. Even if the FCC never finalizes this proposal, the damage is done. Procurement teams at major cloud providers are already reviewing their supply chains. They're asking questions about component origins. They're building contingency plans. This is the regulatory equivalent of a distributed denial-of-service attack โ the threat itself creates the disruption. I've seen this pattern before in my work auditing DeFi protocols: the mere possibility of a vulnerability gets priced into user behavior long before any exploit occurs.
The compliance burden is asymmetric. Large enterprises can absorb the cost of supply chain tracing, alternative vendor certification, and legal review. Small ISPs cannot. The FCC's proposal would force every federal contractor and grant recipient to verify the provenance of every optical module in their networks. That's a BOM-level tracing requirement โ bill of materials granularity โ that most organizations lack the infrastructure to support. The cost isn't trivial. It's millions for large operators, and potentially 5-10% of revenue for smaller players.
The supply chain reality is inconvenient. Chinese manufacturers dominate optical module production. Zhongji Innolight is the world's largest. Eoptolink is number two. American and allied manufacturers don't have the capacity to fill the gap. A category-wide ban creates a short-term supply vacuum. Projects stall. Prices rise. The FCC's own security goals become harder to achieve because network operators can't upgrade infrastructure without components.
The international dimension is explosive. This isn't just a domestic procurement rule. It's a trade barrier. The WTO's TBT Agreement requires that technical regulations not create unnecessary obstacles to international trade. A category-wide ban on optical modules โ without entity-specific evidence of security risks โ is vulnerable to challenge. China has already shown willingness to use WTO mechanisms and retaliatory measures. The optics module dispute could become the next front in the tech trade war.
The precedent problem is the real story. The FCC is testing whether it can shift from entity-based to category-based restrictions. If successful, the Covered List becomes a much more powerful tool. It can be applied to any component class with minimal evidentiary burden. The agency doesn't need to prove a specific company is compromised โ just that a category of products poses "potential" risks. That's a fundamentally different standard.
Contrarian
The bulls have a point. Let me be fair here.

The FCC's concern isn't manufactured. Optical modules are network-adjacent components. They handle data transmission. A compromised module could theoretically be used for surveillance or data exfiltration. The supply chain risk is real โ we've seen hardware backdoors before, from Supermicro's alleged server implants to the Cisco router compromises. The Chinese government's relationship with its tech sector is not the same as Western norms. There's legitimate reason for scrutiny.
And the industry's opposition isn't purely principled. ITI members are large buyers of optical modules. They benefit from low-cost Chinese supply. Their opposition reflects commercial interests as much as legal concerns. The "trusted companies" argument โ that modules from Coherent or Lumentum are safe โ is convenient for companies that want to keep procurement costs down.
The FCC's broader direction also has merit. The "small yard, high fence" approach to technology decoupling has a logic to it. Some components are genuinely critical to national security infrastructure. The question is where the line gets drawn โ and whether the FCC has the authority to draw it.
Takeaway
The FCC's optical module proposal is a test case. Not for optical modules specifically, but for the entire framework of supply chain regulation. If the agency succeeds in shifting from entity-based to category-based restrictions, the Covered List becomes a much more expansive tool. Every network component becomes potentially restricted. Every procurement decision becomes a compliance exercise.
The industry's response will shape the outcome. ITI's opposition is the opening move in what could become a multi-year administrative and legal battle. The FCC will likely adjust โ moving from "all foreign optical modules" to "specific Chinese manufacturers" โ but the precedent question remains unresolved.
The architecture of trust, engineered for failure. That's what happens when regulators expand authority faster than the legal framework can support. The FCC wants to secure the supply chain. The industry wants predictable procurement. Both goals are legitimate. The mechanism is the problem.
Watch the final rule text. Watch for the Major Questions Doctrine argument. Watch whether the FCC pauses implementation to allow industry adjustment. The next 12-18 months will determine whether the Covered List remains a targeted tool or becomes a category-based cudgel.

The modules are small. The precedent is not.