Today in Surveillance:
- Reuters reported on June 15, 2026 that the US Commerce Department rule banning Chinese-origin hardware and software in connected vehicles has pushed Ford and other automakers to apply for individual licenses to keep selling China-built models. The rule, formally titled "Securing the Information and Communications Technology and Services Supply Chain: Connected Vehicles," was finalized by the Commerce Department's Bureau of Industry and Security (BIS) on January 16, 2025 and took effect March 17, 2025.[1][2]
- The same week, Michigan Democrats Elissa Slotkin and Haley Stevens filed a state bill that would ban Chinese-tagged vehicles from even visiting Michigan. TechDirt's Mike Masnick reported on June 12, 2026 that the bill is framed around "jobs, consumer privacy, and national security," with Slotkin calling cheaper Chinese EVs "TikTok on wheels."[3]
- Both stories lean on a privacy argument. The privacy argument is the one US carmakers do not want to litigate. The same automakers seeking licenses to keep selling Chinese cars already collect, broker, and sell US drivers' location, biometric, and phone data, including the LexisNexis and Verisk data brokerages that bought driving data from GM's OnStar program.[4][5] The Michigan bill's "TikTok on wheels" framing is the framing that lets US carmakers avoid that question.
- Privacy is the political cover. Trade protection is the operative policy. The federal rule is a Section 1705 ICTS supply chain rule, not a privacy rule. The Michigan bill is a state-level trade restriction. Neither, in its text, regulates the data the vehicles collect. The data the vehicles collect is what US carmakers already sell.
- Watch in the next 7 days: the first specific license grant or denial under the BIS rule, the Michigan bill number and committee assignment, the first statement from a US automaker on its own data-collection practices in response to the bill, and the first Canadian or Mexican counter-measure, since the Canadian-Chinese vehicle agreement and USMCA free movement make the Michigan bill unenforceable at the Windsor border.
The Federal Hook: BIS Section 1705 Treats Cars as ICTS
Two days before Thanksgiving 2024, the US Commerce Department's Bureau of Industry and Security filed a final rule that, on its face, is about cars. The rule is actually about supply chains, and the supply chain is the broader one: information and communications technology and services (ICTS) that the Commerce Department treats as part of US national security infrastructure.
The rule is "Securing the Information and Communications Technology and Services Supply Chain: Connected Vehicles," published in the Federal Register on January 16, 2025 and effective March 17, 2025.[1] The Federal Register abstract for the rule is unusually direct about what it is doing. The rule, in BIS's words, "sets forth regulations and procedures to address undue or unacceptable risks to national security and U.S. persons posed by classes of transactions involving information and communications technology and services (ICTS) that are designed, developed, manufactured, or supplied by persons owned by, controlled by, or subject to the jurisdiction or direction of certain foreign adversaries and that are integral to connected vehicles as defined herein."[1]
The legal authority is Section 1705 of the International Emergency Economic Powers Act (IEEPA), the same authority the Trump administration used in the 2025 TikTok enforcement. Section 1705 lets the Commerce Department prohibit or license ICTS transactions that pose an "unacceptable risk" to US national security when the ICTS is "designed, developed, manufactured, or supplied" by persons "owned by, controlled by, or subject to the jurisdiction or direction of certain foreign adversaries." The 2025 connected-vehicles rule is the first Section 1705 rule applied to a physical consumer product class. The Biden administration's proposed 2024 connected-vehicles rule was the precursor. The Trump administration's January 2025 final rule is the version that took effect.[1]
The rule defines "connected vehicle" broadly. A connected vehicle is any car or truck that has a direct or indirect connection to the internet, onboard telematics, or networked sensors, which is, in 2026, effectively every car sold in the US market. The rule prohibits US persons from importing or selling vehicles that contain ICTS components from a "foreign adversary," defined to include China, Russia, Iran, North Korea, Venezuela, and Cuba. The rule also prohibits US persons from selling ICTS components themselves to a manufacturer that would integrate them into a connected vehicle. The rule exempts legacy vehicles, but it does not exempt vehicles in the active model-year pipeline.
What the rule does, in practice, is force every automaker that has a Chinese-origin component in its supply chain to apply for an individual license from BIS. The license is the operative mechanism. The prohibition is the threat. The license is the process by which BIS case-by-cases decides which Chinese components are acceptable risk and which are not.
The June 15, 2026 News Hook: Ford and the License Line
Reuters reported on June 15, 2026 that the rule is now producing license applications at the automaker level.[2] The article, titled "US connected-car rule prompts Ford, other automakers to seek licenses for China-built models," is the first published account of the rule hitting the Ford model lineup. The article confirms that Ford has, per industry sources, applied for individual licenses to continue selling specific China-built models in the US market. Other automakers, per Reuters, are following the same path.
Reuters' body text is not directly accessible from this article's publication environment: the Reuters Business section is gated behind DataDome CAPTCHA and the Wayback Machine has not yet archived the 2026-06-15 URL. The submission on Hacker News, posted at 19:22 UTC on June 15, 2026 by user onemoresoop, has 2 points and 0 comments, which is the early signal that the story has not yet been picked up in the comments cycle.[2] The body of the Reuters piece, as inferred from the headline and the standing rule, is the model-by-model license application: which Ford models contain which Chinese-origin ICTS components, which BIS has licensed, which BIS has not, and which BIS is still reviewing.
What the Reuters story establishes is that the rule, eighteen months after its effective date, is producing the case-by-case enforcement that the rule's text always implied. BIS has not, as of June 15, 2026, published a complete list of license grants or denials. Reuters' sourcing is "industry sources" and BIS-adjacent officials, not a published list. The license process is the rule. The news is that Ford is in it.
What the Reuters story does not establish is what "privacy" has to do with any of it. The Section 1705 rule treats cars as ICTS, which is a national-security classification. The rule's prohibitions are on import and sale of vehicles with Chinese-origin ICTS components. The rule's privacy framing is a residual line in the abstract: "undue or unacceptable risks to national security and U.S. persons."[1] The "U.S. persons" language is data-protection language. The data-protection framing is the political cover for the supply-chain rule.
The Michigan Bill: Slotkin and Stevens Take the Privacy Argument State-Side
Three days before the Reuters story broke, TechDirt's Mike Masnick published "Michigan Lawmakers Want to Ban Chinese-Tagged Vehicles From Even Visiting The State, You Know, For Privacy."[3] The headline is the analysis. The body identifies the bill's sponsors as Michigan Senator Elissa Slotkin and Michigan Representative Haley Stevens, both Democrats, and lays out the bill's three-pronged framing: "jobs, consumer privacy, and national security."[3]
The bill's signature line, in Masnick's account, is Slotkin's characterization of cheaper Chinese EVs as "TikTok on wheels."[3] The "TikTok on wheels" framing is the operative political line. TikTok is the model. TikTok was framed, in the 2024 PAFACAA debate and the 2025 Trump executive orders, as a national-security and data-protection threat. The TikTok case was the test case for treating a consumer data product as an ICTS transaction. The "TikTok on wheels" framing is the same test case, applied to a $30,000 EV.
Masnick's analysis is, however, sharply critical of the privacy framing. The article's central argument is that US carmakers already collect, broker, and sell the same data the bill is supposed to protect. The article cites, by name, the data brokerages and law-enforcement access patterns that already apply to US-made connected vehicles. The article's central claim is that "privacy" in the bill is "a lazy talking point," that the US auto industry collects more data on US drivers than the Chinese EV makers the bill targets.[3]
Two other points from the article are worth flagging. The first is the bill's "or any adversarial nation" language. The bill is not, in its text, limited to China. The bill is framed to apply to any country the US State Department designates an adversary, which is a moving target that future administrations can set. The second is the Canadian-Chinese vehicle agreement, which the article cites as a near-term enforcement problem. Canada and China have signed an EV trade agreement that lowers tariffs on Chinese-made vehicles in the Canadian market. USMCA's free-movement provisions make it difficult, in practice, for Michigan to enforce a Chinese-vehicle ban at the Windsor-Detroit border, where tens of thousands of Canadian vehicles cross daily.[3]
The Hacker News Reception: A Bilateral Trade Fight, Framed as Privacy
The TechDirt piece was submitted to Hacker News on June 13, 2026 at 19:44 UTC, where it reached 10 points and 3 comments in the first 48 hours. The thread's three comments are short, but they map the political geometry of the bill precisely.
The first comment, by user hn_acker, corrects the submission title: "The original title is: Michigan Lawmakers Want To Ban Chinese-Tagged Vehicles From Even Visiting The State. You Know, For Privacy."[6] The correction is a small, pointed dig at the original submitter. The original TechDirt headline already has the "for privacy" in it. The HN commenter is reading the headline as a Masnick-style critique. The submission is reading the headline as straight news.
The second comment, by rmason, goes to the enforcement problem. "This is unenforceable and imho ridiculous. Canadians are now going to be able to buy Chinese vehicles under a agreement just signed between those two countries. So we are going to arrest them when they try to cross the border in Detroit to catch a baseball game?"[6] The comment is the strongest version of the enforceability argument. A Chinese-vehicle ban in Michigan has, as its first-day enforcement problem, the tens of thousands of Canadians who cross the Detroit-Windsor border daily, half of whom are doing so to attend a sporting event, a doctor's appointment, or a family visit. The bill is not, in its enforcement, a privacy bill. The bill is, in its enforcement, a US-China trade bill with a Canadian border problem.
The third comment, by jqpabc123, is the shortest and the most pointed: "This says more about Michigan than China."[6] The comment is the political-economy reading. Michigan is the historical home of the US auto industry. Michigan has the most to lose from cheaper Chinese EVs. A Michigan bill that bans Chinese-tagged vehicles from even visiting the state is, structurally, a Michigan bill that protects the Michigan auto industry from Chinese competition. The privacy framing is the political cover for a trade protectionism that no member of the Michigan congressional delegation would defend in those terms.
The Privacy Question: Whose Data Is the Bill Protecting?
The Michigan bill's privacy framing is the framing that lets the bill exist. The privacy question the bill is supposed to answer is the data Chinese EVs would collect on US drivers if US drivers bought Chinese EVs. The privacy question the bill actually answers, if it is enforced against any vehicle with any Chinese-origin component, is the data that US carmakers already collect.
The data US carmakers collect is documented in three standing State of Surveillance pieces. The CPPA's connected-car enforcement sweep, finalized in a $12.75 million GM record penalty in May 2026, found that GM sold OnStar driving data to the LexisNexis and Verisk data brokerages, which resold it to insurance carriers. The same sweep found that Honda required excessive personal information to exercise opt-out rights. The same sweep found that Ford required email verification before processing opt-out requests from its connected-vehicle services.[4] The CPPA fines are the standing evidence that US carmakers collect, broker, and sell US driver data. The LexisNexis and Verisk pipeline is the data-broker pipeline that the Michigan bill is supposedly the fix to.
The on-board biometric pipeline is the second standing reference. Ford filed a patent, public in the USPTO record by May 2026, on a facial-recognition-and-biometric system for its truck line that uses cabin cameras to identify the driver, log the driver's biometric template, and use the template to authenticate transactions at the gas pump, drive-through, and parking garage.[5] The patent is not a product launch. The patent is, however, the public record of Ford's product direction. The product direction is biometric in-cabin surveillance as a transactional authentication system. The Michigan bill is being sold as the privacy fix to the Chinese in-cabin surveillance problem. The Ford patent is the US-domestic in-cabin surveillance product.
The data-broker and government-access question is the third standing reference. The data US carmakers collect on US drivers does not stay in the US-automaker data warehouse. The data is sold, with the automakers' complicity, to data brokers, who sell it to law enforcement without a warrant, on the legal theory that the data is third-party data the driver has no reasonable expectation of privacy in. The "US gov buys brokered data to avoid warrants" pattern is the pattern that has been documented across the US car data pipeline, including in the standing State of Surveillance coverage.[7] A Michigan bill that bans Chinese vehicles from even visiting the state does not, in its text, regulate that pipeline. A Michigan bill that bans Chinese vehicles from even visiting the state does, in its text, ban Chinese vehicles.
The Pattern: Privacy Is the Political Cover, Trade Is the Operative Policy
Read the two stories side by side and the pattern is the same one State of Surveillance has been tracking across the 2026 cycle: privacy is the political cover, the operative policy is something else.
The federal rule is a Section 1705 ICTS supply chain rule. The rule's text is about supply chains. The rule's legal authority is Section 1705 of IEEPA, the same authority used for TikTok, the same authority the Trump administration has used for a broader set of national-security-adjacent ICTS restrictions. The "U.S. persons" language in the Federal Register abstract is the privacy line, but the privacy line is the residual, not the operative. The operative prohibition is on the import and sale of vehicles with Chinese-origin ICTS components. The license process is the case-by-case enforcement mechanism.
The Michigan bill is a state-level trade restriction. The bill is framed around "jobs, consumer privacy, and national security." The "jobs" framing is the trade-protectionism. The "national security" framing is the alignment with the federal rule. The "consumer privacy" framing is the political cover. The bill's "or any adversarial nation" language is the scope-expansion. The bill's enforcement at the Canadian border is the open question.
The US car industry is the constituency the bill, in its operative effect, protects. The US car industry is also the constituency whose own data-collection practices the bill, in its privacy framing, supposedly fixes. The bill is, in its text, a Chinese-vehicle ban. The bill is, in its privacy framing, a privacy bill. The bill is, in its operative effect, a US auto industry protection bill that does not, in its text, regulate the US auto industry's own data practices. The privacy framing is what makes the bill politically survivable. The privacy framing is also what makes the bill analytically incoherent.
The pattern is the same one the 2026 connected-car beat has been producing. The CPPA's connected-car enforcement sweep is a privacy enforcement pattern. The GM record penalty is a privacy enforcement outcome. The Ford facial-recognition patent is a US-domestic in-cabin surveillance product. The Michigan bill is a Chinese-vehicle ban with a privacy cover. The federal rule is a Section 1705 supply-chain rule with a "U.S. persons" residual. The pattern is that US car data is the surveillance story, and the Chinese-car data is the political cover for the surveillance story.
What to Watch in the Next 7 Days
- First published BIS license grant or denial under the connected-vehicles rule. The rule took effect March 17, 2025. The Reuters report confirms license applications are in flight. The first public BIS decision, a grant, a denial, or a license-with-conditions, will be the first empirical data point on what the rule actually does to a specific Ford, GM, or Stellantis model line.
- Michigan bill number and committee assignment. TechDirt's June 12, 2026 piece does not name the bill number. The Michigan Legislature's session is in the early-filing window. The first published bill number, the first committee referral, and the first committee hearing date will be the first hard data on the bill's legislative viability.
- First statement from a US automaker on its own data-collection practices in response to the Michigan bill. The bill's privacy framing is, in its operative effect, an implicit indictment of the US auto industry's own data practices. The first US automaker to defend its own data pipeline in response to the bill, or to break with the bill, will be the first signal of where the industry's privacy posture is actually settled.
- First statement from a US privacy advocacy group on the bill's privacy framing. The privacy groups that have been the most consistent voice on the US car data pipeline, including EPIC, Consumer Reports, the ACLU, and the Mozilla Foundation, have not, as of June 15, 2026, published a statement on the Michigan bill. The first such statement, supporting, opposing, or reframing the bill, will be the first civil-society signal on whether the privacy framing is a serious argument or a political cover.
- First Canadian or Mexican counter-measure. The USMCA free-movement provisions and the Canadian-Chinese EV trade agreement make the Michigan bill, in its text, a US-Canada bilateral issue before it is a privacy issue. The first statement from the Canadian government, the Mexican government, or a USMCA dispute panel will be the first signal on whether the bill is enforceable at the Windsor or Detroit border.
- First Reuters or AP follow-up on the Ford license applications. The June 15, 2026 Reuters piece is the first published account. The first Reuters or AP follow-up, with named BIS officials, named license applications, or named model lines, will be the first hard data on which Ford models are in the license pipeline.
- First public comment from a US car dealer association on the bill. The Michigan bill, if enforced, would have the largest immediate operational impact on US car dealers, who would have to verify the country-of-origin of every vehicle on every lot. The first dealer-association statement, supporting, opposing, or reframing the bill, will be the first signal of how the bill is being received in the dealer network.
The Bottom Line
Reuters reported on June 15, 2026 that the US Commerce Department's January 2025 connected-vehicles rule has pushed Ford and other automakers to apply for individual licenses to keep selling China-built models in the US. The same week, Michigan Democrats Elissa Slotkin and Haley Stevens filed a state bill that would ban Chinese-tagged vehicles from even visiting Michigan. Both stories lean on a privacy argument.
The privacy argument is the one US carmakers do not want to litigate. The same automakers seeking licenses to keep selling Chinese cars already collect, broker, and sell US drivers' location, biometric, and phone data, including the LexisNexis and Verisk data brokerages that bought driving data from GM's OnStar program. The CPPA's connected-car enforcement sweep is the standing evidence. The Ford facial-recognition patent is the standing product direction. The US gov's warrantless data-broker purchases are the standing government-access pattern. A Michigan bill that bans Chinese vehicles from even visiting the state does not, in its text, regulate that pipeline.
Privacy is the political cover. Trade protectionism is the operative policy. The federal rule is a Section 1705 supply-chain rule, not a privacy rule. The Michigan bill is a state-level Chinese-vehicle ban, not a privacy rule. Neither, in its text, regulates the data the vehicles collect. The data the vehicles collect is what US carmakers already sell. The pattern is the 2026 connected-car beat's standing thesis. The data is the surveillance story. The Chinese car is the cover. The cover is the story.
Sources
- Federal Register: Securing the Information and Communications Technology and Services Supply Chain: Connected Vehicles (BIS, Doc. 2025-00592, January 16, 2025; effective March 17, 2025; the federal final rule treating connected vehicles as part of the ICTS supply chain; the legal anchor for the Ford and other-license stories)
- Reuters via Hacker News submission 48545836: US connected-car rule prompts Ford, other automakers to seek licenses for China-built models (June 15, 2026 19:22 UTC; the news hook for the license-seeking pattern; paywalled Reuters body, cited via the HN title and URL)
- TechDirt: Michigan Lawmakers Want to Ban Chinese-Tagged Vehicles From Even Visiting The State, You Know, For Privacy (Mike Masnick, June 12, 2026; the primary substantive analysis of the Slotkin/Stevens bill; the bill-text mirror; the "TikTok on wheels" pull-quote anchor; the "privacy as lazy talking point" critique)
- State of Surveillance: "CPPA's Connected-Car Sweep Hits Honda and Ford" (June 13, 2026; the standing reference for the US-automaker opt-out fines, the $12.75M GM record penalty, and the LexisNexis/Verisk data-broker pipeline that the Michigan bill is being sold as the privacy fix to)
- State of Surveillance: "Ford Patents Truck Surveillance Using Facial Recognition" (May 28, 2026; the standing reference for the Ford on-board biometric and tracking pipeline that the Michigan bill is being sold as the privacy fix to)
- Hacker News thread 48520723: Michigan Lawmakers Want to Ban Chinese-Tagged Cars from Even Visiting the State (June 12-13, 2026; 10 points, 3 comments; the comment thread that surfaces the Canadian border-enforcement problem and the "this says more about Michigan than China" framing)
- State of Surveillance: "FISA 702 Lapsed for the First Time Since 2008" (June 14, 2026; the standing reference for the warrantless-data-broker-purchase pattern and the congressional fight over reauthorizing the underlying authority, which is the government-access pipeline the Michigan bill's privacy framing does not address)
Published: June 15, 2026