DJI and the FCC: banned by order, sold under another name
7 min read
On 22 July 2026 the Federal Communications Commission adopts a rules package that closes what its own documents call the “component part loophole”: a device that incorporates even a single hardware component from a company on the Covered List can no longer be certified, regardless of the brand printed on the casing. It is the latest step in a saga that began in December 2025, when the Commission placed DJI and Autel Robotics on America’s national-security risk blacklist, blocking approval of any new drone from the Chinese manufacturer. In the months since, nine companies — Cogito, Fikaxo and Xtra Technology among others — have come under suspicion of selling the same drones under a different label. The most thoroughly documented case, Odyssey Robot, shows just how thin the line is between a genuinely American product and one merely declared to be.
The facts, in order
- 22 December 2025: the FCC adds all foreign-made UAS (drones) and their critical components to the Secure Networks Act’s Covered List. DJI and Autel Robotics are the hardest-hit manufacturers: 14 already-authorised products lose their certification.
- 20 February – 22 April 2026: DJI petitions the Ninth Circuit Court of Appeals (case 26-1029) against the designation; the Pentagon opposes it citing classified intelligence, and DJI tells the court it expects a $1.56 billion loss for 2026 tied to 25 blocked launches.
- May 2026: the FCC’s Enforcement Bureau sends formal information requests to eight companies — Cogito Tech, Fikaxo Technology, Lyno Dynamics, Skyhigh Tech, Spatial Hover, SZ Knowact, WaveGo Tech, Xtra Technology — suspected of selling rebranded DJI hardware.
- 28 May 2026: DJI submits an independent security audit to the FCC, commissioned from US firm OnDefend on the Air 3S and Matrice 4E models: no backdoors, no data transmission outside the United States, zero critical or high-risk vulnerabilities across five months of testing.
- 5 June 2026: independent researcher Konrad Iturbe publishes an analysis of Odyssey Robot, whose drone was described as “designed, developed, and manufactured by Odyssey in California and assembled by eTak Worldwide Corporation in Texas.” Contacted, eTak denies “any business relationship, contractual relationship, ownership connection, or affiliation” with Odyssey: it is an electronics-recycling firm, not a drone assembler. Compliance testing turns out to have been carried out by TÜV Rheinland in Shenzhen, China.
- 1 July 2026: the FCC releases the draft Third Report and Order (ET Docket 21-232): it closes the component loophole, requires full recertification for any modification made by a Covered List entity, and extends marketing obligations to online marketplaces.
- 10-20 July 2026: the FCC proposes $25,000 fines against the eight companies for failing to respond to its information requests; by the 20 July deadline, none has replied.
- 21 July 2026: the FCC widens the list to nine names, adding XAG, and proposes banning the import and marketing of their products, calling them “an unacceptable risk” to national security.
- 22 July 2026: the Commission adopts the Third Report and Order at its open meeting; the same day it issues an Order to Show Cause against Odyssey Robot, giving it 10 days to explain why its equipment authorisations should not be revoked — the first potential revocation of this kind under the expanded national-security rules. FCC Chairman Brendan Carr says the case “sends a message that the FCC will not allow companies that produce abroad to evade the FCC’s prohibition.”
- The reactions: DJI says concerns about its data security “have not been grounded in evidence and instead reflect protectionism, contrary to the principles of an open market.” Technology journalist Sean Hollister (The Verge) notes that “the US government has never provided specific public evidence” of a genuine threat linked to foreign-made drones.
- The non-responses: Odyssey Robot never replied to the FCC’s initial inquiry or its subsequent deficiency notice. None of the eight investigated companies responded by the 20 July deadline.
On the technical facts there is little real dispute: the December designation was challenged in court, DJI’s independent audit found no backdoors, and the supply chain Odyssey Robot claimed fell apart the moment someone checked the named assembler. The real issue is different: a ban that is well drafted on paper still leaves room for evasion if nobody verifies who actually makes what, where, and with which components.
Lesson one: a ban is only as good as its ability to trace the real supply chain, not the name on the casing
DJI remains the world’s largest consumer-drone maker despite the ban; the nine suspected companies exist precisely because relabelling existing hardware is faster than building an alternative. For anyone buying technology — public bodies, law enforcement, critical-infrastructure operators — the name on the invoice is not a guarantee: only an independent check of who actually designed, assembled and tested what you are buying is. It is the same gap we already flagged in the Hikvision case: an official ban does not close the question if the commercial triangulation still lacks verifiable technical controls.
Lesson two: a clean technical audit does not close a declared political risk
The OnDefend audit found no backdoors or unauthorised data transmission in DJI’s products — yet the risk designation stands, because the basis for the decision is not (only) technical: it is the structural relationship between a Chinese company and its country’s national-security law, regardless of how clean any given product release is. Anyone assessing a critical supplier needs to keep these two planes separate — verifiable technical risk and declared geopolitical risk — because an audit closes the first, not the second. It is the reasoning behind our dual-use compliance controls: technical certification is a necessary condition, never a sufficient one, when the dependency is on a supplier subject to a different legal order.
Lesson three: national-security rules get rewritten while the game is still on
The new Third Report and Order did not come from nowhere: it narrows the definition of “critical infrastructure” because an appeals court had found the previous wording overbroad. Between December and July the Commission has already shifted the boundary once — and it will shift again under the Further Notice just opened, which proposes splitting the Covered List by producer and by production location. For anyone planning multi-year investment in technology subject to export or dual-use controls, this means treating the regulatory perimeter as a variable that moves mid-course, not a condition secured once and for all. It is the same principle from the NATO-Ankara drones case: today’s compliance does not certify tomorrow’s.
What to do
- Verify the declared supply chain, not just the brand: ask for checkable evidence of who designs, assembles and tests the product, and confirm it with an independent source before signing.
- Keep technical risk separate from geopolitical risk: a clean security audit does not offset a structural dependency on a supplier subject to a foreign legal order relevant to national security.
- Write a notification obligation into contracts covering any change in the supplier’s regulatory designation or that of its critical components, not just product changes.
- Treat the regulatory perimeter as a live variable: national-security lists get corrected and rewritten — plan the replaceability of critical suppliers before a regulator does it for you.
Do you manage fleets of drones, sensors or components subject to export controls, and want to check how well your declared supply chain would hold up to an independent review? Half an hour with one of our experts to map the risks and critical suppliers.
Sources
- Federal Communications Commission — Third Report and Order and Third Further Notice of Proposed Rulemaking, ET Docket No. 21-232 (1 July 2026)
- DroneDJ — FCC moves to revoke approvals from alleged DJI-linked drone maker (22 July 2026)
- PetaPixel — Independent Audit Finds No Security Basis for Restricting DJI in the USA (28 May 2026)