The Information Technology Industry Council's formal opposition to the FCC's proposal to include optical modules in the Covered List landed like a cold front over a summer market. For those of us who have watched the evolution from entity-based sanctions to category-based restrictions, this is not a bureaucratic footnote. It is a watershed moment that reveals how the machinery of national security regulation is beginning to outpace the very supply chain realities it purports to protect.
For the uninitiated, the Covered List emerged from the Secure Equipment Act of 2021, a piece of legislation that seemed straightforward enough: identify communications equipment posing national security threats, prohibit federal funds from purchasing it. The first iteration named entities. Huawei. ZTE. The obvious villains of the political theater that had been playing since 2018. But the FCC's recent move to add the entire category of optical modules—the fiber optic components that power data centers, 5G networks, and the entire backbone of digital communications—represents a fundamental shift in regulatory philosophy.
The ITI's argument is precise and devastating. They did not dispute the existence of security threats. They questioned the logic of painting an entire technology class with the same brush. Their recommendation: focus on entities with demonstrable connections to foreign adversaries, not broad swathes of products from trusted companies. It's a subtle but crucial distinction that could reshape how American regulators approach supply chain security.
But the deeper question that no one in Washington seems willing to ask: What exactly is the FCC trying to protect? Optical modules are not sophisticated switching equipment or core routing infrastructure. They are the standardized connectors, the universal building blocks that make the internet physically possible. The same modules from the same Chinese manufacturers, say Innolight or Eoptolink, power the networks of the Western world. The notion that these can be neatly excised from U.S. infrastructure without massive collateral damage is almost laughable to anyone who has actually deployed network infrastructure.
The real substance of this debate lies in the legal interpretation that ITI is challenging. The FCC's rulemaking process under the Secure Equipment Act was never designed for category-based prohibitions. Congress wrote language about "covered entities" and "covered services"—terminology that presumes specific actors. Nowhere in the legislative history is there discussion of banning entire product categories. The regulatory agency is essentially stretching its authority to interpret the law in a way that extends its reach far beyond what Congress intended.
This brings me to a more troubling observation. I spent the early days of my career auditing smart contracts and building risk models for decentralized finance protocols. I have seen how regulatory ambiguity creates opportunities for arbitrage. The same pattern is playing out here. The FCC knows that the Covered List process is slower than the supply chain that must adapt to it. Every week of uncertainty, every month of regulatory limbo, pushes more procurement decisions toward a de facto decoupling.
Take the global supply chain numbers. Chinese manufacturers of optical modules control a staggering share of the world market. The transition of that manufacturing base to alternative locations is not a simple matter of building new factories. It requires re-validating entire product lines, re-testing for performance and reliability standards, and re-establishing the trust that comes with years of shipped product. This is not a six-month project. It is a multi-year endeavor that could delay critical infrastructure projects for the entire sector.
The market impact is already visible. Buyers are moving to de-risk, even before the final rules are published. The procurement managers I speak with are not waiting for the FCC's decision. They are proactively diversifying their supplier base. Not because they believe there is an actual security threat in their current modules, but because they cannot afford to have their supply chains disrupted by a regulatory decision they cannot predict. The market is adapting to the threat of regulation, not the regulation itself.
This is where the pragmatic test comes in. The FCC's broader approach assumes that a comprehensive ban is the most effective way to protect national security. But it overlooks the reality that the network components market is a deeply integrated ecosystem. The same equipment that carries sensitive government communications also carries commercial traffic, educational content, and personal data. A categorical ban on optical modules from certain foreign sources would force U.S. carriers to maintain dual inventory systems, create significant inefficiencies, and possibly degrade overall network resilience.
The ITI's suggestion of a more precise, risk-based approach deserves serious consideration. Instead of banning entire categories, why not require enhanced security protocols for certain suppliers? Why not create a certification system that validates the integrity of the equipment supply chain? The answer is that these approaches require more sophistication and judgment. And in the current political environment, the blunt instrument of a categorical ban is politically easier to implement than a nuanced approach that requires trust in a validation process.
Consider the historical parallel. The CFIUS reviews for foreign investment into the U.S. have evolved over the years to become more precise about what types of investment pose actual threats. It did not simply ban all foreign investment into critical sectors. It created a system that could evaluate risk on a case-by-case basis. The FCC could do the same. Instead of this broad, crude instrument, they could create a mechanism that requires enhanced scrutiny for specific products or suppliers with known connections to foreign adversaries.
The question I keep coming back to, as the FCC's covered list expands to cover more and more of the digital infrastructure, is whether the agency is truly interested in protecting the network or whether it is simply more interested in asserting its own authority. The most charitable interpretation is that they are being deliberately broad to avoid being bypassed. But the consequences are more predictable than they would be with a more surgical approach.
The market is already signaling what it thinks about the FCC's approach. The reaction from network operators, cloud providers, and equipment vendors has been to accelerate their own diversity strategies. They are not waiting for the rule to be finalized. They are already building redundancies, exploring alternative suppliers, and creating more resilient supply chains. The irony is that this could ultimately achieve the FCC's stated goal, but in a far more inefficient way than if the agency had simply stated its concerns more precisely from the beginning.
The larger narrative is the one that matters for the long term. The concept of the physical layer, the hardware on which the digital economy runs, is being pulled into the geopolitical competition. This is not a new phenomenon, but the speed and scope of it are accelerating. The question is whether the regulatory apparatus can handle it. Or whether the FCC is simply creating a more complex game of global supply chain whack-a-mole.
I am reminded of the lessons from the 2017 ICO frenzy. The market was filled with projects that had grandiose claims but lacked the substance to back them up. The regulatory response was heavy-handed, and it swept away legitimate innovators along with the fraudsters. We are seeing the same pattern with this hardware supply chain. The path to a more secure network is not through blanket prohibitions but through targeted, risk-based frameworks that can distinguish between the real threats and the necessary components of a functioning digital economy.
As we watch the FCC's next moves, the question is whether they will find the balance between security and function. The ITI's opposition is not just a lobbyist's protest. It is a signal that the industry believes that the regulatory path is the wrong one. The industry is not opposed to security. They are opposed to the use of security as a broad and rather imprecise weapon that could end up harming the very infrastructure they are trying to protect.
The real test will come in the final rule. Will the FCC listen to the industry and adopt a more targeted approach? Or will it push forward with its broad prohibition, trusting that the market will adjust and the benefits will outweigh the costs? In the meantime, the market is already voting. And it is voting for diversification, for redundancy, and for the kind of resilience that comes from not putting all your eggs in one geopolitical basket. The FCC can either join that movement or be left trying to regulate a reality that has already moved past its assumptions. Trust no one. Verify everything. Summer fades. Builders remain.