The Information Technology Industry Council just filed its opposition to the FCC's proposal to include optical modules on the Covered List. The code never lies, but the regulators do.
This is not a routine comment period. This is a jurisdictional power grab disguised as national security policy. And the industry knows it.
Context: The Regulatory Machine
The Secure Equipment Act of 2021 gave the FCC authority to maintain a Covered List of communications equipment posing national security risks. The original target was clear: Huawei, ZTE, and other named entities. The 2022 list reflected that intent. The 2024 expansion changed everything.
The FCC now wants to classify optical modules—generic network components manufactured by both Chinese and American companies—as a category. Not specific entities. The entire product class.
ITI's opposition is precise: focus on entities with clear ties to foreign adversaries, not broad categories covering entire technology classes from trusted companies.
The logic is sound. The incentives are not.
Core: The Structural Teardown
I've spent 26 years auditing systems where the trust layer fails. This proposal is a textbook case of governance exceeding its authorization boundary.
The statutory language of the Secure Equipment Act targets entities. The FCC's administrative interpretation now targets categories. That is not a legal nuance—it is a constitutional problem. Under the Major Questions Doctrine established in West Virginia v. EPA, agencies cannot make decisions of vast economic and political significance without clear congressional authorization.
Optical modules represent a $10+ billion global market. Chinese manufacturers hold over 50% of it. Zhongji Innolight is the world's largest producer. Excluding an entire category from federal procurement is not a routine administrative action—it is industrial policy by fiat.
Here is what the compliance engineers understand that the policymakers do not: optical modules are embedded components. They go inside switches, routers, and data center infrastructure. The supply chain is opaque by design. A module sourced through a distributor in Singapore may originate from a factory in Suzhou. There is no practical way to trace the provenance of every embedded module without BOM-level tracking systems that do not exist at scale.
This creates a new class of risk: unintentional non-compliance. Federal contractors will violate the rule without knowing it. The compliance burden shifts downstream to integrators like Cisco and Juniper, who will demand indemnification clauses from suppliers, who will pass costs up the chain until the entire pricing structure distorts.
During my audit of the 2021 Bored Ape metadata storage, I identified a similar structural flaw: data stored off-chain via unpinned IPFS links. The risk was invisible until the infrastructure decayed. The same principle applies here. The FCC is creating a compliance regime where the failure point is invisible until the contract is terminated.
The incentive structure is worse than the legal analysis.
The FCC's proposal creates a chilling effect regardless of outcome. Even if optical modules are not ultimately listed, procurement officers will proactively avoid Chinese modules to reduce risk exposure. The market will do what regulation cannot: it will self-censor. Supply chains will shift from cost-optimal to compliance-optimal. This is not a bug in the system—it is the intended feature. The FCC achieves its objective through uncertainty rather than enforcement.
The industry response should not be litigation. It should be data. The FCC's own record shows the disconnect: the Supply Chain Reimbursement Program allocated $1.9 billion to replace Huawei/ZTE equipment. That program has been slow, bureaucratic, and partially unfunded. The FCC cannot execute the mandate it already has, yet it seeks to expand the perimeter. That is inefficiency masquerading as vigilance.
Contrarian: What the Bulls Got Right
The national security concern is not fabricated. Optical modules handle data transmission at the physical layer. A backdoored module could theoretically exfiltrate data or enable network disruption. The threat model is real, even if the probability is low.
The FCC's response to ITI's opposition will likely be a compromise: instead of listing the entire category, they may name specific Chinese entities. That would align with the statutory language and reduce legal exposure. The industry's pushback may actually produce a more legally defensible outcome.
There is also a legitimate argument for proactive supply chain hygiene. The 2020 Curve IRV collapse taught me that incentive misalignment creates predictable failure. The same principle applies to national security: when a single country controls 50%+ of a critical component market, diversification is not protectionism—it is risk management. The industry's dependence on Chinese optical modules is a genuine systemic vulnerability.
Takeaway: The Accountability Question
Trust is a vulnerability with a capital T. The FCC is asking the market to trust its judgment on what constitutes a national security risk. The industry is asking the FCC to trust its ability to self-regulate. Both are asking for blind faith in systems with demonstrated blind spots.
Chaos is just data you haven't modeled yet. The next 12-18 months will reveal whether the FCC's rulemaking survives judicial review, whether Congress clarifies the statutory boundary, and whether the industry's compliance infrastructure can keep pace with regulatory expansion.
The exit liquidity is always someone else's problem—until the final rule drops and the supply chain seizes.
I don't write these words to predict doom. I write them to document the mechanism. The FCC's optical module proposal is a stress test for the entire administrative state's approach to technology governance. The outcome will determine whether future restrictions target entities or entire technology classes.
Watch the rulemaking docket. Watch the D.C. Circuit. And watch your supply chain contracts. The code may not lie, but the regulators are writing new code—and the industry is only now discovering the vulnerabilities in their logic.