The Trump administration issued an executive order banning the acquisition of foreign-made technology used to manage electricity generation and transmission, citing concerns that adversarial nations are building and exploiting backdoors in bulk-power system equipment.
The order targets technology tied to transmission lines rated at 69,000 volts or higher, along with substations, control rooms, power generating stations, reactors, and the associated software and firmware that could be remotely accessed or updated by foreign entities. The White House called such equipment an “unusual and extraordinary threat” to national security.
President Trump referenced findings from his first term that identified the bulk-power system as a likely target for malicious actors seeking to damage the U.S. economy, public health, and national defense.
Response to a Wave of Infrastructure Attacks
The order arrives amid a string of recent attacks on critical infrastructure. Water utilities across at least 12 states were hit by cyberattacks last month, and the federal cyber defense agency reported malicious activity targeting more than 100 internet-exposed systems in the water and wastewater sector. Separately, a small power plant in the United Kingdom was reportedly knocked offline for four days by hackers.
The NSA and FBI also recently issued an advisory describing an AI-powered active threat targeting a specific brand of operational technology used across the energy, water, and agriculture sectors. While officials have not formally attributed these incidents, several experts have pointed to Iranian hacking groups, alongside past attributions of infrastructure attacks to Russian and Chinese actors. The FBI also disrupted a Chinese botnet this week that had been used to breach the Federal Reserve, NASA, and other agencies overseeing critical infrastructure.
New Review and Enforcement Process
Under the order, the Defense, Commerce, and Energy Departments will review transactions involving bulk-power system electric equipment. Federal agencies may impose conditions on equipment already installed, though they must weigh whether viable replacements exist. A list of pre-qualified vendors and equipment is expected to be published.
Senior officials have 120 days to establish implementing rules and identify which countries warrant heightened scrutiny under the order. Agencies must also inventory currently deployed equipment considered high-risk and submit plans to the White House for identifying, isolating, monitoring, or replacing it.
The White House did not respond to questions about what specifically prompted the order. Separately, OpenAI, Google, and other technology and finance companies warned that there is a narrowing window to strengthen defenses before AI-enabled cyberattacks against critical infrastructure become more widespread and sophisticated, noting that security teams protecting these systems have historically been under-resourced.
