FCC's Optical Module Ban: A Regulatory Overreach That Could Break the Internet's Backbone
StackSignal
The data shows a regulatory anomaly. The Information Technology Industry Council (ITI) — the trade association representing Apple, Google, Microsoft, and Amazon — has formally opposed the FCC's proposal to add optical modules to its Covered List. This is not a routine policy squabble. It is a direct challenge to the legal foundation of the Secure Equipment Act of 2021, and it exposes a fundamental flaw in how the FCC interprets its own mandate. Code doesn't lie; audits do. And this audit of the FCC's rulemaking logic reveals a dangerous expansion of administrative power.
For context, the Covered List is the FCC's enforcement mechanism under the Secure Equipment Act. It prohibits the use of federal funds to purchase communications equipment that poses a national security risk. The first version, published in 2022, named specific entities — Huawei, ZTE, and other Chinese firms with clear ties to the Chinese Communist Party. That was defensible. The list targeted bad actors by name, with evidence. But the FCC's current proposal is different. It seeks to add optical modules — a generic, commoditized component used in every data center and telecom network on the planet — as an entire product category. This is a categorical shift from entity-based designation to category-based prohibition. Trust is a bug, not a feature, and the FCC is asking the industry to trust that this expansion is both legal and necessary. It is neither.
Let me decompose the technical reality. Optical modules are the physical layer of the internet. They convert electrical signals to optical signals and back. They are manufactured by dozens of companies globally, including US firms like Coherent and Lumentum, but the market is dominated by Chinese manufacturers — Innolight and Eoptolink hold over 50% of global market share. These are not obscure components with embedded backdoors. They are standardized, interchangeable parts governed by MSA (Multi-Source Agreement) specifications. Any vendor's module can plug into any switch. The supply chain is deep and opaque, with modules passing through multiple distributors before reaching a network operator. This is the crux of the compliance problem.
Based on my audit experience with zero-knowledge proof circuits, I can tell you that verifying the provenance of a component through a multi-tier supply chain is mathematically equivalent to verifying a constraint system with missing witnesses. You cannot prove a negative — you cannot prove that a module has no backdoor, no hidden functionality, no malicious firmware. The FCC's proposal would require procurement officers to trace every optical module to its original manufacturer, through layers of distributors, with no standardized audit trail. This is not a security measure. It is a compliance nightmare that will fail in practice.
The ITI's opposition is not just about trade. It is about the legal principle of ultra vires — acting beyond one's authority. The Secure Equipment Act authorizes the FCC to designate equipment produced by entities that pose a national security risk. It does not authorize the FCC to ban entire product categories. The legislative history is clear: Congress was focused on Huawei and ZTE, not on generic optical transceivers. The FCC is now attempting to expand its mandate through administrative interpretation, without new legislation. This is precisely the kind of overreach that the Supreme Court's Major Questions Doctrine was designed to prevent. In West Virginia v. EPA (2022), the Court held that agencies cannot regulate matters of vast economic and political significance without clear congressional authorization. A ban on all foreign-made optical modules would have exactly that significance — it would disrupt the global internet infrastructure, raise costs for every US carrier and cloud provider, and trigger retaliatory measures from China.
The contrarian angle here is that the FCC's proposal, even if it fails, will achieve its intended effect through a chilling mechanism. The mere threat of inclusion on the Covered List is already causing US companies to preemptively reduce their reliance on Chinese optical modules. This is the "chilling effect" — a regulatory shadow that alters market behavior without a single rule being finalized. I have seen this pattern before in the crypto space, where regulatory uncertainty alone can kill a project. The FCC knows this. The proposal is a negotiating tactic, not a final position. By floating the category-wide ban, the FCC creates leverage to extract concessions from the industry — perhaps a commitment to supply chain transparency, or a voluntary shift away from Chinese suppliers. The ITI's opposition is the first move in a chess game that will play out over the next 12 to 18 months.
But here is the deeper problem. Even if the FCC retreats to a more targeted approach — listing specific Chinese manufacturers rather than the entire category — the damage is already done. The supply chain will have been disrupted. US carriers will have paid premiums for alternative suppliers. Chinese manufacturers will have shifted production to Southeast Asia to evade the restrictions. And the internet will be less efficient, more expensive, and more fragmented. The FCC is solving a real security problem with a blunt instrument that creates new vulnerabilities. The DAO was a warning we ignored — a reminder that well-intentioned security measures can introduce catastrophic unintended consequences when they are not rigorously tested against real-world constraints.
Zero knowledge, maximum proof. The FCC's proposal fails this test. It demands proof of security from an industry that cannot provide it, while offering no proof that the measure will actually improve security. The industry should not accept this regulatory overreach. The legal challenge will come, and it will likely succeed. But the victory will be pyrrhic — the chilling effect will persist, and the supply chain will remain permanently altered. The question is not whether the FCC will back down. It is whether the industry can rebuild trust in a regulatory process that has shown it is willing to sacrifice technical reality for political optics. The answer, based on the data, is not encouraging.