Should Local Governments Ditch Chinese Drones After the Latest U.S. Cybersecurity Warning?

27 min read

Summary

Chinese manufacturer DJI dominates U.S. drone fleets, including over 90% of public safety programs, creating deep dependency across local government and contractor operations.
The 2024 CISA-FBI advisory warned that Chinese-made drones risk exposing critical infrastructure data to PRC authorities under Chinese law.
Federal restrictions tightened significantly by December 2025, with the ASDA grace period expiring and the FCC blocking new Chinese drone model authorizations.
Local agencies using purely local funds remain legally permitted to operate Chinese drones, but legal permissibility and cybersecurity safety are entirely separate questions.
Ground robots face the same risk logic as drones, with Chinese manufacturers expanding aggressively into a market that regulators have not yet fully addressed.
U.S. alternatives from Skydio, Boston Dynamics, and Percepto exist but carry a significant price premium, making grant funding and phased transition planning essential.

Start with the fire department. Or the police department. Or the county agriculture office that monitors crop health along the river basin. Whichever local government operation you pick, there is a better-than-even chance that the drones doing the work were manufactured by DJI, a company headquartered in Shenzhen, China. This is not a fringe situation or a niche procurement quirk. It is the baseline reality of how American public agencies built out their unmanned aerial programs over the past decade, mostly because DJI made excellent hardware at prices that no domestic competitor could match.

The numbers behind that reality are striking. A 2021 survey by the Airborne International Response Team found that 90.4% of U.S. public safety drone programs were running DJI hardware, with law enforcement programs specifically clocking in at 92.1%. Those figures are a few years old now, but they capture the moment when Chinese platforms became the de facto standard for American first responders. Think about what that means operationally: the drone that your local sheriff's office flies over a flood zone, the one that your fire department uses to map a wildfire perimeter, the one that your public works crew sends up to inspect a bridge, almost certainly has a Shenzhen return address.

Zoom out to the broader commercial market and the picture does not get more reassuring. The U.S. Bureau of Industry and Security, in a 2025 regulatory analysis, summarized available market data showing DJI controlling roughly 70% of the global commercial drone market and a comparable share inside the United States. The Special Competitive Studies Project, a federally chartered advisory body, put DJI's grip on the U.S. commercial segment at close to 80%. Independent research firm IMARC described the concentration as "unprecedented" at the platform level. Pick your methodology and your analyst; the conclusion is the same. One Chinese company supplies the overwhelming majority of the drones that American businesses and contractors use every single day, including the municipal fleets that most people assume are subject to tighter oversight.

"The drone that your local sheriff's office flies over a flood zone, the one your fire department uses to map a wildfire perimeter, almost certainly has a Shenzhen return address."

How did this happen? Partly through genuine product excellence. DJI's Phantom and Mavic lines were genuinely better than anything Western manufacturers were producing at comparable price points during the 2010s, and public agencies, operating under tight budget constraints, made the rational procurement call. There was no federal guidance telling a county sheriff in 2017 that buying a DJI Phantom 4 was a national security risk. The price was right, the flight performance was hard to argue with, and the support ecosystem was solid enough to close the deal. By the time policymakers started raising alarms, Chinese hardware was already embedded in thousands of agency fleets across the country.

The depth of that embedment is the part that makes the current policy debate genuinely complicated. This is not a situation where a handful of agencies bought a few units that can be swapped out over a long weekend. A 2026 regulatory update from UC ANR noted that the federal restrictions introduced through 2023 and 2024 primarily apply to federal agencies and federally funded projects, leaving purely state and locally funded operations in a legal gray zone where Chinese drones remain permissible. That carve-out sounds like good news for local budgets, but it also means thousands of agencies have been operating under the assumption that "legal" and "secure" are the same thing. They are not, and the gap between those two words is exactly where the cybersecurity conversation gets uncomfortable.

What the 2024 CISA-FBI Advisory Actually Said (And Why It Still Matters in 2026)

In January 2024, the Cybersecurity and Infrastructure Security Agency and the FBI did something they almost never do: they issued a joint guidance document aimed specifically at a category of consumer and commercial hardware that tens of thousands of American organizations were already using. The document was titled "Cybersecurity Guidance: Chinese-Manufactured Unmanned Aircraft Systems" and it was addressed directly to critical infrastructure owners and state, local, and territorial partners. Not the Pentagon. Not cleared defense contractors. The people running water treatment plants and county emergency management offices.

The core argument in the advisory was not especially subtle. China has enacted laws that give its government "expanded legal grounds for accessing and controlling data held by firms in China," and when you put a Chinese-manufactured drone over a water treatment facility or a natural gas pipeline, you are potentially handing that legal authority a very capable sensor platform. The advisory warned that these drones risk exposing sensitive information to PRC authorities, including facility layouts and network configurations that could support future cyber intrusions. That last part is worth sitting with for a moment. A drone doing a routine infrastructure inspection could be quietly building a map that makes a future cyberattack easier to execute.

The technical risk vectors the advisory identified fell into two broad categories. The first was data collection and transfer: flight telemetry and imagery captured during operations, potentially synced to cloud services subject to Chinese law. The second was the software supply chain: firmware updates pushed to the drone or its controller that could introduce vulnerabilities or alter device behavior. The advisory also flagged docking stations and associated cloud infrastructure as part of the attack surface, which matters because many agencies have moved toward automated drone-in-a-box deployments where the hardware is essentially always connected.

"A drone doing a routine infrastructure inspection could be quietly building a map that makes a future cyberattack easier to execute."

The recommended mitigations in the advisory were practical but telling. CISA suggested isolating Chinese drones on segmented networks, disabling automatic cloud synchronization, tightening control over docking stations, and implementing careful patch management. Those are not trivial steps for a county IT department with two staff members and a backlog of other priorities. More to the point, they are workarounds, not solutions. You are essentially being told to use a product while simultaneously defending yourself against the product's own data infrastructure. That is a strange place to be with equipment you are trusting to inspect your bridges.

The sentence that got the least attention but arguably carries the most weight for local governments came near the end of the CISA news release. The agency explicitly "encouraged" critical infrastructure organizations to "operate UAS that are secure-by-design and manufactured by U.S. companies." That is not a legal requirement. It is not an executive order. But coming from CISA and the FBI in a joint document, it is about as close to an official federal recommendation as you can get without triggering a procurement mandate. Agencies that ignored it in 2024 can no longer claim they had no warning.

By mid-2024, the pressure was building from a second direction. Members of the House Homeland Security Committee publicly urged DHS and the Department of Energy to declassify findings from Sandia National Laboratories about security risks in Chinese drone hardware, specifically naming DJI and Autel Robotics. The fact that classified technical assessments exist, and that Congress is pressing to make them public, tells you something important: the unclassified advisory language about "significant national security risks" is almost certainly the toned-down version of what the labs actually found. Whatever Sandia's full findings say, the publicly available evidence was already enough to prompt a bipartisan push for transparency. That context is what makes the 2026 advisory the continuation of a story that started well before anyone was paying close attention.

From Advisory to Law: How Federal Restrictions Quietly Closed the Door on Chinese Drones

December 22, 2023 is the date that most local procurement officers probably missed, and it is the date that changed the legal landscape for Chinese drones in American government. That was when President Biden signed the FY 2024 National Defense Authorization Act, which included the American Security Drone Act as an embedded provision. The ASDA did not make headlines the way a standalone bill might have, but its practical effect was significant: it prohibited federal agencies from purchasing or using drones manufactured in China or the other countries on the restricted list. No grandfather clause for existing relationships. No "we've been buying from them for years" exemption. Federal agencies were out.

The grace period that followed gave agencies time to work through existing contracts and inventory, but that runway had a hard end date. UC ANR's February 2026 regulatory update confirmed that the ASDA grace period expired on December 22, 2025, at which point purchasing or using Chinese-made drones became "completely prohibited" for virtually all federal-funded projects. The word "virtually" is doing some work in that sentence, but not much. The prohibition now covers federal agencies and contractors, plus any entity spending federal funds on drone operations. If your county emergency management office bought those DJI units with a FEMA grant, you have a problem that your legal team needs to know about.

"If your county emergency management office bought those DJI units with a FEMA grant, you have a problem that your legal team needs to know about."

The FCC moved on a parallel track. In December 2025, the Commission placed foreign-made drones and key components, including hardware from DJI and Autel, on its "Covered List" of equipment deemed an unacceptable risk to U.S. national security. CNN reported that the FCC action prohibited the importation and sale of all new drone models and essential equipment produced by these firms in the U.S. market. Existing approved models could still be sold and used, but no new models would receive equipment authorizations going forward. That distinction matters more than it might appear. It means the Chinese drone ecosystem in the United States is now in a managed wind-down: the hardware already on the market can keep circulating, but the pipeline of new products and software-integrated platforms from Chinese manufacturers is effectively closed.

Read those two moves together and a clear direction emerges. The ASDA cut off federal purchasing. The FCC cut off new product authorizations. The FY 2025 NDAA set up a mechanism under which DJI and Autel drones could be added to the Covered List of communications equipment presenting unacceptable national security risk, which triggers additional restrictions on future FCC authorizations. Each step was incremental and each step was framed in the dry language of procurement law and spectrum regulation, which is probably why none of it generated the kind of public attention that a straightforward ban announcement would have. But the cumulative effect is that the federal government has systematically removed the on-ramps for Chinese drone hardware without ever holding a press conference to announce it.

The piece of this that local governments and small contractors most frequently misread is the scope of "federal funds." It is not limited to direct federal contracts. It extends to grants and reimbursement programs that flow through state agencies before reaching local ones, including cooperative agreements structured to look like state money by the time they hit a local budget. A small environmental consulting firm that wins a state contract funded by EPA dollars, or a county public works department running drone inspections reimbursed through a federal infrastructure program, falls inside the restriction. UC ANR's 2026 update is explicit that the prohibition applies to entities spending federal funds, full stop. "We didn't buy directly from the federal government" is not a defense. If federal money touched the budget line, the ASDA applies.

None of this means that a city using purely local tax revenue to fund its drone program is breaking any law by keeping its DJI fleet operational. That remains legal, at least for now. But the legislative momentum is unmistakable, and the FCC's Covered List decision signals that the regulatory perimeter is expanding beyond direct federal purchasing. Agencies and contractors that are treating the current legal carve-outs as permanent safe harbor are reading the trajectory backwards.

Here is the question that almost never gets asked in county commission meetings or municipal IT reviews: just because we are allowed to keep using this equipment, should we? The legal carve-out for purely locally funded drone operations is real. UC ANR's 2026 regulatory update confirms that the 2023-2024 federal restrictions primarily apply to federal agencies and federally funded projects, not to purely state or locally funded operations. A city running its drone program entirely on municipal budget dollars can, as of today, keep flying its DJI fleet without violating any federal statute. That is a factually accurate statement. It is also, from a cybersecurity standpoint, almost completely beside the point.

The CISA-FBI advisory was not written in the language of legal compliance. It was written in the language of risk. And the risk it described does not care whether your drone was purchased with federal grant money or local tax revenue. The hardware is the same. The firmware is the same. The data routing through DJI's cloud infrastructure is the same. A Chinese-manufactured drone flying over a municipal water treatment facility is collecting the same categories of sensitive operational data regardless of which budget line paid for it. The legal status of the procurement does not change the technical architecture of the device or the legal obligations that Chinese law places on the company that made it.

What makes this particularly awkward for local governments is the nature of what their drones actually fly over. Public safety agencies use them for crime scene documentation and suspect tracking. Public works departments use them for infrastructure inspection, including bridges and electrical substations, along with the pipelines that connect them. Emergency management offices deploy them during disasters to map damage and coordinate response. These are not benign use cases. The imagery and telemetry generated during these operations can reveal facility layouts and infrastructure vulnerabilities that would be genuinely useful to a sophisticated adversary. The CISA advisory specifically flagged that captured data could include "facility layouts and network details that would facilitate cyber intrusion." That warning applies whether or not a federal dollar funded the flight.

"A Chinese-manufactured drone flying over a municipal water treatment facility is collecting the same categories of sensitive operational data regardless of which budget line paid for it."

The mitigation steps CISA recommended are worth examining honestly in the context of local government IT capacity. Isolating drones on segmented networks, disabling automatic cloud synchronization, implementing rigorous patch management, and maintaining tight control over docking stations are all reasonable security practices in theory. In practice, they require dedicated IT expertise and organizational discipline that many smaller agencies simply do not have, and ongoing monitoring capacity that a part-time IT contractor cannot realistically provide. A county sheriff's department is not running a segmented drone network. A small municipal public works office is not auditing firmware update logs. The gap between what the advisory recommends and what most local agencies can actually implement is wide enough to drive a truck through, and that gap is where the real exposure lives.

There is also a liability dimension that local officials are only beginning to reckon with. If a Chinese-manufactured drone operated by a city agency is later found to have transmitted sensitive infrastructure data, the "we didn't know" defense becomes considerably weaker after a federal agency issued a public advisory warning exactly that risk. The CISA-FBI guidance was published in January 2024. The congressional push to declassify Sandia's findings about significant national security risks from Chinese drones in critical infrastructure contexts was public by mid-2024. At some point, continued use of flagged equipment stops being an oversight and starts being a documented decision. Local officials who have not at least formally reviewed their drone procurement posture since 2024 are sitting on a risk that their general counsel probably does not know exists.

The blind spot, in other words, is not ignorance of the law. Most local procurement officers know that the ASDA covers federal funds and that their locally funded fleet sits outside that perimeter. The blind spot is the assumption that staying inside the legal perimeter means the cybersecurity concern does not apply to them. Those are two entirely separate questions, and conflating them is exactly the kind of comfortable reasoning that tends to look very bad in retrospect.

Ground Robots Are Next in Line

The drone conversation has been running for two years now, which means the ground robot conversation is roughly eighteen months behind where it needs to be. Most policymakers and local IT departments have been so focused on what is flying overhead that they have not stopped to ask what is rolling around at ground level, and who made it. The answer, increasingly, is China. The same manufacturing ecosystem that built DJI's dominance in aerial platforms has been quietly expanding into ground-based unmanned systems: inspection robots, security patrol platforms, and quadruped robots showing up in everything from logistics facilities to hospital corridors.

The policy logic that drove the drone restrictions transfers almost perfectly to ground robots, and federal agencies appear to be working through exactly that extension. The CISA-FBI advisory framed its concern around Chinese law giving the PRC government access to data held by Chinese firms, and that legal framework applies to a robot manufacturer in Shenzhen just as cleanly as it applies to a drone manufacturer in the same city. A ground robot doing security patrols in a municipal facility, or an inspection robot crawling through a water treatment plant, is generating the same categories of sensitive operational data that made drone regulators nervous: facility layouts, access patterns, and network-adjacent connectivity. The hardware category changed. The underlying risk model did not.

Chinese manufacturers have moved aggressively into the ground robotics space. Unitree Robotics, based in Hangzhou, has become one of the most visible players in the quadruped robot market, with its Go and B-series robots appearing at price points that dramatically undercut Western competitors. Unitree's hardware has shown up at technology demonstrations and university research programs, and it is increasingly appearing in commercial deployments. The company's robots are not yet as ubiquitous in American public agency fleets as DJI drones became, but the adoption curve in the early 2020s looks recognizable to anyone who watched DJI's market penetration a decade earlier. Low price and minimal early regulatory friction are a pairing that tends to drive rapid market share growth before oversight catches up, and capable hardware closes the deal.

"A ground robot doing security patrols in a municipal facility is generating the same categories of sensitive operational data that made drone regulators nervous: facility layouts, access patterns, and network-adjacent connectivity."

The 2026 cybersecurity advisory's extension to ground robots reflects an awareness that the unmanned systems threat surface is not limited to airspace. When a networked robot is operating inside a secure facility, it is not just a mobility platform; it is a sensor array with wireless connectivity, a local compute node, and a data pipeline that runs back to cloud infrastructure. The questions that CISA raised about drone firmware updates and cloud synchronization apply with equal force to ground robots that receive over-the-air software updates from manufacturer servers. If those servers are subject to Chinese law, the risk profile is structurally identical to the drone scenario, just closer to the ground and often deeper inside the facility perimeter.

What makes the ground robot situation potentially more acute than the drone situation is physical access. A drone flying over a facility is collecting external imagery and telemetry. A ground robot operating inside a facility is moving through interior spaces, mapping floor plans, observing access control points, and potentially operating on the same network segments as operational technology systems. The insider-threat analogy is imperfect but instructive: you would not hand a foreign national unsupervised access to your water treatment plant's control room, but deploying a networked robot manufactured by a company subject to foreign government data access laws achieves something structurally similar, just more slowly and with better plausible deniability.

Local governments and small contractors that are just now getting serious about their drone procurement posture need to run the same analysis on their ground robot purchasing pipeline simultaneously. The regulatory sequence for drones went from advisory to congressional pressure to NDAA restriction to FCC action over roughly two years. There is no particular reason to assume the ground robot sequence will be slower, and several reasons, including the deeper physical access these systems have, to think it could move faster. Agencies that wait for a ground robot equivalent of the ASDA before reassessing their procurement posture will find themselves in the same position that drone-dependent agencies found themselves in after December 2025: legally exposed and operationally dependent on restricted hardware, with domestic alternatives that take real time to qualify and deploy.

What U.S. Drone and Robotics Vendors Can Actually Offer Right Now

The honest answer to "what can American vendors offer?" used to be: not much, at least not at a price that made sense for a county government running on a constrained budget. That answer has changed, though not uniformly across the market. The federal restrictions on Chinese hardware created a demand signal that U.S. manufacturers have been responding to since at least 2023, and the product landscape in 2026 looks meaningfully different from what it looked like when the CISA advisory dropped in January 2024. Whether it is different enough, at the right price points, for local governments and small contractors is a more complicated question.

On the drone side, Skydio is the name that comes up most often in conversations about domestic alternatives. The San Mateo-based company has built its reputation on autonomous flight and obstacle avoidance technology, and its drones are on the Department of Defense's Blue UAS list, which is the Pentagon's approved roster of drone systems cleared for use in sensitive government applications. Skydio's X10 platform targets enterprise and public safety customers directly, and the company has been explicit about positioning itself as the domestic alternative to DJI for law enforcement and critical infrastructure operators. Shield AI has also been active in the defense-adjacent drone space, though its primary focus has been on mission profiles that differ from the inspection and public safety work that most local agencies need covered.

Percepto, an Israeli-American company with U.S. operations, has made significant inroads in the drone-in-a-box market, which is the automated, docking-station-based deployment model that many infrastructure operators prefer for routine inspection work. Their Autonomous Inspection and Monitoring platform is designed specifically for critical infrastructure use cases: power lines, oil and gas facilities, and large industrial sites. For a local utility or a public works department that wants to automate routine inspection flights without a dedicated drone pilot on staff for every flight, Percepto's model is closer to what the operational requirement actually looks like than a standard handheld-controller drone purchase.

"The federal restrictions on Chinese hardware created a demand signal that U.S. manufacturers have been responding to since 2023, and the product landscape in 2026 looks meaningfully different from what it looked like when the CISA advisory dropped."

The ground robotics side of the domestic market is less mature but moving quickly. Boston Dynamics, now owned by Hyundai, remains the most recognizable name in quadruped robotics with its Spot platform, which has been deployed in industrial inspection and infrastructure monitoring roles across the United States, including public safety applications. Spot is not cheap; enterprise pricing puts it well above what a small municipality can absorb without a dedicated grant or capital budget line. Ghost Robotics, a Philadelphia-based company, has been more aggressive in pursuing defense and government contracts with its Vision 60 quadruped, which has seen deployment with U.S. Air Force security forces. For ground-based inspection and security patrol applications, these platforms represent genuine domestic options, even if the price-to-capability ratio still favors Chinese hardware for buyers who are not thinking about the security calculus.

The pricing gap is real and should not be minimized. A DJI Mavic 3 Enterprise runs somewhere in the $2,000 to $5,000 range depending on configuration. Skydio's X10 starts considerably higher. Boston Dynamics' Spot has been reported at around $75,000 per unit for enterprise customers. For a small contractor or a rural county government, those numbers represent a fundamentally different procurement conversation, one that requires capital budget approval rather than an operational expense line. The domestic vendors are aware of this and have been working on financing options and Robots-as-a-Service arrangements that spread the cost over time, but the upfront sticker shock is still a real barrier for smaller buyers.

What domestic vendors offer that Chinese manufacturers structurally cannot is data sovereignty. When a Skydio drone uploads telemetry, that data goes to servers subject to U.S. law. When a Boston Dynamics Spot unit phones home for a software update, the update comes from a company whose source code and infrastructure are not subject to PRC government access requirements. For many buyers, that distinction has historically felt abstract. After two years of federal advisories and regulatory actions specifically describing the data exposure risk from Chinese hardware, it is becoming considerably more concrete. The question local agencies and contractors are starting to ask is not just "what does this drone cost?" but "what does this drone cost us if something goes wrong?"

The Real Cost of Switching (And the Hidden Cost of Not Switching)

Nobody likes a forced platform migration. Ask anyone who has lived through an enterprise software transition, and they will describe a period of reduced productivity and at least one moment where someone seriously suggested going back to the old system, usually right before the new system finally clicked. Switching drone or ground robot platforms is not quite that painful, but it is not a simple hardware swap either. The cost of transitioning away from Chinese unmanned systems is real, it is significant for smaller organizations, and anyone who tells you otherwise is probably selling something.

The direct hardware cost is the most visible line item but not necessarily the largest one. Replacing a fleet of DJI drones with domestic alternatives means writing checks that are two to four times larger per unit, depending on the platform and configuration. For a small contractor running three or four units, that is a manageable capital expense. For a mid-sized county public safety agency that has built out a program with a dozen or more units, plus spare parts and docking infrastructure, the replacement cost runs into six figures before you account for anything else. That number needs to appear in the budget conversation, clearly and without softening, because decision-makers who discover it mid-process tend to stall the whole initiative.

Training is the cost that almost always gets underestimated. Pilots certified on DJI's flight control system and its mission planning software need meaningful retraining time on a new platform. The flight physics transfer reasonably well; the software ecosystem does not. Skydio's autonomous flight model, for example, operates on a fundamentally different pilot interaction paradigm than DJI's manual-with-assists approach. Public safety pilots who have built muscle memory around one system will need structured transition training, not a one-afternoon orientation. For agencies that rely on part-time or volunteer drone operators, that training burden is a genuine operational constraint.

"The cost that almost always gets underestimated is training. Pilots certified on DJI's ecosystem need meaningful retraining time, and 'watch a YouTube tutorial' is not a transition plan for public safety operations."

Now for the hidden cost side of the ledger, which tends to be less visible but potentially more consequential. The first hidden cost is grant eligibility. As UC ANR's 2026 update makes clear, the ASDA prohibition extends to any entity spending federal funds, which includes grant recipients. An agency that continues operating Chinese-made drones on federally funded programs is not just accepting a security risk; it is potentially jeopardizing its eligibility for future federal grants. DHS and FEMA, along with various infrastructure funding programs, have compliance requirements that are becoming more explicit about unmanned systems procurement. An agency that gets flagged during a grant audit for non-compliant drone use faces clawback risk on funds already received, plus exclusion from future rounds. That is a cost that does not show up in any procurement spreadsheet until it is too late.

The second hidden cost is insurance and liability exposure. The cybersecurity risk that CISA explicitly warned about in January 2024 creates a documented record of known risk. Municipal insurers and errors-and-omissions carriers for contractors are beginning to ask questions about unmanned systems procurement in their underwriting processes. An agency that can demonstrate it reviewed its drone fleet posture after the federal advisories, and took documented steps toward compliance, is in a fundamentally different liability position than one that has no record of ever considering the question. The insurance market has not fully priced this yet, but the direction of travel is clear.

The third hidden cost is the one that is hardest to quantify but easiest to understand: the cost of a security incident that traces back to a Chinese-manufactured platform operating in a critical infrastructure context. That cost is not just remediation and notification. It is the reputational damage to the agency, the political fallout for the officials who approved the procurement, and the potential for federal investigation if classified infrastructure data was involved. No one can put a precise dollar figure on that scenario, but it is the kind of cost that ends careers and triggers legislative hearings. Weighed against the price premium of domestic hardware, it reframes the switching cost conversation entirely.

So Should You Pivot? A Practical Framework for Local Agencies and Small Contractors

The answer is yes, with a speed and scope that depends on two factors: how much federal funding touches your unmanned systems operations, and what those systems actually fly over or roll through. Everything else, the brand loyalty, the sunk cost in existing hardware, the comfort with familiar software, is secondary to those two variables. Get clear on both of them before you do anything else, because they determine whether you are managing a compliance deadline or a cybersecurity risk posture, and those are different problems with different timelines.

Step One: Know What You Actually Have and How You Paid for It

This sounds obvious, and it is the step that most agencies skip. Before any procurement decision gets made, someone needs to produce a complete inventory of every unmanned system the agency operates, including the manufacturer, the model, and the funding source used to acquire it. Not an approximation. Not "we have some DJI drones and a couple of other things." A spreadsheet with every unit accounted for. Then, for each unit, the question is simple: was any federal money involved in purchasing or operating it, or in reimbursing the programs it supports? If the answer is yes for any unit, that unit is subject to the ASDA prohibition as UC ANR's 2026 update interprets the restriction, and the transition timeline is not optional.

For units purchased entirely with local funds, the compliance question is different but the risk question is not. The inventory exercise should also document what each drone or ground robot actually does: what facilities it operates over or inside, what data it collects, and where that data goes after the flight. An agency that completes this exercise will almost certainly discover that some of its Chinese-manufactured systems are operating in contexts that the CISA advisory would flag as high-risk, regardless of the funding source. That discovery is uncomfortable, but it is considerably less uncomfortable than discovering it during a federal audit or after a security incident.

Step Two: Segment Your Fleet by Risk, Not Just by Funding

Once the inventory exists, the next move is to sort it by operational risk rather than by procurement category. A DJI drone used exclusively for aerial photography at public events, flying over open spaces with no connection to critical infrastructure networks, presents a materially different risk profile than the same hardware conducting interior mapping of a water treatment facility. The CISA guidance was specifically concerned with critical infrastructure contexts: power generation, water systems, transportation networks, communications infrastructure. If your Chinese-manufactured systems are not operating in or over those contexts, the immediate security urgency is lower, even if the long-term procurement direction should still trend toward domestic hardware.

High-risk use cases, meaning any operation over or inside critical infrastructure, warrant the fastest transition timeline regardless of funding source. For those applications, the CISA mitigation recommendations (network segmentation, disabled cloud sync, rigorous patch management) should be implemented immediately as interim measures while domestic alternatives are evaluated and procured. Medium-risk use cases can follow a planned replacement cycle, prioritizing domestic hardware for the next procurement round rather than forcing an early retirement of existing units. Low-risk use cases, open-area operations with no infrastructure proximity and no network connectivity, can be managed at the end of the replacement queue. This segmentation approach lets agencies move decisively on the highest-exposure applications without blowing up their entire drone budget in a single fiscal year.

Step Three: Find the Funding Before You Find the Hardware

The price premium on domestic hardware is real, but federal and state funding mechanisms exist specifically to help agencies make this transition. DHS grant programs, including the Homeland Security Grant Program and the Urban Areas Security Initiative, have been increasingly explicit about supporting technology modernization that addresses national security concerns. Agencies that frame their domestic drone procurement as a cybersecurity risk mitigation measure, and document that framing with reference to the CISA advisory and ASDA requirements, are in a stronger grant application position than agencies that present it as a routine equipment upgrade.

"Agencies that frame their domestic drone procurement as a cybersecurity risk mitigation measure are in a stronger grant application position than agencies that present it as a routine equipment upgrade."

For small contractors, the calculus is slightly different. If your client base includes federal agencies or federally funded programs, the transition is not optional; it is a contract compliance requirement. The practical move is to get ahead of client conversations rather than wait for a contracting officer to raise the issue during a renewal negotiation. Contractors who proactively document their transition to ASDA-compliant hardware, and who can demonstrate a Blue UAS-listed platform in their operational toolkit, are differentiating themselves in a procurement environment where compliance is becoming a baseline expectation rather than a bonus. The contractors who wait for clients to demand it will find themselves scrambling to qualify new hardware under time pressure, which is the most expensive way to make this transition.

The pivot question is not really binary. Treating it as "switch everything now" versus "do nothing" misses the actual decision in front of you, which is sequencing. Map your exposure by funding source and operational risk. Move the highest-exposure applications, specifically anything flying over or operating inside critical infrastructure, to domestic platforms first, using the DHS grant framing described above to fund it. Apply the CISA interim mitigations to everything else while you work through a replacement cycle. Document every step, because that documentation is your liability shield if questions arise later. The FCC closed the door on new Chinese drone authorizations in December 2025. The ASDA grace period ended the same month. The agencies that treat those two deadlines as the beginning of a managed transition, rather than a crisis or a non-event, are the ones that will be in a defensible position when the next round of restrictions arrives, and based on the last two years, another round is a reasonable expectation.

Sources

The Drone Dominance Map: China's Lead, America's Response, WisdomTree analysis of Chinese drone market dominance and U.S. public safety agency dependence on DJI hardware.

Current Demand (2023 to 2024), U.S. Bureau of Industry and Security, federal regulatory docket summarizing DJI's roughly 70% share of the global and U.S. commercial drone market.

Connected Commercial Drones Report 2025: Asia-Pacific Leads in Drone Adoption, independent market research confirming DJI's 70% global commercial drone market share.

DJI Still Dominates the 2025 Drone Market, industry reporting on DJI's continued market dominance through 2025.

Commercial Drones, Special Competitive Studies Project, federally chartered advisory body analysis placing DJI's U.S. commercial market share at close to 80%.

DJI Statistics By Usage, Sales, Revenue and Facts (2025), aggregated data on DJI's global consumer and commercial drone market penetration.

China's Civilian Drone Industry 2026: Strong Yet Besieged, analysis of the Chinese drone manufacturing ecosystem and its global supply chain position.

Does China Dominate Global Drone Markets?; Wisconsin Watch, nonprofit investigative journalism aggregating multiple independent analyst estimates of Chinese vendor market share.

Drone Market Size, Share and Growth Report, 2026 to 2033; Grand View Research, independent market sizing and forecast data for the global drone industry.

Commercial Drone Market Size, Share, Growth and Forecast; Fortune Business Insights, independent commercial drone market analysis and growth projections.

Drone Market Size, Share, Trends; Market.us, independent drone market research including segment-level data on commercial and consumer platforms.

Drones Market Trends, Analysis, Revenue, and Forecast; Market Research Future, independent market research on global drone industry revenue and adoption trends.

Drones Market Size, Growth and Industry Forecast to 2034; IMARC Group, independent research firm describing DJI's market concentration as "unprecedented" at the platform level.

Top 10 Drone Manufacturers in the World (2025), comparative analysis of global drone manufacturers by market position and product category.

DJI Maintains an Over 70% Market Share of Civilian Drones; China Economy, social media post citing current DJI civilian drone market share figures.

Release: Cybersecurity Guidance on Chinese-Manufactured UAS; CISA, official CISA news release announcing the January 2024 joint advisory with the FBI on Chinese drone risks to critical infrastructure.

Cybersecurity Guidance: Chinese-Manufactured UAS; CISA, the full CISA guidance document detailing technical risk vectors and recommended mitigations for Chinese drone hardware.

Chinese-Manufactured Drones 'Pose a Significant Risk to Critical Infrastructure'; ABC News, news coverage of the CISA-FBI advisory warning on Chinese drone data collection risks.

CISA, FBI Warn on Risks of China-Made Drones; Nextgov, government technology journalism covering the January 2024 joint advisory and its implications for federal and SLTT partners.

House Committee Urges DHS, DOE to Declassify Risks of Chinese-Manufactured Drones; Industrial Cyber, reporting on the June 2024 congressional push to release Sandia National Laboratories findings on Chinese drone security risks.

FBI and CISA Warn of National Security Threat Posed by Chinese Drones; The Record, cybersecurity journalism covering the scope and implications of the 2024 CISA-FBI joint advisory.

Is DJI Banned in the U.S.? A Precise Map of Six Overlapping Restrictions; UAS Feed, detailed explainer mapping the layered federal restrictions on DJI hardware across different regulatory frameworks.

DJI Ban in US 2026 Update, Timeline and Effects; ABJ Academy, timeline of U.S. restrictions on DJI and their practical effects on operators and procurement.

The DJI Ban: Everything You Need to Know; UAV Coach, comprehensive overview of the DJI ban history, current status, and implications for drone operators.

NDAA 2026: Local Police to Gain New Powers; DroneXL, reporting on NDAA 2026 provisions affecting local law enforcement drone authority and Chinese drone restrictions.

2026 Update for Drone Rules and Regulations; UC ANR IGIS, University of California ANR regulatory update explaining ASDA scope, the December 2025 grace period expiration, and FCC Covered List implications for state and local operators.

U.S. Commerce Department Drops Plan to Impose Restrictions on Chinese-Made Drones; Reuters, Reuters reporting on the January 2026 Commerce Department decision and its effect on the broader regulatory landscape.

FCC Bans Foreign-Made Drones Over National Security Concerns; Security Affairs, coverage of the FCC's December 2025 decision placing Chinese drone manufacturers on the Covered List.

House NDAA FY26 Chinese Drones; DroneLife, reporting on House NDAA FY2026 provisions targeting Chinese drone hardware in federal and federally funded programs.

NDAA-Compliant Drones: What the Rules Actually Mean in 2026; FlightBrief, practical guide to NDAA compliance requirements for drone operators and contractors in 2026.

New Drone Laws Take Effect: What Public Safety Agencies Need to Know; Axon, law enforcement technology firm summary of FY2025 NDAA drone provisions and FCC Covered List mechanism.

U.S. Bans New Foreign Drone Models in a Blow to Chinese Giant DJI; CNN, CNN reporting on the FCC's December 2025 prohibition on new foreign drone model authorizations.

U.S. Congress Finalizes FY25 NDAA Without Countering CCP Drones Act; DJI Viewpoints, DJI's own account of FY2025 NDAA outcomes and the statutory mechanism for adding drones to the FCC Covered List; cited as a vendor-attributed primary source, not independent analysis.

DJI Ban and NDAA Compliance; Wingtra Knowledge Base, operator-focused explainer on NDAA compliance requirements and their practical implications for drone fleet management.

DJI Ban: What It Means for Drone Owners in 2026; Drone Bundle, practical overview of the DJI ban's current status and effects on commercial and government drone operators.

Frequently Asked Questions

My city buys its drones with local tax dollars, not federal grants. Does any of this actually apply to us?

Legally? Not directly, at least not yet. The American Security Drone Act and the ASDA grace period that expired in December 2025 apply to federal agencies and any entity spending federal funds. A city running its drone program entirely on municipal budget dollars is not currently breaking any federal law by keeping its DJI fleet in the air.

Practically? The cybersecurity risk the CISA-FBI advisory described does not check your procurement paperwork before deciding whether to be a problem. A Chinese-manufactured drone flying over your water treatment plant or mapping your electrical substation is generating sensitive operational data regardless of which budget line funded it. The legal carve-out is real. Treating it as a security clearance is the mistake.

The other thing worth watching: the FCC's December 2025 decision to block new Chinese drone model authorizations signals that the regulatory perimeter is expanding. Agencies that are comfortable today because they are outside the current federal restriction should be asking themselves how comfortable they will be in eighteen months when the next round of rules arrives.

What exactly did the 2024 CISA-FBI advisory say, and why does it keep coming up in 2026?

The January 2024 advisory was a joint document from the Cybersecurity and Infrastructure Security Agency and the FBI, addressed specifically to critical infrastructure owners and state and local government partners. The core argument was that China's laws give the PRC government expanded legal access to data held by Chinese companies, and that Chinese-manufactured drones used near critical infrastructure could expose sensitive information, including facility layouts and network configurations, to those authorities.

The advisory identified two main technical risk categories: data collection during flights (telemetry and imagery that could sync to cloud services subject to Chinese law) and the software supply chain (firmware updates that could introduce vulnerabilities). It recommended mitigations like network segmentation and disabling cloud sync, while explicitly encouraging organizations to switch to U.S.-manufactured drones.

It keeps coming up in 2026 because every subsequent federal action, the ASDA, the FCC Covered List decision, the congressional push to declassify Sandia's findings, has been built on the same underlying logic the advisory established. It is the foundation document for everything that followed, and agencies that ignored it in 2024 are now operating with a documented record of having been warned.

We receive some federal grant funding but also use local funds for our drone program. How do we figure out which rules apply to which units?

This is exactly the question that most agencies are not asking carefully enough, and the answer requires an actual audit rather than a general assumption. Start with a complete inventory of every unmanned system you operate: manufacturer, model, acquisition date, and the specific funding source used to purchase it. Then, for each unit, trace whether any federal money was involved in buying it, operating it, or reimbursing the programs it supports.

UC ANR's 2026 regulatory update is explicit that the ASDA prohibition applies to any entity spending federal funds, which includes grant recipients and entities receiving federal reimbursements routed through state agencies. "We didn't buy it directly from a federal contract" is not a safe harbor if federal money touched the budget line somewhere upstream.

Units acquired entirely with local funds sit outside the current federal prohibition but not outside the cybersecurity risk. The practical approach is to sort your fleet by both funding source and operational risk simultaneously. A locally funded drone doing aerial photography at a public park is a different conversation than a locally funded drone mapping the interior of a water treatment facility. Both questions matter; neither answer is the same.

Are U.S. drone manufacturers actually good enough to replace DJI, or is this a "buy American" situation where the product is noticeably worse?

Honestly, it depends on the use case, and anyone who gives you a blanket answer in either direction is oversimplifying. For autonomous flight and obstacle avoidance in complex environments, Skydio's technology is genuinely competitive and in some respects more capable than DJI's approach. The X10 is on the Pentagon's Blue UAS approved list, which means it has cleared a level of security scrutiny that DJI hardware cannot. For public safety and infrastructure inspection, it is a credible platform.

For drone-in-a-box deployments, Percepto has built a real business in critical infrastructure inspection and their Autonomous Inspection and Monitoring platform is purpose-built for exactly the kind of routine, automated inspection work that local utilities and public works departments need.

Where the gap is still noticeable is price. A DJI Mavic 3 Enterprise runs roughly $2,000 to $5,000. Skydio's X10 starts considerably higher. Boston Dynamics' Spot quadruped for ground robotics comes in around $75,000 per unit. The hardware quality is there. The price-to-capability ratio still favors Chinese manufacturers for buyers who are not factoring in the security and compliance costs, and those costs are the entire point of this conversation.

What is the FCC Covered List, and what does it actually mean for drones we already own?

The FCC Covered List is the Commission's register of communications equipment deemed an unacceptable risk to U.S. national security. In December 2025, the FCC added foreign-made drones and key components, including hardware from DJI and Autel, to that list. CNN reported that the decision prohibited the importation and sale of all new drone models and essential equipment from these manufacturers in the U.S. market.

Here is the critical distinction: existing approved models can still be sold and used. The FCC action did not make your current DJI fleet illegal to operate. What it did was close the pipeline for new products. No new DJI or Autel drone models will receive FCC equipment authorizations going forward, which means the Chinese drone ecosystem in the U.S. is now in a managed wind-down. The hardware already on the market keeps circulating; the next generation of products from those manufacturers does not enter the market.

For agencies and contractors, the practical implication is that your current Chinese-made drones are not suddenly contraband, but your upgrade path just disappeared. When your existing units age out, the replacement options from those same manufacturers will not be available. Planning your transition to domestic hardware now, rather than when your DJI fleet needs replacing, is considerably less stressful.

Why should we worry about ground robots? The conversation so far has been entirely about drones.

Because the same logic applies, and the physical access is actually worse. A drone flying over your facility collects external imagery and telemetry. A ground robot operating inside your facility is moving through interior spaces, mapping floor plans, observing access control points, and potentially sitting on the same network segments as your operational technology systems. Chinese law gives the PRC government access to data held by Chinese companies. A networked robot manufactured by a Chinese company and deployed inside a critical facility is structurally the same problem as a Chinese drone flying over it, just with better building access.

Unitree Robotics, based in Hangzhou, has been expanding aggressively into the quadruped robot market at price points that undercut Western competitors significantly. The adoption pattern looks a lot like DJI's trajectory a decade ago: capable hardware, low price, minimal early regulatory friction. The drone regulatory sequence went from CISA advisory to NDAA restriction to FCC action in roughly two years. There is no obvious reason the ground robot sequence would be slower, and the deeper physical access these systems have gives policymakers more urgency, not less.

Agencies that are just now getting their drone procurement posture sorted should run the same analysis on their ground robot pipeline at the same time. Doing it twice, sequentially, is the more expensive version of this problem.

What are the hidden costs of not switching that most budget conversations miss?

Three categories tend to get underweighted. The first is grant eligibility. Agencies operating Chinese-made drones on federally funded programs risk jeopardizing future federal grant eligibility and face potential clawback on funds already received if flagged during an audit. That cost does not appear in any procurement spreadsheet until it is already a problem.

The second is insurance and liability. Municipal insurers and errors-and-omissions carriers for contractors are starting to ask about unmanned systems procurement in underwriting processes. An agency that has a documented record of reviewing its drone fleet posture after the federal advisories is in a meaningfully different liability position than one with no record of ever considering the question. The CISA-FBI advisory was published in January 2024. "We didn't know" gets harder to argue with every month that passes.

The third is the hardest to put a number on: the cost of an actual security incident traced back to a Chinese-manufactured platform operating near critical infrastructure. Remediation, notification, reputational damage, political fallout, and potential federal investigation are not line items that fit neatly into a budget comparison with Skydio's X10 pricing. But they are real costs, and weighed against the price premium of domestic hardware, they reframe the switching cost conversation entirely.

We are a small contractor, not a government agency. Do these rules apply to our business?

If any of your clients are federal agencies or run federally funded programs, the ASDA prohibition applies to your drone operations on those contracts. You are an entity spending federal funds the moment federal money flows through a client contract to your work. That is not a gray area; UC ANR's 2026 regulatory update is explicit on this point.

The smarter business question is not just "are we compliant?" but "are we ahead of where our clients are going?" Contracting officers at federal agencies and federally funded programs are increasingly treating ASDA compliance and Blue UAS-listed hardware as baseline expectations rather than nice-to-haves. Contractors who can demonstrate a compliant fleet and documented transition away from Chinese hardware are differentiating themselves in a procurement environment that is moving in one clear direction.

Waiting for a client to raise the issue during contract renewal is the most expensive version of this transition. You end up scrambling to qualify new hardware under time pressure, retraining operators on a compressed schedule, and potentially losing a contract renewal to a competitor who got ahead of it. The proactive version of this conversation, where you bring the compliance documentation to the client before they ask, is both cheaper and better for the relationship.

Thinking About Modernizing Your Agency's Tech Stack?

If this post has you rethinking not just your drone fleet but your broader technology procurement and automation strategy, the Handybots team can help you map out a digital transformation plan that actually fits your budget and operational reality, not a generic framework built for a Fortune 500 company.

Reach out at handybots.ai/contact or drop us a line at info@handybots.ai and we will take it from there.

Table of Contents

Related Posts

REQUEST A CALL

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.