We didn't see this coming. Not the regulatory proposal itself—that was telegraphed months ago through the usual policy whisper network. What caught us off guard was the framing. The Federal Communications Commission, an agency historically focused on spectrum allocation and broadcast decency, is now poised to make a decision that could reshape the global supply chain for one of the most ubiquitous components in modern networking: the humble optical module.
The Information Technology Industry Council (ITI), representing the collective voice of America's largest technology companies—Apple, Google, Microsoft, Amazon—has formally opposed the FCC's proposal to include all foreign-manufactured optical modules in its Covered List. This isn't a niche regulatory skirmish. It's a test case for whether American national security policy will evolve toward precision or default to blanket prohibition.
And for those of us who've spent years watching the intersection of technology, policy, and human consequence, the stakes extend far beyond fiber optic transceivers. This is about how we govern the invisible infrastructure that powers everything from streaming video to blockchain consensus mechanisms.
The Context: A List That Keeps Growing
Let me take you back to 2021. The Secure Equipment Act was passed with bipartisan urgency, mandating that the FCC maintain a "Covered List" of communications equipment and services that pose an unacceptable risk to national security. The initial targets were unambiguous: Huawei, ZTE, and other entities with explicit ties to the Chinese government. The logic was clear—go after the bad actors, not the entire ecosystem.
The first Covered List arrived in 2022. It was surgical. It named specific companies, specific products, specific threats. But then something shifted. By 2024, the FCC began signaling that it might expand the list beyond named entities to entire categories of products. And now, the commission is considering whether to include all foreign-manufactured optical modules—the transceivers that convert electrical signals to light and back again, the connective tissue of every data center and telecommunications network on Earth.
Here's what most people don't understand about optical modules: they're not exotic technology. They're commodity components, manufactured at scale by companies like Innolight and Eoptolink in China, Coherent and Lumentum in the United States, and Sumitomo in Japan. A single data center can contain hundreds of thousands of them. They're the screws and bolts of the digital age—unremarkable, interchangeable, and absolutely essential.
The FCC's proposal would effectively ban federal agencies and federally-funded projects from using any foreign-made optical module. Given that Chinese manufacturers control over 50% of the global market, this isn't a targeted strike at a specific threat. It's a wrecking ball aimed at the entire supply chain.
The Core: When Security Policy Collides with Technical Reality
Based on my experience auditing blockchain infrastructure projects and their underlying network dependencies, I can tell you that the optical module supply chain is far more complex than most policymakers realize. And that complexity creates a fundamental tension with the FCC's apparent approach.
The first problem is traceability. Optical modules are embedded components. They go into switches, routers, and servers manufactured by Cisco, Juniper, Dell, and a dozen other companies. By the time a federal agency purchases a completed networking system, the original manufacturer of each individual optical module is often lost in a labyrinth of distributors, value-added resellers, and system integrators. The FCC's proposal assumes a level of supply chain visibility that simply doesn't exist in practice.
The second problem is substitution. If you ban all foreign-made optical modules, you're not just punishing Chinese manufacturers. You're creating a supply gap that American and allied manufacturers cannot fill. Coherent and Lumentum are excellent companies, but their combined production capacity is a fraction of what the market demands. The result would be project delays, cost overruns, and—ironically—a less secure supply chain, as desperate buyers scramble for whatever components they can find through unofficial channels.
The third problem is the chilling effect. Even if the FCC ultimately backs down, the mere threat of inclusion has already changed behavior. Procurement officers, risk-averse by nature, are preemptively reducing their reliance on Chinese optical modules. Contracts are being renegotiated. Supply chains are being restructured. The FCC's regulatory shadow is achieving what its actual rule might not—a de facto decoupling that's happening without any legislative mandate.
This is where I see a parallel to the blockchain world. In decentralized systems, we talk about "trustless" interactions—mechanisms that don't require you to trust any single party. But the FCC's approach here is the opposite: it's demanding total trust in a specific set of suppliers, while simultaneously making it impossible to verify the provenance of components that are several layers deep in the supply chain.
The Contrarian Angle: What If the FCC Is Right?
Now, let me play devil's advocate, because intellectual honesty demands it. The FCC's concern isn't entirely unfounded. Optical modules are network-adjacent devices. They handle data in transit. A compromised module could theoretically be used for surveillance, data exfiltration, or network disruption. And given the Chinese government's legal requirements for companies to cooperate with intelligence agencies, the risk isn't purely hypothetical.
But here's the uncomfortable truth that the FCC's approach ignores: the threat model is wrong. The risk isn't in the optical module itself—it's in the software and firmware that controls it. A sophisticated adversary doesn't need to compromise the physical hardware. They can achieve the same result through a software update, a compromised management interface, or a supply chain attack on the firmware development process.
By focusing on the physical component, the FCC is fighting the last war. It's like banning all foreign-made tires because you're worried about a car bomb, while ignoring the fact that the bomb could be hidden in the entertainment system.
There's also a deeper question about the "Major Questions Doctrine," which the Supreme Court has increasingly applied to limit agency overreach. In West Virginia v. EPA (2022), the Court held that agencies cannot regulate matters of "vast economic and political significance" without clear congressional authorization. Banning an entire product category that underpins the global internet infrastructure would seem to qualify. If the FCC proceeds, it's inviting a legal challenge that could tie up the rule in litigation for years—and potentially establish precedent that limits the agency's authority in other areas.
The Human Dimension: What This Means for the People Building the Future
I've spent the last decade working with open-source communities and blockchain developers around the world. I've seen firsthand how regulatory uncertainty affects real people—not just corporate compliance officers, but the engineers, entrepreneurs, and community builders who are trying to create a more open, transparent, and equitable digital future.
For the Chinese engineers at Innolight and Eoptolink, this isn't an abstract policy debate. It's their livelihoods. It's the teams they've built, the innovations they've pioneered, the global market they've earned through years of hard work and technical excellence. The assumption that all Chinese-manufactured optical modules are inherently suspect is not just wrong—it's dehumanizing.
For the American network engineers who will have to navigate a fragmented supply chain, it means longer lead times, higher costs, and more complexity. It means explaining to their CFOs why the data center expansion is over budget. It means telling their users why the new service is delayed.
And for the broader ecosystem—the blockchain networks, the cloud providers, the streaming services, the telehealth platforms—it means a less resilient internet. A more expensive internet. A more fragile internet.
We didn't build the internet to be fragile. We built it to be redundant, distributed, and resilient. The FCC's proposal, however well-intentioned, moves us in the opposite direction.
The Path Forward: Precision Over Prohibition
The ITI's recommendation is worth taking seriously. Instead of banning an entire product category, the FCC should focus on entities with demonstrable ties to foreign adversaries. This is the "small yard, high fence" approach that the Biden administration has articulated—targeted restrictions on specific threats, not blanket prohibitions on entire technologies.
But I'd go further. The FCC should consider establishing a certified trusted supplier program—a framework where optical module manufacturers can voluntarily submit to rigorous security audits, supply chain transparency requirements, and ongoing monitoring in exchange for access to the federal market. This would achieve the security goals without disrupting the global supply chain.
This isn't a novel idea. It's how we handle other critical infrastructure. The FAA certifies aircraft components. The FDA certifies medical devices. The FCC itself certifies radio equipment. Extending this model to optical modules would be consistent with established regulatory practice.
There's also a role for the open-source community here. Just as we've developed tools like OpenSSF's Scorecard to assess the security of open-source software, we could develop similar frameworks for hardware supply chain transparency. Blockchain-based provenance tracking—ironically, the very technology that's often dismissed as "useless"—could provide the immutable, verifiable record of component origins that regulators claim they need.
The Takeaway: A Moment of Choice
The FCC's decision on optical modules will set a precedent that extends far beyond this single product category. If the commission succeeds in banning an entire class of technology based on country of origin, it opens the door to similar restrictions on servers, switches, power supplies, and every other component of the digital infrastructure.
This is a moment of choice. We can choose the path of fear—blanket prohibitions that fragment the global economy, raise costs, and ultimately make us less secure by creating new single points of failure. Or we can choose the path of precision—targeted restrictions on actual threats, combined with robust certification frameworks that reward transparency and security.
The blockchain community has long championed the principle that transparency builds trust. It's time to apply that principle to our physical infrastructure. The question isn't whether we should secure our supply chains—we absolutely should. The question is whether we'll do it with the wisdom and precision that the moment demands, or with the blunt instrument of fear.
We didn't build the internet to be a walled garden. We built it to be an open network. Let's not let fear close it down, one optical module at a time.