GAO Reports Federal Agencies Not Sharing Data on Banned Chinese Tech, Hindering Compliance
What's Happening?
A U.S. Government Accountability Office (GAO) report, published on September 22, found that while federal agencies have significantly reduced spending with five prohibited Chinese telecommunications and
surveillance companies, key agencies are not adequately sharing information to ensure broader compliance. The report examined how the General Services Administration (GSA) and the Department of Defense (DoD) have implemented Section 889 of the John S. McCain National Defense Authorization Act for Fiscal Year 2019. This act prohibits federal agencies from procuring covered equipment or services from specific Chinese companies and from contracting with vendors using such items. Although GSA and DoD have developed internal processes and tools to support compliance, they are not broadly sharing implementation insights, including information about the companies' subsidiaries and affiliates, or methods for improving supply chain visibility, with other federal agencies. This lack of information sharing could delay the detection and resolution of compliance issues across the government.
Why It's Important?
The failure of federal agencies to share critical data on banned Chinese technology poses a significant national security risk and undermines the effectiveness of procurement restrictions. Section 889 was enacted to mitigate potential cyberattacks, espionage, and threats to national security stemming from reliance on certain foreign-made items. Without comprehensive information sharing, other federal agencies may inadvertently procure prohibited equipment or services through subsidiaries or affiliates, creating vulnerabilities in their systems. This lack of coordinated effort could lead to inconsistent compliance across the government, leaving gaps that could be exploited by foreign adversaries. For U.S. businesses, particularly those in the technology and defense sectors, it creates an uneven playing field and potential confusion regarding compliance requirements, while also highlighting the need for robust supply chain due diligence to avoid inadvertently using banned components.
What's Next?
The GAO issued four recommendations, urging the GSA Administrator and the Secretary of Defense to periodically share subsidiary and affiliate information with relevant federal agencies and coordinate broader lessons learned from their Section 889 implementation experience. Both GSA and DoD have concurred with these recommendations, indicating a willingness to address the issue. GSA is reportedly working on a plan, and DoD will assess the feasibility of establishing criteria for identifying subsidiary and affiliate information and coordinating with GSA and CISA (Cybersecurity and Infrastructure Security Agency) on information-sharing forums. This suggests that future efforts will focus on establishing formal mechanisms for inter-agency data sharing and collaboration to enhance compliance with procurement restrictions and strengthen the overall security of federal supply chains. The upcoming prohibition on certain Chinese semiconductors and services, scheduled for December 2027, further emphasizes the urgency of these information-sharing improvements.
Beyond the Headlines
The issue of federal agencies not sharing data on banned Chinese technology extends beyond mere procedural inefficiency; it touches upon the complex geopolitical landscape and the ongoing technological competition between the U.S. and China. The procurement restrictions are not just about avoiding specific companies but about safeguarding critical infrastructure and intellectual property from potential state-sponsored espionage. The lack of information sharing highlights a broader challenge in federal governance: the difficulty of achieving seamless coordination and intelligence sharing across diverse agencies, even when national security is at stake. This situation could lead to a fragmented approach to cybersecurity and supply chain integrity, potentially undermining the strategic intent of the restrictions. Ethically, it raises questions about the collective responsibility of federal entities to protect national assets and maintain a unified front against external threats. The long-term implications involve not only the security of government systems but also the resilience of the U.S. technology sector and its ability to compete globally without compromising national interests.