The most consequential number in America’s defense against foreign vehicle software is not a model year, an ownership threshold, or a dollar figure. It is a weight.
Ten thousand and one pounds.
Below that line, the Commerce Department’s connected vehicle rule has effectively outlawed Chinese and Russian software in anything that talks to the outside world. Above it, the federal government has written nothing at all. And almost everything that carries the public for a living — transit buses, school buses, airport shuttles, box trucks, one-ton work pickups — lives above the line.
Which brings us to a bus parked inside a Norwegian mountain.
What Norway actually did
Ruter, the public transport authority for Oslo and Akershus, took two electric buses into an isolated facility carved into a mountain and went after them. One was a brand-new Yutong from China. The other was a three-year-old VDL from the Netherlands. Ruter published the results and has updated the page since.
The VDL turned out to be boring in the best possible way: no autonomous over-the-air update capability, which means no standing remote channel to abuse. The Yutong was a different animal. It had OTA updates, and the manufacturer held direct digital access to the bus’s battery and power supply control systems through a Romanian SIM card. In theory, Ruter concluded, the manufacturer could stop the bus. Testers also found a vulnerability in the Chinese software platform that serves Yutong’s customers, which was subsequently fixed.
“This comprehensive and unique test enables us to implement the proper protection in the buses,” said Ruter CEO Bernt Reitan Jenssen.
We wrote about that finding when it surfaced, and about why every connected vehicle carries some version of the same plumbing. Here is the part that has gone almost entirely unremarked in Washington: the vehicle Norway tested is precisely the vehicle the American rule does not touch.
The fine print nobody reads
The Bureau of Industry and Security published its final connected vehicle rule on January 16, 2025. It took effect March 17, 2025. It bars importing or selling connected vehicles containing vehicle connectivity or automated driving software designed, developed or supplied by parties owned by, controlled by, or subject to the jurisdiction of China or Russia. Covered software is barred starting with model year 2027. Covered hardware follows with model year 2030.
Now the definition. BIS’s own compliance guide defines a connected vehicle as “a vehicle that is below 10,001 pounds and is driven or drawn by mechanical power and manufactured primarily for use on public streets, roads, and highways.”
Below 10,001 pounds. That is the whole rule, and that is where it ends.
Commerce did not hide this. The final rule says plainly that while commercial vehicles such as buses are not in scope, the agency “intends to propose a new rule specifically tailored to the commercial vehicle sector in order to address substantial national security risks.”
It has not. A search of the Federal Register’s BIS filings turns up no such proposal. The January 2025 final rule remains the agency’s most recent connected vehicle action, with the two documents before it being the 2024 proposals that led to it. Twenty months of stated intent, zero published text.
The weight line is drawn upside down
The Department of Energy’s vehicle weight class tables make the geography clear. Class 3 begins at 10,001 pounds. Urban buses sit in the heaviest bracket, above 33,001 pounds. A city transit bus is more than three times the ceiling of the rule written to keep foreign software out of American vehicles.
Also above the line: heavy-duty pickups and chassis cabs, delivery vans, ambulances, shuttle buses, school buses, and motorhomes. A regulation sold to the public as protection from foreign code in their vehicles stops before it reaches the vehicle that takes their kids to school.
If anything, the logic runs backward. The vehicles above the cutoff are worse candidates for exemption than the ones below it. They carry dozens of passengers instead of one family. They stay in service twelve to fifteen years instead of six. They are bought in fleet lots, frequently with public money. And they carry deeper telematics than any passenger car, because fleet operators pay extra for exactly that — remote diagnostics, charge scheduling, driver monitoring. The connectivity is not a side effect of the purchase. It is a line item on the invoice.

Europe regulated this exact bus, and still ended up here
Here is the second thing worth sitting with. Norway is inside the European type-approval system, which has the strictest vehicle cybersecurity rules on the planet. UN Regulation 155 and UN Regulation 156 became mandatory for new vehicle types in the EU in July 2022 and for all new vehicles produced from July 2024.
R155 applies to “vehicles, with regard to cyber security, of Categories L, M, N and O, if fitted with at least one electronic control unit.” Category M is buses and passenger vehicles. The bus was covered.
And R155 does not prohibit manufacturer access. It requires the manufacturer to maintain a cybersecurity management system that includes processes to “monitor for, detect and respond to cyber-attacks, cyber threats and vulnerabilities,” explicitly extending that monitoring to “vehicles after first registration,” with an annual report to the approval authority confirming the mitigations still work. R156 governs how software updates are managed and delivered, which presumes the delivery channel exists.
Read the two together and the conclusion is uncomfortable but unavoidable. The regulation assumes a live link between the factory and the fleet, for the entire life of the vehicle, and then asks the manufacturer to govern it responsibly. Compliance and exposure travel down the same wire.
Norway did not find a backdoor. It found the front door, propped open by regulation, and asked a better question than most governments have bothered to ask: who is standing on the other side of it, and whose courts can reach them?
The kill switch is already American
None of this is a foreign invention. General Motors advertises it. OnStar’s Stolen Vehicle Assistance includes Remote Ignition Block, where after a police report “OnStar can then send a remote signal that blocks the engine from starting,” and Stolen Vehicle Slowdown, where advisors can “remotely slow it down” to help officers end a pursuit. It is a feature, it is on the brochure, and buyers like it.
The difference between that and the Yutong finding is not capability. It is jurisdiction, auditability, and who can be subpoenaed when it goes wrong.
And it does go wrong. In August 2023 the Consumer Financial Protection Bureau sued auto loan servicer USASF Servicing, alleging it wrongly disabled borrowers’ vehicles at least 7,500 times when those borrowers were not in default, triggered warning tones more than 71,000 times against consumers who were current or actively working out payments, and shut off at least 1,500 vehicles after specifically promising not to.
So the first mass failure of vehicle kill switches in the United States was not espionage. It was accounting. Thousands of Americans walked out to a car that would not start because a servicer’s records were wrong, years before anyone thought to test a bus inside a mountain. Manufacturers have been circling the same ground; Ford tried to patent a vehicle that locks out its own owner and was turned down.
Yutong is not hiding any of this
Worth noting, because the espionage framing obscures it: remote fleet control is a product, marketed openly. Yutong’s own materials for its Link+ fleet platform say it “remotely monitors 100+ parts and components,” “tracks vehicle locations and real-time status,” offers remote climate control, and provides geo-fencing that “realizes intelligent speed limits in designated zones.”
Remote speed limiting is remote control of the vehicle. It is sold as an efficiency feature to fleet buyers, and every major bus manufacturer offers some version of it. Nobody had to break in. The capability was in the sales deck.
What actually closes the gap
Ruter’s response is the most useful part of the whole episode, and it has nothing to do with import bans. The agency says it will write stricter security requirements into future procurement, build a firewall around local vehicle controls, and introduce signal delays so incoming updates can be inspected before they reach the bus.
That is a contract problem solved with contract tools. It is available today to every transit agency, every municipal fleet, every logistics company, and it does not require an act of Congress or a two-year rulemaking. A purchase order can demand disclosure of every remote access path, a local veto over remote commands, and staged updates. A customs classification cannot.
For ordinary owners, the equivalent fight is over who gets access to the data and the diagnostic channel in the first place — the REPAIR Act argument playing out in Congress — and over how broadly lawmakers define the vehicles they mean to cover, a problem the current Chinese vehicle legislation keeps stumbling into.
The one thing to remember
The exposure Norway documented is architectural, not national. Any vehicle that can be updated remotely can be reached remotely, and the industry, the regulators and the insurers all decided years ago that the benefits were worth it. Where the country of origin genuinely matters is narrower and more practical than the headlines suggest: it determines whose law governs the company holding the keys, and whether anyone can compel an answer.
A rule that sorts vehicles by curb weight rather than by connectivity gets both halves of that wrong. It exempts the heaviest, most connected, most publicly exposed vehicles on the road, and it does so on a technicality that has nothing to do with the risk it was written to address.
A remote shutdown command does not care what the vehicle weighs. Only the rule does.
So where should the line actually go — at the curb weight, or at the connection? And if it moved, would you accept the same scrutiny on your own truck’s telematics to get there?

