UBIQS

US assembly isn't enough: the case for component-level provenance

The FCC just closed the "component part loophole." Verifying where a device was assembled no longer proves it's clean — and proving genuineness component by component is a harder, more important problem.

Share LinkedIn X Email

The timing here is worth flagging precisely, because it changes what "built in America" actually needs to prove. The FCC closed the component-part loophole — prohibiting authorization for devices that incorporate any logic-bearing hardware component from a Covered List entity, not just the assembled device's country of origin.

That's a meaningfully harder compliance bar than US assembly alone satisfies. A robot assembled in the US can still fail this if a controller, a sensor, or a logic-bearing component inside it originated from a Covered List entity somewhere upstream. And verifying that with genuine confidence — component by component, across a multi-tier supply chain — is a different, harder problem than verifying final assembly location.

Why the vulnerabilities don't care where a box was assembled

The vulnerabilities the FCC cited — remote takeover, exposed camera and microphone feeds — are exactly the kind of risk that persists if a compromised or foreign-sourced component is quietly present inside an otherwise US-assembled device. The threat lives in the part, not in the final assembly line. A clean assembly record says nothing about whether a logic-bearing component three tiers up is what it claims to be.

This is a genuinely valuable direction for the industry regardless of how any single company markets it. The harder question is the honest one: is US assembly alone sufficient proof, or does closing the gap the FCC is targeting actually require verifiable, component-level provenance?

Final assembly location is one bit of information. The regulation is now asking a question with many more bits: is every logic-bearing component in this device genuine, and where did it come from?

Attestation on paper vs. attestation from physics

Most supply-chain provenance today is documentary: a supplier attests, a certificate is issued, a spreadsheet is signed. That chain is only as strong as the weakest attestation in it, and it says nothing about whether the specific physical part on the board is the one the paperwork describes. A substituted, cloned, or counterfeit component passes a paper trail as easily as a genuine one — because the paperwork was never bound to the physics of the part.

The alternative is to let each logic-bearing component prove its own genuineness. If a component carries an identity derived from a physical property of the silicon itself — not a stored serial number that can be re-flashed, but something intrinsic to that specific device — then "is this the genuine part?" becomes a question you can answer by verification, not by trust. Counterfeit and substituted parts stop looking identical to genuine ones, because the identity can't be copied onto an impostor.

From "assembled here" to "provably genuine, part by part"

Component-level provenance turns compliance from an assertion into evidence. Instead of one claim about the finished device, you get a verifiable identity for each logic-bearing component, and a signed, tamper-evident record tying those identities to the assembled device — a bill of components an auditor or regulator can check independently, later, without taking anyone's word for it.

That's the same primitive UBIQS builds for sovereign AI infrastructure: a persistent, silicon-rooted identity that proves which physical thing you're actually looking at, under whose authority, with evidence that survives the moment. The FCC's move is a reminder that the question "is this hardware genuine, all the way down?" is moving from best practice to baseline — and that answering it well takes provenance rooted in physics, not paperwork.

Keep reading

Related

Working on hardware provenance you need to prove?

We're talking with teams building verifiable, component-level trust into infrastructure and devices.