
Robots on the manufacturing facility ground. Self-driving autos on the Las Vegas strip. Even an alternative to man’s finest buddy — the robotic canine.
They’re all a part of the bodily synthetic intelligence buildout that will depend on high-tech, low-cost lidar, the crucial sensors that enable these applied sciences to see their environment.
A Hesai lidar sensor.
CNBC
And on the coronary heart of this buildout is Hesai Know-how, a Shanghai-based lidar producer blacklisted as a nationwide safety menace in 2024 by the U.S. Division of Protection, which designated Hesai as a Chinese language navy entity. Whereas the blacklist prevents Hesai and the 187 different firms and subsidiaries on the checklist from securing Pentagon contracts, there’s nothing unlawful about utilizing these merchandise in nonmilitary functions. Hesai’s presence on the blacklist doesn’t forestall U.S. firms from utilizing Hesai’s know-how.
Authorities officers and safety specialists say using Chinese language lidar might open this new, crucial infrastructure to cyberthreats with probably critical penalties and turn out to be a backdoor for Beijing to entry delicate knowledge collected by the lidar know-how.
David Li, Hesai’s co-founder and CEO, says the narrative that his firm poses a menace is fiction.
David Li, Hesai’s co-founder and CEO.
CNBC
“Within the DOD case, I do not really feel there’s adequate proof, and it is not logical,” Li mentioned. “We’re annoyed by that.”
In his first prolonged interview in regards to the blacklist designation, Li defended the corporate in opposition to allegations that its know-how poses nationwide safety dangers or may very well be utilized by the Chinese language authorities to gather knowledge.
David Li, Hesai’s co-founder and CEO, speaks to CNBC’s Melissa Lee in his first prolonged interview about his firm’s blacklist designation by the U.S. Division of Protection.
CNBC
Regardless of the federal blacklist designation, Hesai’s attain is rising. Below an expanded partnership between Hesai and Nvidia, Hesai sensors shall be one of many choices automakers can select to combine into Nvidia’s autonomous automobile platforms, which the chipmaker hopes will energy the self-driving automobile revolution.
“Our imaginative and prescient is that some day, each single automotive, each single truck shall be autonomous. And we’ve been working in the direction of that future,” Nvidia CEO Jensen Huang mentioned in his keynote deal with on the Shopper Electronics Present in January, when the expanded partnership was introduced.
Huang has mentioned that robotics, which incorporates self-driving vehicles, is the corporate’s second most essential development class after synthetic intelligence. In its newest annual submitting, Nvidia reported automotive income for fiscal 12 months 2026 was up 39% from a 12 months prior, pushed by the adoption of its self-driving platforms.
Hesai is likely one of the dominant suppliers within the international autonomous know-how ecosystem. Its sensors are built-in into a number of autonomous techniques along with Nvidia’s, together with these of Amazon’s robotaxi firm, Zoox; autonomous trucking firms akin to Waabi and Kodiak; autonomous automobile know-how firm Nuro; and agricultural automation agency Agtonomy. The sensors will also be discovered at New York’s John F. Kennedy Worldwide Airport, the place they monitor passenger and site visitors move at safety checkpoints and gate entrances, and even in autonomous garden mowers.
The specter of weaponizing lidar
Not everyone seems to be satisfied that these data-collecting sensors must be built-in into U.S. autonomous techniques.
Craig Singleton is a senior director for the China Program on the Basis for Protection of Democracies, a conservative Washington-based suppose tank recognized for being crucial of the Chinese language authorities. His analysis has concluded that there are safety dangers in Chinese language-made sensors working in U.S. techniques, together with that lidar sensors might allow Beijing “to entry delicate U.S. knowledge or disrupt crucial operations.”
Craig Singleton, a senior director for the China Program on the Basis for Protection of Democracies.
CNBC
Lidar — which stands for “gentle detection and ranging” — works by firing laser pulses and measuring how lengthy it takes for them to bounce off an object and again to the sensors. The sensors then mix hundreds of those measurements to create a “level cloud,” or three-dimensional map, which permits autonomous machines to see and navigate their environment.
Singleton advised CNBC that as Chinese language lidar sensors turn out to be extra prolific throughout the U.S., they’ll transfer nearer to protection nodes, utility grids and airports.
“That knowledge is so delicate and it is so exact that it may very well be weaponized by a hostile international energy in the event that they ever needed to focus on our infrastructure,” Singleton mentioned.
Questions on how and the place Chinese language-made lidar sensors are getting used come alongside broader considerations about Chinese language authorities oversight and the potential for that authorities to entry knowledge collected by Chinese language firms.
The U.S. Securities and Change Fee requires all China-based firms to reveal “the danger of Chinese language authorities intervention or management.” In its SEC filings, Hesai has disclosed that the Chinese language authorities has “important oversight in regulating our operations and should affect or intervene in our operations at any time.”
Singleton mentioned that partly means Hesai will be compelled to share knowledge collected by its lidar sensors with the Chinese language authorities.
“Whether or not they need to transmit that info or not is not a query, it is mandated by regulation,” Singleton mentioned.
Li mentioned the corporate’s sensors maintain no knowledge as a result of they lack the reminiscence capability to take action. He mentioned Hesai’s companions are accountable for securing the information the sensors accumulate and that Hesai has no management over that.
Li additionally rejected considerations that the Chinese language authorities might entry knowledge by way of the corporate.
However Singleton mentioned the fast deployment of autonomous techniques is outpacing scrutiny over potential safety dangers.
“It is a story as outdated as time with Chinese language tech,” he mentioned.
‘Rip and change’
Corporations within the U.S. have beforehand embraced low-cost Chinese language know-how, even from entities that had been blacklisted, solely to later spend billions changing it after the merchandise raised nationwide safety considerations.
Chinese language telecommunications large Huawei, for instance, was positioned on the Protection Division’s blacklist in 2021, however that didn’t cease U.S. firms from utilizing Huawei merchandise. The Federal Communications Fee, which had designated Huawei a “nationwide safety menace” in 2020, pressured U.S. firms to “rip and change” Huawei merchandise from their networks starting in July 2021. Huawei challenged each the choice to bar it from securing federal contracts and FCC’s designation of the corporate as a nationwide safety menace in court docket, however misplaced each circumstances.
Like Huawei, different Chinese language firms have been discovered by the Protection Division to be nationwide safety dangers solely after their merchandise made their means into U.S. properties and companies.
DJI, the world’s largest drone maker, and Wi-Fi router maker TP-Hyperlink Applied sciences, each based mostly in Shenzhen, China, bought fashionable client items. DJI was blacklisted in 2022 by the Pentagon for its ties to the Chinese language authorities, and TP-Hyperlink Applied sciences was added to the checklist in June 2026.
DJI sued the Protection Division in 2024 to be faraway from the blacklist, however a federal choose dominated there was “substantial proof” that the corporate contributes to China’s protection industrial base. DJI is interesting the choice.
In contrast to Hesai, which stays free to promote lidar sensors commercially in the US, a separate FCC ruling in December banned DJI from promoting new merchandise to U.S. customers resulting from nationwide safety dangers, although current fashions stay authorized to make use of.
TP-Hyperlink Applied sciences was additionally barred from promoting new fashions after the FCC in March decided foreign-made routers pose “an unacceptable threat to the nationwide safety of the US.”
Inside a simulated lidar assault
Nationwide safety considerations surrounding foreign-made lidar sensors have additionally spurred tutorial analysis on the potential dangers posed by these gadgets.
Miroslav Pajic, a professor at Duke College who research vulnerabilities in lidar sensors, advised CNBC it is “simple to bodily spoof lidar.”
Miroslav Pajic, a professor at Duke College who research vulnerabilities in lidar sensors.
CNBC
Pajic mentioned any lidar sensor will be compromised with malware inserted on the manufacturing facility throughout manufacturing or by way of firmware updates. Malware will be troublesome to detect, since automakers and different producers often can not entry a lidar maker’s proprietary supply code and malware can stay dormant till triggered.
Inside his lab at Duke, Pajic demonstrated one such assault.
On a pc monitor displaying a lidar sensor’s level cloud picture, the room the sensor was capturing appeared precisely as anticipated. The sensor mapped its environment in actual time, making a 3-D image of the house.
However after Pajic activated malware embedded within the lidar unit, an individual appeared within the sensor’s level cloud. In actuality, no one had entered the room.
The system generated a phantom particular person — a false object created fully by way of manipulated sensor knowledge.
Pajic’s lab has additionally carried out demonstrations which have the alternative impact: manipulating lidar knowledge to take away actual objects from a sensor’s view. In that situation, an autonomous system might fail to detect a pedestrian, automobile or impediment that’s bodily current.
Pajic mentioned comparable assaults might theoretically be used in opposition to autonomous automobile fleets working in cities, inflicting them to malfunction.
When requested in regards to the simulation, Li mentioned a system will be designed to be weak in a lab setting.
However the threat of malfunction is not simply theoretical.
Michael Robbins, CEO of the Affiliation for Uncrewed Automobile Programs Worldwide — a commerce group that represents firms within the business, together with U.S. lidar opponents — mentioned that in 2024 Hesai pushed a firmware replace to all its lidar sensors. The firmware did not bear in mind that 2024 was a bissextile year, so on Feb. 29, all of Hesai’s lidar sensors stopped working.
Michael Robbins, CEO of the Affiliation for Uncrewed Automobile Programs Worldwide.
CNBC
“In that case it was by error, however that may be accomplished deliberately, the place each lidar in use in the US may very well be turned off, or it may very well be used in opposition to us in a nefarious means,” Robbins mentioned.
Whereas the potential for a software program error throughout autonomous autos is widespread, an error in lidar techniques is grave contemplating its implementation in vehicles throughout America.
Li mentioned that within the case of the bissextile year incident there was an missed coding bug within the firmware — not malware. He added that Hesai publishes all its firmware as open supply knowledge, so it may be publicly analyzed. In an announcement to CNBC, Hesai mentioned the difficulty was fastened inside 24 hours.
“We’re making ourselves clear on what precisely this is ready to do,” he mentioned.
Li additionally mentioned autonomous techniques are designed with different sensors akin to cameras and radar techniques that may compensate for lidar failures.
“If any of them cease, the vehicles should reevaluate the state of affairs to know whether or not it is protected sufficient to proceed the course or we’re gonna have to tug over,” he mentioned.
Hesai’s sensors have additionally met the requirements set by Tüv Rheinland and Dekra, that are unbiased third-party firms specializing in product testing, security validation and cybersecurity assessments.
Hesai’s U.S. companions
An individual walks exterior the headquarters of lidar sensor maker Hesai in Shanghai, China, Nov. 26, 2024.
Zoey Zhang | Reuters
Hesai, which is publicly listed on each the Nasdaq and the Hong Kong Inventory Change, is likely one of the world’s greatest lidar producers. It has one-third of the worldwide automotive lidar market, the corporate advised CNBC in an announcement.
And autonomous driving is projected to turn out to be a large international market. McKinsey & Firm estimates the market potential for autonomous driving shall be roughly $300 billion to $400 billion by 2035.
Hesai’s footprint contained in the U.S. autonomous ecosystem has continued to develop.
CNBC reached out to Hesai’s U.S. companions about their relationship with the corporate.
CNBC requested Nvidia greater than a dozen questions, together with whether or not it was conscious that Hesai had been blacklisted by the Pentagon and what safeguards are in place to guard the information the sensors accumulate.
Nvidia didn’t reply to CNBC’s particular questions and as a substitute supplied an announcement:
“Automakers worldwide demand an open, vendor-agnostic reference structure, to allow them to choose elements which are finest for the markets they serve to construct the most secure vehicles. Our NVIDIA DRIVE Hyperion structure offers that flexibility, guaranteeing that American business competes worldwide, in keeping with all regulatory and business necessities.”
In an announcement, Kodiak wrote that its know-how is designed “in order that Hesai doesn’t have entry to the information from their sensors or any knowledge produced by Kodiak’s autonomous system.”
A spokesperson for Waabi wrote that its “autonomous vehicles make the most of an array of sensors” and that it doesn’t “touch upon or disclose particular {hardware} being examined or utilized in our autonomous autos.” The spokesperson added, “Now we have rigorous knowledge safety protocols in place and totally vet all third-party {hardware} to make sure absolutely the integrity and security of our techniques in addition to compliance with all relevant legal guidelines and rules.”
Agtonomy, Nuro and Zoox didn’t reply to CNBC’s request for remark.
Excessive-tech, low price
Hesai’s growth has been pushed partly by pricing.
Hesai advised CNBC it has lowered the price of its lidar items from greater than $10,000 every to lower than $200. By comparability, U.S. lidar producer Aeva advised CNBC its automotive sensors price “within the few tons of of {dollars}” per unit.
Trade analysts say that the pricing benefit is reshaping the market. A 2025 automotive lidar report by the Yole Group, a world advisory and market evaluation agency, mentioned Chinese language corporations akin to Hesai are “dominating resulting from price, scale and authorities help” whereas Western gamers “face larger prices and slower adoption.”
In an announcement to CNBC, Hesai mentioned it is among the many first within the business to mass produce its lidar techniques resulting from its “innovation” and “automotive manufacturing functionality.”
Critics say these decrease costs are solely attainable due to Chinese language authorities help.
“Chinese language lidar firms have benefited from huge unfair state subsidies which have allowed them to scale manufacturing and management the market,” mentioned Singleton, of the Basis for Protection of Democracies.
Li denied his firm receives help from the Chinese language authorities.
“That is an accusation with no proof,” he mentioned. “If you see a participant with the ability to construct sensors at a way more reasonably priced stage, you simply assume that they get assist.”
Based on Hesai’s 2025 annual submitting with the U.S. SEC, the corporate acquired Chinese language authorities subsidies, preferential tax charges of 15% versus the usual 25%, preferential borrowing charges beneath benchmark, and a tax break that lets it deduct 200% of its analysis and improvement prices.
In an announcement to CNBC, Hesai mentioned these applications are usually not uncommon, that “governments worldwide generally supply tax incentives to know-how enterprises as a regular measure to stimulate innovation” and that these incentives are “broadly accessible to all qualifying firms in China, each home and international.”
Hesai additionally wrote that “no authorities group, together with the Chinese language authorities, holds any fairness stake in Hesai.”
Ties to the Chinese language navy
On the middle of Hesai’s authorized battle with the Pentagon is whether or not the corporate contributes to China’s military-civil fusion technique, a nationwide initiative aimed toward integrating civilian and navy technological improvement. The Pentagon says Hesai is a part of that ecosystem.
After the Protection Division blacklisted Hesai in January 2024, the corporate sued the division in federal court docket over the designation, in Could 2024.
In court docket filings, the Protection Division cited a number of components in help of the designation. Amongst them is that Hesai’s Chinese language headquarters are in Shanghai’s Jiading district, an space related to military-civil fusion initiatives.
Li rejected that argument. He mentioned a military-civil fusion zone has not been clearly outlined and that a number of of the businesses within the space are American firms.
“For lack of a greater analogy, simply because the Pentagon is in Virginia, you suppose that Virginia is a spot filled with navy,” Li mentioned. “Anyone working within the state of Virginia turns into navy.”
The Pentagon additionally pointed to provider relationships between Hesai and China Electronics Know-how Group Company, or CETC, a state-owned protection conglomerate tied to the Folks’s Liberation Military. In a prospectus Hesai submitted for attainable itemizing on the Shanghai Inventory Market, CETC is listed as its third-largest provider.
Li mentioned not one of the elements Hesai bought from CETC have a navy utility.
In court docket, Hesai additionally mentioned its sensors are “solely for business and civilian makes use of.”
Li additionally advised CNBC that Hesai’s business settlement strictly prohibits clients from utilizing its gadgets in navy functions. Nevertheless, he additionally mentioned that, like all piece of {hardware}, as soon as sensors depart the manufacturing facility, it’s inconceivable to bodily management the place they find yourself.
Hesai misplaced its lawsuit in opposition to the Protection Division in 2025 and stays on the blacklist. The corporate is interesting the choice.
Further scrutiny
Past the courtroom, the corporate can be dealing with scrutiny from worldwide coverage teams.
In July 2025, the Prague Safety Research Institute — a nonprofit, nongovernmental public coverage group — revealed a white paper on Hesai. Among the many findings: Hesai’s lidar sensor appeared on a navy automobile throughout a 2023 Chinese language navy tv program. This system is named “Land Unmanned Programs Problem,” a Chinese language unmanned techniques competitors hosted by China’s Military Gear Division and arranged by a navy analysis institute.
Chinese language protection supplies describing the occasion say its purpose is to advance China’s military-civil fusion technique. Contributors included navy and civilian universities, state-owned enterprises, personal firms and analysis institutes testing unmanned autos.
Li confirmed that the sensor that appeared within the footage was Hesai lidar know-how however mentioned the corporate didn’t provide the sensor for the navy competitors.
“We shipped in all probability tons of of hundreds of lidars like this,” Li mentioned. “So, there’s a risk that they find yourself someplace that we’re utterly unaware of within the aftermarket.”
Li additionally mentioned Hesai has no solution to talk with or hint the sensors as soon as they’re shipped out, that the sensors ship the information to the corporate utilizing them, to not Hesai.
Proposed laws
On Capitol Hill, lawmakers are elevating alarms about using Chinese language lidar know-how in the US, warning the sensors might create each cybersecurity and nationwide safety dangers.
“These sensors and the power to transmit info is a large concern,” mentioned U.S. Rep. John Moolenaar, R-Mich., chairman of the Home Choose Committee on the Chinese language Communist Get together. The committee’s web site says that it’s “dedicated to engaged on a bipartisan foundation to construct consensus on the menace posed by the Chinese language Communist Get together.”
U.S. Rep. John Moolenaar, R-Mich., chairman of the Home Choose Committee on the Chinese language Communist Get together.
CNBC
A number of the committee’s work has targeted on defending U.S. automakers from Chinese language competitors.
The committee has proposed laws that will section out Chinese language-made lidar know-how in the US, arguing that the Chinese language Communist Get together might in any other case exploit a fast-growing and strategically essential business.
In Could, Moolenaar launched laws that will ban Chinese language autos from U.S. roads.
Li mentioned his firm’s sensors are usually not able to storing knowledge and subsequently couldn’t transmit info to China. However Moolenaar mentioned he’s skeptical of these assurances, arguing that Chinese language know-how has been recognized to have again doorways.
“We have seen again doorways in robots that will transmit info again to those Chinese language Communist pursuits,” he mentioned.
No proposed laws or current legal guidelines at present prohibit blacklisted Chinese language firms from being listed on U.S. inventory exchanges or forestall American traders from shopping for their shares.
Moolenaar mentioned firms targeted on development and shareholder returns might not prioritize nationwide safety considerations in the identical means policymakers do.
“We have to think about what implications there are after we merge these Chinese language applied sciences with American applied sciences,” he mentioned. “Typically laws takes some time to catch up.”
Clarification: This text was up to date to make clear that TP-Hyperlink Applied sciences, based mostly in Shenzhen, China, was added to the Protection Division’s blacklist in June 2026.