Table of Contents
    Get answers from the Community
    Join discussions

    When Polestar announced that it would stop selling new vehicles in the United States starting with model year 2027, it wasn’t a business strategy pivot driven by demand. It was a direct consequence of a regulatory decision that every automaker importing connected vehicles into the U.S. needs to understand.

    The Swedish EV maker was denied authorization under the U.S. Department of Commerce’s Bureau of Industry and Security (BIS) Connected Vehicle Rule. The denial blocks Polestar from selling new models in the U.S. market from MY2027 onward. Existing Polestar 3 and Polestar 4 inventory can still be sold through current stock.

    In response, the company is doubling down on Europe, which already accounts for close to 80% of its retail volume, and accelerating plans to manufacture future models on the continent. This is the first high-profile application of the Connected Vehicle Rule against a named brand, and the implications extend far beyond Polestar.

    What is the Connected Vehicle Rule?

    The Connected Vehicle Rule, codified under 15 CFR Part 791, Subpart D, is administered by BIS and targets a specific risk: connected vehicle technologies with supply chain ties to China or Russia. Under the rule, importers of connected vehicle technologies must attest to the origin of all software libraries used in their connected vehicle systems, including modified open source software (OSS).

    The rule’s logic is straightforward: Modern vehicles are rolling software platforms, and the provenance of that software matters for national security. Connected vehicle systems can transmit sensitive data, receive remote commands, and integrate deeply with national infrastructure. The U.S. government’s position is that software with opaque or adversarial supply chain origins poses an unacceptable risk.

    What makes the Polestar case particularly instructive is what the denial was not based on. The BIS decision focused on software provenance and Polestar’s ownership structure, not simply where the hardware was manufactured. This distinction matters enormously for the broader industry.

    Why it matters to automotive companies

    The rule applies to all importers, regardless of where vehicles are assembled

    Every automotive manufacturer importing connected vehicles into the U.S. must provide the required attestation for MY2027 and beyond, regardless of where the assembly line is located or where the company is headquartered. What matters is the software supply chain inside the connected vehicle systems.

    Being in the same corporate family doesn’t protect you

    Volvo Cars, another brand under the same parent company as Polestar, received a different authorization outcome during the same period. This confirms that BIS is evaluating each brand’s software architecture independently.

    Automakers cannot assume that an approved sibling brand, a shared platform, or a common parent company provides protection. Each application stands on the provenance of its software components.

    Reliable attestation is critical

    The Connected Vehicle Rule’s enforcement mechanism centers on software provenance and the attestation of software library origins. Importers must be able to demonstrate where their software components came from, which versions are in use, and whether any open source components have been modified.

    Modern vehicles incorporate thousands of software components, and connected vehicle systems layer proprietary software on top of open source foundations that include dozens or hundreds of upstream dependencies. Producing a reliable attestation is extremely difficult without systematic tooling and processes, and an inaccurate or incomplete attestation carries serious consequences.

    The cost of getting it wrong is market access

    The Polestar outcome illustrates the stakes plainly. Failure to properly manage the software supply chain and meet the attestation requirements of 791.D can result in loss of access to the U.S. automotive market. For MY2027 and beyond, authorization is required and denial means the vehicles simply cannot be sold new in the United States.

    For companies with significant U.S. revenue, this is an existential commercial risk. For companies in the middle of product development cycles for MY2027 models, the window for addressing software supply chain gaps is closing.

    Black Duck recommends

    Meeting the key OSS requirements of the Connected Vehicle Rule is achievable, but it requires the right combination of tooling and processes. Here is what automotive companies should be doing now.

    Conduct a full software supply chain inventory

    Before you can attest to the origin of your software components, you need to know what’s in your products. This means going beyond first-party code. You must map every open source dependency across your connected vehicle systems, including transitive dependencies that may not be immediately visible.

    Use signature scanning and SBOM comparison to identify modified OSS

    The Connected Vehicle Rule’s focus on modified open source components makes  signature scanning and SBOM comparison critical capabilities. Black Duck® SCA provides both, and allowing companies to identify whether an OSS component has been modified from its upstream version, which version was modified, and who the primary contributors to that component are. This is the foundation of a reliable, defensible attestation.

    Leverage OpenHub to understand contributor provenance

    For components that have been modified or where contributor identity is material to the compliance analysis, Black Duck SCA links to OpenHub to help identify key maintainers and considerably narrow the review scope. This makes it easier for companies to identify the primary contributors, filter the set of components requiring closer review, and focus human analysis where it matters most.

    Don’t assume your architecture is covered by someone else’s authorization

    Given that BIS is making architecture-level determinations, rather than brand- or group-level decisions, each company needs to evaluate its own software stack. Don’t rely on a parent company’s approval, a platform partner’s certification, or an industry peer’s successful authorization as a proxy for your own compliance posture.

    Start now

    The Polestar denial is not an isolated event. It is the Connected Vehicle Rule working as designed and a signal that enforcement will be rigorous, architecture-specific, and consequential. Every automaker importing connected vehicles into the U.S. should treat this as a call to action.