If you follow robotics news, you will have seen the headlines. The US Federal Communications Commission (FCC) has raised concerns about Chinese-manufactured robots - specifically naming Unitree among other Chinese technology companies - citing data security and potential remote access risks. The coverage has been alarming in tone and often imprecise in detail.
For UK buyers of Unitree, DEEP Robotics, or other Chinese robot platforms, the question is simple: does this affect me? The answer is also fairly simple, but the details matter. This piece explains what the FCC actually said, why it does not directly apply to UK buyers, and what obligations UK buyers do have under UK law.
What the FCC Actually Said (and Did Not Say)
The FCC's concerns about Chinese technology companies fall within a broader US policy framework around national security and technology supply chains. The FCC has been designated by the US Congress to review and potentially restrict equipment from companies deemed to pose national security risks under the Secure and Trusted Communications Networks Act.
The concerns about robots - as distinct from telecom equipment, where the FCC has acted more definitively against Huawei and ZTE - centre on several issues:
Data collection: Modern robots with camera and sensor arrays collect substantial data about their environment. The concern is that this data could be transmitted to Chinese servers or accessed by Chinese authorities under Chinese national security law, which requires Chinese companies to cooperate with state intelligence services.
Remote access capability: Networked robots that can be accessed and controlled remotely present a potential vector for surveillance or sabotage if that remote access could be exploited by state actors.
As of September 2026, the FCC has not issued a full ban on Unitree or other Chinese consumer robots. The FCC has placed certain Chinese companies on a "Covered List" of equipment deemed to pose national security risks, primarily focused on telecom and surveillance equipment. The extension of these concerns to robots is an active discussion, and the situation may evolve. US buyers should monitor FCC developments carefully.
The important point for UK buyers: the FCC is a US regulatory body. It has no jurisdiction in the United Kingdom. FCC rules, restrictions, and the "Covered List" do not apply to UK purchases, UK commercial deployments, or UK universities.
The UK Regulatory Framework
UK buyers of Chinese robots are subject to different regulators and different rules:
Ofcom is the UK's communications regulator, with some overlapping jurisdiction to the FCC but focused on UK networks and spectrum. Ofcom has not issued specific guidance on Chinese robots as of September 2026, though it has taken an interest in broader telecoms supply chain security.
The National Cyber Security Centre (NCSC) provides guidance to UK organisations on supply chain security, including technology purchases from higher-risk origins. NCSC guidance does not specifically address consumer robots but is relevant for organisations deploying networked robotic systems in sensitive environments (government, critical national infrastructure, defence-adjacent).
The Information Commissioner's Office (ICO) is the UK's data protection regulator. This is the most directly relevant body for most UK commercial buyers of camera-equipped robots. The ICO enforces the UK GDPR (the retained and amended version of the EU GDPR that applies in the UK following Brexit).
UKCA marking is required for robots sold for commercial use in regulated environments in the UK. This is a product safety requirement, not a data security one, but used robots imported from China for commercial use should be assessed for UKCA compliance.
The UK GDPR Consideration
This is the substantive obligation that UK commercial buyers of camera-equipped robots need to take seriously - regardless of where the robot was manufactured.
If your robot collects camera images, sensor data, or any other information from which individuals can be identified, you are processing personal data under UK GDPR. This applies whether the robot is made by Unitree, Boston Dynamics, or a European manufacturer.
Key UK GDPR obligations for robot deployments:
Data Protection Impact Assessment (DPIA): Required when processing is likely to result in high risk to individuals. Deploying a camera-equipped robot in a workplace where employees or members of the public may be captured almost certainly triggers a DPIA requirement. The DPIA documents what data is collected, why, how long it is retained, who can access it, and what security measures are in place.
Lawful basis for processing: You need a lawful basis to process personal data. In a workplace context, legitimate interests (balanced against employee privacy rights) or contractual necessity are the most common bases. Pure surveillance without a clear purpose or legitimate interest would not meet the lawfulness requirement.
Data minimisation: Collect only the data you actually need. If the robot needs camera data for navigation, you do not necessarily need to retain high-resolution images of every person the robot encounters. Configure data retention and resolution appropriately.
Data transfer restrictions: UK GDPR restricts transfers of personal data to countries without adequate data protection. If your robot's cloud features transmit data to servers in China, this is a restricted transfer that requires either explicit consent, a lawful transfer mechanism (Standard Contractual Clauses with the UK's equivalent), or avoidance (by disabling cloud features).
> Quick win: For most UK commercial deployments of Unitree or other Chinese robots, the simplest GDPR compliance path is to disable cloud connectivity and operate in local-only mode. This eliminates the data transfer issue entirely and significantly reduces the risk profile of the deployment. Review Unitree's developer documentation to confirm local operation configuration before deployment.
Practical Risk Assessment for UK Unitree Buyers
The Unitree Go2 and G1 are among the most commonly discussed robots in the FCC context. Here is a practical risk assessment for UK buyers:
Research and education use (university lab, offline development): Low risk. Configure the unit for local operation, disable cloud features, use the ROS 2 integration for development work. This eliminates the primary data security concerns. Standard DPIA may be required if the lab environment includes people being captured by the robot's cameras during operation.
Commercial indoor deployment (warehouse, facility inspection): Medium risk without mitigation; low risk with appropriate configuration. Disable cloud features, segment the robot from external networks, implement a DPIA, and document the data flows. NCSC guidance on operational technology security is relevant here.
Deployment in sensitive environments (government, defence-adjacent, critical infrastructure): Higher scrutiny required. The NCSC supply chain guidance should be followed, and departmental security advisors consulted. This is not specific to Unitree or Chinese robots - any networked robot in these environments requires this level of assessment.
Consumer home use: The practical risk is low. A Go2 operating in a private home, used by its owner for hobby development, does not typically process third-party personal data and the GDPR obligations are limited. The FCC-origin concerns about state-level surveillance remain theoretical at this scale.
Configuring Unitree Robots for UK GDPR Compliance
Unitree supports several operating modes relevant to UK GDPR compliance:
Local network only: Both the G1 and Go2 can be operated on a local network without cloud account activation. The basic motion control, SDK access, and ROS 2 interfaces work without cloud features. Verify this in your specific firmware version before deployment.
Cloud features: Unitree's cloud services (if activated) provide firmware updates, remote monitoring, and some AI processing features. If you activate these, personal data processed by the robot's cameras may be transmitted to Unitree's servers. This requires a lawful transfer mechanism under UK GDPR.
Firmware updates: Even in local operation mode, occasional connection for firmware updates is practical for security maintenance. This limited connectivity for update purposes does not constitute ongoing cloud-connected operation. Maintain a log of firmware versions for your compliance documentation.
Our full Unitree G1 review covers the G1's software architecture and connectivity options in more detail.
What UK Universities and Businesses Should Document
Institutional buyers - universities, large businesses, public sector organisations - typically have governance requirements beyond basic ICO compliance. Here is what to document:
- Intended use case: What is the robot being used for? Research on locomotion algorithms differs from commercial data collection.
- Data flows: What data does the robot collect? Where is it processed? Who has access? Is any data transmitted externally?
- Network configuration: Is the robot on an isolated network, a managed research network, or connected to the public internet? Document the segmentation.
- DPIA: Completed and signed off by your Data Protection Officer if one is required by your organisation.
- Software and firmware inventory: Current version, update history, and the process for applying future updates.
- Procurement rationale: Why this specific robot? For procurement governance purposes, documenting that you assessed alternatives and the data security considerations is valuable.
This documentation is good practice for any networked robot deployment, not just Chinese-manufactured ones. But it is particularly valuable when deploying equipment that has attracted regulatory scrutiny elsewhere.
> Quick win: The ICO's website provides a free DPIA template and guidance on completing it. For most straightforward commercial robot deployments, a DPIA can be completed in-house with a few hours of work. You do not necessarily need a consultant for a standard deployment - but if the deployment is unusual or the data sensitivity is high, specialist data protection advice is worthwhile.
The Bottom Line for UK Buyers
UK buyers of Unitree, DEEP Robotics, or other Chinese robots are not subject to FCC rules. The US regulatory discussion does not create legal obligations for UK purchases or deployments.
UK buyers are subject to UK GDPR when robots process personal data, and to standard product safety requirements (UKCA marking for commercial use). These obligations apply regardless of robot origin and are manageable with appropriate configuration and documentation.
For most research, education, and commercial users, the practical answer is: buy the robot that best meets your technical and commercial needs, configure it for local operation where cloud connectivity is not required, and complete a DPIA if the deployment processes personal data. The same answer would apply if you were buying a Boston Dynamics Spot or a European-made robot.
The FCC discussion is a signal worth noting for anyone who follows the broader technology geopolitics of China-US relations. It may affect future UK policy. But for today's UK buyer, it is not a reason to avoid Chinese robot platforms.
Before completing any used robot purchase, see our inspection guide for practical due diligence steps. For current Unitree pricing in the UK used market, see our UK robot market roundup for September 2026 and the resale index.
Frequently Asked Questions
Is there a UK ban on Unitree or other Chinese robots? No. As of September 2026, there is no UK ban or import restriction on Unitree, DEEP Robotics, or other Chinese robot manufacturers. The FCC concerns are a US regulatory matter and do not apply in the UK. UK buyers are subject to Ofcom and ICO regulations, not the FCC.
What data security risks should UK buyers of Chinese robots consider? The main consideration for UK commercial buyers is UK GDPR compliance when robots collect camera or sensor data in environments where personal data may be processed. Local processing configuration, network segmentation, and a data protection impact assessment (DPIA) are the practical steps. The FCC's specific concerns about remote access risks are a factor for any networked robot regardless of origin.
Can the Unitree G1 or Go2 be configured to operate without cloud connectivity? Yes. Both the Unitree G1 and Go2 can be configured to operate in a local-only mode without cloud services enabled. This eliminates most of the remote access concerns raised in the US context. Local SDK access, ROS 2 integration, and offline operation are all supported. Review Unitree's developer documentation and disable cloud features if they are not required for your use case.
What should UK universities and businesses document when buying Chinese robots? Document the intended use case, data flows (what camera and sensor data is collected and where it is processed), network configuration (local vs cloud-connected), and your DPIA if the robot processes personal data in commercial settings. Keep records of firmware versions and update history. This documentation supports ICO compliance and institutional governance requirements.
---
Considering a Unitree robot or other Chinese platform? Browse available used units on Robot AutoTrader, check the resale index for current UK pricing, or read our inspection guide before making an offer.
