All Reports

GAO finds DOD and GSA fail to share intelligence on prohibited Chinese telecom affiliates

Bot Mutiny |

A new GAO report reveals that while the DOD and GSA have reduced spending on prohibited Chinese telecommunications equipment, they aren't sharing data on corporate subsidiaries with other federal agencies.

The federal government hasn't figured out how to talk to itself about the risks in its own supply chain. According to a report published on September 22, 2026, by the Government Accountability Office, two of the largest buying arms of the state are keeping critical information about prohibited Chinese tech companies to themselves. The Department of Defense (DOD) and the General Services Administration (GSA) account for nearly two-thirds of all federal contract obligations as of fiscal year 2025. They've spent years figuring out how to comply with Section 889 of the John S. McCain National Defense Authorization Act for Fiscal Year 2019. That law bans agencies from buying equipment or services from five specific Chinese companies and their various affiliates. It also stops them from awarding contracts to any company that uses their tech. ## Data Hoarding in the Supply Chain

The GAO found that the DOD and GSA have actually done a decent job cleaning their own houses. Agencies reduced their spending with the five prohibited companies from 2019 through fiscal year 2025. In three of those years, there was no spending at all. By March 2026, nearly 90 percent of companies with active government contracts claimed they weren't using the banned equipment. But there's a disconnect. The GSA and DOD have built search tools and automated processes to identify these companies and their subsidiaries. They've even started using customs data to track where goods actually come from. They just aren't sharing those insights with the rest of the federal government. ## The Blind Spots

This lack of coordination leaves other agencies vulnerable. The GAO report notes that information about the subsidiaries and affiliates of these five companies is vital. Without it, smaller agencies are essentially guessing whether a vendor is a shell for a prohibited entity. It's not just about the current ban on telecommunications and surveillance gear. The government is looking at upcoming prohibitions on semiconductors. If the DOD and GSA don't start sharing their methods and data now, every other agency will have to reinvent the same security checks from scratch. The GAO made four specific recommendations. It wants the Secretary of Defense and the Administrator of GSA to start periodically sharing information about subsidiaries and affiliates with other agencies. They suggested using the Cybersecurity and Infrastructure Security Agency's (CISA) existing channels to move the data. ## A Slow Response to Known Threats

Concerns about Chinese tech companies facilitating espionage or cyberattacks aren't new. The government has been talking about this for over a decade. While the DOD and GSA have managed to purge most of these products from their own direct contracts, the "publicly represented" compliance from 90 percent of contractors still leaves a 10 percent gap. The GSA and DOD have concurred with the GAO's recommendations. However, as of the report's release, the status for all four recommendations remains open. No concrete actions have been taken yet to satisfy the requirement for better information sharing. Until these agencies open up their databases, the federal supply chain remains as strong as its least-informed department.