Closing Bell - CNBC Special: How a Blacklisted Chinese Tech Firm Is Expanding in the U.S. 7/7/26
Episode Date: July 7, 2026CNBC's Melissa Lee speaks with David Li, Hesai's co-founder and CEO, about the company's partnership with Nvidia, concerns over potential cybersecurity risks, and how Hesai is responding as scrutiny o...f Chinese technology firms continues to grow. Hosted by Simplecast, an AdsWizz company. See https://pcm.adswizz.com for information about our collection and use of personal data for advertising.
Transcript
Discussion (0)
LIDAR, the technology autonomous systems like self-driving cars, used to see their surroundings.
And one of the world's biggest makers of LIDAR is at the center of a growing national security debate in the U.S.
David Lee is a founder and the CEO of Shanghai-based HESai technology.
Does the Chinese government have any influence over the operations of your company?
There is no additional influence other than following the local rules.
Hesai is on what's known as the blacklist.
According to the Department of Defense,
Hesai is a Chinese military company.
While the blacklist is designed to protect against national security threats,
it only bans HESI and other companies on the list from securing DOD contracts.
There's nothing illegal about using HESI sensors in non-military applications,
potentially exposing the public to those risks.
The danger, government officials and security experts say,
Security experts say the Chinese Communist Party could access, hack or manipulate with malware
the sensitive data collected by the LIDAR with potentially serious consequences.
And yet HESI sensors are all over the country.
In autonomous lawnmowers, in airports, including New York's JFK International, and even in
humanoid robots, like the one for sale in the U.S. made by Unitary, another Chinese company
on the blacklist.
And now, HESI's reach is expanding, announcing earlier this year at the Consumer Electronics Show
that its LIDAR is one of the sensors automakers can choose to integrate into NVIDIA's latest self-driving systems.
A system NVIDIA hopes will power this technological wave sweeping cities across the country.
Our vision is that someday every single car, every single truck, will be autonomous, and we've been working towards that future.
In the global race to dominate artificial intelligence, the next frontier is physical AI.
And all of it depends on high-tech, low-cost sensors like LIDAR, to collect the spatial awareness information necessary for the systems to work.
I don't think there's any doubt that HESA is a Chinese military company with ties to the Chinese government.
Craig Singleton is a senior fellow for China at the Foundation for Defense of Democracies,
a conservative DC-based think tank known for being critical of the Chinese government.
His research has focused on the security risks of Chinese-made sensors operating in U.S. systems.
What kind of data are we talking about?
As Chinese LIDAR sensors become more prolific across the United States,
they're going to operate ever closer to our defense nodes, our utility grids, and our transportation hubs.
The data is so sensitive and it's so precise that it could be weaponized by a hostile foreign power
if they ever wanted to target our infrastructure.
We sat down with Lee in his first extended interview
about the company's blacklist designation
and whether his LIDAR is a security risk.
So you're not in the data business at all.
There's no way of getting that data.
Zero.
There's no way of sending it back.
Even if the Chinese government asked you for it,
you would have to say, no, it's impossible.
Exactly that.
And in the future, if the Chinese government said to you,
we want you to manufacture your LIDAR sensors
in a different way,
would you have to comply?
They've never done that.
I won't be able to answer
a hypothetical case that don't exist.
You can't answer whether or not
you'd have to comply
with the Chinese government requests.
If it's by the law required,
we'll follow the rules, right?
But we won't be able to respond
to something that never happened
as a hypothetical case
that is not something
what we do.
That doesn't allay
concerns over Hissai,
which has a third
of the global automotive LIDAR market, now estimated to be a $300 to $400 billion market by 2035.
Government officials and security experts say LIDAR sensors can be compromised with potentially dangerous consequences.
LIDAR sensors work by firing laser pulses and measuring how long it takes for them to bounce off an object and back to the sensor.
The sensor combines thousands of these measurements to create a point cloud or 3D map of the world,
allowing machines like this robotic dog to see and navigate their surroundings.
Miroslav Pajik is a professor at Duke University who studies vulnerabilities in these sensors.
How vulnerable is LIDAR?
It's easy to physically spoof LIDAR.
He says any LIDAR sensor can be compromised with malware inserted at the factory during production
or through firmware updates.
Malware can be difficult to detect since companies deploying the LIDAR usually cannot actually
access a sensor's proprietary source code and malware can remain dormant until triggered.
If that happens, the malware can trick the sensors into creating a false picture of a vehicle's
surroundings.
He demonstrated this in real time at Duke's lab.
So we have in front of us a LiDAR.
Yeah.
Off-the-shelf state-of-D-R device.
It is transmitting laser pulses and those pulses are used to map the world around us.
So pretty much it's building a 3D point cloud and as you can see, they're transmitting the
two of us in the scene.
So we're here.
We're here.
Nobody else.
OK.
What we have here is a triggering device.
It is sending a similar laser pulse.
It just has an encoded, a secret key command that triggers the malware that is deployed
on that particular device, on that lighter.
So when I press this button, it triggers this malware.
It will generate the third fake person.
You see there's no one here.
Right.
But we see in the point cloud that there is another person that is joining us.
Other demos from Pajek's lab show how objects can be removed from the sensor's data, causing a vehicle to crash.
We are preparing now a demo where you fly a drone over it, and you can then, like, I know, all the vehicles in the area that have that kind of sensor will be triggered immediately.
So think of it from DOD applications.
You have deployed like a swarm of ground vehicles or drones.
and then all of a sudden everything has been disabled or even worse attacking their own forces.
And in theory, you could apply that to an autonomous vehicle fleet operating on a city street
with the drone flying over to trigger the malware.
Yes, yes, yes, yes.
It's not science fiction.
No, no. We can do that in a month.
In a statement to CNBC, HESI wrote its LIDARs are protected against hacking.
and remain secure at all times.
And HESI's LIDAR sensors have met the standards
set by Tove Rhineland and DECRA,
independent third-party companies
that specialize in product testing,
safety validation, and cybersecurity assessments.
We interviewed a professor at Duke University
who studies LIDAR security specifically.
And he showed us how LIDAR sensors
can be remotely disabled or manipulated.
I don't know the exact setup,
but I tend to argue if you do that,
in the lab setup, obviously you design a system,
you can design a system to be vulnerable.
That's not very hard.
But Michael Robbins says the risks are not hypothetical.
Robbins is president and CEO of the Association
for Uncrued Vehicle Systems International,
a trade organization that represents companies,
including US LiDAR competitors.
So in 2024, HSAI pushed a firmware update
to all of their LIDAR sensors in the world.
And there was an error in the firmware that didn't take into account the fact that that was a leap year.
And on February 29th, every LiDAR sensor stopped working, every HESI LiDAR sensor, because they didn't account for the leap year.
In that case, it was by error, but that could also be done intentionally, where every LiDAR in use in the United States could be turned off,
or it could be used against us in a nefarious way.
So the real world impact could be a manifest in a physical accident?
It could manifest in chaos.
It was our fault. We had a bug in the firmware that we overlooked.
Who's to say if this happens with this simple error not accounting for the leap year,
that it couldn't be done deliberately?
This is the same possibility of any technology product having a bug that would
cause negative impact to the user.
And the worst case scenario we can see is that this sensor will have an error signal and then
the computer will know.
Beyond NVIDIA, HESI's U.S. partners include the autonomous trucking companies Wabi and Kodiak,
the autonomous vehicle technology company, Nuro, Agtonomy, which builds automation software
for agricultural vehicles, and Robotaxi developer Zouk,
owned by Amazon with vehicles that are equipped with multiple HESI LIDARs.
You can find Zucs vehicles on the Las Vegas Strip, San Francisco, and it's coming to Austin and Miami.
All of these companies operate commercially and legally since the vehicles are not used for military
purposes.
Has HESI technology been used in the military at all?
Our commercial agreement is such that we prohibits.
our customers to use that in any military application anywhere in the world.
But after the LIDAR are shipped, Lee admits there are no guarantees.
It's a piece of hardware. A pure piece of hardware, that the moment you ship,
you actually don't get to fully control. You can legally control, but you couldn't physically
control where they end up. The only thing that you could do, you're saying, is to
require by contract that your products are not used for military purpose. But beyond that,
there's nothing else that you can do. Your hands are tied. I think this is the nature of any
hardware. Hesai has been fighting the DOD over the blacklist designation since it was put on the
list in 2024. 188 entities are on the list as of June. In court, Hesai said its sensors are
solely for commercial and civilian uses, but the DOD's case tells a different story. I want to go
through some of the evidence that was presented by the DOD.
We asked Lee about what the judge deemed to be the DOD's strongest piece of evidence,
an article from a national security and defense publication.
One piece of evidence that was presented is an article from Defense One,
which suggests a connection between HESI and CETC, which is China Electronics Technology Group
Corporation, a company founded to supply electronics to the People's Liberation Army.
Is there a connection between the two companies?
There isn't a connection.
In the IPO filing for your Shanghai debut,
it lists CETC as the third largest supplier to HESA.
So there is a connection between the two companies.
It's a supplier agreement.
They supply components and that's that.
Yes, that's it.
It's not the other way around.
Correct. I just wanted to make it very clear that we did buy from them,
but it was from the civilian part,
and it was some very fundamental electric.
very fundamental electronics stuff that has nothing to do with the military,
nothing to do with communication, nothing to do with data.
Those parts we bought in the past that we no longer do,
and just for that reason to consider that us as a military company,
I feel like it's not biological.
One of the arguments is that you have facilities one or more
in the military civil fusion zone in Jadying district Shanghai.
That's where you're located.
It turns out, A, there's a, there's a,
there isn't a clear boundary of that zone.
We were like, how come we end up in a civil military zone?
The answer is we didn't.
The zone, we have neighbors like American companies,
like European companies next to us.
So it's almost like, for lack of a better analogy,
just because Pentagon is in Virginia,
you think Virginia is a place full of military.
Anybody operating in the state of Virginia becomes military.
Last year, HESI lost its lawsuit against the DOD and remains on the blacklist.
It's appealing the decision.
Beyond the courtroom, the company is also facing scrutiny.
In July 2025, the Prague Security Studies Institute, a non-profit, non-governmental public policy organization, published a white paper on HESI.
Among the findings, Hesai's LIDAR sensor appeared on a military vehicle during a 23 Chinese military TV program.
I want to show you a couple of pictures.
because security experts will say HESI LIDAR has appeared on military vehicles.
Let me show you this one.
This is from a university competition in 2023.
So, well, it says HESI on it.
So I know that is, even though we don't have direct involvement with military entities,
we shipped probably hundreds of thousands of LIDARs like this,
and the millions more that don't look like this.
So there is a possibility that they end up somewhere that we are completely unaware of in the aftermarket.
Lee says Hesai has no way to communicate with the sensors once they are shipped out,
and the sensors send data directly to the company using them, not to Hesai.
Are you familiar with the Land Unmanned Systems Challenge?
That's the competition that this is part of.
This one?
Or I am unfamiliar with that company?
and we're not involved in that.
This is a competition hosted by the Army Equipment Department
and organized by the Army Research Institute.
It involves military players and military research institutes.
Would that be a competition in which HESI-LIDAR would be applied on a vehicle
that would not be considered a military application?
You have to refer to the official definition of an event
that we are not directly involved of, right?
I understand you see a photo of our product in such a competition, but again, I think it's unfair
or irresponsible for me to comment on that nature of the competition.
Sure.
You know, we did look at the Ministry of Defense website for the description of this particular
competition, and they said the goal is, quote, to thoroughly implement President Shea's
strategic thinking on military, civilian integration and create a new pattern of deep
military civilian integration.
Would it be problematic in your view if your
LiDAR sensors were used in this sort of competition,
which clearly promotes military civilian fusion?
I think a better question is that
whether we design such a sensor to be of such a purpose,
the answer is definitely no, right?
Have we done our part to prevent that from happening?
The answer is yes.
But questions about how and
where Chinese-made-LIDAR sensors are being used come alongside broader concerns about Beijing's
oversight and its potential to access data collected by Chinese companies. The SEC requires
China-based companies to disclose the risk of Chinese government intervention or control. In its
SEC filings, HESI has disclosed that the Chinese government has significant oversight in regulating
our operations and may influence or intervene in our operations at any time.
Singleton says that in part that means HESI can be compelled to share data collected by these LIDAR sensors with the Chinese government.
There is no way in your mind that HESI could be operating as a respectable, dependable company that will not transmit information to the Chinese government.
Whether they want to transmit that information or not isn't a question. It's mandated by law.
Still, Lee says HESI has no data to share.
So where does the data live?
live? Is it on the sensor? It's only on the computer? Does it go anywhere else?
So first, what I do know is it definitely doesn't live in my sensor because we don't have the
capability to store that. Is it physically impossible?
Even if we wanted to do, it's physically impossible to do that because our device just
don't have the memory to store that. Of course, again, it's by design because I don't see why we need that.
Do you have safeguards in place with NVIDIA to make sure that all security concerns are addressed?
One part is how they handle their data, which honestly is their safeguard that we don't get to control.
Or they don't even have to tell us because it's really up to them how to make sure the data is in a safe place.
We asked NVIDIA more than a dozen questions, including whether it was aware that
HESI had been blacklisted and what safeguards are in place to protect the data the sensors
collect. The company did not respond to our questions and instead provided the following statement.
Automakers worldwide demand an open vendor agnostic reference architecture so they can
select components that are best for the markets they serve to build the safest cars.
Our Nvidia Drive Hyperion architecture provides that flexibility, ensuring that American
industry competes worldwide consistent with all regulatory and commercial.
requirements. Neuro-Actonomy, Zooks, and Unitary did not respond to CNBC's request for comment.
In a statement, Kodiak wrote, HESI does not have access to the data from their sensors or any
data produced by Kodiak's autonomous system. A spokesperson for Wabi wrote, we have rigorous data
security protocols in place and thoroughly vet all third-party hardware. There is a race right now
to get autonomous vehicles on the road. Shouldn't we emphasize speed?
at this point?
You know, it's a tale of as old as time with Chinese tech.
We told ourselves the same thing on Huawei.
Chinese telecommunications giant Huawei made equipment widely deployed by U.S. companies
until the Federal Communications Commission forced companies to rip and replace the equipment
from their networks in 2021.
This only after the FCC called Huawei a national security threat because the equipment
could potentially be used for surveillance, and the DOD placed it on the blacklist.
It was the cheapest option, and those systems operated well.
And now the U.S. government and governments around the world are spending tens of billions of dollars
to rip out those compromised Chinese systems and replace them with Western alternatives.
I've seen that movie once.
I don't know why we would need to repeat it again on LIDAR.
Besides Huawei, other Chinese companies have been found to be national security risks,
only after making their way into U.S. homes and businesses.
Shen Zhen-based drone maker DJI and the Wi-Fi router maker TPLink both sold popular consumer goods.
Both were blacklisted by the Pentagon for their ties to the Chinese government, like Hesai.
DJI sued the DOD, but a federal judge ruled there was substantial evidence that DJI contributes to China's defense industrial base.
DJI is appealing the decision.
Ultimately, the FCC banned both DJI and TPLink from selling new device members.
models in the U.S. because their products pose a national security risk.
What's really needed are exhaustive national security reviews of Chinese LIDAR systems to
determine, frankly, are they safe?
Has that happened?
No, it hasn't.
Why not?
I think we're just catching up to the fact that this is one of the latest new emerging
technologies that policymakers have to grapple with.
On Capitol Hill, lawmakers are pushing to address these risks.
Proposed legislation would phase out the use of Chinese-made LIDAR in the United States
and prevent the Chinese Communist Party from exploiting a fast-growing, strategically critical technology.
The sensors and the ability to transmit information is a huge concern.
Republican Congressman John Moolinard of Michigan is chairman of the House Select Committee on China,
which it says is committed to working on a bipartisan basis to build consensus on the threat posed by the Chinese Communist Party.
In May, Mulanar introduced legislation to ban Chinese vehicles from U.S. roads.
We spoke to the CEO and founder of Hesai, and he said that his sensors are not capable of storing data.
There is no data to transfer back to the Chinese Communist Party, even if asked.
Are you satisfied with that response?
I am not.
When you think of connected vehicles, when you think of all this technology, these back doors, we've seen it in robots.
That's another area where China is trying to dominate that.
trying to dominate that technology.
And we've seen backdoors and robots that would transmit information back to Chinese
communist interests.
It seems like a daunting task then to keep up with all the Chinese technology that is making
it into the United States and trying to assess what the national security threat may or may
not be for these technologies.
It's true because so many of these are developing technologies and, you know, AI is, you know,
talked about every day.
has been in a leadership role in this, but we've viewed this as a sort of an open process where
technologies are shared. And ultimately, that works when everybody is abiding by the same rules.
But if you're abiding by the rule that says it's whatever the interest of the Chinese
Communist Party, that's a very different partner relationship.
NVIDIA's CEO says, I want this system to be in every single car.
If I'm NVIDIA's CEO, my job is to sell technology.
make money for my shareholders.
I am thinking I've got to operate within the law,
but I am not focused on national security.
And so that's something we need to be concerned with,
and often legislation takes a while to catch up.
In no proposed legislation or existing laws
prohibit blacklisted companies from being listed on U.S. stock markets
or prevent U.S. shareholders from investing in them.
If a US company wants to buy and incorporate foreign sensors into their autonomous vehicle platforms,
can they check before they are installed to make sure that there is no malware on that device?
If I have my product and the secret source is the IP that I really want to protect from you.
So I try to protect the IP in a way that you cannot fully figure out what is happening on the device.
that also provides me a way to hide some of the things that you should not be potentially aware of.
Experts say the decision to use foreign components often comes down to price.
HESI's LIDAR sensors can cost less than $200 per unit at scale.
By comparison, U.S. LIDAR manufacturer Ava told CNBC that its automotive sensors cost in the few hundreds of dollars per unit.
A 2025 automotive LIDAR report by the YOL group, a market analysis firm,
says Chinese firms like HESI are dominating due to cost, scale, and government support.
Critics will say that you're able to sell your sensors at a low price
or a lower price than a lot of the competitors
because the Chinese government supports you in some way,
whether it be subsidies or preferential treatment, tax breaks, you name it.
Is any of that true?
So see, that's an accusation with...
no evidence. First, that's just imagination. When you see a player being able to build sensors
at a much more affordable level, you just assume that they get help. But why don't you look at the
finest, right? So we did. According to HESI's 2025 annual filing with the SEC, the company received
Chinese government subsidies, preferential tax rates of 15% versus the standard 25%, preferential borrow
rates below benchmark and a tax break, which lets it deduct 200% of its research and development costs.
In a statement of CNBC, HESI wrote,
Governments worldwide commonly offer tax incentives to technology enterprises as a standard measure to stimulate innovation,
adding that these incentives are broadly available to all qualifying companies in China, both domestic and foreign.
Hesai also wrote, no government organization, including the Chinese government,
holds any equity stake in HESI.
We've spoken to LIDAR experts who say that, you know,
the data from a single LIDAR sensor or two LIDAR sensors,
it's not enough because usually for an autonomous vehicle,
it's a myriad of sensors, of cameras that are collecting information,
and together they make that picture.
But the data from one sensor is not that useful.
The technology is evolving so fast that it's difficult to predict
what those risks will be in the future.
Thank you.
