Washington’s Two-Track Response to Cable Sabotage
In 2026, US regulators and lawmakers converged on the same threat model from two different directions: undersea fiber-optic cables. On July 8, 2026, the FCC’s public notice DA-26-684 confirmed the effective date for the remaining provisions of the Commission’s submarine cable landing-license overhaul, a rulemaking the FCC voted to adopt in its first Report and Order on August 7, 2025. The order writes a specific ownership restriction into every US-landing cable license: operators may not sign new or extended capacity-lease or Indefeasible Right of Use arrangements that would let an entity “owned by, controlled by, or subject to the jurisdiction… of a foreign adversary” install, own, or manage the submarine line terminal equipment (SLTE) — the onshore gear that decrypts and routes traffic — on any cable landing on US soil, according to Submarine Networks’ analysis of the FCC’s order. Licensees that meet the disqualifying criteria, or whose cable lands in a country designated a foreign adversary, must now file an annual Foreign Adversary Report disclosing ownership and operational details.
Congress moved on a parallel track. The bipartisan Strategic Subsea Cables Act of 2026 exists as two companion bills: S. 3249, sponsored by Sens. Jeanne Shaheen and James Risch and reported out of the Senate Foreign Relations Committee on February 10, 2026, and H.R. 8069, introduced March 24, 2026 by Reps. Joe Wilson and Gregory Meeks and referred to four House committees. Both versions would let the President sanction foreign individuals who knowingly damage or facilitate damage to undersea cable infrastructure — including blocking US market access and revoking visas — require the State Department to add at least 10 dedicated staff focused on subsea cable security, and create an interagency committee to coordinate federal strategy with cable operators and cut through permitting delays, according to Submarine Networks’ coverage of the bill. The Congressional Budget Office estimates the personnel, committee, and reporting requirements would cost $22 million over the 2026-2031 period. Rep. Wilson has framed the threat in terms of “shadow warfare” — hybrid tactics that stay below the threshold of open conflict.
Why Undersea Cables Became a National Security Flashpoint
The regulatory urgency traces back to a physical reality: submarine cables carry an estimated 95-99% of intercontinental internet traffic, with satellites handling only a small fraction of cross-ocean data. That concentration turned a small number of narrow seabed corridors into single points of failure — and, over the past two years, into targets.
In November 2024, two cables were severed within 24 hours of each other in the Baltic Sea — one linking Finland and Germany, another connecting Sweden and Lithuania — in what is now documented as the 2024 Baltic Sea submarine cable disruptions. A Chinese-flagged bulk carrier was later found to have been operating suspiciously close to both damage sites, and the 2024 Estlink 2 incident that knocked out a Finland-Estonia power and data link the following month deepened Baltic states’ alarm. Taiwan reported a similar pattern in early 2025: multiple cable cuts near Keelung tied to vessels with Chinese crews or ownership links, disrupting the island’s external connectivity. These incidents — none of which involved a declared act of war, and all of which left ambiguous evidence trails — are precisely the “gray zone” scenario the FCC’s ownership rule and the Strategic Subsea Cables Act’s sanctions authority were built to deter and punish.
Advertisement
What Enterprise CTOs and Cloud Architects Should Do
For technology leaders outside government, the 2026 rules are not abstract policy — cable ownership, repair timelines, and landing-station jurisdiction directly shape latency, redundancy, and outage risk for any workload that crosses an ocean.
1. Map your data paths to physical cable routes, not just cloud regions
Most enterprise architecture diagrams stop at the cloud region label (“us-east-1”, “eu-west-1”) and never show which physical cable system carries that traffic. Ask your cloud or carrier partner which submarine systems and landing stations sit between your primary and disaster-recovery regions. If both routes share a single cable corridor — a common blind spot for transatlantic or transpacific pairs — a single cut removes your redundancy along with your primary path. Don’t assume multi-region failover implies multi-cable failover; verify it.
2. Build redundancy across cable systems, not just across data centers
A second data center on the same cable system is not disaster recovery — it’s the same single point of failure with extra hardware. Where the business case justifies it, architect critical cross-continental workloads so failover traffic can route over a geographically distinct cable corridor, even if that means accepting a second carrier relationship and a modest latency penalty. The Baltic and Taiwan Strait incidents both show that repair windows for damaged cables run from days to several weeks, not hours.
3. Track foreign-adversary ownership disclosures before signing new IRU agreements
If your organization leases dedicated capacity (an Indefeasible Right of Use) on a cable landing in the US, the FCC’s new rule directly affects who can supply or manage the terminal equipment on that path. Before signing or renewing an IRU, ask the carrier whether the system or its landing-station operator is subject to the FCC’s Foreign Adversary Annual Report requirement — a disclosure obligation now baked into every affected license. A flagged system is a signal to diversify, not necessarily to exit, but it belongs in your vendor risk register.
4. Treat cable-repair timelines as a board-level business continuity variable
Cable-repair ships are a scarce, specialized global fleet, and a surge in simultaneous incidents — exactly the scenario regulators are now preparing for — could stretch repair capacity thin. Quantify, in your business continuity plan, how many hours or days of degraded connectivity your critical systems can absorb before a cable fault becomes a customer-facing outage, and size your redundant-capacity contracts accordingly rather than assuming “the internet reroutes automatically.”
Where This Fits in the Broader Infrastructure-Security Shift
The FCC’s landing-license rule and the Strategic Subsea Cables Act are not isolated actions — they are the connectivity-layer counterpart to a broader 2025-2026 pattern of governments treating digital infrastructure ownership as a national security question, mirroring earlier fights over 5G equipment vendors and cloud data-localization rules. What makes cables different is the physics: unlike a data center or a telecom tower, a cable route cannot simply be relocated inside a friendly jurisdiction, and a large share of the global system was financed and laid before today’s threat model existed. That mismatch between legacy infrastructure and current risk assessment is why the response is regulatory and diplomatic — ownership disclosure, sanctions, interagency coordination — rather than purely technical. For any organization whose business depends on intercontinental data flow, the practical lesson is the same one utilities learned about power grids: resilience has to be designed in at the physical layer, because the policy layer can deter and punish sabotage, but it cannot instantly reroute a severed cable.
Frequently Asked Questions
What does the FCC’s new submarine cable rule actually restrict?
It bars operators of US-landing submarine cables from signing new or extended capacity-lease agreements that would let a foreign-adversary-controlled entity install, own, or manage the terminal equipment that decrypts and routes traffic onshore. Licensees meeting certain risk criteria must also file an annual disclosure report on ownership and operations. The remaining provisions took effect July 8, 2026.
How does the Strategic Subsea Cables Act change U.S. policy on cable sabotage?
It would give the President authority to sanction — including visa revocation and market access bans — any foreign individual who knowingly damages or facilitates damage to undersea cable infrastructure. It also funds additional State Department diplomatic staff on cable issues and creates an interagency committee to speed up permitting and coordinate threat-sharing with cable operators. As of mid-2026 it exists as companion bills in the Senate (S. 3249) and House (H.R. 8069), neither yet signed into law.
Should enterprises outside the United States care about these American rules?
Yes, if their workloads cross the Atlantic or Pacific. US landing-license rules affect which cable systems and carriers can serve US-bound traffic, which reshapes the redundancy options available globally, not just domestically. Combined with the Baltic Sea and Taiwan Strait sabotage incidents, the underlying lesson — verify physical cable diversity, not just cloud-region diversity — applies to any organization with intercontinental infrastructure dependencies, including in Algeria and North Africa.
Sources & Further Reading
- Strategic Subsea Cables Act of 2026 — S. 3249 bill text (GovInfo)
- Strategic Subsea Cables Act of 2026 — H.R. 8069 (Congress.gov)
- US Introduces Strategic Subsea Cables Act of 2026 — Submarine Networks
- US FCC Adopts Order to Accelerate Submarine Cable Buildout & Security — Submarine Networks
- FCC Public Notice DA-26-684 (July 8, 2026)
- S. 3249, Strategic Subsea Cables Act of 2026 — Congressional Budget Office cost estimate
- Do Submarine Cables Account for Over 99% of Intercontinental Data Traffic? — TeleGeography
- 2024 Baltic Sea submarine cable disruptions — Wikipedia
- 2024 Estlink 2 incident — Wikipedia














