Buy American Risk Assessment

Warehouse Automation Risk Assessment: Domestic vs. Foreign Vendors

Tariffs, NDAA restrictions, data sovereignty, and vendor stability — the questions every US warehouse operator should ask before committing to an AMR platform.

Many of the most widely marketed AMR vendors in the US are headquartered in China, manufacture their robots overseas, and operate under legal frameworks that may be incompatible with US data security expectations and federal contractor requirements. This doesn't mean they're wrong for every application — but it does mean US buyers need to ask the right questions before signing a multi-year contract and deploying a fleet that's difficult and expensive to replace.

6 Risk Factors to Evaluate Before Choosing a Vendor

High Risk

Software Development & Support Personnel Location

Many foreign-headquartered AMR vendors staff their US presence with a thin layer of domestic account managers while core software development, engineering, and tier-2 technical support remain overseas — in different time zones and under different legal jurisdictions. When a system goes down at 2 a.m. during peak season, the difference between US-based support engineers who know your operation and an offshore ticket queue can mean hours of lost throughput. A vendor with genuine US-based software and support personnel is a materially lower operational risk than one whose technical depth sits overseas.

Ask Your Vendor

"Where are your software engineers located? Where are your tier-1 and tier-2 support teams based? What are your guaranteed response and resolution SLAs for production-impacting issues?"

High Risk

NDAA & Government Contracting Compliance

The National Defense Authorization Act (NDAA) restricts the use of certain Chinese-manufactured telecommunications and surveillance equipment in federal facilities and by federal contractors. As these restrictions expand, any 3PL, manufacturer, or distributor with federal contracts must scrutinize the country of origin of their automation hardware — including cameras, sensors, and networking components embedded in AMRs.

Ask Your Vendor

"Do your robots use any components from entities on the NDAA restricted list? Are your systems compliant with current federal contractor requirements?"

High Risk

Data Security & Connectivity

AMR fleet management systems collect operational data — throughput, layouts, labor patterns, order volumes — and transmit it to cloud platforms. If your vendor's cloud infrastructure is hosted or managed outside the US, or if data is subject to foreign government access laws (such as China's National Intelligence Law), your operational data may be accessible to foreign state actors.

Ask Your Vendor

"Where is fleet data stored? Is it hosted on US-based servers? Is your company subject to foreign data access laws?"

Medium Risk

Vendor Financial Stability & US Presence

Several AMR vendors are growth-stage companies with limited US infrastructure. If your vendor loses funding, is acquired, or exits the US market, you could be left with a fleet of orphaned robots and no support organization. This risk is elevated for vendors whose primary investor base and operations are outside the US.

Ask Your Vendor

"What is your US revenue and headcount? Who provides hardware support if the company is acquired or restructures?"

Medium Risk

Parts, Service & Long-Term Support

When a robot needs a replacement part, how fast can you get it? Vendors that manufacture overseas and maintain thin US parts inventory create support delays that cascade into throughput loss. Political or logistical disruptions — port slowdowns, export controls, trade restrictions — can strand you without replacement hardware.

Ask Your Vendor

"Where are spare parts stocked? What is your guaranteed parts replacement SLA for US customers?"

Low Risk

Tariff Exposure on Foreign-Made Robots

Section 301 tariffs on Chinese-manufactured goods — which include most AMR hardware from vendors headquartered in China — currently run 25–145%. If your vendor manufactures robots in China and ships them to the US, every bot in your fleet carries tariff risk. Any escalation in trade policy directly increases your total cost of ownership mid-contract.

Ask Your Vendor

"Where are the physical robots manufactured? What is the country of origin for the hardware?"

Lower-Risk AMR Vendors Worth Evaluating

The following vendors have North American or Western-aligned headquarters and support infrastructure, representing materially lower tariff, data sovereignty, and cybersecurity risk than Chinese-headquartered alternatives. This list is not exhaustive — always conduct your own due diligence.

VendorWW HQPlatform TypeNotes
LiftiansSCxChange Recommended
Silicon Valley, CA, USAGoods-To-Person, Store Replenishment via Pallet movement, eCommerce Piece/Each Pick, Rack-To-Person, Tote Picking for higher densitySCxChange Hub's recommended platform. US company — software, IP, people, and support are all American. Hardware manufactured in China (common for US tech companies), but as a US entity Liftians is not subject to China's National Intelligence Law and operational data remains under US jurisdiction.
Locus Robotics
Wilmington, MA, USACollaborative picking AMRUS-founded and headquartered. Strong 3PL and fulfillment center track record.
Fetch Robotics (Zebra Technologies)
San Jose, CA / Lincolnshire, IL, USAAutonomous mobile robots, AMR fleet platformAcquired by US-headquartered Zebra Technologies. Enterprise-grade support infrastructure.
6 River Systems (Ocado Group)
Waltham, MA, USA / Hatfield, UKCollaborative fulfillment robots (Chuck)US-founded, now part of UK-based Ocado Group. Robots designed and supported in the US.
Vecna Robotics
Waltham, MA, USAPallet AMR, autonomous forkliftsUS-headquartered. Focus on heavy-payload autonomous material handling.
Seegrid
Pittsburgh, PA, USAVision-guided autonomous vehicles, tow robotsUS-founded and headquartered. Long track record in automotive and manufacturing.
Gideon AI
USAFlexible autonomous material handling — complex AMR operations, autonomous truck loading forkliftUS-based company building autonomous solutions for complex material handling environments. Purpose-built for operations that require adaptability beyond standard goods-to-person or simple navigation.

Chinese AMR Vendors Active in the US Market

The following vendors are headquartered in China and are actively marketing to US warehouse operators. All are subject to China's National Intelligence Law and carry the tariff, data sovereignty, and cybersecurity risks detailed in this assessment.

VendorWW HQPlatform TypeRisk Notes
Geek+ (Geek Plus)Beijing, ChinaGoods-to-person shelving AMR, sorting robotsChina-headquartered and funded. Subject to China's National Intelligence Law. Hardware subject to Section 301 tariffs.
Hai RoboticsShenzhen, ChinaHigh-density ASRS, case-handling AMRChina-headquartered. US operations are a subsidiary of a Chinese entity. Data and software obligations governed by Chinese law.
QuicktronShanghai, ChinaGoods-to-person AMR, shelving and pallet robotsChina-headquartered with ties to Alibaba's logistics network. Full exposure to Chinese data access laws and tariff risk.

Cybersecurity Risks of Chinese-Headquartered AMR Vendors

Beyond tariffs and NDAA compliance, Chinese-headquartered automation vendors present a distinct category of cybersecurity risk that US warehouse operators are only beginning to fully appreciate. These risks are structural — built into the legal and political framework governing Chinese companies — not just theoretical.

China's National Intelligence Law

China's National Intelligence Law (2017) requires any Chinese organization or citizen to 'support, assist, and cooperate with the state intelligence work' when requested. This applies to Chinese companies operating globally — including their US subsidiaries. It means that a Chinese AMR vendor can be compelled by the Chinese government to provide access to data, software, or systems without your knowledge or consent, and without the ability to notify you.

Facility Mapping & Operational Data Collection

AMRs continuously map your facility — every aisle, rack position, dock door, and workflow path. Fleet management systems collect throughput rates, order volumes, pick patterns, and labor efficiency data in real time. For a Chinese-headquartered vendor, this operational intelligence about your facility is potentially accessible to the Chinese state. For manufacturers, defense contractors, pharmaceutical companies, and critical infrastructure operators, this is not a theoretical risk.

Embedded Hardware Components

AMR hardware contains cameras, LiDAR sensors, processors, and network communication chipsets. Several Chinese AMR vendors source components from entities that have been flagged by the FCC, NDAA, or CISA as posing national security risks. Even if the robot itself is benign, embedded components from restricted entities can create compliance violations — particularly for federal contractors.

Software Update Vectors

AMR fleets receive ongoing software updates from vendor cloud platforms. If a vendor's update infrastructure is operated under Chinese jurisdiction — or if a vendor is compelled to push a compromised update — your entire fleet becomes a potential attack surface. This is not a hypothetical: state-sponsored supply chain attacks via software updates have been documented across multiple industries.

CISA & Federal Warnings

The Cybersecurity and Infrastructure Security Agency (CISA) has issued repeated warnings about Chinese-manufactured technology in critical infrastructure, including logistics and supply chain operations. As warehouses become more deeply integrated with national supply chains, the regulatory environment around Chinese-origin automation hardware is expected to tighten — creating retroactive compliance risk for operations that deploy these systems today.

The practical implication: If you operate in a regulated industry, hold federal contracts, handle sensitive supply chain data, or simply want to avoid becoming a retroactive compliance problem, Chinese-headquartered AMR vendors carry risks that are not offset by hardware price differences. SCxChange Hub recommends requesting a formal cybersecurity assessment of any vendor's data architecture before deployment.

The Vendor Risk Assessment Question Set

Use these questions in your RFP or vendor discovery meetings. Require written responses — verbal assurances are not sufficient for procurement decisions of this magnitude.

Country of Origin

  • ?Where are the physical robots manufactured?
  • ?What is the tariff classification of your hardware, and is tariff cost passed to customers?
  • ?Are any components sourced from NDAA-restricted entities?

US Business Presence

  • ?How many US employees do you have in sales, service, and engineering?
  • ?Where is your US service and support organization headquartered?
  • ?What percentage of your global revenue comes from US customers?

Data & Security

  • ?Where is fleet management data hosted?
  • ?Is your cloud infrastructure operated under US jurisdiction?
  • ?Are you subject to any foreign government data access laws?

Financial Stability

  • ?What is your current funding status? Are you profitable?
  • ?Who are your primary investors, and where are they headquartered?
  • ?What happens to US customers' support agreements if the company is acquired?

Long-Term Support

  • ?Where are spare parts inventoried for US customers?
  • ?What is your guaranteed parts replacement SLA?
  • ?How long do you commit to supporting this hardware platform?

The bottom line on vendor risk

A foreign-made AMR is not automatically a bad choice for your operation. But the risk profile is materially different from a domestically manufactured and supported platform — and that risk needs to be priced into your decision. If tariffs increase, if trade restrictions tighten, or if your vendor's US operations shrink, the cost difference that made a foreign vendor attractive at signing can evaporate quickly. SCxChange Hub helps clients make these comparisons with their eyes open.

Want an independent vendor risk review?

SCxChange Hub conducts independent AMR vendor risk assessments — covering tariff exposure, NDAA compliance, data security, and long-term support risk — before you commit to a platform. We have no vendor relationships and no incentive other than protecting your investment.

Talk to an independent supply chain expert

Independent, vendor-neutral advice. No pressure — we respond within 2 business days.

Related Resources

Also explore these related resources from SCxChange Hub