RegImpact
fccproposed· Published 3/11/2022

Secure Internet Routing

In this document, the Federal Communications Commission (FCC or the Commission) seeks comment on vulnerabilities threatening the security and integrity of the Border Gateway Protocol (BGP), which is central to the Internet's global routing system, its impact on the transmission of data from email, e-commerce, and bank transactions to interconnected Voice-over Internet Protocol (VoIP) and 9-1-1 calls, and how best to address them.

What this rule actually says

The FCC is concerned that the internet's routing system (BGP—the protocol that directs data packets across the global internet) has security vulnerabilities. Bad actors could theoretically hijack or intercept internet traffic, affecting everything from emails to bank transactions to VoIP calls. The FCC is asking for input on whether new rules should require internet service providers and network operators to adopt better security practices to protect this core infrastructure.

Who it applies to

  • If you operate your own internet service provider or backbone network infrastructure: this applies to you.
  • If you build an AI product (medical scribe, hiring assistant, chatbot) that runs on cloud servers you lease from AWS, Google Cloud, or Azure: this does not directly apply to you.
  • If you operate the physical network hardware or manage BGP routing tables yourself: this applies to you.
  • Jurisdictional scope: primarily US-based network operators and ISPs; international implications possible but not the immediate focus.
  • Data scope: this rule is about network infrastructure security, not about user data privacy or AI model governance—those are separate concerns.
  • User data in/out of scope: the rule protects the pipes carrying all data (including user data), but it doesn't regulate what data you collect or how you use it.

What founders need to do

  1. Do a 30-minute self-assessment (~30 minutes): Does your company own or operate internet routing infrastructure? If the answer is no, stop here. If yes, proceed.
  1. Monitor FCC's open comment period (ongoing, low effort): Check the FCC website for the formal comment deadline on this proposed rule. If it applies to you, plan to file comments or engage through industry associations (ISP coalitions, networking groups).
  1. If it applies, audit your BGP security practices (1–2 weeks): Work with your network ops team to document current Route Origin Validation (ROV) and RPKI (Resource Public Key Infrastructure) adoption. Most major ISPs are already moving here.
  1. Plan compliance timeline (low effort until rule finalizes): Once finalized, the FCC typically gives 12–24 months to implement. Budget engineering time accordingly if you operate backbone infrastructure.

Bottom line

Ignore this unless you operate internet service provider or network backbone infrastructure; if you do, monitor the FCC's progress and prepare to implement BGP security hardening within 1–2 years of finalization.