The bill strengthens federal cybersecurity by banning risky apps and creating a centralized governance process, but it risks disrupting federal workflows, imposing recurring administrative costs, and potentially overbanning legitimate commercial apps.
Federal employees and national-security stakeholders: banning risky apps on government devices reduces the chance of data exfiltration and supply-chain cyber risks to federal systems.
Federal agencies and employees: centralized OMB guidance (updated every 180 days) creates a consistent, government-wide process for identifying, removing, and managing risky applications.
Federal employees and agency researchers/intelligence teams: agency-level exception rules with mandated cybersecurity safeguards permit controlled research or intelligence uses while requiring documented risk mitigation.
Federal employees: losing access to widely used apps on government devices may disrupt workflows, reduce productivity, and force use of alternate software or procedures.
Federal employees, tech workers, and taxpayers: a broad definition targeting apps with PRC ties could overreach and ban legitimate commercial apps, complicating procurement and international collaboration.
Federal agencies and taxpayers: implementing app removals, exception processes, and frequent OMB updates will create administrative burdens and recurring costs for agencies and taxpayers.
Based on analysis of 2 sections of legislative text.
Bars covered Chinese-controlled applications from being installed or used on federal devices, requires OMB/agency guidance, and mandates removal within set deadlines.
Official title: To prohibit the download or use of a Chinese application on any Federal Government device.
Introduced January 15, 2026 by Jefferson Shreve · Last progress January 15, 2026
Prohibits downloading or using specified "covered applications" on any federal government device, unless an agency head approves a narrow exception for lawful research or intelligence functions. It requires OMB (with DHS, DoD, and DNI consultation) to publish and regularly update a process for identifying covered apps, directs agencies to remove identified apps from federal devices within 60 days, and requires agency guidance on exception procedures and cybersecurity safeguards within set deadlines.