
The Australian Electric Vehicle Association (AEVA) is urging the Federal Government to treat connected vehicles as a national security issue. It warns that foreign-controlled vehicle data and increasingly sophisticated in-car technology could expose sensitive government facilities, critical infrastructure and strategic transport networks.

In a policy submission approved by its board and delivered to the Federal Government this week, AEVA argues Australia has fallen behind other major automotive markets by failing to introduce mandatory cybersecurity requirements for connected vehicles.
The Association says modern vehicles equipped with cabin cameras, microphones and telematics systems are capable of collecting extensive data, effectively turning them into "rolling sensor platforms" that could capture sensitive imagery or operational information near defence sites, critical infrastructure and strategic transport corridors.
According to AEVA, Australia relies on outdated privacy legislation from the 1980s and voluntary manufacturer practices to govern vehicle cybersecurity, unlike Europe and China, where dedicated regulations apply specifically to connected vehicles.
Among its policy recommendations is a formal government assessment of the national security implications of vehicle-generated data, including information that could reveal the location or operation of sensitive government facilities, public charging infrastructure and other strategically important assets.

The submission points to Europe's regulatory model, which links cybersecurity compliance directly to vehicle market access while encouraging on-device data processing wherever possible.
It also references aspects of China's framework, which requires sensitive data – including vehicle movement information and biometric data – to be stored domestically and assessed before leaving the country.
While AEVA stops short of advocating Australia's adoption of China's broader security approach, it argues some of its data governance mechanisms make sense.
Central to the submission is a call for mandatory adoption of the United Nations UNECE R155 and R156 cybersecurity standards.

If implemented, manufacturers would be legally required to incorporate cybersecurity protections into vehicle design, such as separating critical driving systems such as steering and braking from infotainment systems, while also providing ongoing software updates to protect vehicles against emerging cyber threats.
AEVA says these measures are currently voluntary in Australia, leaving compliance largely to manufacturers despite more than 80 automotive brands selling vehicles sourced from around a dozen countries.
AEVA President James Pickering said the Association's recommendations were not directed at manufacturers from any particular country.
“From Europe to USA, to China and the rest of Asia, we are lucky to welcome such an incredible range of electric cars to our shores.
“We are great believers in compliance over country-of-origin and will continue our discussions with government to support consumer choice and protection, while also maintaining national security”.
Whether the Federal Government acts on AEVA's recommendations remains to be seen, but the submission is likely to add to broader debate around connected vehicle security and data sovereignty, if not national security.
The question around whether Australia should introduce mandatory cybersecurity standards is likely to become a more common topic of debate as more high-tech and connected cars enter the market.
