The Australian Strategic Policy Institute published an analysis Friday arguing that Australia has no idea where the data from thousands of Chinese-made drones ends up. Written by Tilla Hoja, a China analyst at the Canberra think tank, the piece calls for a partial ban on Chinese drone companies and a coordinated allied response to what she describes as a data sovereignty gap. The argument lands three years after Australia’s Defence Department grounded its DJI fleet, and it arrives while the Department of Home Affairs runs a drone security consultation that could finally produce actual rules. DroneXL has covered DJI’s data security fight since the first independent audits in 2020, and Hoja’s piece is the sharpest version of the allied case I’ve read this year.
ASPI Builds Its Case on 160,000 Shark Patrol Flights
Hoja anchors her argument in New South Wales’ shark surveillance program, which has logged more than 160,000 flights since 2017, predominantly on DJI aircraft, and just received roughly $22 million (A$34 million) in 2026 funding to expand coverage across 97 beaches along the Australian coastline. The scale of that single program frames her entire concern.
It’s the same operation DroneXL covered in November 2025, when a four-year government study confirmed shark-spotting drones detect more than twice as many sharks as nets and drum lines. The drones work. That was never the question.

Hoja’s point cuts somewhere else. In her reading, every one of those flights is a networked aircraft generating detailed geospatial intelligence over Australian territory, and nobody in Canberra can say with confidence where that data can travel or who can reach the software that moves it.
DJI states that information from users outside mainland China can be stored on servers in the United States or Europe. Hoja argues server location settles very little, because control over firmware, user accounts, and software administration matters as much as where the files sit.
Canberra Grounded DJI in 2023 but Never Wrote the Rules
Australia’s Department of Defence suspended its DJI fleet in May 2023 and ran a six-month audit, after questioning led by Senator James Paterson revealed more than 3,000 DJI devices across at least 38 government departments, yet three years later no regulatory framework governs where drone data travels or who controls the software. That gap is the core of ASPI’s complaint.
The 2023 suspension rippled outward fast. The Australian Federal Police and the Australian Border Force grounded their DJI fleets that year, with the Border Force alone holding 41 DJI aircraft. The Department of Foreign Affairs and Trade followed.
What never followed was policy. Hoja notes the Federal Police has begun transitioning away from DJI and that Home Affairs opened its drone security consultation this year, but Australia still has no rules on data destination or software control for uncrewed aircraft.
Compare that with Washington. Hoja points to DJI’s addition to Commerce and Treasury restriction lists in 2020 and 2021, and to the Pentagon naming it a Chinese military company. The FCC followed in 2025 by placing DJI on its Covered List.
Hoja Wants a Partial Ban and an Allied Drone Bloc
The paper’s recommendations start with a partial ban on Chinese drone companies and extend to aggregated government purchasing, common security standards, multi-year commitments to domestic manufacturers, and coordination with the United States, Japan, Ukraine, and Taiwan on shared testing and trusted drone standards across allied markets. It’s a full industrial policy agenda, not a simple blacklist.
There’s a sovereign capability angle too. Hoja cites Defence orders for 300 drones from Australian firms, with AMSL Aero, Grabba Technologies, and Boresight each supplying 100 aircraft.
That number tells its own story. Three hundred drones barely registers against the 3,000-plus DJI devices the government was flying in 2023, which shows how far domestic supply sits from replacing the incumbent.
Hoja is candid about why DJI won in the first place: it undercut every competitor on price. That admission matters, because a partial ban does not conjure up cheap, capable replacements. Australia’s shark program runs on DJI aircraft because nothing else delivered that capability at that cost.
DJI Points to Audits That Found Nothing Leaving
DJI’s defense rests on documented third-party testing: a 2020 Booz Allen Hamilton audit of three Government Edition drones found no data transmission to DJI, China, or any unexpected party, and FTI Consulting’s 2024 review of the Mavic 3T recorded zero outbound traffic in Local Data Mode. DroneXL reported on that Booz Allen audit in June 2020, and the pattern has held across seven years of independent testing.
DJI also ships Local Data Mode, which lets operators fly with no internet connection at all, and in 2024 it stopped offering US operators the option to sync flight records to its servers.
None of that makes the security question fake. Audits are snapshots: they verify what shipped firmware did on the day of testing, and they cannot guarantee what a future update does. Hoja’s software control argument lives in exactly that gap, and it deserves a real answer rather than a marketing page.
My read after covering this fight since 2020 stays consistent. The DJI bans have always been political instruments first and technical judgments second, because the audit record keeps landing in DJI’s favor. The trust deficit persists anyway, since trust in a closed system is always borrowed, never owned.
DroneXL’s Take
This whole fight is about the marriage of hardware and software, and divorce is an option nobody’s offering.
I keep waiting for someone to build a Linux for drones. The punchline is that it already exists. PX4 lives under the Linux Foundation through the Dronecode Foundation, ArduPilot has been open source for well over a decade, and companies like Auterion built real government businesses productizing PX4 for enterprise fleets.
What doesn’t exist is DJI hardware that runs any of it. DJI’s aircraft are a closed system, flight software and hardware welded together at the factory, and no major manufacturer today sells a flagship camera drone that lets you install the flight stack you trust. You buy the aircraft, and the software comes bonded to it.
Picture the alternative. DJI keeps building what nobody matches, the gimbals, the cameras, the transmission, the obstacle sensing, and sells a version where the buyer installs PX4 or ArduPilot and points the telemetry wherever they want. Every concern Hoja raises about firmware control and data destination stops being DJI’s problem and becomes the operator’s choice, the same way it works on any computer running an operating system you picked yourself.
Would DJI ever do it? That’s an open question, not a prediction, and nothing in DJI’s public statements points that way today. But watch the Home Affairs consultation: if Canberra writes rules around software control instead of country of origin, decoupled hardware becomes the one architecture that satisfies both the security hawks and the pilots who just want the best camera in the sky.
Right now, nobody sells that drone. The first company that does gets my money. Sources:
- ASPI The Strategist: https://www.aspistrategist.org.au/australia-is-flying-blind-on-chinese-drone-data/
- Australian Aviation: https://australianaviation.com.au/2023/05/border-force-joins-defence-in-grounding-china-linked-drones/
- Senator James Paterson: https://www.senatorpaterson.com.au/news/senator-hold-the-drones
- DJI Trust Center: https://www.dji.com/trust-center/resource/security-audits-certification