- An independent audit by US cybersecurity firm OnDefend found no backdoors, no malware, no unauthorized data transfers, and no critical vulnerabilities in DJI’s Air 3S and Matrice 4E.
- The important caveat: DJI commissioned and paid for the audit. OnDefend is independent and published its methodology, but it is not the government review US law called for.
- The real US risk for buyers was never proven spyware – it is regulatory. DJI remains on the FCC’s Covered List, which blocks new models from being authorized for US sale.
- For now, drones you already own keep flying. The open question is whether future DJI gear will be legally importable in the US – not whether your current drone is spying on you.
For years, the single biggest question hanging over a DJI purchase in the United States has not been image quality or flight time – it has been trust. Is the drone phoning home? Could it be grounded or hijacked? A new independent security assessment aims squarely at that anxiety, and for US drone photographers weighing a DJI buy, the findings are worth understanding clearly – including what they do and do not settle.
In late May, DJI released the results of what it calls its most comprehensive independent security assessment to date, conducted by the US cybersecurity firm OnDefend. The headline: no evidence of the covert behavior critics have long alleged. But the regulatory cloud over DJI in the US has not lifted, and that distinction is the whole story.

What the OnDefend Audit Actually Found
OnDefend examined two representative DJI systems: the consumer-focused Air 3S and the enterprise Matrice 4E mapping drone. Across both, the assessment reported no backdoors, no malware, no unauthorized or foreign data transmission, and no pathways that would let a third party hijack the aircraft. It also flagged no critical, high, or medium-risk vulnerabilities.
In plain terms, the audit says the data these drones generate stays where the operator puts it, and the aircraft do not contain hidden mechanisms to siphon information abroad or take remote control. For a working photographer or videographer, that addresses the most common fear directly: that flying a DJI is quietly leaking client locations, flight paths, or imagery somewhere it should not go.
The Catch: DJI Paid for the Audit
One detail deserves to be front and center rather than buried: DJI commissioned and funded this assessment. OnDefend is a legitimate, independent cybersecurity company and it published its methodology, which is far better than a vague self-certification. But a company paying for an audit of its own products is not the same as the government review US law actually called for.
That is the fair way to read it: this is strong, specific, testable evidence that these two models behave as DJI says – not an official all-clear from a US security agency. Skeptics will rightly note the limits of any self-commissioned audit. Supporters will note that no one else has produced contrary technical evidence, only policy concerns.
The Real US Risk Is Regulatory, Not Spyware
Here is the part that matters most for a purchase decision. The pressure on DJI in the US has shifted from “is it spying?” to “is it allowed?” Under Section 1709 of the 2025 NDAA, a US national-security agency was supposed to audit DJI by December 23, 2025. None did. That inaction triggered a fallback: the FCC moved to add foreign-made drones, DJI included, to its Covered List – and as of June 2026, DJI is still on it.
Being on the Covered List does not retroactively ground the drone in your bag. What it does is block new equipment authorizations, meaning future DJI models may not be able to clear the FCC process required to be legally imported and sold in the US. The threat to buyers is not a knock on the door – it is a slowly closing storefront. The audit is DJI’s evidence in that fight, but it does not change the Covered List status on its own.
What It Means If You’re Buying a DJI Drone
Putting the two halves together gives US drone photographers a clearer way to think about it:
- The data-security fear is the weakest reason to avoid DJI right now. On the models tested, the technical case against the drones did not hold up.
- The availability risk is the strongest reason to think twice. Buying into DJI today means buying into a platform whose US future supply, support, and new releases — like the recently announced DJI Avata 360 — are genuinely uncertain.
- Gear you already own keeps working. Nothing here grounds existing drones or disables features overnight.
- If you need a drone for US client work, weigh resale value and long-term support, and look at how rivals like Autel and US-assembled options are positioning themselves against the same rules.
In short: the audit should retire the spyware talking point for anyone still using it as their main objection. It is also worth tracking the other regulatory pressures on drone flight this year, from FAA no-fly enforcement at major events to import policy. The audit should not be mistaken for a green light from regulators – that decision sits with Washington, and it is still open.

Frequently Asked Questions
Does the audit mean DJI drones are safe to use in the US?
From a data-security standpoint, the OnDefend audit found no backdoors or unauthorized data transfers on the Air 3S and Matrice 4E. It does not resolve the separate regulatory question of whether DJI can keep selling new models in the US.
Is my current DJI drone going to stop working?
No. The FCC Covered List restricts new equipment authorizations; it does not retroactively ground or disable drones people already own.
Was this a US government audit?
No. It was commissioned and paid for by DJI and carried out by the independent firm OnDefend. The government review required under the 2025 NDAA was never completed, which is what triggered the FCC Covered List action.
The Bottom Line
The OnDefend assessment is the most concrete technical answer yet to the “is DJI spying?” question, and that answer is no – at least on the two models tested, and with the caveat that DJI footed the bill. For US drone photographers, that reframes the real decision: the risk worth weighing is regulatory, not espionage. Your current drone is fine. Whether you can buy the next one in the US is the question Washington still has not answered.
Featured image and infographic: PhotoWorkout editorial illustration.
Reporting and primary sources on the DJI OnDefend security assessment and US regulatory status.
The Audit
- DJI – Independent security assessment announcement – DJI media center
- Tom’s Hardware – DJI-commissioned audit finds no major vulnerabilities – Independent reporting
- DroneLife – Security assessment released as debate continues – Industry coverage
US Regulatory Status
- Wiley – FCC adds foreign-made UAS to the Covered List – Legal analysis of the FCC action