IMO the solution is antitrust enforcement that considers hardware, software, and services all different products/markets, and prohibits anticompetitive tying between them. Having a piece of hardware should not force you to use specific software to operate it. And choosing specific software to control your robot vacuum should not force you to use specific network services (for mapping or whatever else the software developer leaves out). Rather there should be competitive markets for software onto existing hardware, and for network services to provide features to that software. If a company develops software for a piece of hardware they manufacture, then every bit of documentation used to write that software should be made publicly available so that competing software can also create an implementation.

Then, casual auditing of the hardware/software would suffice to make sure they weren't bundling other types of product. And the main concern would boil down to data collection by Chinese services - for which the US Software industry could step in with alternatives. And then rather than merely banning "Chinese services", a US GDPR would go a long way towards setting general rules to alleviate the specific concerns regarding data collection / abuse. It would then be up to Chinese companies whether to comply or not.

We've been missing these general approaches because our domestic surveillance industry wants to continue abusing the market, and has stymied any such regulation that would encourage competition with them. But these are the types of general approaches we actually need, rather than simplistic import bans and other ham-fisted protectionism.