EU’s hodgepodge tech policy exposes members to Chinese vendor risks, says think tank

Depending on Chinese technology for European infrastructure poses risks that not every country takes seriously. So says the Royal United Services Institute (RUSI), which suggests that the EU needs to do better in helping members assess the risk and take appropriate action to safeguard the entire bloc.

The UK-based think tank said in a report today that the EU should develop a new risk assessment framework that applies to all members and strengthens its own powers, without encroaching on members’ rights to set their own national security policies.

It must delicately balance the need to secure the union, while maintaining the flexibility that both allows members to set domestic policies and lawmakers to account for different risk profiles across different sectors. The risks affecting telecoms will not necessarily apply to other sectors in the same way.

Speaking of telecoms, currently there is only the voluntary EU Toolbox for 5G Security framework – voluntary being the operative word here, as only 10 of 27 members have fully implemented it since it launched in January 2020.

On paper, it somewhat sets out to achieve what RUSI is calling for: a harmonized set of standards to mitigate 5G-related security risks affecting member states.

Addressing the frustration over the lack of adoption, the European Commission proposed amendments to the Cyber Security Act (CSA) earlier this year that would allow it to build a list of untrusted vendors that members must preclude from the networks of 18 critical sectors.

If passed, any countries using equipment from designated vendors would be forced to rip and replace it within 36 months. The EC has already indicated that it would suggest Huawei and ZTE be listed, should the amendments pass.

But before the EU gets busy listing vendors it considers high-risk, it first needs to decide what a high-risk vendor even is.

There is still no official definition, nor is it a legal category, and at present, it allows countries to wangle their way around these descriptions to buy the tech they want, bypassing whatever scrutiny may come their way should the CSA amendments come into force.

RUSI’s researchers used Germany, Spain, and the UK as examples of how three countries can treat foreign tech vendors, such as Huawei and ZTE, very differently.

Germany’s most important trading partner is China, a relationship worth €251.8 billion ($284.4 billion) annually, and historically the Bund has opted to preserve these valuable economic ties in favor of reducing supply chain risk. 

Under Chancellor Friedrich Merz, this is slowly changing, although RUSI does not expect to see a material shift in the makeup of Germany’s 5G RAN stack in the near future. Chinese suppliers accounted for an estimated 59 percent of the country’s 5G RAN in 2024.

Chinese equipment accounted for an estimated 32 percent of Spain’s 5G RAN in 2024, although that share is expected to shrink. The debate intensified after last year’s controversy, when Spain awarded Huawei a contract involving the storage of judicial wiretap recordings.

Spain’s past procurement decisions have shown it to often favor the most cost-effective option, and its government does not share the same national security concerns about China as the UK or US, or at least not to the same degree.

The UK, meanwhile, looks set to completely eradicate Chinese technology from its telecoms network by the end of next year, and has bent to the US’ vehement demands that Huawei is bad, bad news for Western geopolitical security.

Real security risks

RUSI stated that concerns about Chinese IT vendors “are well-founded,” and that it is true that the Chinese government can empower authorities to exercise control over companies like Huawei.

This includes providing the state with data on demand, hosting Chinese Communist Party (CCP) representatives, and reporting activity that signals a threat to national security.

There is an additional law that requires tech companies to not just report vulnerabilities to the country’s government within 48 hours of discovery, but also to withhold the same disclosure from China’s overseas counterparts, except for the product vendor.

“This converts China’s private sector security research into a state-controlled pipeline that grants intelligence services privileged early access to exploitable vulnerabilities,” RUSI said.

Factoring in all of this, the country has also demonstrated the willingness and capability to launch cyberattacks against the critical national infrastructure of political adversaries, according to RUSI.

Technical security aside, China’s technological advancements introduce economic risks, too. 

In some cases, its vendors have developed more capable products than equivalents in the EU or US, and sold them at more attractive prices.

This advantage makes it difficult for some countries to justify the extra expense on non-Chinese equipment.

In building a global reliance on its products, China could then introduce “unwelcome dependencies,” or cement itself as a dominant player in crucial supply chains, RUSI noted.

China has shown in recent years that it is willing to exercise this influence, such as when it threatened Germany with “consequences” for the two countries’ economic ties during the heated 5G debate of 2019.

Would a high-risk designation system work?

One of the reasons why the think tank is calling for a more considered risk assessment framework for the EU is that there is no guarantee that what the EC is currently proposing in its CSA amendments will have much of an effect.

Issuing blanket bans on companies, or countries, does not explicitly address the underlying security issues that make products vulnerable to attack.

In other words, even if China were excluded entirely from the EU members’ tech stacks, the other vendors from ‘trusted’ countries have proved that they are unable to deliver penetration-proof software, which would open the door to attacks regardless.

Remember, Salt Typhoon’s high-profile attack on US telco networks took place as recently as 2024.

It should also be said that CSA-esque designations could apply to US companies, as some countries in Europe see US vendors as similarly risky, albeit for different reasons.

Merz’s Germany is concerned about the relationship between the US and EU, for example, and similar concerns about dependence on Chinese technology could easily be applied to vendors in the US, should relations sour.

In Spain, US cloud companies dominate, but anti-US sentiment is stronger than many realize, particularly around surveillance concerns. Those, along with higher prices from some non-Chinese suppliers, have reduced Spain’s appetite for ripping out equipment others deem high-risk.

“One participant even noted that some officials view US legal instruments such as the Patriot Act as creating equivalent sovereignty risks to China’s National Intelligence Law, a narrative that is flawed when exploring the legislation, but politically convenient,” RUSI stated.

The think tank suggested that if it wishes to enact change through policy, the EU must gather “greater economic courage” and a willingness to approach tech procurement as a means to secure its critical infrastructure, rather than “a compliance exercise.” ®

Original source EU’s hodgepodge tech policy exposes members to Chinese vendor risks, says think tank

Back to home