
RUSI: EU's fragmented tech policy leaves member states exposed to Chinese vendor risks
The UK-based think tank RUSI says the EU's fragmented tech policy exposes member states to risks from Chinese vendors, and calls for a bloc-wide risk-assessment framework that does not encroach on national security autonomy.
The UK-based think tank RUSI published a report on October 1: the EU's fragmented tech policy leaves member states exposed to risks from Chinese vendors.
RUSI (the Royal United Services Institute) wants a single EU risk-assessment framework covering all members, without encroaching on their right to set national security policy.
Voluntary toolbox, slow adoption
In telecoms, only the voluntary EU Toolbox for 5G Security is in place: since January 2020, just 10 of the EU's 27 member states have fully implemented it.
That weak take-up led the European Commission to propose Cyber Security Act (CSA) amendments earlier this year: a list of untrusted vendors members must exclude from 18 critical sectors and replace within 36 months, with Huawei and ZTE the likely candidates. Yet there is still no official definition of a "high-risk vendor".
Germany, Spain and the UK
For Germany, China is its most important trading partner, with annual trade worth €251.8 billion ($284.4 billion). Under Chancellor Friedrich Merz the stance is slowly shifting, but RUSI sees no material change soon: Chinese suppliers were an estimated 59 percent of Germany's 5G RAN in 2024.
In Spain, Chinese equipment was an estimated 32 percent of 5G RAN in 2024 and is expected to shrink. Debate flared after Spain gave Huawei a contract to store judicial wiretap recordings. Madrid picks the cheapest option and does not share the UK or US level of concern about China.
The UK will eradicate Chinese technology from its telecoms network by the end of next year, having bowed to US demands to treat Huawei as a threat.
Real risks, and the limits of bans
RUSI calls concerns about Chinese vendors "well-founded": Chinese law lets the state demand data from companies like Huawei, place party representatives inside them and receive reports on national-security threats, while another rule requires firms to report vulnerabilities to the government within 48 hours, turning private security research into a state-controlled pipeline.
The report adds that China has both the willingness and the capability to launch cyberattacks on adversaries' critical infrastructure, and that cheap, capable Chinese products create economic dependencies; in 2019 Beijing threatened Germany with "consequences" during the 5G debate.
Blanket bans do not fix the weaknesses that make products vulnerable, RUSI warns: even with China excluded, "trusted" vendors have not shipped penetration-proof software, as the 2024 Salt Typhoon attacks on US networks showed.
CSA-style designations could also hit US companies, since some European countries view US vendors as similarly risky.
The EU needs "greater economic courage" and must treat tech procurement as a way to secure critical infrastructure, not a compliance exercise, RUSI concludes.
SiTech — AI-powered web development
We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.