Skip to main content
Geopolitics & DefenseGovernment & Policy

EU's China Tech Policy Gaps Expose Security Risks

Partially completed 5G cell towers stand under a cloudy sky, with officials in the foreground.

“Only 10 of 27 members have fully implemented” the EU’s voluntary 5G security framework since January 2020, a shortfall that the Royal United Services Institute (RUSI) says leaves the bloc exposed to risks from Chinese vendors and calls for a new, union-level approach to risk assessment.

RUSI’s call for a harmonised EU risk-assessment framework

RUSI argues the European Union needs a fresh risk assessment framework that applies to all members and strengthens the Commission’s powers while “not encroaching on members’ rights to set their own national security policies.” The think tank frames the task as a balancing act: secure the union as a whole while preserving flexibility that allows members to reflect different risk profiles across sectors.

RUSI warns that risks in telecoms will not necessarily map neatly onto other sectors, and that blunt measures risk missing the core technical vulnerabilities that make products exploitable.

EU Toolbox for 5G Security: voluntary rules, patchy uptake

The existing EU Toolbox for 5G Security is voluntary; RUSI highlights that only 10 of the bloc’s 27 members have fully implemented it since its launch in January 2020. On paper the toolbox aims to harmonise standards to mitigate 5G-related security risks, but the low uptake underlines the limits of a voluntary, non-binding approach.

Cyber Security Act amendments: a proposed vendor blacklist and 36-month rip-and-replace

Responding to the Toolbox’s limited adoption, the European Commission this year proposed amendments to the Cyber Security Act (CSA) that would let it compile a list of “untrusted vendors” whose equipment members must exclude from the networks of 18 critical sectors. If the amendments pass, countries using equipment from designated vendors would be required to “rip and replace” it within 36 months. The Commission has already indicated it would suggest Huawei and ZTE for that list, should the amendments take effect.

But RUSI flags a foundational problem: there is no official definition of a “high-risk vendor,” it is not a legal category, and the current ambiguity allows countries to “wangle their way around” such descriptions when procuring equipment.

Three country case studies: Germany, Spain and the UK

RUSI uses Germany, Spain and the UK to show how member states treat Chinese vendors differently. Germany’s most important trading partner is China — a bilateral relationship RUSI quantifies at €251.8 billion ($284.4 billion) annually — and historically Berlin has favoured preserving economic ties over reducing supply-chain exposure. Under Chancellor Friedrich Merz, RUSI says that this is changing slowly, but it does not expect a rapid change to Germany’s 5G radio access network (RAN) makeup; Chinese suppliers accounted for an estimated 59 percent of Germany’s 5G RAN in 2024.

Spain’s estimated share of Chinese equipment in its 5G RAN was 32 percent in 2024. RUSI notes Spain often favours cost-effective procurement and has fewer national-security concerns about China than the UK or the US; the debate intensified after Spain awarded Huawei a contract involving storage of judicial wiretap recordings. The UK, by contrast, “looks set to completely eradicate Chinese technology from its telecoms network by the end of next year,” RUSI reports.

Technical and economic risks attributed to Chinese vendors

RUSI states that concerns about Chinese IT vendors “are well-founded.” The think tank details legal and operational mechanisms in China that could enable state access to companies’ data and activities, including laws that empower authorities to demand data, host political party representatives, and require reporting of activity that signals a national-security threat. RUSI quotes a law that requires tech companies to report vulnerabilities to the Chinese government within 48 hours and to withhold the same disclosure from China’s overseas counterparts, “except for the product vendor.”

RUSI writes: “This converts China’s private sector security research into a state-controlled pipeline that grants intelligence services privileged early access to exploitable vulnerabilities.” Factoring these controls together, the think tank also says China has demonstrated willingness and capability to launch cyberattacks against critical national infrastructure of political adversaries.

Beyond technical exposures, RUSI points to economic risks: Chinese vendors sometimes offer more capable products at lower prices, making it harder for states to justify higher-cost non-Chinese alternatives. That commercial edge can create “unwelcome dependencies,” and RUSI cites past instances of China threatening economic “consequences” — for example during the 2019 5G debate — as evidence the country will exercise influence where it can.

What this means for technologists, policymakers, and procurement leaders

  • Technologists and security teams: RUSI’s account focuses attention on disclosure frameworks and on the operational reality that exclusion of particular vendors does not eliminate software vulnerabilities. The think tank notes that non-Chinese vendors have also shown they cannot deliver pen‑proof software, citing Salt Typhoon’s 2024 attack on US telco networks as context.
  • Policymakers and regulators: The Commission’s CSA amendments would centralise authority to designate vendors for 18 critical sectors, but RUSI argues Brussels must first settle a formal definition of “high‑risk vendor” and craft an assessment framework that respects national security prerogatives while securing the single market.
  • Procurement leaders and buyers: RUSI highlights how cost pressure and differing national risk appetites—Spain’s cost-driven choices, Germany’s economic ties to China, and the UK’s eradication plan—drive divergent procurement outcomes across the EU. Those trade-offs will determine how rapidly member states would comply with any future blacklist or rip-and-replace requirement.

RUSI’s central judgment is clear: Brussels needs “greater economic courage” and a workable, consistent framework for judging vendors if the EU hopes to square security with member states’ economic and political choices. The present patchwork—voluntary toolbox adoption, an ambiguous “high‑risk” label, and competing national preferences—leaves open the question RUSI poses implicitly: can a union of 27 reconcile divergent dependencies and impose meaningful, technically grounded protection across critical sectors?

Original story