A UK-based think tank, the Royal United Services Institute (RUSI), has highlighted that the European Union's current approach to technology policy exposes member states to risks associated with Chinese vendors. In a report published today, RUSI recommended that the EU develop a new risk assessment framework to help members evaluate and address these risks across the bloc.
The report notes that the existing EU Toolbox for 5G Security framework, launched in January 2020, is voluntary, with only 10 out of 27 member states having fully implemented it. Earlier this year, the European Commission proposed amendments to the Cyber Security Act (CSA) that would enable it to create a list of untrusted vendors, whose equipment would be precluded from 18 critical sectors. If these amendments pass, countries using designated vendors would be required to replace their equipment within 36 months, with the EC indicating it would suggest Huawei and ZTE for this list.
RUSI's research used Germany, Spain, and the UK as examples of differing approaches to foreign tech vendors like Huawei and ZTE. Germany, whose most important trading partner is China, has historically prioritised economic ties, though this is reportedly changing under Chancellor Friedrich Merz. Chinese suppliers accounted for an estimated 59 percent of Germany's 5G RAN in 2024. Spain's 5G RAN had an estimated 32 percent Chinese equipment in 2024, a share expected to decrease. The UK aims to remove Chinese technology from its telecoms network by the end of next year.
RUSI stated that concerns about Chinese IT vendors are "well-founded," citing the Chinese government's ability to control companies like Huawei, including requiring data on demand and reporting national security threats. The think tank also noted that China has demonstrated the willingness and capability to launch cyberattacks against critical national infrastructure.