← Back to the feed

RUSI warns EU procurement gaps leave members exposed to Chinese technology risks

The Register ·

The Royal United Services Institute (RUSI) has published a report warning that the European Union's fragmented approach to technology procurement exposes member states to security risks posed by Chinese vendors such as Huawei and ZTE. The think tank argues that whilst individual countries assess these risks differently, the EU needs a unified framework to maintain security across the entire bloc without trampling on national sovereignty.

The disparities are stark: Germany relies on Chinese suppliers for 59 per cent of its 5G infrastructure, driven partly by €251.8 billion in annual trade with China, whilst Spain's share stands at 32 per cent and the UK plans to eliminate Chinese equipment entirely by the end of 2027. Only ten of 27 EU members have fully implemented the voluntary EU Toolbox for 5G Security since its launch in January 2020. The European Commission has proposed amendments to the Cyber Security Act that would create a list of untrusted vendors member states must exclude, forcing any existing equipment to be removed within 36 months—though a formal definition of "high-risk vendor" remains absent.

  • EU countries treat Chinese tech vendors inconsistently, creating bloc-wide security risks.
  • Germany hosts 59% Chinese 5G equipment due to trade ties; UK plans elimination.
  • New EU framework and vendor-blacklist proposals aim to strengthen harmonised security standards.

New here? Start with this

The European Union faces a security concern about technology supplied by Chinese companies such as Huawei and ZTE. Different member states currently rely on these suppliers to varying degrees and each has its own approach to managing the risks, leaving some countries more exposed to potential security vulnerabilities than others.

Such fragmentation is problematic because technology failures or breaches in one country can affect neighbouring nations and the entire continent. The Royal United Services Institute (RUSI), a respected research organisation, has warned that the EU needs a unified framework for assessing and managing these technology risks rather than leaving each country to decide independently which vendors to trust.

The European Commission has proposed creating a list of technology vendors too risky for any member state to use, requiring countries to remove existing equipment from those suppliers within three years. However, the EU has not yet agreed on a clear definition of what makes a vendor "high-risk," making it difficult to create an effective policy that all member states can follow.

Americas Government Politics World

Read the full article at the source →

Originally published by The Register as “EU’s hodgepodge tech policy exposes members to Chinese vendor risks, says think tank”.