The Royal United Services Institute (RUSI), a UK-based think tank, has issued a report highlighting that the European Union's current approach to technology procurement leaves member states vulnerable to risks associated with Chinese vendors. RUSI advocates for a new, comprehensive risk assessment framework applicable across all EU members to strengthen the bloc's collective security without infringing on national security policies.
Currently, the EU's primary mechanism for addressing 5G security, the EU Toolbox for 5G Security, remains voluntary. Since its introduction in January 2020, only 10 of 27 member states have fully implemented it. To address this, the European Commission (EC) proposed amendments to the Cyber Security Act (CSA) earlier this year. These amendments would empower the EC to compile a list of untrusted vendors, whose equipment would then be subject to a mandatory "rip and replace" policy within 36 months for 18 critical sectors. The EC has indicated that Huawei and ZTE would likely be among the first vendors suggested for this list if the amendments pass.
A key challenge, however, is the absence of an official definition or legal category for a "high-risk vendor," allowing individual countries to bypass scrutiny when procuring technology. RUSI's report illustrates this disparity by examining Germany, Spain, and the UK. Germany, with China as its largest trading partner (a relationship valued at €251.8 billion annually), has historically prioritized economic ties. In 2024, Chinese suppliers constituted an estimated 59 percent of Germany’s 5G RAN. While a shift is anticipated under Chancellor Friedrich Merz, RUSI does not foresee immediate significant changes.
Spain's 5G RAN saw an estimated 32 percent share from Chinese equipment in 2024, a figure expected to decrease. Spain's procurement decisions have often favored cost-effectiveness, and its government does not share the same level of national security concerns regarding China as the UK or US. A recent controversy involved Huawei securing a contract for storing judicial wiretap recordings. In contrast, the UK is on track to eliminate Chinese technology from its telecoms network by the end of next year, largely influenced by US concerns regarding Huawei.
RUSI confirms that concerns about Chinese IT vendors are "well-founded." The Chinese government possesses legal authority to compel companies like Huawei to provide data on demand, host Chinese Communist Party representatives, and report activities deemed a threat to national security. Furthermore, a Chinese law mandates that tech companies report vulnerabilities to the government within 48 hours of discovery, while prohibiting disclosure to overseas counterparts, except for the product vendor itself. RUSI states this effectively transforms China's private sector security research into a state-controlled pipeline, granting intelligence services early access to exploitable vulnerabilities.
Beyond technical security, China's technological advancements introduce economic risks. Chinese vendors often offer more capable products at lower prices than their EU or US counterparts, creating a global reliance that could lead to "unwelcome dependencies" or cement China's dominance in critical supply chains. China has previously demonstrated a willingness to leverage this influence, such as threatening Germany with "consequences" for economic ties during the 2019 5G debate.
However, RUSI questions the efficacy of the EC's proposed CSA amendments, arguing that blanket bans do not inherently address underlying security vulnerabilities. Even without Chinese vendors, products from "trusted" countries have demonstrated vulnerabilities, as evidenced by the 2024 Salt Typhoon attack on US telco networks.
RUSI also notes that a CSA-style designation system could potentially apply to US companies. Some European countries view US vendors as similarly risky, albeit for different reasons. Germany, for instance, expresses concerns about its relationship with the US, and similar dependencies on US technology could arise if relations sour. In Spain, where US cloud companies are dominant, anti-US sentiment exists, particularly regarding surveillance concerns. Some officials reportedly view US legal instruments like the Patriot Act as creating sovereignty risks comparable to China’s National Intelligence Law, a narrative RUSI describes as politically convenient but flawed upon legal examination.
To enact meaningful change, RUSI suggests the EU must cultivate "greater economic courage" and approach tech procurement as a means to secure critical infrastructure, rather than merely a compliance exercise.






