Think Tank Warns EU's Patchwork Tech Rules Leave Door Open to Risky Vendors
The Royal United Services Institute (RUSI) has warned that the European Union's fragmented approach to assessing technology vendor risk is leaving member states exposed, particularly where Chinese suppliers are involved. In a new report, the think tank calls for a unified risk assessment framework that applies across all EU members, while still allowing countries flexibility to set their own national security policies.
Currently, the EU relies on a voluntary 5G Security Toolbox introduced in 2020, but only 10 of 27 member states have fully implemented it. In response, the European Commission has proposed amendments to the Cyber Security Act that would let it designate 'untrusted vendors' to be excluded from networks across 18 critical sectors, with a 36 month removal deadline for any existing equipment. Huawei and ZTE have already been flagged as likely candidates for this list.
However, RUSI points out a key gap: there is still no official, legally binding definition of what makes a vendor 'high-risk.' This ambiguity allows countries to interpret the rules differently, as seen in varying approaches taken by Germany, Spain and the UK toward vendors like Huawei and ZTE. Without clearer standards, the report suggests, the EU risks uneven protection across the bloc even if new vendor restrictions are adopted.