Geopolitics and IT Security Cybersecurity as a Tool of Trade Policy

By Henrik Bork | Translated by AI 8 min Reading Time

The U.S., China, and, increasingly, Europe are justifying restrictions on technology providers by citing security risks. However, origin alone says little about the actual vulnerability of hardware and networks. At the same time, there is a risk of high costs and new dependencies.

Securing digital infrastructure is not just about technical risks, but increasingly also about origin, supply chains, and political requirements.(Image: Dall-E / AI-generated)
Securing digital infrastructure is not just about technical risks, but increasingly also about origin, supply chains, and political requirements.
(Image: Dall-E / AI-generated)

Cybersecurity has moved to the forefront of geopolitics. When U.S. President Donald Trump and his Chinese counterpart Xi Jinping meet in Washington during this week in late September 2026, the security of artificial intelligence will also be on the agenda. In the run-up to the meeting, the U.S. has proposed, among other things, a bilateral mechanism through which both sides could share information about serious AI security incidents. What was once an obscure technological topic for a handful of experts has become a political issue that influences a myriad of economic, trade, and alliance-related decisions.

This also raises the question of how AI can be used in cyberattacks and how nations will coordinate their responses to serious AI incidents. Cybersecurity, which used to be primarily the domain of specialized IT and security teams, is increasingly becoming a battle of one AI against another.

This threat is real. In February 2024, U.S. agencies—CISA, the NSA, and the FBI—reported on a group called Volt Typhoon. According to the agencies, this group had infiltrated the networks of American energy providers, water utilities, telecommunications companies, and other critical infrastructure operators. In some cases, the attackers had been operating there for at least five years. In August 2025, security agencies from 13 countries, including Germany, issued a joint warning regarding activities attributed, among others, to Salt Typhoon, which primarily targeted telecommunications infrastructure worldwide.

A few weeks ago, another warning followed. The NSA, FBI, and the Cyber National Mission Force issued a report about a group called QTFY. It is alleged to have been attacking U.S. government agencies and critical infrastructure for years. According to information from U.S. authorities—which was later corrected—facilities belonging to the U.S. Department of Energy, among others, had been successfully compromised; in the case of several other agencies mentioned, however, they were merely targets of attacks, with no evidence of successful breaches.

And It's All About Chips Again

Washington is also using national security arguments to restrict chip exports to China. Cybersecurity, however, is only one aspect of this. The U.S. government justifies its export controls primarily by citing the need to limit China’s access to advanced semiconductors and manufacturing technology for military applications, artificial intelligence, and high-performance computers. For its part, China is fighting back with its own security reviews of American technology companies.

It is often only a small step from labeling something as a threat to implementing trade policy. On January 3, 2025, the U.S. Department of the Treasury imposed sanctions on the Beijing-based company Integrity Technology Group. The allegation was that the company had supported the Flax Typhoon hacking group by providing infrastructure that had been used in attacks on U.S. targets. The rationale in this case was specific.

Fourteen months later, the U.S. regulatory agency, the FCC, added all routers for home use manufactured abroad to its so-called “Covered List.” For new router models, the fact that they are manufactured outside the U.S. is thus initially sufficient as a criterion. However, models that have already been approved may still be imported, sold, and used; furthermore, an exemption may be granted following a security review.

Beijing had long advocated for dialogue, but has since begun to rely on such measures as well. In 2023, the Chinese Cyberspace Administration (CAC) announced that products from the U.S. memory manufacturer Micron had failed a security review. Operators of critical information infrastructure were subsequently prohibited from procuring these products. The agency did not publicly disclose the specific security flaws that had been found in detail.

Subscribe to the newsletter now

Don't Miss out on Our Best Content

By clicking on „Subscribe to Newsletter“ I agree to the processing and use of my data according to the consent form (please expand for details) and accept the Terms of Use. For more information, please see our Privacy Policy. The consent declaration relates, among other things, to the sending of editorial newsletters by email and to data matching for marketing purposes with selected advertising partners (e.g., LinkedIn, Google, Meta)

Unfold for details of your consent

In January 2026, according to a Reuters investigation, Chinese authorities instructed domestic companies to stop using security software from more than a dozen U.S. and Israeli vendors. However, there is no publicly available Chinese regulation on this matter; Reuters cited people familiar with the matter. In addition, an official cybersecurity review by the CAC of Palo Alto Networks products has been underway since August 6, 2026.

And What About the Hardware?

For an issue of such great economic importance, the public debate on cybersecurity and related government decisions is often conducted in a surprisingly sweeping manner. In any case, equating the origin of hardware with a specific security risk is too simplistic. Based on known attack patterns, it is not clear why Chinese hackers would need Chinese electronics to infiltrate corporate servers or military networks in the U.S. or Europe.

In fact, state-sponsored cyberattacks often exploit vulnerabilities, misconfigurations, or stolen credentials in products from a wide variety of sources. Salt Typhoon is a prime example of this. Among other things, the attackers compromised Cisco networking equipment in U.S. telecommunications networks. In the cases Cisco Talos investigated itself, it found evidence in only one instance that an older Cisco vulnerability had likely been exploited. In the remaining cases investigated, the attackers gained access using valid, previously compromised credentials. The devices’ patch status, configuration, and credential management thus played a decisive role.

At the same time, the British testing agency HCSEC spent years examining Huawei’s products and source code. In the process, the auditors found significant and, in some cases, systemic weaknesses in software development and engineering. However, these investigations did not provide evidence of intentionally built-in “backdoors.” The British NCSC generally assessed the risk of hidden malicious functions as “moderate”; in the case of Huawei, it had been reduced from “high” to “moderate” due to the company’s specific audit and control measures.

A Convenient Chain of Reasoning

General threat scenarios and a manufacturer’s country of origin can now quickly become a factor in economic competition. One example is the European Commission’s proposed revision of the Cybersecurity Act (CSA). The draft establishes a mechanism to classify vendors from third countries as high-risk vendors following a risk assessment and to exclude their components from certain critical ICT systems or have them gradually removed. However, China, Huawei, or ZTE are not mentioned in the text of the regulation itself; formally, the mechanism is designed to be technology- and vendor-neutral.

There is ongoing debate over the extent to which such measures will enhance cybersecurity in Europe and what costs they will entail. According to industry estimates, the planned revision of the Cybersecurity Act could result in up to 40 billion euros ($45.6 billion) in compliance costs for European telecommunications companies. This figure comes from an open letter from European telecommunications companies dated September 15, 2026, published by the industry association Connect Europe, and is therefore not a cost estimate from the European Commission.

The European Commission’s proposal covers more than just telecommunications networks. It is intended to secure critical ICT supply chains in the sectors covered by NIS2 and includes, for example, connected vehicles, energy and water systems, cloud services, medical technology, surveillance technology, aerospace, and semiconductors. If providers are classified as high-risk under the proposed procedure, requirements for the phased replacement of certain critical ICT components may also follow.

The signatories of the open letter—including Telekom CEO Tim Höttges and Telefónica CEO Marc Murtra—are particularly opposed to a blanket “rip-out” of technology that has already been installed. They argue that the capital required for such a replacement would then not be available for the expansion of European telecommunications networks and other digital infrastructure.

“The reforms must be coherent. While the Digital Networks Act (DNA) is intended to boost investment, the CSA could drain capital from the sector,” according to the argument put forward by European telecom executives. The German telecommunications industry is also advocating for a risk-based approach, in which bans or the replacement of components should remain a last resort. That sounds quite reasonable.

At the same time, the question arises as to what weight technical security assessments will carry in the future relative to geopolitical and industrial policy criteria. Experts from the Federal Office for Information Security (BSI) in Bonn have been conducting technical assessments for decades to improve the security of critical infrastructure, such as water treatment plants, banks, hospitals, and telecommunications networks. In confidential discussions, experts reportedly expressed concern that decisions for or against certain suppliers are increasingly being made at the political level, and that technical evaluations could lose their weight in the process.

"Tit for Tat"

The political arena is constantly churning out new buzzwords that are picked up by lobbyists and diplomats. The buzzword of the moment is “reciprocity,” which is supposedly lacking. A common argument is that China denies Western manufacturers access to the Chinese market; in return, Europe must restrict access to Chinese products and services more strictly. There are undoubtedly difficulties for European and American companies in winning public tenders in China. However, one cannot generalize from this to conclude that they are completely excluded.

One example is China Mobile’s procurement of 5G wireless technology for 2026 and 2027. The list of shortlisted candidates was published in June. Among the five candidates for each of the two frequency bands are, in addition to Chinese providers, Ericsson China and Nokia Communications Shanghai.

In China Mobile’s previous procurement of 5G core equipment for wireless networks in 2025 and 2026—which included a total of 397,500 base stations—Nokia Shanghai Bell and Ericsson also secured contracts. Just how large these shares were compared to those of their Chinese competitors is another question. However, there is certainly no question of Ericsson or Nokia being completely excluded from these China Mobile tenders.

In Europe, Nokia and Ericsson are often portrayed as European alternatives to Chinese providers, intended to help reduce technological dependencies. At the same time, both companies are deeply integrated into international technology and supply chains. For example, Nokia is developing AI-RAN technology in collaboration with Nvidia, while Ericsson has acquired Vonage, a U.S.-based communications platform; both companies also have extensive operations in the United States.

It cannot be readily concluded from this that Nokia or Ericsson are “under American influence.” However, it does show that even in the case of European providers, it is hardly possible to speak of a supply chain that is entirely European and independent of non-European technology partners. This raises the question of what role manufacturer diversity should play in technological sovereignty.

Although the politicization of cybersecurity is an international game, there is an important difference between Washington, Beijing, and Brussels. Donald Trump and Xi Jinping have a direct line of communication and are currently discussing, among other things, possible procedures for dealing with serious AI security incidents. Europe is not at the table during these bilateral talks.

The European debate is therefore not just about the potential costs running into the billions mentioned by Tim Höttges and other telecommunications executives—costs that, from the industry’s perspective, could be better spent on fiber-optic networks, 5G, 6G, and other digital infrastructure. It is also about the question of whether excluding individual providers actually reduces dependencies—or merely shifts them to a smaller number of remaining suppliers. It is precisely this careful consideration that should not be replaced by blanket assumptions about origin in the field of cybersecurity.