Chinese ZPMC cranes supplied to American ports contained cellular modems that could bypass firewalls, gather information, and disrupt cargo handling. Chinese Yutong buses sold to Oslo came with connected battery and power controls. The Norwegian city’s public transport authority, Ruter, warned that, in theory, the buses “can be stopped or rendered inoperable by the manufacturer.”
Chinese connected vehicles carry cameras, microphones, and location sensors that gather data. Chinese-supplied apps, such as Hikvision’s Hik-Connect, send phone and SIM card identifiers to Chinese servers.
The West long has identified Chinese-supplied telecoms as a danger. It must now wake up and confront the danger of a vast array of Chinese products, ranging from cranes to cameras. Allies need to avoid instituting counterproductive sovereignty requirements. They should build a shared response that limits exposure by private purchase of Chinese consumer goods.
Without action, innocuous looking products will flood the market. A family buys a solar inverter. It looks like an ordinary private purchase, made by a family that chose Chinese because the product was good and affordable. The problem arises if the manufacturer can change the operation of thousands of these devices and threaten the grid.
Can the grid operator prevent such switching, without the manufacturer’s permission? If it can, there is no reason to ban the devices. If switching off thousands of inverters can cause a blackout, China holds dangerous digital leverage.
This threat is not theoretical. The International Energy Agency warns of blackouts from malicious software updates to inverters. Whoever controls enough connected capacity could spread disruption across borders before grid operators restore control. Chinese Deye inverters have stopped working, with warnings that US use was prohibited. China supplies more than 80% of inverter shipments to Europe.
Similarly, data from thousands of privately owned connected cars and cameras, combined through the cloud, can reveal infrastructure data, military supply routes, and activity around military sites. If a Chinese camera or microphone is placed near a military gate, it can capture conversations outside the frame. With cloud or support access, China could combine video, sound, locations, and timestamps from cameras and vehicles, identifying visitors, military supply routes, and daily routines.
A single, seemingly minor private purchase of a connected vehicle, camera, or home solar inverter suddenly becomes a major national security risk.
Alongside worries about Chinese tech, Europeans are questioning the dangers of US technology. An authorized CrowdStrike update for Windows disrupted critical services across industries and borders. The European Commission’s proposed Cloud and AI Development Act rightly addresses concentration, continuity, and foreign legal reach.
But the example of connected cars shows why the US and China are not the same. For a specific commitment by a US supplier on data use, an enforceable contract and an independent audit may be sufficient because they are backed by effective judicial protection, democratic laws, and independent oversight of intelligence services. There is a way to verify the manufacturer’s promise and hold the company to it.
In contrast, the Chinese state can, under its intelligence law, secretly demand access without effective independent review, so a Chinese manufacturer’s promise is not enough. Independent technical verification must then show that access is blocked. If less restrictive measures cannot contain the risk, a ban on that specific use case may be justified.
Allies need to forge a common response. My proposal is a common methodology, Digital Strategic Exposure (DSE), that assesses not only the device, but the cloud, subcontractors, and jurisdictions in which manufacturers operate. The aim is to limit dangerous digital leverage.
Under DSE, Europe would gain a legally defensible way of making decisions to exclude Chinese products where risks cannot be contained, without unnecessarily excluding American technology. Partners could compare their reasoning without sharing confidential evidence. DSE should become a pressure valve for easing transatlantic tensions and preventing a technological split in the West.
The US and the European Commission should run pilot programs in surveillance, energy, transport, and critical cloud and AI. NATO should set collective defense requirements and assess cross-border effects. National teams retain sensitive evidence; EU and national authorities keep regulatory and procurement powers.
My proposal offers a way through the transatlantic sovereignty dispute. Europe gains verifiable control while Washington can address dangerous dependencies without asking allies to copy its bans. Local control, limits on data aggregation, and tested continuity or exit can preserve access to useful American technology. Restrictions remain possible where narrower measures fail.
Humanoid robots raise the stakes: cameras, microphones, and wireless updates in machines that move and act. Uncontrolled digital dependence could soon walk into our factories and homes. We must bring it under control before they arrive.
The bottom line is that allies should de-risk from dangerous leverage, not from one another.
Đuro Lubura is Special Advisor to Croatia’s Deputy Prime Minister and Minister of the Sea, Transport and Infrastructure. He leads high-level interagency working groups on national security issues and critical infrastructure, including the group drafting Croatia’s regulation on security risk assessment for electronic communications equipment. He completed Harvard Kennedy School’s Senior Executives in National and International Security program and holds IAPP’s Artificial Intelligence Governance Professional (AIGP) and Certified Information Privacy Technologist (CIPT) certifications. He has held senior positions in the military, police and intelligence services. He writes in a personal capacity.
Bandwidth is CEPA’s online journal dedicated to advancing transatlantic cooperation on tech policy. All opinions expressed on Bandwidth are those of the author alone and may not represent those of the institutions they represent or the Center for European Policy Analysis. CEPA maintains a strict intellectual independence policy across all its projects and publications.
Steel and Silicon: Allied Innovation for the Next Century
2026 CEPA Tech & Security Conference