Europe has been talking about digital sovereignty for several years. The expression appears in speeches, regulations, and industrial strategies as a response to a legitimate concern: in an increasingly technological and unstable world, any power that aspires to preserve its decision-making capacity needs to maintain certain of its own industrial, scientific, and strategic capabilities.
The problem arises when some of the policies presented today under that label are examined. Then a disturbing paradox appears: part of supposed European autonomy seems to consist of replacing some dependencies with others while proclaiming an independence that is more rhetorical than real.
This transformation is especially visible in the treatment of Chinese technology. What just a few years ago was a debate about competitiveness, innovation, and industrial costs has progressively become a matter of national security. Infrastructures that were considered efficient and acceptable yesterday are now described as strategic threats. And this evolution coincides, not by chance, with the growing technological rivalry between the United States and China.
The issue becomes particularly relevant in the debate Brussels is having about the presence of Chinese suppliers in European telecommunications infrastructures. Over the past few years, the European Commission and several Member States have promoted measures to limit the participation of certain suppliers considered high-risk. The process began with the so-called 5G Toolbox, a set of recommendations to strengthen the security of mobile networks, and now continues with the revision of European cybersecurity legislation, which proposes more binding mechanisms that could facilitate broader restrictions and even the replacement of already installed equipment.
The official justification is well-known: to strengthen the security of critical infrastructures and increase European resilience. The question is whether all these measures truly respond to a logic of security or if, at least in part, they reflect a geopolitical and commercial response presented in more politically acceptable language. In other words: are we building true strategic autonomy or transforming an economic competition problem into a national security issue?
To answer that question, it is worth starting with the economic context.
The true origin of the problem
For decades, the relationship between Europe and China was based on a relatively clear complementarity. Europe exported technology, industrial machinery, and capital goods. China provided manufacturing capacity, competitive costs, and a gigantic market. That balance began to change when China ceased to be solely the factory of the world and also became a technological power.
The growing European trade deficit with China has reinforced the perception that the relationship has become unbalanced. And it is not a completely unfounded concern. However, it is advisable to carefully distinguish between different problems.
A significant part of China's progress is concentrated precisely in sectors that Europe considers strategic for its own economic transformation: electric vehicles, batteries, photovoltaic energy, and technologies linked to the energy transition. China produces many of the goods that Europe needs to meet its climate and industrial objectives with extraordinary competitiveness.

It would be naive to ignore that part of this competitive advantage is related to aggressive industrial policies, public financing, and state support systems that generate controversy. The European Union itself has opened investigations to analyze possible market distortions.
But precisely for this reason, it is advisable to avoid confusion. If the problem is commercial, the response should be commercial: anti-dumping mechanisms, investigations into subsidies, reciprocity clauses, or a more ambitious European industrial policy. It is difficult to justify using instruments designed for national security as substitutes for an economic strategy. When an issue of industrial competition is automatically redefined as a security threat, there is a risk of applying inadequate remedies to real problems.
The curious European strategic autonomy
To this economic context is added another factor impossible to ignore: the growing technological rivalry between the United States and China. Washington has been pressuring its allies for years to reduce the presence of Chinese companies in sectors considered strategic. The arguments are well-known: risks of espionage, backdoors, and hidden vulnerabilities.
Of course, any critical infrastructure deserves rigorous scrutiny. No one disputes the need to protect telecommunications networks or energy systems. What is debatable is the tendency to turn geopolitical suspicions into regulatory certainties.
After years of public accusations and political debates, open technical evidence to justify some of the more radical measures remains scarce. That does not mean the risks do not exist. It simply means that regulatory decisions should be based on verifiable evidence, transparent technical analyses, and assessments proportionate to the real risk.
And here lies one of the great contradictions of the moment. Brussels constantly invokes strategic autonomy while adopting positions extraordinarily aligned with Washington's geopolitical priorities. Europe claims to want to reduce external dependencies, but risks substituting one for another. Excluding certain Chinese suppliers does not create European technological sovereignty; it simply redistributes the market among suppliers considered politically acceptable. If the end result is to depend less on China to depend more on other external actors, surely North Americans, strategic autonomy will have been reduced to a mere change of supplier.
From the 5G Toolbox to CSA2
This political evolution has translated into increasingly ambitious regulatory changes. What began in 2019 as a set of voluntary recommendations is evolving into more restrictive mechanisms through the revision of the Cybersecurity Act, informally known as CSA2.
The European Commission intends to have tools that allow it to identify suppliers considered high-risk, restrict their participation in essential infrastructures, and even promote the withdrawal of already installed equipment.
All this is justified in the name of resilience. The problem is that the concept risks becoming a label capable of legitimizing any measure without demanding the same attention to its costs as to its supposed benefits.
Featured story
The EU's satellite reform opens a vein of defense contracts for Spanish industry
6 minutes
Because costs exist. Replacing already deployed equipment would mean billions of euros for European operators. Resources that would cease to be allocated to innovation, research, or network modernization to fund premature replacements of fully functional infrastructures. And this without clear guarantees that the increase in security would be proportional to the cost incurred.
Another practical problem is added to this. Although some argue that European manufacturers like Nokia and Ericsson can quickly fill any gap, numerous operators in the sector have warned that a massive replacement in a short period would be extremely complex.
Furthermore, the problem might not be limited to telecommunications. The same regulatory logic could extend to energy, transport, or technologies linked to the ecological transition. Europe maintains a significant dependence on Chinese components to meet its decarbonization objectives. Solar panels, batteries, energy storage systems, and numerous industrial components are part of that reality. Automatically applying an exclusion logic to these sectors could increase investment costs, slow down strategic projects, and hinder precisely the industrial and climate objectives that the European Union itself considers priorities.
The paradox would be evident: trying to strengthen strategic autonomy while simultaneously weakening the continent's industrial capacity.
Spanish Pragmatism
Spain has opted, until now, for a relatively more pragmatic approach.
After years of infrastructure deployment and analysis, no evidence has emerged to justify a massive and immediate expulsion of certain suppliers. In parallel, Madrid has opted to attract industrial investment linked to Chinese manufacturers. Projects promoted by Ebro and Chery, the collaboration between Stellantis and CATL, or the future industrial implementation of MG in Galicia represent attempts to transform a commercial relationship into productive capacity located in European territory.

It would be premature to present them as consolidated successes. The history of technological transfers between the West and China offers contradictory examples and reasons for caution. Frequently, knowledge has circulated in only one direction. But even accepting these uncertainties, it is difficult to find a more promising alternative than trying to attract investment, production - and in the long term, know-how - and employment to Europe.
At least this strategy seeks to build its own industrial capacity. A policy based exclusively on prohibitions does not build factories, does not generate employment, and does not create technological autonomy.
The alternative that is barely debated
There is also a surprisingly absent issue in much of the European debate. Even accepting that certain suppliers may present additional risks, why does the only imaginable response seem to be their complete exclusion?
In practically any other technological field, a different logic applies: reduce risks through additional controls. Modern cybersecurity works precisely like this. The most advanced architectures start from a simple idea: do not fully trust anyone. It is not assumed that a supplier is perfect. Systems are designed to continue functioning even if some of their components are compromised.
This is the principle known as Zero Trust. Applied to telecommunications, it implies segmenting infrastructures, isolating critical components, strengthening encryption mechanisms, permanently monitoring traffic, and subjecting hardware and software to continuous audits. Simply put: it is not necessary to fully trust a supplier to use their equipment; it is enough to design the system so that this trust is not essential.

Proponents of widespread exclusions respond that 5G networks present higher levels of technological integration and that completely isolating certain components is more complex. This is a technically legitimate objection. But even accepting it, a fundamental question remains: does it make sense to incur multi-billion euro replacement costs when mechanisms exist that can significantly reduce risks?
Some European operators are already exploring precisely this approach and have begun to develop segmentation and reinforced control strategies aimed at managing risks without necessarily resorting to massive equipment replacements. It is a less spectacular solution politically, but probably more coherent from a technical point of view. Bans generate headlines and allow for the transmission of strong messages. Engineering rarely makes the front page.
Sovereignty or simple change of dependence
If the objective is truly to strengthen European security, there are more proportionate alternatives than those currently proposed: allowing already installed equipment to complete its life cycle, avoiding premature replacements that generate enormous costs with questionable benefits; applying new regulatory requirements only to future deployments, allowing for a gradual and economically sustainable regulatory transition; strengthening the role of the European Union Agency for Cybersecurity (ENISA) through transparent certification mechanisms based on hardware, software, and source code audits applicable to all suppliers without discrimination based on nationality, and perhaps most importantly, extending security architectures based on segmentation, continuous monitoring, and Zero Trust principles.
These measures would allow for the management of real risks without automatically resorting to general bans. Because true security does not consist of trusting some suppliers and distrusting others. It consists of building systems capable of withstanding even when some of them fail.
The difference between sovereignty and following
Europe today faces a strategic choice of great importance. It can bet on autonomy based on its own industrial capabilities, technological innovation, productive investment, and objective technical criteria. Or it can move towards a model where geopolitics progressively replaces economic analysis and engineering.
The difference is fundamental. Changing one dependency for another is not sovereignty. True autonomy consists of depending less on everyone, not choosing whom we want to depend on. If politics ends up substituting engineering and security ends up becoming an instrument of commercial policy by other means, Europe runs the risk of sacrificing competitiveness, increasing infrastructure costs, and slowing down its technological modernization in the name of an independence that it may never achieve.