Home » On China and Russia, Europe’s intelligence services are moving faster than its politics
Hybrid threats • Politics • Technology and Security • World

On China and Russia, Europe’s intelligence services are moving faster than its politics

From connected cars to British universities, from Russian sabotage to Iranian cyber operations, European security services are making increasingly explicit warnings public. The alerts come as Europe heads towards an election-heavy 2027, leaving governments to balance security concerns, diplomatic relationships and economic interests

European intelligence agencies are increasingly warning about security vulnerabilities in interconnected systems, from connected cars to university research partnerships. These warnings highlight the growing concern over data security, industrial competition, and technological dependence, particularly with China and Russia.

As these threats become more public, they reduce the political room for maneuver for European governments, forcing them to address these vulnerabilities and decide where to draw the line between normal interdependence and strategic vulnerability.

When a car becomes a security concern. A car can also be a platform for collecting information. That is the message behind a new warning from Dutch intelligence about the risks associated with the increasingly connected systems installed in modern vehicles.

  • Microphones and cameras can technically be activated remotely, according to the document published on Wednesday. Infotainment systems can hold identifiers from connected devices, contacts, internet traffic, messages and navigation data. GPS and telematics systems can also be used to reconstruct a vehicle’s location and movements. The advice to users is unusually concrete: avoid confidential conversations inside or near the vehicle, and limit the amount of personal or sensitive information entered into onboard systems.
  • The Dutch warning does not identify China or Chinese manufacturers as the source of the threat. It addresses the vulnerabilities of connected vehicles in general. But it comes as the security implications of Chinese-made cars are becoming an increasingly sensitive issue in Europe.

The boom in Chinese electric vehicles was initially discussed largely through two lenses: the green transition and industrial competition. As their presence on the European market has grown, the debate has expanded to subsidies, tariffs, technological dependence and, increasingly, data security.

  • Connected cars combine many of the features that have driven those concerns: sensors, cameras, microphones, geolocation, remotely updatable software and vast quantities of data. In the case of Chinese manufacturers, concerns over data collection intersect with the broader question of the relationship between companies and the state — and whether technologies becoming embedded in everyday European life could generate new strategic dependencies.
  • It is here — rather than in the Dutch warning itself — that the car intersects with Europe’s broader China debate. Data security, industrial competition and technological dependence are increasingly converging around the same product.

For European governments, that creates a particularly difficult trade-off. Mitigating a security risk can carry commercial consequences; protecting European industry can increase the costs of the transition; reducing dependence on Beijing has to coexist with the need to preserve one of Europe’s most important economic relationships.

From universities to semiconductors. Cars are only one part of the picture. On the same day as the Dutch warning, the security of British university research partnerships with Chinese entities came under renewed scrutiny, amid concerns about the potential transfer of sensitive cyber expertise.

  • And there have been other cases: In September, Belgian authorities detained a Chinese national on suspicion of espionage involving the semiconductor industry. Questions have also emerged in Brussels around a Chinese-run networking club frequented by people close to the European institutions.
  • Cars, universities, semiconductors and personal networks are very different dossiers. Taken together, however, they illustrate how far the perimeter within which European security agencies look for vulnerabilities linked to interstate competition has expanded.

Russia and the space below conventional war. With Russia, the picture is different — and more immediately coercive. On September 24, the Danish Defence Intelligence Service published an assessment concluding that Europe’s security environment had deteriorated further. Moscow, the agency said, had intensified its use of sabotage and destructive cyberattacks and was attacking targets in Europe with drones. Its conclusion was stark: “the hybrid war is escalating”. 

  • Copenhagen assesses that Russia is likely to intensify its hybrid campaign further, carrying out more frequent attacks with potentially greater consequences. The scenarios outlined include destructive cyberattacks capable of crippling critical societal functions and acts of sabotage carrying a high risk of casualties. 

More significant still is what comes next. The Danish service assesses that there is a “low but growing” risk that Moscow could launch a limited military attack against one or more Nato countries bordering Russia, even without having built the capabilities required to wage a regional war. At the same time, it still considers an outright Russian invasion of one or more Nato countries “highly unlikely”. 

  • It is precisely the space between those two extremes that appears to be attracting growing attention from European intelligence services. Sabotage, cyber operations, drones, activity around critical infrastructure, covert operations and military pressure can generate strategic effects while remaining below the threshold of conventional war.

Other recent warnings about Russian activity point in the same direction. They range from vessels suspected of performing intelligence functions to Italian assessments that Russia’s hybrid campaign against Europe is entering a more dangerous phase.

Different threats, a widening security perimeter. China and Russia present different challenges, and conflating them would be misleading. But the succession of alerts points to a broader shift: a growing share of Europe’s ordinary economic, technological and civilian life is now being treated by security agencies as a matter of national security.

Iran adds another, more limited dimension. Western intelligence warnings have recently focused on cyber threats targeting Iranian dissidents, bringing another form of state activity into the same security perimeter: the ability to project pressure beyond national borders through digital tools and operations targeting individuals.

The more significant development, however, may be who is delivering these warnings — and how publicly they are doing it.

  • European intelligence agencies are increasingly speaking in public and with a degree of specificity that makes their assessments difficult to confine to the traditional closed-door relationship between security services and governments.
  • An agency that advises people not to discuss sensitive information inside a car, or openly contemplates acts of sabotage carrying a risk of casualties, is no longer simply informing the executive. It is putting an assessment of the threat into the wider public debate.

Intelligence time, political time. This is happening as the political room for manoeuvre of many European governments could soon narrow.

  • Nine EU member states are expected to hold national elections in 2027, including France, Italy, Spain and Poland.
  • Italy will choose Giorgia Meloni’s successor, France Emmanuel Macron’s one, while several other governments will enter election campaigns that will inevitably overlap with European debates over security, defence, and relations with major powers.

Foreign interference in European elections is not a new concern. It has been examined in previous electoral cycles and already forms part of the threat environment European institutions and security agencies have had to confront.

  • There is, however, no basis in the recent alerts considered here to suggest that intelligence services are warning of a specific, coordinated interference campaign targeting the 2027 elections.

The more immediate issue is different. Security time and political time are beginning to diverge.

  • Governments have to keep diplomatic channels open, protect economic interests, manage an increasingly complex relationship with Beijing and contain the risk of escalation with Moscow. Intelligence agencies have a different mandate: identify vulnerabilities and flag them before they can be exploited.
  • Making those risks public inevitably reduces the room for political ambiguity. It does not compel a government to adopt a particular policy towards China, Russia or Iran. But it makes it harder, after the fact, to argue that the risks had not been identified. In that sense, public intelligence warnings can begin to function as policy signals.

Where Europe draws the line. The image of the connected car is useful again here. A conversation inside a vehicle, a university partnership, a semiconductor plant, a railway carrying military equipment or an ostensibly commercial vessel may appear to belong to entirely different worlds.

  • European intelligence services are increasingly explaining why they do not.
  • They are becoming parts of the same strategic question: where does normal interdependence end, and where does strategic vulnerability begin? In 2027, it will increasingly fall to Europe’s governments to decide where that li

Subscribe to our newsletter