
The sweeping new export controls issued by China in October 2025, which cover much of the battery value chain, highlight the critical need for energy storage sovereignty in Europe. This move by China comes amidst significant turmoil in Europe’s battery sector, marked by the bankruptcies of prominent firms. In response, the geopolitical significance of batteries has become a focal point, necessitating a comprehensive examination of the geopolitics surrounding battery technology.
Concerns over security risks linked to connected car technology are gaining traction. In October 2024, the German Association of the Automotive Industry emphasized the importance of ensuring maximum security for the German automotive industry. The vast amount of data collected by connected vehicles, including location tracking and driver behavior analytics, poses significant security risks. Additionally, electric vehicles monitor battery charge and temperature through integrated battery management systems (BMS), which provide a digital interface that could be exploited for cyber-based disruption or sabotage.
The EU already recognizes cybersecurity as a critical issue in the automotive sector. Regulation (EU) 2019/2144, known as the General Safety Regulation (GSR), sets cybersecurity requirements for vehicle manufacturers. It aligns with the United Nations Economic Commission for Europe Regulation No. 155 and the EU’s Directive 2022/2555, known as NIS2. Compared to its predecessor NIS, NIS2 expands the number of entities required to comply with strict cybersecurity regulations. With mandatory compliance for all new vehicles as of July 2024, the GSR establishes mandatory safety requirements for motor vehicles, their trailers, and associated systems. Vehicle manufacturers must demonstrate how the supply chain was managed and how supplier components integrate into the vehicle’s overall cybersecurity architecture. This includes measures to prevent the manipulation of vehicle parameters, such as battery temperature.
However, the GSR regulation omits a crucial aspect: it does not consider the manufacturer’s country of origin. This regulatory gap raises concerns about potential vulnerabilities that could be exploited by strategic competitors, such as China, through Chinese software or hardware components integrated into vehicles at various stages of production or deployment. The EU’s GSR and NIS2 set only technical cybersecurity baselines, falling short in addressing geopolitical risks. Therefore, additional regulations are needed to include non-technical risk factors, such as ensuring the trustworthiness of suppliers of cars or components like battery management software.
EU’s Response to Concerns
In response to these concerns, the EU has been developing a voluntary toolbox to protect supply chains related to information and communication technologies (ICT). This toolbox, proposed by member states, mirrors the EU’s existing 5G security toolbox, which outlines measures for mitigating cyber espionage and interference. The ICT Supply Chain Toolbox might be integrated into a revision of the Cybersecurity Act, making it a binding document for regulators and operators in the EU. Germany appears to be more security-minded, while Hungary and Spain take a more lenient stance in regulating high-risk suppliers. Germany’s position on supply chain regulations highlights a potential threat to its regulatory approach in the cyber realm. In fall 2025, the German government weakened its Supply Chain Act by suspending reporting obligations, raising questions about the willingness of German and other EU companies to adopt further cybersecurity regulations related to the supply chain.
EU’s Ongoing Efforts
The EU’s ongoing efforts to address cybersecurity in connected vehicles represent a crucial step, but further development is needed. Future initiatives like the ICT Supply Chain Toolbox offer hope, but their success depends on consistent member state implementation. Without a unified and comprehensive framework, the EU risks significant vulnerabilities in its connected vehicle ecosystem.
Recommendations for a Comprehensive Cybersecurity Approach
To achieve a comprehensive cybersecurity approach, the EU should draft an additional regulation specifically on the issue of connected vehicles. This new regulation should integrate the following recommendations.
First, the EU should draft a binding rule similar to the one regarding connected vehicle cybersecurity published by the US Department of Commerce’s Bureau of Industry and Security. This rule should restrict the use of Chinese and Russian components in connected vehicles that are particularly exposed to sabotage and espionage, such as Wi-Fi connectivity and advanced driver assistance systems. The US rule explicitly bans cars and components with China and Russia as their country of origin due to the geopolitical risks posed by their governments.
Second, when creating its equivalent of the US connected vehicle cybersecurity rule, the EU should be more precise in the wording of what is banned. The US rule identifies specific components through which the vehicle communicates with the outside world, including the operating system, telematics systems, advanced driver assistance systems, and battery management systems. An EU regulation would benefit from such specificity, allowing for a more granular assessment of risk and reducing costs for industry.
Third, Germany and the EU need to act swiftly. Unlike in 5G, Chinese vendors do not yet have a significant presence in the connected vehicle space in Germany and Europe. The longer Europe waits, the costlier it will become to expunge risky components. With every passing day, the market share of Chinese car companies and providers of hardware and software components may grow due to joint ventures with German carmakers.
Fourth, Brussels and Berlin should closely discuss and fine-tune any regulation with key partners, including Italy, France, Japan, South Korea, and other major car manufacturing countries. This collaboration should determine not only the content of the rule but also the timing of its pronouncement and implementation.
Importancia de la colaboración internacional
La colaboración entre las principales potencias mundiales es crucial para establecer reglas claras y efectivas en el sector de la movilidad. La participación de países como Italia, Francia, Japón y Corea del Sur es fundamental para garantizar que las regulaciones sean justas y beneficiosas para todos.
Finalmente, Alemania debería continuar haciendo la confianza un componente central de las cadenas de suministro relacionadas con cualquier tecnología de movilidad futura, incluidos los drones. Los drones plantean un desafío particularmente desafiante para des-rizar, ya que China domina este sector.
Desafíos en la regulación de drones
La regulación de drones es un tema complejo que requiere una atención especial. La dominación de China en este sector plantea un desafío significativo para las potencias occidentales, que deben encontrar formas de equilibrar la innovación con la seguridad y la estabilidad.
