Estonia’s Chinese scanners lack a paper trail

Thousands of possible connections emerge where Estonia’s oversight remains unseen.
Image composition · tobriefEstonian customs and Tallinn Airport have used X-ray screening equipment made by Nuctech, a Chinese state-owned company, for years (Postimees). The public evidence points to an accountability gap, not a proven spying case. Tender records, contract terms, security-risk assessments and the arrangements for software updates and maintenance remain undisclosed. The basic question: was this purchase ever treated as the security-sensitive decision it plainly is?
The machine is not what you picture
A baggage scanner looks like a passive metal tunnel. In practice, it is closer to a networked computer with an X-ray source bolted on. Modern CT-based airport scanners collect images from multiple angles, then software assembles three-dimensional views that operators rotate and slice to inspect contents (NIST). The machine logs what it scans, flags suspicious items, and depends on regular software updates to keep detection accurate.
That software layer is why the supplier relationship matters. Vendors typically maintain remote access to keep machines running, the digital equivalent of a master key to the building. It may be necessary for repairs, but the buyer needs to know who holds it, when it is used and what it can unlock. Security guidelines from ENISA and the UK's NCSC warn that these maintenance channels can become paths for unauthorized access or quiet configuration changes.
For border scanners, that means someone with deep system access could, in theory, view inspection images or adjust detection thresholds so the machine grows less sensitive to certain objects, without operators noticing. These are structural risks, well-documented across the sector. They are not proof that any particular Nuctech machine has been compromised.
Brussels is asking about money, not espionage
The European Commission's action against Nuctech is a competition investigation, not a security finding. In April 2024, Commission officials inspected Nuctech-linked premises in Poland and the Netherlands under the EU's Foreign Subsidies Regulation, which since 2023 lets Brussels investigate whether financial backing from a non-EU government helped a company undercut competitors in European tenders (European Commission). Nuctech challenged aspects of the data handling from those raids; the EU General Court rejected its interim bid in July 2024. No final decision has been published.
The distinction matters. Brussels is asking whether cheap state-backed pricing distorted competition. That is a different question from whether the machines are safe to trust, and the regulation cannot answer the security side.
A national purchase, a shared risk
Scanners at EU external borders are bought nationally, by individual customs agencies and airports. But once goods clear Estonian customs, they circulate freely across the single market, the 27-country zone where products move without further border checks. Passengers screened at Tallinn fly onward across Schengen. Every checkpoint's integrity is a shared assumption.
Other member states handle that assumption differently. Nuctech operates a production and service centre near Warsaw, so Poland's exposure is physical: repairs and updates flow through a local subsidiary of the Chinese parent. Lithuania's framework for protecting strategically important infrastructure would screen a purchase like this for ownership and remote-access risks. The Netherlands frames Chinese technology through its intelligence service's explicit espionage warnings. Estonia is the case where Nuctech use is confirmed but the governance trail stays invisible.
EU rules like the NIS2 directive push operators of essential services to manage supply-chain risk. Belgium recently blocked a Chinese-linked takeover of a helicopter operator on national-security grounds. But the procurement decision, who assessed the supplier and what access was granted, happens at the national level.
Brussels can make subsidised competition harder. It cannot retroactively audit every scanner already running at a border. The accountability question sits with national buyers. Until Estonia discloses how this purchase was assessed, the debate stays stuck between espionage fears and procurement silence, with the actual governance gap unresolved.
How was this article?
Help us get better
Help us get better
Details about this article
- Model:
- claude-opus-4-6
- Generated:
- 8/14/2026, 2:12:25 AM
- Pipeline run:
- eu_pipeline_20260814_005006
- Watermark:
- SynthID (Google's invisible watermark)
- Human review:
- None before publication