Skip to main content
TECH_SCIENCE04 / 05 · scéal an lae3 nóim · 769 focal · 27 foinsí

Estonia’s Nuctech scanners lack records

Scríofa ag ISto brief AI · 14 Lúnasa 2026, 02:50
Conas a scríobhadh é

Thousands of possible connections emerge where Estonia’s oversight remains unseen.

Cumadóireacht íomhá · tobrief
an téacs · 3 nóim léitheoireachta

Estonia’s customs service and Tallinn Airport have for years used X-ray screening equipment made by Nuctech, a Chinese state-owned company (Postimees). There is no public proof that these machines have been used for spying. The problem is more basic, and in some ways more awkward: the paper trail is missing.

Tender records, contract terms, security-risk assessments, and the arrangements for software updates and maintenance have not been disclosed. So the question is not whether a dramatic espionage case has been proven. It has not. The question is whether a purchase involving border and airport screening equipment was ever treated with the security seriousness it clearly required.

The machine is not what you picture

A baggage scanner looks harmless enough: a metal tunnel, a conveyor belt, a screen for the operator. But modern airport scanners are not passive machines. They are networked computers built around an X-ray system.

CT-based scanners collect images from several angles, and software turns them into three-dimensional views that operators can rotate and slice to inspect what is inside a bag (NIST). The system logs what it scans, flags suspicious items, and relies on regular software updates to keep detection accurate.

That is where the supplier relationship becomes sensitive. Vendors often keep remote access so they can maintain machines, fix faults and install updates. In practical terms, that can amount to a master key. It may be needed to keep the equipment working, but the buyer needs to know who holds it, when it is used, and what it can reach.

Security guidance from ENISA and the UK’s NCSC warns that these maintenance channels can become routes for unauthorised access or quiet changes to system settings.

For border scanners, the risk is plain. Someone with deep system access could, in theory, view inspection images or alter detection thresholds so the machine becomes less sensitive to certain objects, without frontline operators noticing. These are known structural risks in the sector. They are not evidence that any Nuctech machine in Estonia has been compromised.

Brussels is asking about money, not espionage

The European Commission’s action against Nuctech is a competition investigation, not a security finding. In April 2024, Commission officials inspected Nuctech-linked premises in Poland and the Netherlands under the EU’s Foreign Subsidies Regulation, a law in force since 2023 that allows Brussels to examine whether financial backing from a non-EU government helped a company undercut rivals in European tenders (European Commission).

Nuctech challenged aspects of the data handling from those raids. The EU General Court rejected its interim bid in July 2024. No final decision has been published.

That distinction matters. Brussels is examining whether cheap, state-backed pricing distorted competition. That is not the same as deciding whether the machines can be trusted from a security point of view. The foreign subsidies regime was not built to answer that question.

A national purchase, a shared risk

Scanners at the EU’s external borders are bought nationally, by customs agencies and airports. But the risk does not stay neatly inside national borders. Once goods clear Estonian customs, they can move across the single market, the 27-country area where products circulate without routine border checks. Passengers screened at Tallinn can fly onward across Schengen.

Ireland is outside Schengen, but not outside the logic of shared trust. For an island economy inside the single market, and for a State where customs arrangements always carry a Northern Ireland shadow, weak control at another EU entry point is not someone else’s abstraction. The single market works because each member state accepts that the others are doing their part.

Other countries approach that assumption differently. Nuctech has a production and service centre near Warsaw, giving Poland a physical exposure: repairs and updates run through a local subsidiary of the Chinese parent. Lithuania’s framework for protecting strategically important infrastructure would screen a purchase like this for ownership and remote-access risks. The Netherlands places Chinese technology in the context of explicit espionage warnings from its intelligence service. Estonia is the case where Nuctech use is confirmed, but the governance trail remains hidden.

EU rules such as the NIS2 directive push operators of essential services to manage supply-chain risk. Belgium recently blocked a Chinese-linked takeover of a helicopter operator on national-security grounds. But the procurement decision itself, including who assessed the supplier and what access was granted, still sits with national authorities.

Brussels can make subsidised competition harder. It cannot go back and audit every scanner already operating at an EU border. That responsibility rests with the national buyers. Until Estonia explains how this purchase was assessed, the debate will remain trapped between espionage anxiety and procurement silence, while the real accountability gap stays open.

How was this article?

Help us get better

Details about this article
Model:
claude-opus-4-6
Generated:
8/14/2026, 2:12:25 AM
Pipeline run:
eu_pipeline_20260814_005006
Watermark:
SynthID (Google's invisible watermark)
Human review:
None before publication
Learn more about our methodology