> The▁Dutch▁General▁Intelligence and▁Security (AIVD)▁released a▁security▁alert on▁September▁30, for▁modern▁networked▁vehicles, to▁remove the▁risk from the▁parts that▁ordinary▁drivers will▁contact on a▁daily▁basis:▁microphones,▁cameras,▁vehicles. ▁Information▁entertainment▁system,▁GPS,▁remote▁communication▁module and▁charging▁facilities. AIVD▁does not▁name any▁country▁or▁car▁company, but▁explicitly▁warns that▁national▁actors▁may▁obtain▁driver,▁passenger,▁route and▁surrounding▁environment▁data▁through▁these▁systems.

The▁most▁noteworthy of this▁tip is not the▁common▁sense that “cars can▁also be▁connected”, but▁instead that AIVD for the▁first time▁has▁dismantled a▁modern▁car▁into a▁mobile▁terminal that▁keeps▁collecting▁data. The▁microphone in the▁vehicle▁may be▁technically▁open▁at a▁remote▁distance; ▁GPS is▁able to▁keep▁track of▁location and▁movement; ▁Information▁entertainment▁systems▁may▁keep▁contact,▁news,▁Internet▁traffic and▁navigation▁records; ▁Bluetooth,▁Wi-Fi, and▁even▁charge-to-charge▁connections▁may▁also be▁interfaces for▁reading▁data from▁other▁devices.

AIVD▁therefore▁gives▁very▁specific▁advice: do not▁discuss▁sensitive▁matters▁either▁within▁or▁near the▁vehicle; ▁When▁travelling to▁sensitive▁locations,▁consideration▁should be▁given to the▁possibility of▁driving a▁networked▁vehicle with▁an▁external▁camera; The▁risk of▁data▁leakage▁should be▁measured▁before▁connecting to a▁mobile▁phone,▁entering a▁home▁address▁or a▁sensitive▁institutional▁address. ▁These▁recommendations are▁particularly▁important for▁government▁officials,▁personnel in▁key▁positions in▁enterprises and▁those with▁sensitive▁information.

原始来源 · aivd.nlAIVD:现代汽车可能成为间谍工具荷兰情报与安全总局发布的联网汽车间谍风险说明与防范建议。aivd.nl ↗
资料图:现代联网汽车通过中控系统、摄像头、麦克风、GPS和通信模块持续收集数据。荷兰情报机构AIVD警告,这些系统可能被国家行为体用于间谍活动|来源:The Guardian / Tamer Adel / Alamy
资料图:现代联网汽车通过中控系统、摄像头、麦克风、GPS和通信模块持续收集数据。荷兰情报机构AIVD警告,这些系统可能被国家行为体用于间谍活动|来源:The Guardian / Tamer Adel / Alamy · 查看图片来源 ↗

▁At the time of the▁Dutch▁warning, the▁European▁data▁security▁discussion on▁China's▁Internet-connected▁cars was▁warming. The▁Guardian▁reported on▁October▁1, that the▁share of▁Chinese▁brands in▁British▁new▁car▁registrations▁has▁risen to about▁15▁per▁cent this▁year, and that there▁has▁been a▁significant▁increase in▁sales from MG,▁Biadi and Jaecoo. The▁British▁defence▁sector▁had▁previously▁also▁assessed the▁possible▁risks of▁vehicles with▁Chinese▁spare▁parts▁or▁networked▁systems▁entering▁sensitive▁military▁locations.

▁Here,▁two▁layers of▁facts▁must be▁distinguished. The▁first▁level is the▁technical▁risks▁identified▁by AIVD:▁modern▁networked▁cars do have the▁capacity to▁collect▁data in▁large▁quantities, and▁may be▁sought▁by▁malicious▁actors▁or▁State▁agencies. The▁second▁level is the▁national▁security▁concerns▁surrounding the▁Chinese▁brand. AIVD▁itself did not▁identify▁Chinese▁car▁companies▁as▁having▁been▁engaged in▁espionage,▁nor did it▁name▁Biadi, Go-Amour,▁Chiri▁or any▁particular▁business.

▁One▁important▁background for the▁rapid▁extension of▁discussions in▁Europe to▁Chinese▁cars is the▁provisions of▁Chinese▁law,▁such▁as the▁National▁Intelligence▁Law,▁which▁regulates the▁organization and▁assistance of▁citizens in the▁work of▁national▁intelligence. Question </a"▁by▁British▁parliamentarians and▁security▁agencies on▁several▁occasions: in▁which▁circumstances▁may a▁Chinese▁enterprise be▁required to▁provide▁Chinese▁State▁institutions with▁data on the▁location of▁European▁users,▁audio and▁video,▁driving▁habits and▁equipment ▁Help? ▁Can▁companies▁refuse? How▁does▁an▁offshore▁user▁verify▁where the▁data is▁ultimately▁stored and▁processed?

The▁Chinese▁Government and▁Chinese▁enterprises have▁long▁opposed the▁direct▁equivalent of▁such▁legal▁provisions to “all▁Chinese▁enterprises are▁intelligence▁tools”. ▁Beijing▁has▁generally▁emphasized that▁Chinese▁enterprises▁operate in▁accordance with the▁law and that▁Western▁countries▁should not▁invoke▁national▁security▁as a▁reason for▁imposing▁discriminatory▁restrictions. For▁specific▁companies, there is no▁public▁evidence that all▁Chinese▁Internet▁vehicles▁sold in▁Europe have▁handed▁driving▁data to▁Chinese▁intelligence.

But the▁security▁agencies are▁concerned▁precisely with the▁structural▁risks of▁data and▁control,▁rather▁than “are a▁vehicle▁caught▁listening”▁or not. ▁Software▁upgrades in▁smart▁cars,▁cloud-end▁accounts,▁maps,▁remote▁diagnostics and▁recreation▁systems are▁often▁managed on▁an▁ongoing▁basis▁by▁manufacturers▁or▁their▁service▁providers. ▁If the▁manufacturer is▁able to▁access the▁vehicle▁remotely, this▁capability can be▁used for▁repair,▁upgrading and▁improvement of▁experience,▁or▁may▁become▁an▁export of▁data in the▁case of▁legal▁orders,▁hacking▁or▁internal▁misuse.

▁Chinese▁auto▁manufacturers are▁rapidly▁expanding the▁European▁market. In the▁first▁half of this▁year,▁Chinese▁brands▁continued to▁grow in▁many▁European▁countries,▁while▁Biadi and▁others▁simultaneously▁boosted▁local▁production in▁order to▁reduce▁tariffs and▁increase▁market▁penetration. ▁Prices, re-routing,▁software▁functionality and▁configuration▁advantages▁help▁these▁brands▁attract▁consumers,▁while the▁same▁reliance on▁software and▁cloud▁service▁design▁makes▁data▁governance▁an inescapable▁issue.

2026年布鲁塞尔车展上的比亚迪展台。中国品牌在欧洲市场快速扩张,也使联网汽车的数据安全问题受到更多政府和情报机构关注|来源:South China Morning Post
2026年布鲁塞尔车展上的比亚迪展台。中国品牌在欧洲市场快速扩张,也使联网汽车的数据安全问题受到更多政府和情报机构关注|来源:South China Morning Post · 查看图片来源 ↗

For▁European▁regulators, what is▁really▁needed is not a▁political▁slogan for a▁country ' s▁brand, but a▁set of▁verifiable▁technical▁rules:▁which▁data can be▁collected and▁which▁must▁remain▁locally; (b) Whether the▁manufacturer can▁remotely▁turn on the▁microphone▁or▁camera; How the▁business▁must▁disclose when the▁government▁makes a▁data▁request; (b) Whether▁part of the▁functionality of▁vehicles is▁required to be▁closed when▁entering▁military▁bases,▁government▁agencies and▁critical▁infrastructure▁areas; Whether the▁regulator can▁independently▁check the▁flow of▁software and▁data.

This is▁also the▁practicality of the AIVD▁alert. It▁pulls the "smart▁car▁national▁security" from▁abstract▁geopolitical▁arguments to▁specific▁components▁within a▁vehicle that can be▁measured and▁audited. The▁larger the▁European▁market, the▁greater the▁pressure to▁prove that▁data▁processing is▁transparent, that▁software▁privileges are▁controlled, and that▁users▁outside▁China are not▁affected▁by▁China’s▁domestic▁intelligence▁system. For▁European▁Governments,▁genuine and▁effective▁protection▁also▁requires▁evidence,▁technical▁standards and▁transparent▁auditing, and▁cannot▁rely▁solely on▁nationality▁labels.

MEMBER DISCUSSION

Article discussion

Verified members can discuss this report publicly and manage their own content.