China dominates Southeast Asia's digital hardware but fails to export governance rules: PRIO report
Synopsis
Key Takeaways
China has emerged as the leading supplier of digital infrastructure across Southeast Asia, yet regional governments are overwhelmingly adopting European, United Nations, and locally derived governance frameworks rather than Beijing's regulatory model, according to a new report released on 15 September 2026 by the Peace Research Institute Oslo (PRIO).
The report's central finding — that 'Chinese hardware is widespread but Chinese rules are not' — challenges the common assumption that infrastructure dominance automatically translates into normative influence. Researchers cautioned, however, that this governance gap will only persist as long as credible alternatives remain available.
Scale of China's Digital Footprint
Chinese firms have laid fiber-optic cable, constructed smart-city platforms, supplied 5G networks, and even donated laptops to defense ministries across the region. These deployments are part of China's Digital Silk Road (DSR) — the technological arm of the Belt and Road Initiative (BRI) — which aims to spread Chinese-built networks, surveillance systems, and cloud infrastructure across the developing world.
Crucially, the DSR was designed not merely to export technology but to propagate Beijing's preferred norms of digital governance, a goal evident in what the report describes as 'Beijing's own Chinese-language framing of the initiative.'
Why Beijing's Rules Are Not Taking Hold
Despite the hardware penetration, Southeast Asian nations are writing their own regulatory playbooks. Indonesia's cybersecurity agencies enforce technical standards developed in Geneva, anchoring guidance in ISO 27001 — the international standard for information security management. Banks follow central bank regulations while fintech firms answer to the financial services authority.
The Philippines modelled its data privacy law on European regulation. Malaysia's approach to artificial intelligence draws from UN principles and regional frameworks. The PRIO report argues that Chinese norms are 'essentially absent' in the cybersecurity domain across the region.
Institutional lock-in is a key reason. Once a country's banks, telecoms, and certification regimes are built on ISO and Western frameworks, 'the switching costs are prohibitive, and every new regulation layers on top of the old ones,' the report noted.
The Warning to Washington
The PRIO analysis carries a direct message for the United States: it could lose the digital contest in Southeast Asia not through defeat, but through complacency. The report argues that Washington risks ceding ground if it assumes Beijing has already won and stops competing on governance frameworks and standards-setting.
This comes amid intensifying great-power rivalry over technology supply chains and digital standards, with the US, EU, and China each seeking to shape how the next generation of internet infrastructure is governed — from data localisation rules to AI ethics guidelines.
Broader Implications for the Indo-Pacific
The findings add nuance to the ongoing debate over Chinese tech in the Indo-Pacific. While governments including India have moved to restrict Chinese hardware in sensitive sectors, Southeast Asian nations have taken a more transactional approach — accepting the infrastructure without endorsing the governance philosophy that comes with it.
Analysts note that this posture reflects a broader pattern of hedging: smaller states leverage Chinese investment while aligning regulatory frameworks with international or Western standards to retain interoperability and foreign investor confidence. Whether that balance holds will depend significantly on how vigorously the US, EU, and like-minded partners engage on digital governance going forward.