Across Southeast Asia, Chinese firms have laid fiber-optic cable, built smart-city platforms, supplied 5G networks, and even donated laptops to defense ministries. By one common account in Washington, this is what losing looks like: through its Digital Silk Road, Beijing is exporting not just technology but authoritarianism itself.
But ask the officials who actually regulate these systems what rules they follow, and a more complicated picture emerges. Indonesia’s cybersecurity agencies enforce technical standards developed in Geneva. The Philippines modeled its data privacy law on European regulation. Malaysia’s approach to artificial intelligence borrows from U.N. principles and regional frameworks. In three of the Digital Silk Road’s most important partner countries, Chinese hardware is widespread but Chinese rules are not.
China may be winning many of the contracts to build out Southeast Asia’s digital infrastructure, but Beijing is making less headway on the rules. Understanding this – and the factors behind this reality – complicates the prevailing concern about digital authoritarianism. However, there is one scenario in which the hand-wringing about digital authoritarianism could become a self-fulfilling prophecy.
China’s Digital Silk Road
China’s Digital Silk Road (DSR), the technological arm of the Belt and Road Initiative (BRI), has spread Chinese-built networks, surveillance systems, and cloud infrastructure across the developing world. Embedded in that infrastructure, many argue, is a political model: “cyber sovereignty,” centralized data control, and a state’s right to intervene in its digital sphere as it sees fit. Analysts have warned that the world could fragment into technological spheres of influence, and Southeast Asia – a region that is young, rapidly digitalizing, and ambivalent about democracy – is seen as fertile soil for Beijing’s model.
These concerns are legitimate and deserve to be taken seriously. As I wrote last year, the DSR aims to export both China’s technology and its preferred norms, in a bid to set the rules of digital governance rather than simply build the infrastructure. Beijing’s own Chinese-language framing of the initiative leaves little doubt about that ambition. But whether those norms actually take root is a separate question.
Minxin Pei argued in his book “The Sentinel State” that China cannot export its surveillance model at all. According to Pei, the technology is only part of China’s digital authoritarianism; what matters most is the human infrastructure that can mobilize millions of citizen informants against anyone suspected of disloyalty. China’s Leninist police and internal-security bureaucracy reaches into workplaces, campuses, villages, and neighborhood committees. Cameras and facial recognition software has supercharged this apparatus, but technology by itself can’t replicate China’s security state. One may infer from this that a foreign government that buys the hardware without the Leninist bureaucracy essentially inherits a shell.
Pei is right, and his argument is a necessary corrective to much of the hype around exporting digital authoritarianism. But what do host countries’ governments actually want from Chinese technology? What do they do with it once it is installed, and whose rules do they write around it?
Over the past several years, a research project I lead at the Peace Research Institute Oslo (PRIO) has put these questions to the test. I conducted over a hundred interviews with government officials, regulators, technologists, industry figures, and civil society actors in Indonesia, Malaysia, and the Philippines – three of the Digital Silk Road’s flagship partners – alongside systematic analysis of official documents and speeches.
Some of my findings were recently published in the Review of International Studies. To summarize, Southeast Asian governments are not adopting China’s digital governance model together with the technology, at least not yet. Neither are they rejecting it in favor of the West’s model. Rather, they are picking and choosing, taking Beijing’s hardware while writing their own rulebooks, drawing from European regulation, U.N. norms, regional frameworks, and their own political traditions.
Locked Out of Cybersecurity?
Consider the domain where Chinese influence should be quite strong: cybersecurity. Here, Chinese norms are essentially absent.
In Indonesia, the national cyber agency, BSSN, anchors its guidance in ISO 27001, the international standard for information security management. Banks follow central bank regulations; fintech firms answer to the financial services authority; and all of it, as one member of the country’s cybersecurity community described it, aligns ultimately with international standards. Indonesian officials talk a great deal about digital sovereignty, but the rules their institutions actually enforce were mostly written in Geneva and Washington.
Similarly, Malaysia’s cybersecurity governance took shape in response to U.N. processes, and Kuala Lumpur has endorsed U.N. norms of responsible state behavior in cyberspace. Its capacity-building partners are Canadian firms and EU programs. The Philippines aligns even more explicitly with the West: its Data Privacy Act was consciously built on the European GDPR model, and officials describe international cybersecurity governance as a Western-dominated affair.
Thus, in cybersecurity, it seems that balance was struck long ago in favor of the incumbent powers rather than Beijing. Technical standards have enormous inertia. Once a country’s banks, telecoms, and certification regimes run on ISO and Western frameworks, the switching costs are prohibitive, and every new regulation layers on top of the old ones. And Beijing arrived to the standards race decades late.
On top of this, there is widespread official mistrust of Chinese platforms. Such sentiments were voiced repeatedly in interviews, even by officials in governments happy to accept Chinese infrastructure.
Pei argued convincingly that officials abroad could never replicate the Chinese party apparatus. But my research found that nobody in the governments of Indonesia, Malaysia, and the Philippines seemed to be looking to Beijing for rules in the first place – even in areas where Chinese technology is most deeply embedded. Recipient states have their own institutions, values, and strategic calculations, which they seek to pursue while using Chinese technology.
The Opening in AI Governance
Unlike cybersecurity, however, the ethics and governance of artificial intelligence represent new terrain. There is as yet no entrenched standards regime for these technologies. If Chinese norms were going to take root anywhere, it would be here. What is emerging instead is a blend of norms.
This is in spite of China’s obvious efforts to promote its own model. I recent years, Beijing has issued a steady run of normative offers aimed squarely at this space, including a Global Initiative on Data Security in 2020, a Global AI Governance Initiative in 2023, a Global Governance Initiative unveiled at the Shanghai Cooperation Organization summit in Tianjin in September 2025, and most recently the World Artificial Intelligence Cooperation Organization established in July 2026. As Henry Tugendhat observed, despite this succession of declarations, their actual impact is hard to define, let alone measure.
My fieldwork in Southeast Asia suggests one reason why we’re not seeing China’s efforts pay off: No one is actually referencing these initiatives when drafting regulations or statues within the region’s governments.
In Indonesia, officials frame digital ethics through Pancasila, the state’s founding philosophy, insisting that the country’s digital life must reflect national values rather than any imported template. Nonetheless, these same officials describe an ambition to shape global norms, by participating in international forums and pushing for frameworks that fit Indonesia’s circumstances. There’s little interest in simply adopting a foreign approach to AI governance – from China or elsewhere.
Malaysia’s approach is more openly pragmatic. Analysts there acknowledge that the country lacks an indigenous framework for regulating AI. Instead, policymakers study foreign examples, then match these approaches to the domestic market. The biggest policy debate in Kuala Lumpur is whether to absorb Europe’s data protection regulation wholesale, as the price of trading with Europe, or to write a separate privacy law for Malaysian consumption. Either way, the reference points are European and multilateral. China’s preferred models barely feature in the discussion.
For its part, the Philippines’ national AI strategy addresses fairness and bias; agencies across government worry about the ethical deployment of automated systems. On the ground, Filipino data scientists describe retraining imported AI models because they produce skewed results when applied to Philippine data. Foreign technology and its embedded assumptions are conscientiously recalibrated to fit local realities.
Hovering over all three countries is ASEAN. Its regional guides on AI governance and data – documents that are largely ignored outside the region – function as templates through which Southeast Asian governments mediate between external models and domestic priorities. Regional multilateralism, so often dismissed as talk, acts as a filtration system.
In cybersecurity, where the rules were settled long ago, the West’s standards won by default and China is locked out. And in the field of AI, where the rules are still being written, Southeast Asia is drawing overwhelmingly on Western and multilateral sources, adapted through local values and institutions. China’s normative model isn’t winning converts in either case.
Fighting Standards With Standards
It would be a mistake to read these findings as grounds for complacency, though. The strongest predictor of whether a state filters foreign norms rather than absorbing them wholesale, our new research suggests, is institutional and regulatory capacity, the strength of civil society, and the specific ways the technology is adopted. Likewise, states have more scope to exercise their digital autonomy when great powers compete for alignment.
Today, Southeast Asia mixes and matches technology regulations. But in a world of Western retrenchment, China would be the single full-service provider of infrastructure, financing, and governance templates. The outcomes would tilt toward Beijing – less because Chinese norms had become more persuasive than because the available options had shrunk.
This is already happening, as evidenced in Washington’s own documents. The National Security Strategy (NSS) released last year barely mentions Southeast Asia. Where the region did figure in the NSS, as Derek Grossman argued, it was as a vehicle for American economic objectives rather than a strategic partner in its own right. When the Trump administration launched Pax Silica, its initiative to secure semiconductor and critical mineral supply chains, the only Southeast Asian country initially named as a key partner was Singapore. (The Philippines eventually joined in April 2026).
Meanwhile, Chinese officials and firms adjust their pitch over time, tailoring normative messaging to local elites. Huawei’s training programs across Southeast Asia are building relationships with the next generation of engineers and regulators. The adoption of Western-leaning cybersecurity norms might be immovable at this point, but the region’s eventual stance on AI governance is still in flux – and that gives China an opportunity.
Three implications follow for Washington and its partners.
First, stop issuing warnings and start fighting standards with standards. A decade of pressuring Southeast Asian governments to rip out Chinese equipment has yielded little except irritation. The region’s governments buy Chinese hardware because it is cheap and available, and they resent being told their sovereignty is at stake. The physical infrastructure matters less than Washington seems to think; the contest that actually matters is playing out in venues like ISO and ITU processes, regional regulatory forums, and ASEAN’s AI governance track, where the rules attached to the hardware get written. The West’s greatest advantage in Southeast Asia is that its standards are already the region’s default, but that won’t last if no one from Washington or Brussels shows up to defend and extend those principles.
Second, the United States must treat Southeast Asian agency as the asset it is. The instinct in Washington is to demand alignment, but ASEAN’s hedging culture rejects this mentality. The states best able to resist China’s normative influence are not necessarily the most loyal U.S. allies but the most institutionally capable. Supporting regulatory capacity, training, and legal reform – without requiring alignment – can strengthen the filtering mechanisms that have kept Beijing’s model at bay thus far.
Third, Washington must show up for the AI governance contest specifically, because it is here that the end result is most in question. That means funding Southeast Asian participation in international AI forums, engaging ASEAN’s governance process as a serious interlocutor rather than an afterthought, and offering frameworks worth borrowing from. Every element the region’s regulators splice into their hybrid rulebooks is an element someone made available. For now, the ingredients are overwhelmingly Western and multilateral. But if China is the only government offering models for regulating cutting-edge AI, that will change.
Chinese technology has spread through Southeast Asia, and it will continue to. But that doesn’t mean China is writing the rules for that technology. Instead, regional governments are forging their own paths, drawing on a world of options. That will remain true only as long as there is a world of options to draw on. The surest way for Washington to lose the digital contest in Southeast Asia is to assume Beijing has already won.
