The House Select Committee on China’s 49-page investigation, published August 4–5, 2026, is being read primarily as a Salt Typhoon story. That framing understates what it actually found. The report is a governance autopsy. It documents in specific terms what happens when a regulator bans a set of companies at the licensing level while the underlying physical infrastructure — equipment, data centre space, routing relationships — remains woven into the fabric of the networks those companies are no longer permitted to operate.
The central finding is not that Salt Typhoon succeeded. Everyone already knew that. The central finding is that China Mobile International, China Unicom, and China Telecom — all of whom had their US operating licenses denied or revoked between 2019 and 2022 — maintained equipment, data centre presence, and network ties that persisted after those restrictions took effect. And that persistence became operationally relevant. Between September 22 and 25, 2024, China Mobile International’s network appeared in routing paths to 58 groups of IP addresses associated with Salt Typhoon attack infrastructure a total of 192 times. BGP does not check regulatory status. Routes propagate because networks accept them.
What the FCC Bans Were and Were Not
The FCC actions against the three Chinese carriers were real and significant in what they addressed: the right to operate as a telecommunications service provider in the US market. China Mobile lost its authorisation to provide domestic and international services. China Telecom had its authorisation revoked following a National Security Council review. China Unicom’s US subsidiary faced similar restrictions.
What those actions did not address — because they were not designed to — was the physical infrastructure layer. Data centre colocation agreements do not automatically terminate when a licence is revoked. Peering relationships at internet exchange points, maintained through bilateral agreements between network operators, do not dissolve because a regulatory body has changed a firm’s legal status. Equipment that has been sold, installed, or leased into a carrier’s infrastructure does not remove itself.
The report documents that US telecommunications companies had “routine pathways” in their networks to equipment and data centres that may have been connected to the three banned firms. The committee is careful to note that it does not allege the companies’ US employees knew about or actively participated in the Salt Typhoon campaign. The problem is structural, not necessarily conspiratorial. The infrastructure was integrated before the restrictions. The restrictions changed the legal status of the relationship, not the physical one.
109,000 BGP Incidents
The data on broader routing behaviour is worth lingering on. The committee identified nearly 109,000 incidents between January 2018 and May 2025 in which Chinese or Hong Kong-linked networks claimed US internet addresses without authorisation. These incidents — BGP prefix hijacks and route leaks — are individually often ambiguous: they can result from misconfiguration as readily as from deliberate action. In aggregate, across seven years and a hundred thousand separate events, they describe a persistent pattern of Chinese-linked networks claiming visibility into or control of US routing infrastructure.
BGP security has been a known problem for over two decades. The adoption of RPKI (Resource Public Key Infrastructure), which allows network operators to cryptographically validate route announcements, has been slow. US carriers have been inconsistent. The report recommends stronger action here as part of its broader set of proposals. That is correct but overdue. The 109,000 incidents do not represent a novel discovery — they represent the accumulated consequence of an internet infrastructure that was designed for a cooperative model and is now operating in a strategic competition model.
The Rip-and-Replace Problem
The committee recommends rip-and-replace for Chinese-origin equipment in US telecommunications infrastructure. This is the right policy conclusion and also, as a practical matter, an enormous undertaking that has already been moving slowly. The FCC’s rip-and-replace programme for Huawei and ZTE equipment from US carriers — particularly the rural carriers who adopted it most extensively because it was affordable — has been underfunded relative to the scope of the task since it was established. Congress has not fully appropriated what the carriers need to complete it.
The irony the report gestures toward, without fully stating, is that the same governance gap it documents for Chinese telecom operating companies applies to Chinese-manufactured equipment. Banning Huawei from new deployments did not remove existing deployments. Allocating funding for removal did not guarantee the funding would arrive in time or in full. The regulatory action and the operational reality diverged, in both cases, because infrastructure is physical and persistent in ways that licensing decisions are not.
Implications for Allied Networks
The House committee’s focus is US domestic infrastructure, but the same dynamics apply to allied networks — and in some cases more acutely. UK carriers integrated Huawei equipment into 4G and early 5G core networks on a scale that US carriers did not, because the risk assessment made at the time of deployment was different. The UK’s subsequent decisions to mandate Huawei removal by fixed deadlines have been delayed and revised. European carriers are in similar positions.
Salt Typhoon’s targeting of European telecoms — documented by intelligence assessments shared with ENISA and national agencies in April 2026, confirming active access in at least two major European networks — follows the same template. The lawful intercept infrastructure is the target. The integration of Chinese-origin equipment and the persistence of routing relationships with Chinese carriers create the pathways. The speed of regulatory response determines how long those pathways remain available.
The House committee report frames this as a US regulatory failure. It is also a story about the gap between where security policy gets made (licensing boards, regulatory agencies, legislative committees) and where the actual risk lives (BGP tables, data centre cross-connects, firmware versions running on equipment in remote sites). Those two domains operate at very different speeds. Regulatory action takes years. Routing changes take milliseconds. Equipment replacement programmes take a decade and require sustained political will and funding that routinely fails to materialise.
What Changes
The report’s concrete recommendations — stronger FCC enforcement powers, full funding for rip-and-replace, RPKI adoption mandates, closer review of data centre arrangements involving Chinese-connected entities — are the right set of actions. Whether they produce a different outcome depends on implementation at the infrastructure level, not just at the regulatory one.
The 192 appearances of China Mobile International routing in Salt Typhoon C2 paths over four days in September 2024 are a precise illustration of the gap. The company’s licence had been denied for years. Its network infrastructure remained reachable. The regulators had acted. The infrastructure had not caught up. That gap is the story the report is telling, and it is one that applies far beyond this specific company, this specific threat actor, or this specific country.
Telecom infrastructure operates on decadal timescales. Threat actors operate on operational timescales. Getting those two clocks into better alignment is the actual policy problem, and it will not be solved by any single committee report, no matter how well evidenced.