Tuesday, July 28, 2026

The Price Of RAN Security In Europe: 40B Euros... And More

Seven of Europe's largest operators commissioned GSMA Intelligence to price the removal of designated high-risk vendors from their networks, and the number came back this week. Under the European Commission's proposed Cybersecurity Act 2, stripping out equipment from suppliers such as Huawei would cost the region's operators between thirty and forty billion euros in direct costs, split across mobile at up to twenty two billion, fixed at around five billion, and transport at up to twelve billion. The figure that matters more, though, is the second one. GSMAi finds that the same measure would push mobile equipment prices up by roughly twenty four percent, because forcing designated vendors out of the market shrinks the field of suppliers, and a smaller field charges more. Deutsche Telekom, Fastweb plus Vodafone, Meo, Orange, Telefonica, United Group and Vodafone Group supplied the underlying data.

I have spent part of my career making the opposite bet. The entire economic premise of Open RAN, the work I led at Telefonica and have written about for years, is that opening the interfaces widens the supplier base, and a wider base drives the cost of the radio down. You can read my longer assessment of where that project actually stands on the state of Open RAN, but the direction of the argument was never in doubt: more suppliers, more competition, lower unit cost. What the Cybersecurity Act 2 proposal does is run that logic in reverse. It removes suppliers, it narrows competition, and the price goes up. The twenty four percent is not a side effect anyone chose. It is arithmetic. You cannot both mandate a smaller supplier pool and expect the survivors to hold their prices.

What makes this more than a European regulatory footnote is where it occurs. It lands on top of a repricing that is already under way for an entirely different reason. I have been arguing for some weeks that the AI build-out is bidding up the exact components a modern radio depends on, high bandwidth memory, advanced substrates, power semiconductors, because AI factories and the RAN supply chain now compete for the same silicon. The consequence I keep pointing to is that even an operator which never buys a single GPU still pays more for its radios, because the AI boom has repriced the inputs. Now set the GSMAi finding beside that. You have two independent forces, one driven by AI demand and one driven by security regulation, both pushing the unit cost of the radio in the same direction, at the precise moment operators are being told to find capital for AI.

Beware of stacked figures though, so let me be precise. Do not add the two numbers. The forty billion is a one-time direct cost of replacement. The twenty four percent is a forward price trajectory on new equipment. They measure different things over different horizons, and stacking them produces a headline number no operator will ever see on an invoice, which is the same error I flag when vendors add their individual RAN energy savings into a total no network has ever achieved. The direction is clear, though.The radio is getting more expensive from two sides at once, and only one of those sides is optional.

This sharpens a position I have held on the location question. If the radio is being repriced upward by both AI demand and regulation, the case for distributing expensive compute out to every cell site gets weaker, not stronger. Costly, repriced silicon is exactly the kind of asset you concentrate where you can amortise it, at the central office and the switching centre, not the kind you scatter across tens of thousands of sites on the promise of a latency budget that most workloads do not need. I made that argument on its own terms when I wrote that operators are leaning in on AI Grid location and set out the fabric versus location considerations underneath it. The cost side now reinforces the physics side. Scarcity concentrates capital.

There is a monetisation discipline here as well, and it is the one I set out when I argued for separating revenue from cost avoidance. High-risk vendor removal is not a modernisation and it is not a growth programme. It is a defensive cost, imposed from outside, that produces no new revenue line and buys no new capability. An operator can, of course, use a forced swap-out as the occasion to modernise, and some will. But the spend itself belongs on the cost side of the ledger, named honestly, and not folded into an AI or transformation story where it does not belong. The moment a swap-out driven by security regulation starts appearing in a slide about AI readiness, someone has mixed the flows again.

At last, this is RAN. While going forward these elements will become more programmatic, it is still unclear whether a 2G, 3G or 4G radio from a high risk vendor actually represents a security risk. The highest compromise risk is in the Core, the OSS and ancillary systems. It is easier to install IMEI catchers and antenna spoofs than to hack into a deployed live system.

Europe may well decide the security case is worth forty billion euros. That is a legitimate political choice. What the choice is not is free, and it is not neutral for competition. A framework designed to reduce dependence on one class of vendor achieves it by reducing dependence on vendors generally, which is to say by making the market smaller and the equipment dearer. Operators should book that outcome for exactly what it is: a defensive, imposed, largely non-recoverable cost, landing on an equipment line that the AI build-out was already repricing without any help from regulators. It is certainly not random that the leading RAN vendors are predominantly europeans, with emerging Korean and Japanese options.

The political decision would transfer value from networks to vendors. It is unclear whether that is sustainable if the pool of vendors does not increase substantially.

Monday, July 27, 2026

Verizon Earning: From Copper to Fibre to Edge

 

Verizon disclosed on its second quarter earnings call last week a dark fibre agreement with Google worth well in excess of a billion dollars, and chief executive Dan Schulman was explicit that it is the first of several, with further deals expected by year end worth multiple billions of dollars in revenue over the coming years. The headlines went to the number and to the counterparty. The more instructive detail came later in the same call, where Schulman described retrofitting thousands of central offices, the copper now being decommissioned, into edge data centres for low latency AI inferencing. One operator, one earnings call, two of the arguments I have been making all month, and they are not the same argument.

Let's start with the fibre. This is not cost avoidance dressed as growth, which is the trap I wrote about when Google Cloud called agentic AI a sixty billion dollar opportunity and every figure underneath the headline turned out to be a saved operating cost. It is also not the speculative new revenue that strategy decks reach for. It is my second money flow, AI creating fresh demand for what the operator already sells, landed on the income statement as contracted revenue. Schulman called it incremental, long duration, high quality, and drawn from some of the most demanding infrastructure customers in the world. He is right to be pleased. Route and real estate are exactly the assets an operator holds that a hyperscaler cannot conjure at will, and the AI build out is short of both.

Now look at what Verizon actually sold. Dark fibre is unlit glass. Google puts its own optics on each end, chooses its own wavelengths, runs its own capacity, and owns everything above the physical layer. Verizon is the landlord of the route and nothing more. On the capacity, platform, outcome ladder I set out two weeks ago, this is not even rung one, it is the ground the ladder stands on. That is not a criticism. A contracted, long duration, low churn landlord business against demand this strong is a genuinely good thing to own, and it is more defensible than most of what operators like to call platforms. The discipline is only this: name it correctly. The moment next year's deck describes a dark fibre lease as an AI platform business, the margin expectation that travels with the word platform will arrive, and a landlord business will not carry it.

The central office retrofit is the disclosure I want to emphasize. For two years I have argued that AI grid compute belongs first at the central office and the mobile switching office, not at the cell site, because power, cooling, fibre, real estate and security all favour the building the operator already runs. I made the fabric versus location case in early July and watched operators lean into central office siting a few days later. Verizon has now put capital behind it on an earnings call. The copper decommission is what makes it work: retiring the old plant frees the floor space and, more importantly, the power feed and the fibre entrance, which are the two constraints that actually bind at an inference site. I built what was probably the first fully programmable multi access edge platform at Telefonica in 2018, and the lesson from that programme was that the physics was never the obstacle. The obstacle was a paying tenant. Low latency inference is the tenant the central office was always waiting for.

The reason to read the two disclosures together is that they resolve a question people keep posing as a choice. Fabric or location, route or venue, is the AI grid a transport problem or a siting problem. Verizon's answer, in one call, is both, and the call even tells you which is which today. The fabric is the contracted revenue, available now, sold in its rawest form. The location is the capital project, the copper coming out and the racks going in, its revenue still ahead of it. An operator that understood only the first would sell glass to hyperscalers and miss the building. An operator that understood only the second would light up central offices with no anchor tenant, which is precisely the mistake the edge computing industry made for a decade. Verizon is doing both, and the sequencing is correct.

So I would put the deal through the same three questions I put to every operator AI business case. Which money flow is this. It is flow two, defended and grown connectivity revenue, honestly labelled, not flow three in disguise. What binding constraint does the buyer pay to remove. Google is paying for route diversity and a dedicated physical layer it controls end to end, away from shared congestion, which is a real constraint and an operator asset. And where does it sit on the ladder. Rung one for the fibre, with a credible path upward only if the central office retrofit becomes a platform the operator actually operates, rather than a colocation cage it merely rents to the same hyperscalers. The fibre deal is booked. The ladder question is still open, and it will be answered in the buildings, not on the routes.

I wrote a fortnight ago that the operators who will be interesting in 2030 are not the ones with the most GPUs but the ones who can still tell you which of the three flows each dollar came from. Verizon has just given the cleanest demonstration yet of the discipline: a fabric dollar and a location dollar, named separately, on the same call. The test now is whether it keeps them separate all the way up the ladder, or whether the word platform arrives before the platform does.