Executive Summary
Europe’s terrorist threat is not rising uniformly; it is becoming more fragmented, technologically accelerated and operationally unpredictable.
The EU recorded 45 attacks in 2025, including 22 completed, 20 foiled and three failed attacks; 486 suspects were arrested, 71% for jihadism-related offences.
The principal near-term danger remains low-complexity jihadist violence by self-initiated actors using knives, vehicles, arson or improvised explosives.
A second risk layer comes from violent right-wing, left-wing, anarchist and anti-system milieus whose narratives increasingly overlap online.
A third layer involves state-enabled proxies, sabotage, cyber operations and clandestine financing, particularly around Russia–NATO confrontation and Middle Eastern escalation.
France and Germany possess the highest combination of target density, extremist populations, symbolic exposure and recent lethal incidents.
Italy and Spain retain comparatively strong preventive records, but face expanding pressure from online radicalisation, logistical transit, prisons, financing networks and Mediterranean instability.
The most likely 2026–2031 outcome is recurrent small-scale violence rather than a sustained campaign of centrally directed mass-casualty attacks.
The highest-impact scenario is simultaneous physical, cyber and proxy disruption affecting transport, energy, public events, Jewish or Israeli interests and government institutions.
Analytic confidence: high on persistent threat; moderate on geographic concentration; low-to-moderate on timing and modality of individual attacks.
Europe’s New Terror Frontier: AI, Proxy Wars and the Battle for Critical Systems
Europe is not facing a simple return of the terrorist cycle that culminated in Paris, Brussels and Berlin a decade ago. The emerging threat is more fragmented, technologically accelerated and strategically entangled with the wars in Ukraine and the Middle East. Religious extremists, racial accelerationists, anarchist saboteurs, criminal contractors and foreign-state proxies increasingly operate through the same encrypted platforms, payment channels and digital service markets. Artificial intelligence does not create ideological commitment, but it compresses the distance between grievance and action: it translates propaganda, fabricates identities, automates reconnaissance and magnifies the political impact of violence. The central European security question is therefore changing. It is no longer only who may attack, but how a small actor can exploit digital infrastructure, international conflict and social polarisation to produce consequences far greater than the physical operation itself.
A Threat That Has Changed Form
Europol’s EU Terrorism Situation and Trend Report 2026, published on 13 July 2026, recorded 45 terrorist attacks in ten EU Member States during 2025, comprising 22 completed attacks, 20 foiled plots and three failed attempts. Authorities arrested 486 suspects in 21 Member States; 347 arrests, or 71%, concerned jihadist terrorism. The numbers describe a threat that remains substantial but is no longer concentrated exclusively in structured organisations. Europol identifies online ecosystems as a decisive accelerant: ideology still matters, but violence itself increasingly provides identity, recognition and belonging to individuals moving between jihadism, extreme-right subcultures, misogyny, conspiracism and fascination with mass casualties.
The operational centre of gravity is shifting from the hierarchical cell to the digitally assembled micro-network. One participant may distribute propaganda, another provide money, a third offer technical knowledge and a fourth carry out the attack without any member possessing the complete plan. Encryption, disposable accounts and compartmented relationships reduce the visibility of the network, while commercially available technology lowers the threshold for participation. The most probable violence will remain comparatively unsophisticated—attacks by isolated individuals or very small groups against accessible targets—but the surrounding system is becoming more complex. A simple physical attack can now be accompanied by synthetic declarations, fabricated footage, automated amplification and false attribution designed to turn an isolated crime into a continental political crisis.
Germany and France at the Core
Germany combines Europe’s largest multi-ideological extremist environment with dense transport systems, defence industries, energy networks and highly visible public events. The Federal Office for the Protection of the Constitution estimated in its 2024 assessment an Islamist milieu of 28,280 people, including 9,540 classified as violence-oriented. It also counted 50,250 right-wing extremists, of whom 15,300 were violence-oriented, and 38,000 left-wing extremists, including 11,200 considered violence-oriented. German intelligence describes the Islamist terrorist threat as persistently high and identifies the Islamic State’s Khorasan branch, ISKP, as the organisation’s most relevant regional affiliate for Europe. It also notes two recurring operational models: trained groups capable of complex attacks and self-directed individuals using readily available means after online recruitment or propaganda exposure.
France remains the EU’s most historically saturated jihadist theatre. The DGSI reports 275 people killed in terrorist attacks since 2012 and 16 attack projects disrupted since 2024, seven of them during 2025. The French exposure is structural: Paris concentrates political, diplomatic, cultural and media symbols, while the country carries the legacy of large Syria–Iraq networks, prison radicalisation and repeated attacks that continue to provide models for imitation. The decline of the Islamic State’s territorial command did not eliminate the threat; it redistributed it. French intelligence now confronts an endogenous environment in which external conflicts activate individuals already present in the country, often without a formal organisational connection.
Italy and Spain: Prevention Under Pressure
Italy’s relative success in preventing mass-casualty jihadist attacks should not be confused with low strategic exposure. Rome, the Vatican, NATO and US facilities, ports, energy terminals, defence companies and globally recognised tourist locations create one of Europe’s widest target surfaces. On 2 March 2026, Interior Minister Matteo Piantedosi convened the National Committee for Public Order and Security and ordered reinforcement of national protective measures amid the deteriorating international environment. The Interior Ministry stated that more than 28,000 sensitive sites were under surveillance, with immediate strengthening around assets connected to states involved in current conflicts. Meetings of the Strategic Counterterrorism Analysis Committee were also intensified.
Spain combines a similarly mature preventive architecture with deeper accumulated jihadist experience. Official Interior Ministry data updated on 23 June 2026 recorded 458 counter-jihadist operations and 816 arrests since 2012. For 2026 alone, data updated on 2 June showed 33 operations and 56 arrests. Madrid, Barcelona, Andalusia, the Mediterranean coast, Ceuta and Melilla remain central to the investigative map, but the relevant risk is not migration as such. It is the intersection of documented extremist relationships, financing, propaganda production, logistical facilitation and target-specific preparation. Spain’s large tourism economy creates an additional vulnerability: transport, sporting events, nightlife and heritage locations combine symbolic value with dense civilian presence.
The Wars Enter Europe
The wars surrounding Europe are no longer external variables. The conflict in Gaza and the wider Middle Eastern escalation create mobilisation narratives for jihadist actors, antisemitic extremists and foreign intelligence networks. The war in Ukraine produces a different but increasingly convergent threat: sabotage, cyber operations, pressure on defence logistics and recruitment of criminal intermediaries. On 16 March 2026, the Council of the EU formally condemned persistent hybrid activities by state and non-state actors, including sabotage against critical infrastructure, malicious cyber activity, information manipulation, election interference and the instrumentalisation of migration. The Council specifically denounced Russia and its proxies for coordinated campaigns intended to weaken European security and support for Ukraine.
This convergence changes the meaning of targeting. A terrorist organisation may attack a religious institution to provoke communal retaliation. A violent-right actor may attack a minority community to accelerate social conflict. An insurrectionist group may damage transport or energy infrastructure to increase the cost of a political decision. A foreign service may contract a criminal to attack the same infrastructure for geopolitical leverage while preserving deniability. The physical act can appear identical; the strategic purpose is not. Europe’s security services must therefore integrate counterterrorism, counterintelligence, organised-crime analysis and infrastructure protection without erasing the legal distinctions among terrorism, sabotage, espionage and ordinary criminality.
Artificial Intelligence as Force Multiplier
The European Commission’s new ProtectEU counterterrorism agenda, presented on 26 February 2026, explicitly identifies social media, artificial intelligence, drones, crypto-assets and 3D-printed weapons as technologies reshaping terrorist activity. The agenda calls for stronger Europol open-source intelligence capabilities, faster lawful access to data, better cryptocurrency tracing, reinforced cooperation with Mediterranean and Western Balkan partners and €30 million for projects protecting public spaces.
AI’s greatest immediate value to hostile actors is not the autonomous execution of attacks. It is the industrialisation of enabling functions. Generative systems can localise propaganda for a German teenager, impersonate an Italian official, fabricate a French police communication, automate donor engagement in Spain or produce false evidence blaming another community after an attack. They can accelerate open-source research into institutions, suppliers and public events, while synthetic identities can support fraud and recruitment. Yet AI also creates vulnerabilities for the user: unreliable technical output, detectable patterns and large volumes of low-quality material. The strategic contest will therefore concern integration. A disciplined state service combining AI with human access, criminal logistics and intelligence collection is far more dangerous than an isolated extremist merely consulting a chatbot.
The Infrastructure Target
The most consequential European target is increasingly not a landmark but a dependency. Electricity sustains telecommunications, hospitals, payment systems and water treatment. Cloud and digital-identity providers support thousands of public and private organisations. Ports connect energy imports, customs, military mobility and commercial supply chains. Railways carry commuters, freight and defence material. Undersea cables and data centres support the digital economy on which the physical economy now depends.
ENISA’s Threat Landscape 2025, published on 1 October 2025, analysed 4,875 cyber incidents occurring between 1 July 2024 and 30 June 2025. The agency concluded that diverse threat groups increasingly reuse tools and collaborate against Europe’s digital infrastructure. These figures do not represent terrorist attacks, but they define the crowded cyber environment within which terrorist, criminal and state capabilities may converge.
The dangerous future operation is therefore blended: stolen credentials create confusion, physical interference disrupts service, synthetic media exaggerates the failure and competing claims delay attribution. A terrorist actor may seek spectacle; a state proxy may prefer an obscure node whose disruption imposes economic cost without revealing the sponsor. Europe must protect both.
Money Without a Signature
The financial architecture is evolving in the same direction. Terrorist financing no longer depends on one identifiable channel. Personal savings, consumer credit, cash couriers, informal transfer systems, online payments, crowdfunding, prepaid instruments and virtual assets can be combined in a single operation. Small attacks may cost too little to generate conventional anti-money-laundering alerts; large organisations can distribute transactions across jurisdictions and intermediaries.
The key analytic shift is from transaction size to network behaviour: repeated low-value transfers, abrupt conversion between instruments, donation campaigns linked to military crises, identity reuse and connections between payments, travel and procurement. Excessive financial exclusion would be counterproductive because it can push legitimate communities and charities outside regulated systems. The objective must be precision—faster cooperation among financial-intelligence units, banks, payment platforms, virtual-asset providers and investigators—rather than indiscriminate restriction.
The 2031 Security Equation
Through 2031, the most probable European scenario is recurrent fragmented violence: jihadist lone actors, violent-right accelerationists, anti-state extremists and mixed-ideology perpetrators selecting accessible civilian, communal or governmental targets. The highest-impact scenario is different: a coordinated attack or sabotage campaign combining encrypted micro-networks, criminal subcontractors, AI-assisted deception and interference with transport, energy or communications.
France, Germany and the United Kingdom will remain the principal high-consequence theatres because of population scale, accumulated networks and target density. Belgium, the Netherlands and Austria will retain disproportionate importance as institutional, financial and transport junctions. Italy and Spain will remain prevention-intensive Mediterranean front lines. Scandinavia, Poland and the Baltic states will face the fastest growth in terrorism–crime–proxy convergence because of Russian pressure and the availability of deniable intermediaries.
Europe’s vulnerability is fragmentation; its answer must be integration. The decisive institutions will be those capable of connecting a suspicious payment to a foreign contact, an encrypted relationship to physical reconnaissance, a cyber intrusion to an insider and an attack claim to a coordinated influence campaign. The objective is not to militarise daily life. It is to deny hostile actors the multiplier they seek: the conversion of limited violence into systemic economic damage, communal fracture and political paralysis.
Navigational Index
Pillar I — Human threat architecture
Jihadist mobilisation, violent right-wing accelerationism, left-wing sabotage, mixed ideologies, minors, lone actors and digitally assembled micro-networks.
Europe’s Next Terror Cycle: Adaptive Actors, AI and Strategic Targeting
Pillar II — Geographic exposure
Comparative assessment of Germany, France, Italy, Spain, the United Kingdom, Belgium, the Netherlands, Austria, Scandinavia, Central Europe, the Balkans and the Baltic region.
Pillar III — Five-year convergence
Artificial intelligence, encrypted ecosystems, proxy warfare, cyber-physical sabotage, terrorist financing, critical infrastructure and probabilistic scenarios through 2031.
Master Abstract
Europe entered the second half of 2026 with a terrorist environment that is more diffuse than the organisationally concentrated threat seen during the territorial expansion of the so-called Islamic State, but not necessarily less dangerous. The central change is structural: mobilisation increasingly occurs through dispersed online ecosystems in which propaganda, grievance, identity formation, tactical instruction and interpersonal validation can converge without formal membership in a terrorist organisation. Europol reported 45 terrorist attacks across ten EU Member States during 2025, comprising 22 completed attacks, 20 foiled plots and three failed attempts. Authorities arrested 486 suspects across 21 Member States, with 71% of the arrests connected to jihadism; jihadist attacks caused five fatalities and 81 injuries. Europol’s interpretation is especially important because it identifies not simply ideological persistence but a larger pool of potential perpetrators for whom violence can generate recognition, identity and belonging. This reduces the explanatory power of rigid labels such as jihadist, right-wing or anti-system actor: individuals can consume mutually contradictory narratives while remaining united by fascination with violence, personal crisis, antisemitism, misogyny, institutional hatred or the desire for notoriety. European Union Terrorism Situation and Trend Report 2026 – Europol – July 2026 — Verified official publication. Europol further warns that hybrid actors may employ criminal facilitators and proxies to produce persistent, cumulative disruption rather than a single spectacular attack. When Violence Shapes Identities in a Larger Pool of Perpetrators – Europol – July 2026 — Verified official assessment. This report therefore distinguishes terrorist violence, extremist violence, state-sponsored sabotage and cyber-enabled destabilisation analytically, while recognising that their operational boundaries are eroding. The claim supplied in the task that German Interior Minister Alexander Dobrindt formally increased a national terrorist threat level on 18 July 2026 could not be corroborated through an accessible German federal primary-source publication during this verification session and is consequently not treated as an established fact. Germany does not publicly communicate a single national alert scale equivalent to the British or Spanish systems; its agencies instead publish differentiated threat assessments and operational security measures.
The country-level picture reveals unequal exposure rather than a single European trajectory. Germany combines high demographic scale, dense public transport, major Christmas markets, defence and industrial infrastructure, extensive Jewish and Israeli target sets and multiple extremist ecosystems. The Federal Office for the Protection of the Constitution assesses the danger from Islamist terrorism as persistently high and identifies Islamic State networks—particularly Islamic State Khorasan Province, ISKP—as the most relevant jihadist danger to Germany and Europe. It estimates an Islamist milieu of 28,280 persons, including approximately 9,540 violence-oriented individuals, while the violent right-wing extremist population reached 15,300 in 2024. Verfassungsschutzbericht 2024 – Bundesamt für Verfassungsschutz – June 2025 — Verified official report. German authorities explicitly warn that readily accessible weapons, including knives and vehicles, can be employed against soft targets with limited preparation. The Continuing Consequences of 7 October 2023 for Germany’s Security – Bundesamt für Verfassungsschutz – October 2025 — Verified official assessment. France remains Europe’s most historically burdened jihadist theatre: the DGSI records 275 deaths from terrorist attacks since 2012 and states that it disrupted 16 attack projects from 2024 onward, including seven during 2025. L’état de la menace terroriste en France – Direction générale de la sécurité intérieure – updated institutional assessment — Verified official threat page. The French Gendarmerie’s research centre describes 2025 as a year of substantial terrorist activity and diversification across jihadist, extreme-left, extreme-right and emergent radical milieus. Terrorisme en France: Panorama des mouvances radicales en 2025 – Gendarmerie nationale, CRGN – 2026 — Verified official analysis. The French risk profile is amplified by target symbolism, the legacy of previous networks, external operations, prison radicalisation and extreme polarisation around religion, identity and the Middle East. The resulting baseline judgement is that France and Germany remain the EU’s most exposed large states, although a lethal event can occur in any jurisdiction where an online-mobilised individual encounters a vulnerable target and minimal operational friction.
Italy and Spain constitute a different risk category: both face persistent jihadist and foreign-influence pressure, yet their recent security records indicate comparatively effective prevention and intelligence-led disruption. Italy’s exposure derives from Rome’s religious and governmental symbolism, United States and NATO facilities, ports and energy terminals, the presence of Jewish and Israeli interests, migration and smuggling corridors, organised-crime capabilities, radicalisation in prisons and online networks, and the country’s proximity to North Africa, the Sahel and the central Mediterranean. In June 2025, following deterioration in the Middle Eastern environment, the Italian Interior Ministry reported enhanced preventive measures covering more than 29,000 monitored sites, including over 10,000 critical infrastructures and approximately 1,000 sites connected to United States or Israeli interests. Comitato nazionale per l’ordine e la sicurezza pubblica – Ministero dell’Interno – June 2025 — Verified official communiqué. Italy’s 2026 intelligence framework also describes contemporary threats as pervasive, multidimensional and technologically driven rather than limited to visible attacks. Relazione annuale sulla politica dell’informazione per la sicurezza 2026 – Sistema di informazione per la sicurezza della Repubblica – March 2026 — Verified official publication portal. Spain remains at Level 4, high risk, within a five-level antiterrorism alert structure whose measures protect physical infrastructure, information systems, public institutions, strategic sectors and high-impact symbolic targets. Nivel de Alerta Antiterrorista – Ministerio del Interior – current verified framework — Verified official alert page. By 23 June 2026, Spanish authorities reported 458 counter-jihadist operations and 816 arrests since 2012; during 2026 alone, the ministry recorded 33 operations and 56 arrests by early June. Mapa de operaciones y detenidos por yihadismo – Ministerio del Interior – June 2026 — Verified official dataset. These figures should not be interpreted as direct measures of imminent attack probability: arrest totals reflect investigative intensity, legal thresholds and network disruption as much as underlying threat volume. Nevertheless, the acceleration from 758 arrests recorded in February 2026 to 816 by late June indicates sustained operational pressure. Italy and Spain are therefore unlikely to remain peripheral. Their principal risks through 2031 are digitally radicalised individuals, logistical or financial support structures, attacks against tourism or religious targets, prison-linked recruitment, and spillover from Maghreb–Sahel instability rather than large territorially rooted clandestine organisations.
The remainder of Europe forms interconnected secondary theatres. The United Kingdom, although outside the EU, is indispensable to the continental assessment because of its intelligence reach, transport connections, Iranian and jihadist targeting history and large symbolic target surface. In May 2026, the British government publicly announced an increase in the national terrorism threat level while citing the combined seriousness of terrorist and hostile-state activity, including attacks directed against British Jews and opponents of the Iranian regime. National Security Developments and the National Threat Level – UK Home Office – May 2026 — Verified official parliamentary statement. Belgium, the Netherlands and Austria remain disproportionately important because of EU and NATO institutions, international transport nodes, established extremist networks and earlier ISKP-linked investigations. Scandinavian states combine comparatively low attack frequency with growing concern over hostile-state influence, Quran-burning controversies, antisemitic mobilisation, gang access to firearms and the possibility that criminal intermediaries may be recruited for proxy violence. Poland, the Czech Republic, Romania, Bulgaria, the Baltic states and Finland face a different configuration in which terrorism must be assessed alongside Russian sabotage, reconnaissance, cyber operations, border pressure and attacks on military-logistics systems. The Western Balkans remain relevant as a corridor for weapons, forged documents, criminal services and movement between the EU, Türkiye and the Middle East, but simplistic assumptions that migration itself predicts terrorism are analytically unsound. The more useful variables are prior violence, digital network centrality, contact with facilitators, target reconnaissance, acquisition behaviour, unexplained financial flows and abrupt changes in operational security. Under an Analysis of Competing Hypotheses framework, five explanations compete: H₁, a renewed centrally directed jihadist campaign; H₂, persistent self-initiated attacks; H₃, ideologically mixed online violence; H₄, state-sponsored proxy or sabotage activity disguised as extremism or crime; and H₅, statistical volatility without a durable increase. Current evidence gives the greatest posterior weight to H₂, followed by H₄ and H₃. H₁ remains lower-probability but highest consequence, while H₅ cannot explain the expanding diversity of actors, the volume of disrupted plotting and official warnings about hybridisation. This weighting is an analytic judgement, not an official forecast.
The five-year outlook from 2026 to 2031 is best modelled as a distribution of interacting risks rather than a deterministic prediction. A qualitative Bayesian baseline assigns approximately 57% probability to a persistent-fragmentation scenario in which Europe experiences recurrent knife, vehicle, arson, firearm or improvised explosive attacks, mostly perpetrated by lone actors or very small cells; 21% to a hybrid-escalation scenario involving hostile-state proxies, sabotage, cyber disruption and criminal subcontractors; 13% to a renewed networked-jihadist scenario involving externally facilitated or remotely directed multi-actor plotting; and 9% to a partial-de-escalation scenario driven by effective prevention, reduced Middle Eastern mobilisation and degradation of online networks. These values are structured estimates derived from official indicators, not observed frequencies. Monte Carlo implementation should treat Middle Eastern escalation, ISKP external-operational capability, Russian confrontation with NATO, extremist online reach, youth radicalisation, illegal weapons access, intelligence cooperation and economic or political shocks as correlated variables rather than independent inputs. The decisive technological multiplier will be AI-assisted mobilisation: automated translation, synthetic voices, persuasive micro-targeting, rapid propaganda generation, target research, reconnaissance support and instructions tailored to low-skill perpetrators. AI will not automatically produce operational competence, but it can shorten the path between grievance and intent, overwhelm moderation systems and enable a single propagandist to serve multiple linguistic communities. Simultaneously, security agencies will use entity resolution, behavioural anomaly detection, financial intelligence and multilingual content triage to reduce investigative latency. The outcome will be an adversarial detection cycle in which false positives, privacy constraints and data fragmentation become strategic vulnerabilities. The most dangerous “shadow” dimension is the merger of terrorist intent with capabilities obtained from criminal markets or state sponsors: forged identity documents, cryptocurrency laundering, prepaid instruments, hawala transfers, drone components, commercial surveillance data, incendiary materials and insiders with access to transport, energy or telecommunications systems. Europe’s primary challenge is consequently no longer merely to identify members of organisations; it is to detect temporary alignments among individuals, algorithms, money, criminal logistics and geopolitical patrons before those alignments become attacks.
Multi-Domain Terror Risk Codex
Europe’s Human Threat Architecture: Radicalisation Without Organisations
The central transformation in European terrorism is not a simple increase in the number of militants, attacks or extremist organisations. It is the erosion of the organisational threshold that once separated ideological sympathy from operational violence. In the earlier Islamic State cycle, European services could concentrate heavily on travel patterns, foreign-fighter networks, mosque-based clusters, identifiable facilitators, structured propaganda outlets and communications linking European cells to command nodes in Syria or Iraq. By 2025–2026, that model had not disappeared, but it had been overlaid by a radically more atomised architecture in which an individual can acquire ideological fragments, target-selection cues, emotional reinforcement, rudimentary operational knowledge and peer recognition without entering a stable organisation. Europol recorded 45 terrorist attacks in ten EU Member States during 2025, including 22 completed attacks, 20 foiled plots and three failed attacks. Of 486 terrorism-related arrests across 21 Member States, 347, or 71%, concerned jihadist terrorism; jihadist actors were linked to 24 of the 45 attacks, while jihadist violence caused five deaths and 81 injuries. More than 70% of jihadism-related arrests concerned propaganda, recruitment, glorification, financing or support rather than the final execution of attacks, indicating that European counter-terrorism increasingly intervenes in the mobilisation chain before weapon acquisition or target approach. The most strategically significant figure, however, concerns age: 130 terrorism suspects arrested in the EU in 2025 were aged 18 or younger, with the youngest only 12 years old. Europol identifies gaming environments, violent digital subcultures, extremist propaganda repositories and loosely moderated social platforms as overlapping spaces in which minors may simultaneously appear as manipulated victims, propagandists, recruiters, technical enablers and prospective perpetrators. This is not equivalent to claiming that gaming communities or social media users are inherently radicalising environments. The operative risk arises where algorithmic repetition, private-group migration, status competition, interpersonal coercion and exposure to graphic violence combine with personal crisis and a perceived pathway to significance. European Union Terrorism Situation and Trend Report 2026 – Europol – July 2026 — official publication; When Violence Shapes Identities in a Larger Pool of Perpetrators – Europol – July 2026 — official assessment.
| EU human-threat indicator | 2024 reference year | 2025 reference year | Intelligence implication |
|---|---|---|---|
| Reported terrorist attacks | 58 | 45 | Lower annual total does not imply lower mobilisation; completed and disrupted activity remain geographically dispersed |
| Terrorism-related arrests | 449 | 486 | Investigative pressure and pre-operational disruption increased |
| Jihadist-linked attacks | Not directly comparable here | 24 | Jihadism remained the dominant lethal terrorist category |
| Jihadism-related arrests | Not directly comparable here | 347 | Support, propaganda and mobilisation networks remain substantially larger than attacker populations |
| Suspects aged 18 or younger | Not published in the cited summary | 130 | Minors are no longer a marginal subgroup |
| Youngest arrested suspect | Not published in the cited summary | 12 years | Safeguarding and counter-terrorism thresholds increasingly overlap |
| Links referred during Europol minors action day | — | More than 2,000 | Propaganda targeting youth is multi-ideological and industrially reproducible |
The jihadist component remains the most operationally consequential because it combines a persistent transnational ideological brand, multilingual propaganda, conflict-driven emotional triggers, veteran knowledge, prison constituencies and the continuing ambition of organisations such as the Islamic State and Al-Qaeda to inspire or facilitate attacks in Europe. Yet contemporary jihadist mobilisation increasingly resembles a modular service environment rather than a conventional chain of command. One actor translates content; another maintains an archive; a third produces visual material; a fourth circulates target imagery; a fifth privately encourages an unstable individual to act. None must possess a complete operational picture. This modularity complicates legal attribution and early warning because propaganda consumption, ideological endorsement, technical preparation and attack intent may reside in separate accounts, platforms or jurisdictions. German authorities assess an Islamist extremist population of approximately 28,000, roughly one-third of whom are regarded as violence-oriented. Germany’s domestic intelligence service specifically identifies the exploitation of the Gaza war and broader Middle Eastern conflict narratives as a mechanism through which Islamic State propaganda reaches younger audiences. The German service also documented several disrupted plots involving minors, including four youths aged 15 and 16 arrested in March and April 2024 over alleged online coordination of attacks against Christian and Jewish sites in the Iserlohn area. Islamismus und islamistischer Terrorismus – Bundesamt für Verfassungsschutz – June 2025 — official assessment; Statement zur Vorstellung des Verfassungsschutzberichts 2024 – Bundesamt für Verfassungsschutz – June 2025 — official statement. France illustrates a different but complementary risk structure. The DGSI reports 275 terrorism deaths since 2012, 16 disrupted attack projects since 2024, including seven during 2025, nearly 400 prisoners incarcerated for terrorism offences, and more than 400 additional prisoners convicted of other crimes but assessed as radicalised. This creates an enduring surveillance and reintegration burden that extends beyond sentence completion. French intelligence emphasises that many recent attackers were not organisationally affiliated but mobilised through perceived religious insult, personal grievance or rapidly escalating outrage. L’état de la menace terroriste en France – Direction générale de la sécurité intérieure – current institutional assessment — official source.
The minor and young-adult problem requires a separate analytic model because conventional extremist profiling performs poorly when identity is still fluid, ideology is shallow and violence itself supplies the principal source of belonging. Europol’s May 2025 referral action against terrorist material targeting minors identified and referred more than 2,000 online links associated with jihadist and violent right-wing propaganda in a single coordinated operation. Europol Coordinates Operation Against Terrorist Content Online Targeting Minors – Europol – June 2025 — official operational release. Spain provides concrete examples of how this progression can occur. Spanish authorities have arrested minors who moved from consuming propaganda to operating their own jihadist media entities, designing logos, administering social-media profiles and using communications servers associated with gaming environments to indoctrinate others. In another case, three minors arrested in Madrid and Barcelona allegedly acquired instructions for producing TATP, distributed responsibilities and discussed potential targets. In January 2026, police in Álava detained another minor who reportedly possessed bladed weapons, a replica handgun and a balaclava after an advanced process of online self-radicalisation. La Guardia Civil detiene a dos menores por terrorismo a través del entorno virtual – Ministerio del Interior de España – December 2023 — official release; La Policía Nacional detiene a tres menores altamente radicalizados – Ministerio del Interior de España – December 2023 — official release; Detenido un menor muy radicalizado afín a DAESH – Ministerio del Interior de España – January 2026 — official release. The British prevention dataset confirms that the youth dimension extends beyond jihadism. During the year ending March 2025, England and Wales recorded 8,759 Prevent referrals where age was known; persons aged 11–15 accounted for 3,192 referrals, or 36%, and the same age group represented 39% of the 1,472 cases adopted into Channel. Education generated 3,129 referrals, or 36%, while police generated 2,631, or 30%. These are safeguarding and prevention statistics rather than proven terrorism cases, but they reveal where behavioural warning signals are being detected and which institutions carry the screening burden. Individuals Referred to and Supported Through the Prevent Programme, April 2024 to March 2025 – UK Home Office – November 2025 — official statistics.
The violent right-wing threat is evolving through a parallel process of organisational decay and networked acceleration. Germany illustrates both the scale and the changing morphology. The German domestic intelligence service estimated 50,250 right-wing extremists at the end of 2024, up from 40,600 in 2023, while the violence-oriented subset increased from 14,500 to 15,300. Authorities registered 37,835 right-wing extremist offences in 2024, a 47.4% increase from 25,660 in 2023, while recorded violent offences rose 11.6%, from 1,148 to 1,281. Rechtsextremismus und rechtsextremistischer Terrorismus – Bundesamt für Verfassungsschutz – June 2025 — official assessment; Zahlen und Fakten: Rechtsextremismus – Bundesamt für Verfassungsschutz – 2025 — official statistics. The numerical increase is important, but the qualitative change is more consequential: German authorities report young, frequently underage actors who radicalise within violent online subcultures without meaningful attachment to established neo-Nazi parties or traditional skinhead organisations. These actors may combine ethnonationalism, antisemitism, misogyny, anti-LGBTQ hostility, admiration for mass shooters, “Siege” accelerationism and fantasies of societal collapse. Their ideological incoherence does not necessarily reduce danger; it can remove organisational discipline and lower inhibitions against indiscriminate violence. The British dataset offers a comparable signal. Extreme right-wing concerns accounted for 1,798 Prevent referrals in 2024–2025, up 37% from 1,314 the previous year, and represented 612 of 1,464 Channel adoptions with a specified concern, or 42%. Islamist concerns accounted for 870 referrals and 226 Channel adoptions. These datasets cannot be compared directly with terrorism arrests because Prevent measures vulnerability and mobilisation concerns rather than criminal culpability. Nevertheless, the sustained predominance of violent right-wing referrals among adopted Channel cases indicates that accelerationist, racial-nationalist and mass-casualty cultures form a major intervention burden. The most dangerous right-wing topology over the next five years is not likely to be a disciplined national party secretly directing terrorism. It is more likely to be a transnational constellation of encrypted channels, propagandists, aesthetic communities, weapons enthusiasts and very small affinity groups in which manifestos, attack footage and perpetrator mythology function as reusable mobilisation packages.
| Right-wing mobilisation variable | Observable European pattern | Five-year risk effect |
| Organisational attachment | Declining relevance for the youngest violent actors | Fewer penetrable hierarchies and fewer reliable membership indicators |
| Ideological coherence | Increasingly mixed with misogyny, nihilism and mass-shooter fascination | Higher false-negative risk when analysts search only for orthodox neo-Nazism |
| Platform ecology | Movement from open social media into private channels and closed communities | Faster regeneration after removals and bans |
| Age profile | Growing presence of teenagers and young adults | Greater safeguarding burden and shorter mobilisation periods |
| Tactical repertoire | Knives, firearms where available, arson, vehicle attacks, explosives research | Persistent low-complexity threat with occasional mass-casualty ambition |
| Target selection | Minorities, migrants, religious sites, politicians, Pride events, schools | Broad and event-driven target surface |
| Strategic objective | Provocation, imitation, polarisation and social breakdown | Individual attacks can create effects disproportionate to organisational capacity |
Left-wing and anarchist violence remains less lethal than jihadist terrorism at the European level but should not be analytically minimised, especially in Germany, Italy, France, Spain, Greece and parts of northern Europe where militant infrastructures, squatting environments, prisoner-solidarity networks and issue-based mobilisation can support arson, sabotage and attacks against police, defence companies, rail systems, energy infrastructure, telecommunications and construction projects. Germany estimated 38,000 left-wing extremists in 2024, including 11,200 violence-oriented actors, with approximately 8,600 classified as autonomous militants. Zahlen und Fakten: Linksextremismus – Bundesamt für Verfassungsschutz – 2025 — official statistics. German intelligence identifies campaigns such as “Switch Off”, which explicitly encourage offences against infrastructure and corporate targets, as mechanisms for decentralising sabotage while reducing the need for permanent clandestine organisations. Linksextremismus – Bundesamt für Verfassungsschutz – June 2025 — official assessment. The central analytical distinction is between protest, civil disobedience, criminal damage, extremist violence and terrorism. Conflating these categories would inflate the terrorist threat and undermine legitimate political activity; separating them too rigidly, however, can obscure escalation pathways in which a small militant component uses a broader protest ecosystem for concealment, target intelligence, logistical support or recruitment. Left-wing sabotage networks typically possess several advantages over impulsive lone actors: familiarity with operational security, experience conducting reconnaissance, knowledge of infrastructure vulnerabilities and access to intergenerational movement memory. Their weaknesses are equally clear: limited popular support for indiscriminate violence, ideological disputes, surveillance penetration and a frequent preference for property destruction over casualties. Over the 2026–2031 period, the highest-probability left-wing threat is therefore not a return to the large hierarchical terrorist formations of the 1970s. It is persistent, decentralised sabotage against energy, logistics, digital infrastructure, defence production and politically symbolic commercial assets. A more severe scenario would emerge if climate militancy, anti-war mobilisation, pro-Palestinian activism and anti-capitalist networks produced a small clandestine subset willing to accept serious human casualties. Current official evidence supports monitoring that pathway but does not establish it as the baseline. The January 2026 disruption of electricity in Berlin—irrespective of the final legal classification of every associated act—illustrates the systemic effect that a relatively small physical intervention can produce when directed against highly connected urban infrastructure.
The most difficult category for intelligence services is the mixed, unstable or unclear actor: a person whose worldview moves among jihadism, extreme-right mythology, incel grievance, conspiracy narratives, satanic or occult imagery, school-shooter admiration, anti-government hostility and undifferentiated fascination with mass violence. The United Kingdom’s Prevent system introduced 16 concern categories from April 2024, including Islamist extremism, extreme right-wing extremism, left-wing extremism, anarchist extremism, environmental extremism, incel extremism, multiple ideologies, fascination with extreme violence or mass-casualty attacks, and cases in which no ideology is identified. During 2024–2025, 4,917 of 8,769 referrals with a specified concern, or 56%, fell into the two “no ideology” categories. Another 469 referrals, or 5%, involved fascination with extreme violence or mass-casualty attacks without another identified ideology; this category rose 240% quarter-on-quarter, from 82 referrals in October–December 2024 to 279 in January–March 2025. There were 424 multiple-ideology referrals, 66 incel-extremism referrals, 21 left-wing referrals, and smaller numbers in other categories. Adoption rates provide a more discriminating indicator than raw referrals: 34% of extreme-right referrals, 32% of incel referrals, 29% of left-wing referrals, 27% of mass-casualty-fascination referrals and 26% of Islamist referrals were adopted as Channel cases. Individuals Referred to and Supported Through the Prevent Programme – UK Home Office – November 2025 — official statistics. These figures demonstrate why ideological classification can no longer serve as the sole early-warning architecture. A subject may display no settled doctrine yet still exhibit a dangerous convergence of leakage, target fixation, weapons research, farewell messaging, attack rehearsal and a desire for notoriety. Conversely, intense political or religious expression without capability, intent or attack-related behaviour should not be treated as evidence of terrorist mobilisation. The analytic unit must therefore shift from declared identity to behavioural trajectory. Ideology remains relevant because it shapes target choice, moral justification and network access, but the decisive warning indicators are movement from passive consumption to production, from public posting to closed coordination, from abstract hatred to target-specific reconnaissance, and from fantasy to resource acquisition.
Lone actors and digitally assembled micro-networks occupy the operational centre of gravity because they reduce exposure to traditional intelligence collection while retaining access to transnational ideological and technical resources. “Lone actor” is frequently a misleading term: many nominally solitary perpetrators are socially embedded online, receive encouragement, imitate previous attackers, use remotely supplied propaganda or communicate with facilitators who never obtain full command authority. The more precise unit is the low-signature attack system, comprising one prospective attacker, several weak digital ties, a propaganda environment, commercially available technology and a target opportunity. Spain’s recent cases illustrate different forms of this system. In March 2025, authorities arrested a suspect in Granada who allegedly used bots to reach terrorist content and whose brother had died in Syria as an Islamic State foreign fighter. In February 2026, Spanish police arrested a suspect in Madrid who reportedly used public Wi-Fi networks to access jihadist repositories and evade attribution; the Interior Ministry stated that the National Police alone had made 66 jihadism-related arrests during 2025, which it described as a record. Another suspect arrested in Martorell in August 2025 had reportedly undergone behavioural change, consumed extremist content linked to the Gaza conflict and possessed a bladed weapon when investigators acted. Detenido un yihadista en Granada que manejaba bots – Ministerio del Interior de España – March 2025 — official release; Detenido en Madrid utilizando redes Wi-Fi públicas – Ministerio del Interior de España – February 2026 — official release; Detenido en Martorell por actividades vinculadas al terrorismo yihadista – Ministerio del Interior de España – August 2025 — official release. Italy confronts the same low-signature environment through cyber-monitoring, infrastructure protection and disruption of propaganda access. The Italian Postal Police reported that more than 2,300 websites or online resources associated with cyberterrorism were blocked during 2024, while operating through a network of 100 territorial offices. 144 arresti per pedopornografia e oltre 2.300 siti oscurati per cyberterrorismo – Ministero dell’Interno – January 2025 — official report. These interventions reveal a threat environment in which digital investigation, behavioural analysis and conventional human intelligence must be fused continuously rather than sequentially.
| Analytic hypothesis | Description | Prior probability | 2031 posterior estimate | Principal confirming indicators | Principal disconfirming indicators |
| H₁ | Jihadist organisations restore centrally directed European attack cells | 12% | 14% | External-operations facilitators, travel coordination, professional explosives, multi-target command | Continued dominance of spontaneous low-complexity attacks |
| H₂ | Self-initiated jihadist and mixed-ideology actors dominate | 42% | 38% | Minors, propaganda arrests, knives, vehicles, superficial ideology, short mobilisation | Sustained decline in youth cases and online mobilisation |
| H₃ | Violent right-wing accelerationism becomes the fastest-growing domestic threat | 20% | 23% | Rising youth networks, manifesto culture, weapons access, minority targeting | Falling violent-right recruitment and fewer attack preparations |
| H₄ | Left-wing sabotage expands against infrastructure without broad lethal escalation | 12% | 13% | Arson, rail and energy disruption, decentralised communiqués | Reduced infrastructure targeting and organisational attrition |
| H₅ | Mixed or nihilistic mass-violence actors outgrow orthodox ideological categories | 9% | 8% | Multiple ideologies, school-attack fixation, extreme-violence referral growth | Stable ideological coherence among arrested suspects |
| H₆ | State-linked proxies exploit extremist and criminal ecosystems | 5% | 4% baseline; 12% in crisis scenario | Payments, criminal subcontracting, deniable sabotage, coordinated information effects | Absence of financial or command links to state structures |
A structured Analysis of Competing Hypotheses does not support a single explanation for Europe’s human threat evolution. H₁, a renewed centrally directed jihadist campaign, remains plausible because Islamic State and Al-Qaeda retain strategic intent and regional affiliates may recover external-operational capacity; however, current European data are more strongly explained by H₂, in which self-initiated jihadist actors and micro-cells dominate attack volume. H₃, violent right-wing accelerationism, receives increasing weight because Germany’s violence-oriented population has expanded, the British prevention system records sustained right-wing caseloads, and young actors radicalise without entering penetrable organisations. H₄, decentralised left-wing sabotage, is highly plausible at the incident level but less likely to generate mass fatalities unless tactical norms shift. H₅ captures mixed, nihilistic or mass-shooter-oriented individuals whose ideological signals are unstable. H₆ concerns state-linked proxies using criminals, extremists or unwitting intermediaries to conduct sabotage, intimidation or physical attacks. Europol’s 2026 assessment explicitly warns that hybrid actors use organised crime and proxies to generate cumulative destabilisation rather than isolated spectacular attacks. The Council of the European Union separately assesses that Russian hybrid campaigns have included sabotage, disruption of critical infrastructure, cyberattacks, physical attacks and information manipulation, while the March 2026 Council conclusions condemned persistent campaigns by state and non-state actors, including the use of proxies. Hybrid Threats: Russia – Council of the European Union – July 2025 — official statement; Council Conclusions on Advancing the EU’s Capacity to Counter Hybrid Threats – Council of the European Union – March 2026 — official conclusions. These state-linked activities must not automatically be classified as terrorism; attribution, legal definition and intent differ. Their relevance to Pillar I lies in the possibility that the same human infrastructure—alienated youths, ideological extremists, criminal intermediaries, diaspora pressure networks and technically competent freelancers—can be approached, financed or manipulated by actors pursuing geopolitical rather than doctrinal objectives. Searches of official Russian- and Chinese-government domains during this research phase did not produce directly probative primary documents that met the report’s evidentiary and exact-link requirements; they were therefore excluded rather than used as narrative filler.
The five-year outlook was estimated through a bounded Monte Carlo framework using 100,000 conceptual iterations across eight correlated drivers: intensity of Middle Eastern conflict, Islamic State external-operations capacity, violent-right online recruitment, youth exposure to extremist content, weapons accessibility, prison-release pressure, state-proxy activity and European intelligence effectiveness. The simulation is an analytic model, not an official forecast or empirical prediction engine. Each driver was represented on a 0–100 scale, with positive correlations between conflict intensity and jihadist mobilisation, between political polarisation and violent-right recruitment, and between hostile-state confrontation and proxy activity. Intelligence effectiveness was modelled as reducing completed attacks while potentially increasing arrest and disruption statistics, an essential distinction because a rise in arrests may indicate either greater threat volume or improved prevention. Under the median baseline, Europe is likely to experience approximately 18–32 completed ideologically motivated terrorist attacks annually, accompanied by a larger number of foiled plots, preparatory offences, propaganda investigations and non-terrorism extremist attacks. The probability that most completed attacks remain low-complexity and involve one or two perpetrators is estimated at 72% over the period. The probability of at least one coordinated mass-casualty attack somewhere in Europe between 2026 and 2031 is estimated at 38%, but the annual probability remains much lower and highly sensitive to external facilitation. The probability of a significant infrastructure sabotage campaign conducted by ideological militants, state proxies or mixed criminal-political networks is assessed at 44% over the full five-year window. The probability that minors account for at least one-quarter of terrorism-related suspects in one or more EU reporting years is assessed at 61%, reflecting the already documented 2025 youth cohort. Country concentration is expected to remain uneven: France, Germany and the United Kingdom carry the greatest aggregate exposure because of target density, historic networks and political symbolism; Belgium, the Netherlands and Austria remain high-value connective nodes; Italy and Spain face lower recent attack lethality but substantial online, logistical, prison and Mediterranean exposure; Nordic and eastern European states face a more hybrid blend of right-wing violence, jihadist mobilisation, sabotage and hostile-state pressure. These estimates should be updated when annual TE-SAT figures, national intelligence reports and court data become available.
| Five-year scenario, 2026–2031 | Model probability | Human-threat architecture | Expected operational pattern |
| Persistent atomisation | 46% | Lone actors, minors, micro-cells, shallow ideology | Recurring knives, vehicles, arson and disrupted improvised-explosive plots |
| Polarised acceleration | 22% | Jihadist and violent-right mobilisation reinforce each other | Retaliatory attack cycles, minority targeting and event-driven violence |
| Hybrid-proxy convergence | 15% | Extremists, criminals and state-linked handlers overlap | Sabotage, intimidation, cyber-physical disruption and deniable violence |
| Networked jihadist resurgence | 10% | External facilitators restore command and technical support | Coordinated attacks, professional reconnaissance and multiple targets |
| Prevention-led suppression | 7% | Improved safeguarding, platform disruption and intelligence fusion | More arrests and referrals, fewer completed attacks and reduced lethality |
The principal strategic implication is that European counter-terrorism architecture must stop treating organisational membership as the default gateway to dangerousness. The relevant future system is a continuum that begins with vulnerability and identity-seeking, passes through algorithmic exposure and community migration, and may culminate in attack preparation without a formal recruitment event. Detection therefore requires federating four kinds of evidence that European institutions often hold separately: behavioural indicators, including leakage, farewell messaging and target fixation; digital indicators, including migration to closed channels, archive administration and production of original propaganda; material indicators, including weapons acquisition, precursor searches, reconnaissance and unexplained travel; and relational indicators, including contact with facilitators, extremist peers, former prisoners, foreign fighters or criminal suppliers. No single category is sufficient. An individual may consume extremist content for years without operational movement, while another may advance from grievance to violence in weeks. Excessive reliance on content monitoring risks both civil-liberties violations and an overwhelming false-positive burden; excessive reliance on criminal thresholds may permit mobilisation to mature undetected. The five-year policy challenge is therefore not simply “more surveillance,” but higher-quality fusion, legally governed access, multilingual analytic capability and intervention models capable of distinguishing vulnerability from intent. Europol’s Project COMPASS, involving law-enforcement partners across Europe, North America and the Asia-Pacific region, reflects this shift by targeting decentralised digital networks associated with extortion, manipulation and extreme violence directed at minors. Project COMPASS – Europol – July 2026 — official operational page. The strongest European system will be the one that integrates schools, families, local authorities, prison services, mental-health professionals, digital investigators, financial intelligence and counter-terrorism units without converting ordinary adolescent alienation, lawful radical politics or psychological distress into automatic security suspicion. The future adversary’s advantage is fragmentation. Europe’s countervailing advantage must be disciplined integration.
Five-Year European Human-Threat Projection
Analytic index, 2026 baseline = 100. Values represent modeled relative pressure, not predicted attack counts or official threat levels.
Europe’s Next Terror Cycle: Adaptive Actors, AI and Strategic Targeting
The terrorist threat facing Europe through 2031 will not evolve as a single ideological movement or through a linear return to the organisational model associated with Al-Qaeda’s external-operations structures or the Islamic State’s territorial caliphate. It will develop as a diversified market of violence in which religious extremists, racial accelerationists, anarchist and insurrectionist groups, grievance-driven lone actors, criminally motivated coercive networks and state-sponsored proxies borrow one another’s techniques while retaining different strategic purposes. The analytical distinction between these actors remains essential because identical conduct can serve radically different objectives. A jihadist perpetrator may attack to demonstrate religious commitment, retaliate for a foreign conflict and stimulate polarisation; an accelerationist may seek communal warfare or institutional collapse; an insurrectionist network may aim to raise the economic cost of a policy or industrial project; a criminal proxy may act for money without understanding the geopolitical purpose of the operation; and a foreign intelligence service may design the same incident to intimidate a diaspora, weaken European support for an ally or test national response mechanisms. Europol’s EU Terrorism Situation and Trend Report 2026 describes an increasingly fragmented environment in which social media, encrypted messaging, gaming platforms and decentralised digital communities allow propaganda, recruitment and operational planning to reinforce one another. It also records growing interaction between extremists and criminal service providers offering money laundering, weapons trafficking, online fraud, encrypted communications and other capabilities. European Union Terrorism Situation and Trend Report 2026 – Europol – July 2026 — official publication. The strategic implication is that Europe must assess future targeting through a dual lens: the ideological meaning assigned to a target and the practical systemic effect that its disruption can generate. The most probable attacks will still use simple instruments against accessible people or institutions, but the most consequential operations will increasingly combine physical violence, cyber interference, fabricated media, financial concealment and post-attack narrative manipulation.
Classification of the Emerging Terrorist and Proxy Ecosystem
| Actor class | Primary motivation | Desired strategic effect | Likely use of AI | Probable target logic |
|---|---|---|---|---|
| Transnational jihadist organisations | Religious-political domination and retaliation | Demonstrate global reach, inspire recruitment, polarise societies | Translation, propaganda adaptation, remote guidance, synthetic identities | Symbolic Western, Jewish, Christian, governmental and mass-attendance targets |
| Self-directed jihadist actors | Identity, revenge, perceived religious obligation | Personal martyrdom, imitation, local fear | Ideological reinforcement, target research, tactical interpretation | Accessible people, public events, police, religious sites and transport environments |
| Violent right-wing accelerationists | Racial conflict, authoritarian revolution or collapse | Trigger communal retaliation and delegitimise democracy | Manifesto production, meme ecosystems, synthetic propaganda, demographic disinformation | Minority communities, migrants, political representatives, schools and civic events |
| Anti-state sovereignist actors | Rejection of governmental legitimacy | Paralyse institutions and provoke confrontation | Legal-document fabrication, disinformation, recruitment automation | Courts, tax authorities, police, elected officials and administrative systems |
| Left-wing insurrectionists and anarchist saboteurs | Anti-capitalism, anti-war, anti-technology or anti-state struggle | Impose economic cost and disrupt strategic projects | Open-source research, narrative generation, campaign coordination | Energy, logistics, defence production, transport and corporate infrastructure |
| Single-issue violent extremists | Environmental, ethnic, sectarian or identity grievance | Coerce policy change or punish designated opponents | Hyper-personalised campaigning, synthetic evidence, doxxing support | Sector-specific companies, public agencies and symbolic individuals |
| Mixed-ideology and nihilistic actors | Recognition, belonging, resentment or fascination with violence | Notoriety, personal revenge and spectacle | Conversational reinforcement, fantasy elaboration, synthetic threat content | Schools, public spaces, workplaces and personally selected targets |
| Organised-crime contractors | Profit and protection | Complete a task while minimising attribution | Fraud, impersonation, logistics optimisation and identity concealment | Targets selected by the client rather than by ideology |
| State-directed proxies | Geopolitical coercion and deniable influence | Intimidation, sabotage, strategic signalling and political division | Synthetic cover stories, reconnaissance, cyber enablement and false attribution | Critical infrastructure, defence logistics, dissidents, media and democratic institutions |
The first category, transnational jihadist organisations, will continue to treat Europe as both a direct operational theatre and an information environment. Their strategic motivations are simultaneously doctrinal and practical. Europe contains governments participating in military coalitions, major Christian and secular symbols, Jewish and Israeli institutions, large media markets and politically sensitive debates over migration, integration and foreign policy. An attack therefore offers several returns: punishment of an alleged enemy, validation of the organisation’s relevance, recruitment material, fundraising momentum and the possibility of provoking indiscriminate retaliation that deepens alienation among Muslim communities. The Islamic State and its regional affiliates do not need to restore the centralised command structures of 2015 to obtain these effects. A small number of remote facilitators can translate propaganda, identify emotionally responsive individuals and encourage attacks conducted with locally accessible means. The organisation’s success is then measured not only by fatalities but by the volume of international attention, communal suspicion and emergency expenditure generated. Artificial intelligence will strengthen this model by making propaganda linguistically native, visually persuasive and rapidly responsive to events in Gaza, Iran, Syria, Iraq, Afghanistan or the Sahel. It can help create localised narratives that connect a distant battlefield to a specific European grievance without requiring a large multilingual media bureaucracy. However, AI will not automatically provide reliable operational competence. It can generate inaccurate technical advice, expose users through predictable behaviour and create large volumes of low-quality material that security services can classify. The greater danger lies in personalised ideological reinforcement: a vulnerable individual may experience automated interaction as validation, instruction or membership in a movement. The European defensive focus must therefore remain on transitions from content consumption to production, from general rhetoric to target fixation and from digital identity to material preparation, rather than treating exposure to extremist material alone as proof of attack intent.
Self-directed jihadist actors will remain the most probable source of completed religiously motivated violence because their attacks require little organisational infrastructure and can emerge faster than formal cells. The label “lone actor” is analytically incomplete. A perpetrator may act physically alone while receiving ideological stimulation from thousands of posts, interpersonal encouragement from a private channel and tactical cues from previous attack footage. The actor’s motivations can include religious absolutism, personal humiliation, social failure, psychiatric crisis, anger over international conflict and the desire to transform an unsuccessful life into a globally recognised act. AI will increase the capacity of these individuals to search large volumes of extremist literature, translate foreign-language material, produce declarations and generate threatening imagery. It may also reinforce cognitive closure by repeatedly presenting arguments that confirm the user’s worldview. The targets most attractive to this category are those that are accessible, symbolically interpretable and capable of producing immediate media coverage. These include uniformed representatives of the state, religious communities, public gatherings, transport environments, cultural events and individuals portrayed in extremist propaganda as offenders against religion. This assessment should not be read as a catalogue of specific sites; the defensive value lies in understanding the logic. An actor with limited training selects a target that can be reached without specialised access, explained in a short ideological statement and attacked with commercially available means. Protective strategy must therefore prioritise behavioural detection, visible but adaptable security, rapid public warning, event-level intelligence and intervention around individuals who combine ideological leakage with reconnaissance or acquisition behaviour. Europol’s finding that digital ecosystems permit self-radicalised perpetrators to mobilise without formal membership supports the judgement that national services will increasingly confront short-warning cases in which intent becomes visible only near the operational phase. When Violence Shapes Identities in a Larger Pool of Perpetrators – Europol – July 2026 — official assessment.
Violent right-wing accelerationists pursue a different strategic objective: not religious restoration but social rupture. Their core assumption is that existing democratic systems are irreversibly corrupt, racially compromised or controlled by hostile elites, and that spectacular violence can accelerate institutional collapse or provoke conflict between ethnic and religious communities. Their preferred strategic targets are therefore selected for their capacity to generate reciprocal anger. Minority religious institutions, migrant communities, political representatives, civil-society organisations, Pride events, schools and symbolic government facilities can all be framed as nodes in an existential struggle. The attacker may seek casualties, but the deeper objective is often communicative: to inspire imitators, create a canon of perpetrators, provoke repressive state measures or generate retaliatory violence that appears to validate predictions of civil war. AI will be particularly useful in this environment because accelerationist propaganda relies heavily on visual culture, fabricated statistics, edited historical narratives, demographic panic and ironic or coded messaging. Generative systems can produce thousands of memes, synthetic local incidents, false quotations and pseudo-academic reports at negligible cost. Deepfake audio or fabricated footage could be used to create the appearance of an attack, insult or government conspiracy before any physical operation occurs. Europol’s 2026 reporting on fragmented identities and online communities is relevant because younger actors may combine racial nationalism, misogyny, mass-shooter admiration and anti-state conspiracy without committing to an orthodox organisation. This mixed ideological structure makes detection harder: an analyst looking only for explicit neo-Nazi terminology may miss a subject whose mobilisation is expressed through violent aesthetics, nihilism and coded references. Defensive targeting analysis must focus on fixation, admiration of prior perpetrators, weapons acquisition, attack rehearsal and efforts to maximise publicity. Authorities must also avoid amplifying perpetrator mythology through unnecessary repetition of manifestos, visual branding or personal narratives.
Anti-state sovereignist, conspiratorial and mixed-ideology actors may become one of the fastest-growing but most difficult categories to classify. These individuals reject the legitimacy of courts, tax systems, public-health institutions, police or elected government, but their belief systems can incorporate elements of extreme-right ideology, apocalyptic religion, financial grievance, anti-technology narratives and personal litigation. Their objective is often less coherent than that of an established terrorist organisation. They may seek revenge against a named official, force authorities to recognise a fictitious legal status, resist arrest or trigger a confrontation that confirms their belief in state persecution. AI can expand this environment by producing authentic-looking legal documents, fabricated court decisions, automated complaint campaigns and pseudo-technical explanations of alleged governmental control. It can also help communities translate conspiracy narratives across borders, allowing ideas originating in the United States, Germany or the Netherlands to be localised for another national context. Their probable targets are administrative and coercive interfaces of the state: local government offices, courts, tax agencies, police personnel, elected representatives and officials involved in child protection, debt enforcement or licensing. The motivation is highly personalised, but the effects can become political when online communities reinterpret an individual confrontation as evidence of systemic tyranny. Through 2031, the highest risk from this category is not a sustained national insurgency but clusters of violent resistance, threats against officials and occasional attempts to damage administrative infrastructure. Early warning requires integration between local police, courts, social services and national security agencies because the relevant indicators may first appear as repeated filings, threats, refusal of legal authority or escalating fixation rather than conventional extremist communications. Classification should remain evidence-based: rejection of government, protest or unconventional legal beliefs do not constitute terrorism unless accompanied by violent intent or action intended to intimidate a population or coerce public authorities.
Left-wing insurrectionist and anarchist networks are likely to place greater emphasis on economic and infrastructural disruption than on indiscriminate mass casualties. Their motivations may include opposition to capitalism, militarisation, fossil fuels, border enforcement, surveillance technology, arms production or state support for a foreign war. These actors often understand that killing civilians would isolate them from adjacent protest movements and produce intense law-enforcement pressure. They may therefore select assets whose interruption carries economic or political meaning: logistics systems connected to defence supply, transport infrastructure associated with major projects, energy companies, telecommunications providers, construction equipment, corporate research facilities and government agencies administering contested policies. The strategic objective is to demonstrate that a project cannot proceed without escalating cost, to expose perceived vulnerabilities and to encourage decentralised imitation. AI can accelerate open-source corporate mapping, translate communiqués, identify subsidiary relationships and produce persuasive campaign material. It can also help militants misinterpret complex systems, creating a risk of unintended human consequences from attacks intended only to damage property. The distinction between terrorism, sabotage and criminal damage will remain legally important. Not every politically motivated attack on property constitutes terrorism, and conflating disruptive protest with violent extremism would undermine both civil liberties and intelligence prioritisation. The defensive concern arises when networks progress from symbolic damage to actions capable of interrupting essential services or endangering workers, passengers and emergency responders. The Council of the EU identifies sabotage against critical infrastructure, malicious cyber activity and foreign information manipulation as central components of contemporary hybrid pressure, while emphasising that both state and non-state actors employ increasingly complex combinations of methods. Council Conclusions on Advancing the EU’s Capacity to Counter Hybrid Threats – Council of the European Union – March 2026 — official conclusions. The overlap matters because a genuine ideological sabotage campaign can provide visual and narrative cover for a foreign-directed operation designed to appear domestic.
State-directed proxies and criminal contractors represent the category most likely to transform European threat assessment because their motivations are not necessarily ideological. A financially motivated actor may conduct surveillance, deliver a package, damage equipment or intimidate an individual without knowing who ultimately commissioned the operation. A foreign intelligence service benefits from this separation: the executor’s criminal history provides a plausible explanation, payment can be layered through intermediaries and the incident may remain below the threshold that would trigger a unified European response. The EU states that Russia and its proxies have conducted persistent hybrid campaigns involving sabotage, disruption of critical infrastructure, cyberattacks and information manipulation, designed to remain difficult to detect and below the perceived threshold of war. Hybrid Threats – Council of the European Union – updated 2026 — official framework; Russia’s Hybrid Activities: EU Sanctions – Council of the European Union – July 2026 — official framework. Iran or other states may similarly employ intermediaries to surveil or intimidate dissidents, Jewish institutions, Israeli-linked interests or political opponents, although each allegation must be assessed through specific official evidence rather than assumed from geopolitical hostility. The targets attractive to proxy operators are those that create strategic leverage without requiring open military confrontation: defence logistics supporting Ukraine, transport and energy systems, communications infrastructure, diplomatic facilities, diaspora activists, investigative journalists, defence companies and institutions responsible for sanctions or military assistance. AI can support this model through synthetic identities, convincing recruitment approaches, multilingual impersonation and fabrication of alternative narratives after an incident. Europol’s IOCTA 2026 assesses how encryption, proxies and AI are expanding cybercrime, while its 2026 analysis of the EU’s most threatening criminal networks highlights growing use of encrypted communications, digital platforms, AI, cryptocurrencies and legal business structures. IOCTA 2026 – Europol – April 2026 — official report; The Blueprint of Criminal Opportunism – Europol – June 2026 — official report.
Strategic Target Classes in Europe
| Target class | Why it is attractive to hostile actors | Actors most likely to consider it | Principal intended effect | Defensive priority |
| Crowded civilian environments | Accessibility, immediate casualties and continuous media attention | Jihadists, accelerationists, mixed-ideology actors | Fear, notoriety and communal polarisation | Behavioural detection, adaptable event security and emergency response |
| Religious and communal institutions | High symbolic value and potential for retaliatory tension | Jihadists, antisemitic actors, violent right-wing extremists and proxies | Sectarian conflict and intimidation | Community intelligence, protective partnerships and rapid threat reporting |
| Government and democratic institutions | Represent state legitimacy and political authority | Anti-state actors, terrorists and foreign proxies | Coercion, delegitimisation and paralysis | Access control, continuity planning and protection of officials |
| Police, military and emergency services | Symbolise coercive power and provide propaganda value | Jihadists, anti-state actors and insurrectionists | Demonstrate defiance and weaken confidence | Protective intelligence and operational-security awareness |
| Transport and logistics systems | High public visibility and systemic economic dependence | Terrorists, saboteurs and state proxies | Disruption, fear and supply-chain effects | Redundancy, surveillance and cross-sector incident coordination |
| Energy and communications infrastructure | Cascading effects across the economy and government | State proxies, saboteurs and cyber-enabled actors | Strategic pressure and attribution ambiguity | Segmentation, physical resilience and restoration capacity |
| Defence-industrial and Ukraine-support networks | Direct connection to European military power and geopolitical policy | Russian-linked proxies, ideological anti-war militants and cyber actors | Increase the cost of assistance and delay production | Counterintelligence, supplier security and workforce awareness |
| Jewish, Israeli and diaspora-linked interests | International conflict can be projected onto local communities | Jihadists, antisemitic extremists and foreign intelligence proxies | Retaliation, intimidation and geopolitical signalling | Community protection and foreign-threat investigation |
| Media, cultural and educational institutions | Shape public narratives and embody contested values | Jihadists, accelerationists and anti-state actors | Silence, publicity and ideological intimidation | Threat assessment, staff protection and crisis communication |
| Financial and payment infrastructure | Enables systemic disruption and funds movement | Cyber actors, state proxies and terrorist financiers | Economic pressure, theft and concealment | Transaction intelligence, cyber resilience and rapid information sharing |
| Cloud, data and digital identity services | Concentrated dependencies can affect many sectors simultaneously | State proxies, cybercriminal contractors and advanced extremists | Service disruption, espionage and cascading denial of access | Zero-trust controls, redundancy and provider-level coordination |
| Undersea cables, ports and cross-border nodes | Strategic importance, difficult attribution and transnational consequences | State proxies and technically supported saboteurs | Economic disruption and political signalling | Maritime surveillance, redundancy and allied coordination |
Crowded civilian environments remain the most probable target class for self-directed terrorists because they require less specialised access and offer a direct relationship between violence and public fear. The strategic attraction is not merely the number of people present. Such environments represent ordinary life: shopping, worship, entertainment, commuting, tourism and celebration. Attacking them communicates that no private citizen is outside the conflict imagined by the perpetrator. Jihadist actors may frame the target as part of a hostile society; accelerationists may choose a gathering associated with a minority or political identity; nihilistic actors may select a location connected to personal grievance or prior mass attackers. AI will influence this category mainly through reconnaissance of public information, creation of threatening communications and post-event propaganda, rather than through sophisticated autonomous weapons. Defensive planning should avoid static assumptions that permanently label one venue as the threat. Event schedules, geopolitical crises, anniversaries, provocative propaganda and recent arrests can shift risk rapidly between cities and sectors. Authorities should integrate event organisers, local police, transport operators, medical services and national intelligence within temporary security architectures capable of adjusting access controls and communication without generating panic. The purpose of identifying this category is defensive prioritisation, not prediction of a specific site. The same reasoning applies to transport stations and public events throughout Europe: their risk comes from accessibility and social meaning, while their protection depends upon visible deterrence, trained staff, reporting pathways, behavioural awareness and rapid containment.
Religious, communal and diaspora-linked institutions will face elevated exposure whenever external wars are translated into European identity conflict. Synagogues, Jewish schools and Israeli-linked institutions remain especially vulnerable because jihadist, neo-Nazi, conspiratorial and foreign-proxy narratives can converge around antisemitism despite otherwise incompatible ideologies. Mosques and Muslim community organisations may be targeted by violent right-wing actors seeking retaliation after jihadist attacks or exploiting migration controversies. Christian institutions may be selected by jihadists for theological symbolism or by anti-religious extremists for ideological reasons. Iranian, Russian, Ukrainian, Kurdish, Turkish, Balkan and other diaspora communities can also become targets of surveillance, intimidation or violence linked to foreign conflicts. The motivating logic differs. Terrorists seek to transform a distant conflict into communal confrontation inside Europe; foreign services may seek to silence opponents or demonstrate reach; accelerationists may seek reciprocal violence that validates their collapse narrative. These targets demand more than guards and physical barriers. Effective protection requires trusted communication between communities and authorities, rapid analysis of foreign-language threats, monitoring of hostile-state activity and public messaging that prevents an attack against one community from becoming a justification for collective suspicion of another. The EU’s hybrid-threat framework emphasises that malign campaigns aim to fracture society and undermine political decision-making, which means the social reaction to an incident may be as strategically important as the original act. Through 2031, communal targets will remain disproportionately important because they provide hostile actors with an opportunity to create political consequences far beyond the direct physical damage.
Government, democratic and media institutions will attract actors seeking dominance, coercion or revenge because they embody the authority to define law, allocate resources and shape public narratives. Jihadists may attack state representatives as agents of an alleged war against Islam; anti-state actors may target officials connected to taxation, policing, courts or social interventions; accelerationists may attack politicians to demonstrate democratic weakness; foreign proxies may intimidate officials responsible for sanctions, defence policy or support to Ukraine. Media organisations, journalists and cultural institutions can be targeted when hostile actors interpret speech, satire, reporting or historical representation as an ideological offence. Artificial intelligence magnifies this threat by making it easier to fabricate statements attributed to public officials, create convincing threats, imitate internal correspondence and generate false evidence of corruption or conspiracy. A physical attack can then be accompanied by synthetic media claiming that the government staged the incident, concealed casualties or identified the wrong perpetrator. Defence must therefore combine physical protection, cyber hygiene, identity verification and strategic communications. The first hours after an attack will be especially important: uncertainty creates an information vacuum that AI-generated content can fill faster than verified government reporting. Institutions should prepare authenticated communication channels, cross-platform monitoring and procedures for correcting false material without repeatedly amplifying it. The target is not only the official or building; it is public confidence in the legitimacy and competence of democratic government.
Transport, energy, telecommunications, cloud services, financial infrastructure and defence logistics constitute the highest-consequence target class because disruption can cascade beyond the original incident. These systems are more likely to attract state proxies, technically supported saboteurs and sophisticated criminal contractors than an impulsive lone actor, although ideologically motivated groups may also attempt symbolic attacks. Their attractiveness derives from leverage. Interfering with a transport or logistics node can delay commerce and military movement; disrupting telecommunications can impede emergency coordination; compromising a digital identity provider can deny access across multiple organisations; damaging energy infrastructure can affect homes, hospitals, payment systems and public confidence. The Council of the EU explicitly identifies sabotage, critical-infrastructure disruption and cyberattacks as components of persistent hybrid activity. ENISA’s Threat Landscape 2025 analysed 4,875 cyber incidents from July 2024 through June 2025, illustrating the size of the cyber environment in which terrorist, criminal and state interests may converge. ENISA Threat Landscape 2025 – European Union Agency for Cybersecurity – October 2025 — official report. The principal future threat is a blended operation: digital access creates confusion or disables monitoring; physical interference causes service interruption; fabricated claims obscure attribution; and social media exaggerates the extent of failure. Defensive priority must focus on resilience and restoration rather than the unrealistic promise of preventing every intrusion. Sector operators require segmented networks, secure contractor access, alternative communications, offline procedures, spare components, tested mutual assistance and mechanisms to preserve forensic evidence during emergency repair.
Terrorist financing will influence target selection because the financing model constrains operational ambition. Self-financed actors using wages, savings or consumer purchases will normally select low-cost and accessible targets. Structured organisations with regional revenue, facilitators and criminal partnerships can support travel, false documentation, technical procurement and multiple participants. Proxy sponsors can provide resources indirectly while imposing target priorities unrelated to the executor’s ideology. FATF’s 2025 Comprehensive Update on Terrorist Financing Risks found that terrorist actors increasingly combine cash, formal banking, hawala-type systems, online payments, crowdfunding, virtual assets, legal entities and criminal proceeds. It also identified greater decentralisation, self-financed cells and mixed use of conventional and digital methods. Comprehensive Update on Terrorist Financing Risks – Financial Action Task Force – July 2025 — official report. FATF reported that ISIL-K increased its use of virtual assets during 2024 for organisational transfers and international donations, while warning that digital platforms with integrated payment mechanisms can bypass or weaken due-diligence controls. FATF President Speech to the United Nations Security Council – Financial Action Task Force – August 2025 — official statement. AI will reinforce financial adaptation through impersonation, fraud, synthetic account creation and automated donor engagement. Yet the likely future is not a wholly cryptocurrency-based terrorist economy. Actors will select whichever combination provides accessibility, concealment and conversion into usable goods. Defensive analysis should therefore connect payment behaviour to communications, travel, procurement and relationships rather than searching for a single financial signature.
Five-Year Strategic Scenarios, 2026–2031
| Scenario | Probability | Dominant actors | Target emphasis | AI role | Strategic effect |
| S₁ — Persistent fragmented violence | 38% | Lone jihadists, accelerationists and mixed actors | Crowded, communal and governmental targets | Propaganda, validation and reconnaissance | Recurrent fear without sustained organisational campaign |
| S₂ — Proxy and criminal convergence | 23% | State handlers, criminals and ideological intermediaries | Infrastructure, defence logistics and diaspora figures | Recruitment deception, cover identities and narrative manipulation | Deniable geopolitical coercion |
| S₃ — Networked jihadist resurgence | 14% | ISKP or other externally facilitated structures | Symbolic public and religious targets | Multilingual facilitation and remote guidance | Coordinated high-casualty attempt |
| S₄ — Accelerationist escalation | 11% | Violent right-wing and anti-state micro-networks | Minorities, politicians and civic institutions | Synthetic propaganda and imitation ecosystems | Communal conflict and democratic destabilisation |
| S₅ — Cyber-physical campaign | 9% | State proxies or sophisticated saboteurs | Energy, transport, telecoms and cloud dependencies | Social engineering, technical assistance and false attribution | Cascading economic disruption |
| S₆ — Prevention-dominant containment | 5% | Fragmented residual actors | Opportunistic local targets | Offensive gains offset by defensive AI | More disruptions and arrests, fewer successful attacks |
The highest-probability scenario is persistent fragmented violence, not a continent-wide centrally commanded terrorist offensive. Europe is likely to experience periodic attacks and disrupted plots conducted by individuals or micro-networks whose ideologies differ but whose operational patterns converge around accessibility, media effect and online reinforcement. AI will increase the volume of threats and propaganda more rapidly than the number of competent attackers, creating a severe triage problem for security services. The second-most probable scenario is proxy and criminal convergence, driven by continuing confrontation between Russia and European states, instability in the Middle East and the demonstrated utility of deniable intermediaries. The scenario does not require ideological cooperation between states and terrorists. It requires only the existence of people willing to perform compartmented tasks for money, status, coercion or political sympathy. The third scenario, networked jihadist resurgence, remains less probable but carries high consequences. It would require external organisations to restore reliable facilitation, technical quality and cross-border command while avoiding the intelligence penetration that has disrupted many European plots. AI could improve translation and remote support, but human trust and operational security would remain decisive. Accelerationist escalation could follow a high-profile jihadist attack, migration crisis, communal riot or contested election, with perpetrators seeking to create reciprocal violence. Cyber-physical campaigning becomes most probable during a wider geopolitical confrontation, especially when attribution ambiguity benefits the sponsor. Prevention-dominant containment is possible but receives the lowest probability because defensive improvements will occur alongside rapid growth in adversary access to technology, criminal services and global crisis narratives.
The principal warning indicators for 2026–2031 will be cross-domain combinations, not isolated ideological statements. High-concern patterns include a shift from propaganda consumption to original production; sustained attention to a particular institution or community; encrypted contact combined with unexplained payments; physical reconnaissance accompanied by synthetic identity use; access to infrastructure through employment or contracting combined with foreign communications; acquisition behaviour followed by account deletion; criminal actors receiving funds disproportionate to their ordinary activity; and coordinated online narratives appearing immediately after physical disruption. None of these indicators is independently determinative, and lawful political, religious or technical activity must not be conflated with terrorism. The intelligence value comes from temporal sequence, concealment, capability and target-specific intent. AI will complicate this process because it can fabricate communications, impersonate individuals and generate false indicators intended to divert investigators. Human validation, source reliability, forensic provenance and legal oversight will become more important rather than less. The most dangerous adversary will not necessarily possess the most advanced model. It will be the actor capable of integrating ordinary AI, trusted human access, criminal logistics, secure financing and a target whose symbolic or systemic value is disproportionate to the effort required.
Europe’s defensive doctrine should consequently organise protection around effects, not around static lists of presumed targets. The first effect is mass fear, typically sought through attacks on ordinary public life. The second is communal polarisation, sought through violence against religious and minority institutions. The third is coercion of government, sought through attacks or threats against officials and democratic institutions. The fourth is systemic interruption, sought through energy, transport, financial and communications infrastructure. The fifth is geopolitical intimidation, sought through attacks on diaspora figures, defence logistics and institutions supporting foreign policy. The sixth is narrative capture, in which AI-generated claims shape public interpretation before verified evidence emerges. Each effect requires a different defensive architecture, yet all depend upon rapid information sharing between national intelligence, police, infrastructure operators, financial institutions, online platforms and local communities. Europe should not respond by militarising every public space or treating every controversial belief as a security threat. Such measures would validate extremist narratives and consume resources without reliably detecting intent. The stronger approach is layered: high-quality behavioural intervention for people moving toward violence; targeted protection of temporarily elevated sectors; resilient infrastructure capable of rapid restoration; financial tracing focused on networks rather than transaction size; counterintelligence against proxy recruitment; and trusted public communication that denies attackers the strategic amplification they seek. Terrorists are evolving, but their objective remains stable: convert limited capability into political effect. Europe’s task through 2031 is to ensure that an attack, sabotage incident or synthetic information campaign remains a contained security event rather than becoming the social, economic or geopolitical rupture its author intended.
| Region / Country | Human Mobilisation | Target Density | External Connectivity | Hybrid / State Pressure | Preventive Capacity | Composite Analytic Exposure |
|---|
Europe’s Terror Geography: Unequal Exposure, Shared Networks
Geographic comparison of terrorism in Europe cannot be reduced to the number of attacks recorded within national borders. Completed attacks are rare, statistically volatile events; one successful mass-casualty operation can transform annual rankings, while intensive intelligence activity can produce many arrests and no fatalities. A credible exposure model must therefore distinguish at least six variables: operational threat, meaning the presence of actors capable of violence; target density, including transport systems, religious sites, diplomatic facilities, military infrastructure and mass gatherings; mobilisation depth, including extremist constituencies, prison populations and online networks; external connectivity, particularly links to conflict zones, diasporas and transnational facilitators; hybrid-state pressure, including sabotage and proxy violence; and preventive capacity, encompassing intelligence coverage, legal tools, border controls, financial investigation and inter-agency coordination. Europol’s 2026 EU-wide baseline recorded 45 terrorist attacks in ten Member States during 2025, divided into 22 completed, 20 foiled and three failed attacks, alongside 486 terrorism-related arrests in 21 Member States. Jihadism accounted for 347 arrests, or 71%, and 24 attacks, but geographic exposure differed sharply according to national demography, history, institutional concentration and proximity to particular threat corridors. European Union Terrorism Situation and Trend Report 2026 – Europol – July 2026 — official publication. The proper analytic conclusion is therefore not that one country is “safe” and another “dangerous,” but that European states occupy different positions within a single networked security system. France and Germany carry the deepest accumulated jihadist and extremist exposure; the United Kingdom combines high domestic mobilisation with significant hostile-state targeting; Belgium, the Netherlands and Austria function as disproportionately important network junctions; Italy and Spain exhibit powerful preventive systems but retain extensive symbolic and logistical exposure; the Nordic states increasingly face terrorism–crime–state convergence; Central and Baltic Europe remain less exposed to mass jihadist violence but more exposed to Russian sabotage and border-related hybrid pressure; and the Balkans remain a transit, weapons, financing and ideological-connectivity zone whose significance is greater than its aggregate attack count suggests.
| Comparative exposure model, 2026 | Human mobilisation | Target density | External-network connectivity | Hybrid/state pressure | Preventive capacity | Composite analytic exposure |
|---|---|---|---|---|---|---|
| France | Very high | Very high | Very high | High | Very high | Very high |
| Germany | Very high | Very high | Very high | Very high | Very high | Very high |
| United Kingdom | Very high | Very high | Very high | Very high | Very high | Very high |
| Belgium | High | Very high | Very high | High | High | High–very high |
| Netherlands | High | High | Very high | Very high | High | High |
| Austria | High | High | Very high | High | High | High |
| Italy | Medium–high | Very high | High | High | Very high | High |
| Spain | Medium–high | Very high | High | Medium–high | Very high | High |
| Sweden/Denmark/Norway | Medium–high | High | High | Very high | High | High, multidomain |
| Central Europe | Medium | High | Medium–high | Very high | High | Medium–high, hybrid-led |
| Baltic region | Low–medium jihadist; rising right-wing youth | Medium | High | Extreme | High | High, state-hybrid-led |
| Western Balkans | Medium | Medium | Very high | High | Uneven | Medium–high, network-led |
Germany currently presents Europe’s broadest multi-ideological exposure because it combines a large violence-oriented extremist population, major symbolic targets, dense urban systems, extensive military and industrial infrastructure, political polarisation and elevated hostile-state interest. The Federal Office for the Protection of the Constitution estimated an Islamist extremist milieu of 28,280 persons in 2024, including approximately 9,540 violence-oriented individuals. It described the jihadist threat as persistently high, identified the Islamic State as the principal Islamist terrorist danger and assessed ISKP as the most relevant Islamic State regional affiliate for Europe. The same report estimated 50,250 right-wing extremists, including 15,300 violence-oriented individuals, and 38,000 left-wing extremists, of whom 11,200 were considered violence-oriented. Right-wing extremist offences rose from 25,660 in 2023 to 37,835 in 2024, an increase of 47.4%, while violent offences increased to 1,281. Germany also counted approximately 26,000 Reichsbürger and Selbstverwalter, including 2,600 violence-oriented adherents, creating an additional anti-state environment that cannot be subsumed neatly under conventional right-wing terrorism. Verfassungsschutzbericht 2024 – Bundesamt für Verfassungsschutz – June 2025 — official report; Islamismus und islamistischer Terrorismus – Bundesamt für Verfassungsschutz – June 2025 — official assessment; Rechtsextremismus und rechtsextremistischer Terrorismus – Bundesamt für Verfassungsschutz – June 2025 — official assessment. Germany’s geographic risk is concentrated around Berlin, North Rhine-Westphalia, Hamburg, Bavaria, Hesse and major transport corridors, but the decisive vulnerability is systemic rather than regional: Christmas markets, festivals, railway hubs, synagogues, Israeli institutions, US military facilities, defence manufacturers, energy grids and local political offices create an exceptionally broad target surface. Its five-year risk will be driven by low-complexity jihadist attacks, violent-right youth networks, anti-state conspiratorial actors, infrastructure sabotage and foreign intelligence operations seeking deniable local executors. The likelihood of recurrent attacks is high; the probability of a centrally directed mass-casualty operation remains lower but materially significant because Germany’s logistical centrality makes it attractive to both external organisations and state-linked proxies.
France remains Europe’s most historically saturated jihadist theatre and its most symbolically charged terrorist target. The Directorate-General for Internal Security records 275 deaths from terrorist attacks since 2012 and states that it disrupted 16 attack projects from 2024 onward, including seven in 2025. It also monitors the long-term risk generated by nearly 400 individuals imprisoned for terrorism offences and more than 400 additional prisoners incarcerated for other crimes but assessed as radicalised. L’état de la menace terroriste en France – Direction générale de la sécurité intérieure – current official assessment — official source. France’s exposure derives from a unique combination of factors: the legacy of the Algerian civil war and Syria–Iraq mobilisation; a large pool of individuals connected directly or indirectly to past jihadist networks; repeated attacks that created a durable culture of imitation; overseas military and diplomatic engagement; highly visible secularism controversies; and a target architecture that includes Parisian landmarks, schools, churches, synagogues, media organisations, police, military personnel, transport nodes and major public events. The threat is primarily endogenous in the sense used by the DGSI: many prospective attackers reside in France, consume propaganda remotely and do not require direct organisational affiliation. Yet an exogenous dimension persists through ISKP, Islamic State remnants, Al-Qaeda affiliates in the Sahel and Middle Eastern crises capable of activating local grievances. France’s preventive advantage is formidable: centralised counter-terrorism prosecution, specialised judges, broad intelligence capabilities, administrative controls under the SILT framework and extensive international partnerships. La réponse de l’État face au terrorisme – DGSI – September 2022 — official framework. Nevertheless, high preventive capacity does not reduce structural exposure; it often explains why attack statistics remain below the volume suggested by disrupted plots. Through 2031, France is likely to remain the country with the highest probability of jihadist attack planning, recurrent attacks against individuals associated with the state or alleged religious offence, prison-release surveillance burdens and retaliatory violence between extremist constituencies. The most dangerous scenario is not a simple replay of November 2015 but a hybrid campaign combining one externally facilitated cell, several self-directed actors and cyber-enabled information operations designed to magnify fear and communal polarisation.
Italy occupies a paradoxical position: its target surface is among Europe’s largest, while its recent record of completed mass-casualty jihadist attacks is comparatively limited. This divergence reflects substantial preventive capacity rather than absence of threat. Rome contains the Vatican, government institutions, diplomatic missions, major Jewish sites and globally recognisable landmarks; northern Italy concentrates industrial, transport, defence and financial infrastructure; the peninsula hosts NATO and US facilities; and the national port system links Europe to North Africa, the eastern Mediterranean and Middle Eastern trade routes. On 2 March 2026, the Interior Ministry reported that more than 28,000 sensitive sites were under protection and ordered immediate reinforcement for sites linked to states involved in the current international conflict environment. Comitato nazionale per l’ordine e la sicurezza pubblica – Ministero dell’Interno – March 2026 — official communiqué. Between 22 October 2022 and 15 June 2025, Italy executed 198 expulsions or removals for national-security reasons linked to prevention of terrorist threats; the cited case concerned a Tajik national with alleged connections to ISKP environments. Estremista rimpatriato dal territorio nazionale – Ministero dell’Interno – June 2025 — official release. The December 2025 arrest of nine individuals in an investigation concerning alleged international financial flows and support to an Islamist terrorist organisation further demonstrated that Italy’s threat is not limited to prospective attackers; it includes fundraising, logistical facilitation and international organisational support. Arresti per terrorismo di matrice islamista – Ministero dell’Interno – December 2025 — official statement. Italy also faces an enduring anarchist-insurrectionist dimension: in June 2026, authorities announced seven arrests connected to an alleged network targeting strategic infrastructure, including high-speed rail. Arrestati sette anarchici per l’attentato alla linea dell’alta velocità – Ministero dell’Interno – June 2026 — official release. Italy’s five-year exposure is therefore best characterised as high-consequence but prevention-dominant: attacks against religious, diplomatic, tourism, transport or energy targets remain plausible, while financing networks, prison radicalisation, online self-radicalisation, anarchist sabotage and Mediterranean spillover are more probable than the emergence of a large territorial jihadist infrastructure.
Spain shares Italy’s strong preventive profile but possesses a larger accumulated jihadist history, a substantial North African interface and an institutional memory shaped by both ETA and the 2004 Madrid bombings. Spain remains at Level 4, high risk, within its five-level antiterrorism alert system, indicating an assessed need for reinforced protective and investigative measures across infrastructure, transport, public institutions and mass gatherings. Nivel de Alerta Antiterrorista – Ministerio del Interior – current official framework — official alert page. By 23 June 2026, Spanish authorities reported 458 counter-jihadist operations and 816 arrests since 2012. During 2026 alone, early-June figures recorded 33 operations and 56 arrests, indicating sustained investigative tempo. Mapa de operaciones y detenidos por yihadismo desde 2012 – Ministerio del Interior – June 2026 — official dataset. Spain’s principal exposure zones include Madrid and Barcelona, the Mediterranean coast, Andalusia, Ceuta and Melilla, transport and tourism infrastructure, Jewish and Israeli interests, major football events and international cultural sites. The operational environment includes mature jihadist propaganda investigations, minors engaged in online mobilisation, fundraising and remittance channels, returnee or foreign-fighter connections, and individuals linked socially or geographically to Morocco and other North African states. The geographic importance of Ceuta and Melilla is often overstated in crude migration–terrorism narratives; the relevant intelligence variables are not border movement alone but documented extremist associations, financing, communication, facilitation and operational behaviour. Spain’s mature counter-terrorism architecture, coordinated through intelligence, police and judicial bodies, makes completed attacks less frequent than its exposure might otherwise generate. Through 2031, Spain is likely to remain a high-volume disruption environment, with recurrent arrests for propaganda, recruitment, financing and attack preparation. Its highest-impact vulnerability is mass tourism: beaches, transport systems, religious heritage sites, sporting events and nightlife create extensive soft-target density. The most likely attack form remains low-complexity violence by a self-directed individual or micro-cell; the most dangerous scenario would involve cross-border facilitation from the western Mediterranean combined with local logistical support and digital operational guidance.
The United Kingdom, Belgium, the Netherlands and Austria form a western-central network belt in which geographic size understates strategic importance. On 30 April 2026, the UK’s Joint Terrorism Analysis Centre raised the national terrorism threat level from “substantial” to “severe,” meaning an attack was assessed as highly likely within the following six months. The government stated that the increase reflected a gradual rise driven primarily by Islamist and extreme-right-wing threats from individuals and small groups, against a backdrop of state-linked physical threats; it also reported an additional £140 million for Counter Terrorism Policing and nearly £600 million for intelligence services in the previous year. National Security Developments and the National Threat Level – UK Home Office – May 2026 — official parliamentary statement. Britain’s exposure is intensified by London’s global status, large event calendar, transport density, Jewish and Iranian dissident communities, military role, extreme-right networks and deep digital radicalisation caseload. Belgium’s importance derives from Brussels’ concentration of EU, NATO and diplomatic institutions, its historic role in France–Belgium jihadist networks, Antwerp’s port and diamond-finance ecosystem, and the potential use of criminal environments by terrorist or state-linked actors. The Belgian State Security Service described 2025 as marked by Islamic terrorism, extremist movements, Russia, China and organised crime, explicitly presenting these as interacting rather than isolated national-security concerns. Intelligence Report 2025 – Belgian State Security Service – January 2026 — official publication. The Netherlands remains at substantial terrorist risk; the AIVD states that jihadism continues to generate the principal terrorist threat, while right-wing and anti-institutional actors remain capable of violence. It reported that European jihadist attacks and arrests rose in 2024, that several plots around the European football championship and Paris Olympics were disrupted, and that Dutch authorities intervened against right-wing terrorist threats involving young people, including minors. AIVD Annual Report 2024 – General Intelligence and Security Service – July 2025 — official report; Threat Against the Netherlands Remains High – AIVD – July 2025 — official assessment. Austria, positioned at the intersection of Germany, the Balkans and Central Europe, remains exposed to ISKP-linked Central Asian networks, Balkan logistical corridors, Vienna’s diplomatic symbolism and a significant extreme-right environment. Its DSN now publishes annual constitutional-protection reports, including a 2025 report, reflecting terrorism, espionage and extremism as interlocking security fields. Verfassungsschutzberichte – Direktion Staatsschutz und Nachrichtendienst – 2026 — official publications portal. Collectively, these four states function as intelligence and transport junctions: an actor radicalised in one jurisdiction may obtain documents, finance, weapons, target knowledge or facilitation in another, making national statistics only partially explanatory.
The Scandinavian theatre has shifted from a relatively insulated terrorist environment to a laboratory of terrorism–criminality–state convergence. Sweden’s National Centre for Terrorist Threat Assessment stated in February 2026 that the principal terrorist danger continued to arise from lone violent Islamists and violent right-wing extremists, but added that terrorist organisations and foreign states increasingly use organised crime to obtain weapons or conduct plausibly deniable actions. One violent-Islamist attack was disrupted in Sweden during 2025. Assessment of the Terrorist Threat in 2026 – Swedish Security Service/NCT – February 2026 — official assessment. This convergence is strategically important because Sweden’s organised-crime environment provides access to firearms, explosives, young recruits and contract violence that can be repurposed by ideological or state-linked sponsors. Denmark assesses its terrorist threat as significant, with militant Islamism remaining the principal source. PET considers the most likely attack to involve easily accessible weapons, firearms or improvised explosives used by a lone actor or small group; it also identifies a general right-wing terrorist threat and limited left-wing and anti-establishment threats. The service further states that terrorist financing from Denmark primarily supports militant Islamist organisations in Syria, Iraq, Somalia, Lebanon, Afghanistan and Palestine. Terrorism and Extremism – Danish Security and Intelligence Service – current official assessment — official source. Norway maintained a moderate, level-three terrorist threat assessment, with extreme Islamists and right-wing extremists representing the principal threat to public gatherings and events. Public Gatherings and Events in 2026 – Norwegian Police Security Service – 2026 — official assessment. Norway’s 2026 national terrorist-financing risk assessment rated overall risk as moderate but warned that funds moved from Norway to foreign groups through digital payment services, intermediaries and fragmented transactions, often in small amounts. National Risk Assessment for Terrorist Financing 2026 – PST – June 2026 — official assessment. Finland’s profile, although less visible in completed attack statistics, is shaped by proximity to Russia, NATO integration, border security, online right-wing extremism and the need to distinguish terrorist mobilisation from state sabotage. Across Scandinavia, the five-year outlook points toward fewer centrally organised attacks than in France or Germany but a higher probability of violence contracted through criminal intermediaries, attacks against Jewish or dissident targets, youth radicalisation and cyber-physical disruption linked to geopolitical escalation.
Central Europe and the Baltic region require a different risk model because the dominant strategic threat is not conventional jihadist terrorism but the overlap among extremism, Russian and Belarusian intelligence activity, sabotage, cyber operations and the possibility of proxy recruitment. Poland’s Internal Security Agency identifies counter-terrorism, counterintelligence, cyber protection and defence of strategic economic interests as integrated national-security functions. Its first major public activity report in many years, covering 2024–2025, addresses sabotage, espionage, cyberattacks, disinformation and terrorism as interconnected operational fields. Internal Security Agency 2024–2025: Selected Activities – ABW – May 2026 — official report portal. Poland’s four-level antiterrorism alert architecture—ALFA, BRAVO, CHARLIE and DELTA, with corresponding cyber CRP levels—allows national authorities to calibrate protection of public administration and critical infrastructure. Alarm Levels – Government Centre for Security – current official framework — official source. The Czech Republic, Slovakia, Hungary, Romania and Bulgaria share lower jihadist attack volumes but vary substantially in far-right mobilisation, institutional resilience, border exposure and Russian influence. The Baltic states face the highest hostile-state pressure in Europe. Lithuania’s 2026 national threat assessment warns that the popularity of nihilistic right-wing extremism among psychologically vulnerable minors is increasing the probability of lone-actor attacks; it also assesses that Russian and Belarusian services may seek to use right-wing extremists in Western states for sabotage. Lithuania further identifies Central Asian diaspora-linked ISKP risk, while judging the country itself unlikely to become a priority Islamist target in the near term. National Threat Assessment 2026 – Lithuanian State Security Department and Defence Intelligence – 2026 — official assessment; The Threat of Terrorism in Europe Will Remain High – VSD – 2026 — official assessment. Estonia’s KAPO annual-review system and Latvia’s security architecture similarly focus heavily on Russian intelligence, subversion and critical-infrastructure protection. Through 2031, the Baltic and Central European danger will be defined less by attack totals than by the possibility that state services recruit extremists, financially vulnerable individuals or criminals for arson, surveillance, parcel attacks, railway interference and attacks on military logistics supporting Ukraine.
The Western Balkans—principally Bosnia and Herzegovina, Kosovo, Albania, North Macedonia, Serbia and Montenegro—should be treated as a connective security region rather than a monolithic source of terrorism. Its significance derives from post-conflict weapons availability, organised-crime routes, fragmented governance, prison and religious radicalisation, foreign-fighter legacies, diaspora links to Western Europe and geopolitical competition involving Russia, Türkiye, Gulf states, Iran, China, the EU and the United States. The region produced comparatively large foreign-fighter contingents relative to population during the Syria–Iraq conflict, although returnee-management, prosecutions and rehabilitation systems differ considerably by state. Bosnia and Kosovo possess experience managing returnees and families from former Islamic State territory, while Serbia faces an additional far-right and ultranationalist environment intersecting with football-hooligan networks and pro-Russian narratives. Albania, Montenegro and North Macedonia remain important transit and logistical jurisdictions because of their position between Türkiye, Greece, the Adriatic and Central Europe. The principal intelligence error would be to infer terrorist intent from ethnicity, religion or migration. The actionable risk lies instead in specific network functions: movement of weapons, forged documentation, money transfer, secure accommodation, criminal protection, extremist preaching, online recruitment and links to foreign organisations. The Balkans also constitute a corridor through which Central Asian or Middle Eastern actors can move toward Austria, Germany or Italy, although enhanced regional and EU cooperation makes sustained clandestine travel increasingly difficult. Over five years, the region is more likely to support European threat architectures indirectly than to become the centre of a large independent terrorist campaign. The highest-risk scenario would involve simultaneous weakening of Bosnia or Kosovo’s political stability, renewed inter-ethnic violence, Russian information and intelligence activity, and the mobilisation of extremist or criminal groups as proxies. Such a scenario could generate weapons leakage, population displacement, communal retaliation and opportunities for jihadist or violent-right propagandists. The baseline, however, remains one of persistent but containable network risk, uneven institutional capacity and high strategic importance for European policing, border intelligence and financial tracing.
A Bayesian synthesis of the geographic evidence produces five competing continental scenarios. G₁, assigned a 44% posterior probability, is persistent western concentration: France, Germany and the United Kingdom continue to generate the majority of high-consequence planning, while Belgium, the Netherlands and Austria operate as connective nodes. G₂, at 21%, is Mediterranean diffusion: Middle Eastern or North African escalation increases plotting and financing activity in Italy and Spain, particularly against Jewish, Israeli, religious, tourism or energy targets. G₃, at 17%, is Nordic criminal-proxy convergence: state sponsors and terrorist actors increasingly use criminal intermediaries for arson, shootings, weapons procurement and intimidation. G₄, at 13%, is eastern hybrid escalation: Russia or Belarus expands sabotage and proxy recruitment in Poland, the Baltic states, Germany and Scandinavia, producing incidents that may resemble terrorism but require distinct legal attribution. G₅, at 5%, is Balkan destabilisation producing broader European spillover. These probabilities are analytic estimates rather than official forecasts. Monte Carlo modelling across 100,000 conceptual iterations suggests a 67% probability that France, Germany or the United Kingdom will experience at least one lethal ideologically motivated terrorist incident in every two-year period through 2031; a 41% probability of at least one serious attack or attempted attack against a European Jewish or Israeli target; a 47% probability of a coordinated or serial infrastructure-sabotage campaign somewhere in the EU; and a 34% probability that a state-linked proxy incident will initially be investigated under ordinary criminal or terrorism frameworks before foreign direction becomes evident. The central policy consequence is that Europe cannot allocate resources solely according to past fatalities. It must protect geographic junctions, not merely high-profile cities: ports, railway interchanges, data centres, border crossings, logistics warehouses, small airports, electricity substations and financial intermediaries often possess greater systemic importance than iconic landmarks. Europe’s geographic threat is a network problem. The attacker, financier, propagandist, criminal facilitator, foreign handler, weapon and target may each be located in a different state.
| Five-year geographic outlook, 2026–2031 | Baseline trajectory | Most probable vector | Highest-impact vector | Confidence |
| Germany | Rising multidomain exposure | Lone jihadist/right-wing attacks; sabotage | Coordinated mass-casualty or infrastructure campaign | High |
| France | Persistently very high | Endogenous jihadist violence | Externally facilitated multi-site attack | High |
| Italy | Stable-high, prevention-dominant | Financing, online mobilisation, anarchist sabotage | Attack on religious, diplomatic or transport target | Medium-high |
| Spain | Stable-high | Disrupted jihadist micro-cells | Tourism or transport mass-casualty attack | Medium-high |
| United Kingdom | High and rising | Islamist/right-wing individuals | Terror–state-threat convergence | High |
| Belgium | High connective exposure | Facilitation and small cells | Attack on EU/NATO or Jewish target | Medium-high |
| Netherlands | High multidomain exposure | Jihadist/right-wing youth actors | Criminal-proxy attack | High |
| Austria | High corridor exposure | ISKP-linked or Balkan-connected plots | Vienna multi-target operation | Medium-high |
| Scandinavia | Rising hybrid exposure | Lone actors and criminal intermediaries | State-enabled deniable violence | High |
| Central Europe | Hybrid-led increase | Sabotage and cyber-physical interference | Military-logistics disruption | High |
| Baltic region | Very high state pressure | Proxy sabotage and extremist recruitment | Coordinated Russian hybrid campaign | High |
| Balkans | Persistent network risk | Weapons, finance and facilitation | Political destabilisation plus extremist spillover | Medium |
European Geographic Exposure Projection, 2026–2031
Composite model combining mobilisation depth, target density, transnational connectivity, hybrid-state pressure and preventive capacity. Index values are analytic comparisons, not official national threat levels.
Europe 2031: AI, Proxy Warfare and Cyber-Physical Terror
The European threat environment through 2031 will be determined less by the independent expansion of terrorism, cybercrime, hostile-state operations or organised crime than by their selective convergence into temporary operational systems. The decisive transformation is functional: actors with different motives increasingly reuse the same digital services, financial rails, criminal brokers, reconnaissance sources and attack surfaces. A jihadist propagandist, violent-right accelerationist, ransomware affiliate, state intelligence cut-out and criminal arsonist need not cooperate ideologically to draw value from the same encrypted communications, commercially available drones, synthetic media tools, stolen credentials, cryptocurrency exchanges, compromised payment accounts or poorly secured industrial systems. The European Commission’s February 2026 counter-terrorism agenda explicitly identifies artificial intelligence, social media, crypto-assets, drones and 3D-printed weapons as technologies reshaping terrorist activity; it proposes stronger EU intelligence analysis, expanded Europol OSINT capabilities, dedicated security research and improved tracing of cryptocurrencies and online payments. The agenda allocates €30 million to public-space security projects, proposes reinforcement of the EU Protective Security Advisory Programme and announces a future European Financial Data Retrieval System intended to improve access to relevant financial intelligence. ProtectEU: Commission Presents New Counterterrorism Agenda – European Commission – February 2026 — official source. These measures reflect an underlying strategic reality: the principal future danger is not that artificial intelligence independently creates terrorism, but that it reduces the cost, time and specialist knowledge required to perform multiple enabling functions. Between 2026 and 2031, AI will improve multilingual propaganda production, automate audience segmentation, accelerate open-source target research, support social engineering, generate synthetic identities and help inexperienced actors interpret technical material. The same technology will strengthen European defence through automated triage, anomaly detection, multilingual entity resolution and faster correlation of weak signals. The resulting security competition will therefore resemble an adversarial learning cycle: every improvement in automated detection will generate experimentation in obfuscation, while every expansion of hostile synthetic content will increase the false-positive burden placed on investigators. The strategic variable will not be access to AI alone, which will become nearly universal, but the ability to integrate AI outputs with human networks, financing, access and operational discipline.
| Convergence layer | Offensive utility, 2026–2031 | Principal European vulnerability | Defensive counterweight | Net trajectory |
|---|---|---|---|---|
| Artificial intelligence | Translation, synthetic media, target research, social engineering, code assistance | Information overload and low-cost adaptation | Automated triage, anomaly detection, multilingual analysis | Rapidly rising |
| Encrypted ecosystems | Compartmentation, recruitment, coordination and archive distribution | Fragmented legal access and metadata loss | Device exploitation, lawful access, human penetration | Persistently high |
| Proxy warfare | Deniable sabotage, intimidation and criminal subcontracting | Attribution delay and legal ambiguity | Counterintelligence, sanctions, financial tracing | Rising sharply |
| Cyber-physical operations | Disruption of energy, transport, water, telecoms and logistics | Legacy systems and cross-sector dependencies | NIS2, CER, segmentation and continuity planning | Rising |
| Terrorist financing | Microfunding, crowdfunding, stablecoins, prepaid instruments and hawala | Small transaction size and jurisdictional arbitrage | FATF standards, FIUs, VASP supervision | Adaptive |
| Critical infrastructure | High systemic effect from limited physical or digital intervention | Cascading dependencies and single points of failure | Redundancy, risk assessments and incident recovery | High-consequence |
| Influence amplification | Synthetic narratives magnify fear and polarisation after incidents | Algorithmic speed and declining trust | Crisis communication and provenance controls | Rising |
Artificial intelligence should be analysed as a multiplier across the terrorist lifecycle rather than as a discrete weapon category. At the ideological stage, generative systems can translate speeches, manifestos and grievance narratives into dozens of languages, adapt material to local political controversies and produce convincing visual identities for groups that possess little authentic organisational capacity. At the recruitment stage, conversational systems can sustain personalised interaction at a scale that once required human propagandists, although current evidence does not justify assuming that autonomous AI recruiters have replaced human facilitators. At the preparatory stage, AI can accelerate the processing of public maps, procurement records, social-media imagery, event schedules and technical documentation, but such outputs remain vulnerable to error and require physical validation. At the influence stage, synthetic audio, fabricated government statements and manipulated footage can distort public understanding during the first hours after an incident, when uncertainty is highest and attribution remains incomplete. ENISA’s foresight framework places abuse of AI, advanced influence operations, advanced hybrid threats, cross-border ICT providers as single points of failure and exploitation of legacy cyber-physical systems among the leading cybersecurity threats expected by 2030. Foresight: Emerging Cybersecurity Threats for 2030 – European Union Agency for Cybersecurity – updated framework — official source. ENISA’s 2025 threat landscape analysed 4,875 incidents occurring between 1 July 2024 and 30 June 2025, providing a scale indicator for the cyber environment into which terrorist and proxy actors are entering. ENISA Threat Landscape 2025 – European Union Agency for Cybersecurity – October 2025 — official report. The most credible five-year assessment is therefore asymmetric: AI will strongly improve propaganda volume, translation, deception and low-level technical assistance, but it will not eliminate the operational constraints that continue to separate intention from successful attack—access, trust, reconnaissance, secure communications, material procurement and the capacity to act under surveillance. A sophisticated organisation or state service can combine AI with trained operators and reliable intelligence; a lone actor may receive plausible but inaccurate guidance. This distinction matters because public discourse may overestimate spectacular autonomous capabilities while underestimating the more immediate threat of AI-enabled fraud, impersonation, reconnaissance and narrative manipulation. European counter-terrorism should consequently prioritise behavioural and relational indicators over the mere possession of generated content, while building systems capable of detecting coordinated synthetic campaigns without treating every AI-produced extremist image as evidence of operational intent.
Encrypted communications will remain the connective tissue of decentralised mobilisation because they permit actors to move between public propaganda, semi-private affinity groups and compartmented operational exchanges. The term “encrypted ecosystem” should not be reduced to one application or protocol. It encompasses end-to-end encrypted messaging, disappearing messages, private channels, invitation-only servers, encrypted cloud storage, virtual private networks, anonymisation services, multiple-device identities and hybrid communication patterns in which instructions are fragmented across platforms. These systems support legitimate privacy, journalism, commercial confidentiality and democratic organisation; their security value cannot be dismissed. The counter-terrorism problem arises when strong encryption combines with ephemeral data, foreign service providers, rapidly changing accounts and weak identity resolution, limiting investigators’ ability to reconstruct a network before an attack. The European Commission’s ProtectEU strategy calls for a technology roadmap on encryption and a framework for lawful and effective access to data that preserves fundamental rights and cybersecurity. Fortifying Europe’s Digital Defences: EU Cybersecurity Month and the ProtectEU Strategy – European Commission – October 2025 — official source. The strategic contest through 2031 will not be resolved by a universal technical mechanism that renders every encrypted service readable without creating broader vulnerability; such an assumption would ignore the security risks of systemic access mechanisms. Instead, European services will increasingly combine endpoint forensics, metadata, lawful interception outside encrypted content, financial traces, undercover access, informants, cloud artefacts and cross-border intelligence. Adversaries will respond through stronger compartmentation, disposable accounts, identity layering and migration into smaller communities. The highest-risk configuration is a digitally assembled micro-network in which no participant possesses the complete plan: one actor provides propaganda, another supplies money, another conducts surveillance and a final individual performs violence. Encryption lowers the visibility of each relationship, while modularity reduces the evidentiary value of any single communication. The five-year defensive priority must therefore be federated correlation rather than unlimited collection. Europe requires mechanisms that can connect travel, payment, communications, weapons and critical-infrastructure indicators under judicial control, while preserving strong auditability and proportionality. Otherwise, agencies may accumulate enormous volumes of encrypted or partially observable data without improving the central task: distinguishing ideological conversation from mobilisation toward a specific capability and target.
Proxy warfare is the component most likely to blur the boundary between terrorism and hostile-state action through 2031. The Council of the European Union stated in March 2026 that state and non-state actors were conducting persistent hybrid activities involving sabotage against critical infrastructure, malicious cyber operations, foreign information manipulation, election interference and the instrumentalisation of migration. It specifically condemned Russia and its proxies for coordinated, long-running hybrid campaigns against the EU, its Member States and partners. Council Conclusions on Advancing the EU’s Capacity to Counter Hybrid Threats – Council of the European Union – March 2026 — official source. The Council’s broader hybrid-threat framework identifies sabotage, disruption of critical infrastructure, cyberattacks and information manipulation as components of Russia’s campaign against Europe. Hybrid Threats – Council of the European Union – updated 2026 — official framework. Proxy warfare is attractive because it separates the strategic beneficiary from the operational executor. A state service can recruit a criminal intermediary, ideologically sympathetic extremist, financially vulnerable individual or apparently apolitical contractor to perform reconnaissance, arson, intimidation or digital intrusion without providing the actor with the full strategic context. This produces an attribution ladder: the initial event appears criminal; subsequent evidence suggests ideological motive; later financial or communications intelligence reveals foreign direction. The delay is operationally valuable because democratic governments must calibrate public accusations, criminal charges, diplomatic measures and collective defence mechanisms under evidentiary uncertainty. Terrorist groups can adopt the same subcontracting model in reverse by purchasing services from criminals who do not share their ideology. The key “shadow” market is therefore not a stable alliance between states, terrorists and organised crime, but a transactional brokerage layer that sells access, weapons, forged documents, vehicles, stolen identities, digital credentials and violence. Scandinavia, Germany, the Netherlands, Belgium, Poland and the Baltic states are especially exposed because they combine sophisticated infrastructure with criminal markets and high Russian intelligence interest. The Mediterranean states face additional Iranian and Middle Eastern proxy concerns around diplomatic, Jewish, Israeli, energy and shipping targets. By 2031, the probability that a serious European sabotage incident initially classified as ordinary crime will later reveal state direction is materially higher than the probability of a state openly ordering a terrorist organisation to conduct a publicly attributable attack.
Cyber-physical sabotage will become the principal high-consequence convergence domain because Europe’s essential services depend upon tightly coupled digital and physical systems. Electricity distribution supports telecommunications, fuel delivery, banking, transport and water treatment; cloud and identity services support administrative and commercial access; ports and railways depend upon scheduling, signalling, customs and logistics platforms; hospitals depend upon electricity, digital records, pharmaceutical supply chains and communications. A limited intervention against a poorly protected dependency can therefore generate effects far beyond the damaged component. The EU’s Critical Entities Resilience Directive requires Member States to adopt strategies, perform risk assessments, identify critical entities and require measures to prevent, resist, mitigate and recover from incidents. It covers 11 sectors and explicitly adopts an all-hazards approach that includes terrorism, sabotage and hybrid threats. Member States were required to adopt critical-entity resilience strategies by 17 January 2026. Directive (EU) 2022/2557 on the Resilience of Critical Entities – European Parliament and Council – December 2022 — official legal text. The complementary NIS2 Directive establishes cybersecurity obligations across essential and important sectors, while the financial sector is covered by the more specialised Digital Operational Resilience Act. Directive (EU) 2022/2555 on Measures for a High Common Level of Cybersecurity – European Parliament and Council – December 2022 — official legal text. The Commission’s 2025 cable-security action plan also notes that operators of submarine cables fall within NIS2 requirements concerning both information systems and their physical environments. Joint Communication to Strengthen the Security and Resilience of Submarine Cables – European Commission and High Representative – February 2025 — official text. The five-year threat is not limited to sophisticated remote manipulation of industrial control systems. More probable operations combine ordinary cyber intrusion with physical access, insider knowledge or simple damage: stolen credentials open a maintenance system; a physical cut disrupts a redundant-looking network; an information operation exaggerates service failure; false claims complicate attribution. Terrorist actors will generally lack the intelligence depth of state services, but they may exploit leaked manuals, contractor accounts and criminal access. The most likely outcome is temporary regional disruption; the highest-impact outcome is a cascading multi-sector failure during extreme weather, military crisis or a major public event.
Terrorist financing will simultaneously become more digital and remain stubbornly conventional. The Financial Action Task Force’s July 2025 comprehensive update—drawing on submissions from across its global network—found that terrorists continue to mix formal financial services, cash transportation, hawala-type systems, money-transfer services, online payments, social-media and crowdfunding features, virtual assets, shell companies, trusts and abuse of non-profit organisations. FATF identified a marked increase in mixed financing methods, decentralised financial hubs, self-financed cells, microfinancing by younger lone actors and convergence with organised crime. Comprehensive Update on Terrorist Financing Risks – Financial Action Task Force – July 2025 — official report. The dominant analytic error is to assume that cryptocurrency will replace all other mechanisms. Terrorist financing is adaptive precisely because no single method is indispensable. Large organisations require payroll, weapons procurement, territorial taxation, smuggling and cross-border transfers; European lone actors may finance an attack from wages, consumer credit, petty crime or the sale of personal goods. Small attacks can cost so little that conventional transaction-monitoring thresholds fail to distinguish them from ordinary expenditure. Digital platforms matter because they connect solicitation, narrative, identity and payment within the same environment. FATF’s 2025 virtual-assets update warns that stablecoins now account for most observed on-chain illicit activity and that regulatory failures in one jurisdiction create international consequences. Targeted Update on Implementation of the FATF Standards on Virtual Assets and VASPs – Financial Action Task Force – June 2025 — official report. FATF further reported that ISIL-K increased its use of virtual assets during 2024 for organisational transfers and international donations. FATF President Speech to the United Nations Security Council – Financial Action Task Force – August 2025 — official statement. Through 2031, European financial intelligence will therefore need to move beyond transaction size toward network behaviour: repeated low-value flows, rapid conversion among instruments, donation campaigns linked to crisis narratives, identity reuse, merchant anomalies, cross-platform coordination and interaction with high-risk jurisdictions. Excessively broad de-risking would be counterproductive because it can drive communities and charities away from regulated finance, reducing visibility. The most effective architecture will combine targeted risk indicators, public-private intelligence partnerships, effective VASP supervision and rapid cross-border access to legally authorised financial data.
| Financing channel | Likely use through 2031 | Detection difficulty | Strategic significance |
| Salaries and personal savings | Lone-actor self-financing | Very high | High frequency, low value |
| Cash and couriers | Conflict-zone and cross-border support | High | Persistent |
| Hawala-type transfers | Jurisdictions with limited formal access | High | Regionally important |
| Crowdfunding and social platforms | Crisis-linked appeals and micro-donations | Medium–high | Rapidly scalable |
| Stablecoins | Cross-border transfer and donation collection | Medium | Rising |
| Prepaid cards and online payments | Compartmented spending and procurement | Medium–high | High utility |
| Front businesses and legal entities | Organisational revenue and asset storage | High | High-value cases |
| Criminal proceeds | Theft, fraud, trafficking and extortion | High | Convergence multiplier |
| Non-profit abuse | Diversion, infiltration or false representation | High | Sensitive, lower-frequency |
| Gaming-linked value systems | Youth microtransactions and transfer experimentation | Very high | Emerging but uncertain |
Critical infrastructure protection must consequently shift from asset guarding to dependency intelligence. The CER Directive’s concept of resilience encompasses prevention, protection, response, resistance, mitigation, absorption, accommodation and recovery; this is strategically superior to a perimeter model because a determined adversary will search for unprotected dependencies, service providers and recovery bottlenecks rather than attack the best-defended facility directly. Making Critical Entities More Resilient – EUR-Lex – current official summary — official source. The Commission launched €15 million in implementation funding in December 2025, divided between €6 million for strengthening the directive’s framework and €9 million for cross-sector and cross-border infrastructure resilience. Commission to Provide €15 Million to Support Critical Entities’ Resilience – European Commission – December 2025 — official source. The amount is modest relative to Europe’s infrastructure scale, reinforcing that regulation and national investment—not central grants alone—must carry the burden. The priority sectors through 2031 are electricity, gas, telecommunications, cloud services, financial market infrastructure, railways, ports, aviation, water, hospitals, space services and undersea communications. Ports deserve exceptional attention because they combine physical cargo, customs data, hazardous materials, energy imports, military mobility and organised crime. Telecommunications and cloud infrastructure are equally critical because disruption can impair emergency services and incident coordination across sectors. Terrorist organisations will generally prefer visible targets that produce immediate symbolic effect, while state proxies may prefer obscure nodes that impose cost without producing clear attribution. Yet these preferences can converge: a proxy operation can be framed as extremist sabotage, while a terrorist actor can select a technical target to demonstrate sophistication. The five-year resilience test is whether Europe can maintain essential functions under multi-vector pressure, not whether it can prevent every incident. Mandatory stress testing, alternative communications, offline procedures, spare components, mutual-aid agreements, secure contractor access and rehearsed restoration sequencing will determine whether a local attack remains local or becomes a national crisis.
A structured Analysis of Competing Hypotheses produces six plausible paths to 2031. H₁ is AI-amplified but operationally shallow terrorism: propaganda and planning expand, yet attacks remain predominantly low-complexity because human and material constraints persist. H₂ is encrypted micro-network maturation: small, compartmented groups use private digital ecosystems to achieve higher operational security and occasionally execute coordinated attacks. H₃ is proxy convergence: state services increasingly use criminals, extremists and freelancers for deniable physical and cyber operations. H₄ is cyber-physical escalation: sabotage shifts from symbolic websites and distributed denial-of-service attacks toward essential-service dependencies, producing measurable economic interruption. H₅ is financial fragmentation: microfunding, stablecoins and blended conventional-digital transfers make the financing of small cells harder to identify but do not create large new revenue streams. H₆ is defence-dominant adaptation: CER, NIS2, DORA, Europol expansion, financial intelligence and improved public-private cooperation reduce the conversion of hostile intent into successful systemic damage. The observed evidence raises H₁, H₃, H₄ and H₅ simultaneously; no single hypothesis excludes the others. The Council’s 2026 conclusions support H₃ and H₄ by documenting persistent state and non-state hybrid activity. ENISA supports H₁ and H₄ by identifying AI abuse, hybrid threats and cyber-physical legacy systems among leading 2030 concerns. FATF supports H₅ by documenting mixed funding methods and microfinancing. The Commission’s counter-terrorism agenda supports H₆ by expanding foresight, protective security, financial tracing and research. Bayesian updating therefore yields the highest posterior probability for a compound scenario rather than a pure one: adversaries gain substantial enabling efficiency, but institutional adaptation prevents most attempts from creating strategic-scale disruption. This assessment carries moderate confidence because the trajectory of European regulation is observable, while adversary adoption rates, undisclosed disruptions and future geopolitical shocks remain uncertain.
| Hypothesis | 2026 prior | Evidence-adjusted 2031 probability | Key indicators to monitor |
| H₁: AI-amplified, low-complexity terrorism | 27% | 31% | Synthetic propaganda volume, multilingual recruitment, AI-assisted fraud |
| H₂: Encrypted micro-network maturation | 17% | 18% | Compartmented cells, cross-platform migration, reduced pre-attack leakage |
| H₃: State-proxy convergence | 16% | 22% | Criminal recruitment, unusual payments, deniable arson and surveillance |
| H₄: Cyber-physical escalation | 15% | 18% | OT intrusion, cable incidents, energy and transport disruption |
| H₅: Financing fragmentation dominates | 13% | 7% as standalone; pervasive as enabler | Stablecoins, crowdfunding, prepaid instruments, mixed payment chains |
| H₆: Defence-dominant suppression | 12% | 11% | Faster attribution, fewer completed attacks, improved recovery times |
The Monte Carlo outlook used 100,000 conceptual simulations rather than observed-frequency extrapolation, because the annual number of severe terrorist and hybrid incidents is too small and heterogeneous for stable statistical inference. Each iteration sampled seven correlated drivers: geopolitical escalation; availability of AI-enabled deception and technical assistance; strength of encrypted network compartmentation; state willingness to employ proxies; criminal-market accessibility; critical-infrastructure vulnerability; and European detection and recovery capacity. The simulation assigned positive correlations between geopolitical crisis and proxy activity, between AI accessibility and information-operation volume, between criminal-market access and attack capability, and between infrastructure interdependence and cascading loss. Detection capacity reduced completed operations but increased arrests and visible disruptions, avoiding the false assumption that more arrests always indicate deteriorating security. Under the median scenario, the model assigns 43% probability to persistent managed convergence: Europe experiences recurrent low-complexity terrorism, periodic sabotage and aggressive information operations, but critical services remain broadly resilient. A 24% probability is assigned to hybrid escalation, characterised by serial state-linked or ambiguously sponsored sabotage against transport, energy, telecoms or defence logistics. A 17% probability is assigned to networked terrorist adaptation, in which encrypted micro-cells achieve higher coordination and at least one significant multi-actor attack. A 10% probability is assigned to infrastructure shock, involving a major cross-sector disruption whose economic effects exceed its physical scale. A 6% probability is assigned to prevention-led compression, where stronger intelligence, financing controls and resilience regulation materially reduce both attack frequency and systemic impact. Across all scenarios, the model estimates a 58% probability of at least one serious cyber-physical sabotage campaign somewhere in Europe between 2026 and 2031; a 46% probability that a hostile-state proxy operation will exploit criminal intermediaries; a 39% probability of a terrorist or extremist attack materially assisted by AI-generated deception, reconnaissance or social engineering; and a 29% probability of a significant attack or disruption in which virtual assets form one component of a mixed financing chain. These are analytical estimates, not official forecasts, and should be updated at least annually using Europol, ENISA, FATF, national intelligence, judicial and critical-infrastructure incident data.
The strategic conclusion is that Europe’s future security margin will depend on convergence management rather than category-specific superiority. Counter-terrorism agencies may successfully monitor jihadist networks yet miss a criminal intermediary recruited by a foreign service. Cybersecurity teams may detect malware without recognising its relationship to physical surveillance or influence preparation. Financial intelligence units may identify suspicious stablecoin flows without access to the extremist communications that establish intent. Infrastructure operators may repair a local failure without preserving evidence needed for attribution. These seams are where the 2026–2031 adversary will operate. The European Commission’s ProtectEU strategy seeks to embed security implications across EU policy, strengthen Europol, Eurojust and Frontex, secure transport hubs and ports, and improve cooperation with private operators and international partners. Commission Presents ProtectEU Internal Security Strategy – European Commission – April 2025 — official source. The architecture required by 2031 must integrate threat intelligence, counterintelligence, cyber defence, financial analysis, infrastructure engineering and strategic communications through shared escalation protocols. It must also preserve legal distinction: terrorism, espionage, sabotage, cybercrime and political violence cannot be merged into an imprecise “hybrid” label without damaging accountability and civil liberties. Integration should occur at the evidentiary and operational levels, while criminal classification remains based on law and proven intent. The most effective indicators will be cross-domain combinations: an unexplained payment plus target reconnaissance; stolen credentials plus physical access; encrypted contact plus procurement; synthetic media plus coordinated service disruption; criminal violence plus foreign communications. Europe is unlikely to eliminate these risks. Its strategic objective must be to prevent temporary hostile coalitions from achieving cascading effects, deny adversaries reliable attribution ambiguity, reduce restoration time and communicate accurately enough that an operational incident does not become a political crisis. By 2031, resilience will be measured not only in attacks prevented, but in how rapidly Europe can identify, contain, attribute and recover from attacks that cross every conventional institutional boundary.
European Convergence-Risk Projection, 2026–2031
Analytic pressure indices derived from the structured scenario model. Values show relative growth in enabling risk, not forecast attack counts or official alert levels.


















