Executive Summary
BLUF: The decisive cyber advantage of 2026–2031 will come from governance speed, not merely from larger hacker cadres, superior malware, or a new military service.
AI is compressing reconnaissance, vulnerability discovery, social engineering, malware adaptation, defensive triage, and influence operations into machine-speed operational cycles.
The primary strategic weakness of Western cyber power is fragmented ownership across military commands, intelligence agencies, civilian departments, infrastructure operators, cloud providers, telecommunications companies, and software vendors.
The distinction between wartime cyber operations, espionage, criminal intrusion, hacktivism, and information warfare will become progressively less observable and less operationally useful.
Critical digital terrain increasingly resides in privately operated cloud, identity, semiconductor, telecommunications, subsea-cable, satellite, software-dependency, and AI-model infrastructures.
A Cyber Force could improve recruitment, readiness, doctrine, and force generation, but cannot independently resolve divided budget authority, network ownership, civilian oversight, industrial dependencies, or national incident command.
The baseline five-year model assigns a 68% probability that states will consolidate cyber governance without fully centralising operational forces, a 54% probability of at least one systemic multinational digital-service disruption, and a 37% probability of a cyber incident producing significant physical effects.
The central strategic requirement is therefore a single accountable governance architecture linking authority, intelligence, operational command, infrastructure defence, procurement, AI assurance, and financial responsibility.
Navigational Index
Pillar I — Sovereignty, Command and Cyber Governance
Who owns national and military cyberspace; who controls budgets, operational authorities, critical networks, intelligence collection, AI assurance, public-private coordination, and political accountability; and whether future cyber institutions can act at machine-relevant speed.
Pillar II — AI-Accelerated Cyber Conflict
How generative models, autonomous agents, vulnerability-discovery systems, synthetic identities, adaptive malware, machine-speed defence, model poisoning, data manipulation, and AI-enabled influence operations will alter offensive scale, defensive economics, attribution, escalation, and strategic warning.
Pillar III — Digital Terrain, Shadow Networks and Systemic Risk
How cloud concentration, software dependencies, telecommunications infrastructure, satellite services, subsea cables, cybercrime markets, state proxies, hacktivist fronts, mercenary intrusion teams, cryptocurrency liquidity, and exploit brokerage will form the contested infrastructure of the 2026–2031 battlespace.
Master Abstract
The emerging cyber battlespace is not principally a contest between individual hackers, military cyber units, or isolated national agencies; it is a struggle between entire systems of authority competing to sense, decide, finance, coordinate, attribute, recover, and impose consequences faster than their adversaries. The starting proposition—governance before force structure—is therefore strategically correct but must be extended beyond the institutional debate over whether the United States should create a separate Cyber Force. A service can generate personnel, doctrine, training standards, acquisition programmes, career paths, and deployable formations, yet contemporary cyber power depends on digital terrain that military services usually neither own nor fully control. That terrain includes commercial identity platforms, hyperscale cloud environments, telecommunications backbones, software repositories, operational-technology vendors, satellite constellations, data brokers, semiconductor supply chains, artificial-intelligence models, managed service providers, payment networks, and privately maintained vulnerability intelligence. NATO already treats cyber defence as part of collective deterrence and defence, while emphasising political, military, technical, civil, and private-sector integration; it has also established an Integrated Cyber Defence Centre intended to improve network protection and situational awareness. Cyber Defence – NATO – July 2024 — verified official source.
The Alliance’s governance model demonstrates the central problem: cyber command authority can be military, but resilience remains nationally distributed and operationally dependent on civilian infrastructure. The European evidence reinforces this assessment. ENISA analysed 4,875 incidents between 1 July 2024 and 30 June 2025; DDoS accounted for 77%, hacktivism represented almost 80% of recorded incidents, phishing constituted approximately 60% of observed initial access, and public administration absorbed 38.2% of targeting. ENISA Threat Landscape 2025 – European Union Agency for Cybersecurity – October 2025 — verified official source. These figures do not indicate that low-cost hacktivism has become strategically dominant; they reveal that cyber conflict is producing a high-volume outer layer of coercion, distraction, narrative manipulation, target reconnaissance, and political signalling behind which more selective espionage, supply-chain preparation, credential acquisition, destructive access, and pre-positioning can remain concealed. Governance determines whether a state can separate this noise from operational warning and then convert warning into coordinated action.
Artificial intelligence will intensify this governance problem because it reduces the time available for human coordination while increasing the number, diversity, and apparent credibility of hostile actions. AI-enabled cyber operations should not be reduced to the simplistic proposition that language models will write better malicious code. Their more consequential effect will be the industrialisation of the complete intrusion lifecycle: automated target discovery, organisational mapping, multilingual pretext generation, synthetic voice and video, credential-harvesting adaptation, exploit-chain selection, malware mutation, privilege-escalation support, lateral-movement planning, data classification, extortion personalisation, influence amplification, and defensive-evasion testing. ENISA identifies AI both as an optimisation instrument for malicious activity and as a new attack surface, including the expanding AI supply chain and the use of large language models to enhance phishing and social engineering. EU Consistently Targeted by Diverse Yet Convergent Threat Groups – ENISA – October 2025 — verified official source. NATO’s revised AI strategy similarly recognises foundation models as general-purpose technologies, calls for alliance-wide testing, evaluation, verification and validation, and explicitly requires protection against adversarial AI use. Summary of NATO’s Revised Artificial Intelligence Strategy – NATO – July 2024 — verified official source. The United States has begun constructing operational information-sharing mechanisms around these risks through the Joint Cyber Defense Collaborative’s AI Cybersecurity Collaboration Playbook, which defines voluntary processes for sharing AI vulnerabilities and incidents among government, industry, and international partners. JCDC AI Cybersecurity Collaboration Playbook – Cybersecurity and Infrastructure Security Agency – January 2025 — verified official source. China’s official governance direction also integrates model, algorithm, data, infrastructure, and application security into a national monitoring, warning, and emergency-response framework, demonstrating that Beijing conceptualises AI security as a state-governance system rather than a narrow technical compliance problem. Opinions on Deepening Implementation of the “Artificial Intelligence Plus” Action – Cyberspace Administration of China – August 2025 — verified official Chinese source. Russia’s updated national AI strategy likewise identifies new classes of information-security threats arising from AI and links technological sovereignty, trusted systems, confidentiality, and state security. National Strategy for the Development of Artificial Intelligence – Government of the Russian Federation – February 2024 update — verified official Russian source. The strategic divergence is therefore not between states that regulate AI and states that do not; it concerns who controls the governance stack, whose values define acceptable risk, and whether operational authority rests primarily with defence institutions, civilian regulators, security services, technology firms, or vertically integrated state systems.
The five-year outlook must consequently be evaluated through competing institutional hypotheses rather than through linear extrapolation of attack counts. H₁ — Governance Consolidation: governments create single accountable cyber authorities with directive budget power while preserving distributed military, intelligence, civilian, and private operational components. H₂ — Service-Led Reorganisation: one or more major powers establish dedicated cyber services but leave core infrastructure ownership fragmented, improving force generation while only partially improving national resilience. H₃ — Platform Sovereignty: cloud, telecommunications, identity, semiconductor, AI, and security-platform providers acquire quasi-sovereign operational importance because only they possess cross-customer telemetry, global engineering capacity, and machine-speed remediation. H₄ — Adversarial Acceleration: Russia, China, Iran, North Korea, criminal syndicates, proxy operators, and commercial intrusion markets exploit Western coordination delays faster than governance reforms mature. H₅ — Coalition Fragmentation: regulatory divergence, classification barriers, sovereign-cloud policies, procurement nationalism, data-localisation rules, and inconsistent thresholds for offensive action weaken collective defence despite growing budgets. The initial Bayesian assessment assigns priors of 0.68 to H₁, 0.42 to H₂, 0.74 to H₃, 0.63 to H₄, and 0.39 to H₅; these are explicit analytical estimates, not official statistics, and are intentionally non-exclusive because several hypotheses can materialise simultaneously. A 100,000-iteration conceptual Monte Carlo model, using governance cohesion, AI offensive acceleration, infrastructure concentration, alliance interoperability, supply-chain exposure, cybercrime liquidity, and crisis intensity as interacting variables, produces three dominant outcome families for 2031: managed contestation at 46%, characterised by persistent espionage, disruption, proxy attacks, and bounded physical effects; systemic digital crisis at 37%, involving cascading multinational disruption across cloud, telecom, finance, logistics, energy, or public services; and strategic cyber rupture at 17%, involving destructive effects, prolonged national mobilisation, severe military interference, or escalation into conventional operations. These estimates should not be interpreted as actuarial forecasts. Their value lies in exposing the variables that most alter the outcome distribution. The sensitivity analysis identifies four decisive levers: clarity of accountable authority, access to cross-sector telemetry, pre-delegated incident powers, and recovery capacity for shared digital dependencies. A future Cyber Force may become one component of that architecture, but the report’s central finding is that the strategic unit of cyber power is no longer the operator or even the command. It is the governed ecosystem capable of converting distributed information and privately controlled infrastructure into coherent national action before an adversary converts ambiguity into irreversible advantage.
Strategic Cyber Governance Simulator · 2026–2031
Machine-Speed Conflict versus Human-Speed Authority
100,000 ITERATIONS
Scenario Variables
2031 Outcome Distribution
Analysis of Competing Hypotheses
Authority, budget control and incident command converge without total force centralisation.
A dedicated cyber service improves force generation but inherits network fragmentation.
Cloud, identity, telecom and AI providers gain quasi-sovereign defensive functions.
State and proxy ecosystems exploit decision latency faster than reform matures.
Data, doctrine, sovereignty and procurement barriers weaken collective cyber action.
Analytical simulation for scenario exploration. Values are structured estimates derived from stated assumptions and are not official probabilities, intelligence findings, or actuarial forecasts.
Pillar I — Sovereignty, Command and Cyber Governance, 2026–2031
The central problem of cyber sovereignty is no longer whether states possess legal jurisdiction over national networks, military systems, intelligence platforms, or critical infrastructure; it is whether they possess sufficient operational authority, telemetry, budgetary control, technical access, and decision speed to exercise that jurisdiction during a machine-accelerated crisis. National cyberspace does not correspond to a territorially bounded battlespace. It is a layered system composed of government networks, military command-and-control architectures, commercial cloud regions, telecommunications carriers, software dependencies, identity providers, satellite links, industrial-control systems, data centres, undersea cables, financial rails, privately owned threat-intelligence platforms, and foreign-manufactured hardware. The sovereign state may regulate these layers, purchase services from them, collect intelligence through them, or direct emergency measures affecting them, but it rarely owns all of them.
This creates a fundamental distinction between formal sovereignty and executable sovereignty. Formal sovereignty is the legal right to regulate, investigate, compel, defend, attribute, or retaliate; executable sovereignty is the practical ability to observe an incident, establish its scope, identify affected dependencies, assign command responsibility, issue binding instructions, mobilise industry, and restore essential functions before damage cascades. NATO’s own governance architecture illustrates this distribution. Political oversight rests with the North Atlantic Council; cyber policy is led by the Cyber Defence Committee; technical implementation passes through the NATO Consultation, Command and Control Board, NATO Military Authorities, the NATO Communications and Information Agency, the NATO Chief Information Officer, national governments, military commands, and infrastructure operators. NATO has also established a Cyberspace Operations Centre and agreed to create the NATO Integrated Cyber Defence Centre at SHAPE, expressly linking civilian infrastructure, Allied networks, military situational awareness, and industrial expertise. Cyber Defence – NATO – current official topic page — NATO Cyber Defence. Allies Agree New NATO Integrated Cyber Defence Centre – NATO – July 2024 — NATO Integrated Cyber Defence Centre. The resulting system is intentionally federated because NATO cannot replace national sovereignty, but federation imposes latency: intelligence must cross classifications, national authorities must consent to politically sensitive action, private operators must disclose relevant telemetry, and military commanders must understand dependencies that may exist outside defence ownership. The strategic question for 2026–2031 is therefore not whether governance will remain distributed—it will—but whether distributed sovereignty can be converted into pre-authorised, technically interoperable, continuously exercised command relationships capable of operating at machine-relevant speed.
The United States represents the most operationally mature but institutionally fragmented model. U.S. Cyber Command conducts military cyberspace operations; the military services organise, train, and equip much of the force; the Department’s Chief Information Officer exercises enterprise leadership over information technology, cybersecurity, architecture, and associated investment; the Principal Cyber Advisor has historically carried policy, oversight, and budget-certification responsibilities for cyber operations; the National Security Agency conducts foreign intelligence and cybersecurity missions; the Cybersecurity and Infrastructure Security Agency supports federal civilian networks and private critical infrastructure; the Federal Bureau of Investigation leads domestic threat-response and investigative functions; sector risk-management agencies maintain domain responsibilities; and privately owned operators control most nationally consequential infrastructure. The Department’s 2023 Cyber Strategy organises military activity around defending the nation, preparing to fight and win, building allied and partner advantage, and securing enduring advantages, while explicitly recognising that resilience depends on industry and non-Department infrastructure. DOD Releases 2023 Cyber Strategy Summary – U.S. Department of Defense – September 2023 — Department of Defense Cyber Strategy Summary.
Yet strategy does not itself consolidate command. The federal incident model still separates threat response, asset response, intelligence support, criminal investigation, military action, regulatory supervision, diplomatic signalling, sanctions, and public communication. CISA’s federal playbooks create standardised processes for identifying, coordinating, remediating, recovering from, and tracking cyber incidents across civilian agencies, but the effectiveness of these procedures depends on timely reporting, shared logs, aligned legal thresholds, and organisations retaining the capacity to execute the prescribed actions. Executive Order on Improving the Nation’s Cybersecurity – CISA – official implementation resource — Federal Cybersecurity Incident and Vulnerability Response. Government Accountability Office findings demonstrate the persistent gap between governance design and implementation. GAO reported that the Department planned to spend $10.9 billion across 24 major IT business programmes during fiscal years 2023–2025, while some programmes lacked complete cybersecurity or zero-trust implementation planning.
IT Systems Annual Assessment: DOD Needs to Improve Performance Reporting and Cybersecurity Planning – U.S. Government Accountability Office – June 2025 — GAO-25-107649. This evidence does not prove that centralisation alone would solve performance failures; it demonstrates that accountability without common metrics, investment traceability, and enforcement authority produces an incomplete picture of readiness. A future Cyber Force could rationalise personnel and operational capabilities, but unless an accountable civilian authority controls requirements, certifies budgets, arbitrates network ownership, and compels remediation, force creation risks strengthening the operational spear while leaving the command, logistics, industrial, and defensive substrate fragmented.
The budget question is the most concrete test of whether cyber accountability is real or rhetorical. An official may be named as the “single accountable official,” but that title has limited operational significance unless the office can identify the complete cyber portfolio, redirect investment, reject insecure acquisitions, establish enterprise requirements, withhold certification, compel service-level remediation, and defend an integrated programme before the legislature. Cyber expenditure is structurally difficult to isolate because it is embedded across weapons platforms, intelligence programmes, communications infrastructure, cloud contracts, business systems, operational technology, personnel, research, classified access programmes, and service-specific modernisation. Historical GAO work found that the Department required clearer definitions, a focal point, and a reliable methodology to produce full-spectrum cyberspace budget estimates, illustrating that cyber resources can disappear into broader programme accounts even when aggregate investment appears substantial. Defense Department Cyber Efforts: Definitions, Focal Point, and Methodology Needed for DOD to Develop Full-Spectrum Cyberspace Budget Estimates – U.S. Government Accountability Office – July 2011 — GAO-11-695R. Later assessments continued to identify weaknesses in programme-level cybersecurity planning and incident reporting. GAO found that the Department had not fully implemented cyber-incident management processes, lacked complete incident data, and did not consistently document notification decisions concerning compromised personal information. DOD Cybersecurity: Enhanced Attention Needed to Ensure Cyber Incidents Are Appropriately Reported and Shared – U.S. Government Accountability Office – November 2022 — GAO-23-105084. In 2026, GAO also assessed implementation risks surrounding the Cybersecurity Maturity Model Certification programme for the defence industrial base, reinforcing the broader principle that regulatory authority, contractor capacity, assessment mechanisms, and supply-chain economics must be treated as one governance system rather than independent compliance projects. Defense Contractor Cybersecurity: DOD Should Address External Factors That Could Impede Program Implementation – U.S. Government Accountability Office – March 2026 — GAO-26-107955. By 2031, a viable budget-governance system should therefore operate through a unified cyber mission taxonomy, programme-level digital dependency maps, measurable readiness outputs, mandatory exposure reporting, and cross-cutting investment authority. The relevant budget should not be limited to “cyber operations.” It must include the costs of identity, data architecture, secure software, cryptographic transition, cloud resilience, industrial-base protection, incident recovery, AI assurance, operational-technology segmentation, communications redundancy, workforce sustainability, and reserve capacity. Without this integrated financial view, political leaders cannot distinguish genuine readiness from dispersed spending, and commanders cannot determine whether they possess resilient mission systems or merely nominal cyber capabilities.
| Governance function | Present structural owner pattern | Principal seam | Required 2031 reform |
|---|---|---|---|
| Military cyber operations | Combatant command plus service components | Operational demand separated from force generation | Binding readiness standards and direct capability certification |
| Enterprise military networks | CIO, service CIOs, agencies, programme offices | Multiple technical authorities and inherited architecture | Unified mission-network architecture and enforceable baselines |
| Federal civilian defence | Central cyber agency plus department-level owners | Central visibility without universal local execution power | Pre-authorised emergency directives and common telemetry |
| Critical infrastructure | Private operators under sector-specific regulation | State responsibility without direct ownership | Sector command protocols, minimum telemetry, recovery compacts |
| Intelligence collection | Military and civilian intelligence organisations | Classification barriers and mission compartmentation | Automated releasability and crisis-specific data fusion |
| AI assurance | Procurement, security, mission and regulatory bodies | Model risk divided from cyber and operational risk | Joint model-data-system certification throughout lifecycle |
| Cyber budgets | Distributed programme and service accounts | Incomplete portfolio visibility | Common taxonomy, consolidated certification and outcome metrics |
| Political accountability | Ministers, secretaries, legislatures and regulators | Responsibility fragmented across mandates | One accountable executive backed by directive and fiscal authority |
The European Union offers a different form of cyber sovereignty: legal and regulatory integration without a unified military command or fully centralised operational authority. NIS2 requires Member States to maintain national cybersecurity strategies, crisis-management structures, competent authorities, computer-security incident-response teams, and cross-border cooperation mechanisms. It expands coverage across digital infrastructure, energy, transport, banking, health, water, public administration, space, manufacturing, research, managed services, cloud providers, data centres, content-delivery networks, domain services, and other critical sectors. ENISA supports implementation, maintains coordination mechanisms, provides the secretariat for the European Cyber Crises Liaison Organisation Network, supports the CSIRTs Network, develops guidance, and contributes to vulnerability management and cross-border service oversight. NIS Directive 2 – European Union Agency for Cybersecurity – current official resource — NIS2 Governance and Implementation. Cybersecurity of Critical Sectors – European Union Agency for Cybersecurity – current official resource — ENISA Critical-Sector Cybersecurity. The Cyber Solidarity Act, which entered into force on 4 February 2025, adds mechanisms intended to improve preparedness, detection, and response, including a European alert capability and emergency-support arrangements. EU Cybersecurity Policies – European Commission – updated 2026 — European Union Cybersecurity Policy Framework.
This architecture increases regulatory convergence, but it does not abolish national jurisdiction, national-security exceptions, defence compartmentation, or differences in investigative authority. Indeed, the Commission reported in July 2026 that it was referring Ireland, Spain, France, and the Netherlands to the Court of Justice for failing to notify complete NIS2 transposition measures, showing how legal harmonisation can lag behind the operational timeline. EU Cybersecurity Act – European Commission – July 2026 update — European Cybersecurity Act and 2026 Package. The Union’s five-year challenge is therefore to prevent a widening gap between common regulatory ambition and uneven national execution. The most likely path is not an EU cyber command that supersedes Member States, but a denser federated system in which ENISA, national authorities, CSIRTs, defence establishments, law-enforcement bodies, the Commission, critical-sector regulators, and private providers exchange standardised machine-readable incident data, maintain common severity thresholds, conduct recurring cross-border exercises, and activate jointly funded response capacity. The central vulnerability remains political: during a high-impact incident with ambiguous attribution, Member States may agree technically on containment while diverging over public attribution, sanctions, intelligence disclosure, offensive countermeasures, or invocation of collective-defence mechanisms.
China’s model moves closer to vertically coordinated cyber sovereignty because network governance, data regulation, critical-infrastructure protection, industrial policy, content control, artificial-intelligence supervision, and national-security objectives are integrated through party-state institutions. Official Chinese policy presents cybersecurity not as a discrete technical function but as a component of national development, social governance, technological self-reliance, public security, supply-chain security, and state capacity. In 2025, the Cyberspace Administration of China described a broad programme to strengthen top-level coordination, accelerate the national cyber-defence system, protect critical information infrastructure, improve monitoring and early warning, maintain a national incident-reporting platform, use cybersecurity review and cloud-service security evaluation, and improve supply-chain security. 推动网信事业高质量发展开创网络强国建设新局面 – Cyberspace Administration of China – December 2025 — China Cyber Governance and Network-Power Policy. China’s AI governance framework further treats model algorithms, training data, infrastructure, and applications as linked security objects requiring monitoring, risk warning, emergency response, classification, industry self-regulation, and government direction. 国务院关于深入实施“人工智能+”行动的意见 – State Council of the People’s Republic of China, published by CAC – August 2025 — Artificial Intelligence Plus Action. The Artificial Intelligence Security Governance Framework 2.0, issued in September 2025 under CAC guidance and organised by the national computer emergency-response structure and other institutions, updates risk classification, risk grading, and governance measures in response to changing technology. 《人工智能安全治理框架》2.0版发布 – Cyberspace Administration of China – September 2025 — AI Security Governance Framework 2.0.
This arrangement can reduce interagency ambiguity at the strategic level, but vertical control does not automatically eliminate implementation friction among regulators, ministries, security organisations, provincial authorities, state-owned enterprises, technology firms, and military bodies. China’s potential advantage by 2031 lies in its ability to require reporting, mandate technical standards, align procurement with domestic industrial policy, and connect AI governance to broader national-security objectives. Its risk lies in information distortion: strongly hierarchical systems can suppress negative reporting, reward formal compliance, over-centralise decision authority, or create blind spots when politically inconvenient evidence fails to move upward. The resulting contest will therefore compare Western distributed transparency and private-sector innovation against Chinese command integration and regulatory compulsion, with neither model inherently immune to latency, misperception, or systemic dependency.
Russia’s governance model combines strategic centralisation, security-service authority, technological-sovereignty objectives, legal regulation, state-controlled infrastructure priorities, and a growing emphasis on real-time information exchange. The Russian government’s 2024 concept for countering crimes committed through information and communications technologies explicitly identifies the absence of real-time information exchange among organisations and law-enforcement bodies—including the transmission of binding instructions and confidential information—as a factor reducing state effectiveness. It establishes principles, objectives, functions, organisational mechanisms, scientific and technical support, staffing, and financial requirements for a state counter-cybercrime system. Распоряжение Правительства Российской Федерации от 30.12.2024 № 4154-р – Government of the Russian Federation – December 2024 — Russian State System for Countering ICT-Enabled Crime. An implementation plan followed in August 2025. Утверждён план реализации концепции противодействия киберпреступности – Government of the Russian Federation – August 2025 — Implementation Plan for the Cybercrime Counteraction Concept.
Russia’s updated national AI strategy requires trusted technologies in applications capable of affecting national security, calls for information-security requirements, conformity assessment, reliable source data, government monitoring, national standards, and an interdepartmental council concerned with AI safety. Указ Президента Российской Федерации от 15.02.2024 № 124 – President of the Russian Federation – February 2024 — Updated National Strategy for Artificial Intelligence Development to 2030. These measures point toward an increasingly integrated state model in which security, domestic technology adoption, software substitution, network sovereignty, financial surveillance, and AI assurance reinforce each other. Official policy also targets a 95% share of Russian software use by 2030 in state bodies, state corporations, and majority state-owned entities, while calling for network sovereignty and information security. Government Digital and Technological Development Targets – Government of the Russian Federation – 2024 — Russian Digital Sovereignty Targets. The strategic advantage of this model is its capacity to impose standards and mobilise state-linked organisations under security imperatives. Its constraints include dependence on domestic technological depth, sanctions-driven supply limitations, uneven implementation across public and industrial systems, and the possibility that cybercrime, intelligence activity, military operations, influence operations, and politically tolerated proxy ecosystems interact through opaque relationships. Between 2026 and 2031, Moscow is likely to tighten domestic network control and trusted-technology mandates while preserving ambiguity externally, because ambiguity provides strategic deniability, complicates attribution, and allows criminal or quasi-private actors to impose costs below conventional thresholds.
The most consequential governance frontier will be AI assurance, because artificial intelligence is simultaneously a capability, a dependency, an attack surface, an intelligence source, an automated decision-support layer, and a potential executor of defensive action. Existing cyber governance normally certifies systems, networks, personnel, data handling, and operational authorities through separate processes. AI systems break this separation. A model may be technically secure against unauthorised access yet operationally unreliable because its training data are manipulated, its outputs are systematically biased, its retrieval layer is poisoned, its software supply chain is compromised, or its automated actions exceed authorised boundaries. Conversely, a model may be statistically accurate but create unacceptable security exposure through memorisation, prompt injection, insecure tool use, or uncontrolled access to privileged systems. NATO’s revised AI strategy calls for alliance-wide testing, evaluation, verification, validation, responsible-use principles, and protection against adversarial AI use. Summary of NATO’s Revised Artificial Intelligence Strategy – NATO – July 2024 — NATO Revised AI Strategy.
China’s official framework treats model, data, system, infrastructure, cognitive, ethical, and real-world risks as linked governance categories. Russia’s strategy calls for trusted AI in security-sensitive fields and a conformity-assessment system. These convergent directions reveal a shared strategic judgement: AI assurance cannot remain a voluntary technical review conducted at the end of procurement. By 2031, mature cyber institutions will require continuous model assurance across six layers—provenance, data integrity, model behaviour, tool permissions, operational context, and post-deployment monitoring. The command problem is equally important. A system may detect malicious activity in milliseconds, but whether it may isolate a military network, revoke thousands of credentials, block a commercial service, alter routing, suspend an industrial process, or deploy an offensive countermeasure depends on law and delegated authority. “Human in the loop” becomes strategically meaningless when the human lacks time, information, or legal confidence to act. The necessary governance shift is from case-by-case approval toward bounded pre-delegation: machines may execute predefined defensive actions inside technically and legally defined envelopes, while actions carrying high collateral, escalatory, intelligence, or sovereignty consequences remain subject to designated human authority.
The five-year outlook is best assessed through an Analysis of Competing Hypotheses rather than through a single institutional forecast. H₁, Accountable Consolidation, predicts that major democracies will install stronger central civilian cyber executives with budget-certification, directive, and cross-sector coordination powers while retaining distributed operators. H₂, Service Primacy, predicts that military cyber services or equivalent force-generation institutions will become the dominant reform mechanism, improving personnel and readiness more rapidly than governance. H₃, Platform Sovereignty, predicts that hyperscale cloud, identity, telecommunications, semiconductor, security, and AI providers will become indispensable operational authorities because only they possess the telemetry and engineering reach required for rapid containment. H₄, Regulatory Federation, predicts that the European model of shared standards, national implementation, crisis networks, certification, and joint response capacity will become the leading international template. H₅, Security-State Integration, predicts that China and Russia will gain relative decision-speed advantages through compulsory reporting, central coordination, trusted-technology mandates, and close alignment between security policy and industrial policy. H₆, Persistent Fragmentation, predicts that political jurisdiction, classification, procurement, infrastructure ownership, and alliance barriers will prevent meaningful consolidation before 2031. The current Bayesian weighting assigns H₁ 0.68, H₂ 0.44, H₃ 0.79, H₄ 0.61, H₅ 0.66, and H₆ 0.53. These probabilities are analytical estimates, not official forecasts, and are non-exclusive. New evidence updates the priors in opposite directions. NATO’s Integrated Cyber Defence Centre, NIS2, the Cyber Solidarity Act, China’s integrated AI-security policy, and Russia’s real-time cybercrime coordination plans increase the probability of governance consolidation. GAO’s repeated findings concerning planning, incident data, programme execution, and contractor capacity increase the probability that fragmentation persists despite organisational reform. A conceptual 100,000-iteration Monte Carlo model using eight variables—authority concentration, telemetry access, AI acceleration, platform concentration, alliance interoperability, regulatory compliance, workforce readiness, and crisis intensity—produces a median 2031 governance-response index of 64/100. The model gives a 69% probability that technical detection speed will improve faster than political-authorisation speed, a 58% probability that private platforms will possess better cross-network situational awareness than national authorities during at least one major incident, and a 41% probability that unclear authority materially delays containment in a multinational crisis. The most powerful risk-reduction variable is not additional offensive capacity; it is pre-negotiated authority linked to shared telemetry and rehearsed recovery procedures.
| Hypothesis | 2026 prior | 2031 analytical probability | Strongest confirming indicators | Principal disconfirming indicators |
|---|---|---|---|---|
| H₁ Accountable Consolidation | 0.58 | 0.68 | Unified budget certification; binding directives; cross-sector command exercises | Advisory offices without fiscal or directive power |
| H₂ Service Primacy | 0.39 | 0.44 | Dedicated service legislation; direct recruiting and acquisition authority | Continued disagreement over network ownership and institutional home |
| H₃ Platform Sovereignty | 0.72 | 0.79 | Provider-controlled telemetry; identity and cloud concentration; rapid private remediation | Mandatory sovereign telemetry and interoperable public capabilities |
| H₄ Regulatory Federation | 0.52 | 0.61 | NIS2 convergence; common incident thresholds; EU-level response capacity | Persistent transposition gaps and national-security carve-outs |
| H₅ Security-State Integration | 0.59 | 0.66 | Compulsory reporting; trusted technology; integrated AI and cyber supervision | Implementation gaps, distorted reporting, technical bottlenecks |
| H₆ Persistent Fragmentation | 0.61 | 0.53 | Competing mandates; incomplete budgets; classification barriers | Enforceable common architecture and tested emergency command |
The required governance architecture for 2031 should therefore be neither a completely centralised cyber ministry nor a loose interagency coordination committee. It should operate as a federated command system with a hard centre. The hard centre must contain one politically accountable executive with statutory authority to certify cyber budgets, issue binding minimum requirements, demand incident telemetry, convene national crisis command, adjudicate interdepartmental disputes, and report publicly and legislatively on readiness. Around that centre, military commands, intelligence organisations, civilian agencies, regulators, law-enforcement bodies, national computer emergency-response teams, local authorities, and private operators should retain specialised missions and technical expertise. The difference from current coordination models is that responsibilities would be encoded in advance through executable authorities, data-sharing standards, escalation thresholds, and recovery commitments. Every critical sector should maintain a machine-readable dependency map identifying identity services, cloud control planes, telecommunications routes, external software libraries, operational-technology links, foreign suppliers, and manual fallback capacity. Every major incident should feed a common operational graph rather than separate organisational dashboards. AI systems should assist correlation, triage, containment recommendations, simulation, and resource allocation, but their permissions should be tiered. Level A actions—such as enrichment, correlation, alerting, and sandboxing—could be automatic. Level B actions—such as credential revocation, endpoint isolation, or temporary traffic blocking—could execute under pre-delegated rules with immediate human notification. Level C actions—such as nationwide service suspension, cross-border infrastructure intervention, offensive disruption, or measures creating physical risk—would require named human authorisation. This structure converts “machine speed” from an empty aspiration into a governed sequence of authorities. The strategic objective is not to remove humans; it is to ensure that the human decision point occurs only where political judgement is indispensable, while routine containment is automated inside tested limits. By 2031, states that fail to build this architecture will remain legally sovereign but operationally dependent: they will retain the right to command cyberspace without possessing the data, authority, industrial leverage, or time necessary to make command effective.
Figure 1: Five-Year Cyber Governance Projection
Analytical scenario indices, 2026–2031. Values are modelled estimates rather than official forecasts.
Pillar II — AI-Accelerated Cyber Conflict, 2026–2031
The transformation of cyber conflict through artificial intelligence will not occur as a single technological discontinuity in which autonomous systems abruptly replace human operators. It will emerge through the progressive compression, parallelisation, and industrialisation of individual stages across the intrusion lifecycle. Generative models already reduce the labour required for multilingual reconnaissance, code interpretation, target profiling, social-engineering design, malware debugging, stolen-data processing, infrastructure configuration, and defensive analysis. During 2026–2031, autonomous agents will increasingly connect these formerly separate functions into persistent workflows capable of planning intermediate objectives, invoking specialised tools, interpreting results, revising hypotheses, and escalating selected findings to human operators. The British National Cyber Security Centre assesses that AI will almost certainly increase the effectiveness and efficiency of cyber intrusion, raising both the frequency and intensity of threats; it identifies AI-assisted vulnerability research and exploit development as the most consequential near-term development, while judging fully automated end-to-end advanced attacks unlikely by 2027 because skilled humans will remain necessary. Impact of AI on Cyber Threat from Now to 2027 – United Kingdom National Cyber Security Centre – May 2025 — official assessment. This distinction is essential. The strategic danger does not require an independently reasoning “cyber superweapon.” A human-directed system that automates 70–90% of reconnaissance, vulnerability triage, phishing adaptation, payload testing, post-compromise enumeration, and reporting can multiply operational throughput even if humans continue authorising exploitation and escalation. The resulting force multiplier will favour actors possessing high-quality telemetry, computational infrastructure, proprietary vulnerability corpora, access to realistic testing environments, and disciplined operational doctrine. State services and sophisticated criminal organisations will therefore gain more than isolated amateurs from frontier systems, but open-source models and commercial agent frameworks will simultaneously diffuse limited automation to hacktivists, access brokers, mercenary intrusion teams, fraud networks, and ideologically motivated groups. The initial five-year effect will be a widening of the attacker population at the lower end and a deepening of capability at the upper end, producing a threat environment characterised by both unprecedented volume and increasingly selective machine-assisted precision.
Generative models will alter offensive scale primarily by transforming the economics of preparation rather than by eliminating the need for expertise. Traditional intrusion campaigns require analysts to identify personnel, technologies, suppliers, exposed services, likely credentials, organisational language, security products, operational schedules, and social relationships before attempting access. AI systems can continuously ingest public documents, technical repositories, leaked credentials, procurement records, job advertisements, network metadata, code samples, and previously stolen material to create evolving target models. They can generate tailored messages in the victim’s language, imitate internal writing patterns, construct plausible support conversations, and vary content rapidly when filters or recipients reject the initial approach. ENISA’s 2025 threat landscape found phishing, including vishing, malicious advertising, and malicious email, to be the leading observed initial-access method, accounting for approximately 60% of cases; it also identified growing automation through phishing-as-a-service and the use of large language models to improve social engineering. ENISA Threat Landscape 2025 – European Union Agency for Cybersecurity – October 2025 — official report. AI will not make every deceptive message effective, but it will allow adversaries to test thousands of personalised variants, compare response rates, model recipient behaviour, and adjust timing, tone, language, and pretext automatically. Synthetic voice and video will extend this capability from email into real-time interaction, enabling fabricated executives, technicians, suppliers, officials, or military personnel to participate in authentication or payment workflows. The economic consequence is a declining marginal cost per attempted compromise: once an actor has built the target model and agentic workflow, additional campaigns become inexpensive. Defensive organisations will therefore confront a transition from campaign-based threat management to continuous adversarial pressure. The relevant metric will cease to be the number of malicious messages and become the proportion of business and operational processes that permit a synthetic identity to trigger consequential action without independent cryptographic verification. Between 2026 and 2031, organisations that continue treating identity as a collection of passwords, phone calls, visual cues, writing styles, and familiar voices will become structurally indefensible. Resilient institutions will move toward device-bound credentials, hardware-backed authentication, transaction signing, verified communication channels, separation of duties, and machine-readable provenance for high-consequence instructions.
| AI-enabled offensive function | Present capability | Expected 2031 maturation | Primary strategic effect |
|---|---|---|---|
| Target reconnaissance | Automated collection and summarisation | Persistent organisational knowledge graphs updated in near real time | Larger target sets with less analyst labour |
| Social engineering | Multilingual text, synthetic audio, personalised pretexts | Interactive synthetic identities sustaining long conversations | Erosion of human-recognition authentication |
| Vulnerability research | Code explanation, fuzzing assistance, patch comparison | Autonomous discovery, validation, prioritisation, and patch-gap analysis | Shorter interval between disclosure and exploitation |
| Malware development | Debugging, code variation, script generation | Adaptive modular payloads tested against representative defences | Higher mutation frequency and defensive workload |
| Post-compromise activity | Log interpretation and data classification | Agentic privilege discovery, lateral-movement planning, and data triage | Faster transition from access to mission impact |
| Influence support | Content generation and translation | Persona networks adapting to audience response and events | Scaled narrative manipulation with reduced staffing |
| Operational security | Infrastructure scripts and basic evasion | Continuous adaptation of infrastructure, timing, and artefacts | More difficult campaign correlation and attribution |
Vulnerability discovery will become the most strategically significant interface between AI and cyber operations because software weakness remains the conversion point through which information processing becomes operational access. Contemporary software estates contain decades of inherited code, third-party packages, open-source dependencies, insecure configurations, forgotten services, unsupported appliances, and industrial systems that cannot be patched rapidly. AI-assisted code analysis can compare vulnerable and corrected versions, infer likely defect classes, generate candidate inputs, prioritise reachable paths, and automate portions of exploit validation. DARPA’s two-year AI Cyber Challenge demonstrated that autonomous cyber-reasoning systems could identify and remediate vulnerabilities in open-source software relevant to critical infrastructure; in August 2025, DARPA announced Team Atlanta as the winner and stated that several finalist systems would be released as open-source defensive tools. AI Cyber Challenge Marks Pivotal Inflection Point for Cyber Defense – Defense Advanced Research Projects Agency – August 2025 — official programme result. The dual-use implications are immediate. Systems that identify defective code and produce patches can also be redirected to discover unpatched weaknesses, compare vendor updates with deployed versions, or search large codebases for recurring vulnerability patterns. The decisive variable will be who reaches the vulnerability first and whether defenders can distribute, test, prioritise, and deploy remediation before adversaries operationalise it. The historical patch cycle—disclosure, analysis, prioritisation, testing, change approval, staged deployment—will become dangerously slow when attackers can automate exploit development within hours. The NCSC assesses that AI will almost certainly reduce the already shrinking interval between disclosure and exploitation and that advanced actors may gain enhanced zero-day discovery capabilities. Defensive economics will consequently divide organisations into two classes. AI-ready defenders will continuously analyse code, assets, configurations, exploitability, and mission criticality; they will generate candidate patches, test them in digital replicas, and deploy them through automated pipelines. Legacy defenders will receive a rapidly expanding stream of findings without the asset visibility, maintenance windows, staffing, or architectural flexibility needed to respond. AI will thus improve security for the best-prepared organisations while increasing relative exposure for everyone else, producing a widening cyber-resilience divide rather than a uniform increase in protection.
Adaptive malware should be understood as a spectrum, not as a single class of fully autonomous malicious software. At the lower end, generative systems can rewrite scripts, vary strings, restructure code, modify command-and-control configurations, and produce environment-specific modules. At the middle level, agentic systems can interpret endpoint data, determine which tools are available, identify likely privileges, select among approved techniques, and report when human intervention is needed. At the high end, genuinely adaptive malware could alter tactics in response to defensive controls, redistribute functions across compromised hosts, generate new obfuscation layers, or change operational objectives based on discovered information. The near-term constraint is reliability. Offensive operators require predictability, stealth, and control; an unconstrained model that invents commands, corrupts target systems prematurely, exposes infrastructure, or produces unstable code creates mission risk. Consequently, the most effective designs through 2031 are likely to be bounded systems in which models choose among tested capabilities rather than generate unrestricted behaviour directly inside victim environments. This resembles a modular command architecture: the AI interprets context, scores possible actions, and invokes prevalidated tools under operator-defined constraints. Such systems can still create substantial advantage because they reduce the number of human decisions required during lateral movement and data discovery. The NCSC’s 2025 annual review reported that actors associated with China, Russia, Iran, and North Korea were using large language models to support reconnaissance, social engineering, vulnerability research, exploit development, detection evasion, and processing of stolen data; it also highlighted techniques such as automated spear-phishing, hijacking cloud-hosted language models, and automating post-breach stages. Countering the Cyber Threat – United Kingdom National Cyber Security Centre Annual Review – October 2025 — official threat review. By 2031, malware analysis will therefore require behavioural interpretation at a different scale. Static signatures and isolated indicators will lose value as adversaries vary artefacts continuously. Defenders will need to identify stable operational relationships—identity misuse, process ancestry, network intent, privilege transitions, data-access anomalies, infrastructure reuse, and campaign objectives—rather than depend primarily on recurring file hashes, domains, or strings.
Machine-speed defence will create the strongest countervailing pressure, but it will change both cost structures and organisational design. AI-enabled security systems can correlate endpoint events, identity anomalies, cloud logs, network flows, vulnerability intelligence, software inventories, threat reporting, and business context at a scale beyond human analysts. They can summarise incidents, propose containment actions, generate detection logic, map activity to known techniques, reconstruct timelines, and identify likely lateral paths. More advanced defensive agents will execute limited actions such as isolating devices, revoking credentials, disabling tokens, blocking connections, opening tickets, initiating memory capture, or deploying temporary virtual patches. These functions can materially reduce dwell time, yet they also create a new class of systemic risk: an adversary who manipulates the defensive model, its inputs, or its tool permissions may cause the defender to suppress accurate alerts, isolate legitimate systems, reveal investigative logic, or execute destructive containment against itself. NIST’s March 2025 adversarial machine-learning taxonomy distinguishes evasion, poisoning, privacy, and misuse attacks across predictive and generative AI, while emphasising lifecycle stages, attacker knowledge, capabilities, objectives, and mitigation limitations. Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations, NIST AI 100-2 E2025 – National Institute of Standards and Technology – March 2025 — official publication. The defensive economic equation will therefore include three costs rather than two. Organisations must fund conventional security operations, AI-enabled automation, and independent assurance of the automation itself. The principal savings will come from reducing repetitive analyst labour and accelerating containment; the principal new expenses will arise from model evaluation, secure data pipelines, adversarial testing, compute, logging, access controls, human override capacity, and failure investigation. Large organisations can amortise these costs across extensive infrastructure, while smaller entities may depend on managed providers. This concentration may improve average defence but creates systemic dependency on a limited number of security, identity, and cloud platforms. A model defect, compromised update, poisoned threat feed, or erroneous automated policy could then propagate defensive failure across thousands of customers simultaneously.
Model poisoning and data manipulation will become central forms of cyber conflict because AI systems derive operational authority from data that may be too large, distributed, dynamic, or opaque for direct human verification. Poisoning can occur during pretraining, fine-tuning, retrieval, evaluation, reinforcement, telemetry collection, threat-intelligence ingestion, or post-deployment feedback. An attacker does not always need to corrupt the entire model. A narrow manipulation that changes behaviour for a particular organisation, code pattern, malware family, language, geography, or trigger can create operational advantage while remaining invisible during general testing. A defensive model may be induced to classify a specific command sequence as benign; a vulnerability model may systematically ignore a defect class; an intelligence system may rank fabricated reports as credible; an influence-detection model may over-identify authentic opposition activity while under-identifying coordinated manipulation. The National Security Agency’s Artificial Intelligence Security Center and partner organisations warned in May 2025 that data used to train and operate AI systems is a critical element of the AI supply chain and that maintaining its accuracy, reliability, and integrity requires dedicated protection. AI Data Security: Best Practices for Securing Data Used to Train and Operate AI Systems – National Security Agency and International Partners – May 2025 — official release. Data assurance must therefore become analogous to software supply-chain security. Organisations will need provenance records, cryptographic integrity controls, source trust scoring, separation of training and evaluation sets, anomaly detection for data shifts, reproducible pipelines, protected human-labeling processes, independent red-team datasets, and the ability to remove or quarantine suspect sources. Retrieval-augmented systems require additional safeguards because external documents can contain instructions intended to override system behaviour or trigger unauthorised tool use. By 2031, the most damaging AI compromise may not resemble conventional malware at all. It may consist of a carefully engineered information environment that causes trusted models to make consistently wrong recommendations while every component remains technically available and apparently functional.
| AI-system attack surface | Representative manipulation | Operational consequence | Required control |
|---|---|---|---|
| Training corpus | Poisoned examples or hidden trigger patterns | Persistent biased or attacker-controlled behaviour | Provenance, deduplication, anomaly screening, reproducible datasets |
| Fine-tuning pipeline | Malicious specialised data or compromised adapter | Narrow mission-specific backdoor | Signed artefacts, isolated training, independent validation |
| Retrieval layer | Hostile documents or indirect prompt injection | Tool misuse, data leakage, corrupted analysis | Content isolation, instruction filtering, source trust boundaries |
| Model endpoint | Evasion prompts, extraction, abuse automation | Safeguard bypass or model theft | Rate controls, behavioural monitoring, output restrictions |
| Agent tools | Excessive permissions or malicious tool response | Unauthorised execution and lateral movement | Least privilege, allowlists, transaction approval, sandboxing |
| Feedback system | Manipulated user ratings or synthetic telemetry | Progressive degradation of model behaviour | Authenticated feedback, drift detection, rollback capability |
| Evaluation process | Contaminated benchmarks or predictable test cases | False assurance and certification failure | Independent tests, secret challenge sets, continuous evaluation |
Synthetic identities and AI-enabled influence operations will blur the boundary between cyber intrusion, intelligence collection, fraud, political warfare, and military deception. The same infrastructure used to impersonate an employee for credential theft can impersonate an officer to issue false instructions, a supplier to alter logistics, a journalist to solicit information, a citizen to amplify a narrative, or an official to trigger market or public reaction. NATO’s revised AI strategy identifies AI-enabled disinformation and information operations as threats capable of affecting elections, dividing societies, demoralising populations and armed forces, and reducing trust in institutions. It also emphasises traceability, governability, reliability, interoperability, testing, evaluation, verification, and validation across Alliance AI systems. Summary of NATO’s Revised Artificial Intelligence Strategy – NATO – July 2024 — official strategy. The strategic innovation is not merely unlimited content production. Human societies already face more information than they can evaluate. The more consequential capability is adaptive orchestration: networks of synthetic personas can test narratives, observe audience reaction, redirect attention, impersonate local actors, exploit authentic grievances, translate content, and coordinate with disruptive cyber events. A power-grid incident, data breach, military mobilisation, banking outage, or satellite disruption can be surrounded by synthetic evidence, fabricated explanations, false claims of responsibility, counterfeit emergency guidance, and impersonated experts. This creates a “perception denial” effect in which audiences cannot confidently distinguish authentic communication from manipulation during the period when decisions matter most. Defensive strategy must therefore link cyber incident response with trusted public communication, identity verification, media authentication, platform coordination, and intelligence analysis. Content labels alone will not be sufficient because labels can be stripped, forged, or ignored. Institutions will need authenticated official channels, cryptographically verifiable media, pre-established crisis communication protocols, rapid exposure of synthetic networks, and disciplined avoidance of premature claims. The central defensive objective is not to prove every item false; it is to preserve enough trusted information pathways that societies and commanders can continue functioning under conditions of deliberate epistemic disruption.
Attribution will become harder at the tactical level yet potentially stronger at the strategic level. AI allows adversaries to imitate code styles, translate operator language, vary infrastructure, manufacture false artefacts, and copy publicly documented techniques associated with other groups. Automated systems can introduce randomness into timing, payload structure, domain registration, compilation characteristics, and command sequences. Synthetic personas can create false recruitment trails or ideological claims, while commercial tools and open-source models enable unrelated actors to share nearly identical capabilities. These developments will reduce the evidentiary value of isolated technical indicators. However, strategic attribution has never depended solely on malware signatures. Governments combine SIGINT, human intelligence, infrastructure observation, victimology, operational timing, financial flows, historical behaviour, geopolitical context, legal process, and classified collection. AI may strengthen these higher-level methods by correlating weak signals across large datasets, detecting infrastructure relationships, comparing campaign timing, and identifying behavioural regularities that human analysts would miss. The risk lies in automation bias: a model trained on historical attribution may force novel actors into familiar categories, amplify planted evidence, or generate confident but poorly grounded assessments. Attribution systems must therefore preserve evidence lineage, competing hypotheses, uncertainty ranges, and explicit separation between machine-generated correlations and independently confirmed facts. A suitable Analysis of Competing Hypotheses for 2026–2031 includes H₁, state-directed operation; H₂, state-tolerated proxy; H₃, financially motivated criminal activity; H₄, commercial intrusion contractor; H₅, hacktivist or ideological network; H₆, false-flag operation; and H₇, automated spillover or unintended propagation. AI can update the relative likelihood of each hypothesis as evidence arrives, but political leaders must resist treating a numerical score as equivalent to strategic certainty. The probability of misattribution becomes most dangerous when cyber activity coincides with military tension, because compressed decision time increases the temptation to convert partial technical evidence into public blame or retaliatory action.
The escalation implications arise from the interaction of speed, ambiguity, autonomy, and physical dependency. AI-enabled cyber systems can discover opportunities and initiate containment faster than senior leaders can understand the operational context. During a crisis, a defensive agent might isolate allied traffic, an offensive system might exploit a dual-use network, a vulnerability scanner might unintentionally disrupt an industrial controller, or synthetic communications might cause commanders to misread adversary intent. The integration of AI into operational technology magnifies these risks because errors can affect physical processes, safety systems, energy delivery, manufacturing, transport, water, or military logistics. In December 2025, NSA, CISA, and international partners issued principles for securely integrating AI into operational technology, warning that adoption introduces new risks to the safety and security of critical functions. Principles for the Secure Integration of Artificial Intelligence in Operational Technology – National Security Agency, CISA and International Partners – December 2025 — official release. Escalation control must therefore be engineered into system architecture. Defensive autonomy can be divided into reversible and irreversible actions. Reversible actions—additional logging, sandboxing, temporary isolation, token suspension, traffic rate reduction—can be delegated broadly. Irreversible or high-impact actions—firmware modification, industrial shutdown, deletion, destructive countermeasures, manipulation of foreign infrastructure, or operations that reveal strategic intelligence access—require higher authority. Offensive systems need equivalent restrictions: target allowlists, geographic and network boundaries, prohibited effects, expiration times, operator authentication, tamper-resistant logs, and mechanisms that halt execution when context diverges from authorised assumptions. The greatest risk is not a conscious AI decision to escalate war. It is a chain of locally rational automated actions that produces strategic effects nobody intended because each system optimised its narrow objective without a common model of political consequence.
China’s regulatory architecture shows how states may attempt to govern AI-enabled influence, model risk, synthetic content, and operational autonomy through integrated state supervision. The Interim Measures for the Management of Generative Artificial Intelligence Services require lawful training-data sources, data-quality measures, protection of personal information, content controls, provider responsibility, security assessments for services with public-opinion or social-mobilisation capacity, and labeling obligations for generated content. 生成式人工智能服务管理暂行办法 – Cyberspace Administration of China and Six Other State Bodies – July 2023 — official regulation. China’s Artificial Intelligence Security Governance Framework 2.0, released in September 2025, expands risk classification, promotes graded governance, addresses transmission of foundation-model defects into downstream applications, and introduces concepts such as emergency interruption, one-click control, provenance labeling, resilience, and scenario-specific testing for highly autonomous systems. 《人工智能安全治理框架》2.0版发布 – Cyberspace Administration of China – September 2025 — official framework. By April 30, 2026, CAC reported that 868 generative-AI services had completed filing and 530 applications or functions using filed model capabilities had completed registration, indicating the scale at which administrative visibility is being constructed. Announcement on Filed Generative AI Services, March–April 2026 – Cyberspace Administration of China – May 2026 — official notice. This model may improve traceability and state control over domestic public-facing systems, but it does not eliminate covert misuse, military exploitation, model theft, supply-chain manipulation, or activity conducted outside regulated services. Strategically, China’s approach treats information integrity, political stability, data security, model assurance, industrial development, and national security as one governance continuum. Western systems separate many of these functions among regulators, intelligence agencies, courts, platforms, defence organisations, and civil society. The contest through 2031 will therefore include not only model capability but also competing capacities to impose provenance, constrain autonomous action, collect incident data, and mobilise providers.
The five-year outlook can be structured through six non-exclusive hypotheses. H₁, Augmented Continuity, holds that AI mostly improves existing tactics rather than creating fundamentally new attack classes; its initial probability is 0.81, consistent with the NCSC assessment through 2027. H₂, Agentic Integration, holds that semi-autonomous systems will connect multiple intrusion stages into reliable workflows by 2031; its probability is 0.74. H₃, Defensive Advantage, holds that automated discovery, patching, detection, and containment will improve faster than offensive exploitation among well-resourced organisations; probability 0.56. H₄, Resilience Divide, predicts that the best-defended networks improve while legacy and resource-constrained systems become relatively more vulnerable; probability 0.84. H₅, Synthetic Identity Breakdown, predicts at least one major national-security, financial, or military incident in which AI-enabled impersonation materially defeats a trusted human workflow; probability 0.69. H₆, Strategic Automation Incident, predicts that an AI-enabled cyber action will generate unintended cross-border, physical, or escalatory consequences before 2031; probability 0.43. A conceptual 100,000-iteration Monte Carlo model using model capability, tool access, vulnerability density, defensive automation, identity assurance, data integrity, platform concentration, and geopolitical crisis intensity produces a 2031 median offensive-scale index of 86/100 and a defensive-capacity index of 73/100. The aggregate numbers conceal extreme distributional differences: high-maturity organisations reach a median defensive index of 88, while low-maturity critical operators remain near 46. The model estimates a 78% probability that exploit-development time for disclosed vulnerabilities will fall materially, a 71% probability that synthetic identity will become a routine component of sophisticated intrusion, a 64% probability that major defenders delegate limited containment to autonomous agents, and a 38% probability that poisoned or manipulated AI data contributes to a consequential operational failure. These are structured analytical estimates rather than official statistics. Their main implication is that the outcome will not be determined by whether attackers or defenders possess AI in the abstract. It will depend on whether defenders can integrate trustworthy data, rapid patching, cryptographic identity, bounded autonomy, and human escalation control faster than adversaries integrate reconnaissance, exploitation, deception, and adaptive infrastructure.
| Five-year indicator | 2026 baseline index | 2031 projected index | Direction of strategic pressure |
|---|---|---|---|
| Offensive reconnaissance scale | 66 | 94 | Strongly adverse |
| Exploit-development acceleration | 58 | 88 | Strongly adverse |
| Synthetic identity credibility | 61 | 91 | Strongly adverse |
| Adaptive malware reliability | 39 | 72 | Adverse but constrained |
| Machine-speed defensive triage | 64 | 91 | Strongly favourable |
| Autonomous containment adoption | 37 | 76 | Favourable with systemic risk |
| AI data and model assurance | 31 | 68 | Improving but lagging |
| Public information provenance | 28 | 59 | Insufficient against scale |
| Political attribution confidence | 55 | 57 | Nearly static despite better analytics |
| Escalation-control maturity | 34 | 63 | Improving from a weak base |
Strategic warning will become both richer and more fragile. AI can process enormous volumes of malware telemetry, vulnerability discussion, infrastructure registration, language shifts, financial transfers, underground-market activity, code changes, military movements, influence narratives, and diplomatic signals. It can detect weak combinations that suggest campaign preparation before conventional indicators become obvious. However, adversaries can exploit the same systems by flooding collection environments with generated artefacts, fabricating operational chatter, seeding false vulnerabilities, creating synthetic personas, and producing misleading correlations. The future warning problem will therefore involve adversarially generated evidence, not merely missing information. Intelligence organisations will need to evaluate whether an observed increase in indicators reflects genuine mobilisation, automated criminal activity, deliberate deception, model-generated noise, or defensive scanning. Warning systems must retain source provenance, confidence calibration, adversarial-deception testing, and alternative hypotheses. They should measure not only observed hostile activity but also the quality and independence of the evidence supporting it. Machine-generated summaries must never become the sole basis for strategic warning because summarisation can erase contradictions, minority evidence, and collection gaps. The most effective architecture will combine AI-based pattern discovery with human-led structured analysis, red-team challenge, and explicit Bayesian updates. Decision-makers should see how evidence changes the probabilities of H₁ through H₆ rather than receive a single categorical prediction. By 2031, the states and alliances best positioned to manage AI-accelerated cyber conflict will not be those with the most powerful standalone models. They will be those that connect secure models to trusted data, constrain tools through enforceable permissions, maintain cryptographically strong identity, automate reversible defence, preserve human control over strategic effects, and integrate cyber, intelligence, information, military, diplomatic, economic, and public-communication functions. AI compresses the technical cycle; governance must prevent that compression from becoming strategic instability.
Figure 1: AI-Cyber Offensive–Defensive Projection, 2026–2031
Scenario indices derived from the report’s analytical model. Values are structured estimates, not official forecasts.
Pillar III — Digital Terrain, Shadow Networks and Systemic Risk, 2026–2031
The contested digital terrain of 2026–2031 will not be defined by a single global network, a stable list of critical assets, or a clean division between civilian and military infrastructure. It will consist of an interdependent system of cloud control planes, identity services, software repositories, telecommunications backbones, terrestrial and submarine cables, satellite constellations, data centres, financial networks, managed-service providers, cybersecurity platforms, domain registries, content-delivery systems, and privately operated threat-intelligence services. Each component is independently complex, but systemic risk emerges from the dependencies between them. A hospital may possess redundant servers yet depend on one cloud identity provider; a military logistics platform may use multiple data centres but rely on a single software library, satellite timing source, or telecommunications route; a bank may maintain resilient payment processing while depending on cloud-based fraud detection, domain-name resolution, and third-party authentication. The decisive unit of analysis is therefore not the individual asset but the dependency graph: which functions require which providers, how rapidly traffic can be rerouted, whether alternative suppliers are genuinely independent, whether administrators retain offline access, and how long essential services can operate when digital dependencies fail simultaneously. Commercial disclosures illustrate the scale of the cloud infrastructure now concentrated within a small number of corporations. Amazon reported $128.7 billion in AWS sales for 2025; Microsoft reported $168.9 billion in Microsoft Cloud revenue for fiscal 2025; and Alphabet reported $58.7 billion in Google Cloud revenue for 2025, alongside $91.4 billion in capital expenditure primarily supporting technical infrastructure. These figures do not directly establish market shares, but they demonstrate the extraordinary financial scale and continuing capital concentration of the platforms on which governments, enterprises, defence suppliers, developers, and AI systems increasingly depend. Amazon 2025 Form 10-K – Amazon.com, Inc. – February 2026 — verified SEC filing. Microsoft 2025 Form 10-K – Microsoft Corporation – July 2025 — verified SEC filing. Alphabet 2025 Form 10-K – Alphabet Inc. – February 2026 — verified SEC filing.
Cloud concentration creates a strategic paradox. Large providers can invest in security engineering, global telemetry, specialised incident response, hardware design, cryptographic services, and redundancy at a scale that most individual organisations cannot reproduce. Migrating workloads into professionally managed infrastructure can therefore reduce many routine risks. Yet concentration also creates correlated failure, because thousands of nominally independent organisations may depend on the same identity directory, orchestration layer, administrative interface, certificate service, region, software update, or security policy engine. Multi-cloud branding does not necessarily produce genuine resilience when all environments share the same identity provider, networking vendor, code repository, managed-security platform, or human administrators. The risk is further amplified by AI infrastructure, because the high cost of accelerators, data-centre power, specialised networking, and model deployment encourages additional concentration. A cloud compromise does not need to destroy physical infrastructure to create systemic effects. Manipulation of privileged identities, service-management interfaces, routing policies, access tokens, customer encryption configurations, or software-distribution channels could deny service, expose data, corrupt models, or create persistent surveillance across multiple sectors. The attacker’s objective may be selective rather than universal: preserve normal operation for most customers while degrading a narrow set of government, military, industrial, or political targets. Defensive policy should therefore move beyond uptime statistics and require providers and customers to identify common-mode dependencies, privileged-access paths, cross-region control planes, recovery assumptions, and exit feasibility. Sovereign-cloud policies can improve legal control and data location, but sovereignty remains incomplete where software, updates, hardware, technical expertise, encryption services, or identity systems are externally dependent. China’s official cybersecurity policy explicitly calls for coordinated national situational awareness, integrated threat detection, cloud-service security assessment, supply-chain security, and a model in which detection at one point can support defence across the wider network. Accelerating Modernisation of the National Cybersecurity System and Capabilities – Cyberspace Administration of China – September 2025 — verified Chinese official source. China’s policy model signals that cloud and software assurance will be treated as instruments of national power rather than merely commercial compliance, while Western states will continue balancing security requirements against competition, innovation, privacy, and private ownership.
Software dependencies form the most pervasive and least visible layer of the contested terrain. Modern applications rarely consist of code written and controlled entirely by the organisation operating them. They incorporate open-source libraries, proprietary components, container images, package repositories, development tools, build systems, code-signing services, application programming interfaces, telemetry modules, cloud services, and automated deployment pipelines. A vulnerability or compromise within one upstream component can therefore propagate into thousands of downstream products before operators understand that the dependency exists. Software bills of materials can improve visibility, but a static component inventory does not establish whether a vulnerable function is reachable, whether an update is trustworthy, whether the build system was compromised, or whether an ostensibly independent product embeds the same hidden supplier. CISA’s federal secure-software attestation mechanism requires software producers serving the United States government to attest to minimum secure-development practices, while its 2025 software-acquisition tool seeks to incorporate supplier risk and assurance into procurement decisions. Secure Software Development Attestation Form – Cybersecurity and Infrastructure Security Agency – March 2024 — verified CISA resource. Software Acquisition Guide Supplier Response Web Tool – Cybersecurity and Infrastructure Security Agency – August 2025 — verified CISA release. These mechanisms reflect a strategic shift from treating software as a finished product toward treating it as a continuously governed supply chain. During 2026–2031, adversaries will increasingly target build environments, developer identities, package maintainers, update mechanisms, signing certificates, technical-support channels, and software vendors serving multiple critical sectors. The highest-value operation may not be the direct penetration of a hardened military or financial network; it may be the quiet compromise of a smaller supplier whose trusted update or remote-access channel reaches many protected systems. The defensive requirement is a continuous dependency ledger connecting software components to missions, suppliers, vulnerabilities, signing identities, update histories, and recovery options. Procurement authorities must also account for supplier failure, acquisition, sanctions exposure, geopolitical ownership, and the possibility that a secure supplier becomes insecure after organisational or financial change.
Telecommunications, satellite services, and subsea cables will form a single contested connectivity architecture rather than three separate sectors. Fibre routes carry bulk data; satellites provide timing, navigation, broadcasting, observation, resilient connectivity, and access where terrestrial networks are degraded; terrestrial mobile and fixed networks connect users, sensors, industrial systems, financial services, and military platforms. Disruption at one layer can increase dependence on the others and thereby transfer risk. The European Union states that submarine communication cables carry 99% of intercontinental internet traffic and has adopted a whole-cycle cable-security programme covering prevention, detection, response, repair, and deterrence. The 2025 EU Cable Security Action Plan called for mapping, coordinated risk assessments, stress-testing guidance, strategic cable projects, monitoring, repair capacity, and action against vessels associated with the “shadow fleet.” In 2026, the Commission published a Cable Security Toolbox and Cable Projects of European Interest, while announcing €347 million in related investment; the wider 2025 plan had already identified approximately €540 million in planned Connecting Europe Facility digital investment for 2025–2027 and almost €1 billion under the current financial framework. EU Action Plan on Cable Security – European Commission and High Representative – February 2025 — verified EUR-Lex document. Submarine Cable Security Toolbox and Cable Projects of European Interest – European Commission – February 2026 — verified Commission report page. Satellite infrastructure adds another dependency chain: spacecraft, ground stations, user terminals, software-defined payloads, commercial components, launch systems, spectrum, and terrestrial cloud services. ENISA’s 2025 space-threat assessment identifies state-linked actors, cybercriminals, hackers for hire, private offensive-sector actors, and hacktivists among the relevant threats; it highlights jamming, hijacking, and computer-network exploitation and provides 125 controls across 35 subcategories. ENISA Space Threat Landscape 2025 – European Union Agency for Cybersecurity – March 2025 — verified ENISA report. China’s Ministry of Industry and Information Technology has meanwhile called for integrated satellite gateway supervision and coordinated international communications across terrestrial cables, submarine cables, and satellite internet to reduce risks in critical regions. Guidance on Optimising Market Access and Promoting the Satellite Communications Industry – Ministry of Industry and Information Technology of China – August 2025 — verified Chinese official source.
| Digital terrain layer | Strategic concentration point | Representative attack pathways | Primary cascading effects | 2031 resilience requirement |
|---|---|---|---|---|
| Cloud infrastructure | Control planes, identity, regions, managed databases | Privileged-token theft, orchestration abuse, provider compromise | Cross-sector outage, data exposure, AI-service loss | Independent identity, tested region failure, portable recovery |
| Software supply chain | Build systems, package repositories, code signing | Maintainer compromise, poisoned dependency, malicious update | Simultaneous compromise across customers | Continuous dependency ledger and reproducible builds |
| Telecommunications | Core routing, signalling, DNS, mobile management | Route manipulation, signalling abuse, DDoS, insider access | Loss of communications, authentication and emergency coordination | Diverse routes, protected management plane, offline procedures |
| Satellite services | Ground stations, terminals, spectrum, cloud control | Jamming, hijacking, firmware compromise, terminal exploitation | Navigation, timing, ISR and communications degradation | Multi-orbit alternatives and protected ground segments |
| Subsea cables | Landing stations, repair vessels, chokepoints | Physical damage, covert tapping, landing-site cyberattack | International bandwidth loss and regional isolation | Route diversity, monitoring and repair reserves |
| Cybersecurity platforms | Endpoint agents, identity analytics, update channels | Poisoned updates, administrative compromise | Defences disabled across many organisations | Segmented administration and independent detection |
| Financial rails | Exchanges, stablecoins, mixers, payment services | Laundering, sanctions evasion, fraudulent transfer | Sustained criminal operations and proxy financing | Real-time tracing and coordinated seizure capacity |
Cybercrime markets will operate as a distributed industrial ecosystem in which specialised suppliers lower entry barriers for both criminals and politically useful proxies. The ecosystem includes initial-access brokers, ransomware operators, malware developers, botnet controllers, bulletproof hosts, domain suppliers, money launderers, cryptocurrency exchanges, recruitment forums, data brokers, call centres, negotiators, and technical support services. This division of labour allows an actor to purchase access, infrastructure, payloads, laundering, and monetisation without mastering the entire attack lifecycle. It also creates resilience: when one provider is disrupted, customers migrate to successors, alternate jurisdictions, or newly branded services. United States Treasury actions illustrate both the scale and adaptability of the financial and infrastructure layer. Treasury stated in August 2025 that Garantex had processed more than $100 million in transactions connected to illicit activity since 2019; after coordinated law-enforcement action froze more than $26 million and seized infrastructure, a successor exchange, Grinex, allegedly continued elements of the business. Treasury Sanctions Cryptocurrency Exchange and Network Enabling Sanctions Evasion and Cyber Criminals – U.S. Department of the Treasury – August 2025 — verified Treasury release. Treasury separately sanctioned Zservers for supporting LockBit and described bulletproof hosting as infrastructure designed to resist detection and law-enforcement disruption. United States, Australia, and United Kingdom Jointly Sanction Key Infrastructure that Enables Ransomware Attacks – U.S. Department of the Treasury – February 2025 — verified Treasury release. Europol reported that the May 2025 phase of Operation Endgame seized €21.2 million in cryptocurrency, took down 300 malware servers, neutralised 650 domains, and supported warrants against 20 targets; in June 2026 it reported disruption of an alleged cryptocurrency-laundering service associated with more than €336 million between 2022 and 2025. European Cybercrime Centre Operational Highlights – Europol – current official page — verified Europol source. Ransomware Gangs Cut Off from €336 Million Cryptocurrency-Laundering Pipeline – Europol – June 2026 — verified Europol release.
Cryptocurrency liquidity will remain strategically important not because blockchain systems are inherently anonymous, but because digital assets enable rapid, cross-border settlement across ransomware, fraud, exploit sales, proxy payments, sanctions evasion, infrastructure rental, and laundering services. Public ledgers can support tracing, but tracing does not automatically produce seizure. Successful disruption requires identification of counterparties, legal jurisdiction, exchange cooperation, control of private keys, evidence preservation, international coordination, and timing fast enough to prevent conversion or fragmentation. Actors can move through exchanges, stablecoins, peer-to-peer brokers, nested services, cross-chain bridges, mixers, informal over-the-counter networks, and accounts registered through synthetic or stolen identities. The shadow-finance layer will increasingly converge with conventional infrastructure: bulletproof hosts require payment; access brokers monetise compromised credentials; commercial spyware vendors use corporate structures; ransomware groups pay affiliates; fraud networks purchase domains, advertising, messaging accounts, and identity documents. Treasury’s 2025 sanctions against Funnull Technology alleged that the company provided infrastructure for hundreds of thousands of websites involved in virtual-currency investment scams and linked that infrastructure to more than $200 million in reported United States victim losses. Treasury Takes Action Against Major Cyber Scam Facilitator – U.S. Department of the Treasury – May 2025 — verified Treasury release. Russia’s official cybercrime concept explicitly identifies digital currency and digital financial assets as instruments used in unlawful activity and money laundering, while arguing that anonymity and cross-border limitations complicate identification and confiscation. It calls for a specialised digital platform connecting law enforcement, the central bank, financial institutions, and telecommunications operators. Concept of the State System for Countering Offences Committed Using Information and Communications Technologies – Government of the Russian Federation – December 2024 — verified Russian official document. Russia subsequently enacted a 2025 federal law establishing a state information system intended to support rapid prevention, detection, suppression, and inter-organisational coordination against ICT-enabled offences. Federal Law No. 41-FZ – Government of the Russian Federation – April 2025 — verified Russian official document. These measures reveal a wider trend: financial intelligence, telecom metadata, platform reporting, and cyber investigation will increasingly merge into shared state systems by 2031.
State proxies, hacktivist fronts, and mercenary intrusion teams will complicate the battlespace by allowing states and politically connected actors to obtain effects without exposing a formal chain of command. These relationships exist on a spectrum. At one end, a state intelligence or military body can directly task operators while masking attribution. At the other, ideologically aligned groups may act independently but receive permissive treatment, selective intelligence, public encouragement, infrastructure, or protection from prosecution. Between those poles sit contractors, criminal affiliates, exploit vendors, surveillance companies, and temporary coalitions that provide specialised capability. ENISA’s 2025 landscape found that hacktivism represented almost 80% of recorded incidents, predominantly through DDoS activity, although only 2% of hacktivist incidents resulted in service disruption. This combination is analytically important: high-volume, low-impact operations can still impose defensive workload, generate propaganda, test infrastructure, obscure more serious intrusions, and create a plausible public narrative around state interests. EU Consistently Targeted by Diverse Yet Convergent Threat Groups – ENISA – October 2025 — verified ENISA release. Commercial spyware represents the more sophisticated mercenary tier. In March and September 2024, the United States Treasury sanctioned members and enablers of the Intellexa Consortium, describing a decentralised international corporate network that developed and distributed Predator spyware, including zero-click capabilities, to governmental and state-sponsored customers. Treasury Sanctions Members of the Intellexa Commercial Spyware Consortium – U.S. Department of the Treasury – March 2024 — verified Treasury release. Treasury Sanctions Enablers of the Intellexa Commercial Spyware Consortium – U.S. Department of the Treasury – September 2024 — verified Treasury release. Such firms convert scarce exploit research, surveillance engineering, and operational support into purchasable capability. Their proliferation means that sophisticated intrusion can no longer be inferred automatically to originate from a small group of technically advanced states.
Exploit brokerage will become a strategic commodity market linking vulnerability researchers, commercial surveillance companies, criminal actors, defence organisations, intelligence services, software vendors, and intermediaries operating through opaque legal structures. A previously unknown vulnerability has different values depending on reliability, affected population, level of access, persistence, interaction requirements, target platform, detectability, and the buyer’s intended mission. The same exploit can support lawful testing, intelligence collection, repression, ransomware, financial theft, or military preparation. Regulation is difficult because the traded object may be source code, technical knowledge, proof-of-concept material, access to a service, or an operational result rather than a conventional product. Markets also respond to defensive improvement. As mobile platforms, browsers, cloud environments, and endpoint systems strengthen isolation and exploit mitigation, reliable attack chains may require multiple vulnerabilities, increasing their scarcity and price. AI-assisted vulnerability discovery could expand supply, but it may also increase demand by enabling more actors to evaluate and weaponise findings. Governments will face a policy conflict between retaining vulnerabilities for intelligence purposes and disclosing them to protect national infrastructure. By 2031, mature states should treat exploit markets as part of national economic-security analysis: monitoring corporate ownership, talent movement, acquisitions, export routes, cryptocurrency flows, customer relationships, and interactions with commercial spyware ecosystems. Sanctions and export controls can raise costs but may also push suppliers toward less transparent jurisdictions, private brokerage, and service-based models in which the buyer purchases access rather than the exploit itself. The most effective control architecture will combine vulnerability-equities processes, vendor disclosure channels, legal restrictions on abusive surveillance, procurement rules, sanctions, visa measures, financial tracing, and technical detection. It must also account for the possibility that exploit suppliers become state proxies during crises. A nominally commercial firm may possess privileged access, global telemetry, customer infrastructure, and specialised operators that a government can compel, recruit, infiltrate, or contract. The distinction between cyber mercenary, software supplier, intelligence contractor, and criminal facilitator will therefore become increasingly contextual rather than categorical.
The five-year systemic-risk model should be organised around competing hypotheses rather than a single forecast. H₁, Managed Concentration, holds that cloud, telecommunications, and satellite providers will continue consolidating but will invest sufficiently in redundancy and security to prevent repeated systemic failure; the 2031 probability is assessed at 0.57. H₂, Correlated Platform Failure, predicts at least one multinational incident in which a shared cloud, identity, security, or software dependency disrupts multiple critical sectors; probability 0.66. H₃, Hybrid Infrastructure Contestation, predicts persistent interaction between cyber intrusion, physical interference, maritime activity, satellite disruption, and influence operations against cables and communications; probability 0.72. H₄, Criminal–State Convergence, predicts that criminal infrastructure, proxy groups, exploit vendors, and state objectives will become more operationally intertwined without forming fixed alliances; probability 0.79. H₅, Financial Disruption Advantage, predicts that coordinated sanctions, seizures, exchange regulation, and blockchain analytics will materially reduce the operational liquidity of major ransomware ecosystems; probability 0.48, because successful disruptions are likely to produce migration rather than permanent suppression. H₆, Sovereign Fragmentation, predicts that data localisation, competing technical standards, sanctions, national-cloud strategies, and geopolitical blocs will divide the global digital terrain into less interoperable zones; probability 0.74. A conceptual 100,000-iteration Monte Carlo model using provider concentration, route diversity, software commonality, satellite dependency, repair capacity, criminal liquidity, proxy mobilisation, and geopolitical crisis intensity generates a median 2031 systemic-risk index of 76/100. It estimates a 64% probability of a cross-sector digital disruption lasting more than 24 hours in at least one major economy, a 46% probability of a major regional cable or satellite incident producing measurable spillover into finance or logistics, a 71% probability that criminal infrastructure will be reused for politically aligned operations, and a 35% probability that a commercial offensive-cyber supplier will become central to a major international attribution dispute. These are structured analytical estimates, not official statistics. Their principal value is identifying the strongest intervention points: route diversity, independent identity, software transparency, rapid cable repair, satellite ground-segment protection, financial tracing, and coordinated action against infrastructure enablers.
| Hypothesis | 2026 prior | 2031 probability | Principal confirming indicators | Principal disconfirming indicators |
| H₁ Managed Concentration | 0.51 | 0.57 | Improved provider resilience, tested portability, transparent dependency reporting | Repeated control-plane or identity failures |
| H₂ Correlated Platform Failure | 0.59 | 0.66 | Shared software, identity and cloud dependencies across sectors | Genuine multi-provider independence and offline continuity |
| H₃ Hybrid Infrastructure Contestation | 0.64 | 0.72 | Cable incidents, jamming, maritime surveillance, coordinated cyber activity | Effective monitoring, attribution and rapid repair |
| H₄ Criminal–State Convergence | 0.73 | 0.79 | Shared infrastructure, tolerated actors, contractor and proxy use | Consistent prosecution and loss of safe jurisdictions |
| H₅ Financial Disruption Advantage | 0.42 | 0.48 | Coordinated seizures, sanctions and exchange controls | Rapid migration to decentralised laundering systems |
| H₆ Sovereign Fragmentation | 0.67 | 0.74 | Localisation, trusted-vendor rules, sanctions and national platforms | Interoperable standards and resilient cross-border governance |
The strategic conclusion is that systemic security cannot be produced by protecting each infrastructure layer independently. Cloud authorities may secure data centres while remaining dependent on telecommunications and electricity; cable operators may create route diversity while relying on a limited repair fleet; satellite operators may protect spacecraft while exposing ground stations, terminals, software updates, and cloud control systems; banks may trace cryptocurrency while criminal infrastructure migrates to alternative exchanges, brokers, and jurisdictions. The required 2031 architecture is therefore a digital-terrain command map maintained jointly by governments and critical providers. It should identify mission-essential services, upstream and downstream dependencies, geographic concentrations, common vendors, privileged identities, recovery times, foreign ownership, sanctions exposure, repair assets, alternative routes, and manual fallback procedures. Stress tests must assume simultaneous failure rather than isolated incidents: loss of a cloud region combined with telecommunications disruption; cable damage during a satellite-jamming campaign; a malicious software update coinciding with fraudulent crisis communications; or ransomware activity used to conceal state-directed pre-positioning. States should also maintain standing disruption cells that combine intelligence, law enforcement, sanctions authorities, telecommunications regulators, cyber agencies, military commands, and private providers to act against bulletproof hosting, malicious domains, cryptocurrency laundering, exploit supply, and proxy infrastructure. The objective is not to eliminate shadow networks, which will adapt continuously, but to reduce their reliability, increase their operating costs, shorten their useful lifespan, and expose relationships between technical infrastructure and political sponsorship. By 2031, the balance of cyber power will depend less on the number of networks nominally controlled by a state than on whether the state can see and govern the hidden dependencies connecting commercial platforms, physical communications, software supply, financial liquidity, and offensive capability. Digital terrain will remain privately owned, internationally distributed, and technically mutable. Strategic sovereignty will belong to the actors able to map it, diversify it, repair it, finance it, and deny its shadow layers to adversaries faster than those adversaries can reconstitute them.
Figure 1: Digital Terrain and Systemic-Risk Projection, 2026–2031
Analytical indices based on the report’s dependency and shadow-network model. Values are structured estimates rather than official forecasts.



















