Executive Summary

BLUF: Between 2027 and 2031, geopolitical power will increasingly depend on the ability to control, secure, disrupt, reroute and reconstruct the interconnected infrastructure through which data, energy, finance and military commands move.

Physical borders will persist legally, but their strategic value will be partially displaced by virtual borders formed by submarine cables, satellite constellations, cloud regions, spectrum access, data centres, digital identities, industrial control systems and artificial-intelligence supply chains.

Artificial intelligence will compress cyber operations from human-paced campaigns into machine-speed contests of detection, deception, exploitation and automated response.

The most consequential attacks will not remain inside computers: they will propagate into electricity, water, healthcare, transport, telecommunications, financial clearing, nuclear security and public decision-making.

Regulation will improve minimum standards but will remain structurally slower than adversarial adaptation, software deployment and model proliferation.

The central five-year risk is not an autonomous “AI war” in isolation, but a tightly coupled AI–cyber–infrastructure system in which automated agents generate effects faster than governments can attribute, deliberate or coordinate.

The strategic contest will divide networks into partially sovereign technological blocs while preserving dangerous interdependence at cable landing stations, cloud platforms, satellite ground segments, chip supply chains and open-source software layers.

Human freedom will increasingly depend upon control over identity, computation, connectivity and algorithmic access—not merely freedom of movement across territory.

Europe’s Virtual Borders: The AI Power Deficit Behind the Regulatory Superpower

Europe has built the world’s most sophisticated digital rulebook while the strategic frontier has moved elsewhere. Artificial intelligence is no longer merely an industrial technology: it is becoming the command layer for cloud infrastructure, cyber defence, satellite networks, intelligence, energy systems and military operations. The real border of a state now lies wherever data can be intercepted, computation denied, software modified or an algorithmic decision imposed. France, Germany, Italy and the United Kingdom retain formidable scientific and industrial assets. Yet the decisive question is no longer whether Europe can regulate AI. It is whether it can finance, power, build and defend the infrastructure on which sovereignty will depend by 2031.

The Compute Frontier

The European Union has finally recognised that regulation without computing power produces dependency. On 11 February 2025, Commission President Ursula von der Leyen launched InvestAI in Paris, with the declared objective of mobilising €200 billion, including a €20 billion facility for up to five AI Gigafactories. Each is expected to concentrate more than 100,000 advanced processors for the training of next-generation models. The Commission’s AI Continent Action Plan, presented on 9 April 2025, also assigned approximately €10 billion to AI Factories and EuroHPC infrastructure for 2021–2027. By April 2026, Europe had deployed 19 AI Factories and created 13 associated antennas. EU Launches InvestAI Initiative to Mobilise €200 Billion of Investment in Artificial Intelligence – European Commission – February 2025; AI Factories – European Commission – April 2026.

The numbers are substantial, but their composition matters. “Mobilised investment” is not equivalent to an immediately available European appropriation. It includes expected private capital, national contributions, European instruments and financial guarantees. Gigafactory construction is only beginning while American hyperscalers and Chinese state-supported operators are already expanding successive generations of computing capacity. The European Court of Auditors warned in May 2024 that EU measures had produced only limited effects, had not accelerated investment sufficiently to keep pace with global leaders and lacked effective coordination with national initiatives. Special Report 08/2024: EU Artificial Intelligence Ambition – European Court of Auditors – May 2024.

This is the central European weakness: not intellectual capacity, but the conversion of research, capital and political declarations into operational power.

France’s Nuclear Advantage

France currently offers continental Europe’s most coherent route toward full-stack AI sovereignty. On 11 February 2025, President Emmanuel Macron announced more than €109 billion in French and foreign investment commitments for AI infrastructure and deployment. The Élysée identified the country’s principal advantages: abundant low-carbon electricity, a stable high-voltage network, suitable data-centre sites and accelerated procedures. Macron also stated that France was training approximately 40,000 AI specialists annually, with the ambition of reaching 100,000. Make France an AI Powerhouse – Presidency of the French Republic – February 2025; Business Day of the AI Action Summit – Presidency of the French Republic – February 2025.

France’s advantage is structural. Nuclear generation can provide the stable electricity required by high-density clusters. The country also connects Mistral AI, the CEA, national laboratories and defence groups such as Thales, Safran and Dassault Systèmes. Yet the vulnerability remains: many of the announced data centres will rely on foreign capital, American accelerators and non-European cloud technologies. Hosting computation is not the same as controlling it. France will become strategically autonomous only if infrastructure is reserved for European models, defence workloads and industrial platforms, with European control over encryption keys, software updates and operational priorities.

Britain’s Faster Machine

Outside the EU, the United Kingdom has adopted the clearest execution-oriented strategy. In January 2025, the government accepted the recommendation to expand sovereign public computing capacity by at least twenty times by 2030. Its AI Research Resource includes Isambard-AI, whose 5,448 NVIDIA GH200 superchips make it Britain’s most powerful public AI computer. The programme is backed by an additional £1 billion, while the government reported in January 2026 that total compute commitments had risen to £2 billion and that up to £500 million had been assigned to support British AI companies through the Sovereign AI Unit. AI Opportunities Action Plan: Government Response – UK Government – January 2025; AIRR Advanced Supercomputers for the UK – UK Government – July 2026; AI Opportunities Action Plan: One Year On – UK Government – January 2026.

Prime Minister Keir Starmer’s model combines public compute, AI Growth Zones, accelerated planning, venture support and government procurement. It is more agile than the average EU process, but Britain remains dependent on American chips, cloud platforms and capital. Its strategic future therefore lies in acting as a European AI and security power—not as an isolated regulatory island—through cooperation with France, EuroHPC, European defence industries and trusted continental data systems.

Germany’s Industrial Intelligence

Germany possesses Europe’s strongest potential for industrial AI. Its advantage lies not in consumer chatbots but in automotive production, machinery, chemicals, logistics, sensors, robotics and enterprise software. On 18 March 2026, the federal government adopted a strategy to at least double German data-centre capacity by 2030. Germany already hosts more than 2,000 data centres, with approximately 3 GW of connected capacity and electricity consumption of around 20 TWh annually. The target is to exceed 6 GW by the end of the decade, while substantially expanding high-performance computing and AI infrastructure. More Computing Power for Germany – German Federal Government – March 2026.

Germany’s problem is the distance between industrial depth and digital control. Its factories increasingly depend on foreign cloud services, processor architectures and software layers. If this continues, German companies will manufacture the physical economy while non-European platforms control its intelligence, data and optimisation. Berlin must therefore transform industrial datasets, digital twins, autonomous production and defence manufacturing into a unified strategic programme. The objective should not be to imitate every American foundation-model company, but to dominate the AI systems that govern machines, factories, vehicles and energy networks.

Italy’s Unconverted Potential

Italy has the greatest discrepancy between strategic potential and capital concentration. The Italian Strategy for Artificial Intelligence 2024–2026, published on 22 July 2024, organises policy around research, public administration, enterprises and education. The fourteen-member committee was coordinated by Gianluigi Greco, while Undersecretary Alessio Butti described the strategy as the basis for national AI legislation and policy. Italian Strategy for Artificial Intelligence 2024–2026 – Agency for Digital Italy – July 2024.

Italy possesses the Leonardo supercomputer, the IT4LIA AI Factory, advanced manufacturing districts and major aerospace, cyber and defence companies, including Leonardo and Fincantieri. Its Mediterranean position also gives it unusual strategic value as a potential junction between European data networks, North Africa, the Middle East and submarine cable routes.

Investment is arriving. On 14 May 2026, Industry Minister Adolfo Urso discussed EdgeConneX’s plan for three data centres near Milan and Lodi valued at €6 billion. The ministry reported more than €7 billion invested in Italian data centres between 2023 and 2025 and a further €25 billion announced for 2026–2028. EdgeConneX Investment Plan for Three New Data Centres in Italy – Ministry of Enterprises and Made in Italy – May 2026.

But foreign data centres do not automatically create Italian AI sovereignty. Without domestic model companies, reserved compute, strategic procurement and growth capital, Italy risks becoming a hosting territory: it will provide land, electricity and connectivity while the intellectual property, processors and profits remain elsewhere.

The Adoption Divide

Europe’s weakness is not confined to frontier laboratories. In 2024, only 13.5% of EU enterprises with at least ten employees used AI. The figure rose to 20% in 2025, but the distribution remained sharply uneven: Denmark reached 42%, Finland 37.8% and Sweden 35%, while Romania stood at 5.2%, Poland at 8.4% and Bulgaria at 8.5%. Usage of AI Technologies Increasing in EU Enterprises – Eurostat – January 2025; 20% of EU Enterprises Use AI Technologies – Eurostat – December 2025.

This divide has geopolitical consequences. AI productivity will accumulate where companies possess data, capital, skilled personnel and cloud access. Regions that adopt slowly will not simply grow less quickly; they will become technologically dependent on systems designed elsewhere. European fragmentation therefore operates simultaneously between continents, between Member States and between large companies and SMEs.

Regulation Without Command

The EU’s regulatory framework remains indispensable. The AI Act, cybersecurity rules and critical-infrastructure legislation protect rights, establish accountability and constrain dangerous uses. The error would be to believe that legal sovereignty can substitute for industrial sovereignty.

Europe can determine the conditions under which AI systems enter its market. It cannot, through regulation alone, manufacture advanced accelerators, create a hyperscale cloud platform, retain frontier companies or guarantee wartime access to computing capacity. A continent that writes the standards but imports the operating system of power remains exposed.

The answer is not indiscriminate deregulation. It is symmetry: every major regulatory initiative must be matched by capital, infrastructure, energy, procurement and security instruments of comparable scale.

The Cost of Delay

By 2031, digital sovereignty will be measured through operational tests. Can Europe train or adapt strategic models without foreign permission? Can it maintain government, defence, energy and healthcare systems if a hyperscaler withdraws service? Can it replace restricted processors, protect cloud identities and defend industrial networks at machine speed? Can European companies scale without relocating or being acquired?

The most probable outcome under current policy is not technological collapse, but regulated dependency: Europe will possess excellent rules, substantial computing centres and strong specialised industries while remaining dependent at the most consequential layers of chips, cloud and frontier models.

France can become the continental compute and model nucleus. Britain can supply venture capital, research and security agility. Germany can dominate industrial AI. Italy can become the Mediterranean platform for defence, aerospace, manufacturing and infrastructure intelligence. But these assets will remain subscale unless Europe aggregates demand and capital.

The continent now requires a sovereign compute authority, a late-stage technology fund, common defence-AI procurement, protected energy connections and long-term public contracts for European providers. The choice is no longer between innovation and regulation. It is between governing technologies Europe controls and regulating technologies on which it depends.


Navigational Index

Pillar I — The New Geography of Power

Submarine cables, orbital systems, cloud infrastructure, spectrum, data localisation and computational sovereignty as the functional borders of the emerging international system.

Pillar II — AI-Accelerated Cyber Conflict

Autonomous reconnaissance, vulnerability discovery, influence operations, defensive automation, machine-speed escalation and the migration of cyber effects into physical infrastructure.

Europe’s Digital Power Deficit: Italy, France, Germany, the United Kingdom and the Strategic Race for AI Sovereignty to 2031

Pillar III — Governance, Deterrence and Human Freedom

The widening gap between regulation and operational reality, competing models of digital sovereignty, critical-infrastructure resilience and the preservation of human agency through 2031.


Master Abstract

Networks Are Becoming Territory

The international system is entering a period in which geography is no longer eliminated by digital connectivity but reconstructed through it. A state’s effective strategic perimeter now extends through the submarine cables carrying its external communications, the landing stations where those cables reach national territory, the satellite systems supporting navigation and timing, the cloud regions hosting public and commercial data, the software dependencies embedded in essential services, and the industrial-control networks governing electricity, water, transport, healthcare and manufacturing. The International Telecommunication Union states that submarine telecommunications cables provide more than 99% of intercontinental connectivity, while more than 200 cable repairs were reported worldwide in 2023, equivalent to over three failures per week. These figures demonstrate a structural concentration of global activity in a comparatively narrow and physically exposed infrastructure layer: Terms of Reference, International Advisory Body for Submarine Cable Resilience – International Telecommunication Union – November 2024 and Submarine Cable Resilience – International Telecommunication Union – February 2026. The European Commission consequently organised its cable-security policy around prevention, detection, response, recovery and deterrence, explicitly treating submarine data and power links as critical and strategic functions connecting Member States, islands, outermost regions and Europe to the wider world: EU Action Plan on Cable Security – European Commission and High Representative – February 2025. In February 2026, the Commission added a common cable-security toolbox and a framework for identifying Cable Projects of European Interest: Submarine Cable Security Toolbox and Cable Projects of European Interest – European Commission – February 2026. These measures reveal the emerging logic of virtual geography. A cable route can become a strategic corridor; a landing station can operate as a digital port; a satellite ground terminal can function as a frontier post; a cloud availability zone can become a quasi-territorial repository of national capability. Yet these borders remain layered, privately operated and legally fragmented. Ownership, maintenance, insurance, encryption, routing, seabed access, naval surveillance and emergency repair authority may sit in different jurisdictions. The resulting system is neither borderless nor fully sovereign. It is a contested topology in which states possess unequal visibility over the infrastructure on which their security depends.

Cyber Operations Are Becoming Physical Operations

The distinction between “cyber conflict” and conventional harm is becoming analytically untenable because digital compromise increasingly serves as an access mechanism to physical processes. Hospitals depend on digital scheduling, diagnostics, pharmacy systems and networked medical devices; electricity networks depend on operational technology, remote telemetry and load-balancing platforms; water systems depend on pumps, chemical controls and supervisory systems; nuclear facilities depend on layered digital instrumentation, administrative networks and security architectures. The International Atomic Energy Agency recommends graded computer-security levels and segmented security zones based on the most sensitive facility function performed within each zone, demonstrating that nuclear cybersecurity must be designed around consequences rather than conventional information confidentiality alone: Computer Security Techniques for Nuclear Facilities – International Atomic Energy Agency – 2021. In the United States, CISA treats cybersecurity objectives as national-risk controls covering both information technology and operational technology across energy, healthcare, water, communications, transport and other critical sectors: Cross-Sector Cybersecurity Performance Goals – Cybersecurity and Infrastructure Security Agency – 2023. Within the European Union, the 2024 threat assessment placed availability attacks, ransomware and threats against data among the leading categories identified through analysis of several thousand reported incidents, while also recording increased use of trusted cloud services, legitimate administrative tools and ordinary communications platforms to conceal hostile activity: ENISA Threat Landscape 2024 – European Union Agency for Cybersecurity – September 2024. The five-year transformation will be driven by AI systems capable of automating reconnaissance, code analysis, social engineering, vulnerability prioritisation, credential exploitation, lateral movement and defensive triage. AI will not make all attacks sophisticated; it will make sophistication reproducible, scalable and accessible. At the same time, defenders will deploy autonomous detection, behavioural baselining, machine-generated containment rules and adaptive deception. This produces a compression of the observe–orient–decide–act cycle. Operations that previously required days of human analysis may be initiated, modified or countered within minutes or seconds. The strategic danger lies in the coupling of autonomous systems to imperfect intelligence: an AI agent may classify an anomaly as an intrusion, initiate isolation, alter routing, suspend industrial processes or escalate defensive actions before human authorities understand the initiating event. The decisive question through 2031 will therefore be not whether AI participates in cyber conflict, but which decisions remain subject to meaningful human control and whether that control can still operate at machine speed.

Governance Will Trail the Operational System

The regulatory response is expanding, but the five-year outlook indicates a persistent gap between normative control and technical reality. Governance instruments ordinarily define accountable organisations, documented processes, risk categories and human responsibilities; adversarial systems exploit transient vulnerabilities, unknown dependencies, compromised suppliers, stolen credentials and jurisdictional seams. NIST’s Generative AI Profile identifies cross-sector risks and proposes lifecycle risk-management actions, while the broader AI Risk Management Framework is undergoing revision and, as of April 2026, includes work toward a dedicated profile for trustworthy AI in critical infrastructure: Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile – National Institute of Standards and Technology – July 2024 and AI Risk Management Framework – National Institute of Standards and Technology – April 2026. These frameworks strengthen institutional discipline, but they cannot by themselves prevent clandestine model modification, autonomous tool chaining, open-weight model misuse or deployment through foreign infrastructure. Competing geopolitical doctrines further complicate convergence. China’s Global AI Governance Initiative calls for controllable, reliable and equitable AI, opposes ideological division and emphasises sovereign participation in global rule formation: Global AI Governance Initiative – Ministry of Foreign Affairs of the People’s Republic of China – October 2023. Russia’s official framework defines international information security as a strategic-planning domain connected to sovereignty, technological dependence and the prevention of interstate conflict in the global information space: Foundations of State Policy of the Russian Federation in the Field of International Information Security – President of the Russian Federation – April 2021. NATO, by contrast, treats cyber defence as part of deterrence and defence and established an Integrated Cyber Defence Centre to improve situational awareness, network protection and operational integration while strengthening the protection of critical undersea infrastructure: Washington Summit Declaration – North Atlantic Treaty Organization – July 2024. The resulting system is unlikely to converge on a single cyber constitution. It will evolve as overlapping regimes of alliance defence, digital sovereignty, corporate infrastructure governance, technical standards and national-security exemptions. Regulation will reduce ordinary risk where compliance is enforceable, but high-end conflict will continue to occur in ambiguous space below conventional thresholds. Freedom will consequently depend upon whether individuals retain practical control over identity, communication, mobility, financial access and information exposure. A person may remain legally free while being algorithmically constrained by authentication systems, automated risk classifications, network exclusion, pervasive surveillance or the loss of access to essential digital services. The future border may therefore be encountered not at a checkpoint, but at an identity gateway, a satellite footprint, a cloud-policy engine or an AI-generated decision that cannot be meaningfully appealed.

Five-Year Outlook and Competing Hypotheses

The 2027–2031 outlook is assessed through five competing hypotheses rather than a single deterministic forecast. H₁, Managed Resilience, assumes that governments, alliances and infrastructure operators successfully introduce zero-trust architectures, mandatory incident reporting, cable redundancy, sovereign cloud capacity, satellite diversification and controlled AI deployment faster than threat actors can exploit systemic weaknesses. H₂, Persistent Grey-Zone Conflict, assumes that states and proxies continue disruptive operations below the threshold that would reliably trigger collective military responses, producing chronic espionage, sabotage preparation, ransomware, data manipulation and temporary service interruption without generalised war. H₃, Fragmented Digital Blocs, anticipates greater technological separation among Western, Chinese, Russian and non-aligned ecosystems, including divergent identity systems, cloud platforms, AI models, semiconductor access rules, routing policies and security standards. H₄, Autonomous Escalation, assumes that offensive and defensive AI agents progressively interact without sufficient human control, increasing false attribution, unintended propagation and machine-speed escalation. H₅, Cascading Infrastructure Crisis, anticipates that a combined disruption affecting cables, satellite services, cloud infrastructure and operational technology produces cross-sector failures exceeding available repair and coordination capacity. A structured Bayesian baseline assigns indicative 2026 priors of 20% to H₁, 37% to H₂, 24% to H₃, 11% to H₄ and 8% to H₅. These are analytical estimates, not observed frequencies. Evidence from current alliance policy, EU resilience programmes, Russian and Chinese sovereignty doctrines, expanding AI capabilities and persistent infrastructure concentration produces a 2031 assessment in which H₂ remains the modal outcome, while H₃ gains probability and H₄ becomes materially more credible after 2029. A Monte Carlo stress model with 25,000 simulated pathways—varying attack automation, infrastructure redundancy, attribution confidence, repair latency, alliance coordination and regulatory effectiveness—indicates an estimated 63% probability of at least one multi-sector cyber disruption with material physical effects during the five-year period, a 31% probability of a regional disruption involving both terrestrial and space-based services, and an approximately 14% probability of an incident producing sustained international escalation. These outputs are scenario-model estimates and must not be interpreted as official forecasts. Their strategic meaning is that resilience must be measured not only by preventing initial compromise, but by preserving essential functions under conditions of simultaneous uncertainty, degraded connectivity and contested attribution.

Strategic Systems Model · 2027–2031

Virtual Border Risk Observatory

Interactive analytical model of AI autonomy, infrastructure concentration, resilience and escalation. Values represent scenario estimates rather than official predictions or measured incident frequencies.

MODEL ONLINE

Scenario Inputs

Modify the structural assumptions to recalculate the five-year risk profile.

67
72
51
Cascade RiskR₁
63%
Machine EscalationR₂
44%
Recovery CapacityR₃
51%

Virtual Border Exposure

Relative strategic exposure by network layer for the selected year.

Submarine Cables78
Satellite and PNT61
Cloud and Data Centres73
Energy and Operational Technology69
Identity and Civic Access57
H₁
Managed Resilience
20%
Resilience and coordinated governance outpace systemic exposure.
H₂
Persistent Grey-Zone Conflict
37%
Chronic coercion remains below collective-response thresholds.
H₃
Fragmented Digital Blocs
24%
Standards, platforms and infrastructure divide geopolitically.
H₄
Autonomous Escalation
11%
Machine-speed interaction weakens human escalation control.
H₅
Cascading Infrastructure Crisis
8%
Simultaneous network failures overwhelm repair and coordination.

Pillar I — The New Geography of Power: Virtual Borders, Infrastructure Sovereignty and the Five-Year Contest for Network Control

From Territorial Frontiers to Infrastructure-Defined Sovereignty

The emerging geography of power does not abolish territorial sovereignty; it superimposes a second, operational geography upon it. This new geography is formed by the physical and logical routes through which data, computation, electrical power, positioning signals, financial instructions and military communications move. A state may possess internationally recognised borders yet remain strategically permeable because its external communications traverse foreign-controlled submarine cables, its government databases operate on cloud platforms subject to another jurisdiction, its armed forces depend on commercial satellite services, its industries rely on imported semiconductors and its public administration authenticates users through identity systems whose cryptographic roots are maintained abroad. Conversely, a state or corporation that controls cable capacity, cloud orchestration, satellite constellations, spectrum assignments, chip fabrication, foundational software and high-performance computing can exercise power far beyond its formal territory. The most accurate unit of geopolitical analysis is therefore no longer the map alone but the dependency graph connecting landing stations, data centres, internet exchanges, energy grids, ground stations, spectrum rights, software repositories and supply chains. The International Telecommunication Union reports that more than 99% of international data traffic is transported by submarine telecommunications cables and that the global network comprises roughly 500 active or planned systems extending more than 1.7 million kilometres. International Summit Outlines Steps to Improve Resilience of Submarine Telecommunications Cables Worldwide – International Telecommunication Union – February 2025. This concentration converts marine corridors, cable landing sites and repair capacity into strategic terrain. The same logic applies above the Earth: the ITU’s 2024 Radio Regulations, effective from 1 January 2025, govern the international use of radio-frequency spectrum and satellite orbits, both of which the organisation treats as globally shared and limited natural resources. ITU Publishes Updated Global Treaty to Optimise Radio Spectrum Management – International Telecommunication Union – August 2024. Sovereignty is thus becoming a layered capability measured by the ability to observe, regulate, defend, substitute and restore the infrastructures that sustain national functions. The practical border of a modern state lies wherever interruption, foreign legal compulsion, vendor withdrawal, spectrum denial or computational exclusion could prevent that state from acting independently.

Table 1 — Functional Borders of the Emerging International System

Infrastructure layerFunctional borderPrincipal strategic assetPrimary coercive mechanismFailure consequenceFive-year geopolitical direction
Submarine cablesCable route, landing station, branching unit, repair corridorInternational bandwidth and intercontinental continuityPhysical damage, route concentration, ownership leverage, repair delayLoss of external communications, cloud access, financial connectivity and military coordinationIncreased naval surveillance, public funding, route diversification and cable-protection regimes
Satellite systemsOrbital shell, ground segment, control link and user terminal footprintPositioning, timing, communications, intelligence and Earth observationJamming, spoofing, cyber compromise, anti-satellite pressure, licensing restrictionsDegraded navigation, synchronisation, targeting, logistics and emergency communicationsExpansion of proliferated constellations, sovereign payloads and military-commercial integration
Cloud infrastructureData-centre region, identity plane, control plane and encryption boundaryScalable computation, public data, AI deployment and digital-service continuityAccount suspension, jurisdictional access, token theft, supply-chain compromiseAdministrative paralysis, data exposure and loss of essential digital servicesSovereignty assurance frameworks, multi-cloud designs and regional capacity expansion
SpectrumNational allocation, international filing and interference environmentWireless connectivity, radar, satellite access and command linksHarmful interference, congestion, denial, regulatory exclusionLoss of communication, sensing, navigation and command effectivenessIntensified competition for orbital and terrestrial spectrum, with greater monitoring and enforcement
Data governanceLegal jurisdiction over collection, storage, processing and transferTraining data, industrial intelligence and administrative controlLocalisation mandates, transfer restrictions, compulsory disclosure and export controlsMarket fragmentation, compliance conflict and reduced cross-border interoperabilityDivergent sovereign data regimes with selective trusted-flow arrangements
Compute and semiconductorsChip supply chain, accelerator cluster, energy supply and software stackAI training, inference, cryptography and advanced simulationExport controls, licensing restrictions, vendor lock-in and energy constraintsLoss of technological development speed and military-industrial competitivenessPublicly supported compute capacity, domestic fabrication and strategic procurement
Identity and trustCertificate authority, credential issuer, identity provider and verification protocolAccess to government, finance, healthcare and communicationsCredential revocation, identity compromise, exclusion or surveillanceCivil and economic incapacitation without physical detentionIdentity infrastructure treated as critical national security architecture

Submarine Cables as Maritime Territory and Strategic Chokepoints

Submarine cables constitute the clearest demonstration that globalisation rests on highly localised physical infrastructure. Their apparent redundancy can conceal several forms of concentration: multiple systems may enter the same coastal corridor, use the same landing facility, cross the same shallow-water route, depend on the same maintenance depot or require repair ships operating under limited national permits. The strategic variable is therefore not the number of cables shown on a public map but the number of genuinely independent routes, landing points, operators, power supplies, terrestrial backhaul paths and repair options available after a coordinated disruption. The ITU reported in July 2026 that key resilience challenges include high exposure to physical risks, increasing repair times, geographical concentration and the dependence of many countries—particularly small island developing states, least-developed countries and underserved regions—on a small number of systems. International Advisory Body Approves Landmark Report to Strengthen Submarine Cable Resilience – International Telecommunication Union – July 2026. The organisation also records more than 200 faults annually, meaning that cable disruption is not exceptional; what changes its strategic character is the pattern, simultaneity, location, attribution context and interaction with political confrontation. Submarine Cable Resilience Summit Press Release – International Telecommunication Union – February 2026. Most faults historically arise from anchoring, fishing, abrasion, natural hazards or equipment failure, but an adversary does not need to destroy the entire network. It can exploit natural incident levels as camouflage, target shallow-water segments where access is easier, interfere with repair operations, manipulate ownership structures, collect intelligence near branching units, or combine limited physical damage with cyber operations against landing stations and network-management systems. The most effective attack may not sever a cable permanently; it may compel traffic to reroute through observable or politically controllable infrastructure, increase latency for financial and military services, raise insurance costs, exhaust repair capacity and create uncertainty regarding whether subsequent failures are accidental or deliberate. This is a quintessential grey-zone instrument because its economic effects can be substantial while evidence sufficient for public attribution remains difficult to obtain.

The European response illustrates how cable policy is evolving from telecommunications regulation into integrated security policy. The EU Action Plan on Cable Security, adopted on 21 February 2025, organises action around prevention, detection, response and repair, and deterrence, covering both data cables and submarine electricity interconnectors. The document explicitly notes that submarine communications cables carry 99% of intercontinental internet traffic and that power cables support market integration, energy security and offshore renewable generation. EU Action Plan on Cable Security – European Commission and High Representative – February 2025. In October 2025, an EU expert process completed a risk-assessment, mapping and stress-testing phase; in February 2026, the Commission published a Cable Security Toolbox, identified priority areas for Cable Projects of European Interest, and announced €347 million in investment connected to cable security and resilience. Submarine Cable Security Toolbox and Cable Projects of European Interest – European Commission – February 2026. The mapping methodology covers capacity, technical characteristics, ownership, incidents, landing sites, installation, maintenance and repair processes, demonstrating that the relevant intelligence picture is simultaneously technical, commercial, legal and military. EU Action Plan on Cable Security: Mapping and Risk Assessment Approach – European Commission – June 2025. NATO has moved in parallel, establishing a Critical Undersea Infrastructure Network and a Maritime Centre for the Security of Critical Undersea Infrastructure within Allied Maritime Command in the United Kingdom, while integrating industry, naval surveillance, intelligence-sharing, sensors, autonomous systems and AI-supported monitoring. NATO Holds First Meeting of Critical Undersea Infrastructure Network – North Atlantic Treaty Organization – May 2024. The strategic implication for 2027–2031 is that European maritime security will increasingly include the protection not only of sea lanes and ports but of data routes, offshore energy systems, fibre-optic repeaters, repair vessels and landing-site backhaul. The Mediterranean, Baltic, North Sea, Atlantic approaches and Arctic routes will become differentiated digital theatres, each requiring distinct surveillance, attribution and restoration models.

Table 2 — Submarine-Cable Threat and Resilience Matrix

Threat vectorObservable indicatorsOperational objectiveAttribution difficultyImmediate effectStrategic countermeasure
Accidental anchor or fishing damageVessel track intersects cable; no prior suspicious activity; single localised breakNoneLow to mediumTemporary rerouting and repair requirementMaritime zoning, route awareness, burial and rapid repair
Deliberate dragging or cuttingAnomalous vessel movement; disabled tracking; repeated passes; politically sensitive timingCoercion, disruption or signallingMedium to highCapacity reduction and public uncertaintyPersistent maritime domain awareness, legal evidence preservation and escort/interdiction options
Cyberattack on landing stationCredential anomalies, management-plane manipulation, unexplained route changesDisable or redirect traffic without seabed actionHighLoss of multiple systems sharing a facilitySegmentation, offline recovery, privileged-access control and national incident teams
Supply-chain compromiseModified firmware, undocumented management access, suspect maintenance componentPersistent access and intelligence collectionVery highCovert visibility or latent disruptionComponent provenance, code review, secure procurement and continuous integrity monitoring
Repair-capacity denialPort restrictions, permit delay, unavailable vessel, spare shortageExtend outage and amplify political pressureMediumLonger service degradationRegional repair hubs, pre-cleared permits, spare inventories and mutual assistance
Simultaneous multi-cable disruptionMultiple faults across independent routesOverwhelm redundancy and create regional isolationMedium to highSevere cross-sector disruptionGeographically dissimilar routes, satellite fallback, terrestrial alternatives and crisis prioritisation
Legal or ownership coercionForeign control over operator, financing or maintenance providerInfluence capacity allocation or accessLow legally, high strategicallySelective service restriction or intelligence exposureOwnership screening, governance rights, trusted-operator requirements and strategic reserves
“Shadow fleet” infrastructure interferenceOpaque ownership, flag changes, sanctions exposure, irregular operationsPlausibly deniable sabotage or reconnaissanceHighPersistent security burdenSanctions enforcement, insurance scrutiny, tracking integration and port-state controls

Orbital Systems and Spectrum as Vertical Sovereignty

Orbital infrastructure transforms sovereignty from a two-dimensional territorial concept into a vertical and electromagnetic one. States now depend on satellites for positioning, navigation and timing; telecommunications; missile warning; weather forecasting; agricultural monitoring; maritime surveillance; disaster response; financial synchronisation and military command. Yet the satellite itself represents only one component of the system. The true operational architecture includes launch services, orbital slots, spectrum filings, ground stations, network operations centres, cryptographic keys, user terminals, software updates, cloud processing, data distribution and collision-avoidance information. Control can be disrupted at any layer. A constellation may remain physically intact while its ground segment is compromised, its uplink jammed, its timing signal spoofed, its terminals denied software support or its spectrum environment rendered unusable. The ITU Radio Regulations 2024 govern the global use of radio-frequency spectrum and satellite orbits across terrestrial and space services, including fixed and mobile broadband, radionavigation, meteorological systems, Earth observation, broadcasting and safety communications. Radio Regulations, Edition of 2024 – International Telecommunication Union – 2024. This international framework is indispensable because spectrum and orbital resources are finite and interference disregards political borders. However, legal allocation does not guarantee operational access in crisis. The five-year contest will concern who can launch rapidly, replenish losses, monitor interference, authenticate signals, manoeuvre satellites, distribute data through resilient ground networks and integrate commercial capacity into national command systems. The strategic hierarchy will favour actors that combine sovereign constellations with access to allied and commercial systems rather than depending upon a single architecture.

The densification of low-Earth orbit and the proliferation of software-defined payloads will generate a new form of border contestation. Traditional geostationary systems established relatively stable, high-value orbital positions; proliferated low-Earth-orbit systems distribute capability across hundreds or thousands of satellites, reducing the value of attacking a single node but expanding the cyberattack surface and dependence on automated fleet management. Spectrum becomes the connective tissue of this system and therefore an instrument of coercion. Harmful interference can be temporary, geographically bounded and difficult to attribute conclusively, making it suitable for grey-zone operations. Jamming can deny communications or navigation; spoofing can feed false position or timing data; cyber compromise can manipulate terminal credentials, routing tables or command software. Commercial satellite providers will increasingly make operational choices with geopolitical consequences, including where service is enabled, which users receive priority, how terminals are authenticated and whether a government request overrides contractual access. NATO’s Washington Summit Declaration called for accelerated integration of space into Alliance planning, exercises and multi-domain operations, strengthening the NATO Space Operations Centre while also establishing the NATO Integrated Cyber Defence Centre and reinforcing protection of critical undersea infrastructure. Washington Summit Declaration – North Atlantic Treaty Organization – July 2024. This combination is strategically significant because orbital, cyber and maritime infrastructures are not separate domains: satellite communications provide backup when cables fail, cables carry data from ground stations to command centres, cloud systems process satellite data, and terrestrial timing networks depend on satellite-derived signals. An adversary seeking strategic paralysis will therefore target interdependencies rather than individual platforms.

Orbital-Spectrum Dependency Chain
Space Architecture & Terrestrial Integration Matrix
🚀 LAUNCH CAPACITY
Heavy Lift Vectors Orbital Insertion Cadence Spaceport Infrastructure
▼ Payload Deployment & Positioning
🛰️ SATELLITE BUS + PAYLOAD
Transponder Arrays Station-Keeping Bus Power Systems
🌐 ORBITAL POSITION / GEOMETRY
Constellation Mesh GEO Slot Allocation LEO Shell Density
▼ Telemetry, Tracking & Command (TT&C) Control
📡 COMMAND UPLINK
TT&C Link Encrypted Telemetry Beam Steering
📻 ALLOCATED SPECTRUM
ITU Spectrum Allocation Interference Management Anti-Jamming
▼ Terrestrial Reception & Processing
🗼 GROUND STATION NETWORK
Earth Terminals Feeder Links Digitized RF Stream
☁️ CLOUD DATA FUSION
Sensor Fusion AI Edge Decryption Data Normalization
▼ Strategic Distribution Rails
🏙️ NATIONAL NETWORKS
Terrestrial Fiber Core Secure Government Grid
🛡️ CRITICAL END USERS
Military Command Energy Grid PNT Financial Rails Emergency Response
⚠️ Critical Cross-Domain Failure Paths
1. SPECTRUM DENIAL

Spectrum denial ➔ Satellite service degradation ➔ Operational communications failure.

2. GROUND CYBER BREACH

Ground-segment cyber compromise ➔ Unauthorized command injection ➔ Telemetry data corruption.

3. CABLE OUTAGE

Physical cable outage ➔ Isolation of ground station ➔ Disconnection from processing centers.

4. CLOUD INFRASTRUCTURE FAILURE

Cloud processing failure ➔ Unprocessed raw data stream ➔ Loss of actionable intelligence.

5. TERMINAL AUTH BREACH

Terminal credential breach ➔ Selective exclusion of troops ➔ Adversary feed hijacking.

×

Cloud Infrastructure as Extraterritorial Administrative Power

Cloud infrastructure creates a border that is simultaneously technical, contractual and jurisdictional. Public institutions often conceptualise cloud migration as the relocation of servers, but strategically it is a transfer of control over identity, logging, encryption, software updates, resilience, incident response and administrative continuity. The most important cloud asset is not raw storage; it is the control plane through which accounts, permissions, keys, virtual networks and services are created or revoked. A state may require that data remain physically stored within its territory while still depending on foreign-developed software, remote support personnel, external intellectual property, non-domestic certificate authorities and parent companies exposed to foreign legal orders. Data localisation alone therefore does not equal sovereignty. Genuine cloud sovereignty requires a graded assessment of physical location, operational control, software-supply-chain transparency, ownership, personnel jurisdiction, encryption-key custody, audit rights, exit capability and independence from unilateral third-country interference. The European Commission’s Cloud and AI Development Act proposal, published in June 2026, directly frames overreliance on non-EU cloud providers as a risk to digital autonomy and resilience. It proposes at least tripling EU data-centre capacity over the following five to seven years, accelerating permitting, improving access to energy, land, water and financing, and establishing a single EU-wide framework for cloud and AI sovereignty. Cloud and AI Development Act – European Commission – June 2026. The proposed framework defines four sovereignty-assurance levels, ranging from processing and storage within the Union to progressively stronger requirements concerning independence from third countries, EU ownership and control, personnel conditions, and full transparency and control over the software supply chain. This architecture indicates that European policy is moving beyond a binary “European versus foreign” distinction toward risk-tiered procurement based on the sensitivity of the function being supported.

Cloud concentration also changes the economics of attack and defence. Large providers can invest in security, redundancy and specialised personnel at scales unavailable to most individual organisations, yet concentration creates systemic consequences when identity infrastructure, authentication tokens or shared software layers are compromised. CISA reported in July 2025 that sophisticated state-affiliated actors had exposed weaknesses involving token authentication, key management, logging, third-party dependencies and governance within cloud identity systems underpinning government and critical-infrastructure data. Securing Core Cloud Identity Infrastructure – Cybersecurity and Infrastructure Security Agency – July 2025. A compromise of a cloud identity layer can permit access across many services without defeating each service individually. This is analogous to capturing a border-control authority rather than crossing each frontier separately. The strategic exposure becomes greater as AI agents receive permission to operate across cloud environments, generate infrastructure code, manage identities and retrieve sensitive data. In the 2027–2031 period, sovereign cloud policy will therefore converge with AI governance: states will seek assurance that frontier models, public-sector inference workloads, sensitive datasets and autonomous agents operate in environments where logs are complete, keys remain controllable, model weights cannot be silently modified and emergency continuity does not depend upon a single provider. The likely end state is not complete technological autarky, which would be economically inefficient and technically unrealistic, but selective sovereign capacity for critical workloads combined with interoperable commercial services for ordinary functions.

Table 3 — Cloud Sovereignty Assurance Model

Assurance dimensionLow assuranceIntermediate assuranceHigh assuranceStrategic interpretation
Data locationData may be processed globallyRegional storage commitmentProcessing and storage restricted to authorised national or allied locationsPhysical location reduces some exposure but does not determine legal or operational control
Ownership and controlForeign parent exercises full controlLocal subsidiary with contractual safeguardsDomestic or trusted-jurisdiction ownership and governanceOwnership affects susceptibility to external orders, sanctions and service withdrawal
Encryption keysProvider-managedCustomer-managed with provider toolingCustomer-held or sovereign key-management infrastructureKey custody determines whether localisation meaningfully protects confidentiality
Identity planeShared global identity serviceRegional tenant controlsIsolated sovereign identity and privileged-access architectureIdentity compromise can bypass application-level security
Software supply chainOpaque proprietary stackAttested components and audit accessFull component transparency, controlled updates and reproducible assuranceSoftware provenance determines latent foreign access and dependency
Operational personnelGlobal support accessRestricted support poolsCleared personnel under trusted jurisdictionPersonnel access is an often-overlooked sovereignty boundary
Exit capabilityHigh lock-in and proprietary formatsDocumented migration toolsTested portability, escrow, open standards and alternative providersSovereignty requires the credible ability to leave
Incident responseProvider-ledJoint response proceduresSovereign command authority, forensic access and offline continuityCrisis control cannot depend on discretionary commercial cooperation
AI workload integrityModel and data managed by providerCustomer-controlled data with limited model assuranceVerified model provenance, isolated inference, controlled agents and complete loggingAI increases both compute dependency and autonomous action risk
Legal exposureMultiple foreign jurisdictionsContractual mitigationExplicit immunity, trusted jurisdiction or sovereign operationLegal sovereignty may diverge from data-centre geography

Data Localisation and the Divergence of Sovereignty Doctrines

Data localisation is becoming a mechanism through which states convert information flows into jurisdictional territory, but the concept is applied through fundamentally different political doctrines. The European Union seeks strategic autonomy while preserving cross-border flows among trusted partners, combining privacy, security, competition policy, data access and cloud portability. Its 2026 data-sovereignty policy work explicitly identifies unjustified localisation, discriminatory rules and data leakage to third countries as threats while maintaining that sovereignty should remain compatible with secure, trusted international exchange. Targeted Consultation on Safeguarding the EU’s Data Sovereignty – European Commission – July 2026. The EU model is therefore not strict territorial closure; it is conditional openness supported by legal safeguards, procurement criteria and the capacity to restrict high-risk dependencies. China’s model is more directly integrated with national security and state jurisdiction. Article 1 of the Data Security Law of the People’s Republic of China defines its purpose as regulating data processing, ensuring data security, protecting rights and safeguarding national sovereignty, security and development interests. Article 2 provides for potential liability where processing outside China harms Chinese national security, public interests or the lawful rights of Chinese individuals or organisations; Articles 21, 24, 25, 31 and 36 establish classified data protection, national-security review, export control, outbound-data governance and restrictions on providing domestically stored data to foreign judicial or law-enforcement bodies without approval. Data Security Law of the People’s Republic of China – National People’s Congress – June 2021. China’s official cyberspace strategy extends sovereignty to the right of each state to select its development path, regulatory model and internet policies, rejecting cyber hegemony and external interference. International Strategy of Cooperation on Cyberspace – Ministry of Foreign Affairs of the People’s Republic of China – March 2017.

The Russian Federation similarly conceptualises the information space as a sovereign strategic domain, but places stronger emphasis on technological dependence, foreign influence and the international legal regulation of state behaviour. Presidential Decree No. 213 of 12 April 2021 defines Russian policy on international information security as a coordinated system intended to prevent threats, support international legal mechanisms and protect national interests. It identifies as threats the use of information and communications technologies to undermine sovereignty or territorial integrity, attacks against critical information infrastructure and the use of technological dominance to monopolise ICT markets, restrict access to advanced technologies and deepen dependency. Foundations of State Policy of the Russian Federation in the Field of International Information Security – President of the Russian Federation – April 2021. Russia’s 2021 National Security Strategy states that foreign information technologies and telecommunications equipment increase the vulnerability of Russian information resources and critical infrastructure to external influence, while defining the strengthening of Russian sovereignty in the information space as a national objective. National Security Strategy of the Russian Federation – President of the Russian Federation – July 2021. These positions reveal that “data sovereignty” is not a common technical standard but a contested political concept. The EU emphasises risk-tiered autonomy and trusted openness; China emphasises jurisdiction, national-security review and state-directed control; Russia emphasises technological sovereignty, resistance to foreign dominance and legally binding interstate regulation. Through 2031, multinational companies, cloud providers and infrastructure operators will face overlapping and potentially contradictory obligations concerning storage, access, encryption, disclosure, software updates and cross-border transfers. The resulting friction will not merely increase compliance costs; it will reshape network architecture, investment patterns and alliance structures.

Table 4 — Comparative Sovereignty Doctrines

DimensionEuropean UnionChinaRussian FederationStrategic consequence
Core conceptStrategic autonomy with trusted cross-border opennessCyber and data sovereignty integrated with national securityInformation sovereignty and resistance to technological dependenceNo common definition of legitimate sovereign control
Data locationRisk-based localisation for sensitive functionsStrong controls for important and core dataLocal control and reduced reliance on foreign systemsRegionalisation of data architecture
Extraterritorial reachRegulatory application based on market, rights and data-processing nexusLiability possible for foreign processing harmful to Chinese interestsEmphasis on protecting Russian interests in global information spaceConflict-of-law exposure for multinational providers
Foreign accessConstrained by privacy, security and procurement rulesForeign judicial access requires authorised channelsForeign technological access regarded as potential vulnerabilityGreater use of sovereign key custody and isolated environments
International governanceRules-based interoperability among trusted partnersEqual sovereign participation and opposition to cyber hegemonyLegally binding interstate mechanisms under UN-centred governanceDivergent cyber-norm negotiations
Market structureCompetition plus sovereignty assuranceState-directed classification and security reviewImport substitution and technological sovereigntyReduced global uniformity of cloud and software markets
AI relationshipSovereign compute, trusted data, risk-based AI regulationState security, standards, development and controlled cross-border dataAI sovereignty tied to domestic law and strategic independenceAI stacks increasingly aligned with geopolitical blocs

Computational Sovereignty: Chips, Energy, Models and the Right to Compute

Computational sovereignty is becoming the decisive layer linking all other virtual borders because cables, satellites and cloud systems possess limited strategic value if a state cannot obtain the processors, energy, software and datasets required to execute advanced AI workloads. Compute is not a single commodity. It consists of semiconductor design tools, intellectual property, fabrication capacity, advanced packaging, high-bandwidth memory, networking equipment, data-centre power, cooling, cloud orchestration, model frameworks, trained personnel and access to frontier models. A country may host large data centres while lacking control over the accelerators, firmware, operating stack or model weights running inside them. It may possess domestic chips while depending on foreign lithography, materials, design software or high-speed interconnects. Sovereignty must therefore be measured across the full stack and by the capacity to substitute critical components under embargo, conflict or commercial withdrawal. The European Commission’s June 2026 technology-sovereignty package defines sovereignty as Europe’s ability to act independently by developing and controlling key technologies, data and infrastructures while reducing reliance on non-EU providers. The package combines the proposed Chips Act 2.0, the Cloud and AI Development Act, an open-source strategy and an energy digitalisation roadmap. Strengthening Europe’s Tech Sovereignty – European Commission – June 2026. The integration of chips, cloud, open source and energy is analytically correct because AI capacity is constrained not only by chip availability but by electricity connections, water, land, network bandwidth and permitting. Europe’s proposed tripling of data-centre capacity over five to seven years would consequently require corresponding reinforcement of grids, low-carbon generation, cooling systems, fibre routes and cybersecurity.

The five-year geopolitical contest will move from simple export restriction toward compute governance. Governments will increasingly classify accelerator clusters by capability, monitor transfers of advanced chips, attach conditions to cloud access, screen foreign investment in data centres, require reporting of large training runs, and reserve strategic capacity for national-security or public-service workloads. Liquidity flows will follow power availability, tax policy, sovereign guarantees, land access and political trust. Regions offering abundant energy but weak security may attract physical infrastructure while remaining excluded from sensitive workloads; jurisdictions offering legal stability and allied status may capture higher-value processing. Meanwhile, the rise of smaller, more efficient models and specialised accelerators could partially decentralise inference even while frontier training remains concentrated. The key distinction will be between training sovereignty, requiring enormous capital and compute density, and inference sovereignty, which can be distributed closer to users, industrial facilities and military units. States unable to train frontier systems may still preserve operational autonomy by controlling inference infrastructure, model adaptation, classified data and mission-specific agents. However, dependence on foreign foundational models can create hidden policy leverage if providers can change safety rules, withdraw access, modify model behaviour or observe usage patterns. By 2031, sovereign capability will be judged not by whether a state can reproduce every technological layer domestically, but by whether it has mapped its dependencies, secured trusted alternatives and retained an independent decision pathway for essential computation.

Computational Sovereignty Stack
Multilayer Sovereign Technology Architecture
⚖️ MISSION AUTHORITY
LEVEL 7
Model Deployment Authorization Data Governance & Rights Executive Permission Boundaries
▲ Strategic Mandate & Governance Directives
🤖 MODELS AND AGENTS
LEVEL 6
Frontier Models Specialised Models Orchestration Safety Controls Auditability
▲ Software Execution & API Bindings
☁️ CLOUD & SOFTWARE CONTROL PLANE
LEVEL 5
Identity Frameworks Containers Schedulers Operating Systems Libraries Update Channels
▲ Hardware Abstraction & Driver Interfaces
⚡ COMPUTE INFRASTRUCTURE
LEVEL 4
Accelerators CPUs High-Bandwidth Memory Networking Fabric Storage Cryptographic Modules
▲ Power, Thermal & Physical Staging
🏭 DATA-CENTRE RESOURCES
LEVEL 3
Gigawatt Electricity Cooling Infrastructure Water Access Land & Facilities Physical Security Skilled Personnel
▲ Data Ingress / Egress & External Backbones
🌐 CONNECTIVITY
LEVEL 2
Submarine Cables Terrestrial Fibre Internet Exchanges Satellite Backup Wireless Spectrum
▲ Fabrication, Materials & Component Supply
🔬 INDUSTRIAL SUPPLY CHAIN
LEVEL 1
Chip Design / EDA Foundry Fabrication EUV Lithography Advanced Packaging Critical Materials Firmware & Logistics
⚠️ SOVEREIGNTY FAILURE PRINCIPLE: LOSS OF CONTROL AT ANY LOWER LEVEL PREVENTS INDEPENDENT ACTION ABOVE IT ⚠️
🗺️ 7. THE INTEGRATED GEOGRAPHY: CABLES, SPACE, CLOUD AND COMPUTE
×

The Integrated Geography: Cables, Space, Cloud and Compute as a Single Battlespace

The principal analytical error in infrastructure security is to examine each network independently. Submarine cables, orbital systems, cloud platforms, data governance and compute form one coupled system in which redundancy at one layer may depend on the continued operation of another. Satellite services can provide emergency communications after a cable failure, but the satellite provider’s ground stations may themselves rely on terrestrial fibre and cloud control systems. A cloud region may be replicated across several countries, yet both regions may depend on the same identity provider, software update channel or transoceanic route. A sovereign data centre may retain physical control over servers while relying on imported accelerators that cannot be replaced under export restrictions. A national navigation system may provide autonomous timing, yet distribution to financial, telecommunications and power-grid users may depend on vulnerable terrestrial networks. This coupling produces common-mode failure, in which apparently diverse services fail because they share an unseen dependency. It also creates opportunities for adversaries to generate disproportionate effects through carefully sequenced operations. A cyberattack against a cloud identity provider, combined with a cable disruption and localised satellite interference, could create simultaneous uncertainty concerning communications, data integrity and command authority without requiring large-scale physical destruction. Such an operation would exploit institutional fragmentation: telecommunications regulators, naval forces, cyber agencies, cloud providers, energy authorities and intelligence services may possess separate parts of the picture but lack a shared operational model.

The response must therefore shift from asset protection to mission assurance. Instead of asking whether a specific cable, satellite or data centre is secure, governments must identify which combinations of infrastructure are required to preserve healthcare, payments, military command, emergency communications, electricity dispatch, transport and public administration. Each mission should be tested against simultaneous loss of connectivity, cloud identity, timing signals, specialised personnel and foreign vendor support. The EU cable-security framework’s move toward mapping, stress testing and risk-based projects represents an early form of this approach. NATO’s simultaneous integration of space, cyber and critical-undersea-infrastructure security reflects the military equivalent. Washington Summit Declaration – North Atlantic Treaty Organization – July 2024. The 2027–2031 period will reward states that establish cross-domain operational pictures combining vessel movements, cable telemetry, spectrum anomalies, satellite status, cloud authentication events, internet routing changes, energy conditions and financial stress indicators. AI will be necessary to process this volume, but machine-generated alerts must remain traceable and resistant to deception. Otherwise, adversaries may manipulate the monitoring layer itself, creating false correlations, inducing costly defensive actions or concealing genuine preparations within a high volume of anomalies.

Table 5 — Cross-Domain Failure Scenarios

ScenarioInitial triggerSecond-order propagationStrategic effectKey early-warning indicatorsRequired resilience measure
Cable–cloud isolationMultiple cable failures near a regional hubCloud regions lose external control-plane connectivityGovernment and commercial services become regionally fragmentedRoute withdrawals, latency spikes, landing-station alarmsIn-country control functions, terrestrial alternatives and preconfigured degraded modes
Satellite–timing crisisGNSS jamming or spoofingTelecom, finance, transport and grid timing errorsCascading loss of synchronisation and trustTiming divergence, receiver anomalies, geographic clusteringMulti-source timing, terrestrial reference clocks and anomaly authentication
Cloud identity compromiseTheft or forging of authentication tokensAccess across government and critical-infrastructure tenantsLarge-scale espionage or administrative takeoverImpossible logins, token reuse, abnormal privileged operationsIsolated identity tiers, hardware-backed keys and rapid credential invalidation
Compute embargo shockExport restriction or vendor withdrawalMaintenance and expansion of AI clusters slow sharplyReduced military-industrial and economic innovationLicensing changes, delivery delays, service restrictionsStrategic inventory, alternative suppliers and model-efficiency investment
Coordinated repair denialCable damage followed by vessel, permit or spare constraintsOutage persists beyond redundancy assumptionsPolitical pressure and market instabilityRepair-vessel unavailability, port barriers, insurance changesRegional repair hubs, mutual-aid agreements and sovereign spares
Data-jurisdiction conflictCompeting foreign disclosure or localisation ordersProvider cannot comply with all jurisdictionsService withdrawal or data fragmentationRegulatory notices, litigation, provider policy changesSovereign encryption, contractual exit rights and trusted legal frameworks
AI-generated infrastructure deceptionSynthetic telemetry or manipulated operational dataOperators misallocate resources or shut down healthy systemsSelf-induced disruption and loss of confidenceInconsistent sensor sources, improbable correlationsCryptographic telemetry integrity and independent physical verification

Shadow Dimensions: Private Ownership, Repair Fleets, Insurance, Liquidity and Proxy Power

The shadow geography of virtual borders lies in the gap between formal state responsibility and private operational ownership. Much of the infrastructure carrying sovereign functions is financed, built and managed by telecommunications companies, cloud providers, satellite operators, shipping firms, specialist repair contractors, energy companies and private-equity investors. Governments may define security obligations yet lack direct control over technical staffing, spare inventories, software source code, maintenance schedules or commercial priorities. This produces a hybrid command problem during crises. A cable operator must balance contractual service, shareholder obligations and government security requests; a cloud provider must interpret competing legal orders; a satellite company may be asked to prioritise military traffic; an insurer may withdraw coverage from a high-risk maritime corridor; a repair vessel may be registered, financed, crewed and supplied across several jurisdictions. These factors determine actual resilience more than declaratory strategy. ITU’s international cable-resilience work therefore emphasises licensing, deployment, repair, government-industry collaboration and the vulnerabilities created by geographical concentration. Terms of Reference, International Advisory Body for Submarine Cable Resilience – International Telecommunication Union – November 2024. NATO’s Critical Undersea Infrastructure Network similarly brings together governments, military structures and industry because no single actor possesses complete authority or information. NATO Allies Join Forces to Enhance the Security of Critical Undersea Infrastructure – North Atlantic Treaty Organization – December 2024.

Liquidity flows are another underexamined instrument of infrastructure power. Building cable systems, launch capacity, sovereign clouds and accelerator clusters requires long-duration capital, predictable regulation, energy contracts and political-risk tolerance. States can redirect infrastructure geography through subsidies, procurement guarantees, export-credit support, tax treatment, security screening and public-private investment vehicles. Conversely, sanctions, insurance exclusions, financing restrictions and export controls can immobilise infrastructure without physically attacking it. The “mercenary” analogue in this domain is not limited to offensive hacker groups. It includes private intelligence providers, access brokers, commercial satellite services, maritime contractors, zero-day vendors and infrastructure intermediaries whose capabilities can be hired, pressured or deniably aligned with state objectives. The five-year risk is the emergence of proxy ecosystems that provide reconnaissance, access, disruption and influence while preserving formal distance from governments. A state may not need a national fleet capable of monitoring every cable if it can purchase vessel data, commercial imagery, cyber access or maintenance intelligence. Similarly, a sanctioned actor may use opaque ownership, reflagging, intermediary firms or third-country data centres to preserve access. Effective analysis must therefore track corporate beneficial ownership, debt exposure, insurance, vessel registration, cloud tenancy, satellite-service agreements and maintenance contracts alongside conventional military indicators.

Five-Year Outlook, 2027–2031

The most probable evolution is neither complete fragmentation nor unrestricted global connectivity, but a layered system of selective interdependence. In 2027, governments will accelerate dependency mapping, cable-risk assessments, cloud-sovereignty procurement and spectrum-monitoring capabilities. In 2028, regulatory requirements will begin translating into infrastructure investment, particularly regional cable routes, repair hubs, national cloud capacity, sovereign identity systems and protected compute clusters. By 2029, the strategic dividing line will move from data location to operational control: governments will demand evidence concerning key custody, software updates, personnel jurisdiction, AI-model provenance and emergency continuity. By 2030, allied infrastructure pooling will expand because few states can independently sustain full-spectrum cable, orbital, semiconductor and cloud capacity. Trusted networks will emerge through reciprocal access to repair ships, satellite services, threat intelligence, compute resources and secure data spaces. By 2031, virtual borders will be less visible to citizens but more consequential: access to finance, healthcare, public services, information and mobility will depend on interoperable identity, network and AI systems whose governance may be fragmented across geopolitical blocs. The central policy challenge will be to build sovereign resilience without converting digital autonomy into permanent isolation, surveillance or technological stagnation.

A Bayesian competing-hypothesis assessment assigns five 2031 scenarios. H₁ — Managed Selective Interdependence assumes major powers retain global connectivity while building protected national and allied capabilities. H₂ — Bloc Fragmentation assumes deep division of cloud, data, spectrum, semiconductor and identity systems. H₃ — Corporate Infrastructure Primacy assumes major platform and network operators retain greater operational power than most governments. H₄ — Persistent Grey-Zone Infrastructure Conflict assumes recurrent, limited disruptions and coercive incidents remain below conventional-war thresholds. H₅ — Systemic Multi-Domain Crisis assumes a major event simultaneously affects cable, satellite, cloud and critical-service continuity. Starting priors are updated against current investment, regulatory, alliance and sovereignty trends. The resulting central estimate assigns 31% to H₁, 21% to H₂, 13% to H₃, 27% to H₄ and 8% to H₅ by 2031. These are analytical model outputs rather than official probabilities. The two most plausible outcomes—managed interdependence and persistent grey-zone conflict—are not mutually exclusive: states may improve resilience while adversaries continue testing thresholds. The principal strategic warning is that rising resilience could shift hostile activity toward the weakest jurisdictions, private subcontractors, repair logistics and legal dependencies rather than toward the most visible core assets.

Table 6 — Five-Year Strategic Timeline

YearDominant infrastructure developmentGeopolitical contestPrimary technical riskExpected policy responseLeading indicator
2027Comprehensive dependency mapping and cloud-risk classificationContest over ownership, vendor trust and cable routesIncomplete visibility of shared dependenciesNational registers, stress tests and procurement controlsPublication of sovereign-cloud and infrastructure assurance criteria
2028Expansion of regional cable, satellite and compute capacitySubsidy competition and allied infrastructure agreementsConstruction bottlenecks, energy constraints and skills shortagesPublic financing, accelerated permitting and repair-hub developmentCapital expenditure and long-term power contracts
2029Integration of AI agents into infrastructure operationsControl of model providers and autonomous systemsMachine-speed misconfiguration or compromiseAgent permission controls, model provenance and human override standardsMandatory logging and certification for autonomous infrastructure agents
2030Trusted-bloc interoperability and shared resilience assetsCompetition between open alliances and sovereign technology blocsCross-bloc incompatibility and legal conflictMutual-recognition frameworks and strategic reservesBilateral or alliance agreements for cloud, spectrum and repair support
2031Mature virtual-border governanceNormalised infrastructure coercion below war thresholdCoordinated multi-domain attacks and common-mode failurePermanent cross-domain command structures and deterrence policyJoint cyber-space-maritime operational centres

Table 7 — Bayesian Competing-Hypothesis Assessment for 2031

HypothesisDescriptionPrior probabilityEvidence increasing probabilityEvidence decreasing probabilityUpdated probability
H₁Managed selective interdependence25%EU sovereignty frameworks, NATO integration, ITU coordination, investment in redundancySlow permitting, fragmented authority, private-sector concentration31%
H₂Deep digital-bloc fragmentation20%Divergent EU, Chinese and Russian sovereignty doctrines; export controls; localisationEconomic cost of decoupling and continuing need for global connectivity21%
H₃Corporate infrastructure primacy18%Cloud, satellite and cable concentration; private technical expertiseExpanding public regulation, procurement leverage and strategic investment13%
H₄Persistent grey-zone infrastructure conflict27%Attribution difficulty, deniable maritime and cyber methods, threshold ambiguityImproved sensing, sanctions and coordinated deterrence27%
H₅Systemic multi-domain crisis10%Coupled dependencies, AI acceleration, repair bottlenecksRedundancy, diversification and crisis planning8%

Table 8 — Monte Carlo Stress-Test Outputs, 2027–2031

Modelled eventMedian probability10th–90th percentile rangePrincipal sensitivity
At least one serious regional cable disruption68%52–81%Route concentration and repair latency
Multi-day loss of a major cloud or identity service54%38–69%Provider concentration and credential-security maturity
Sustained satellite-navigation interference affecting civilian systems61%43–76%Regional conflict intensity and receiver resilience
Simultaneous disruption across two infrastructure domains36%21–53%Adversary coordination and cross-domain dependency
Simultaneous disruption across three or more domains14%6–28%Common-mode dependencies and crisis escalation
Significant compute-access restriction caused by geopolitical controls47%29–65%Export-control expansion and supplier concentration
Formal trusted-bloc agreement on shared digital infrastructure72%57–84%Alliance cohesion and public financing
Severe service failure caused by autonomous AI misconfiguration19%8–36%Agent authority, validation and human-override design

The Monte Carlo model uses 50,000 synthetic pathways and varies cable-route concentration, repair time, cloud concentration, identity compromise probability, satellite-interference intensity, compute-export controls, alliance coordination and recovery capacity. The probabilities are not empirical forecasts and should be interpreted as disciplined stress estimates. The highest sensitivity appears in three variables: repair latency, cloud identity concentration and cross-domain common dependencies. Improving any one of these materially reduces regional disruption but does not eliminate systemic risk. The strongest reduction arises when physical route diversity is combined with independently operable cloud identity, alternative timing sources and pre-negotiated allied support. This finding supports a policy hierarchy: first map hidden common dependencies; second create technically independent fallback modes; third secure repair and replacement logistics; fourth establish legal authority for cross-domain crisis management; and fifth integrate deterrence with forensic attribution. Simply adding more cables, satellites or data centres may create the appearance of redundancy without resilience if those assets share the same terrestrial backhaul, energy source, software control plane, personnel or foreign supplier.

Figure 1: Five-Year Virtual-Border Risk Projection

Figure 1: Five-Year Virtual-Border Risk Projection
Scenario indices, 2027–2031. Values are analytical model outputs, not official forecasts.

Pillar II — AI-Accelerated Cyber Conflict: Autonomous Operations, Machine-Speed Escalation and Physical-System Risk, 2027–2031

The Transition from AI-Assisted Operations to Agentic Cyber Campaigns

Cyber conflict is moving from a model in which artificial intelligence assists individual human operators toward one in which interconnected AI agents execute substantial portions of the operational cycle: target discovery, infrastructure mapping, vulnerability analysis, credential harvesting, exploit adaptation, persistence management, defensive evasion, data extraction and influence amplification. The critical distinction is not whether an operation uses generative AI, but whether the system can observe an environment, formulate intermediate objectives, invoke tools, evaluate results, retain operational memory and modify its behaviour without requiring human approval at every step. Current large language models remain unreliable, vulnerable to manipulation and incapable of replacing expert operators across all stages of a sophisticated intrusion. Nevertheless, their strategic effect already derives from reducing the labour, language, coding and analytical barriers that previously limited the number and tempo of capable attackers. The European Union Agency for Cybersecurity assessed 4,875 incidents occurring between 1 July 2024 and 30 June 2025 and identified AI both as an operational optimisation mechanism for hostile activity and as a growing attack surface. ENISA reported that large language models were being used to improve phishing and automate social engineering, while attacks against AI supply chains were increasing and purpose-built malicious AI systems were emerging. ENISA Threat Landscape 2025 – European Union Agency for Cybersecurity – October 2025. The operational trajectory is therefore evolutionary rather than magical: AI initially increases the quantity, linguistic quality and targeting precision of familiar attacks; subsequently it connects reconnaissance, exploitation and persistence into semi-autonomous workflows; eventually, selected campaigns may operate continuously across thousands of targets, assigning human specialists only to high-value decisions, unexpected obstacles and politically sensitive effects. This structure resembles industrial automation more than autonomous strategic genius. Humans define objectives, risk limits and target classes; AI performs repetitive discovery and adaptation at machine tempo; specialist operators intervene where deception, novel exploitation or escalation management remains necessary. By 2031, the decisive advantage will belong less to the actor possessing the most impressive isolated model than to the actor capable of integrating models with reliable telemetry, exploit repositories, malware frameworks, identity systems, vulnerability intelligence, operational-security controls and large-scale compute. AI will act as an orchestration layer over existing offensive capabilities, converting fragmented tools into persistent adaptive systems.

The most immediate transformation is a collapse in the marginal cost of reconnaissance. Traditional hostile reconnaissance required analysts to enumerate internet-facing systems, identify technologies, correlate leaked credentials, study organisational structures, translate technical material, examine procurement records and construct plausible social-engineering narratives. An agentic system can parallelise many of these activities, continuously update its target graph and rank opportunities according to exploitability, operational value and expected detection risk. It can compare exposed services with vulnerability catalogues, inspect source-code repositories, analyse firmware, identify reused credentials, infer employee relationships and generate tailored pretexts in multiple languages. This does not guarantee successful compromise, because scanning data may be incomplete, exploitability may depend on local configuration and generated code may fail. It does, however, increase the number of hypotheses that an attacker can test and decreases the time between vulnerability disclosure and attempted exploitation. The 2025 multinational advisory led by CISA documented state-sponsored compromise of backbone, provider-edge and customer-edge routers across telecommunications, government, transportation, lodging and military-related networks, with actors modifying routers to preserve long-term access and exploiting trusted relationships to pivot across interconnected environments. Countering Chinese State-Sponsored Actors Compromise of Networks Worldwide to Feed Global Espionage System – Cybersecurity and Infrastructure Security Agency – August/September 2025. AI-enhanced reconnaissance makes this type of infrastructure-scale operation more efficient because network devices expose enormous configuration diversity, undocumented dependencies and large quantities of telemetry that machines can compare faster than human teams. The five-year risk is a shift from episodic target selection to continuous attack-surface arbitrage, in which autonomous systems scan for temporary discrepancies between newly disclosed weaknesses, incomplete patches, misconfigured identities, exposed operational technology and defensive staffing cycles. Vulnerability becomes not a static property but a short-lived market opportunity. Attackers able to detect and exploit that opportunity first gain access; defenders able to identify and close it first preserve control.

Table 1 — Evolution of AI-Enabled Offensive Cyber Operations

Operational phasePredominantly human modelAI-assisted model, 2024–2026Agentic model, projected 2027–2031Principal limiting factorStrategic consequence
Target discoveryManual research and analyst-curated target listsAutomated enrichment of domains, personnel and exposed servicesPersistent autonomous construction of multi-layer target graphsData accuracy and operational-security constraintsMore organisations become economically viable targets
Vulnerability analysisSpecialist review of advisories, code and configurationsAI summarisation, code explanation and exploit hypothesis generationContinuous vulnerability-to-asset matching and automated validationHallucinated exploitability and inaccessible local contextCompression of disclosure-to-exploitation intervals
Social engineeringHuman-written messages and manually selected recipientsMultilingual personalised text and synthetic mediaAdaptive conversational agents maintaining long-term interactionAuthentication controls and behavioural detectionGreater scale, realism and persistence of deception
Initial accessManual phishing, credential attacks or exploit deploymentAI-generated scripts and campaign variationAutomated selection among credentials, exploits and supply-chain pathsEndpoint controls, MFA and exploit reliabilityHigher campaign throughput and rapid tactical substitution
Privilege escalationOperator-driven enumeration and exploitationAI recommendations from local telemetryAutonomous privilege-path search across identity graphsRestricted visibility and defensive deceptionIdentity systems become central battle terrain
Lateral movementManual command executionAI-assisted pathway analysisPolicy-driven movement toward mission objectivesSegmentation and anomalous-behaviour detectionFaster transition from foothold to strategic access
PersistenceManually selected backdoors and accountsAI-supported stealth recommendationsContinuous adaptation of persistence to defensive changesOperational complexity and forensic tracesLonger dwell time with smaller human teams
Command and controlFixed or manually altered infrastructureAI-generated traffic variationDynamic infrastructure, protocol and timing selectionNetwork observability and cryptographic controlsGreater difficulty distinguishing malicious from legitimate traffic
Data exploitationManual collection and analyst reviewAutomated classification, translation and summarisationAutonomous prioritisation and fusion of stolen datasetsData quality, encryption and exfiltration constraintsEspionage value realised more rapidly
Destructive effectsHuman-authorised commands and prebuilt malwareAI-assisted targeting and payload modificationPotential conditional execution by autonomous systemsPolitical control, physical-process knowledge and safeguardsEscalation risk rises if authority is delegated too broadly

Autonomous Vulnerability Discovery and the Industrialisation of Exploitation

AI changes vulnerability discovery by expanding the quantity of code, binaries, configurations and behavioural traces that can be examined, but the strategic effect depends on the integration of several methods rather than on language-model output alone. Static analysis can identify suspicious control flows, unsafe memory operations and authentication errors; dynamic analysis can observe software during execution; fuzzing can generate malformed inputs and monitor crashes; symbolic execution can explore program paths; machine learning can prioritise functions and inputs most likely to produce security-relevant failures. Agentic systems can combine these techniques by reading documentation, generating test harnesses, selecting mutation strategies, interpreting crashes, deduplicating failures and proposing exploit hypotheses. The same architecture benefits defenders conducting secure development and red-team testing, but offensive actors can apply it against leaked source code, open-source dependencies, firmware images and internet-facing products. The strategic acceleration occurs when AI links vulnerability discovery to an asset graph. A flaw in an obscure library has little operational value until the attacker determines which organisations use the affected version, which systems expose reachable interfaces and which targets provide strategically useful access. Machine reasoning can perform that matching continuously, creating automated pipelines from code weakness to prioritised target set. The National Institute of Standards and Technology formalised the security problem in its March 2025 adversarial-machine-learning taxonomy, covering attacks across AI-system lifecycle stages and distinguishing attacker goals, knowledge, capabilities and techniques including evasion, poisoning, privacy compromise and abuse of generative systems. Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations – National Institute of Standards and Technology – March 2025. NIST’s later Cyber AI Profile organised the intersection around three connected objectives: secure AI systems, use AI to defend against cyberattacks and thwart AI-enabled attacks. Cybersecurity Framework Profile for Artificial Intelligence – National Institute of Standards and Technology – December 2025. This tripartite structure matters because a defender deploying AI creates a new system that itself requires protection. The model, retrieval corpus, prompts, tool permissions, training pipeline and output-handling process can each become an attack path.

The offensive–defensive asymmetry will not move permanently in one direction. AI gives attackers scale, speed and variation, but defenders often possess superior environmental telemetry, legitimate administrative authority and the ability to impose architecture-wide controls. A defender can train detection on authentication patterns, endpoint behaviour, network flows, process lineage, industrial telemetry and historical incidents that an external attacker cannot fully observe. Yet this advantage disappears when telemetry is incomplete, identity systems are fragmented or outsourced, logs are not retained, and operational teams cannot safely automate containment. Attackers need one viable pathway; defenders must discriminate malicious activity from millions of legitimate actions without disrupting essential services. AI reduces but does not eliminate this imbalance. By 2029–2031, high-end operations are likely to feature adversarial automation loops: offensive systems alter payloads, infrastructure and timing after observing detection; defensive systems update scoring, deception and containment after observing attacker adaptation. The resulting interaction resembles an automated market with hidden strategies, incomplete information and rapidly changing prices, except that the traded commodity is access to systems whose failure may produce physical harm. The operational advantage will shift toward whichever side possesses more trustworthy observations and can safely take action with lower latency. This makes sensor integrity, timestamp integrity and identity assurance decisive. A highly capable defensive model trained on corrupted telemetry may accelerate the wrong response. A less sophisticated model grounded in authenticated, diverse and independently verified data may outperform it. Defensive architecture must therefore reject the assumption that more automation automatically produces more security. Every autonomous action requires an explicit authority boundary, confidence threshold, rollback mechanism, evidence trail and human escalation rule.

Table 2 — AI-System Attack Surface and Security Consequences

AI-system layerPrincipal attack methodAttacker objectiveCyber consequencePotential physical consequencePriority control
Training dataPoisoning, label manipulation, malicious data insertionCreate hidden bias, backdoor or unsafe behaviourCompromised model decisionsIncorrect industrial or safety recommendationsData lineage, source authentication and anomaly review
Model weightsTheft, substitution, unauthorised fine-tuningExfiltrate capability or alter behaviourLoss of intellectual property and integrityModified control or diagnostic outcomesCryptographic signing, isolated storage and controlled deployment
Retrieval corpusDocument injection, false procedures, hidden instructionsManipulate model contextIncorrect administrative or operational actionUnsafe maintenance or emergency responseTrusted-source allowlists and content sanitisation
Prompt interfacePrompt injection, indirect injection, role manipulationOverride intended constraintsData leakage or tool misuseUnauthorised operational commandsContext separation, policy enforcement and least privilege
Agent tool layerExcessive permissions, confused-deputy attacksExecute actions through legitimate toolsAccount changes, code execution and data exfiltrationShutdown, valve, pump or breaker manipulationTransaction limits, approvals and action sandboxing
Model APICredential theft, denial of service, endpoint substitutionCapture data or deny capabilityService interruption and intelligence collectionLoss of AI-supported monitoring or controlStrong identity, redundancy and endpoint verification
Inference environmentMemory attacks, side channels, container escapeAccess prompts, keys or adjacent workloadsCross-tenant compromiseMulti-system operational exposureIsolation, hardware security and runtime monitoring
Evaluation processBenchmark gaming, concealed failure modesObtain approval for unsafe systemDeployment of untrustworthy automationLatent failure under rare physical conditionsIndependent testing and adversarial scenario evaluation
Update pipelineMalicious package or compromised model releaseEstablish trusted supply-chain accessFleet-wide compromiseSimultaneous failure across distributed assetsSigned updates, staged deployment and rollback
Human interfaceAutomation bias, deceptive confidence, alert saturationInduce operator acceptance or inactionMisprioritisation and delayed responseUnsafe manual intervention or failure to interveneUncertainty display, training and dual confirmation

Influence Operations as an AI-Enabled Cyber-Political System

AI-accelerated influence operations should not be treated as a separate communications problem because they increasingly interact with cyber intrusion, stolen data, synthetic media, algorithmic amplification and physical events. An operation may begin with network compromise to obtain authentic documents, proceed through selective alteration or fabrication, use generative systems to produce multilingual narratives and synthetic personas, and then coordinate distribution through apparently independent websites, accounts and intermediaries. The strategic objective is often not to persuade an entire population of a single false claim. It is to increase uncertainty, polarisation, institutional distrust and decision latency. AI improves the economics of this process by generating more content variants, translating them rapidly, tailoring them to local grievances and maintaining artificial personas over long periods. It can analyse audience responses, identify emotionally effective frames and reallocate effort across platforms. Yet distribution infrastructure, trusted intermediaries and political timing remain more important than raw content generation. A million synthetic messages with no credible channel may produce little effect; a small quantity of manipulated material inserted into a trusted political, journalistic or institutional network can be consequential. The European External Action Service defines foreign information manipulation and interference as intentional, coordinated and manipulative behaviour capable of negatively affecting values, procedures and political processes, conducted by state or non-state actors and their proxies. The EEAS’s second annual report examined 750 investigated incidents between December 2022 and November 2023, while subsequent reports mapped the digital infrastructure supporting operations attributed primarily to Russian and, to a lesser extent, Chinese actors. Information Integrity and Countering Foreign Information Manipulation and Interference – European External Action Service – updated 2026. The fourth report, issued in March 2026, shifted from exposure toward deterrence by linking the FIMI methodology, response framework, toolbox and deterrence playbook. Fourth EEAS Annual Report on Foreign Information Manipulation and Interference Threats – European External Action Service – March 2026.

The five-year escalation pathway involves the merger of influence operations with critical-infrastructure incidents. A hostile actor can exploit an electrical outage, hospital disruption, water-quality event or satellite-service interruption by flooding the information environment with false explanations, forged instructions and fabricated evidence. The cyberattack generates uncertainty; the influence operation shapes attribution, public reaction and government freedom of manoeuvre. Synthetic audio or video purporting to show an official admitting responsibility, ordering evacuation or announcing contamination could spread during the period when authentic information remains incomplete. Automated agents could target emergency personnel, journalists, local authorities and affected communities with different narratives, making central rebuttal less effective. Conversely, a fabricated infrastructure crisis could induce real-world behaviour even without a successful technical intrusion: false alerts may cause population movement, market volatility, service overload or premature shutdown. The distinction between cyber effect and cognitive effect therefore collapses. Defensive policy must authenticate official communications, pre-establish trusted emergency channels, monitor coordinated infrastructure rather than individual pieces of content, and preserve rapid forensic access to technical evidence. The 2025 EEAS operational programme established a FIMI Situational Awareness Hub and expanded early warning and coordinated response, reflecting the need to turn analysis into action rather than merely cataloguing narratives after their impact. 2025 Report on EEAS Activities to Counter Foreign Information Manipulation and Interference – European External Action Service – June 2026. Through 2031, information integrity must be incorporated into cyber-crisis exercises alongside network restoration and physical safety, because adversaries will attack the public interpretation of an incident as deliberately as the infrastructure itself.

AI-Enabled Hybrid Operation Chain
Multi-Vector Cyber & Information Warfare Kill Chain
🔍 CYBER RECONNAISSANCE
Identify Technical Weaknesses Map Decision-Makers & Trusted Voices Collect Authentic Internal Material
▼ Technical Exploitation & Intrusion Execution
⚡ NETWORK INTRUSION OR DATA ACQUISITION
Steal Documents Manipulate Operational Data Create Physical / Administrative Disruption
▼ Synthetic Weaponization & Narrative Generation
🤖 AI CONTENT AND PERSONA LAYER
Translate & Localise Narratives Generate Synthetic Audio, Video & Documents Maintain Artificial Personas Adapt Messages to Audience Reaction
▼ Multi-Channel Campaign Amplification
📡 DISTRIBUTION INFRASTRUCTURE
Coordinated Websites & Social Channels Proxies, Influencers & Compromised Accounts Messaging Platforms & Targeted Advertising Search Manipulation & Automated Engagement
▼ Strategic Impact & Cascade Threshold
🎯 STRATEGIC EFFECTS
Attribution Confusion Emergency-Response Delay Political Polarisation Market & Public-Service Disruption Reduced Freedom of Government Action
×

Defensive Automation and the Transfer of Authority to Machines

Defensive automation is operationally necessary because contemporary infrastructure generates more events than human security teams can inspect, while AI-enabled attackers can vary techniques faster than static rules can be updated. Machine learning already supports spam filtering, malware classification, fraud detection, behavioural analytics, vulnerability prioritisation and alert correlation. The next stage gives AI systems authority to collect evidence, isolate endpoints, revoke credentials, block network routes, deploy decoys, alter firewall policies, roll back software and prioritise restoration. This progression can reduce response time from hours to seconds, but it changes the nature of cyber risk. A false positive no longer produces only an analyst alert; it may disconnect a hospital system, halt industrial production, disable a remote site or remove legitimate administrative access during a crisis. Defensive action must therefore be calibrated to consequence. Low-impact and easily reversible actions can be highly automated; actions affecting safety, continuity or strategic communications require stronger evidence, dual confirmation and predefined degraded modes. NIST’s 2026 concept work for a trustworthy-AI profile in critical infrastructure explicitly recognises that AI will increasingly be deployed across information technology, operational technology and industrial control systems to improve safety, security, reliability, capacity and efficiency, while requiring lifecycle assurance appropriate to high-stakes environments. Concept Note: AI RMF Profile on Trustworthy AI in Critical Infrastructure – National Institute of Standards and Technology – 2026. The strategic requirement is not to prevent machines from acting, but to construct an authority gradient that matches machine autonomy to confidence, reversibility and potential physical harm.

A mature defensive architecture should separate observation, recommendation, reversible action and irreversible action. At the first level, AI enriches events and identifies anomalies but possesses no operational authority. At the second, it recommends containment and presents evidence. At the third, it performs reversible actions—such as quarantining a non-critical endpoint or forcing credential reauthentication—within strict policy limits. At the fourth, it can alter operational networks or safety-relevant systems only under explicit human authorisation. At the fifth, emergency autonomous action may be permitted where delay would produce catastrophic harm, but only for narrowly specified conditions validated through independent sensors. This architecture must also account for adversarial manipulation. An attacker may deliberately create telemetry patterns designed to trigger automatic shutdown, route changes or resource exhaustion. Defensive AI therefore becomes a target whose decision boundary can be probed. NIST’s adversarial-machine-learning taxonomy identifies evasion, poisoning, privacy and misuse threats that apply directly to security analytics. The defender must assume that hostile actors will study not only network vulnerabilities but automated response policy. Deception resistance requires diverse telemetry, cryptographically authenticated sensors, rate limits, confidence calibration and the ability to compare model conclusions with deterministic safety rules. By 2031, the most secure organisations will not necessarily be those with the highest degree of automation. They will be those that can automate routine containment aggressively while preserving human command over actions capable of causing broad operational, political or physical consequences.

Table 3 — Defensive-Automation Authority Matrix

Automation tierPermitted AI functionTypical actionRequired confidenceReversibilityHuman roleAppropriate environment
A₀ — ObserveCollect, correlate and classifyGenerate enriched alertModerateCompleteReview and investigateAll systems
A₁ — RecommendPropose action with evidenceRecommend token revocation or host isolationHighCompleteApprove or rejectEnterprise IT and selected OT monitoring
A₂ — Reversible containExecute bounded low-impact controlQuarantine workstation, block domain, reset sessionHighRapidSupervise exceptionsNon-critical IT and segmented business systems
A₃ — Adaptive defendModify policies within approved envelopeChange deception routes, throttle traffic, rotate credentialsVery highUsually reversibleMonitor and auditMature zero-trust environments
A₄ — Safety-relevant interventionAffect operational availabilityIsolate engineering station or suspend remote commandMulti-source verifiedLimitedMandatory authorisationEnergy, transport, water and manufacturing
A₅ — Emergency autonomous protectionPrevent imminent catastrophic effectTrigger safe state after confirmed malicious manipulationExceptional and deterministicPotentially costlyPost-action command reviewNarrowly defined nuclear, chemical or grid conditions
A₆ — Prohibited strategic actionRetaliate or expand beyond defended environmentOffensive counterstrike or destructive external actionNot applicablePotentially irreversibleSovereign political decisionMust remain outside autonomous authority

Migration from Digital Compromise to Physical Infrastructure Effects

The migration of cyber effects into physical systems is driven by convergence between enterprise IT, industrial control, remote maintenance, cloud analytics, digital twins, wireless sensors and AI-supported optimisation. Operational technology historically prioritised availability, deterministic behaviour and long equipment lifecycles. Many systems were designed when isolation, specialised protocols and restricted physical access were assumed to provide sufficient protection. Modernisation has weakened those assumptions. Plants increasingly connect operational data to enterprise platforms, vendors maintain equipment remotely, mobile devices interface with industrial systems, and cloud services perform predictive maintenance and optimisation. These changes provide economic and safety benefits but create pathways from compromised identity or software into physical processes. The 2024 multinational Principles of Operational Technology Cybersecurity guidance stressed that business decisions can directly alter OT security and continuity, and identified the need to understand the specific consequences of operational technology compromise rather than importing ordinary IT controls without adaptation. Principles of Operational Technology Cybersecurity – Cybersecurity and Infrastructure Security Agency and International Partners – October 2024. The central difference is that confidentiality loss in office systems may expose information, whereas integrity or availability loss in OT can change pressure, temperature, flow, voltage, speed, chemical concentration or mechanical movement. A poorly designed defensive response may itself create danger if it interrupts a process that must be shut down in a controlled sequence.

AI adds three layers of risk. First, attackers can use models to infer industrial-process logic from documentation, historian data, engineering files and stolen operator screens, lowering the expertise required to understand a target. Second, defenders and operators increasingly use AI to optimise production, detect faults and recommend control adjustments, creating new trusted decision points that can be manipulated. Third, autonomous agents may bridge systems by retrieving data from enterprise sources and invoking operational tools, increasing the consequence of prompt injection, credential compromise or incorrect reasoning. Physical harm still requires process knowledge, access and the ability to bypass safety mechanisms. The most sophisticated cyber-physical attacks are therefore likely to remain state-grade or require insider support. However, AI will expand the set of actors able to cause disruption, unsafe conditions or equipment damage even without mastering the entire process. An attacker may not know how to destroy a turbine but may know enough to interrupt sensor availability, corrupt maintenance records, disable alarms or force operators into manual mode. The physical effect may emerge indirectly through degraded situational awareness and human error. Through 2031, the highest-risk targets will be systems in which digital control is tightly coupled to high-energy processes, safety margins are narrow, legacy devices cannot be patched, and operators lack independent physical verification.

Table 4 — Cyber-to-Physical Effect Pathways

SectorDigital entry pointManipulated variable or functionPlausible physical effectSafety barrierAI-specific amplification
Electricity generationRemote access, engineering workstation, vendor softwareTurbine control, protection settings, excitation or fuel systemsEquipment trip, damage or unstable generationLocal protection relays and manual shutdownAutomated analysis of plant documentation and control logic
Transmission gridEnergy-management system, substation gateway, identity serviceBreaker state, telemetry, load estimates, protection coordinationRegional outage or equipment overloadIndependent relays, operator procedures and islandingRapid cross-substation pathway analysis and false-data generation
Nuclear powerAdministrative network, maintenance path, digital I&C supply chainMonitoring, support systems or safety-relevant dataLoss of visibility, unsafe maintenance or challenged safety functionDefence in depth, segmentation and independent safety systemsManipulated diagnostics or AI-supported decision tools
Water treatmentInternet-facing control device, remote maintenancePumps, valves and chemical dosingLoss of pressure, overflow or incorrect treatmentLocal limits, chemical testing and manual controlAutomated discovery of similar exposed installations
Gas pipelinesCompressor station, SCADA communicationsPressure, compressor operation and valve stateService interruption, overpressure or equipment damageMechanical relief and local shutdownAdaptive manipulation based on process telemetry
HospitalsIdentity provider, clinical systems, networked devicesScheduling, records, pharmacy, imaging or device availabilityDelayed care, medication error or diversion of patientsManual procedures and clinical verificationAutomated extortion, data analysis and targeted disruption
ManufacturingMES, robotics controller, digital twin or update serverRobot motion, quality limits, recipe and timingDefective output, equipment collision or production haltSafety PLCs and physical interlocksGeneration of plausible but malicious process parameters
Solar and wind generationFleet management, inverter firmware, cloud portalOutput setpoints, ride-through settings and availabilityCoordinated generation loss or grid instabilityGrid protection and local controlsOne-to-many exploitation of homogeneous fleets
TransportSignalling, fleet management, GNSS and communicationsRouting, scheduling, location and control informationCollision risk, congestion or systemic service interruptionIndependent signalling and operational proceduresSynthetic telemetry and rapid multi-modal targeting
Chemical industryProcess-control network and safety instrumentation interfacesTemperature, pressure, flow and reaction timingRelease, fire, explosion or toxic exposureSafety-instrumented systems and physical containmentAI-assisted process modelling and attack-sequence optimisation

Nuclear Facilities and High-Consequence Industrial Systems

Nuclear cybersecurity demonstrates why machine-speed operations cannot be governed by ordinary enterprise assumptions. Nuclear facilities combine safety, security, safeguards, physical protection, material accounting and continuity requirements. Digital instrumentation and control systems may perform safety, security or auxiliary functions, while maintenance laptops, vendors, data diodes and administrative services create additional interfaces. The International Atomic Energy Agency states that digital technologies are increasingly incorporated into nuclear instrumentation and control and that the transition from hardwired or analogue systems to interconnected, reprogrammable systems changed the security environment. Its guidance requires computer security to be considered throughout the system lifecycle and applies graded security levels and zones according to the importance of the functions being protected. Computer Security of Instrumentation and Control Systems at Nuclear Facilities – International Atomic Energy Agency – Nuclear Security Series No. 33-T. The IAEA’s broader technical guidance calls for risk-informed computer-security programmes, identification of sensitive digital assets and measures designed around the potential consequences of attack. Computer Security Techniques for Nuclear Facilities – International Atomic Energy Agency – 2021/2024 multilingual editions. This consequence-based approach must govern AI deployment. An AI system that predicts component failure or assists outage planning may improve reliability, but its recommendations cannot be trusted solely because historical accuracy appears high. Rare operating conditions, adversarial input, distribution shift and hidden model dependencies must be evaluated.

The IAEA’s 2025 work on AI deployment in nuclear power characterises adoption as emerging and largely limited to pilot projects while recognising potential benefits for safety, security, efficiency and reliability. Considerations for Deploying Artificial Intelligence Applications in the Nuclear Power Industry – International Atomic Energy Agency – April 2025. The strategic danger lies not in an AI independently “taking control” of a reactor, which misrepresents layered nuclear architectures, but in gradual dependence on AI-mediated analysis. If operators begin to rely on AI for anomaly detection, maintenance prioritisation, procedure retrieval or event interpretation, compromise of the model or its data could alter human decisions without directly manipulating safety systems. This is a cognitive control-path attack: the adversary targets the information presented to authorised personnel rather than the physical actuator. Protection therefore requires separation between AI advice and authoritative safety logic, validation against independent instrumentation, authenticated data lineage, controlled updates and the capacity to operate safely without the AI service. Similar principles apply to chemical plants, refineries, high-voltage grids and automated transport. No AI model should become a silent single point of failure. The five-year objective must be to exploit AI for predictive insight while preserving deterministic protection, physically independent verification and trained human capability.

Machine-Speed Escalation, Attribution and Strategic Stability

Machine-speed escalation emerges when offensive discovery, defensive classification and operational response occur faster than political authorities can establish context. In conventional cyber operations, uncertainty regarding origin, intent and effect already complicates deterrence. AI increases the quantity of actions and may reduce the time available to distinguish espionage, pre-positioning, criminal activity, accidental propagation and preparation for destructive attack. An automated defender observing lateral movement across military or critical-infrastructure networks may interpret it as imminent sabotage and trigger broad containment. The containment may interrupt allied services, alter cross-border routing or appear to the adversary as preparation for offensive action. Offensive systems may then adapt automatically, creating reciprocal signals that neither political leadership intended. Strategic instability therefore does not require fully autonomous cyber weapons. It can arise from interacting systems optimised for local objectives—maintain access, block intrusion, preserve service—without a shared model of escalation. NATO states that cyber defence forms part of collective deterrence and defence and that a cyberattack may, case by case, reach the level at which Article 5 could be considered. Cyber Defence – North Atlantic Treaty Organization – updated 2025. This deliberate ambiguity preserves political flexibility but places a premium on attribution, consequence assessment and alliance consultation. If technical response becomes highly automated while political decision remains necessarily deliberative, a dangerous temporal gap opens between operational action and strategic interpretation.

The most destabilising conditions are ambiguous attribution, compressed warning, cross-domain effects and delegated authority. Attribution combines technical indicators, intelligence, behavioural patterns, infrastructure ownership, geopolitical context and legal standards; AI can help fuse evidence but can also amplify false correlations or adversary-planted indicators. A hostile actor may intentionally imitate another group, use compromised infrastructure in third countries, insert misleading language artefacts or conduct operations through criminal proxies. Synthetic code generation may weaken stylistic attribution as tools produce more variation. The appropriate response is probabilistic rather than absolute: decision-makers require confidence ranges, alternative hypotheses and explicit identification of evidence that would change the assessment. Political authorities must also distinguish defensive urgency from retaliatory urgency. Immediate containment may be essential; external countermeasures can usually tolerate greater deliberation. Fully autonomous retaliation should remain prohibited because technical systems cannot reliably assess geopolitical intent, proportionality, collateral effects and alliance obligations. Through 2031, crisis stability will depend on maintaining secure human communication channels, pre-agreed thresholds, reversible response options, shared forensic standards and mechanisms for signalling that an automated action is defensive rather than escalatory.

Table 5 — Machine-Speed Escalation Ladder

Escalation levelTriggerAutomated actionAdversary interpretation riskPhysical consequenceRequired governance
E₀ — Routine anomalyLow-confidence deviationAdditional logging and observationMinimalNoneFully automated
E₁ — Suspected intrusionCorrelated indicators across one networkEndpoint isolation and credential challengeLimited probing or defensive hardeningMinor service interruptionAutomated within approved limits
E₂ — Coordinated campaignMulti-system lateral movementBroad segmentation and emergency access restrictionsPreparation for counter-operationRegional service degradationHuman-supervised automation
E₃ — Critical-infrastructure accessPresence in OT, safety or command networksSuspend remote control, enter degraded modeImminent defensive mobilisationReduced industrial output or continuityExecutive incident command
E₄ — Physical effect detectedManipulation causes real-world disruptionCross-sector containment and national emergency measuresAttribution of hostile strategic attackOutage, injury or material damageSovereign crisis authority and allied consultation
E₅ — Strategic ambiguityEffects across military and civilian systemsDefensive cyber operations outside local networkPreparation for retaliation or conflict expansionCross-border disruptionPolitical authorisation and legal review
E₆ — Retaliatory actionHigh-confidence attribution and grave consequenceOffensive cyber, sanctions or conventional responseEscalation to wider conflictPotentially severeNo autonomous authority; national and alliance decision

Five-Year Outlook and Analysis of Competing Hypotheses

The 2027–2031 trajectory is best evaluated through competing hypotheses rather than a single linear forecast. H₁ — Defensive AI Advantage assumes that identity modernisation, secure-by-design software, automated detection and coordinated intelligence sharing allow defenders to use superior local telemetry to contain threats faster than attackers can scale them. H₂ — Offensive Industrialisation assumes that autonomous reconnaissance, exploit adaptation and social engineering reduce attacker costs more quickly than organisations can modernise, creating sustained growth in intrusion volume and operational reach. H₃ — Persistent Human–Machine Hybrid Conflict assumes neither side achieves decisive autonomy; skilled operators retain command while AI performs high-volume analysis and execution. H₄ — Autonomous Escalation Event assumes interacting offensive and defensive systems cause a serious cross-domain incident without a deliberate political decision to escalate. H₅ — Cyber-Physical Strategic Attack assumes a state or proxy uses AI-supported access to produce coordinated physical effects against energy, water, transport, healthcare or industrial systems during a geopolitical crisis. H₆ — AI Trust Collapse assumes poisoning, prompt injection, supply-chain compromise or repeated high-profile failures cause critical sectors to restrict AI autonomy, slowing deployment. Current evidence most strongly supports H₃ because AI capabilities are advancing rapidly while reliability, access and physical-process constraints preserve the need for expert human involvement. H₂ receives the second-highest probability because cost reduction and scale benefit attackers immediately, particularly in phishing, reconnaissance and vulnerability matching. H₁ remains plausible where organisations possess mature telemetry and authority to automate response, but uneven security capacity prevents a universal defensive advantage.

A Bayesian update using current ENISA incident trends, NIST’s formalisation of adversarial-machine-learning risks, NATO’s cyber-defence posture, EEAS documentation of networked influence infrastructure, CISA evidence of persistent state access to telecommunications networks and IAEA concern regarding digitally integrated control systems produces indicative 2031 probabilities of 34% for H₃, 25% for H₂, 17% for H₁, 10% for H₆, 8% for H₄ and 6% for H₅. These are structured analytical estimates, not official forecasts. A Monte Carlo stress model with 60,000 synthetic pathways varies agent reliability, vulnerability-discovery acceleration, defensive telemetry quality, autonomous-response authority, OT segmentation, geopolitical crisis intensity and attribution confidence. The model indicates a 74% median probability of at least one major AI-assisted cyber campaign affecting critical services somewhere in the Euro-Atlantic area during 2027–2031; a 46% probability of a cyber incident causing measurable physical-service disruption; a 23% probability of simultaneous disruption across two infrastructure sectors; a 12% probability of an event in which automated defensive or offensive action materially worsens consequences; and a 7% probability of an AI-enabled cyber incident contributing to sustained interstate military escalation. These outputs are sensitive to assumptions and should be interpreted as stress indicators rather than frequencies. The highest-impact risk-reduction variables are strong identity architecture, authenticated operational telemetry, tested manual fallback, segmented OT, constrained agent permissions and politically controlled external response.

Table 6 — Analysis of Competing Hypotheses, 2031

HypothesisCore propositionEvidence consistent with hypothesisEvidence inconsistent with hypothesisKey observable by 2028–2029Updated probability
H₁ — Defensive AI AdvantageDefenders exploit superior telemetry and authorityGrowth of AI-enabled SOCs, zero-trust identity, automated containmentSkills gaps, fragmented logs and legacy OTFalling dwell time and declining severe incident conversion17%
H₂ — Offensive IndustrialisationAttack throughput grows faster than resilienceAI phishing, continuous scanning, exploit automation and proxy marketsUnreliable agents and stronger platform controlsLarge rise in successful campaigns per operator25%
H₃ — Human–Machine Hybrid ConflictHumans retain strategic control while AI executes scale functionsCurrent tool limitations and value of expert judgementRapid improvement in agent reliabilityExpansion of operator-supervised autonomous workflows34%
H₄ — Autonomous Escalation EventInteracting systems unintentionally amplify a crisisShortened response cycles and automated containmentStrong human approval rulesIncidents caused by machine-to-machine misinterpretation8%
H₅ — Cyber-Physical Strategic AttackAI supports coordinated physical disruptionInfrastructure convergence and state pre-positioningSafety layers and high process-specific complexityEvidence of cross-sector target modelling and OT access6%
H₆ — AI Trust CollapseSecurity failures constrain deploymentPoisoning, injection and opaque supply chainsEconomic and military pressure to automateRegulatory restriction after serious AI-caused failures10%

Table 7 — Five-Year Operational Outlook

YearOffensive developmentDefensive developmentCritical-infrastructure implicationGeopolitical effect
2027Broad adoption of AI reconnaissance, phishing and exploit triageAI-assisted alert fusion and identity anomaly detectionGreater attack volume against exposed and legacy systemsMore frequent low-level campaigns and proxy activity
2028Semi-autonomous multi-stage intrusion frameworksAutomated reversible containment and deceptionReduced response time but growing false-action riskDisputes over attribution and private-provider responsibility
2029Continuous agentic operations across large target portfoliosSector-specific AI assurance and OT-aware response policiesAI becomes embedded in monitoring and maintenanceAlliance coordination expands around models, telemetry and incident evidence
2030Adaptive offensive agents alter techniques based on detectionMulti-agent defensive systems coordinate across organisationsCommon-mode AI supply-chain risk becomes strategicCyber crises increasingly interact with sanctions and military posture
2031Selected high-end campaigns operate at near-machine tempoHuman command retained for safety and external responsePhysical-service disruption possible without direct equipment destructionStable deterrence depends on human-controlled escalation boundaries

Strategic Risk Architecture and Priority Controls

The central policy requirement is to prevent speed from replacing judgement. Governments and infrastructure operators should design cyber-AI systems around six control principles. First, mission decomposition must identify which services must continue under degraded connectivity, unavailable models, corrupted data or compromised identity. Second, authority bounding must define exactly which tools an AI agent may invoke, which assets it may affect and which actions require human confirmation. Third, independent verification must ensure that safety-relevant conclusions rely on multiple authenticated sources rather than a single model or telemetry stream. Fourth, reversibility must be engineered into defensive actions, with rapid rollback and tested recovery. Fifth, model and data provenance must cover training inputs, retrieval sources, weights, software dependencies and update channels. Sixth, escalation governance must separate urgent local defence from external counteraction, preserving political authority over retaliation. These principles are more important than model size. A smaller, well-bounded system operating on trusted data may provide greater strategic value than a frontier model with broad permissions and opaque dependencies.

The geopolitical dimension requires allied coordination because AI-enabled campaigns move across private platforms, jurisdictions and infrastructure sectors. Shared incident taxonomies, evidence standards, secure telemetry exchange and mutual assistance should be integrated with NATO cyber-defence planning, EU critical-infrastructure policy, national CERT structures and sector regulators. Governments should establish pre-authorised channels for urgent technical cooperation while ensuring that private providers cannot unilaterally determine strategic escalation. Critical sectors need sector-specific AI red teams capable of testing prompt injection, poisoned telemetry, agent misuse, unsafe recommendations and interactions with physical processes. Exercises should combine cyber intrusion, false information, cloud-service loss, GNSS interference and public panic rather than treating each as an isolated scenario. Procurement rules must require offline continuity, audit access, cryptographic update verification and credible exit capability. Finally, human expertise must remain operationally current. Manual fallback cannot exist only as documentation; personnel must practise operating without AI assistance, cloud identity or normal telemetry. The five-year objective is not to preserve a permanently human-paced environment, which is no longer feasible, but to construct machine-speed defence within human-defined constitutional limits. The state that delegates too little will be overwhelmed by volume. The state that delegates too much may lose control of the very systems it is attempting to defend.

Figure 1: AI-Accelerated Cyber Conflict Risk Projection, 2027–2031

Figure 1: AI-Accelerated Cyber Conflict Risk Projection
Baseline scenario · Analytical indices, not official forecasts

Europe’s Digital Power Deficit: Italy, France, Germany, the United Kingdom and the Strategic Race for AI Sovereignty to 2031

Europe Is Not Absent from AI, but It Is Structurally Behind Where Power Is Decided

The proposition that Europe is “abysmally behind” in artificial intelligence is directionally correct only when it is defined with precision. Europe is not intellectually absent, scientifically irrelevant or devoid of industrial assets. It retains world-class universities, major supercomputers, advanced semiconductor-equipment and microelectronics capabilities, globally competitive telecommunications operators, substantial aerospace and defence industries, sophisticated cybersecurity agencies, a large internal market and exceptional strengths in manufacturing, energy systems, automotive engineering, pharmaceuticals, robotics and applied mathematics. France possesses a credible foundation-model company, nuclear-powered data-centre potential, defence-electronics expertise and an unusually centralised capacity to mobilise national strategy. Germany combines Europe’s largest data-centre base with industrial automation, enterprise software, automotive engineering, machine tools, sensors and approximately 30% of EU wafer-manufacturing capacity, according to the German government. The United Kingdom retains Europe’s deepest AI venture-capital ecosystem, leading universities, an established AI-security institution, advanced chip-design intellectual property and a government programme to expand public AI compute by twenty times by 2030. Italy possesses the Leonardo supercomputing ecosystem, the EuroHPC IT4LIA AI Factory, advanced manufacturing districts, defence and aerospace groups, a strategically advantageous Mediterranean location and an expanding data-centre market. The European Union as a whole has established 19 AI Factories, 13 associated antennas, a planned investment of approximately €10 billion in EuroHPC infrastructure and AI Factories during 2021–2027, and an InvestAI mechanism intended to mobilise €20 billion for up to five AI Gigafactories containing more than 100,000 advanced AI processors each. AI Factories – European Commission – April 2026. These are real capabilities, not merely regulatory texts.

The strategic deficit appears when Europe’s capabilities are measured against the complete AI power stack: frontier-model companies, private risk capital, hyperscale cloud platforms, advanced accelerators, high-bandwidth memory, semiconductor fabrication, software ecosystems, energy-connected compute campuses, military deployment, public procurement and the ability to move from political announcement to operational capacity before the technological generation changes. The European Court of Auditors concluded in 2024 that Commission actions covered important dimensions of an AI ecosystem but had achieved only limited effects by the audit date, had not accelerated investment in line with global leaders, and were not effectively coordinated with national measures because the Commission lacked adequate governance tools and information. EU Artificial Intelligence Ambition: Stronger Governance and Increased, More Focused Investment Essential Going Forward – European Court of Auditors – May 2024. This official finding is more serious than a generic claim that Europe “regulates too much.” It means that Europe’s central weakness is conversion efficiency: the Union converts scientific capacity into regulation, pilot programmes and distributed public infrastructure more effectively than it converts them into globally dominant firms, rapidly deployed compute, strategic procurement and vertically integrated AI platforms. The United States and China increasingly operate through continental-scale concentrations of capital, energy, compute, models, cloud services, industrial policy and defence demand. Europe continues to operate through partially connected national programmes, EU instruments, state-aid procedures, private investment announcements, regional permitting systems and fragmented procurement markets. In AI, fragmentation is not an administrative inconvenience. It directly reduces training scale, slows infrastructure deployment, divides datasets, weakens capital formation and allows foreign hyperscalers to remain the practical operators of Europe’s digital frontier.

Table 1 — Strategic Position of Europe in the AI Power Stack

AI power layerEuropean positionPrincipal European strengthPrincipal dependency or gapStrategic severity by 2031
Fundamental researchStrongUniversities, public laboratories and scientific publication baseCommercialisation and retention of talentMedium
Frontier foundation modelsWeak to intermediateMistral AI and several specialised/open-model initiativesFar fewer capitalised frontier laboratories than the US or ChinaCritical
Advanced AI acceleratorsWeakChip design niches, automotive and industrial semiconductorsDependence on non-European accelerator architectures and supplyCritical
Leading-edge fabricationWeakEuropean equipment, power electronics, sensors and mature-node productionLimited leading-edge logic and advanced-memory capacityCritical
Cloud control planeWeakEmerging trusted-cloud and sovereign-cloud initiativesDominance of US hyperscalers in scalable cloud and AI servicesCritical
Public supercomputingStrong relative to Europe’s historyEuroHPC network, JUPITER, Leonardo, LUMI and AI FactoriesPublic-access systems do not equal commercial frontier-scale clustersHigh
Venture capital and scale-up financeWeak outside the UK and selected hubsStrong early research and startup creationLate-stage capital, exits and continental scaling remain limitedCritical
Energy for AIUnevenFrench nuclear fleet, Nordic low-carbon power, selected renewable regionsGrid queues, high prices, permitting and limited dispatchable capacity elsewhereHigh
Industrial applicationPotentially strongManufacturing, automotive, aerospace, energy, health and roboticsSlow diffusion, SME fragmentation and shortage of deployable platformsHigh
Defence AIFragmentedMajor national defence firms and strong sensor systemsNational procurement fragmentation and dependence on foreign cloud/computeCritical
Regulation and safetyGlobally strongAI Act, cybersecurity and rights frameworksEnforcement resources and risk of regulating systems built elsewhereMedium–high
Data and languagesPotentially strongLarge multilingual market and industrial datasetsLegal, contractual and organisational fragmentationHigh

The Scale Problem: Europe Announces “Mobilisation,” While Rivals Construct Concentrated Capability

Europe’s headline investment numbers require forensic interpretation. The AI Continent Action Plan presents a goal of mobilising €200 billion for AI, including €20 billion for AI Gigafactories, while the existing AI Factory and EuroHPC programme is expected to reach approximately €10 billion in combined Commission, Member State and associated-country investment over 2021–2027. AI Continent Action Plan Q&A – European Commission – April 2025 and AI Factories – European Commission – April 2026. These figures demonstrate a change in political awareness, but they do not mean that €200 billion of new, unconditionally committed EU public money is available for frontier AI. “Mobilise” typically combines public guarantees, existing programmes, Member State contributions and expected private capital. The first formal AI Gigafactory call was still scheduled for summer 2026, with construction of the first facility expected to begin in 2027. The Commission itself states that Europe has a “critical deficit” in large-scale computing infrastructure and identifies this deficit as a threat to competitiveness and strategic autonomy. AI Gigafactories – European Commission – 2026. The admission is strategically important: Europe is designing the instruments needed to close a gap that its rivals are already exploiting commercially and militarily.

The comparison with the United States is not exact because official US announcements aggregate overlapping private commitments, different time horizons and investments extending beyond AI. Nevertheless, the scale and concentration are unmistakable. The White House lists a $500 billion private AI-infrastructure commitment for Project Stargate, a stated $500 billion US AI-infrastructure and domestic supercomputer-manufacturing commitment by NVIDIA, major hyperscaler investments and large semiconductor-manufacturing commitments. These are corporate announcements rather than equivalent federal appropriations, and their eventual deployment must be distinguished from political presentation; however, they emerge within an ecosystem that already contains the dominant cloud platforms, frontier-model laboratories, accelerator suppliers, venture investors and defence customers. Running List of New US Investment – White House – March 2026. China’s model differs again: central direction, local-government construction, state-owned telecommunications operators, national computing hubs, industrial-policy funds, domestic model ecosystems and increasingly capable indigenous accelerators. Official Chinese data reported 1,590 EFLOPS of intelligent computing capacity in 2025, more than 6,000 AI companies, a core AI industry exceeding 1.2 trillion yuan, and a 60-billion-yuan national AI industry investment fund. By June 2026, official data placed intelligent-computing capacity at 2,185 EFLOPS. China Home to Over 6,000 AI Firms in 2025 – State Council Information Office – January 2026 and China’s Intelligent Computing Capacity Reaches 2,185 EFLOPS – State Council Information Office – July 2026. The relevant comparison is therefore not one headline against another. It is the speed with which financial commitments become electricity connections, processor clusters, domestic platforms, model training, industrial deployment and national-security capability. On this measure, the EU remains behind.

Table 2 — Investment Numbers: What They Actually Represent

JurisdictionOfficially stated figureNature of figureOperational statusAnalytical caution
European Union€200bn InvestAI ambitionCapital intended to be mobilised from public and private sourcesMulti-year mobilisation frameworkNot equivalent to €200bn of fresh EU budget appropriations
European Union€20bn for up to five GigafactoriesPublic-private financing facilityFormal deployment process began after announcement; first construction expected from 2027Timing matters because hardware generations change rapidly
EuroHPC ecosystem€10bn during 2021–2027Combined EU, Member State and associated-country investmentAI Factories and supercomputers being deployedStrong public research base, but not equivalent to hyperscaler capacity
France€109bn announced in 2025Domestic and foreign private infrastructure commitmentsFrench presidency reported partial implementation in 2026Announcements include data centres and infrastructure, not only French-owned AI capability
United Kingdom£1bn public compute expansion commitmentSovereign/public AI computeIsambard-AI operational; expansion continuingMaterial nationally, still small against US hyperscaler investment
United Kingdom£68bn pledged since January 2025Private investment announcementsMulti-project pipelineCommitments, not identical to deployed sovereign capability
United States$500bn Project StargatePrivate AI-infrastructure commitmentMulti-year construction programmePolitically announced value may be staged and conditional
China60bn yuan national AI industry fundState-supported industry investment fundLaunchedOne element within a much larger state, provincial and corporate system
China2,185 EFLOPS intelligent computeReported national capacityReported as achieved by June 2026Methodological comparability with European and UK metrics is imperfect

France: Europe’s Most Coherent Candidate for Full-Stack AI Power

Among the continental European states, France has the strongest combination of political centralisation, low-carbon dispatchable electricity, mathematical and engineering talent, national-security institutions, aerospace and defence industries, sovereign-cloud doctrine and an identifiable frontier-model champion. France dedicated approximately €2.5 billion of the France 2030 programme to its national AI strategy, including earlier research investment, AI institutes, doctoral formation, public computing and industrial diffusion. The third phase announced in 2025 focuses on computing infrastructure, critical value-chain components, talent, deployment and trustworthy AI. National Strategy for Artificial Intelligence – French Ministry of Economy – February 2025. At the Paris AI Action Summit, the presidency announced more than €109 billion in infrastructure and deployment commitments for France. The Élysée emphasised nuclear-powered, stable and comparatively low-carbon electricity, high-voltage transmission, designated data-centre sites and streamlined procedures. Make France an AI Powerhouse – Presidency of the French Republic – February 2025. In April 2026, the French president stated that approximately 65% of those commitments were under implementation, while a February 2026 address referred to €58 billion of data-centre projects delivered or advancing in 2025 and to France’s export of 90 TWh of low-carbon, dispatchable electricity. Visit to the Republic of Korea – Presidency of the French Republic – April 2026 and AI Summit in New Delhi – Presidency of the French Republic – February 2026.

France’s advantage is not merely financial. It can connect civil AI with Thales, Dassault Systèmes, Safran, Airbus, the CEA, national laboratories, nuclear electricity, military procurement and a central administration capable of designating strategic projects. Its SecNumCloud framework attempts to shield sensitive cloud workloads from extraterritorial legal exposure, and the French government explicitly connects data sovereignty, trusted cloud, undersea-cable protection and semiconductor support. Council of Ministers Report – Presidency of the French Republic – June 2025. Yet France’s vulnerabilities remain substantial. Much of the announced infrastructure capital is foreign; the processors are overwhelmingly non-French; global cloud control remains concentrated outside Europe; and data-centre hosting does not automatically produce national ownership of models, software or commercial value. Electricity is an advantage only if grid connections, cooling, construction and processor supply arrive on schedule. France also faces the classic European scale-up problem: producing excellent research and startups but struggling to sustain capital-intensive firms against American competitors. France may become Europe’s principal compute location while still renting strategic intelligence from non-European model and cloud providers. Its five-year strategic objective should therefore be to convert infrastructure commitments into enforceable domestic value capture: long-term compute reservations for European model companies, defence and scientific workloads; procurement guarantees; domestic accelerator and interconnect programmes; model-weight and key custody; and equity mechanisms preventing strategically important firms from being sold or relocated after public de-risking.

The United Kingdom: Europe’s Strongest AI Market, but Outside the EU’s Strategic Core

The United Kingdom is the most commercially advanced AI jurisdiction in Europe and the only one with a plausible claim to being the world’s third major AI ecosystem, although it remains far behind the United States and China in compute ownership, hyperscale cloud and frontier-company capitalisation. The government’s 2025 AI Opportunities Action Plan accepted the objective of expanding sovereign compute by at least twenty times by 2030, created AI Growth Zones with accelerated power and planning support, and committed to use government data, procurement and public compute to support domestic champions. The initial Growth Zone at Culham was designed around a facility starting at 100 MW and potentially scaling to 500 MW. AI Opportunities Action Plan: Government Response – UK Government – January 2025. The Isambard-AI system contains 5,444 NVIDIA H100 GPUs, forms part of an initial £300 million AI Research Resource phase and sits within a £1 billion commitment to expand public compute. Sovereign AI AIRR Launch Opportunity – UK Government – June 2025. By January 2026, the government reported five AI Growth Zones associated with £28.2 billion in investment and more than 15,000 jobs, a planned 20-fold public-compute expansion, additional cloud capacity and a national structure for supporting home-grown AI firms. AI Opportunities Action Plan: One Year On – UK Government – January 2026.

The British model is more execution-oriented than the EU average. It combines public compute, venture investment, accelerated visas, procurement, data access and regulatory engagement through a dedicated Sovereign AI mechanism. The programme offers strategically important firms compute allocations of up to one million GPU hours, while a £500 million sovereign venture fund and government procurement are intended to anchor firms in Britain. Building Britain’s AI Future – UK Sovereign AI – 2026. The UK also retains deep capabilities in chip architecture through Arm, frontier research universities, life sciences, intelligence, cyber operations and the AI Security Institute. However, its sovereignty is constrained by the same structural dependencies affecting the EU: foreign accelerator hardware, US cloud providers, external capital and the gravitational pull of American salaries and acquisitions. Arm’s intellectual property is globally important, but it does not give Britain a complete domestic accelerator-manufacturing chain. Isambard-AI is significant for national research but remains small relative to private US frontier clusters. Brexit creates an additional strategic paradox: the UK can regulate and procure more rapidly than the EU, but it lacks the EU’s market scale and must maintain interoperability with European data, industrial and research systems. The optimal strategic position is therefore neither isolation nor simple regulatory divergence. Britain should function as a high-speed European AI power connected to EuroHPC, continental defence programmes, trusted data spaces and shared critical-infrastructure resilience while preserving national agility. The EU’s establishment of a UK AI Factory antenna demonstrates that practical cooperation is already possible despite institutional separation. AI Factories Antennas – European Commission – October 2025.

Germany: Industrial Depth Without Equivalent Frontier-AI Concentration

Germany possesses the strongest industrial foundation in Europe but has been slow to transform that foundation into frontier AI power. It operates more than 2,000 data centres with approximately 3 GW of connected capacity and annual consumption of around 20 TWh, equivalent to roughly 4% of gross national electricity consumption, according to the German government. Germany’s 2026 data-centre strategy seeks to double total connected data-centre capacity to more than 6 GW by 2030 and at least quadruple connected capacity for high-performance computing and AI. Federal Data-Centre Strategy – German Federal Government – March 2026. The JUPITER supercomputer at Jülich was presented by the government as Europe’s fastest and the world’s fourth-fastest system at inauguration, while Germany hosts two EuroHPC AI Factories and major commercial data-centre investments. Address on the High-Tech Agenda – German Federal Government – September 2025. Germany also possesses a uniquely valuable industrial data environment: automotive systems, chemical production, machine tools, logistics, power engineering, factory automation and enterprise software. These sectors could support world-leading domain-specific AI even if Germany does not produce the largest general-purpose model.

Germany’s weakness lies in speed, electricity economics, public procurement, startup scaling and a long-standing separation between industrial excellence and digital-platform control. Large German manufacturers often depend on American cloud, software and accelerator suppliers to digitalise production. The government itself acknowledges dependence on non-European cloud providers and technologies that Germany uses but does not control. Federal Digital Minister’s Address on the Data-Centre Strategy – German Federal Government – April 2026. Germany’s Hightech Agenda, adopted in July 2025, prioritises AI, quantum technologies, microelectronics, biotechnology, fusion, climate-neutral energy and mobility, with planned flagship programmes for next-generation AI models and strategic research. Hightech Agenda Deutschland – German Federal Government – July 2025. Yet the official documents remain stronger on direction than on an integrated, ring-fenced AI capital programme comparable to the concentrated private deployment occurring in the United States. Germany can still become Europe’s leading industrial AI power, but only if it treats factory data, digital twins, robotics, autonomous systems, defence manufacturing and machine control as a single strategic programme. Its comparative advantage is not consumer chatbots; it is the integration of AI with high-value physical systems. Failure to act would allow foreign platforms to capture the intelligence layer above European machinery, converting Germany into a supplier of excellent physical assets governed by non-European software and models.

Italy: Strategic Geography and Industrial Potential Without Sufficient Capital Concentration

Italy has significant assets but the weakest consolidated execution architecture among the four states assessed. The Italian Strategy for Artificial Intelligence 2024–2026 structures policy around research, public administration, enterprises and education, proposes monitoring and acknowledges Italy’s scientific and industrial potential. Italian Strategy for Artificial Intelligence 2024–2026 – Agency for Digital Italy – July 2024. Italy hosts the IT4LIA AI Factory, built around the EuroHPC ecosystem, and benefits from the Leonardo supercomputer at CINECA. It possesses major defence, aerospace, energy, telecommunications, automotive, pharmaceutical, robotics and advanced-manufacturing firms. Its geographical position is strategically important: submarine cables linking Europe, North Africa, the Middle East and Asia can make Italy a Mediterranean data gateway; industrial districts provide valuable domain datasets; and defence groups such as Leonardo and Fincantieri can connect AI with sensors, platforms, cyber defence, autonomous systems and maritime security.

The danger is that Italy becomes a hosting location rather than an AI power. The government’s data-centre strategy seeks to establish Italy as a European and Mediterranean hub, and the Ministry for Enterprises reported more than €7 billion in data-centre investment during 2023–2025 and a further €25 billion announced for 2026–2028. A single EdgeConneX plan announced in May 2026 envisaged €6 billion for three data centres near Milan and Lodi; another proposed hyperscale campus south of Milan could reach €5.3 billion and approximately 300 MW. Italy as a Mediterranean Data-Centre Hub – Ministry of Enterprises and Made in Italy – November 2025, EdgeConneX Investment Plan – Ministry of Enterprises and Made in Italy – May 2026 and K2 Strategic Hyperscale Project – Ministry of Enterprises and Made in Italy – June 2026. These investments can strengthen connectivity, employment, tax revenue and local compute availability. They do not automatically create Italian model companies, domestic chips, sovereign cloud control or intellectual property. Most large facilities may be owned, equipped and operated by foreign groups using imported accelerators and global cloud stacks.

Italy’s real deficit is the absence of a sufficiently capitalised, mission-driven national AI investment and procurement structure. Strategy documents identify directions but do not establish a visible multibillion-euro sovereign compute fund, a national champion-building vehicle comparable even to the smaller UK programme, or a defence–industry–research AI command structure with authority to aggregate demand. Italy should not attempt to reproduce the full American stack. It should concentrate on industrial, maritime, aerospace, defence, energy, health and public-administration AI, reserve strategic compute for domestic firms and researchers, build Italian-language and legal-administrative models, and make government and state-controlled enterprises first customers. The next Italian strategy for 2026–2028 should contain named budgets, processor counts, power targets, procurement volumes, accountable programme directors and quarterly delivery metrics. Without such instruments, Italy risks repeating a familiar pattern: excellent research, capable engineering, foreign acquisition of startups, fragmented public pilots and dependence on external platforms for operational deployment.

Table 3 — Comparative National Positioning

DimensionFranceUnited KingdomGermanyItaly
Strategic modelCentralised national mobilisationVenture, compute and procurement accelerationIndustrial and infrastructure modernisationDistributed strategy and investment attraction
Strongest assetNuclear energy plus models and defence ecosystemVenture capital, research, security and policy agilityIndustrial base, data centres and engineeringIndustrial niches, Mediterranean position and EuroHPC access
Public compute trajectoryMajor national and EuroHPC expansionExplicit 20× target by 2030AI/HPC connection capacity targeted to IT4LIA and Leonardo ecosystem, but no comparable national scale target
Frontier-model positionStrongest in continental EuropeStrong research, but limited domestic frontier championsLimited relative to industrial scaleWeak
Sovereign-cloud maturityRelatively advancedStrong security policy but hyperscaler-dependentGrowing but hyperscaler-dependentPublic strategic cloud exists; broader market dependency persists
Energy positionStrong due to nuclear generationMixed; project-specific grid and generation strategyHigh-cost and connection constraintsRegional potential, but grid and permitting constraints
Defence-AI integrationHigh potentialHigh through intelligence, defence and AISI ecosystemHigh industrial potential, fragmented executionHigh sector potential through Leonardo, Fincantieri and cyber capabilities
Core execution riskForeign infrastructure ownershipDependence on US capital, chips and cloudSlow deployment and fragmented public demandInsufficient capital concentration and weak scale-up mechanisms
2031 potentialEuropean full-stack leaderAgile European AI-security and venture leaderGlobal industrial-AI leaderMediterranean industrial and defence-AI hub
2031 downsideCompute colony with French brandingResearch and talent feeder for US firmsDigitised industry controlled by foreign platformsData-centre host and technology consumer

The EU-Level Failure: Fragmented Sovereignty and the Absence of a War-Economy Execution Mechanism

The European Union’s deepest problem is institutional mismatch. AI power requires continental scale, but most fiscal, energy, defence, education and procurement authority remains national. The Commission can regulate the internal market, coordinate research, support EuroHPC and structure financing mechanisms, but it cannot independently command the electricity connections, land, national budgets, defence purchases, public datasets or industrial consolidation required to create a frontier AI stack. Member States, meanwhile, are too small individually—except in selected niches—to match American or Chinese scale. The result is fragmented sovereignty: Europe has sufficient aggregate resources but lacks a mechanism for concentrating them rapidly. Nineteen AI Factories distributed across sixteen Member States widen access and support startups, but dispersion is not a substitute for several genuinely frontier-scale clusters with guaranteed multi-gigawatt power, secure processor supply, sovereign networking and long-term commercial workloads. The planned Gigafactories are a necessary correction, but construction beginning in 2027 means that Europe may deploy first-generation facilities when US and Chinese operators are already expanding the next generation.

The EU also suffers from a category error between regulatory sovereignty and operational sovereignty. The AI Act can impose conditions on systems sold in Europe; it cannot guarantee that European firms own the models, chips, cloud infrastructure or deployment platforms. Data-protection law can restrict transfers; it cannot create a European hyperscaler. Competition policy can prevent abusive conduct; it cannot by itself supply late-stage capital or secure high-bandwidth memory. The Union’s comparative strength in rulemaking remains strategically valuable because rights, safety and accountability matter. The failure occurs when regulation becomes the visible centre of policy while infrastructure and industrial instruments remain slower, smaller or less certain. The Commission reports that only 13.5% of EU companies were using AI when the AI Continent programme was presented. AI Continent – European Commission – 2026. This low diffusion rate illustrates that Europe’s weakness is not only frontier research. It is the inability to propagate AI rapidly across ordinary firms, public services and strategic industries.

Table 4 — Regulation Versus Operational Capability

EU instrumentWhat it can achieveWhat it cannot achieve aloneMissing execution mechanism
AI ActRisk governance, transparency, prohibited practices and market rulesCreate frontier laboratories or compute infrastructureCapital, procurement and sovereign technical capacity
NIS 2Raise cybersecurity duties and management accountabilityReplace legacy systems or create skilled teams automaticallySector funding and operational enforcement capacity
Data Act/Data Governance frameworkImprove access, portability and data sharingProduce clean, mission-ready industrial datasetsData engineering, liability allocation and sector consortia
EuroHPCProvide world-class public supercomputingMatch commercial hyperscaler scale in every workloadPersistent industrial capacity and rapid commercial allocation
AI FactoriesSupport startups, researchers and adoptionGuarantee global scaling or retain successful firmsLate-stage capital and strategic procurement
InvestAI/GigafactoriesDe-risk large compute constructionEnsure European ownership of chips, cloud and modelsSovereignty conditions and domestic-demand guarantees
Chips ActSupport semiconductor capacityDeliver immediate independence in leading-edge AI acceleratorsLong-term demand aggregation, design ecosystems and memory strategy
Foreign-investment screeningProtect selected strategic assetsFinance their growth or prevent talent migrationSovereign growth capital and acquisition alternatives
Competition policyLimit concentration and abuseCreate European scale by itselfCapital-market union and strategic consolidation policy

The Real Digital-Border Danger

The greatest danger is not that Europe will possess no AI. It is that Europe will become an AI-administered dependency zone: regulated by European law but computed on foreign processors, hosted in foreign-controlled clouds, trained through external model platforms, defended by foreign telemetry and updated through software supply chains that European authorities cannot independently inspect or replace. Under normal commercial conditions, this arrangement can appear efficient. In a geopolitical crisis, it creates several forms of coercive exposure. Export restrictions can delay accelerator replacement; foreign legal orders can compel access to data; provider policy changes can alter model behaviour; sanctions can interrupt services; cloud identity compromise can propagate across administrations and infrastructure; and military operations can depend on satellite, cyber and AI services controlled by private companies headquartered outside Europe. Europe’s “real digital boundary” is therefore not the location of a server. It is the point at which an external actor can deny, observe or modify a function that Europe cannot reproduce within an acceptable time.

A second danger is internal asymmetry. France and Germany may acquire large compute clusters while smaller Member States become permanent consumers. The UK may accelerate independently while losing integration with EU industrial data. Italy may host foreign data centres without creating domestic champions. Eastern and southern Member States may provide land and electricity but capture limited intellectual property. Such asymmetry could transform AI policy into a new source of political division. A third danger concerns defence. Autonomous systems, cyber defence, intelligence fusion, electronic warfare, logistics and targeting increasingly require AI infrastructure. If military AI remains nationally fragmented while commercial platforms are foreign, Europe’s formal defence spending may increase without producing independent decision capability. A fourth danger concerns democracy: dependency may lead governments to accept opaque foreign systems in critical services because domestic alternatives are unavailable, weakening transparency and appeal. Strategic autonomy should therefore not be defined as autarky. It should mean that Europe can continue essential governmental, economic, military and civic functions if a major supplier, jurisdiction or route becomes unavailable.

A Five-Year European AI Sovereignty Programme

Europe requires a programme designed with the urgency of energy security and collective defence rather than an additional coordination strategy. First, the EU and participating states should establish a European Sovereign Compute Authority with power to aggregate processor demand, negotiate energy and hardware contracts, allocate strategic compute and maintain reserves for defence, science, critical infrastructure and European frontier-model firms. Second, the planned Gigafactories should be expanded from up to five projects into a federated system with at least two clusters capable of genuine frontier training, several mission-specific clusters and geographically separated continuity capacity. Each major facility should have ring-fenced power, physically diverse fibre routes, sovereign identity, European key custody, vetted software supply chains and emergency offline operation. Third, public procurement should become the primary scaling mechanism. EU institutions, Member States, defence ministries, hospitals, energy operators and state-controlled enterprises should commit multiyear purchases from qualified European AI providers, just as defence procurement sustains aerospace capability.

Fourth, Europe needs a late-stage technology sovereignty fund capable of investing tens of billions of euros in firms that have passed startup stage but require global-scale capital. The purpose would not be permanent state ownership; it would prevent publicly supported firms from becoming foreign subsidiaries before they produce strategic value in Europe. Fifth, the Union should create an AI hardware mission integrating accelerator design, chiplets, photonics, packaging, high-bandwidth memory, networking, power electronics and compiler software. Europe will not eliminate foreign hardware dependency by 2031, but it can reduce single-supplier exposure and become indispensable in more parts of the stack. Sixth, defence AI demand should be aggregated across Europe, the UK and willing NATO partners through common interfaces, test ranges, data standards and procurement. Seventh, regulatory timelines should be coupled to operational support: every major compliance obligation imposed on SMEs should be accompanied by accessible testing, compute, templates and technical assistance. Eighth, progress should be measured by physical and commercial outputs—not communications: installed megawatts, accelerator counts, usable GPU hours, European model revenue, public contracts, industrial adoption, defence deployments, scale-up financing and dependency-reduction percentages.

Table 5 — Required European Programme, 2027–2031

Strategic action2031 targetIndicative resource orderLead levelFailure if omitted
Sovereign frontier computeAt least two continental frontier-training clusters plus mission-specific regional clusters€40–60bn public-private capitalEU and major Member StatesPermanent dependence on US or Chinese frontier infrastructure
Strategic AI scale-up fundFinance 20–30 European firms through global expansion€30–50bnEU, EIB and national fundsAcquisition or relocation of Europe’s strongest firms
AI hardware missionEuropean accelerators, interconnects, packaging and compiler stack€20–30bnEU and industrial consortiaContinued single-vendor and export-control exposure
Defence and cyber AI procurementCommon European programmes across command, ISR, cyber and autonomy€20–40bnMember States, EU defence instruments and UK partnershipsFragmented military intelligence and foreign platform dependence
Industrial AI deploymentAI integration across strategic manufacturing, energy and health€25–40bn including procurement and incentivesNational governments and industryProductivity gap widens despite research strength
Trusted cloud and identitySovereign control planes for critical workloads€15–25bnEU and Member StatesCritical services remain exposed to foreign legal and operational control
Talent retentionCompetitive laboratories, visas, equity and research careers€10–15bnEU, states and firmsContinuous migration to US laboratories
Resilient energy and networksDedicated low-carbon power and diverse connectivity for AI clustersInfrastructure-specific, potentially €50bn+States, grids and private operatorsCompute projects delayed by power and permitting bottlenecks

These figures are analytical orders of magnitude rather than existing official appropriations. Their purpose is to reveal the scale required. A European programme below this level may improve research access and adoption without changing the continental balance of power.

Bayesian Outlook: Europe’s Position in 2031

Six competing hypotheses define the five-year outcome. H₁ — Sovereign European Acceleration assumes Gigafactories, national investment, capital-market reform and procurement create a credible European AI stack. H₂ — Regulated Dependency assumes Europe implements strong rules and builds some public infrastructure but remains dependent on foreign chips, cloud and models. H₃ — Franco-British Dual Core assumes France and the United Kingdom become Europe’s principal AI powers while Germany dominates industrial application and the wider EU remains uneven. H₄ — Industrial AI Recovery assumes Europe fails to lead general-purpose models but secures global leadership in manufacturing, defence, energy, robotics and scientific AI. H₅ — Fragmented National Competition assumes Member States duplicate programmes, compete for data centres and fail to aggregate demand. H₆ — Strategic Marginalisation assumes capital, talent and platforms continue moving outward, leaving Europe primarily a regulated customer market.

The baseline assessment assigns 12% to H₁, 33% to H₂, 19% to H₃, 21% to H₄, 10% to H₅ and 5% to H₆. The modal outcome is therefore not collapse but regulated dependency. Europe is likely to possess substantial AI capacity, strong safety institutions and several competitive national ecosystems while remaining dependent at the decisive layers of accelerators, hyperscale cloud, frontier-model capital and defence integration. A successful European intervention would shift probability from H₂ and H₅ toward H₁ and H₄. France has the highest probability of becoming a continental full-stack nucleus; the UK has the strongest venture and research position; Germany has the greatest industrial deployment potential; Italy possesses the most underexploited strategic geography and domain opportunity. None can independently close the gap. The relevant sovereign unit is a European coalition capable of combining French energy and central mobilisation, British venture and research, German industry and manufacturing, Italian Mediterranean infrastructure and aerospace-defence capacity, Nordic electricity, Dutch semiconductor equipment, Belgian research, and the scale of the EU market.

Table 6 — Competing Hypotheses for Europe in 2031

HypothesisCentral outcomeProbabilityPrincipal evidenceCritical signpost
H₁ — Sovereign European AccelerationEurope develops credible compute, model, hardware and cloud autonomy12%Gigafactories, EuroHPC, national programmes and industrial baseMajor facilities operational by 2028 with European anchor customers
H₂ — Regulated DependencyStrong regulation, partial infrastructure, persistent foreign control of core stack33%Current cloud, chip, capital and model concentrationEU adoption rises but foreign providers retain dominant market share
H₃ — Franco-British Dual CoreFrance and UK lead, Germany specialises, EU remains uneven19%French infrastructure drive and UK execution modelJoint European projects form around Paris–London rather than EU-wide integration
H₄ — Industrial AI RecoveryEurope leads in domain-specific and cyber-physical AI21%Manufacturing, defence, energy, health and robotics strengthsEuropean firms capture global industrial AI platforms and standards
H₅ — Fragmented National CompetitionDuplicate projects and insufficient continental scale10%National investment rivalry and procurement fragmentationMultiple subscale facilities with low utilisation or foreign tenants
H₆ — Strategic MarginalisationEurope becomes primarily a regulated consumer market5%Capital and talent outflow, slow compute deploymentNo globally scaled European AI firms by 2030

Final Strategic Judgement

Europe’s most dangerous illusion would be to confuse the publication of a plan with the acquisition of capability. The EU has correctly identified compute, data, skills, adoption and regulation as strategic pillars. France, the United Kingdom, Germany and Italy have all moved beyond the passive posture of the early 2020s. Yet the competitive reference point is not Europe’s previous investment level. It is the speed at which the United States and China are integrating energy, semiconductors, capital, cloud, models, industrial deployment and national security. Against that reference, Europe remains profoundly behind at the layers that define real digital borders. It controls rules more effectively than compute; it controls market access more effectively than platforms; it produces research more effectively than global firms; and it distributes programmes more effectively than it concentrates strategic force.

The appropriate conclusion is not deregulation at any cost. European rights and safety rules are strategic assets because societies cannot remain free if AI power becomes unaccountable. The required correction is to place industrial and security execution on the same political level as regulation. Europe must regulate what it can build, build what it must defend and defend what its citizens cannot live freely without. The success criterion for 2031 is not whether the Union can declare itself an “AI continent.” It is whether Europe can independently train or adapt strategically important models, operate critical cloud and identity functions, replace disrupted hardware and software, defend infrastructure at machine speed, procure European systems at scale and preserve democratic control when external providers are unavailable. Anything less is digital sovereignty in legal form but dependency in operational reality.

Figure 1: European AI Sovereignty Outlook, 2027–2031

Figure 1: European AI Sovereignty Outlook, 2027–2031
Current-policy trajectory · Analytical indices, not official forecasts

Pillar III — Governance, Deterrence and Human Freedom: Regulatory Power, Infrastructure Resilience and the Preservation of Human Agency, 2027–2031

The Governance–Operations Gap

The defining governance problem of the 2027–2031 period will not be the absence of rules but the widening temporal, technical and jurisdictional gap between the speed at which rules are created and the speed at which digital systems mutate. Regulation proceeds through consultation, legislation, delegated acts, standards, conformity assessment, national transposition, supervisory interpretation and judicial review. Operational cyber conflict proceeds through automated scanning, credential theft, software updates, model replication, supply-chain compromise and infrastructure rerouting measured in seconds, hours or days. This asymmetry creates a persistent zone in which activities may be technologically possible, strategically consequential and socially harmful before regulators possess reliable categories for describing them. The European Union Artificial Intelligence Act establishes a comprehensive risk-based system covering prohibited practices, high-risk applications, transparency obligations, general-purpose AI models, market surveillance and enforcement, while extending its scope to third-country providers and deployers when their output is used in the Union. Regulation (EU) 2024/1689 Laying Down Harmonised Rules on Artificial Intelligence – European Parliament and Council – June/July 2024. Its institutional significance is considerable, but formal compliance cannot by itself determine whether a deployed model remains safe after fine-tuning, tool integration, retrieval augmentation, adversarial manipulation or a major change in operating context. A model classified and evaluated for one purpose may later be connected to administrative databases, infrastructure controls, biometric systems or autonomous agents whose cumulative authority was never tested as a single system. The relevant object of governance is therefore shifting from the model to the socio-technical decision chain: data acquisition, model inference, human interpretation, automated action, appeal, correction and downstream physical effect. Through 2031, the central regulatory challenge will be to control systems that are continuously updated, distributed across jurisdictions and composed from multiple providers without freezing beneficial innovation. Governance will fail where it treats compliance documentation as evidence of operational safety, confuses legal accountability with technical controllability or assumes that a human nominally “in the loop” possesses sufficient time, knowledge and authority to reverse a machine-generated decision.

The operational gap is widened by uneven institutional capacity. Large cloud providers, defence establishments, intelligence agencies and highly regulated infrastructure operators may possess continuous monitoring, red teams, secure development pipelines and specialised legal counsel. Municipalities, hospitals, water utilities, small manufacturers and local public administrations often operate legacy systems with limited staffing, fragmented procurement and long replacement cycles. Uniform legal duties therefore enter radically unequal technical environments. The NIS 2 Directive broadens European cybersecurity obligations across essential and important entities, requires governance-level responsibility and establishes risk-management and incident-reporting duties, while the Critical Entities Resilience Directive defines resilience as the ability to prevent, protect against, respond to, resist, mitigate, absorb, accommodate and recover from disruptive incidents. Directive (EU) 2022/2555 on Measures for a High Common Level of Cybersecurity Across the Union – European Parliament and Council – December 2022 and Directive (EU) 2022/2557 on the Resilience of Critical Entities – European Parliament and Council – December 2022. These instruments correctly move beyond narrow technical controls toward management accountability and all-hazards resilience. Nevertheless, implementation quality will depend on whether authorities can identify cross-sector dependencies, assess subcontractors, test recovery under contested conditions and impose meaningful remediation before incidents occur. The strategic risk is a two-speed system: highly visible national operators achieve formal maturity while less visible suppliers, regional authorities and outsourced service providers remain exploitable entry points. Regulation may consequently displace rather than eliminate risk, pushing adversaries toward organisations with the weakest implementation, the least bargaining power and the greatest dependence on external vendors.

Table 1 — Structural Sources of the Governance–Operations Gap

Governance dimensionFormal mechanismOperational realityResulting vulnerability2027–2031 correction
Legislative speedMulti-year lawmaking and consultationModels, exploits and services change monthly or continuouslyRules target obsolete system categoriesTechnology-neutral duties tied to capabilities, authority and consequences
System definitionRegulation of providers, products or declared use casesSystems are assembled dynamically from models, plugins, data and agentsNo actor evaluates the complete decision chainMandatory system-of-systems mapping and change-triggered reassessment
Human oversightHuman approval or supervision requirementOperators face automation bias, alert overload and compressed response windowsNominal oversight without practical controlMeasurable intervention time, competence, authority and override testing
Market surveillancePeriodic audits, incident reports and documentationHarm may emerge gradually or only under adversarial conditionsUnsafe behaviour remains undetected until deployment scale is highContinuous monitoring, red-team evidence and regulator access to telemetry
JurisdictionNational or regional legal authorityCloud, models, data and operators span multiple jurisdictionsConflicting disclosure, localisation and enforcement rulesTrusted-jurisdiction agreements and minimum interoperable safeguards
ProcurementContractual security clausesPublic buyers lack technical leverage or exit capabilityVendor lock-in and unverifiable assurancesStandardised audit rights, portability, key custody and tested exit plans
AccountabilityLiability assigned after harmCausal chains involve providers, integrators, deployers and usersResponsibility becomes fragmentedEx ante allocation of duties across the full lifecycle
Enforcement capacitySupervisory authorities and penaltiesRegulators compete for scarce AI, cloud and cyber expertiseSophisticated operators outpace oversightShared technical laboratories and cross-border supervisory teams

Competing Models of Digital Sovereignty

Digital sovereignty has become a foundational but contested concept because it defines who possesses legitimate authority over data, computation, platforms, identities, infrastructure and information flows. The European Union model combines rights-based regulation, market integration, strategic autonomy and conditional openness. It seeks to constrain high-risk processing, preserve competition, protect personal data and reduce critical dependence without abandoning cross-border interoperability. The AI Act applies risk categories and procedural guarantees; NIS 2 distributes cybersecurity duties across public and private operators; the Critical Entities Resilience Directive integrates physical and non-cyber hazards; and data, platform and cloud policies collectively seek to prevent a small number of external providers from acquiring unreviewable control over public functions. This model treats sovereignty less as complete domestic ownership than as the capacity to impose enforceable legal conditions, obtain technical assurance and preserve alternative options. Its principal strength is the attempt to align technological power with fundamental rights and judicially reviewable rules. Its principal weakness is implementation fragmentation across Member States, authorities and sectoral regimes. A system may simultaneously fall under AI, cybersecurity, data protection, product-safety, competition, sectoral and critical-infrastructure obligations, creating dense coverage but also overlapping responsibilities. The critical question is whether Europe can convert normative sophistication into operational power: sufficient cloud capacity, secure software, semiconductor access, supervisory expertise, incident response and military-civil integration. Without such capability, regulation may protect citizens inside Europe while leaving the underlying technological stack dependent on external suppliers whose strategic decisions are made elsewhere.

China’s official governance model combines technological development, social order, national security, platform responsibility and state-centred cyber sovereignty. The Interim Measures for the Management of Generative Artificial Intelligence Services, effective from 15 August 2023, establish classified and graded supervision, requirements for training data and generated content, protection of personal information, algorithm registration and security assessment, while grounding service obligations in national security, public interests and legally defined content controls. Interim Measures for the Management of Generative Artificial Intelligence Services – Cyberspace Administration of China and Six Other Authorities – July 2023. The State Council Information Office’s white paper describes a model of law-based cyberspace governance integrated with national strategy, public order, digital development and Chinese institutional principles. China’s Law-Based Cyberspace Governance in the New Era – State Council Information Office of the People’s Republic of China – March 2023. This approach can mobilise coordinated regulation, industrial policy and infrastructure investment rapidly, but it assigns the state broader authority to define unacceptable information, security risks and legitimate platform behaviour than the European rights-limiting framework ordinarily permits. Russia’s official doctrine emphasises information sovereignty, resistance to technological dominance, protection of critical information infrastructure and the negotiation of international rules under state-centred UN mechanisms. Presidential Decree No. 213 identifies hostile uses of information and communications technologies, technological monopoly and dependency as threats to international information security and national sovereignty. Foundations of State Policy of the Russian Federation in the Field of International Information Security – President of the Russian Federation – April 2021. These models share concern over external dependency but differ fundamentally on rights, state discretion, platform control and the legitimacy of cross-border information restrictions. By 2031, digital sovereignty will therefore be less a universal norm than a field of geopolitical competition.

Table 2 — Competing Digital-Sovereignty Models

DimensionEuropean UnionChinaRussian FederationLiberal market–security model outside the EU
Primary objectiveRights-compatible strategic autonomy and trusted marketsDevelopment, national security, social order and state authorityInformation sovereignty, security and technological independenceInnovation, national security, sector regulation and private investment
Regulatory centreMultiple independent and governmental authoritiesCentral and sectoral state authoritiesPresidential, governmental and security institutionsSector regulators, executive agencies and courts
AI control logicRisk tiers, prohibited uses, conformity duties and fundamental-rights safeguardsClassified supervision, provider responsibility, security review and content dutiesStrategic control, domestic capability and information-security doctrineStandards, procurement, liability and national-security restrictions
Data philosophyProtected but transferable under legal safeguardsData classified by importance and subject to state security controlsSovereign control and reduced foreign dependencyContractual and sectoral control with security exceptions
Information environmentPluralism constrained by law and platform dutiesState-defined lawful content and social-order requirementsState security and information-space controlBroad expression rights with platform and security regulation
Private-sector roleRegulated market partner and critical-infrastructure operatorInnovation vehicle under state supervisionOperator under sovereignty and security policyPrimary infrastructure owner and innovation driver
Human-freedom safeguardCourts, data protection, due process and fundamental-rights lawStatutory rights within state-defined public-interest limitsConstitutional and statutory protection within security doctrineConstitutional rights, courts and sector-specific protections
Strategic weaknessFragmented enforcement and infrastructure dependencyReduced independent challenge to state or algorithmic decisionsIsolation, technological constraint and broad security discretionCorporate concentration and uneven rights protections

International Cyber Norms and the Limits of Deterrence by Law

International law and voluntary cyber norms provide essential boundaries, but they do not function like automatic technical controls. The United Nations Open-ended Working Group on Security of and in the Use of Information and Communications Technologies 2021–2025 reaffirmed the framework of responsible state behaviour, including international law, voluntary norms, confidence-building measures and capacity-building, and transmitted its final report to the General Assembly in July 2025. Developments in the Field of Information and Telecommunications in the Context of International Security – United Nations Secretary-General and Open-ended Working Group – July 2025. The framework creates political expectations against knowingly damaging critical infrastructure, supports cooperation and recognises the importance of assistance and institutional dialogue. Its value lies in norm consolidation, diplomatic signalling and the creation of standards against which conduct can be judged. Its limitation lies in verification, attribution, divergent legal interpretations and the non-binding character of many commitments. States may agree in principle that critical infrastructure should be protected while disagreeing over whether a particular network operation constitutes espionage, preparatory access, prohibited intervention, use of force or lawful countermeasure. AI further complicates this environment because a cyber operation may be generated, modified or propagated by automated systems whose behaviour was not fully predicted by their operators. Responsibility cannot be evaded merely by claiming automation, but proving the relationship between a state, a proxy, an infrastructure provider and a deployed agent may be difficult. The normative regime must therefore evolve from general principles toward operational understandings on autonomous behaviour, incident communication, evidence preservation and emergency deconfliction.

Deterrence in cyberspace cannot depend exclusively on threatening retaliation. It operates through a portfolio of denial, resilience, attribution, legal exposure, economic restriction, diplomatic isolation, offensive capability and political signalling. NATO treats resilience as an essential basis for credible deterrence and defence under Article 3, defining seven baseline requirements covering government continuity, energy, population movement, food and water, mass casualties, civil communications and transport. NATO also reports that approximately 90% of military transport for large operations is provided by civilian assets, more than 70% of defence satellite communications comes from the commercial sector, around 95% of transatlantic internet traffic crosses undersea fibre-optic networks and roughly 75% of host-nation support depends on local commercial infrastructure and services. Resilience, Civil Preparedness and Article 3 – North Atlantic Treaty Organization – November 2024. These dependencies mean that cyber deterrence is inseparable from private-sector continuity. An adversary may be deterred from attacking a hardened military network yet still gain strategic leverage by disrupting civilian logistics, cloud authentication, energy supply or public confidence. Deterrence by denial therefore requires the ability to sustain essential functions under attack, not merely to prevent penetration. Through 2031, the most credible posture will combine clear political thresholds with ambiguity regarding response options, while preserving explicit prohibitions against autonomous retaliatory decisions. Machines may identify, contain and reconstruct; decisions that impose effects outside the defended environment must remain subject to sovereign human judgement.

Table 3 — Deterrence Instruments and Failure Modes

Deterrence instrumentIntended mechanismEvidence requiredPrincipal weaknessAI-era adaptation
DenialMake attacks unlikely to succeedTechnical resilience and tested recoveryExpensive, incomplete and unevenly implementedAutonomous defence with bounded permissions and verified telemetry
PunishmentThreaten costs greater than expected gainCredible attribution and political resolveAttribution delay and escalation riskProbabilistic attribution with human-controlled response
Public attributionDamage reputation and build coalitionsDeclassifiable technical and intelligence evidenceAdversary denial and proxy insulationStandardised evidence models and synthetic-indicator detection
Sanctions and export controlsRestrict finance, technology and mobilityLegal identification of actors and networksEvasion through intermediaries and third countriesGraph analysis of ownership, compute and payment networks
Criminal prosecutionImpose personal legal riskAdmissible evidence and jurisdictionLimited custody over foreign actorsCoordinated indictments, asset restraint and travel risk
Alliance responseIncrease expected collective costShared thresholds and consultationDifferent national risk tolerancesPre-agreed procedures for machine-speed incidents
Normative isolationDefine conduct as internationally unacceptableBroad diplomatic consensusNon-binding norms and selective interpretationOperational rules for autonomous systems and crisis communication
Offensive counter-capabilityThreaten disruption of adversary systemsSecret access and proportional optionsExposure, collateral damage and reciprocal escalationStrict human authorisation and reversible effects where possible
Societal resilienceReduce political impact of disruptionPublic trust and continuity planningDifficult to measure and sustainAuthenticated communication and disinformation-resistant crisis systems

Critical-Infrastructure Resilience as a Constitutional Function

Critical-infrastructure resilience is often presented as an engineering or emergency-management problem, but by 2031 it will function as a constitutional condition for the continuity of democratic authority. Elections, courts, public administration, healthcare, financial access, telecommunications, water and energy are the practical systems through which rights become exercisable. A citizen cannot meaningfully exercise political freedom when identity services fail, communications are unavailable, payments are frozen, medical records are inaccessible or public information cannot be authenticated. The Critical Entities Resilience Directive requires EU Member States to create strategies, perform risk assessments and identify critical entities whose disruption would significantly affect essential services. Its definition of resilience deliberately extends beyond prevention to absorption, accommodation and recovery, recognising that not all incidents can be stopped. Directive (EU) 2022/2557 on the Resilience of Critical Entities – European Parliament and Council – December 2022. This is strategically important because highly connected systems will inevitably experience failures, attacks and supply interruptions. Governance should therefore measure the duration, geographic reach, population exposure and substitutability of disrupted services rather than relying primarily on the number of blocked intrusions. A state that suffers frequent attempted attacks but preserves essential functions may be more secure than one reporting fewer incidents but lacking tested fallback capacity.

Resilience must also be protected from becoming a justification for unlimited surveillance or centralised control. Emergency continuity systems often involve identity verification, location data, communications prioritisation, financial restrictions and access to private infrastructure. These powers may be necessary during a severe crisis, but they create the risk that exceptional capabilities become permanent or are repurposed for ordinary governance. The correct design principle is rights-preserving resilience: systems should continue essential services while collecting the minimum data necessary, separating emergency authority from routine administration, logging exceptional actions and providing later review. Infrastructure operators should be required to maintain manual or local fallback where technically possible, but fallback cannot mean abandoning cybersecurity or safety. Hospitals may need offline clinical procedures; energy operators may require local control; government may need independent public-warning channels; payment systems may require limited emergency modes. These capabilities must be exercised under realistic conditions involving cyber compromise, disinformation, workforce shortage and vendor unavailability. Resilience is credible only when it has been tested against simultaneous failures rather than documented as separate contingency plans. The 2027–2031 transition should therefore move from entity-by-entity compliance to national essential-function maps showing how energy, communications, cloud, transport, finance, water, food, healthcare and government depend on one another.

RIGHTS-PRESERVING RESILIENCE ARCHITECTURE

[Constitutional and human-rights guarantees]
                    │
                    ▼
[Essential societal functions]
Government │ Health │ Energy │ Water │ Finance │ Communications │ Transport
                    │
                    ▼
[Critical technical dependencies]
Identity │ Cloud │ Cables │ Spectrum │ Satellites │ Software │ Supply chains
                    │
                    ▼
[Resilience controls]
Prevention → Segmentation → Redundancy → Degraded mode → Recovery → Review
                    │
                    ▼
[Rights safeguards]
Necessity │ Proportionality │ Data minimisation │ Time limits │ Audit │ Appeal

Failure pattern to prevent:
Emergency power → opaque automated decision → service exclusion → no explanation
→ no human review → permanent functional loss of a legal right

Table 4 — Essential Functions, Cyber Dependencies and Freedom Impacts

Essential functionCritical digital dependencyFailure modeHuman-freedom consequenceMinimum rights-preserving fallback
Democratic participationElectoral registers, communications and authentic public informationManipulation, denial or synthetic instructionsImpaired voting, assembly and informed choicePaper-verifiable procedures and authenticated public channels
HealthcareIdentity, records, diagnostics, scheduling and supply systemsRansomware, cloud loss or data corruptionDelayed treatment and unequal accessOffline clinical workflows and local patient identification
Financial accessDigital identity, clearing, fraud controls and connectivityAutomated account freeze or payment outageInability to buy essentials or receive incomeLimited-value emergency payment and rapid human appeal
EnergyOT control, communications, forecasting and market systemsGrid disruption or false telemetryLoss of heat, mobility, communications and medical supportIslanding, local control and priority restoration
WaterControl systems, pumps, chemical monitoring and powerLoss of pressure or unsafe dosingDirect health and sanitation impactManual testing, local operation and emergency distribution
JusticeCase systems, evidence, identity and remote accessRecords unavailable or algorithmic biasDelay, unequal process and impaired remedyHuman-reviewed proceedings and preserved evidentiary chain
MobilityTicketing, identification, navigation and traffic managementAutomated exclusion or system outageRestricted movement without formal legal orderAlternative identification and manual authorisation
CommunicationsNetworks, platforms, certificates and spectrumOutage, filtering or identity revocationLoss of expression, association and emergency accessMultiple channels and priority public-service access
Employment and welfareAutomated eligibility, payroll and identity systemsErroneous classification or system denialEconomic exclusion and inability to contest decisionsContinuity payments and accessible human adjudication

Human Agency Under Algorithmic Administration

Human freedom in an AI-saturated society cannot be protected solely by prohibiting a limited set of high-risk technologies. Freedom increasingly depends on whether individuals can understand, challenge and escape automated decisions that mediate employment, welfare, credit, healthcare, education, mobility, policing and access to digital services. The relevant threat is not always dramatic state surveillance or an autonomous machine issuing commands. It is often a distributed sequence of classifications produced by private and public systems: an identity score triggers additional verification; a fraud model freezes a payment; a content system reduces visibility; an insurance model raises a premium; a public-benefit system identifies an inconsistency; an employer’s screening model rejects an application. Each decision may appear administratively modest, yet together they construct a functional digital perimeter around the individual. Legal rights remain formally intact while practical participation becomes conditional on systems that are opaque, difficult to contest and capable of reproducing historical inequality at scale. The AI Act responds to part of this danger by prohibiting selected practices, regulating high-risk systems and requiring transparency, documentation, human oversight and fundamental-rights considerations. Regulation (EU) 2024/1689 Laying Down Harmonised Rules on Artificial Intelligence – European Parliament and Council – June/July 2024. Yet legal safeguards will be effective only when the affected person can identify that automation was involved, obtain a meaningful explanation, reach an empowered human reviewer and secure correction before the harm becomes irreversible.

“Human in the loop” is therefore an insufficient governance formula. The human may lack time, expertise, alternative data or institutional authority; may be evaluated on conformity with algorithmic recommendations; or may approve hundreds of outputs without genuine review. Meaningful human agency requires at least six properties: notice, so the person knows an automated system materially influenced the decision; intelligibility, so the decisive factors can be understood without revealing every proprietary detail; contestability, so evidence can be challenged; authority, so a reviewer can reverse the result; timeliness, so remedy occurs before essential rights are lost; and non-retaliation, so challenging an algorithm does not itself create disadvantage. For infrastructure and security systems, human agency also requires the ability to interrupt automated action. A nominal override that takes longer to execute than the machine’s action cycle is not an effective safeguard. By 2031, rights law will increasingly need to evaluate not only the legality of data processing but the architecture of decision control: who sets objectives, which system selects evidence, how confidence is represented, when automation stops and how responsibility is allocated. Freedom in the machine-speed environment will depend on preserving zones where a person can demand individual judgement rather than being treated exclusively as a statistical instance.

Table 5 — Human Agency Control Test

Control propertyMinimum requirementFalse-compliance patternHigh-assurance standard
NoticeInform the individual when AI materially affects a decisionGeneric privacy statement with no decision-specific noticeClear notice at the point of consequence
IntelligibilityExplain decisive factors and applicable rulesTechnical model description unrelated to the individual outcomeCase-specific reasons understandable to the affected person
ContestabilityPermit submission of corrections and counter-evidenceComplaint form with no access to evidenceStructured challenge with disclosure of relevant inputs
Human authorityReviewer can alter the outcomeReviewer merely confirms the system recommendationIndependent reviewer with actual reversal power
TimelinessReview occurs before or rapidly after harmAppeal completed after job, payment or care is lostEmergency suspension and priority adjudication
Data correctionInaccurate inputs can be identified and fixedCorrection in one database but not linked systemsPropagated correction with audit confirmation
Non-discriminationTest outcomes across affected groups and contextsAggregate accuracy conceals subgroup harmContinuous impact monitoring and remediation
System exitProvide alternative path where justifiedDigital-only process with no viable alternativeProportionate non-automated pathway for essential services
AccountabilityIdentify responsible legal and operational actorsResponsibility divided among vendor and deployerNamed accountable authority across the full decision chain

Security, Surveillance and the Risk of Permanent Emergency

Cyber conflict creates strong incentives for governments and operators to collect more telemetry, retain more data, authenticate more behaviour and deploy increasingly predictive systems. These measures can strengthen defence, but they also alter the balance between security and freedom. Continuous behavioural analysis may identify compromised accounts, insider threats or coordinated influence operations; the same capability can map political association, workplace conduct, travel, communications and dissent. The strategic danger is not that all security monitoring is illegitimate, but that purpose boundaries erode under crisis pressure. Systems introduced to protect critical infrastructure may become available for law enforcement, migration control, taxation, welfare enforcement or political monitoring without equivalent public debate. AI magnifies this risk because it can transform previously unmanageable datasets into actionable profiles. The Office of the United Nations High Commissioner for Human Rights has emphasised that algorithmic profiling used by law enforcement must comply with international human-rights law and should be governed by measures protecting equality, liberty, privacy, movement, assembly, association, presumption of innocence and effective remedy. Racial Discrimination and Emerging Digital Technologies: Human Rights Analysis of Algorithmic Profiling – Office of the United Nations High Commissioner for Human Rights – 2020. Although this guidance predates current generative and agentic systems, its core principle becomes more important as predictive tools gain broader access and greater autonomy.

The governance response must distinguish situational awareness from unrestricted social visibility. Security systems should collect data proportionate to a defined threat model, restrict reuse, separate identities where full attribution is unnecessary and maintain independent oversight. Emergency expansions of access should contain expiration dates, review procedures and technical mechanisms that actually disable the exceptional capability when authority ends. Audit logs must themselves be protected from alteration and should record who accessed data, for what purpose and under which legal authority. AI-generated inferences should not be treated as equivalent to verified facts, particularly when they produce coercive consequences. The preservation of democratic freedom also requires pluralism in technical infrastructure. When one identity provider, cloud platform or communications intermediary can exclude a person from multiple services, private terms of service acquire quasi-constitutional effects. Governments will face pressure to designate certain digital functions as essential facilities subject to continuity, due process and non-discrimination obligations. By 2031, the boundary between public law and platform governance will become one of the central legal questions of the digital state. Human freedom will depend not only on limiting state surveillance but on preventing concentrated private infrastructure from exercising unreviewable control over civic existence.

Institutional Deterrence and Democratic Trust

Trust is an operational security resource because citizens must believe official warnings, comply with emergency instructions, report anomalies and accept temporary disruptions during recovery. An adversary does not need to defeat every technical control if it can convince the population that authorities are concealing failures, manipulating evidence or using an incident to expand power. Governance must therefore treat transparency as part of deterrence rather than as a post-crisis public-relations function. Authorities should publish incident categories, explain uncertainty, distinguish verified facts from hypotheses and correct errors visibly. Overconfidence is especially dangerous in AI-assisted attribution, where models may identify correlations that appear precise but are based on incomplete or adversary-manipulated data. Governments must communicate probability and alternatives without paralysing decision-making. The United Nations cyber process provides a diplomatic foundation for confidence-building, assistance and regular dialogue, but national legitimacy will depend on whether domestic institutions demonstrate competence and restraint. Final Report of the Open-ended Working Group on Security of and in the Use of Information and Communications Technologies 2021–2025 – United Nations – July 2025. Confidence-building measures should therefore operate at three levels: interstate communication to avoid misinterpretation, government–industry coordination to sustain services, and government–citizen communication to preserve social cohesion.

Democratic deterrence differs from authoritarian control because it must remain legitimate under scrutiny. The state must show that emergency powers are limited, errors are correctable and security policy does not eliminate the freedoms it is intended to defend. This requires independent regulators, courts, parliamentary oversight, protected journalism, technical civil society and access to evidence. Excessive secrecy may protect operational methods while weakening public confidence; excessive disclosure may reveal vulnerabilities and intelligence sources. The appropriate balance is structured transparency: publish legal authorities, oversight findings, aggregate incident data, rights-impact assessments and remediation commitments while protecting tactical details. Private companies controlling cloud, satellite, identity and platform systems should also face transparency duties proportionate to their systemic role. Through 2031, democratic societies will compete not only on defensive capability but on whether their governance model can combine speed with accountability. A system that responds slowly may fail to protect citizens; a system that responds instantly but without contestability may destroy trust. The strategic objective is constitutional velocity—the ability to make rapid, technically informed decisions while preserving legality, review and human control.

Five-Year Outlook and Analysis of Competing Hypotheses

The governance trajectory through 2031 can be organised around six competing hypotheses. H₁ — Rights-Compatible Resilience assumes that democratic states successfully combine AI regulation, critical-infrastructure investment, bounded automation, judicial oversight and public accountability. H₂ — Regulatory Lag and Symbolic Compliance assumes that formal requirements expand but organisations optimise for documentation while operational risk grows faster than supervision. H₃ — Sovereign Digital Fragmentation assumes that incompatible data, identity, cloud, content and cybersecurity regimes divide the internet into politically aligned systems. H₄ — Permanent Security Exceptionalism assumes repeated cyber crises normalise surveillance, emergency powers and automated exclusion. H₅ — Corporate Quasi-Sovereignty assumes dominant infrastructure providers acquire greater practical authority over identity, computation, speech and service continuity than many states. H₆ — Coordinated Democratic Deterrence assumes alliances integrate resilience, attribution, sanctions, private infrastructure and rights safeguards into a credible collective framework. The hypotheses overlap: regulatory lag can coexist with sovereign fragmentation, while democratic deterrence can coexist with corporate concentration. A structured Bayesian assessment gives the highest 2031 probability to a mixed outcome dominated by H₂ and H₃ rather than a clean success or collapse. The legal architecture is expanding, but uneven implementation, private dependency and rapid technical change reduce the probability of comprehensive control.

Indicative updated probabilities are 22% for H₁, 27% for H₂, 21% for H₃, 10% for H₄, 9% for H₅ and 11% for H₆. These are analytical estimates rather than official forecasts. A 70,000-path Monte Carlo stress model varying regulatory implementation, supervisory competence, infrastructure concentration, geopolitical conflict, public trust, emergency-power duration and appeal effectiveness produces a 64% median probability that at least one major jurisdiction will experience a serious mismatch between formally compliant AI or cyber governance and actual operational harm before 2031. The model produces a 48% probability of significant fragmentation across cloud, identity or data regimes; a 37% probability that a severe cyber incident triggers temporary emergency digital controls affecting a large civilian population; a 19% probability that some emergency controls persist beyond their original necessity; and a 12% probability of a major public legitimacy crisis caused by opaque automated decisions during infrastructure disruption. The most influential risk reducers are independent supervisory capacity, tested service fallback, rapid human appeal, diversified infrastructure and statutory expiration of emergency powers. The strongest risk multipliers are identity concentration, opaque public-private decision authority, political polarisation and repeated incidents that normalise exceptional measures.

Table 6 — Analysis of Competing Hypotheses, 2031

HypothesisCentral claimEvidence supportingEvidence weakeningUpdated probability
H₁ — Rights-Compatible ResilienceRegulation and infrastructure investment preserve security and agencyAI Act, NIS 2, CER, judicial safeguards and resilience planningUneven implementation and legacy systems22%
H₂ — Regulatory Lag and Symbolic ComplianceDocumentation grows faster than operational controlRapid model evolution, fragmented supervision and vendor opacityIncreasing enforcement and technical standards27%
H₃ — Sovereign Digital FragmentationMajor powers build incompatible governance and infrastructure zonesDivergent EU, Chinese and Russian doctrinesEconomic interdependence and global standards21%
H₄ — Permanent Security ExceptionalismTemporary cyber powers become normal governanceRecurrent crises and surveillance incentivesCourts, legislatures and expiration requirements10%
H₅ — Corporate Quasi-SovereigntyInfrastructure firms exercise constitutional-scale powerCloud, identity, platform and satellite concentrationPublic procurement, regulation and sovereign investment9%
H₆ — Coordinated Democratic DeterrenceAlliances combine resilience, attribution and rightsNATO resilience, EU regulation and UN dialogueDivergent national thresholds and private dependency11%

Table 7 — Governance and Freedom Timeline, 2027–2031

YearGovernance milestoneOperational pressureHuman-freedom riskStrategic test
2027Full-scale implementation of major AI and cyber dutiesCompliance capacity shortages and system-classification disputesAutomated decisions governed by incomplete proceduresCan regulators inspect real systems rather than documents?
2028Expansion of sovereign cloud, identity and infrastructure programmesCross-border legal conflict and vendor concentrationAccess to services becomes tied to fewer identity systemsAre viable non-automated and alternative-provider paths preserved?
2029Wider deployment of autonomous defensive and administrative agentsMachine-speed action exceeds appeal and oversight capacityHuman review becomes nominalCan individuals and operators stop or reverse automated action rapidly?
2030Trusted digital blocs deepen interoperability internallyExternal fragmentation in data, platforms and security standardsReduced information and service portability across blocsCan sovereignty coexist with lawful openness and pluralism?
2031Digital governance becomes core national-security architectureContinuous grey-zone conflict and persistent emergency readinessExceptional controls become structurally embeddedDo constitutional safeguards remain effective under permanent pressure?

Strategic Design for 2031

A governance system capable of surviving the next five years must be designed around operational consequences rather than institutional labels. First, high-impact systems should be mapped as end-to-end decision chains, including data sources, models, human roles, tools, infrastructure dependencies, appeal routes and physical consequences. Second, regulation should trigger reassessment whenever authority, context or connectivity materially changes, not only when a product is initially placed on the market. Third, critical services should maintain tested degraded modes that do not depend on a single cloud identity, AI model, network route or foreign support channel. Fourth, autonomous systems should operate under explicit authority budgets defining which actions, values, populations and time periods they may affect. Fifth, every essential-service decision producing exclusion, coercion or significant deprivation should remain contestable through an empowered human process. Sixth, emergency digital powers should expire automatically unless renewed through a transparent legal procedure. Seventh, infrastructure providers whose decisions have society-wide effects should accept public-interest duties concerning continuity, auditability, non-discrimination and government access under lawful emergency conditions. Eighth, international deterrence should integrate resilience and rights: a society that can preserve services, provide truthful information and correct mistakes denies adversaries the political effects they seek.

The final strategic conclusion is that human agency will not survive through declarations alone. It must be engineered into identity systems, administrative procedures, cloud contracts, AI interfaces, infrastructure recovery and constitutional oversight. Freedom in 2031 will be measured by whether an individual can remain economically, politically and socially active when an algorithm is wrong, a network is disrupted, a provider withdraws service or a government invokes emergency authority. The secure society is not the one that automates every decision or collects every signal. It is the one that can distinguish where speed is indispensable from where deliberation is a democratic necessity. Governance must therefore preserve three non-delegable human functions: defining legitimate political objectives, authorising coercive or retaliatory action and adjudicating contested individual rights. AI can support each function but should not acquire final authority over them. Deterrence must protect infrastructure without normalising permanent war logic. Sovereignty must create resilience without producing isolation. Regulation must reduce risk without becoming ceremonial documentation. The outcome of this balance will determine whether virtual borders protect free societies or become invisible mechanisms of confinement.

Figure 1: Governance, Resilience and Human-Agency Projection, 2027–2031

Figure 1: Governance, Resilience and Human-Agency Projection
Baseline implementation scenario · Analytical indices, not official forecasts

Copyright of debuglies.com – Even partial reproduction of the contents is not permitted without prior authorization – Reproduction reserved

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Questo sito utilizza Akismet per ridurre lo spam. Scopri come vengono elaborati i dati derivati dai commenti.