Skip to content
EU Parl Watch

Changes between two versions

What changed between the plenary report and the adopted text

From · plenary report· 20 Jul 2026

A-10-2026-0212

on Hybrid warfare and the protection of the EU’s territorial integrity and critical security and defence infrastructure

To · adopted text· 16 Sept 2026

TA-10-2026-0303

Hybrid warfare and the protection of the EU’s territorial integrity and critical security and defence infrastructure

AI:What changed, in short

Parliament adds a recital and a paragraph describing recent hybrid attacks, including incidents attributed to Russia and the assault on Ceuta, and calls for an independent investigation into the latter.17 It also welcomes the completion of the cyber coordination centre project and progress towards a permanent EU Cyber Defence Coordination Centre, and calls for its swift operationalisation.34 The other changes are formal: a recital letter and decimal separator are updated and footnote markers are removed.256

4 changes of substance · 3 formal · 0 of wording only

Written by AI from the two texts only · read the changes before relying on it · 17 Sept 2026 · Report a problem

+7 added · −19 removed · 14 changed paragraphs, packaging included.

Part 1 of 4: MOTION FOR A EUROPEAN PARLIAMENT RESOLUTION

Removed:MOTION FOR A EUROPEAN PARLIAMENT RESOLUTION

Added:P10_TA(2026)0303

Changed:on Hybrid warfare and the protection of the EU’s territorial integrity and critical security and defence infrastructure

Removed:(2026/2024(INI))

Added:Committee on Security and Defence

Added:PE788.818

Added:European Parliament resolution of 16 September 2026 on Hybrid warfare and the protection of the EU’s territorial integrity and critical security and defence infrastructure (2026/2024(INI))

7 unchanged paragraphs

The European Parliament,

– having regard to the UN Charter and the fundamental principles of international law,

– having regard to Title V of the Treaty on European Union (TEU), in particular Chapter Two, Section Two thereof on provisions on the common security and defence policy,

– having regard to the Treaty on the Functioning of the European Union (TFEU),

– having regard to Articles 42(7) and 222 TEU,

– having regard to its previous resolutions on Ukraine, Russia and Belarus, in particular those adopted since Russia’s annexation of the Crimean Peninsula in February 2014 and Russia’s full-scale invasion of Ukraine in February 2022,

– having regard to the international legal framework for preventing and fighting terrorism, including UN Security Council Resolution 2341 on protection of critical infrastructure against terrorist acts, adopted on 13 February 2017,

Changed:– having regard to Regulation (EU) 2019/452 of the European Parliament and of the Council of 19 March 2019 establishing a framework for the screening of foreign direct investments into the Union1,Union,

– having regard to the ‘Strategic Compass for Security and Defence – For a European Union that protects its citizens, values and interests and contributes to international peace and security’, approved by the Council on 21 March 2022 and endorsed by the European Council on 25 March 2022,

– having regard to the Council conclusions of 21 June 2022 on a framework for a coordinated EU response to hybrid campaigns,

Changed:– having regard to Directive (EU) 2022/2557 of the European Parliament and of the Council of 14 December 2022 on the resilience of critical entities and repealing Council Directive 2008/114/EC2,2008/114/EC,

– having regard to the Final Assessment Report of 29 June 2023 by the NATO-EU Task Force on the Resilience of Critical Infrastructure,

– having regard to the report of 30 October 2024 by Sauli Niinistö entitled ‘Safer Together – Strengthening Europe’s Civilian and Military Preparedness and Readiness’ (Niinistö report),

– having regard to the Commission communication of 11 December 2024 on countering hybrid threats from the weaponisation of migration and strengthening security at the EU’s external borders (COM(2024)0570),

Changed:– having regard to Regulation (EU) 2025/37 of the European Parliament and of the Council of 19 December 2024 amending Regulation (EU) 2019/881 as regards managed security services3,services,

Changed:– having regard to Regulation (EU) 2025/38 of the European Parliament and of the Council of 19 December 2024 laying down measures to strengthen solidarity and capacities in the Union to detect, prepare for and respond to cyber threats and incidents and amending Regulation (EU) 2021/694 (Cyber Solidarity Act)4,Act),

– having regard to the joint communication from the Commission and the High Representative of the Union for Foreign Affairs and Security Policy of 21 February 2025 entitled ‘EU Action Plan on Cable Security’ (JOIN(2025)0009),

Changed:– having regard to its resolution of 12 March 2025 on the white paper on the future of European defence5,defence,

4 unchanged paragraphs

– having regard to the joint white paper from the Commission and the High Representative of the Union for Foreign Affairs and Security Policy of 19 March 2025 entitled ‘Joint White Paper for European Defence Readiness 2030’ (JOIN(2025)0120),

– having regard to the joint communication from the Commission and the High Representative of the Union for Foreign Affairs and Security Policy of 26 March 2025 on the European Preparedness Union Strategy (JOIN(2025)0130)),

– having regard to the Commission communication of 1 April 2025 to the European Parliament, the Council, the European Economic and Social Committee and the Committee of the Regions on ProtectEU: a European Internal Security Strategy (COM(2025)0148),

– having regard to the Declaration of the North Atlantic Council Summit in The Hague, adopted by the Heads of State and Government participating in the meeting of the North Atlantic Council on 25 June 2025,

Changed:– having regard to its resolution of 9 October 2025 on a united response to recent Russian violations of the EU Member States’ airspace and critical infrastructure6,infrastructure,

– having regard to the non-paper of November 2025 by the Italian Minister of Defence entitled ‘Countering hybrid warfare: an active strategy’,

– having regard to the Commission proposal of 10 December 2025 for guidelines for trans-European energy infrastructure (COM(2025)1006),

Changed:– having regard to its resolution of 18 December 2025 on the continuous Belarusian hybrid attacks against Lithuania7,Lithuania,

– having regard to the Commission communication of 18 February 2026 on the EU’s eastern regions bordering Russia, Belarus and Ukraine (COM(2026)0082),

Changed:– having regard to its resolution of 21 January 2026 on the implementation of the common security and defence policy – annual report 20258,2025,

– having regard to the Council conclusions of 16 March 2026 on advancing the European Union’s capacity to counter hybrid threats,

– having regard to Rule 55 of its Rules of Procedure,

– having regard to the report of the Committee on Security and Defence (A10-0212/2026),

Added:– having regard to the Declaration of the North Atlantic Council Summit adopted by the Heads of State and Government participating in the meeting of the North Atlantic Council in Ankara on 8 July 2026,

4 unchanged paragraphs

A. whereas the intensity and scope of hybrid attacks against the EU have escalated significantly since the start of Russia’s war of aggression against Ukraine, with incidents repeatedly linked to authoritarian states, notably Russia, Belarus, China, Iran and North Korea;

B. whereas Russia constitutes the primary and most significant security threat to the EU and its Member States; whereas Russia has persistently violated the principle of territorial integrity and political independence set forth in Article 2(4) of the UN Charter; whereas hybrid attacks represent a threat to democracy in the EU and its Member States;

C. whereas the severity of these attacks has increased drastically and constitute a blatant violation of Member States’ sovereignty, the EU’s territorial integrity and international law; whereas hybrid warfare has become a structural feature of the current geopolitical environment;

D. whereas recent hybrid attacks can include unauthorised drone incursions, ‘smuggling balloons’, airspace violations, clandestine tunnels for infiltration and smuggling, sabotage of and espionage targeting critical security and defence infrastructure, the sabotage of undersea cables and energy infrastructure, GPS jamming and navigation spoofing, cyberattacks, arson and assassination plots, the instrumentalisation of migration and organised crime, elite capture, covert foreign investment, economic coercion, data exfiltration and other acts of political subversion and economic penetration, foreign information manipulation and interference (FIMI), and interference in political and electoral processes;

Change 1

Added:E. whereas, in the summer of 2026, the EU witnessed an intensification of physical hybrid activities and attacks across EU territory; whereas this included an attempted explosive drone attack targeting Ukrainian cargo aircraft at Leipzig/Halle Airport in Germany, an attempted attack by an explosive-laden maritime drone against a Romanian offshore gas project, a foiled Russian-directed sabotage and espionage plot targeting military infrastructure and Ukrainian cargo aircraft in Romania, an arson attack targeting a defence contractor in Estonia, deliberate sabotage and arson attacks targeting defence and drone manufacturing facilities in Poland, a Russian cruise missile violating Polish airspace and crashing in the Lublin region, and a foiled arson plot in Slovakia targeting a Ukrainian drone manufacturer; whereas the Leipzig/Halle Airport attack, the targeting of the Romanian offshore gas project and the sabotage plot targeting military infrastructure and Ukrainian cargo aircraft in Romania have been publicly attributed to Russia by the respective national authorities; whereas following the attack on Leipzig/Halle Airport, the German authorities closed the Russian consulate in Bonn and the Russian House in Berlin;

7 unchanged paragraphs

F. whereas the sovereignty and territorial integrity of all Member States are foundational principles of the EU; whereas hostile state actors, in particular Russia, target the EU’s territorial integrity on two fronts: through direct physical attacks against Member States and through influence operations aimed at undermining the unity of the EU, by engineering Member States’ withdrawal from the EU;

G. whereas hybrid threats increasingly affect the EU as a whole, including overseas countries and territories such as Greenland, but the EU’s external border regions and the EU’s maritime areas are particularly susceptible to attacks; whereas these attacks also target candidate countries and EU neighbours, notably Ukraine, Moldova, Armenia, Georgia and the Western Balkans; whereas the territorial integrity of the EU’s neighbourhood is key to ensure peace, stability and security in Europe and the wider world;

H. whereas interference in Greenland by non-EU countries, notably inflammatory narratives and the conduct of hybrid actions on Greenland’s territory, as well as the US Government’s formulation of explicit threats against Greenland’s sovereignty, have raised concerns regarding Greenland’s sovereignty and territorial integrity;

I. whereas Georgia is an example of successful Russian hybrid interference resulting in Kremlin-aligned Georgian Dream-led authorities replicating Russia’s playbook of hybrid operations against Georgia’s own civil society and democratic institutions;

J. whereas sabotage activities by Russian intelligence are increasingly being carried out using intermediaries, vulnerable social groups, including underaged persons, proxies and ‘disposable agents’, thereby complicating attribution and response; whereas religious institutions, including the Russian Orthodox Church and networks linked to the Muslim Brotherhood, have been exploited to conduct interference operations in the EU, undermining democratic values, the rule of law and the EU’s ability to defend itself;

K. whereas these attacks aim not only to create chaos and destabilise the EU Member States, but also to undermine democratic integrity, manipulate decision-making processes, deepen political divisions, weaken social cohesion, sow fear and public distrust among EU citizens, and weaken defence readiness and the EU’s support for Ukraine, generating cascade effects across the EU;

L. whereas the invocation of NATO Article 5 following the 9/11 terrorist attacks demonstrates that collective defence can be triggered following attacks not only by the actions of a state actor but also by attacks involving non-state actors and complex networks operating across national borders; whereas this precedent highlights the evolving nature of security threats and the need to adapt collective response mechanisms accordingly, including with improved common standards and procedures for attribution;

Change 2

Changed:L.M. whereas there has been a drastic increase in cognitive warfare together with FIMI; whereas, according to the European External Action Service (EEAS) 4th Annual Report on FIMI Threats, Russian FIMI activity is expected to intensify in 2026, with the budget for state-controlled media projected to reach approximately EUR 1.561,56 billion, 7 % higher than in 2025, with the Baltic Sea and Arctic regions anticipated to be among the primary targets;

8 unchanged paragraphs

N. whereas FIMI operations use sophisticated cognitive-psychological methods, including reflexive control, a technique rooted in Soviet military theory that introduces specific informational inputs to limit a target’s perceived choices and steer decisions toward the influencer’s strategic goals;

O. whereas Russia’s 2015 and 2021 national security strategies frame the promotion of so-called traditional values and the ‘Russian World’ as instruments of its broader hybrid warfare strategy and geopolitical influence; whereas Russia has strategically deployed historical, religious, cultural and values-based narratives as part of its hybrid warfare strategy to influence public discourse, and ecclesiastical dynamics, weaken social cohesion, and undermine democratic resilience and Transatlantic integration;

P. whereas the transversal nature of the cognitive domain requires cognitive indicators to be fully integrated into the common operational picture used by cyber, intelligence, law enforcement, military and critical infrastructure structures;

Q. whereas the success of modern military operations and the effectiveness of public institutions increasingly depend on the control of cyberspace and on the strategic use of digital resources and information systems;

R. whereas internal security remains a responsibility of the Member States, although the cross-border, interconnected and multi-dimensional nature of those hybrid attacks requires strengthened cooperation, systematic information sharing and coordinated action at EU level, supported by adequate funding and complemented by long-term strategies to strengthen societal resilience and protect institutional integrity;

S. whereas EU Justice and Home Affairs (JHA) agencies have a key role to play in cooperation with national authorities, in establishing and maintaining common situational awareness of risks related to such threats and in assisting front-line Member States in crisis situations; whereas the Commission has included the strengthening of the European Border and Coast Guard Agency (Frontex) in its flagship initiatives for the 2024-2029 legislative terms, as well as a revision of the mandates of European Union Agency for Law Enforcement Cooperation (Europol) and European Union Agency for Criminal Justice Cooperation (Eurojust); whereas other initiatives such as the ‘Eastern Flank Watch’ may contribute to strengthening the protection of the external borders and increasing resilience against hybrid threats;

T. whereas the emergence of advanced AI systems represents a structural disruption to existing cybersecurity architectures, invalidating threat models and defensive assumptions developed over previous decades; whereas hostile state and non-state actors are already exploiting AI capabilities to increase the speed, scale and precision of hybrid operations, including cyber intrusions, AI poisoning, disinformation campaigns and critical infrastructure targeting; whereas the EU’s collective cyber resilience frameworks must be adapted to address these new vulnerabilities;

U. whereas despite the significant efforts undertaken by Member States, and the development of tools and mechanisms to counter hybrid threats, the EU’s response to hybrid attacks continues to suffer from legislative gaps, the lack of a harmonised approach among Member States, differing levels of awareness, and the absence of a dedicated structure or entity to monitor such attacks; whereas as a consequence, despite the urgency, EU Member States have yet to develop a fully coordinated and coherent response to hybrid warfare both individually, at European level and, where relevant, with NATO;