Skip to content
EU Parl Watch

Changes between two versions

What changed between the draft committee report and the plenary report

From · draft committee report· 8 May 2026

SEDE-PR-788818

on hybrid warfare and the protection of the EU’s territorial integrity and critical security and defence infrastructure

To · plenary report· 20 Jul 2026

A-10-2026-0212

on Hybrid warfare and the protection of the EU’s territorial integrity and critical security and defence infrastructure

These two texts have too little in common to compare paragraph by paragraph: they are different documents rather than versions of one (for example one group’s motion and the joint text that was adopted).

+137 added · −29 removed · 13 changed paragraphs, packaging included.

Part 1 of 5: MOTION FOR A EUROPEAN PARLIAMENT RESOLUTION

MOTION FOR A EUROPEAN PARLIAMENT RESOLUTION

Changed:on hybridHybrid warfare and the protection of the EU’s territorial integrity and critical security and defence infrastructure

(2026/2024(INI))

The European Parliament,

– having regard to the UN Charter and the fundamental principles of international law,

Removed:– having regard to the Treaty on the Functioning of the European Union (TFEU),

– having regard to Title V of the Treaty on European Union (TEU), in particular Chapter Two, Section Two thereof on provisions on the common security and defence policy,

Added:– having regard to the Treaty on the Functioning of the European Union (TFEU),

5 unchanged paragraphs

– having regard to Articles 42(7) and 222 TEU,

– having regard to its previous resolutions on Ukraine, Russia and Belarus, in particular those adopted since Russia’s annexation of the Crimean Peninsula in February 2014 and Russia’s full-scale invasion of Ukraine in February 2022,

– having regard to the international legal framework for preventing and fighting terrorism, including UN Security Council Resolution 2341 on protection of critical infrastructure against terrorist acts, adopted on 13 February 2017,

– having regard to Regulation (EU) 2019/452 of the European Parliament and of the Council of 19 March 2019 establishing a framework for the screening of foreign direct investments into the Union1,

– having regard to the ‘Strategic Compass for Security and Defence – For a European Union that protects its citizens, values and interests and contributes to international peace and security’, approved by the Council on 21 March 2022 and endorsed by the European Council on 25 March 2022,

Added:– having regard to the Council conclusions of 21 June 2022 on a framework for a coordinated EU response to hybrid campaigns,

Added:– having regard to Directive (EU) 2022/2557 of the European Parliament and of the Council of 14 December 2022 on the resilience of critical entities and repealing Council Directive 2008/114/EC2,

– having regard to the Final Assessment Report of 29 June 2023 by the NATO-EU Task Force on the Resilience of Critical Infrastructure,

– having regard to the report of 30 October 2024 by Sauli Niinistö entitled ‘Safer Together – Strengthening Europe’s Civilian and Military Preparedness and Readiness’ (Niinistö report),

Added:– having regard to the Commission communication of 11 December 2024 on countering hybrid threats from the weaponisation of migration and strengthening security at the EU’s external borders (COM(2024)0570),

Added:– having regard to Regulation (EU) 2025/37 of the European Parliament and of the Council of 19 December 2024 amending Regulation (EU) 2019/881 as regards managed security services3,

Added:– having regard to Regulation (EU) 2025/38 of the European Parliament and of the Council of 19 December 2024 laying down measures to strengthen solidarity and capacities in the Union to detect, prepare for and respond to cyber threats and incidents and amending Regulation (EU) 2021/694 (Cyber Solidarity Act)4,

– having regard to the joint communication from the Commission and the High Representative of the Union for Foreign Affairs and Security Policy of 21 February 2025 entitled ‘EU Action Plan on Cable Security’ (JOIN(2025)0009),

Changed:– having regard to the Commissionits communicationresolution of 1812 FebruaryMarch 20262025 on the EU’s easternwhite regionspaper borderingon Russia,the Belarusfuture andof UkraineEuropean (COM(2026)0082),defence5,

– having regard to the joint white paper from the Commission and the High Representative of the Union for Foreign Affairs and Security Policy of 19 March 2025 entitled ‘Joint White Paper for European Defence Readiness 2030’ (JOIN(2025)0120),

Changed:– having regard to itsthe resolutionjoint ofcommunication 12from Marchthe 2025Commission onand the whiteHigh paperRepresentative onof the futureUnion for Foreign Affairs and Security Policy of 26 March 2025 on the European defence2,Preparedness Union Strategy (JOIN(2025)0130)),

Changed:– having regard to itsthe resolutionCommission communication of 91 OctoberApril 2025 onto athe unitedEuropean responseParliament, tothe recentCouncil, Russianthe violationsEuropean Economic and Social Committee and the Committee of the EURegions Memberon States’ProtectEU: airspacea andEuropean criticalInternal infrastructure3,Security Strategy (COM(2025)0148),

Removed:– having regard to its resolution of 21 January 2026 on the implementation of the common security and defence policy – annual report 20254,

Added:– having regard to the Declaration of the North Atlantic Council Summit in The Hague, adopted by the Heads of State and Government participating in the meeting of the North Atlantic Council on 25 June 2025,

Changed:– having regard to its resolution of 189 DecemberOctober 2025 on a united response to recent Russian violations of the continuousEU BelarusianMember hybridStates’ attacksairspace againstand Lithuania5,critical infrastructure6,

Added:– having regard to the non-paper of November 2025 by the Italian Minister of Defence entitled ‘Countering hybrid warfare: an active strategy’,

Added:– having regard to the Commission proposal of 10 December 2025 for guidelines for trans-European energy infrastructure (COM(2025)1006),

Added:– having regard to its resolution of 18 December 2025 on the continuous Belarusian hybrid attacks against Lithuania7,

Added:– having regard to the Commission communication of 18 February 2026 on the EU’s eastern regions bordering Russia, Belarus and Ukraine (COM(2026)0082),

Added:– having regard to its resolution of 21 January 2026 on the implementation of the common security and defence policy – annual report 20258,

– having regard to the Council conclusions of 16 March 2026 on advancing the European Union’s capacity to counter hybrid threats,

– having regard to Rule 55 of its Rules of Procedure,

Changed:– having regard to the report of the Committee on Security and Defence (A10-0000/2026),(A10-0212/2026),

Change 1

Changed:A. whereas the intensity and scope of hybrid attacks against the EU have escalated significantly since the start of Russia’s war of aggression against Ukraine, with incidents repeatedly linked to authoritarian states, notably Russia, Belarus, China, Iran and North Korea;

Change 2

Removed:B. whereas the severity of these attacks has increased drastically, representing a blatant violation of Member States’ sovereignty, the EU’s territorial integrity and international law;

Added:B. whereas Russia constitutes the primary and most significant security threat to the EU and its Member States; whereas Russia has persistently violated the principle of territorial integrity and political independence set forth in Article 2(4) of the UN Charter; whereas hybrid attacks represent a threat to democracy in the EU and its Member States;

Change 3

Changed:C. whereas hostilethe stateseverity actorsof targetthese theattacks EU’shas territorialincreased integritydrastically onand twoconstitute fronts:a throughblatant directviolation physicalof attacksMember againstStates’ Membersovereignty, Statesthe EU’s territorial integrity and throughinternational politicallaw; operationswhereas aimedhybrid atwarfare engineeringhas Memberbecome States’a withdrawalstructural fromfeature of the EU;current geopolitical environment;

Change 4

Removed:D. whereas these attacks aim to create chaos, destabilise the political situation in the Member States, sow fear and public distrust among EU citizens, test defence readiness and weaken the EU’s support for Ukraine;

Added:D. whereas recent hybrid attacks can include unauthorised drone incursions, ‘smuggling balloons’, airspace violations, clandestine tunnels for infiltration and smuggling, sabotage of and espionage targeting critical security and defence infrastructure, the sabotage of undersea cables and energy infrastructure, GPS jamming and navigation spoofing, cyberattacks, arson and assassination plots, the instrumentalisation of migration and organised crime, elite capture, covert foreign investment, economic coercion, data exfiltration and other acts of political subversion and economic penetration, foreign information manipulation and interference (FIMI), and interference in political and electoral processes;

Removed:E. whereas EU Member States have so far failed to develop a coordinated and coherent response to hybrid attacks;

Added:E. whereas the sovereignty and territorial integrity of all Member States are foundational principles of the EU; whereas hostile state actors, in particular Russia, target the EU’s territorial integrity on two fronts: through direct physical attacks against Member States and through influence operations aimed at undermining the unity of the EU, by engineering Member States’ withdrawal from the EU;

Removed:F. whereas sabotage activities are increasingly being carried out using intermediaries, proxies and ‘disposable agents’, thereby complicating attribution and response;

Added:F. whereas hybrid threats increasingly affect the EU as a whole, including overseas countries and territories such as Greenland, but the EU’s external border regions and the EU’s maritime areas are particularly susceptible to attacks; whereas these attacks also target candidate countries and EU neighbours, notably Ukraine, Moldova, Armenia, Georgia and the Western Balkans; whereas the territorial integrity of the EU’s neighbourhood is key to ensure peace, stability and security in Europe and the wider world;

Removed:G. whereas significant increases in Member States’ defence spending, in combination with the EU’s defence initiatives, are beginning to address long-standing capability shortfalls, but a faster translation into concrete operational capabilities is needed to better protect the EU and its citizens against hybrid attacks;

Added:G. whereas interference in Greenland by non-EU countries, notably inflammatory narratives and the conduct of hybrid actions on Greenland’s territory, as well as the US Government’s formulation of explicit threats against Greenland’s sovereignty, have raised concerns regarding Greenland’s sovereignty and territorial integrity;

Added:H. whereas Georgia is an example of successful Russian hybrid interference resulting in Kremlin-aligned Georgian Dream-led authorities replicating Russia’s playbook of hybrid operations against Georgia’s own civil society and democratic institutions;

Added:I. whereas sabotage activities by Russian intelligence are increasingly being carried out using intermediaries, vulnerable social groups, including underaged persons, proxies and ‘disposable agents’, thereby complicating attribution and response; whereas religious institutions, including the Russian Orthodox Church and networks linked to the Muslim Brotherhood, have been exploited to conduct interference operations in the EU, undermining democratic values, the rule of law and the EU’s ability to defend itself;

Added:J. whereas these attacks aim not only to create chaos and destabilise the EU Member States, but also to undermine democratic integrity, manipulate decision-making processes, deepen political divisions, weaken social cohesion, sow fear and public distrust among EU citizens, and weaken defence readiness and the EU’s support for Ukraine, generating cascade effects across the EU;

Added:K. whereas the invocation of NATO Article 5 following the 9/11 terrorist attacks demonstrates that collective defence can be triggered following attacks not only by the actions of a state actor but also by attacks involving non-state actors and complex networks operating across national borders; whereas this precedent highlights the evolving nature of security threats and the need to adapt collective response mechanisms accordingly, including with improved common standards and procedures for attribution;

Added:L. whereas there has been a drastic increase in cognitive warfare together with FIMI; whereas, according to the European External Action Service (EEAS) 4th Annual Report on FIMI Threats, Russian FIMI activity is expected to intensify in 2026, with the budget for state-controlled media projected to reach approximately EUR 1.56 billion, 7 % higher than in 2025, with the Baltic Sea and Arctic regions anticipated to be among the primary targets;

Added:M. whereas FIMI operations use sophisticated cognitive-psychological methods, including reflexive control, a technique rooted in Soviet military theory that introduces specific informational inputs to limit a target’s perceived choices and steer decisions toward the influencer’s strategic goals;

Added:N. whereas Russia’s 2015 and 2021 national security strategies frame the promotion of so-called traditional values and the ‘Russian World’ as instruments of its broader hybrid warfare strategy and geopolitical influence; whereas Russia has strategically deployed historical, religious, cultural and values-based narratives as part of its hybrid warfare strategy to influence public discourse, and ecclesiastical dynamics, weaken social cohesion, and undermine democratic resilience and Transatlantic integration;

Added:O. whereas the transversal nature of the cognitive domain requires cognitive indicators to be fully integrated into the common operational picture used by cyber, intelligence, law enforcement, military and critical infrastructure structures;

Added:P. whereas the success of modern military operations and the effectiveness of public institutions increasingly depend on the control of cyberspace and on the strategic use of digital resources and information systems;

Added:Q. whereas internal security remains a responsibility of the Member States, although the cross-border, interconnected and multi-dimensional nature of those hybrid attacks requires strengthened cooperation, systematic information sharing and coordinated action at EU level, supported by adequate funding and complemented by long-term strategies to strengthen societal resilience and protect institutional integrity;

Added:R. whereas EU Justice and Home Affairs (JHA) agencies have a key role to play in cooperation with national authorities, in establishing and maintaining common situational awareness of risks related to such threats and in assisting front-line Member States in crisis situations; whereas the Commission has included the strengthening of the European Border and Coast Guard Agency (Frontex) in its flagship initiatives for the 2024-2029 legislative terms, as well as a revision of the mandates of European Union Agency for Law Enforcement Cooperation (Europol) and European Union Agency for Criminal Justice Cooperation (Eurojust); whereas other initiatives such as the ‘Eastern Flank Watch’ may contribute to strengthening the protection of the external borders and increasing resilience against hybrid threats;

Added:S. whereas the emergence of advanced AI systems represents a structural disruption to existing cybersecurity architectures, invalidating threat models and defensive assumptions developed over previous decades; whereas hostile state and non-state actors are already exploiting AI capabilities to increase the speed, scale and precision of hybrid operations, including cyber intrusions, AI poisoning, disinformation campaigns and critical infrastructure targeting; whereas the EU’s collective cyber resilience frameworks must be adapted to address these new vulnerabilities;