Changes between two versions
What changed between the draft committee report and the plenary report
From · draft committee report· 8 May 2026
on hybrid warfare and the protection of the EU’s territorial integrity and critical security and defence infrastructure
To · plenary report· 20 Jul 2026
on Hybrid warfare and the protection of the EU’s territorial integrity and critical security and defence infrastructure
These two texts have too little in common to compare paragraph by paragraph: they are different documents rather than versions of one (for example one group’s motion and the joint text that was adopted).
+137 added · −29 removed · 13 changed paragraphs, packaging included.
Part 2 of 5: Paragraphs 61–120
Added:T. whereas despite the significant efforts undertaken by Member States, and the development of tools and mechanisms to counter hybrid threats, the EU’s response to hybrid attacks continues to suffer from legislative gaps, the lack of a harmonised approach among Member States, differing levels of awareness, and the absence of a dedicated structure or entity to monitor such attacks; whereas as a consequence, despite the urgency, EU Member States have yet to develop a fully coordinated and coherent response to hybrid warfare both individually, at European level and, where relevant, with NATO;
Added:U. whereas national defence spending would benefit from increased coordination and pooling between Member States or further investment in European collaborative projects; whereas significant increases in Member States’ defence spending, in combination with the EU’s defence initiatives such as SAFE and other measures under the Defence Readiness 2030 framework, are beginning to address long-standing capability shortfalls, but a faster translation into concrete operational capabilities is needed to better protect the EU, its Member States and their citizens against hybrid threats; whereas in this area further potential remains for dual-use technologies; whereas further response is equally required in the area of internal security;
Added:V. whereas responsibility for national security remains primarily with the Member States and any measures and initiatives coordinated or proposed at EU level must be framed and implemented in full respect of Member States’ exclusive competences and aligned with the EU Hybrid, FIMI and Cyber Diplomacy Toolboxes;
Added:W. whereas the EU’s dependence on foreign actors and foreign-made technologies in critical infrastructure and supply chains, including the sourcing of raw materials from third countries, is one of the EU’s most significant vulnerabilities and a key challenge for European security and strategic autonomy;
Added:X. whereas the current security environment confronting the EU is characterised by neither peace nor open armed conflict, but phase zero warfare in which adversaries deploy hybrid instruments to exploit the gap between the EU’s peacetime governance structures and the decisiveness required to deter and respond; whereas existing EU foreign and security policy frameworks, calibrated for consensus-based deliberation, generate structural latency that adversaries actively exploit; whereas this in-between state demands a fundamental reassessment of EU decision-making architecture in the security and defence domain;
Added:Y. whereas the credibility of deterrence rests not only on the material capabilities and technological edge of the European and allied forces, but decisively on political will, strategic cohesion and a common understanding of the threat; whereas Russia’s hybrid strategy is calibrated to erode precisely these qualities – through ambiguity, division and sub-threshold pressure – in order to degrade the credibility of collective defence commitments before any kinetic threshold is reached;
Hybrid warfare: between war and peace
Change 5
Changed:1. AffirmsStresses that hybrid operations are continuous,deliberate, coordinatedcombined, attacksintelligence-led carriedand outcoordinated acts by statestates and– including through non-state actorsactors, acrossintermediaries and proxies – spanning multiple domains;domains simultaneously; stresses that they are designed to resembleappear as isolated incidents in order toand stayremain below the threshold of armed conflict, while producinghaving the potential to produce effects comparable to thoseconventional aggression, thus making attribution and an effective response significantly harder; calls therefore on the EU and the Member States to recognise that hybrid acts can constitute a form of warfare regardless of whether conventional aggression;force is employed;
Change 6
Changed:2. Underlines that the primary objective of hybrid warfare is to erodedestabilise, divide and undermine the EU’sEU and its Member States by exploiting systemic vulnerabilities, and weakening their security, resilience and democratic foundations, and their defence readiness by disrupting itsthe EU’s defence industrial base and critical infrastructure,infrastructure undermining public and political support for EU defence, and installingby governmentsstrengthening political forces favourable to the perpetrators through systematic interference in democratic processes;
Change 7
Removed:Information warfare and cognitive security
Added:3. Affirms that Russia, acting directly or via multiple proxies such as Belarus, is the gravest hybrid-threat state actor targeting the EU and its Member States; notes that China, Iran, North Korea and others have been implementing hybrid campaigns aimed at undermining European democracies and eroding the EU’s security interests; underlines that the EU must adopt a comprehensive approach to hybrid threats that addresses not only Russian and Belarusian activities but also the growing strategic role of China, Iran and North Korea in enabling and amplifying hostile actions against European interests and security; notes with concern that non-state actors – including terrorist groups, organised crime networks, oligarchic and kleptocratic networks, religious institutions and faith networks, private military companies, extremist movements and influence-for-hire operators – may also conduct or enable hybrid campaigns against European democracies;
Removed:3. Underlines that information warfare is one of the core elements of hybrid warfare; expresses concern at the growing scale of foreign information manipulation and interference (FIMI), which aims to erode trust, polarise societies and undermine public support for European security and defence, including support for Ukraine; highlights that AI tools – deepfakes, algorithmic amplification and automated account networks – are making such influence operations faster, cheaper and harder to detect;
Added:4. Calls on the Commission and the Council to assess the adequacy of existing EU legal frameworks for addressing hybrid threats, close identified gaps, and treat sub-threshold hybrid operations that cannot be addressed through law enforcement alone as collective security matters, requiring a combined civil-military response;
Removed:4. Notes that the EU’s response to FIMI remains largely reactive and insufficiently operational, due to the lack of permanent real-time monitoring, attribution and response capabilities; insists that FIMI must be treated as a serious security threat requiring an operational approach, including early detection, predefined response options and stronger protection of democratic processes;
Added:Information warfare, cognitive security and societal resilience
Removed:5. Calls on the Member States to adopt whole-of-government and whole-of-society approaches, prioritising resilience and preparedness as emphasised in the Niinistö report; urges the Member States and calls for the EU institutions to invest in democratic resilience;
Added:5. Underlines that information warfare is one of the core elements of hybrid warfare; expresses concern at the growing scale of cognitive warfare together with FIMI, which aims to erode societal trust in democratic institutions, increase polarisation, undermine democratic decision-making and public support for European security and defence, including support for Ukraine;
Added:6. Highlights that the above-mentioned objectives (see paragraph 5) are predominantly being pursued through sophisticated and coordinated operations spanning multiple domains of social life and employing strategic cognitive and psychological techniques designed to shape decision-making processes, individual and collective perceptions, identity formation, cultural norms, historical memory, moral frameworks and religious belief systems, while exploiting technological infrastructure, media ecosystems and economic and political vulnerabilities; notes with concern that FIMI operations employ sophisticated cognitive-psychological methods, including reflexive control, which are difficult to detect, attribute or counter through conventional responses; stresses therefore that the EU FIMI toolkit must explicitly integrate countermeasures against such advanced influence techniques in order to safeguard the integrity of EU decision-making;
Added:7. Warns that individual kinetic incidents may either trigger or be deliberately engineered to provide cover for immediate, synchronised and orchestrated FIMI operations, with hostile actors exploiting the gap before official statements are issued to shape public perception; calls for this information gap to be duly addressed through enhanced European coordination, in particular by improving public-private coordination in the information domain; stresses the need to develop common tools such as communication playbooks enabling faster, coordinated and accurate communication before hostile narratives saturate the information space;
Added:8. Expresses concern about Russia’s use of historical revisionism, in particular regarding the Second World War and the Soviet legacy, FIMI, and the selective reinterpretation of historical events as tools of hybrid warfare aimed at polarising public opinion, undermining societal cohesion and democratic resilience, and delegitimising the territorial integrity of sovereign states;
Added:9. Underlines that FIMI extends beyond traditional media into educational, cultural and religious domains; highlights the strategic use of religious institutions and faith networks, including the instrumentalisation of the Russian Orthodox Church, to project moral authority, disseminate state-sponsored narratives, and gradually undermine societal resilience and democratic cohesion; calls furthermore on the EU to detect hybrid threats exploiting religious channels, and train EU officials in interfaith engagement and religious literacy, and in the identification of financial influence, organisational capture and information manipulation that undermine democratic values and social cohesion;
Added:10. Condemns the use of online platforms by hostile actors for hybrid activities; calls for stronger enforcement of existing EU rules on the transparency of recommendation systems, political advertising, coordinated inauthentic behaviour and the rapid dissemination of manipulated or AI-generated content linked to hostile foreign interference;
Added:11. Underlines that hostile actors employ increasingly sophisticated and adaptive hybrid techniques; highlights that AI tools – deepfakes, algorithmic amplification and automated account networks – make influence operations faster, cheaper and harder to detect; considers that the EU response to AI-enabled FIMI must treat AI as both a threat vector and as a critical defence capability;
Added:12. Notes that the EU’s response to FIMI remains reactive, lacking real-time monitoring, attribution and proactive response capabilities; insists that FIMI must be treated as a serious security threat requiring an operational approach, better coordination and cooperation between Member States at all levels, including early detection, adequate response options and stronger protection of democratic processes, particularly during electoral periods;
Added:13. Welcomes the EEAS’s work in monitoring, detecting and responding to FIMI and underlines the relevance of the EU’s Rapid Alert System (RAS) for coordinated joint responses to disinformation; invites the Commission and the Member States to assess and build on the recommendations of the Special Committee on the European Democracy Shield (EUDS); calls for the RAS to be further strengthened to address information manipulation in real time with clear operational responsibilities; calls for standardised pre-bunking and rapid-response mechanisms across the EU and with partner countries, including structured early-warning communication channels; encourages the development of proactive strategic communication tools capable of warning populations in advance about anticipated disinformation tactics, narrative patterns and fabricated content ahead of critical events such as elections, energy negotiations or security crises;
Added:14. Calls, furthermore, on the Commission, the High Representative and the Member States to fully operationalise and make consistent and coordinated use of the FIMI Toolbox and to apply the FIMI Deterrence Playbook, including through coordinated public attribution and, where appropriate, the use of restrictive measures, targeting not only individual incidents but the illicit financial flows, technical infrastructure, and intermediary and proxy networks that sustain FIMI operations;
Added:15. Stresses that European public opinion remains a primary target of Russian hybrid operations; recalls that decades of peace have created conditions of strategic complacency that adversary influence operations exploit and deepen; considers that governments and EU institutions share responsibility to build public understanding of the nature and proximity of the hybrid threat, and that the failure to do so undermines preparedness and deterrence from within;
Added:16. Calls on the Member States to adopt whole-of-government and whole-of-society approaches, prioritising resilience and preparedness as emphasised in the Niinistö report; recalls that hybrid threats target society as a whole, as hostile actors exploit vulnerabilities across interconnected domains, services, communities and information spaces; believes that trust and social cohesion are fundamental to societal resilience; underlines, therefore, that resilience against hybrid threats must extend beyond military, technical and institutional measures by bringing together public authorities, the private sector, civil society – including local communities and constituencies that are hard to reach – academia and independent media to strengthen democratic trust, public awareness and societal preparedness, thereby fostering a new European security culture;
Added:17. Stresses the need to strengthen public resilience to FIMI through civic education, media literacy, strategic communications, support to independent media including investigative journalism, fact-checking networks such as the European Digital Media Observatory, and AI-enabled tools to detect and analyse disinformation campaigns at scale; calls for stronger cooperation with media and audiovisual actors in detecting, attributing and responding to FIMI; calls for incentivising, including through public-private initiatives, the detection, analysis and attribution of FIMI, secure data-sharing mechanisms and interoperable early-warning systems;
Added:18. Expresses concern over continuous reports of foreign interference in European elections, including through cyberattacks and AI-enabled disinformation; recalls that the integrity and resilience of electoral processes are central to the EU’s democratic foundations and a key target of hybrid operations; underlines that FIMI tends to intensify before elections and that continued vigilance and coordination are therefore essential to safeguard electoral integrity and democratic stability across the EU and in partner countries, including candidate and potential candidate countries; welcomes the Joint Communication ‘European Democracy Shield: Empowering Strong and Resilient Democracies’ and the establishment of the European Centre for Democratic Resilience and calls for a clear definition of its tasks to avoid duplication with existing initiatives;
Added:19. Calls for recognising and addressing cognitive vulnerabilities in the context of hybrid warfare in the upcoming EU security strategy and for the Commission to take further steps by providing cognitive vulnerability mapping and resilience benchmarks;
Added:Cybersecurity
Added:20. Stresses that cyberattacks have become a central element of hybrid campaigns, exploiting the increasing digitalisation of critical sectors such as healthcare, finance and energy, causing cascading disruptions with potentially severe economic and societal consequences;
Added:21. Notes that cyberspace has become established as the fifth military domain and as a central enabler of hybrid threats; underlines that the growing dependence of military platforms, critical infrastructure and command, control, communications and intelligence systems on digital technologies makes cybersecurity essential to operational superiority and resilience across all domains; stresses, therefore, the need for sovereign cyber capabilities for detection, attribution, response and intelligence, including offensive capabilities to neutralise threats and ensure credible deterrence;
Added:22. Underlines the convergence between FIMI and cybersecurity, noting that cyberattacks often occur at the early stages of FIMI campaigns; calls for counter-FIMI mechanisms to be systematically connected with cybersecurity capabilities in order to detect, attribute and disrupt coordinated manipulation infrastructure at an early stage;
Added:23. Warns of the risks posed by convergent cyber operations, in which state-aligned actors actively adopt the operational profiles, methodologies and personas of independent hacktivists or commercially motivated cybercriminals to conceal attribution and align cyber activity with geopolitical events, elections or kinetic operations; stresses that responses to hybrid cyber threats must clearly distinguish between legitimate forms of political expression or civil dissent and financially motivated cybercrime and state-sponsored operations, so as to protect fundamental freedoms while improving attribution, accountability and deterrence;
Added:24. Warns that the expansion of the Internet of Things increases the risk that cyberattacks generate physical effects in critical infrastructure and essential services, and calls for security-by-design obligations to ensure connected devices do not become entry points for hybrid operations with real-world consequences;
Added:25. Warns that full cyber protection does not exist and that a shift in mindset towards cyber resilience is needed; stresses that Europe’s cyber resilience must be built up through frequent and realistic cyber exercises; underlines that cyber resilience not only concerns systems, but also data protection, which is both a target and an enabler of hybrid threats; underlines further the need to strengthen cyber resilience across the European economic fabric, including small and medium-size enterprises (SMEs) and providers of essential digital services;
Added:26. Stresses the EU’s added value in helping Member States to connect national capabilities, build common situational awareness and enable faster, more coherent responses to hybrid threats; recommends that the Commission explore proposals for a more unified framework to support Member States in the planning, operational coordination and execution of cyber operations; welcomes the Permanent Structured Cooperation (PESCO) project on the Cyber and Information Domain Coordination Centre (CIDCC) and the proposal for an EU Cyber Defence Coordination Centre (EU CDCC);
Added:27. Calls for greater harmonisation of incident-reporting obligations and key legal concepts across EU cybersecurity and resilience frameworks, to reduce fragmentation, improve interoperability and ensure that rapid restoration of essential services remains a central priority in hybrid crisis scenarios;
Added:28. Recognises the EU Cybersecurity Reserve, managed by the European Union Agency for Cybersecurity (ENISA) under the Cyber Solidarity Act, as a strategic EU cyber rapid-response capacity; calls for its funding to be adapted to operational demand and highlights its first deployment in Moldova as an important step in strengthening the EU’s operational cyber resilience and support to partner countries; calls on Member States’ cybersecurity authorities to foster structured cooperation with the Reserve’s trusted providers to make full use of available incident response capabilities when hybrid threats materialise through significant or large-scale cyber incidents;
Added:29. Reaffirms the importance and calls for adequate EU resourcing of the PESCO Cyber Rapid Response Teams as a standing cyber defence capability, deployable upon request from Member States, partner countries and common security and defence policy (CSDP) missions facing cyber attacks with implications for security and defence;
Added:30. Reiterates the importance of making full use of the Cyber Diplomacy Toolbox to prevent, deter and respond to cyber threats and malicious cyber activities; takes note of the launch in March 2026 of the first permanent UN Global Mechanism on cybersecurity, and believes that the EU should focus on areas where there is clear European added value while further strengthening European cyber diplomacy;
Added:31. Stresses that cyber resilience and defensive measures are insufficient to ensure credible deterrence against hybrid threats as highlighted in the Joint White Paper for European Defence Readiness 2030; calls on the Commission and the Member States in cooperation with NATO to examine the legal, procedural and operational prerequisites for proportionate, legally compliant cyber countermeasures; reiterates its position calling for the establishment without undue delay of the EU CDCC and calls for the swift implementation of a mandate in line with the Council conclusions on the EU Policy on Cyber Defence, in order to achieve a more credible and capable EU cyber defence;
Added:32. Warns in this regard that AI is not only a tool used in hybrid cyber activities, but is also a critical technology that can itself be targeted, manipulated or compromised through prompt injection, training data poisoning and supply-chain attacks; stresses that, given the growing reliance on commercial and dual-use AI systems in civilian, security and defence contexts, the EU must develop a clear position on the cybersecurity, resilience and governance of dual-use AI, including safeguards for model integrity, trusted supply chains and oversight at the boundary between civilian, defence and national security applications;
Added:33. Stresses the need for increased protection of critical public digital infrastructure and sensitive state-managed data registers, including electoral infrastructure, as they form potential targets of hybrid threats, given their role in digital identity, public administration, data governance, secure communications, access to essential services and the integrity of democratic processes;
Critical infrastructure
Change 8
Changed:6.34. Condemns the hybrid warfare attacks targeting the EU’s critical infrastructure;infrastructure – in particular energy, transport, communications and satellite infrastructure, including that for military mobility – both critical enablers and strategic assets for the EU’s collective defence, resilience and civilian protection; highlights that this critical infrastructure performs as an interconnected system that cannot be protected in isolation, and that greater digital connectivity increases vulnerability; welcomes the focus on the protection and resilience of energy and military mobility infrastructure in the Commission proposal for a regulation on military mobility (COM(2025)0847);(COM(2025)0847) and the Commission proposal for guidelines for trans-European energy infrastructure (COM(2025)1006); calls on the Commission and the Member States to take adequateall necessary measures to ensure this infrastructure isits protected;protection;
Change 9
Removed:7. Is concerned about the EU’s dependence on high-risk non-EU countries, particularly China, for the supply of network-connected hardware and software; stresses the urgent need to address these vulnerabilities and calls on the Commission to extend supply chain security assessments systematically, across all critical infrastructure sectors, and to accelerate efforts to reduce such strategic dependencies;
Added:35. Underlines that the space domain has become an increasingly important arena for hybrid warfare, with hostile actors targeting satellite-based communications, navigation and observation systems through cyber operations, physical attacks, jamming and spoofing or the exploitation of strategic dependencies; stresses that disruption of space assets can have significant consequences for the EU’s civil security, critical infrastructure, military mobility and crisis-response capabilities; calls, therefore, for stronger resilience of EU space systems, including increased space situational awareness, protection of ground infrastructure, cybersecurity requirements, supply-chain security, regular exercises and alternative or backup positioning, navigation and timing (PNT) capabilities; calls further for the integration of the space domain into the EU’s broader framework for countering hybrid threats;
Removed:8. Stresses that submarine cables represent a key strategic vulnerability; commends the 2024 Commission Recommendation on Secure and Resilient Submarine Cable Infrastructures6 and the 2025 Joint Communication of the EU action plan on cable security as important first steps towards strengthening the security and resilience of submarine cables;
Added:36. Notes that hostile actors, mainly Russia, are increasingly weaponising energy infrastructure, energy markets and energy dependencies to exert political pressure; emphasises the strategic importance of critical energy infrastructure for both defence and civil needs; urges the Commission and the EU Member States to establish an EU legal and financial framework under the next multiannual financial framework 2028-2034 that would ensure sufficient protection and resilience of critical energy infrastructure, prioritising Commission proposals for guidelines for trans-European energy infrastructure (COM(2025)1006) and the Connecting Europe Facility (COM(2025)0547);
Removed:9. Recognises that a significant share of critical infrastructure linked to essential public services and military capabilities is privately owned or operated; calls for permanent and structured public-private cooperation frameworks to be established, including for information sharing, contingency planning and coordinated crisis response; calls for defence requirements to be systematically integrated into civilian infrastructure planning, design and funding as a condition for EU support;
Added:37. Condemns Russia’s shadow fleet activities that increase the risk of maritime accidents, conceal state-linked sabotage, and jeopardise critical infrastructure such as undersea cables, offshore energy installations and port facilities; calls for enhanced monitoring, inspection and enforcement measures in European waters and for the EU to step up its response to hybrid threats in maritime zones; encourages the Commission to explore – drawing on the Proliferation Security Initiative as a model – legal and operational frameworks to enable the boarding of vessels linked to shadow fleets, and calls on the Financial Action Task Force to further examine the role of opaque ownership structures, flag registries and associated financial networks in facilitating the circumvention of sanctions and illicit financial flows;
Removed:From fragmentation to coordinated and decisive response
Added:38. Stresses that undersea cables are a key strategic vulnerability and target of hybrid sabotage, espionage and influence operations due to their physical exposure and systemic disruption potential as they carry the vast majority of intercontinental internet traffic; commends the 2024 Commission Recommendation on Secure and Resilient Submarine Cable Infrastructures9 and the 2025 Joint communication on the EU action plan on cable security (JOIN(2025)0009) as important first steps towards strengthening the security and resilience of submarine cable infrastructure; calls further for maritime domain awareness capabilities, integrating satellite, surface and subsea sensor data to detect, monitor and attribute physical threats to submarine cable and offshore energy infrastructure in strategic maritime areas, including the Baltic Sea, North Sea, Black Sea, and Arctic and Mediterranean regions; recommends strong criminal liability provisions to deter such attacks and redundant systems to ensure resilience; stresses further the need for a comprehensive, multilayered approach combining technological innovation, enhanced intelligence integration, improved attribution capabilities, and strengthened cooperation between NATO, the EU Member States, and relevant private-sector actors in order to ensure coherent protection of undersea infrastructure;
Removed:10. Notes that the sovereignty and territorial integrity of all Member States are foundational principles of the EU; considers that the EU must move from a reactive to a proactive strategy that credibly raises the cost of hostile action; stresses that any violation of Member States’ sovereignty must be met with immediate retaliation; calls on the Commission and the Council to develop a cross-domain action plan against hybrid warfare, including calibrated EU retaliatory options proportionate to the severity of hostile activities and clear response chains complementing those of NATO; calls on the Member States, in coordination with NATO allies, to review rules of engagement across all threat domains in order to ensure timely and adequate responses to attacks on their sovereignty or critical infrastructure;
Added:39. Calls on the Commission and the Member States to establish a coordinated, EU-wide interpretation of the United Nations Convention on the Law of the Sea (UNCLOS) in order to ensure coherent action against and effective criminalisation and deterrence of hybrid activities, acts of sabotage and violations of sovereign rights in the EU’s maritime areas, notably in the Baltic Sea, while recalling UNCLOS’s objective of ensuring the peaceful use of the seas; encourages the Commission and the Member States to draw on the Australian example of establishing ‘cable protection zones’, providing legal safeguards and criminalising damage to submarine cables beyond the 12-nautical-mile territorial sea limit, accompanied by active monitoring, surveillance and response in cooperation with relevant third-country partners;
Removed:11. Highlights the EU’s unique added value in aggregating cross-border data to detect patterns of coordinated hybrid campaigns that no Member State can identify on its own; calls for this cross-border pattern-recognition function to be formally recognised as a core EU competence; insists that a permanent Russian crisis cell be established; believes that intelligence sharing needs to be urgently advanced;
Added:40. Calls on the Member States and the European Defence Agency (EDA) to advance the PESCO projects Critical Seabed Infrastructure Protection (CSIP), Harbour & Maritime Surveillance and Protection (HARMSPRO), Integrated Multi-Layer Air and Missile Defence System (IMLAMD) and Counter Unmanned Aerial System (C-UAS) to boost surveillance, detection and defence capabilities against airborne and maritime threats; calls on the Commission, in cooperation with the High Representative and in consultation with the Member States, to propose a European defence project of common interest dedicated to the integrated defence of the maritime environment and the seabed;