Sittings · Compare

What changed

From · Plenary report · 2026-07-20 A-10-2026-0212 on Hybrid warfare and the protection of the EU’s territorial integrity and critical security and defence infrastructure
To · Adopted text · 2026-09-16 TA-10-2026-0303 Hybrid warfare and the protection of the EU’s territorial integrity and critical security and defence infrastructure
✦ In short · AI narration of the differences below, generated 17 Sept 2026

Parliament adds a recital and a paragraph describing recent hybrid attacks, including incidents attributed to Russia and the assault on Ceuta, and calls for an independent investigation into the latter. #1#7 It also welcomes the completion of the cyber coordination centre project and progress towards a permanent EU Cyber Defence Coordination Centre, and calls for its swift operationalisation. #3#4 The other changes are formal: a recital letter and decimal separator are updated and footnote markers are removed. #2#5#6

4 changes of substance, plus 3 formal (marked below). Each change below carries a one-line ✦ note from the same model. Written from the two texts only — read the highlighted passages before relying on it.

+7 added · −19 removed · 14 modified paragraphs

MOTION FOR A EUROPEAN PARLIAMENT RESOLUTION

P10_TA(2026)0303

on Hybrid warfare and the protection of the EU’s territorial integrity and critical security and defence infrastructure

(2026/2024(INI))

Committee on Security and Defence

PE788.818

European Parliament resolution of 16 September 2026 on Hybrid warfare and the protection of the EU’s territorial integrity and critical security and defence infrastructure (2026/2024(INI))

The European Parliament,

– having regard to the international legal framework for preventing and fighting terrorism, including UN Security Council Resolution 2341 on protection of critical infrastructure against terrorist acts, adopted on 13 February 2017,

– having regard to Regulation (EU) 2019/452 of the European Parliament and of the Council of 19 March 2019 establishing a framework for the screening of foreign direct investments into the Union1,Union,

– having regard to the ‘Strategic Compass for Security and Defence – For a European Union that protects its citizens, values and interests and contributes to international peace and security’, approved by the Council on 21 March 2022 and endorsed by the European Council on 25 March 2022,

– having regard to the Council conclusions of 21 June 2022 on a framework for a coordinated EU response to hybrid campaigns,

– having regard to Directive (EU) 2022/2557 of the European Parliament and of the Council of 14 December 2022 on the resilience of critical entities and repealing Council Directive 2008/114/EC2,2008/114/EC,

– having regard to the Final Assessment Report of 29 June 2023 by the NATO-EU Task Force on the Resilience of Critical Infrastructure,

– having regard to the Commission communication of 11 December 2024 on countering hybrid threats from the weaponisation of migration and strengthening security at the EU’s external borders (COM(2024)0570),

– having regard to Regulation (EU) 2025/37 of the European Parliament and of the Council of 19 December 2024 amending Regulation (EU) 2019/881 as regards managed security services3,services,

– having regard to Regulation (EU) 2025/38 of the European Parliament and of the Council of 19 December 2024 laying down measures to strengthen solidarity and capacities in the Union to detect, prepare for and respond to cyber threats and incidents and amending Regulation (EU) 2021/694 (Cyber Solidarity Act)4,Act),

– having regard to the joint communication from the Commission and the High Representative of the Union for Foreign Affairs and Security Policy of 21 February 2025 entitled ‘EU Action Plan on Cable Security’ (JOIN(2025)0009),

– having regard to its resolution of 12 March 2025 on the white paper on the future of European defence5,defence,

– having regard to the joint white paper from the Commission and the High Representative of the Union for Foreign Affairs and Security Policy of 19 March 2025 entitled ‘Joint White Paper for European Defence Readiness 2030’ (JOIN(2025)0120),

– having regard to the Declaration of the North Atlantic Council Summit in The Hague, adopted by the Heads of State and Government participating in the meeting of the North Atlantic Council on 25 June 2025,

– having regard to its resolution of 9 October 2025 on a united response to recent Russian violations of the EU Member States’ airspace and critical infrastructure6,infrastructure,

– having regard to the non-paper of November 2025 by the Italian Minister of Defence entitled ‘Countering hybrid warfare: an active strategy’,

– having regard to the Commission proposal of 10 December 2025 for guidelines for trans-European energy infrastructure (COM(2025)1006),

– having regard to its resolution of 18 December 2025 on the continuous Belarusian hybrid attacks against Lithuania7,Lithuania,

– having regard to the Commission communication of 18 February 2026 on the EU’s eastern regions bordering Russia, Belarus and Ukraine (COM(2026)0082),

– having regard to its resolution of 21 January 2026 on the implementation of the common security and defence policy – annual report 20258,2025,

– having regard to the Council conclusions of 16 March 2026 on advancing the European Union’s capacity to counter hybrid threats,

– having regard to the report of the Committee on Security and Defence (A10-0212/2026),

– having regard to the Declaration of the North Atlantic Council Summit adopted by the Heads of State and Government participating in the meeting of the North Atlantic Council in Ankara on 8 July 2026,

A. whereas the intensity and scope of hybrid attacks against the EU have escalated significantly since the start of Russia’s war of aggression against Ukraine, with incidents repeatedly linked to authoritarian states, notably Russia, Belarus, China, Iran and North Korea;

D. whereas recent hybrid attacks can include unauthorised drone incursions, ‘smuggling balloons’, airspace violations, clandestine tunnels for infiltration and smuggling, sabotage of and espionage targeting critical security and defence infrastructure, the sabotage of undersea cables and energy infrastructure, GPS jamming and navigation spoofing, cyberattacks, arson and assassination plots, the instrumentalisation of migration and organised crime, elite capture, covert foreign investment, economic coercion, data exfiltration and other acts of political subversion and economic penetration, foreign information manipulation and interference (FIMI), and interference in political and electoral processes;

Adds a recital listing physical hybrid activities and attacks across the EU in the summer of 2026, including incidents attributed to Russia by national authorities and the closure of the Russian consulate in Bonn.

E. whereas, in the summer of 2026, the EU witnessed an intensification of physical hybrid activities and attacks across EU territory; whereas this included an attempted explosive drone attack targeting Ukrainian cargo aircraft at Leipzig/Halle Airport in Germany, an attempted attack by an explosive-laden maritime drone against a Romanian offshore gas project, a foiled Russian-directed sabotage and espionage plot targeting military infrastructure and Ukrainian cargo aircraft in Romania, an arson attack targeting a defence contractor in Estonia, deliberate sabotage and arson attacks targeting defence and drone manufacturing facilities in Poland, a Russian cruise missile violating Polish airspace and crashing in the Lublin region, and a foiled arson plot in Slovakia targeting a Ukrainian drone manufacturer; whereas the Leipzig/Halle Airport attack, the targeting of the Romanian offshore gas project and the sabotage plot targeting military infrastructure and Ukrainian cargo aircraft in Romania have been publicly attributed to Russia by the respective national authorities; whereas following the attack on Leipzig/Halle Airport, the German authorities closed the Russian consulate in Bonn and the Russian House in Berlin;

F. whereas the sovereignty and territorial integrity of all Member States are foundational principles of the EU; whereas hostile state actors, in particular Russia, target the EU’s territorial integrity on two fronts: through direct physical attacks against Member States and through influence operations aimed at undermining the unity of the EU, by engineering Member States’ withdrawal from the EU;

L. whereas the invocation of NATO Article 5 following the 9/11 terrorist attacks demonstrates that collective defence can be triggered following attacks not only by the actions of a state actor but also by attacks involving non-state actors and complex networks operating across national borders; whereas this precedent highlights the evolving nature of security threats and the need to adapt collective response mechanisms accordingly, including with improved common standards and procedures for attribution;

Formal Updates the letter of the recital and the decimal separator in the figure for the projected budget of state-controlled media.

L.M. whereas there has been a drastic increase in cognitive warfare together with FIMI; whereas, according to the European External Action Service (EEAS) 4th Annual Report on FIMI Threats, Russian FIMI activity is expected to intensify in 2026, with the budget for state-controlled media projected to reach approximately EUR 1.561,56 billion, 7 % higher than in 2025, with the Baltic Sea and Arctic regions anticipated to be among the primary targets;

N. whereas FIMI operations use sophisticated cognitive-psychological methods, including reflexive control, a technique rooted in Soviet military theory that introduces specific informational inputs to limit a target’s perceived choices and steer decisions toward the influencer’s strategic goals;

25. Warns that full cyber protection does not exist and that a shift in mindset towards cyber resilience is needed; stresses that Europe’s cyber resilience must be built up through frequent and realistic cyber exercises; underlines that cyber resilience not only concerns systems, but also data protection, which is both a target and an enabler of hybrid threats; underlines further the need to strengthen cyber resilience across the European economic fabric, including small and medium-size enterprises (SMEs) and providers of essential digital services;

Welcomes the completion of the PESCO project on the Cyber and Information Domain Coordination Centre and progress towards its transition into a permanent EU Cyber Defence Coordination Centre.

26. Stresses the EU’s added value in helping Member States to connect national capabilities, build common situational awareness and enable faster, more coherent responses to hybrid threats; recommends that the Commission explore proposals for a more unified framework to support Member States in the planning, operational coordination and execution of cyber operations; welcomes the completion of the Permanent Structured Cooperation (PESCO) project on the Cyber and Information Domain Coordination Centre (CIDCC) and the proposalprogress fortowards anits transition into a permanent EU Cyber Defence Coordination Centre (EU CDCC);

27. Calls for greater harmonisation of incident-reporting obligations and key legal concepts across EU cybersecurity and resilience frameworks, to reduce fragmentation, improve interoperability and ensure that rapid restoration of essential services remains a central priority in hybrid crisis scenarios;

30. Reiterates the importance of making full use of the Cyber Diplomacy Toolbox to prevent, deter and respond to cyber threats and malicious cyber activities; takes note of the launch in March 2026 of the first permanent UN Global Mechanism on cybersecurity, and believes that the EU should focus on areas where there is clear European added value while further strengthening European cyber diplomacy;

Welcomes progress towards establishing the EU Cyber Defence Coordination Centre and calls for its swift operationalisation and for implementation of a mandate in line with the Council conclusions on the EU Policy on Cyber Defence.

31. Stresses that cyber resilience and defensive measures are insufficient to ensure credible deterrence against hybrid threats as highlighted in the Joint White Paper for European Defence Readiness 2030; calls on the Commission and the Member States in cooperation with NATO to examine the legal, procedural and operational prerequisites for proportionate, legally compliant cyber countermeasures; reiterateswelcomes itsthe positionprogress callingmade fortowards the establishment without undue delay of the EU CDCC and calls for theits swift operationalisation and for the implementation of a mandate in line with the Council conclusions on the EU Policy on Cyber Defence, in order to achieve a more credible and capable EU cyber defence;

32. Warns in this regard that AI is not only a tool used in hybrid cyber activities, but is also a critical technology that can itself be targeted, manipulated or compromised through prompt injection, training data poisoning and supply-chain attacks; stresses that, given the growing reliance on commercial and dual-use AI systems in civilian, security and defence contexts, the EU must develop a clear position on the cybersecurity, resilience and governance of dual-use AI, including safeguards for model integrity, trusted supply chains and oversight at the boundary between civilian, defence and national security applications;

37. Condemns Russia’s shadow fleet activities that increase the risk of maritime accidents, conceal state-linked sabotage, and jeopardise critical infrastructure such as undersea cables, offshore energy installations and port facilities; calls for enhanced monitoring, inspection and enforcement measures in European waters and for the EU to step up its response to hybrid threats in maritime zones; encourages the Commission to explore – drawing on the Proliferation Security Initiative as a model – legal and operational frameworks to enable the boarding of vessels linked to shadow fleets, and calls on the Financial Action Task Force to further examine the role of opaque ownership structures, flag registries and associated financial networks in facilitating the circumvention of sanctions and illicit financial flows;

Formal Removes footnote markers from the references to the 2024 Commission Recommendation and the 2025 Joint communication on cable security.

38. Stresses that undersea cables are a key strategic vulnerability and target of hybrid sabotage, espionage and influence operations due to their physical exposure and systemic disruption potential as they carry the vast majority of intercontinental internet traffic; commends the 2024 Commission Recommendation on Secure and Resilient Submarine Cable Infrastructures9Infrastructures and the 2025 Joint communication on the EU action plan on cable security (JOIN(2025)0009) as important first steps towards strengthening the security and resilience of submarine cable infrastructure; calls further for maritime domain awareness capabilities, integrating satellite, surface and subsea sensor data to detect, monitor and attribute physical threats to submarine cable and offshore energy infrastructure in strategic maritime areas, including the Baltic Sea, North Sea, Black Sea, and Arctic and Mediterranean regions; recommends strong criminal liability provisions to deter such attacks and redundant systems to ensure resilience; stresses further the need for a comprehensive, multilayered approach combining technological innovation, enhanced intelligence integration, improved attribution capabilities, and strengthened cooperation between NATO, the EU Member States, and relevant private-sector actors in order to ensure coherent protection of undersea infrastructure;

39. Calls on the Commission and the Member States to establish a coordinated, EU-wide interpretation of the United Nations Convention on the Law of the Sea (UNCLOS) in order to ensure coherent action against and effective criminalisation and deterrence of hybrid activities, acts of sabotage and violations of sovereign rights in the EU’s maritime areas, notably in the Baltic Sea, while recalling UNCLOS’s objective of ensuring the peaceful use of the seas; encourages the Commission and the Member States to draw on the Australian example of establishing ‘cable protection zones’, providing legal safeguards and criminalising damage to submarine cables beyond the 12-nautical-mile territorial sea limit, accompanied by active monitoring, surveillance and response in cooperation with relevant third-country partners;

40. Calls on the Member States and the European Defence Agency (EDA) to advance the PESCO projects Critical Seabed Infrastructure Protection (CSIP), Harbour & Maritime Surveillance and Protection (HARMSPRO), Integrated Multi-Layer Air and Missile Defence System (IMLAMD) and Counter Unmanned Aerial System (C-UAS) to boost surveillance, detection and defence capabilities against airborne and maritime threats; calls on the Commission, in cooperation with the High Representative and in consultation with the Member States, to propose a European defence project of common interest dedicated to the integrated defence of the maritime environment and the seabed;

Formal Removes footnote markers from the references to the Critical Entities Resilience Directive and the NIS2 Directive.

41. Welcomes the adoption of the Critical Entities Resilience (CER) Directive10Directive and the NIS2 Directive11Directive as important steps towards strengthening resilience against hybrid attacks, but stresses that implementation delays across the Member States represent a shared urgent vulnerability and calls for their full and timely implementation; urges the Commission to make full use of its monitoring and enforcement powers; calls on the Member States to embed resilience by design as a standard requirement in all new and revised legislation;

42. Expresses concern over foreign ownership of critical infrastructure in the EU, in particular by Russia and China, which greatly increases the risk of espionage and interference and strategic dependence; welcomes the political agreement reached between Parliament and the Council on a strengthened EU foreign direct investment (FDI) screening mechanism; calls on the Member States to rapidly implement this regulation, complemented by a ‘Buy European’ approach, where possible, for critical infrastructure and defence equipment with a view to strengthening the EU’s strategic autonomy;

64. Strongly condemns the instrumentalisation of migration by third countries or hostile non-state actors in order to destabilise a Member State or put pressure on the EU; notes the specific provisions on the instrumentalisation of migration recently included in key pieces of EU legislation; notes the Commission’s announced revision of the mandate for Frontex; underlines that this revision should provide for the legal basis, analytical capabilities, and adequate human, financial and technical resources required, which would also help strengthen the EU’s response to hybrid threats;

Adds a paragraph condemning the assault on the EU's southern border in Ceuta on 30 and 31 July 2026 and the subsequent invasion of Ceuta, and calls for an independent investigation.

65. Strongly condemns the assault on the EU’s southern border in the city of Ceuta, carried out on 30 and 31 July 2026, as well as the subsequent invasion of Ceuta, constituting an attack on the territorial integrity and sovereignty of a Member State; deplores the use of irregular migration flows as an instrument of hybrid warfare directed against the stability and security of a Member State, and therefore calls for an independent and comprehensive investigation to clarify responsibility for the planning and execution of this attack and identify the objectives pursued;

66. Condemns Russia’s systematic drone incursions and cross-border provocations targeting the Member States along the EU’s eastern flank as a calculated campaign of intimidation against civilian populations; welcomes the Commission communication on the EU’s eastern regions bordering Russia, Belarus and Ukraine, and its explicit recognition that the EU’s eastern border regions face structural and sustained threats from Russia and Belarus; calls on the Commission to translate this recognition into dedicated funding streams under the 2028-2034 multiannual financial framework, including dedicated funding to enhance integrated border protection capabilities, modernise physical and digital border surveillance infrastructure – in line with NATO standards – at the EU’s external land borders; underlines that focus should be placed on advanced detection, monitoring and countermeasure systems against unmanned aerial systems to protect critical infrastructure such as airports, energy facilities, and transport hubs and support the Member States in deploying interoperable airspace awareness systems, electronic protection measures, and rapid incident response capacities; stresses that measures must be proportionate, defensive, and civilian-protection-oriented, ensuring continuity of essential services and freedom of movement within the Schengen area;

86. Instructs its President to forward this resolution to the Council, the High Representative and the Commission.

EXPLANATORY STATEMENT

A war that does not look like war

The European Union today is neither at peace nor in open armed conflict. Adversaries operate deliberately in the grey zone, below the threshold of an armed attack. Hybrid operations are not random incidents. They are combined, intelligence-led and coordinated acts, carried out by states — including through proxies, intermediaries and non-state actors — designed to appear as isolated events, while producing effects comparable to conventional aggression. Their ambiguity is by design: it makes attribution harder and slows our response. This report starts from a simple but consequential premise: hybrid acts can constitute a form of warfare regardless of whether conventional force is used. The security environment we face is not peace, but a kind of “zero-stage” warfare in which adversaries exploit the gap between our peacetime governance structures and the speed a real response demands.

Who is behind it

Russia — acting directly or through Belarus and other proxies — is the gravest hybrid threat facing the Union and its Member States. China, Iran and North Korea are also developing hybrid campaigns. Non-state actors — organised crime, kleptocratic networks, private military companies, faith networks and influence-for-hire operators — may conduct or enable them as well. The report therefore calls for a comprehensive approach that addresses Russian and Belarusian activity while recognising the growing role of China, Iran and North Korea.

The main battlegrounds

Information and cognitive warfare. Foreign information manipulation and interference (FIMI) is a core element of hybrid warfare, aimed at eroding trust in democratic institutions, deepening polarisation and undermining support for European defence — including support for Ukraine. These campaigns increasingly use sophisticated cognitive-psychological methods and are amplified by AI-generated content, deepfakes and automated networks. Our response remains too reactive; the report insists FIMI be treated as a serious security threat, with real-time detection, attribution and proactive response, and that societal resilience — media literacy, independent journalism, civic preparedness — be treated not as a secondary concern, but as a central pillar of security.

Cybersecurity. Cyberspace is now the fifth military domain and a central enabler of hybrid campaigns. The report stresses that full cyber protection does not exist, and that Europe must shift its mindset towards resilience — trained through frequent, realistic exercises and extended across the whole economic fabric. But it is equally clear that resilience and defence alone cannot deter hostile actors: it therefore calls for sovereign cyber capabilities — for detection, attribution and response, including offensive capabilities — and, in cooperation with NATO, for work on the prerequisites for proportionate, lawful cyber countermeasures to ensure credible deterrence. It warns that AI is now both a weapon and a target.

Critical infrastructure. Energy, transport and communications are both critical enablers and strategic assets for the Union’s defence, resilience and civilian protection, and they are increasingly the target of hybrid attacks. This infrastructure forms an interconnected system that cannot be protected in isolation, and greater connectivity increases its vulnerability. The report condemns the hybrid attacks targeting it and calls for reduced reliance on high-risk suppliers, stronger investment screening and full implementation of existing resilience law (CER Directive, NIS2), and the protection of the space domain. It also calls on Member States to embed resilience by design as a standard requirement in all new and revised legislation.

From fragmentation to a decisive response

The central argument of this report is that the Union must move from a reactive to a proactive posture, to be able not only to withstand hybrid attacks, but also to deter and respond to them. That starts with a shared threat picture: no single Member State can detect coordinated campaigns alone, which is why the report urges Member States to increase intelligence sharing through the EU’s Single Intelligence Analysis Capacity (SIAC), and calls for the EU’s role in aggregating cross-border data and coordinating common procedures for situational awareness and attribution to be formally recognised as EU coordination and support competences. On this basis, the report calls for a cross-domain action plan against hybrid warfare and a single point of coordination between the Commission and the EEAS — and insists that any violation of a Member State’s sovereignty be met with an effective, proportionate and coordinated response, including calibrated retaliatory options. It presses for every accountability tool to be used, including a dedicated horizontal sanctions framework for hybrid threats and action against the illicit financial flows that fund attacks on our democracies. And it urges advancing towards a genuine European Defence Union as a stronger European pillar of NATO, with the mutual defence clause (Article 42(7) TEU) operationalised for severe hybrid scenarios. It is equally clear about the limits: national security remains primarily a Member State responsibility, and a stronger EU role must respect exclusive competences and the protection of classified information.

Geographical considerations

Hybrid threats affect the whole Union but take different forms across regions. The report condemns Russia’s drone incursions and provocations along the Eastern Flank and calls for dedicated funding to protect the EU’s external borders, while maintaining a 360-degree approach that recognises the distinct vulnerabilities of the Baltic, Nordic-Baltic, Black Sea, Mediterranean, south-eastern and Arctic regions. It strongly condemns the instrumentalisation of migration by third countries and hostile non-state actors to destabilise a Member State or put pressure on the Union, and notes the announced revision of the Frontex mandate as an opportunity to strengthen the EU’s response to hybrid threats. It stresses that funding should follow strategic exposure and demonstrated need, while ensuring support for all regions facing hybrid threats.

Working with allies and partners

NATO remains the cornerstone of collective defence for its members, and the report calls for EU-NATO action that is complementary, mutually reinforcing and operationally coordinated. It supports deeper cooperation with Ukraine, Moldova, Armenia and the Western Balkans — front-line testing grounds for Russia’s tactics, and sources of learnt lessons — and with like-minded partners including the United Kingdom, Norway, Canada, Japan, Korea, Australia and Taiwan, . It highlights in particular Taiwan’s whole-of-society resilience model as one the EU can learn from.

Why this matters now

The credibility of deterrence rests not only on capabilities, but on political will, cohesion and a shared understanding of the threat — precisely the qualities Russia’s hybrid strategy is designed to erode before any military threshold is reached. Building public understanding of how close and how real this threat is itself a matter of preparedness and deterrence. This report is intended as a step towards that clarity — and towards a Union able to defend not only its territory, but the democratic foundations on which its security depends.