CEPA

How can the US and other democracies safely use drones, including those made in China or using Chinese components? Commercial and civilian drone use has expanded in recent years and will undoubtedly continue to grow as tech evolves. Drones use the airspace in ways that challenge existing regulations and raise concerns about supply chain security, since many drone components and over 85% of drones operating in the US are of Chinese origin. 

The Federal Communications Commission’s ban on all foreign-made drones failed to address the root of the supply chain issue: Chinese firm DJI still dominates the global market. Of the almost 840,000 drones registered with the Federal Aviation Administration (FAA), DJI made more than two-thirds. Public safety agencies such as police and fire departments currently operate approximately 25,000 DJI drones. The expense of replacing these is beyond the budget of most agencies. Chinese companies also dominate production of the microelectronics used in drones and other products, with a more than 70% market share. Even Ukraine’s drone makers depend on Chinese components. Bans don’t work because it is impossible to achieve “full self-sufficiency.” 

Instead, the issue at hand is how to manage and secure an airspace populated by Chinese-made drones. The immediate solution is not a ban or a requirement to buy only western-made drones. This may be a good long-term goal, but it will take time and investment to replace China. 

DJI and China are only one part of a larger problem. Chinese suppliers are deeply embedded in American consumer goods from dishwashers to cars and trucks, and many are connected to the internet — thus vulnerable to cyber-espionage or disruption. The cost to the US of replacing Chinese products in all goods, not just drones, is estimated at roughly $14 trillion over 25 years. 

So, how can we ensure security in a world populated by connected Chinese devices?

The Trump Administration has taken valuable steps to manage drones in US airspace. A June 2025 Executive Order created an interagency task force to secure US airspace from drone incursions by foreign actors, drug cartels, and unauthorized operators near critical infrastructure, military installations, and mass gatherings. The EO requires the FAA to provide automated, real-time access to identifying information linked to drone ID signals, restricts drone flights over sensitive facilities, and streamlines federal grant programs to let state and local agencies acquire advanced counter-drone and drone detection technologies. This is good progress, but there is more to do. 

CEPA’s Solving the Drone Dilemma series explores the problem and suggests practical policy solutions.

The series explores several key themes centered on the challenges and necessities of supply chain security and regulating drones:

  1. The US and Europe’s heavy reliance on Chinese drone components creates data exfiltration risks and exposes western firms to retaliatory export bans. 
  2. Blanket bans on Chinese technology are counterproductive, stifle innovation, and fail to address DJI and other Chinese companies’ existing market saturation. 

The series urges greater cooperation with Ukraine and emphasizes international collaboration and industrial investment, urging Western nations and NATO allies to diversify supply chains, leverage wartime innovations from Ukraine, and provide long-term government contracts to build a resilient manufacturing base. There is a strong focus on airspace safety and modernization, advocating for a shift away from inefficient, temporary “no-fly” bans toward centralized drone traffic control systems, standardized tracking protocols (such as Remote IDs), and unified regulatory frameworks inspired by international models to safely unlock commercial potential.

Get the Latest
Sign up to receive regular Bandwidth emails and stay informed about CEPA's work.

A reliance on Chinese drone technology is both risky and unavoidable. The options are to accept risk, ban the products, or find a way to manage risk. All three options can work, depending on the level of risk and the cost of alternatives. The risks of connectivity vary by device. We may accept the risk of using Chinese white goods (like washing machines) and require alternative approaches for others, such as cars or drones. 

Taking advantage of digital connectivity is one solution that could become a useful precedent for consumer devices. An architecture to reduce risk could use cloud-based data intermediaries. DJI drones, for example, would not communicate directly with China, but to a US-based intermediary. For drones, this could build on existing FAA drone databases and law enforcement’s recently authorized, automated, real-time access to Remote ID signals. A few telecom companies are already developing drone protection systems that take advantage of 5G connectivity.

A new drone management structure would combine mandatory identification, data intermediaries, and permissions or geofencing (a virtual boundary around a specific geographic location) for sensitive areas. Unauthorized drones could be quickly identified and acted upon under 2026 “Safer Skies” authorities. Drones transmit digital identifiers that can be used to avoid the kind of disruption around airports seen in the US and Europe. The risk to data and services in sensitive use cases, such as for law enforcement or commercial applications like deliveries or imaging, can be managed by data monitoring. 

Elements of a near-term response already exist. Many digital technologies are already connected to the cloud for updates and servicing. The spread of 5G and 6G networks will accelerate this. The interconnected economy could provide risk management in new ways that take advantage of advances in telecommunications, cloud services, and artificial intelligence tools. Think of it as a spam filter on steroids. 

The concept of data intermediaries could be extended to include other consumer technologies to reduce risk from Chinese supply chains without entailing unacceptable costs, since in the near term, creating an alternative supply chain will be an expensive and lengthy process.

Ultimately, securing Western airspace and consumer markets does not require an all-or-nothing choice between bans and vulnerability. Building independent Western supply chains is an important long-term goal, but the immediate situation requires new tools for risk management rather than reactive bans. Using digital connectivity, cloud-based data intermediaries, ubiquitous networks, and automated oversight can allow the US and other market economy allies to safely use Chinese-manufactured technology and commercial services. Beginning with drones, a network-centric approach provides a scalable blueprint to safeguard airspace and critical infrastructure today while laying the regulatory and technological foundation to secure an increasingly interconnected global economy.

Bandwidth is CEPA’s online journal dedicated to advancing transatlantic cooperation on tech policy. All opinions expressed on Bandwidth are those of the author alone and may not represent those of the institutions they represent or the Center for European Policy Analysis. CEPA maintains a strict intellectual independence policy across all its projects and publications.

Tech 2030

A Roadmap for Europe-US Tech Cooperation

Learn More
Read More From Bandwidth
CEPA’s online journal dedicated to advancing transatlantic cooperation on tech policy.
Read More

In July, the continent acquired two rulebooks for one defense base. The EU Commission proposed five flagship projects under the European Defence Industry Programme (EDIP) on July 3, then NATO endorsed its own Strategy for Industry-NATO Cooperation four days later.

Two blueprints less than a week apart, yet the fact that there is more than one multilateral body overseeing military procurement is mentioned only once.

That one mention is in the NATO document, which says cooperation with the EU will run “through staff-to-staff contacts,” to “avoid unnecessary duplication.” This role isn’t handed to any joint body or agreement; it will just be individuals talking to each other.

There are two access points for the defense industry, one marked requirements, the other funding, and every company will be left to decide which one to trust.

The NATO strategy scraps its 2013 framework and offers a single portal, the NATO Front Door for Industry, where a demand signal based on the alliance’s planning will tell companies what capabilities it expects to need.

Alongside this, the NATO Engine, a broker service, will match companies with no spare capacity to factories with an available line, providing “contractor- or factory-for-hire,” the alliance said.

The service targets smaller suppliers, is voluntary, and NATO says it carries “no direct funding implications or legal impact.”

Over at the EU, the EDIP comes laden with money and conditions. There are €1.5bn ($1.7bn) in grants available, a security-of-supply regime, and its own demand aggregation and procurement track.

There are also rules on content. Parts from the EU or associated countries must make up at least 65% of the cost of the components used, and design authority must be in the bloc.

The different regimes raise an obvious question. Since 23 of NATO’s 32 member states are also in the EU, why run two systems at all?

The answer is that the two memberships do not match. The US, UK and Turkey are in NATO but sit outside the funding perimeter of the EDIP, and its content rule is deliberately designed to build a European base and keep money spent on procurement inside the bloc.

The NATO strategy pushes the other way, toward an allied base that keeps American, British, and Turkish suppliers inside the tent.

As it was endorsed at NATO’s summit in Ankara on July 7, Secretary General Mark Rutte announced tens of billions of US dollars in transatlantic defense deals, the sort EDIP’s content rule restricts.

The division has a logic. NATO defines the requirement and how the kit must fit, while the EU provides money and industrial-policy strings. One side organizes demand, the other conditions supply.

The trouble is where they join.

Get the Latest
Sign up to receive regular emails and stay informed about CEPA's work.

And they don’t need to duplicate a single project to collide. Manufacturers increase factory capacity based on confidence, and they need a signal they can bank on. Here, there are two bodies giving signals which do not align.

NATO can tell a company that a capability is wanted across the alliance, yet commit none of its members to buying it. The EDIP can put money behind a related product, but only if enough of it is built and designed in the EU.

For a major manufacturer with a compliance team, that is a puzzle. For a mid-sized supplier weighing a new line, it is harder. Which signal would convince them to take out a loan for expansion? The safe answer is to build smaller, or wait.

The gap belongs to no one. Each system is coherent on its own. The risk of failure lives in the space between them, which no single body answers for — because the two don’t even share a membership. When the only link across that space is “staff-to-staff contacts,” and it breaks, each side can say with plausibility that the job was never theirs.

The cost is not split evenly either. A major manufacturer keeps a government-relations office, fluent in both regimes, while a supplier in Košice or Cracow files twice with no one to spare. Such fixed costs fall hardest on the smallest firms, the ones the EU and NATO both claim to want.

The case for hurrying Europe’s factories has already been convincingly made, and the two systems need to be made legible to each other before their routines harden.

That will mean a joint demand annex for both systems, mutual recognition of routine compliance filings, and one entry point for small- and medium-sized enterprises that qualify under each.

None of it needs a treaty, only for two secretariats to stop treating each other’s paperwork as someone else’s problem.

A factory that is hedging its bets doesn’t ramp up production. And Europe’s readiness is the cost of such hedging.

Europe has spent three years teaching itself to spend on defense again. It has not yet learned to avoid duplication of that spending.

Miro Sedlák is an associate research fellow at the Institute for Central Europe and a doctoral candidate in security and defense studies at the Armed Forces Academy of General M. R. Štefánik in Slovakia.

Europe’s Edge is CEPA’s online journal covering critical topics on the foreign policy docket across Europe and North America. All opinions expressed on Europe’s Edge are those of the author alone and may not represent those of the institutions they represent or the Center for European Policy Analysis. CEPA maintains a strict intellectual independence policy across all its projects and publications.

Comprehensive Report

Unleashing Defense Innovation

By CEPA International Leadership Council

Building a future-capable force.

May 5, 2026
Learn More
Europe's Edge
CEPA’s online journal covering critical topics on the foreign policy docket across Europe and North America.
Read More

When Anthropic deemed Claude Mythos too dangerous to release, the only non-American given access to judge its safety was the UK’s AI Security Institute. Within a week, the British institute published an evaluation warning that Mythos could hack into previously secure critical infrastructure.

How to ensure the safety of AI models has become a pressing challenge. Governments around the globe do not want to depend on the companies’ own claims, or on classified assessments from the US government. OpenAI CEO Sam Altman has called for a US-led standard-setting forum, and Demis Hassabis from Google DeepMind has voiced support for the creation of a US standards body.

So far, this political momentum is creating a cacophony rather than solutions. Japan leads a G7 AI Safety project, the European Union is developing an AI Act that it hopes will become the “global benchmark,” and the US runs evaluations through the Commerce Department’s Center for AI Standards and, since June, a classified benchmarking process. The United Nations is getting in the game, too: its International Scientific Panel on AI risk recently released its own set of principles and standards.

National safety institutes aim to build governments’ technical capacity to check the risks of frontier AI models. The US, EU, Japan, Singapore, South Korea, Canada, France, Kenya, and Australia were founding members of the International Network of AI Safety Institutes, launched in 2024 alongside the UK. Since then, Germany, Brazil, Israel, and China have also established their own institutes.

Third-party testing is “a really important part of the AI ecosystem,” says Anthropic co-founder Jack Clark. These institutes can play an important role in safety evaluations because they have access to specific national security information that frontier labs do not. Yet if every government starts developing competing standards, companies could face a patchwork of overlapping evaluation regimes with confusing, fragmented standards. And complete AI safety represents a quixotic mirage. OpenAI’s new cybersecurity models recently went rogue, escaped a safe testing sandbox, connected to the Internet, and attacked Hugging Face, a digital library popular among developers.

Amid the rush for government oversight against such risks, the UK institute is out ahead. Born out of the world’s first major AI safety summit, convened at Bletchley Park in 2023, it poached top talent from Google’s London-based AI lab DeepMind and other leading labs. This helped build trust with companies. In recent months, it has reached agreements with OpenAI, Microsoft, Anthropic, and Google DeepMind, who have shared access to their frontier models for evaluation before deployment.

Get the Latest
Sign up to receive regular Bandwidth emails and stay informed about CEPA's work.

The Institute’s success stems from obtaining “political will early on, freedom to operate, funding, and attracting top talent,” says Herbie Bradley, a Cambridge PhD candidate who helped set up the institute and is now founding an AI startup in San Francisco.

The UK institute has uncovered major safety gaps in every leading AI model it has tested. Before OpenAI released its cutting-edge GPT-5 chatbot last year, the institute found more than a dozen vulnerabilities that would have allowed users to develop biological weapons, all of which were fixed before release.

The Institute has done “world-leading work” according to a recent assessment by the Ada Lovelace Institute, an independent research body. Governments, industry, and researchers depend on the Institute’s evaluations of more than 30 frontier models. Rather than keeping its methods and findings proprietary, the platform publishes them on its open-source evaluation platform Inspect.

Britain’s booming AI sector adds credibility. So far this year, British technology startups have raised over $14.5 billion in venture capital, more than all other major European markets combined. Britain’s Nobel Prize winners Geoffrey Hinton and Sir Demis Hassabis, founder of Google’s DeepMind, have developed much of AI’s basic science. Britain sits outside the EU’s AI Act, which critics say holds firms and their customers to burdensome compliance requirements.

Admittedly, the UK approach does not represent a silver bullet. The London institute lacks the power to impose decisions on governments or companies. It also does not cover the full range of prospective threats. Different AI risks require different expertise, which is why specialized private sector and non-profit analysts have emerged, such as METR, a research institute based in Berkeley that specializes in testing for autonomous replication, or Apollo Research, a start-up headquartered in London that focuses on deceptive and scheming behavior. Bradley is skeptical that any single third-party evaluator could set global standards.

But for now, the UK institute enjoys a unique position, respected both in Washington and Brussels. The partnership with the US government is, in Bradley’s words, “very robust,” built on Britain’s position inside the Five Eyes intelligence-sharing network. Bradley can even imagine safety warnings being shared with China for catastrophic risks, such as a model that could help build a biological weapon.

Anthropic’s Mythos and OpenAI’s rogue Hugging Face attack will not be the last AI scares. When the next crisis arrives, governments will need an independent appraisal. For now, the best place to conduct such a review is in London.

Marta Granados Hernández is a US Google Public Policy Fellow at the Center for European Policy Analysis and a master’s candidate at Georgetown University’s Master of Science in Foreign Service program, concentrating in Science, Technology, and International Affairs. 

Bandwidth is CEPA’s online journal dedicated to advancing transatlantic cooperation on tech policy. All opinions expressed on Bandwidth are those of the author alone and may not represent those of the institutions they represent or the Center for European Policy Analysis. CEPA maintains a strict intellectual independence policy across all its projects and publications.

Tech 2030

A Roadmap for Europe-US Tech Cooperation

Learn More
Read More From Bandwidth
CEPA’s online journal dedicated to advancing transatlantic cooperation on tech policy.
Read More

On July 12, three explosives-laden Unmanned Surface Vessels (USVs) motored into an enemy port, maneuvered past whatever defenses may have been in place, and blew up a drydock cradling a submarine undergoing maintenance.

If the USVs had been Ukrainian and the target had been Russian, the robot raid would have been old news.

But the 8-meter (26 ft) Saronic Technologies Corsair USVs belonged to US Central Command. And the target was a naval base in the Iranian port of Bandar Abbas. It was “the first time American forces have employed sea drones in combat operations,” CENTCOM stated.

In the same way, more countries, including the United States, are adopting the Shahed-style one-way aerial attack drones that both Russia and Ukraine fling at each other by the hundreds; more countries are also adopting the kinds of one-way USVs that Ukrainian forces have built their sea denial strategy around.

USVs are cheap and hard-hitting. But they’re no naval panacea. In rushing explosive robot boats into service, countries risk using them the wrong way. For all their many benefits, strike USVs aren’t one-for-one replacements for pricier anti-ship munitions. They’re complementary, not supplementary.

The concept of an explosives-laden, remotely controlled attack boat isn’t new. But the Ukrainian military honed the idea to a sharp point after losing most of its warships in the first days of Russia’s wider war on Ukraine starting in February 2022. By the following year, Ukrainian USVs including the 6-meter Sea Baby and the 5.5-meter Magura, both costing a few hundred thousand dollars per copy, were chasing down Russian warships on the Black Sea.

Three years later, the satellite-controlled USV victims include at least one corvette, a couple of landing ships, some patrol boats, a survey vessel and a tanker. Armed with remotely aimed guns, rockets, surface-to-air missiles, and even first-person-view aerial attack drones, the drone boats have shot down Russian helicopters and jets and harassed ground forces along the Black Sea coast, especially in Crimea. 

In July, a Ukrainian USV even beached itself on the Kinburn Spit in southern Ukraine and landed a gun-armed ground robot: history’s first all-robot amphibious assault.

Get the Latest
Sign up to receive the Age of Autonomy newsletter and CEPA's latest work on Defense Tech.

Given their low cost and high-profile kills, it’s no wonder USVs caught the attention of other countries. The US Navy isn’t lacking for traditional warships, but even it has found a niche in its force structure for explosive USVs. Now navies everywhere are rushing to field their own one-way explosive boats. Taiwan is practically rewriting its sea denial strategy to incorporate a large flotilla of USVs.

These late adopters should proceed with caution. Slow, easy to spot from the air and prone to getting lost amid heavy radio jamming, USVs are actually pretty easy for a prepared foe to defeat.

There were zero hard kills against Russian warships between late 2024 and late 2025 as the survivors of its Black Sea Fleet retreated to the anchorage in Novorossiysk in southern Russia, which is protected by physical barriers, aerial and sea patrols, and lots of sailors manning heavy machine guns. Ukrainian USVs finally started registering hits again as 2025 ground into 2026, but only because Ukrainian leaders made the deliberate and risky decision to escalate the Black Sea naval war by striking 183 dry cargo ships, tankers, and auxiliaries belonging to Russia’s unregistered commercial “shadow fleet” up to July 19. That move has triggered retaliatory Russian strikes on Ukrainian grain ships.   

USVs cannot replace fast, accurate and low-flying anti-ship cruise missiles, which might cost five or six times as much per unit as a USV per unit, but which are much more survivable and pack much more destructive potential thanks to their combination of big warheads and kinetic energy. 

It’s not for no reason that the majority of anti-ship strikes in America’s on-again, off-again war on Iran have been executed by air-launched cruise missiles or, in one chilling case, a torpedo fired by a lurking nuclear-powered attack submarine. 

For all their early success on the Black Sea, USVs are still weapons of desperation. Or, at best, expedients that provide inexpensive munitions for bulking up a sea denial force. It’s telling that Ukraine itself is still investing billions of dollars in new anti-ship cruise missiles even as it leans hard into USVs.

That those American Corsairs could motor into Bandar Abbas and blow up a drydock says more about the state of Iranian coastal defenses after months of sporadic bombardment than it does about the potential for such unmanned vessels to rewrite naval doctrine.

David Axe is a journalist, author, and filmmaker in South Carolina. For 20 years, he has covered war for Forbes, Rolling Stone, The Daily Beast, The New York Times, The Washington Post, Vice, The Village Voice, Voice of America, and others. He has reported from Syria, Afghanistan, Iraq, Somalia, and elsewhere. His current focus is on covering Russia’s wider war on Ukraine. 

Europe’s Edge is CEPA’s online journal covering critical topics on the foreign policy docket across Europe and North America. All opinions expressed on Europe’s Edge are those of the author alone and may not represent those of the institutions they represent or the Center for European Policy Analysis. CEPA maintains a strict intellectual independence policy across all its projects and publications.

Comprehensive Report

Unleashing Defense Innovation

By CEPA International Leadership Council

Building a future-capable force.

May 5, 2026
Learn More
Europe's Edge
CEPA’s online journal covering critical topics on the foreign policy docket across Europe and North America.
Read More

Explosive drones can kill you but also transport you to medics. They can sink ships and reconnoiter the battlefield in incredible detail. They can do something else too — they can make the frontline infantry lighter and nimbler by lifting heavy equipment that would otherwise have to be carried.

That represents a significant development on Ukraine’s frontlines, where the armed forces are again developing new skills which every army will have to consider in this new world of warfare.

That’s because both armies have used small first-person-view (FPV) drones to establish heavily policed kill zones along the front line. “With a 20 km kill zone, it’s practically impossible to organize logistics,” Anatolii Tkachenko, a Ukrainian mortar battery commander with 92 Brigade, told the author. “Infantry are walking 30 km. Mortar crews and drone operators are walking 10 to 15 km.”

In key sectors such as Kostiantynivka and Pokrovsk, Russia deploys its top drone units, as do the Ukrainians. Russia typically sends waves of infantry to infiltrate Ukrainian positions, while its drone operators, such as from Rubicon, focus on striking Ukrainian logistics — a model that was first successfully used in Kursk.

In such kill zones, traditional resupply by truck is extremely hard. Resupply runs are growing rarer in those strategic sectors, so many soldiers have to walk for miles, carrying everything they will need. Unmanned Ground Vehicles (UGVs) are now used across the front for logistics, but the road leading to Kostiantynivka is littered with their wreckage. The next option, and what Ukraine has increasingly been relying upon for resupply, has been heavy bomber drones.

“Heavy bomber drones are currently the only viable way to resupply forces within 10 km of the front line,” Andrii, a drone operator from 59 Brigade (Da Vinci Wolves), said in an interview. “UGVs still provide fairly unreliable logistics because of enemy FPV drones. Any offensive without logistics is doomed from the outset, and so is a sustainable defense.”

This is far from easy. Russia has gotten better at shooting those drones down. Data from its Rubicon Center claims a 54% year-over-year increase in multicopter drone takedowns in June, which includes heavy bombers. 

But the tactic is being used and is drawing attention. Russian milblogger Alexander Karchenko stated that lightly equipped Ukrainian infantry are infiltrating positions, while pressing ahead via resupply from the heavy bomber drones. Once they reach an advanced position and receive heavier equipment for an assault, they can quickly attack. Previously, slow-moving targets, such as soldiers burdened with heavy loads, made for easier drone prey.

“One of the consistent themes in ground warfare is the problem created by the increasing weight carried by infantry and special operations soldiers,” Rob Lee, senior fellow at the Foreign Policy Research Institute, told the author. “Infantry mobility is critical, but militaries have struggled dealing with the tradeoff between force protection and mobility.”

Get the Latest
Sign up to receive the Age of Autonomy newsletter and CEPA's latest work on Defense Tech.

So why can’t Russia do the same? The answer is that the Kremlin’s forces still lack high-quality heavy bomber drones of their own, something Vladimir Putin was forced to admit in a December press briefing. Russian soldiers have even been forced to scour the battlefield for downed Ukrainian heavy bomber drones, while also creating an ecosystem devoted to their repair and re-use.

Ukrainian heavy bomber drones, such as the Vampire, which the Russians have nicknamed the Baba Yaga, can also fly at night, while having a reach of up to 60 km (37 miles). Operating at night, even while being loud, makes them harder to shoot down.

Lee added that some Ukrainian assault regiments and special forces (SSO) battalions have “adapted by employing heavy bomber drones in direct support of small infantry or SSO teams.”

Drones such as the Vampire can “sustain these teams with food, water, ammunition, medical gear, and other logistics needs.”

During an assault, Ukrainian units will be limited by their ammunition supply, for example. If Ukrainian special forces conduct a raid behind enemy lines, they will need to be resupplied as soon as their supplies begin to run low. Heavy bomber drones flying at night increase the odds of keeping the unit supplied and sustaining its operations.

As artificial intelligence proliferates across the front on both sides, minimizing signatures will become increasingly crucial, making lightly equipped troops the key to future operations.

Drones are the main obstacle to staying alive on the front, so “remaining in tree lines or forest with cover and concealment as much as possible is a priority,” said Lee. “In some cases, assault teams will try to cross open fields as fast as possible by carrying minimal gear and sprinting across. Heavy bomber drones can then bring their rucksacks and other equipment to them once they are under the concealment of trees.”

If Ukraine’s ongoing drone counteroffensive proves successful in the coming months, Ukrainian soldiers will need to press ahead to take ground. While it may make the gray zone somewhat less dangerous to traverse, drones will remain a significant threat.

The ability to remain agile and move quickly will be important for soldiers advancing to recapture ground while being resupplied by heavy bomber drones. This is just one piece in the broader effort to develop combined arms warfare with unmanned systems on the battlefields in Ukraine.

David Kirichenko is a Ukrainian-American freelance journalist who has been covering Russia’s full-scale war against Ukraine since 2022, and is an Associate Research Fellow at the Henry Jackson Society. He can be found on X/Twitter @DVKirichenko.

Europe’s Edge is CEPA’s online journal covering critical topics on the foreign policy docket across Europe and North America. All opinions expressed on Europe’s Edge are those of the author alone and may not represent those of the institutions they represent or the Center for European Policy Analysis. CEPA maintains a strict intellectual independence policy across all its projects and publications.

Comprehensive Report

Unleashing Defense Innovation

By CEPA International Leadership Council

Building a future-capable force.

May 5, 2026
Learn More
Europe's Edge
CEPA’s online journal covering critical topics on the foreign policy docket across Europe and North America.
Read More

For much of the past decade, American strategic debate has been dominated by a single proposition. The United States is told it must choose between theaters of conflict. China is described as the pacing threat, and Washington should therefore commit its finite resources toward the Indo-Pacific. Europe, while important, can no longer be the center of gravity.

The logic is understandable. China possesses the world’s second-largest economy and the most formidable long-term challenge to the international order.

Yet the debate rests on a false premise. While the Asia theater adherents say America must choose, its adversaries do not. They increasingly treat the two theaters as inseparable.

Russia’s war against Ukraine has made this unmistakably clear. Moscow’s defense industrial base now depends heavily on Iranian drones, North Korean ammunition, and Chinese dual-use technologies. Beijing may not have crossed the threshold into direct military support, but Chinese firms have provided critical components that sustain Russia’s ability to wage war. Its military secretly engages in joint planning with Russia to degrade and destroy the Starlink satellite system. North Korea has used the conflict to deepen military cooperation with Moscow while testing new systems and gaining leverage. Iran, meanwhile, has demonstrated how rapidly technologies developed in one conflict can migrate to another.

The strategic question is not whether Russia and China have formed a formal alliance. They have different interests and priorities. What matters is that their activities are complementary: Moscow diverts Western attention and military resources, Beijing supplies economic and technological capacity, while Iran and North Korea provide military support.

The implications extend well beyond Ukraine. China is studying the war closely — not because Taiwan is Ukraine, but because the conflict offers lessons about alliance cohesion, sanctions, industrial mobilization, and democratic resilience. Russia, for its part, has become increasingly dependent on relationships that strengthen China’s broader geopolitical position. The result is a loose system of mutual reinforcement.

For decades, the US organized its national security apparatus around geography. Combatant commands, diplomatic bureaus, and alliances evolved to manage distinct regions. That model made sense when threats could largely be contained within theaters. Today’s authoritarian competitors ignore those boundaries.

The challenge is not simply military. China and Russia cooperate on energy, critical minerals, space, cyber capabilities, and influence operations while exploiting democratic vulnerabilities and shaping the international environment in ways that favor authoritarian governance. Their strength lies not in centralized coordination but in flexibility.

This does not mean the US should abandon prioritization. Strategic choices remain unavoidable. Elbridge Colby at the Department of Defense and others are right that China represents the most significant long-term challenge to the international order. But recognizing China as the pacing threat does not mean Europe becomes a secondary theater whose importance is steadily diminishing.

NATO offers a useful reminder: the alliance embodied a broader truth — that security in Europe, North America, and beyond is interconnected. That insight remains valid.

Get the Latest
Sign up to receive the Age of Autonomy newsletter and CEPA's latest work on Defense Tech.

Europe’s role in this new strategic environment must change. European allies must assume greater responsibility for deterrence, accelerate defense-industrial production, and reduce critical dependencies. Increased defense spending is necessary but insufficient. Europe must develop the capacity not only to defend itself, but also to compete effectively.

At the same time, Washington must resist the temptation to frame every strategic debate as a contest between theaters. The choice between Europe and Asia is, in many respects, a symptom of a deeper problem: the erosion of institutions capable of thinking across regions and time horizons.

The US once excelled at integrating military power, economic statecraft, technological innovation, and alliance management into coherent strategies. Today, too much policymaking is reactive, fragmented, and consumed by immediate crises. Governments struggle to address “meta threats” that cut across regions, domains, and bureaucratic boundaries. The result is a tendency to reduce strategy to false binaries: Europe or Asia, deterrence or competition, military power or economic security.

The answer is not to abandon strategic prioritization, but to organize democratic power around the reality that these challenges increasingly reinforce one another.

First, the United States and NATO should reject the premise that strategic success requires choosing between Europe and Asia. They possess the economic resources, alliance networks, and military capabilities to address multiple challenges simultaneously — provided they organize themselves accordingly.

Policymakers should integrate European and Indo-Pacific strategy rather than treating them as competing portfolios. NATO’s engagement with Japan, South Korea, Australia, and New Zealand reflects the reality that developments in one theater increasingly shape outcomes in another.

Second, the transatlantic community must accelerate defense-industrial integration. The wars and crises of the coming decades will not be decided solely by the size of military inventories, but by the ability of democracies to innovate, produce, and sustain collective action over time.

Third, democratic governments must devote greater attention to the political dimension of strategic competition. Authoritarian powers understand that their greatest opportunities often lie not in defeating Western militaries, but in exploiting divisions within alliances and eroding public confidence in democratic institutions.

The central challenge of our time is not choosing between Europe and Asia. It is recognizing that America’s competitors have already linked regions, technologies, and political systems that democratic governments still approach separately.

The decisive advantage will belong not to those who concentrate on a single theater, but to those who can think and act across all of them.

David M. Cattler is a Senior Fellow at the Center for European Policy Analysis (CEPA). He is a senior transatlantic security leader with more than 35 years of experience across the US government, NATO, and the Intelligence Community. Most recently, he served as Director of the Defense Counterintelligence and Security Agency (DCSA) and was previously NATO’s Assistant Secretary General for Intelligence and Security, the alliance’s senior intelligence official. Cattler is a graduate of the US Naval Academy and Georgetown University and was an MIT Seminar XXI Fellow.

Europe’s Edge is CEPA’s online journal covering critical topics on the foreign policy docket across Europe and North America. All opinions expressed on Europe’s Edge are those of the author alone and may not represent those of the institutions they represent or the Center for European Policy Analysis. CEPA maintains a strict intellectual independence policy across all its projects and publications.

Comprehensive Report

Unleashing Defense Innovation

By CEPA International Leadership Council

Building a future-capable force.

May 5, 2026
Learn More
Europe's Edge
CEPA’s online journal covering critical topics on the foreign policy docket across Europe and North America.
Read More

Hungary’s MPs might ordinarily hope to pack their bags in mid-June and head off to Lake Balaton to enjoy the delights of summer. Not this year.

July 21 marks 100 days since Viktor Orbán and his illiberal democrats were swept from power in Hungary, and 73 since the Péter Magyar-led government took office. During that period, the country’s institutions have witnessed a storm with few precedents.

The parliamentary spring session formally ended in mid-June, but extraordinary sittings are being held almost daily as the new government works around-the-clock to dismantle the last of its predecessor’s bastions.

This has only been possible because Magyar’s Tisza party won a two-thirds majority in the legislature, which hands it extraordinary powers to act, including through changes to the constitution. The result has been a full-frontal assault on the system Orbán had carefully crafted over the past 16 years.

That power forced the country’s head of state, President Tamás Sulyok, from office on July 19, and will also remove the head of the Constitutional Court. Both were important Orbán allies and could have disrupted the government’s plans.

As part of the so-called Operation Cleansing Fire, announced by Magyar, the new government began dismantling the long-standing state of emergency legal framework that Orbán’s administration had maintained, temporarily suspended the public broadcaster, and shut down the Sovereignty Protection Office. Established in 2024, the latter institution investigated foreign-funded activities and used this to target journalists, academics and civil society groups.

As old offices are dismantled, the government is creating new bodies, like the National Asset Protection and Recovery Office. Its main objective is to track unlawfully appropriated public assets and the recovery of what the government describes as squandered public funds.

Aware that he may be accused of a partisan power grab, Magyar has introduced other changes that will apply to him and other politicians. Parliament passed another set of changes to the constitution which established a term limit of two four-year mandates for the prime minister. Calculated retroactively from 1990, this bars Orbán from returning to power as prime minister, but will apply to all holders of the office.

Get the Latest
Sign up to receive regular emails and stay informed about CEPA's work.

The new constitutional amendments, adopted on July 13, will also retire judges aged over 70. That will remove four of the 15 Constitutional Court justices, including the body’s president. Sulyok was basically forced to sign his own death warrant; he did not resign but was ousted by the constitutional amendments he had virtually no choice but to sign.

The president argued that “the democratic rule of law in Hungary has come to an end”, and he even sought a legal opinion from the Venice Commission.

Magyar pledged consultation with all parties and citizens on the new president who, according to the prime minister, must be able to represent all Hungarians without any political affiliations. Not even a day after Sulyok was ousted, he officially recommended Hungarian chess grandmaster Judit Polgár, whose life is chronicled in a recent Netflix documentary, as a candidate. But this hasty decision, made in the absence of public consultation, caused an uproar and resulted in Polgár publicly announcing that she would not accept the nomination. So far, this is Magyar’s first public blow.

On the economic front, Hungary’s sluggish economy will reap some benefits from the government’s agreement to make reforms in exchange for more than €16bn ($17bn) in frozen EU funds. It was not only one of the major promises during the campaign but a vital sum that, if used smartly, can kickstart the country’s economic growth and development. Hungary has also joined the European Public Prosecutor’s Office, an EU body responsible for investigating financial crimes and misappropriation.

What about Orbán himself? He is watching, using his own words, this “arbitrary rule” from the US, where he and some family members have been attending the final three games of the World Cup.

His popularity has continued to plunge. According to the latest polls by Medián, one of Hungary’s most reliable pollsters, 69% of Hungarians would not want to see him in any important political position in the future.

Other senior members of the previous Fidesz administration have been seeking new roles. Gergely Gulyás, Fidesz parliamentary leader, has resigned, while former foreign minister Péter Szijjártó announced he would become external relations executive for the Chinese electric car maker, BYD.

Szijjártó, who was taped making offers of help to Russian Foreign Minister Sergey Lavrov, had previously co-signed many agreements between Hungary and BYD. The government has announced an inquiry into the appointment.

Hungary’s election spring clean provided a popular mandate to change the government; the summer has demonstrated just how seriously the new administration takes that role. The autumn, in order to keep the promises and maintain public support, should be about the return of accountability and economic growth.

Ferenc Németh is a Ph.D. candidate at Corvinus University of Budapest and a Fulbright visiting researcher at Georgetown University. He has previously conducted research in Toronto and Skopje, worked as a research fellow at the Hungarian Institute of International Affairs, and interned at EULEX Kosovo. His areas of expertise include Central and Southeast Europe, EU enlargement, and regional security. Ferenc was a Denton Fellow at CEPA in 2024. 

Europe’s Edge is CEPA’s online journal covering critical topics on the foreign policy docket across Europe and North America. All opinions expressed on Europe’s Edge are those of the author alone and may not represent those of the institutions they represent or the Center for European Policy Analysis. CEPA maintains a strict intellectual independence policy across all its projects and publications.

Comprehensive Report

Unleashing Defense Innovation

By CEPA International Leadership Council

Building a future-capable force.

May 5, 2026
Learn More
Europe's Edge
CEPA’s online journal covering critical topics on the foreign policy docket across Europe and North America.
Read More

Serbia’s greatest security vulnerability today is not hostile foreign spies. It’s the structure of its own intelligence system.

Built to protect governments rather than the nation, shaped by political loyalty more than professional expertise, Serbia’s security institutions remain poorly adapted to an era of hybrid threats, economic coercion, cyber conflict, and strategic competition.

Cosmetic reform is no longer enough. Serbia needs a new intelligence system.

The problem is older than today’s government, and older than the one before it.

Like many intelligence services across post-communist Europe, Serbia’s security institutions inherited a philosophy from the Cold War period. The security apparatus was primarily designed to protect the political system from internal opposition rather than to protect the state from external threats. That outlook recognized that the likeliest threat to regime survival came from the people not from outsiders, however malevolent.

Loyalty therefore mattered more than professional expertise. Domestic surveillance received greater priority than strategic intelligence. In plain terms, it was a tool of political control and was routinely used against opposition figures and even ordinary citizens. After all, the security services had a prized ability to eavesdrop, intimidate and disrupt; it was a tempting weapon for many post-communist governments across Central and Eastern Europe.

The overthrow of Slobodan Milošević’s regime in October 2000 transformed legislation and organizational charts. But it did not transform institutional culture. Political influence over appointments remained extensive. Parliamentary oversight developed formally but never acquired genuine authority. The operational habits inherited from the previous system — monitoring domestic opponents and serving political principals — persisted well beyond the moment of democratic transition.

So did the absence of accountability and a resort to the so-called black arts. The 1999 assassination of newspaper founder and anti-regime figure Slavko Ćuruvija remains unresolved to this day.

Serbia entered the 21st century with institutions operating inside democratic structures while preserving the reflexes of their authoritarian past.

That legacy matters because the security environment has fundamentally changed.

Serbia’s principal challenges now originate elsewhere: foreign influence campaigns, cyber operations, critical infrastructure vulnerabilities, energy coercion, technological dependency, and strategic competition over supply chains and critical minerals. These are not threats that can be managed through domestic surveillance or internal control. They require strategic intelligence, long-term analysis, inter-agency coordination, and above all, public legitimacy.

Get the Latest
Sign up to receive regular emails and stay informed about CEPA's work.

An institution designed to monitor political opponents cannot easily switch to become a gatherer and interpreter of complex geopolitical competition. The gap between what Serbia’s security sector was built to do and what it now needs to do has become a strategic liability.

Serbia need not be a passive target. But it will remain vulnerable until it builds institutions capable of recognizing and resisting external pressure — including Russia’s well-documented interest in sustaining precisely this kind of institutional vacuum in the Western Balkans.

Meaningful reform requires more than replacing directors or passing another intelligence law. It requires a redesign of the entire system around clear mandates, genuine accountability, and institutional separation.

First, domestic security, military intelligence, and foreign intelligence must be clearly separated, each anchored to a single ministry with unambiguous lines of responsibility. The current overlapping competencies is not accidental; it is convenient for those who wish to avoid scrutiny, and is damaging to the security of the state.

Second, communications interception must operate under a single, exclusive legal framework, concentrated in one accountable agency and subject to judicial authorization in every case. Dispersed and poorly supervised interception powers are not a security capability. They are a source of institutional corruption and a standing invitation to abuse.

Third, Serbia needs an independent analytical center for strategic assessments — a body whose sole function is to provide the government and parliament with an independent picture of the external strategic environment. Not to monitor domestic opponents and not to serve the political needs of the moment, but to understand the world.

Fourth, senior appointments must depend on professional qualifications rather than political loyalty, with fixed mandates and transparent accountability to parliament. This is not merely an administrative preference. It is the minimum condition for institutions capable of earning — rather than demanding — public trust.

Fifth, parliamentary oversight must become substantive rather than ceremonial. Supervision without access, expertise, and the genuine capacity to sanction wrongdoing is not oversight. It is theater.

Perhaps the most consequential reform concerns neither institutions nor legislation. It concerns trust.

Hybrid threats and foreign influence operations succeed most easily where citizens already distrust their own institutions. Disinformation spreads fastest where official sources have lost credibility. Every confirmed abuse, every politically motivated appointment, every instance of surveillance turned against citizens rather than external threats widens the space available to those who wish to destabilize Serbia from outside.

Public trust is therefore not a democratic luxury. It is a national security asset. An intelligence service that citizens fundamentally distrust cannot effectively protect them, regardless of its budget, its authorities, or its staff.

In an era of great-power competition, intelligence services are no longer instruments of regime survival. They are instruments of national resilience.

Nikola Lunić is a Serbian geopolitical and security analyst and retired Navy Captain. He previously served as Serbia’s Defense Attaché in London and as Executive Director of the Council for Strategic Policy. He is currently a strategic affairs consultant and a regular guest lecturer at the Faculty of Law, University of Osijek. He writes on Balkan security, intelligence governance, and European defense policy for outlets including the Kyiv Post and New Eastern Europe.

Europe’s Edge is CEPA’s online journal covering critical topics on the foreign policy docket across Europe and North America. All opinions expressed on Europe’s Edge are those of the author alone and may not represent those of the institutions they represent or the Center for European Policy Analysis. CEPA maintains a strict intellectual independence policy across all its projects and publications.

Comprehensive Report

Unleashing Defense Innovation

By CEPA International Leadership Council

Building a future-capable force.

May 5, 2026
Learn More
Europe's Edge
CEPA’s online journal covering critical topics on the foreign policy docket across Europe and North America.
Read More

Ask an AI system for tips on how to shoplift without getting caught in English, and it will refuse to help. If the prompt is made in a different language, you may well get a response to assist you in committing a theft.

Current AI systems are less accessible, less useful, and less safe for users of so-called “low-resource languages.” These are languages such as Swahili and Burmese that may well be spoken by many, but for which little digitized data is available.

Market forces have not mobilized the necessary investment to address these shortcomings. Fierce economic and geopolitical competition funnels attention and resources into the development of a narrow set of frontier models, which are optimized for a small set of dominant and well-resourced languages.

This imbalance results in a global inequity that warrants policymakers’ attention. The longer the gap exists, the wider it will grow. If AI accelerates socio-economic development, it is urgent to address this imbalance now. Access to frontier AI capacity is already limited by high cost and a lack of infrastructure in low-income countries. And even for those with technical access, language can be a constraint.

Although models can process prompts in different languages, their multilingual capacity fails to remove all access barriers. Researchers point to a so-called “token tax”; access to models is usually billed by use of tokens, the units into which natural language is split for processing. Some languages require more tokens to represent the same content compared to English. This gap drives up cost and latency.

Get the Latest
Sign up to receive regular Bandwidth emails and stay informed about CEPA's work.

Models generally reason more effectively in English than in other languages, studies show. Bias creeps in — for instance when a multilingual model associates the word “dove” in all languages with “peace” even though in Basque it can be an insult.

This language gap also represents a safety risk. Researchers have shown that it is possible to jailbreak AI systems — that is, to breach their safeguards — by machine-translating prompts into other languages. Studies have also demonstrated that translating malicious input into a low-resource language generates more unsafe content than sticking to English.

The weak performance of models in low-resource languages is not because they are less suitable for AI than English is. Model design choices and the limited availability of training datasets are responsible. Until now, market forces have not directed resources to address this challenge, and they are unlikely to do so.

Policymakers must correct course. They should:

It’s important to tackle the systemic disadvantage of low-resource languages. Otherwise, much of the world risks missing out on the promise of the AI revolution.

Christian Schlaepfer is a former Swiss diplomat and negotiator of tech and AI policy at the United Nations. He is a guest at the Institute for Logic, Language and Computation at the University of Amsterdam and policy advisor at the think tank Starling Institute.

Bandwidth is CEPA’s online journal dedicated to advancing transatlantic cooperation on tech policy. All opinions expressed on Bandwidth are those of the author alone and may not represent those of the institutions they represent or the Center for European Policy Analysis. CEPA maintains a strict intellectual independence policy across all its projects and publications.

Tech 2030

A Roadmap for Europe-US Tech Cooperation

Learn More
Read More From Bandwidth
CEPA’s online journal dedicated to advancing transatlantic cooperation on tech policy.
Read More