From Disinformation to Cognitive Warfare 

Cognitive warfare has moved from NATO research papers into a State of the Union speech. Europe's monitoring machinery has not moved with it. 

In Strasbourg on 16 September, Ursula von der Leyen told the European Parliament that election campaigns poisoned by foreign propaganda and conspiracy theories built on deepfake video amount to "cognitive warfare". She asked for a European capacity to anticipate, detect and respond. (European Commission) 

The term is borrowed. NATO researchers have used it for years to describe attempts to shape cognition and behaviour below the threshold of armed conflict. (NATO) What is new is the venue, and the words institutions choose end up deciding what they build capacity to look for. 

Europe has relabelled this problem roughly every three years: fake news, then misinformation, then disinformation, then Foreign Information Manipulation and Interference, or FIMI, the EU's current term for organised influence activity by outside states. Each relabelling widened the unit of analysis. Fake news described a post. FIMI described an actor and a behaviour. Cognitive warfare describes a campaign with objectives. 

Checking claims, missing campaigns 

Fact-checking was built for the narrowest definition and works there. It does less when an operation is not selling one specific falsehood. A single campaign carries false claims, true claims stripped of context, emotional video, real grievances, satire, memes and commentary from people with no idea whose ecosystem they are feeding. Parts contradict other parts, which costs the operator nothing if the objective is distrust rather than agreement. 

So the question widens: where did the narrative start, who amplified it, how did it mutate across platforms and languages, which networks carried it. 

Mentions, keywords and sentiment scores describe what is visible, which is what media monitoring sells. Narrative intelligence tries to describe the structure underneath. Which narratives keep travelling together. Whether a message surfaces on Telegram before it appears in short-form video. Whether the framing changes as it moves from Russian into French, Lithuanianor Spanish. Whether accounts that look independent behave as a network. Network analysis produces evidence for those questions; attributing the result to a particular state remains a separate and harder problem. 

We traced that pattern in Armenia's election cycle - where narratives moved from Russian-language Telegram into local short-form video before they reached broadcast.

AI changed the price, not the idea 

Generative models let one operation produce hundreds of variants of a message, translate them, rewrite them for different political communities, and test which version performs before producing more of it. The gain is tempo: more languages, more formats, more chances that something sticks. Deepfakes get the conference slides; volume is the cheaper capability. Recommendation algorithms supply the second half, since influence depends on what platforms repeat, not only on what someone produces. 

The same economics run the other way. Video, podcasts, broadcast television, Telegram, TikTok, Facebook, online news and comment sections now form one environment no analyst team can read by hand. The open question is what the detection systems are asked to find: keyword matches, or the shape of an operation. 

Lots of Signals. No Shared View.

Governments track interference. Intelligence services investigate networks. The EU maintains FIMI frameworks. Researchers study hybrid threats, fact-checkers verify claims, platforms run their own monitoring. Operations cross the boundaries these bodies are organised around. A narrative can begin in Russian-language Telegram, enter a domestic political community, pick up a local messaging app and reach mainstream debate in three countries before the first monitoring report clears review. 

What the framing implies is not more content monitoring but a common operating picture: agreed methods for identifying narratives, tracing networks, measuring amplification, separating coordination from organic argument, and setting evidentiary standards for attribution. That requires comparable outputs, not a single central system. 

The informational side of autonomy 

A day after the speech, Canada's prime minister, Mark Carney, addressed the same parliament while the EU discussed deeper ties, including Mrs von der Leyen's proposal to make Canada its first "associate member", a status the treaties do not currently contain. (Reuters) Canada is also the first non-European country to join procurement under SAFE, the EU's joint defence instrument, after an agreement concluded in June 2026. (Council of the European Union) 

Strategic autonomy is usually argued in physical terms: weapons production, semiconductors, cloud infrastructure, critical minerals, energy, and now the AI infrastructure European states rent. A country can secure all of it and still have little idea what is happening inside its own information environment. The capability in question is not control over what citizens think, but the ability to tell democratic argument apart from an organised attempt to manufacture it. 

Where the caution belongs 

"Warfare" is a heavy word for a democracy to apply to its own public debate. Political disagreement is not an attack, criticism of institutions is not foreign interference, and an unpopular opinion is not a hostile operation. NATO's definition is broad enough to swallow ordinary politics if handled loosely, which is why evidentiary standards decide whether the category is useful or merely convenient. 

The Commission has proposed a capacity to anticipate, detect and respond. Its next documents will have to specify what that capacity contains, which bodies it connects, what it may monitor, and what standard of proof it applies before calling something an operation. 

Sources 
European Commission; NATO; Reuters; Council of the European Union  

Next
Next

SEB finances Repsense's next stage of growth with €1M in venture debt