It is tempting, but wrong, to see the crisis in Ukraine’s war leadership as a simplified tale of personal spats between the youthful Defense Minister Mykhailo Fedorov and the Soviet-trained Commander-in-Chief Oleksandr Syrskyi.
Each was clearly irritated by the other, and each has paid for it with the loss of his job, opening the way for a new C-in-C, the reformist Gen. Mykhailo Drapatyi.
But the confrontation concerned real and unavoidable issues. It was a fundamental battle over the character of the Ukrainian state and its way of war. It was never about drone procurement or digital apps; it was a battle over resource allocation, civilian oversight, and force design.
Barry Posen, the MIT political scientist whose The Sources of Military Doctrine remains the standard account of how militaries change, made an argument that still holds: armed forces do not resist new technology; they resist losing control over how resources are allocated and who decides. Personalities matter, but the substance of the confrontation is essentially institutional.
Fedorov’s tenure at the Defense Ministry brought this friction to a decision point.
His procurement reforms did not just seek to modernize Ukrainian defense spending: they challenged the General Staff’s control over how personnel, equipment, and resources were allocated. Similarly, after conducting a comprehensive performance audit of Ukraine’s 120 brigades, Fedorov’s team discovered that nearly a sixth suffered disproportionately from poor leadership and high casualty rates. His solution was pragmatic: consolidate underperforming brigades and reallocate their personnel to competent and more effective units that were chronically short of manpower.
Unsurprisingly perhaps, the General Staff resisted. The breaking point seems to have occurred when civilian reformers tried to resource innovative, technology-led units, only to find the military hierarchy prioritizing manpower for legacy formations, such as the controversial 425 Assault Regiment, which persisted in high-casualty attacks.
Fedorov originally entered the ministry with an integrated air-land-economy plan: to protect Ukrainian airspace, halt Russian advances on the ground, and attack the economic foundations of Moscow’s war effort. Taking office in January, he argued that after six months Ukraine was beginning to regain the initiative and had created an opportunity to compel Russia toward peace through force. His dismissal therefore appeared to his supporters on the streets as an interruption of a strategy that was beginning to work.
By dismissing Fedorov, President Zelenskyy underestimated Ukrainian civil society. Having seen the prospect of finally taking the fight deep into Russia through asymmetric warfare, the public believed that momentum was at risk. Just as in 2014 and 2022, citizen groups proved decisive to reset the state’s trajectory.
Zelenskyy has already made one major concession to the backlash by replacing the 61-year-old Syrskyi, but has stopped short of restoring his 35-year-old rival, Fedorov, to the Defense Ministry. Fedorov rejected Zelenskyy’s initial offer to remain as an adviser. The president has since offered the ex-minister several other positions, including deputy prime minister for military innovation. Fedorov has refused them all, arguing that only three offices genuinely determine the course of the war: the president, the defense minister, and the commander-in-chief.
Fedorov and his supporters want reinstatement. More Protests are expected.
Zelenskyy therefore faces a tough decision. The stakes could not be higher. He must preserve executive authority, while restoring street stability, and maintain the confidence of both his military leaders and his Western donors.
Whatever his decision, Ukraine’s reformers have spent years identifying the military’s weaknesses and arguing that the country must fight differently. Now, with Drapatyi in charge of the military, that reform agenda has moved from outside criticism to the highest ranks of the wartime command structure. But even the restoration of Fedorov would not guarantee success.
Both Drapatyi and Fedorov would need sustained backing from the president and parliament, along with the authority to overcome resistance within the institutions he is trying to reform. Without that mandate, his return could reproduce the confrontation that led to his initial dismissal.
Expectations must remain realistic. Drapatyi inherits a military with limited manpower, entrenched interests, and a larger enemy determined to continue the fight. He also lacks the deep institutional networks built by his predecessors. Even the best commander cannot reform mobilization, training, procurement, and force organization without sustained backing from the president and an empowered defense minister.
The reformers have won the public argument, and one of their own now commands the army. This was the easy part. Drapatyi must now prove that the reformers’ diagnosis delivers battlefield results, while Zelenskyy must decide whether to grant his military commanders full civilian backing at some cost to his own executive authority.
Maksym Beznosiuk is an analyst whose work focuses on Russia, Ukraine, and international security. He is an Associate Fellow at GLOBSEC.
William Dixon is a Senior Associate Fellow of the Royal United Services Institute and an Associate Fellow at GLOBSEC. He specializes in cyber and international security issues.
Europe’s Edge is CEPA’s online journal covering critical topics on the foreign policy docket across Europe and North America. All opinions expressed on Europe’s Edge are those of the author alone and may not represent those of the institutions they represent or the Center for European Policy Analysis. CEPA maintains a strict intellectual independence policy across all its projects and publications.
Russian shadow warfare is a many-headed hydra. Its efforts can rise and fall in intensity, can close airports or menace heads of state, target electricity grids in midwinter and sever undersea cables.
The latest threat comes from Russia’s highly developed electronic warfare capabilities, which are being used to misdirect explosive-filled drones into NATO airspace. A May 19 incident over Estonia saw a NATO jet shoot down the device.
That, anyway, is the conclusion of the Ukrainian government. “Russia continues to redirect Ukrainian drones into the Baltics with the use of its electronic warfare,” Foreign Ministry spokesperson Heorhii Tykhyi said. “We apologize to Estonia and all of our Baltic friends for such unintended incidents.” Ukraine’s military only ever used Russian airspace for its attacks, he said.
Similarly, on May 15 Finnish authorities directed citizens in the Helsinki region to remain indoors due to suspicious drone sightings, which reportedly may have been the result of Russian GPS hijacking.
Although Russia denies involvement, Ukrainians blame an electronic warfare technique called “spoofing” for the breach. Russian forces began employing GPS-deception techniques against Ukrainian drones as early as 2022, with documented spoofing efforts becoming increasingly common by 2023. But it wasn’t until March 23 that the first case of a Ukrainian drone breaching NATO airspace due to Russian interference was recorded in Lithuania.
So, what exactly is spoofing? Spoofing, jamming, and meaconing are three terms that fall under the umbrella of electronic interference, and each poses its own risks.
Spoofing sends a counterfeit signal, which is interpreted as authentic by the receiver. Jamming blocks a receiver by producing a noisy signal, causing it to lose its position. Meaconing (a combination of the words masking and beacon) is a subtype of spoofing that uses real GNSS (Global Navigation Satellite System) signals, rather than fabricated ones, but introduces a delay to mislead a system on where exactly it is. Jamming is rather obvious; spoofing is difficult to detect, and meaconing is the most covert of the three.
Russia has been developing these techniques for years, even using such techniques during the Cold War. In 2017, several ships in the Black Sea experienced abnormalities with their GPS position, which showed them located at an airport.
This was an indication of spoofing efforts for drone defense — drones have geofencing rules that prevent them from flying over airports. By changing a drone’s position to an airport, the drone is programmed to reroute or land immediately.
Electronic interference affects more than just drones. Spoofing is an example of signal disruption, but jamming still poses a powerful threat. Russian satellites have jammed GPS signals across Europe on at least three occasions since 2019. Experts are unsure of the aim. While each interruption lasted less than 10 seconds, the military application of this technology is broad; jamming from a satellite has significantly more range than from the ground. But whether intentional or accidental, this disruption warrants serious concern.
The Baltic states have been scrambling to counter electronic warfare, but a widespread, reliable method of defense has yet to be implemented. Ukraine, however, is taking action to address the root cause. It has launched an investigation to determine how Russia is interfering with receiver signals, while also developing drones that can fly without satellite assistance and are thus less vulnerable to hostile interference. While individual NATO states have integrated spoofing defense strategies into their national security framework, alliance-wide coordination for an effective solution remains a challenge.
As long as Russia continues to avoid consequences, it will continue its electronic warfare efforts. While NATO has condemned Russia’s actions, a lack of clear repercussions has failed to alter the Kremlin’s cost-benefit assessment. Russia’s gray-zone toolkit goes beyond GPS spoofing to include cyberattacks, subsea cable cutting, and drone-induced airport closures. Shadow warfare or hybrid attacks against alliance states have more than tripled since 2023 and will undoubtedly continue to rise unless NATO acts. The logical next step for NATO members is to invoke Article 4.
Article 4 has been invoked seven times since NATO’s founding. It allows the parties to consult together, “whenever, in the opinion of any of them, the territorial integrity, political independence or security of any of the Parties is threatened.” Most recently, Poland and Estonia invoked Article 4 in early 2025, after Russian aircraft entered their airspace. Since then, Ukrainian drones spoofed by the Russians have breached NATO borders at least a dozen times.
If Article 4 is invoked when Russian aircraft enter NATO airspace, why not when Russian electronic interference causes Ukrainian drones to cross NATO borders? And why not in response to persistent gray-zone operations targeting critical infrastructure, in which Article 4 has not been invoked despite the operational investments NATO has made to counter such threats?
Whether or not NATO members choose to invoke Article 4, more Ukrainian drones will certainly enter allied airspace as a result of Russian interference. As Ukraine’s attacks on Russia succeed (the new offensive has struck dozens of targets up to July 24), NATO can expect Russian retaliation, and with it, spillover that further endangers NATO member states. Given that spoofing, jamming, and meaconing are as effective as they are low-cost, they are a phenomenon that is here to stay.
Erin Bailey is an intern at the Transatlantic Defense and Security program at CEPA.
Dr. Benjamin L. Schmitt is a Senior Fellow at the Department of Physics and Astronomy and the Kleinman Center for Energy Policy at the University of Pennsylvania, a Senior Fellow for Democratic Resilience at the Center for European Policy Analysis, a fellow of the Duke University “Rethinking Diplomacy” Program, and a Term Member of the Council on Foreign Relations. (Twitter: @BLSchmitt).
Europe’s Edge is CEPA’s online journal covering critical topics on the foreign policy docket across Europe and North America. All opinions expressed on Europe’s Edge are those of the author alone and may not represent those of the institutions they represent or the Center for European Policy Analysis. CEPA maintains a strict intellectual independence policy across all its projects and publications.
Russian telecom operators have just admitted a significant decline in mobile internet use across the country— up to 40% in some regions. Overall, a national decline of up to 10% is expected by the end of the year.
This is new; there was no parallel decline in 2024–2025; thus the present-day change is caused not by the worsening Russian economy but by the Kremlin’s interfering hand. It is an act of policy.
This years-long effort was the ultimate goal of the Kremlin and the FSB all along. It is true that the decline in mobile internet use affects economic activity, which has already been under a lot of pressure because of the war and Ukrainian drone attacks. It’s worth remembering that the Kremlin and its security services are happy to pay whatever economic price their political aims require.
Their main concern is to wean Russians off their phones and away from sharing online what they witness in their daily lives. It’s a recognition that internet footage can damage public morale — from a drone attack to protests to riots. The FSB seems unable to prevent people from posting such videos, including the latest campaign against the warehouses of Wildberries, Russia’s Amazon.
A few years before the start of the full-scale invasion, the Russian authorities recognized that the major challenge online was not posed by content created by the hard-core opposition, like Navalny’s organization, or foreign media, like Radio Liberty and the BBC Russian service, or Russian media in exile.
Rather, it would be content generated by the users themselves on social media — the sort of stuff people see from their windows.
To curtail this essential feature of social media was the main reason for introducing the Russian Sovereign Internet a few years before the start of the full-scale war —it was built to create a switch allowing censors the option to isolate a region or city where a crisis deemed dangerous for the political regime was unfolding.
Since the war started, more repressive measures were introduced to complement this technical system to prevent ordinary users from generating and sharing dangerous content. First, global social media like Facebook, Twitter, and YouTube were banned and blocked, and Russian outlets were heavily censored. Second, posting footage of drone attacks became punishable. Initially, this was with fines, but the FSB has now hinted that those posting videos of attacks could be accused of high treason.
But even the security services understand that in a time of danger and destruction, the urge to share could become almost irresistible. The threat of punishment, even high treason charges, may not stop Russians from sharing.
The next option is to try to change social behavior. This was tried once, at the start of the war, when people were taught not to discuss politics in public. A wide range of measures were applied to change this bad habit — from outright repression to all sorts of rumors — including claims that people were being denounced by their fellow passengers on the Moscow metro for checking news on Ukrainian media. As a result, Russians did indeed stop talking about sensitive things in public spaces, including public transport and coffee shops.
Since the summer of 2025, a new effort to change social behavior has been underway — most importantly, to wean them off mobile internet. It was introduced first in regional centers, like Nizhny Novgorod, and as a result, the majority of Nizhny’s residents moved to old-fashioned public Wi-Fi networks. The map of publicly available Wi-Fi nodes in coffee shops and libraries became a sought-after thing.
The experiment faced its biggest test this year, when the authorities extended the shutdown to the two great Russian cities of Moscow and St Petersburg. Mobile internet interruptions were implemented incessantly, using a variety of excuses.
The shutdowns did create outrage from ordinary people and the elites — after all, it may be illegal to protest against the war but not so much against an inconvenience in everyday life. Most blamed the FSB, but in truth the measure was implemented with the full consent of a Kremlin paranoid about political stability.
As a result, some habits did change. The popularity of public Wi-Fi rose sharply. In the first half of 2026, the number of connections to public Wi-Fi networks increased 3.5-fold compared to the first half of 2025.
But this model works, apparently, only when things are stable and predictable and there is time to plan for one’s actions — in business and private life, in other words, the Kremlin may be able to change routine behavior.
But when drones hit refineries, when petrol stations are suddenly without gas, and queues form miles down the road, Russians keep posting and sharing videos, expressing their frustration and outrage. For that phenomenon, the Kremlin currently has no good answer.
Andrei Soldatov and Irina Borogan are Non-resident Senior Fellows with the Center for European Policy Analysis (CEPA). They are Russian investigative journalists and co-founders of Agentura.ru, a watchdog of Russian secret service activities. Their book , Our Dear Friends in Our Dear Friends in Moscow, The Inside Story of a Broken Generation, was published in 2025.
Europe’s Edge is CEPA’s online journal covering critical topics on the foreign policy docket across Europe and North America. All opinions expressed on Europe’s Edge are those of the author alone and may not represent those of the institutions they represent or the Center for European Policy Analysis. CEPA maintains a strict intellectual independence policy across all its projects and publications.
The dismissal of Defense Minister Mykhailo Fedorov on July 15 has exposed a deeper divide within Ukraine’s military leadership: a conflict between an older Soviet-influenced approach to warfare and a younger generation seeking to modernize the armed forces through technology and institutional reform.
The dismissal has caused week-long protests and is far from resolved. It is about much more than personalities — it represents a key junction in the country’s war for survival.
The decision to dismiss the 35-year-old Fedorov was made without any communication with policymakers or the public and was announced as parliament began a 30-day summer recess. It triggered some of Ukraine’s largest protests since 2022, largely because of Fedorov’s popularity and reputation as a dynamic, IT-savvy minister impatient with the old structures.
Over the past few months, he had become one of the government’s most recognizable and widely supported figures. Appointed Defense Minister in January, Fedorov built on his reputation for digital transformation by bringing the same approach to the military.
He pursued the integration of new technology into the armed forces, a course that some Ukrainian military bloggers argue proved largely successful. At the same time, six months was too short a time to judge the success of his reforms. Many of the structural problems facing the armed forces, with mobilization the most prominent, remain unresolved. His dismissal, therefore, interrupted a reform program whose long-term effectiveness had yet to be tested.
The decision to dismiss Fedorov continued the President’s Administration’s tradition of sidelining figures who accumulate political weight, although the dismissal was explained by deteriorating relations between Fedorov and Commander-in-Chief Gen. Olexandr Syrskyi. “I wanted unity very much. The sides did not achieve it,” President Zelenskyy said. He argued that it was impossible to have a military commander and a defense minister unable to communicate.
Fedorov, however, presented a different account during a press conference held amid the protests. “All the initiatives that we proposed began to be blocked, and Syrskyi is not ready to personally talk about problems face to face,” he argued, adding that the general had given Zelenskyy an ultimatum to dismiss him.
If Zelenskyy’s team had thought Fedorov would go quietly, they were wrong. His dismissal opened a Pandora’s box that extended far beyond the fate of one minister. Days of crisis meetings followed as a single personnel decision rapidly escalated into a broader crisis about how Ukraine should fight the war.
The president reconsidered. On July 21, he replaced Syrskyi with Maj. Gen. Mykhailo Drapatyi, a prominent 43-year-old officer with a stellar war record who had supported Federov’s criticisms.
Syrskyi, a 60-year-old veteran four-star general, represents an older generation of officers trained in Soviet military academies who continued their careers after Ukraine gained independence, carrying many elements of that military tradition with them. Having been educated in the same system as many Russian generals, Syrskyi understands the logic of Russian military operations, as demonstrated by his successful operational planning in 2022–2024, including the widely praised Kharkiv counteroffensive.
However, that background also has a downside. Syrskyi has repeatedly been criticized for a Soviet-style approach to military planning that often prioritized symbolic victories over soldiers’ lives.
During the first phase of the war, operations such as the liberation of the Kyiv and Kharkiv regions were fast, innovative, and highly successful. After the bloody battle of Bakhmut, however, Syrskyi acquired a reputation as a “butcher” because of heavy personnel losses (an estimated 10,000 dead and seriously wounded during that 2022-23 engagement) and the continued reliance on costly frontal assaults that treated personnel as expendable.
His reputation deteriorated further following the chaotic withdrawal from Russia’s Kursk region, which resulted in heavy losses. Other criticisms included appointing loyal rather than competent officers to senior military positions, as well as turning a blind eye to human rights abuses within some units of the armed forces, and a chaotic order of battle that saw some units split and others poorly improvised. As a result, Syrskyi’s image struggled to compete with Fedorov’s reputation as a young and innovative reformer.
By contrast, new Commander-in-Chief Drapatyi enjoys broad public support and represents a different generation of Ukrainian military leadership.
Trained in independent Ukraine, all his experience stems from the war against the Russians. Part of his reputation stems from an action in May 2014, when he led his battalion into Mariupol to free hostages held in the city’s police headquarters during clashes with Russian-backed separatists. The video of this encounter is now famous. Less well-known, but more impressive to his comrades, was his fighting withdrawal from Russian encirclement in southeastern Luhansk in 2014 and his stabilization of the threatened Kharkiv sector in 2025. He is also seen as considerate for the welfare of his troops and willing to listen to subordinates.
All of which sounds good. However, the emergence of a younger generation of military leaders does not automatically resolve Ukraine’s challenges. As Antony Lloyd, the longtime Times war correspondent, wrote, only time will tell whether the new men are right or whether Syrskyi fought the only way he could and is “rehabilitated as a commander who unflinchingly accepted terrible costs because no less bloody path existed.”
It might appear Zelenskyy drew the poison from the crisis by appointing a new commander-in-chief, but Federov’s future remains unresolved. The former defense minister says he wants his old job back, and although there is an acting minister, it is still unclear who will ultimately take the position. Reappointing a just-sacked minister might be hard for the president to swallow, while Ukrainian civil society is increasingly demanding a defense minister who also embodies a new approach to waging the war.
Ukraine, therefore, faces a dilemma. At its core, this debate is not about age but about two competing concepts of warfare: one built around hierarchy and attrition, the other around technology, decentralization, and preserving scarce human resources.
The challenge is thus not simply choosing between an older and a younger generation of commanders, but combining two strengths that rarely coexist: the institutional memory and understanding of Russian military thinking possessed by the old guard with the technological innovation, accountability, and adaptability championed by the new one. It is fraught with risk; much like reconstructing an aircraft already in flight.
There is a well-known saying that “a small Soviet-style army will never defeat a large Soviet-style army.” Yet abandoning the experience accumulated over decades carries risks of its own. Whoever becomes the next Defense Minister, working alongside the new Commander-in-Chief, will inherit problems, including manpower and equipment shortages, that have no simple solution and will have to be addressed under intense public scrutiny.
Mykyta Vorobiov is a political analyst focusing on Russian and Eastern European politics, security, and information campaigns. He holds a BA in Ethics and Politics from Bard College Berlin, where his research focused on Russian visual propaganda, and an MSc in Russian and Eastern European Studies from the University of Oxford, where he examined how the Russian state uses political discourse, media, and propaganda to legitimise wartime policies. For the past five years, Nikita has published articles on politics and security for CEPA, VoxEurop, JURIST, and other outlets.
Europe’s Edge is CEPA’s online journal covering critical topics on the foreign policy docket across Europe and North America. All opinions expressed on Europe’s Edge are those of the author alone and may not represent those of the institutions they represent or the Center for European Policy Analysis. CEPA maintains a strict intellectual independence policy across all its projects and publications.
It has been a bruising few weeks in Europe for US tech firms. The latest salvo was two new fines for Google, totaling €890m, making it the third US tech firm fined by the European Union under the Digital Markets Act (DMA) after Apple (€500m) and Meta (€200m). This comes quickly on the heels of the European Court of Justice upholding massive historic fines against Google and Apple. In sum, the EU has now fined US firms €1.59 billion under the DMA. There were fines for Chinese firms ByteDance (€530m), AliExpress (€550m), and Temu (€200m) under the General Data Protection Regulation (GDPR), and fines related to the Digital Services Act (DSA) now total €1.28 billion.
The fines certainly do nothing to further transatlantic harmony. US Trade Representative, Ambassador Jamieson Greer, was quick to respond: “The EU often claims that it is looking for stability and predictability in our trading relationship, but these actions are driving massive uncertainty for US exports of goods and services to Europe.” Greer also cited recent state-backed support for Airbus: “the EU continues to target the most competitive US companies.” But Ambassador Greer did stop short of initiating a 301 action against the EU – others want that to happen.
The latest fine is the first for Google under the DMA. The company has protested the decision and stated it will damage the user experience for European users and could undermine privacy and security. There are calls in Washington for the US to retaliate via retaliatory tariffs. The European Commission is unrepentant. More DMA actions are forecast.
The Commission’s statement on the new fines had a business-as-usual air. Google was found in breach of the DMA provisions on self-preferencing in search results and ‘steering’ users to its own products in the Google Play store. Two separate decisions and two separate fines. The company has 60 days to change its search results and its store or face further penalties — including a “periodic penalty of up to 5% of its total worldwide turnover.” Commission Vice Presidents Ribera and Virkkunen chimed in with strongly worded quotes. The Commission statement did acknowledge “constructive dialogue” with the company and “good progress” on changes the Commission requires.
Google itself is likely to appeal the decision, citing impact on search results quality and the knock-on impact for small businesses in the EU. “To comply, we are having to strip away real-time Search features Europeans love — like instant pricing and direct availability for hotels, flights, and restaurants – and dismantle safety protections on Google Play,” Google Global Affairs chief Kent Walker said in his statement. There are security and privacy concerns. Google, Apple, and Meta pour billions into cyber protections that users benefit from. The data sharing requirements in the DMA have been condemned by privacy advocates and national security experts.
The fines came on the day Google announced expansion plans in Europe. Such decisions might be different if the fines continue, distracting the US and Europe at precisely the moment when China’s tech threat is most acute. Just a week before the DMA fines, Chinese AI firm Moonshot released Kimi K3, a soon-to-be fully open-source frontier AI model touted as a rival to OpenAI and Anthropic’s most advanced models. While a preliminary evaluation of Kimi K3 by the US and UK’s AI vetting shops found the model “performs significantly below the most recent frontier cyber-capable models,” Moonshot’s latest “DeepSeek moment” clearly shows how quickly China is moving in the tech race — and that this is not the time for more tech-driven division between allies like the US and Europe.
The Commission has previously rejected accusations of anti-US bias out of hand, pointing to the other US companies that have launched complaints against Google and Apple and benefit from its decisions. A US version of the DMA, the “App Store Freedom Act,” was discussed on Capitol Hill this week. One of its authors, Representative Kat Cammack, offered a distinctly European view when introducing the bill: “For too long, consumers and developers have borne the brunt of anti-competitive practices on major app store marketplaces.”
The fear remains that the EU will turn its digital regulations into de facto tax collection. Ambassador Greer called for a “ceasefire” on DMA actions. The Commission is unlikely to stop here. The EU’s stated endgame is “innovation opportunities,” but this new phase for the DMA will not make Europe more competitive, and Europe will be better served by focusing more on scaling its own tech champions and investing in its capacity for tech innovation.
We at the CEPA have long focused on the opportunities for a positive, pragmatic tech agenda for both sides. There is still room for such an agenda. As China’s highly subsidized tech sector continues to find more gaps to exploit in global markets, there is a real need for this agenda.
Ronan Murphy is Director of the Tech Policy Program at the Center for European Policy Analysis.
Read more from CEPA on the DMA and a vision for a positive US-Europe tech agenda
How can the US and other democracies safely use drones, including those made in China or using Chinese components? Commercial and civilian drone use has expanded in recent years and will undoubtedly continue to grow as tech evolves. Drones use the airspace in ways that challenge existing regulations and raise concerns about supply chain security, since many drone components and over 85% of drones operating in the US are of Chinese origin.
The Federal Communications Commission’s ban on all foreign-made drones failed to address the root of the supply chain issue: Chinese firm DJI still dominates the global market. Of the almost 840,000 drones registered with the Federal Aviation Administration (FAA), DJI made more than two-thirds. Public safety agencies such as police and fire departments currently operate approximately 25,000 DJI drones. The expense of replacing these is beyond the budget of most agencies. Chinese companies also dominate production of the microelectronics used in drones and other products, with a more than 70% market share. Even Ukraine’s drone makers depend on Chinese components. Bans don’t work because it is impossible to achieve “full self-sufficiency.”
Instead, the issue at hand is how to manage and secure an airspace populated by Chinese-made drones. The immediate solution is not a ban or a requirement to buy only western-made drones. This may be a good long-term goal, but it will take time and investment to replace China.
DJI and China are only one part of a larger problem. Chinese suppliers are deeply embedded in American consumer goods from dishwashers to cars and trucks, and many are connected to the internet — thus vulnerable to cyber-espionage or disruption. The cost to the US of replacing Chinese products in all goods, not just drones, is estimated at roughly $14 trillion over 25 years.
So, how can we ensure security in a world populated by connected Chinese devices?
The Trump Administration has taken valuable steps to manage drones in US airspace. A June 2025 Executive Order created an interagency task force to secure US airspace from drone incursions by foreign actors, drug cartels, and unauthorized operators near critical infrastructure, military installations, and mass gatherings. The EO requires the FAA to provide automated, real-time access to identifying information linked to drone ID signals, restricts drone flights over sensitive facilities, and streamlines federal grant programs to let state and local agencies acquire advanced counter-drone and drone detection technologies. This is good progress, but there is more to do.
CEPA’s Solving the Drone Dilemma series explores the problem and suggests practical policy solutions.
The series explores several key themes centered on the challenges and necessities of supply chain security and regulating drones:
- The US and Europe’s heavy reliance on Chinese drone components creates data exfiltration risks and exposes western firms to retaliatory export bans.
- Blanket bans on Chinese technology are counterproductive, stifle innovation, and fail to address DJI and other Chinese companies’ existing market saturation.
The series urges greater cooperation with Ukraine and emphasizes international collaboration and industrial investment, urging Western nations and NATO allies to diversify supply chains, leverage wartime innovations from Ukraine, and provide long-term government contracts to build a resilient manufacturing base. There is a strong focus on airspace safety and modernization, advocating for a shift away from inefficient, temporary “no-fly” bans toward centralized drone traffic control systems, standardized tracking protocols (such as Remote IDs), and unified regulatory frameworks inspired by international models to safely unlock commercial potential.
A reliance on Chinese drone technology is both risky and unavoidable. The options are to accept risk, ban the products, or find a way to manage risk. All three options can work, depending on the level of risk and the cost of alternatives. The risks of connectivity vary by device. We may accept the risk of using Chinese white goods (like washing machines) and require alternative approaches for others, such as cars or drones.
Taking advantage of digital connectivity is one solution that could become a useful precedent for consumer devices. An architecture to reduce risk could use cloud-based data intermediaries. DJI drones, for example, would not communicate directly with China, but to a US-based intermediary. For drones, this could build on existing FAA drone databases and law enforcement’s recently authorized, automated, real-time access to Remote ID signals. A few telecom companies are already developing drone protection systems that take advantage of 5G connectivity.
A new drone management structure would combine mandatory identification, data intermediaries, and permissions or geofencing (a virtual boundary around a specific geographic location) for sensitive areas. Unauthorized drones could be quickly identified and acted upon under 2026 “Safer Skies” authorities. Drones transmit digital identifiers that can be used to avoid the kind of disruption around airports seen in the US and Europe. The risk to data and services in sensitive use cases, such as for law enforcement or commercial applications like deliveries or imaging, can be managed by data monitoring.
Elements of a near-term response already exist. Many digital technologies are already connected to the cloud for updates and servicing. The spread of 5G and 6G networks will accelerate this. The interconnected economy could provide risk management in new ways that take advantage of advances in telecommunications, cloud services, and artificial intelligence tools. Think of it as a spam filter on steroids.
The concept of data intermediaries could be extended to include other consumer technologies to reduce risk from Chinese supply chains without entailing unacceptable costs, since in the near term, creating an alternative supply chain will be an expensive and lengthy process.
Ultimately, securing Western airspace and consumer markets does not require an all-or-nothing choice between bans and vulnerability. Building independent Western supply chains is an important long-term goal, but the immediate situation requires new tools for risk management rather than reactive bans. Using digital connectivity, cloud-based data intermediaries, ubiquitous networks, and automated oversight can allow the US and other market economy allies to safely use Chinese-manufactured technology and commercial services. Beginning with drones, a network-centric approach provides a scalable blueprint to safeguard airspace and critical infrastructure today while laying the regulatory and technological foundation to secure an increasingly interconnected global economy.
Bandwidth is CEPA’s online journal dedicated to advancing transatlantic cooperation on tech policy. All opinions expressed on Bandwidth are those of the author alone and may not represent those of the institutions they represent or the Center for European Policy Analysis. CEPA maintains a strict intellectual independence policy across all its projects and publications.
Tech 2030
A Roadmap for Europe-US Tech Cooperation
In July, the continent acquired two rulebooks for one defense base. The EU Commission proposed five flagship projects under the European Defence Industry Programme (EDIP) on July 3, then NATO endorsed its own Strategy for Industry-NATO Cooperation four days later.
Two blueprints less than a week apart, yet the fact that there is more than one multilateral body overseeing military procurement is mentioned only once.
That one mention is in the NATO document, which says cooperation with the EU will run “through staff-to-staff contacts,” to “avoid unnecessary duplication.” This role isn’t handed to any joint body or agreement; it will just be individuals talking to each other.
There are two access points for the defense industry, one marked requirements, the other funding, and every company will be left to decide which one to trust.
The NATO strategy scraps its 2013 framework and offers a single portal, the NATO Front Door for Industry, where a demand signal based on the alliance’s planning will tell companies what capabilities it expects to need.
Alongside this, the NATO Engine, a broker service, will match companies with no spare capacity to factories with an available line, providing “contractor- or factory-for-hire,” the alliance said.
The service targets smaller suppliers, is voluntary, and NATO says it carries “no direct funding implications or legal impact.”
Over at the EU, the EDIP comes laden with money and conditions. There are €1.5bn ($1.7bn) in grants available, a security-of-supply regime, and its own demand aggregation and procurement track.
There are also rules on content. Parts from the EU or associated countries must make up at least 65% of the cost of the components used, and design authority must be in the bloc.
The different regimes raise an obvious question. Since 23 of NATO’s 32 member states are also in the EU, why run two systems at all?
The answer is that the two memberships do not match. The US, UK and Turkey are in NATO but sit outside the funding perimeter of the EDIP, and its content rule is deliberately designed to build a European base and keep money spent on procurement inside the bloc.
The NATO strategy pushes the other way, toward an allied base that keeps American, British, and Turkish suppliers inside the tent.
As it was endorsed at NATO’s summit in Ankara on July 7, Secretary General Mark Rutte announced tens of billions of US dollars in transatlantic defense deals, the sort EDIP’s content rule restricts.
The division has a logic. NATO defines the requirement and how the kit must fit, while the EU provides money and industrial-policy strings. One side organizes demand, the other conditions supply.
The trouble is where they join.
And they don’t need to duplicate a single project to collide. Manufacturers increase factory capacity based on confidence, and they need a signal they can bank on. Here, there are two bodies giving signals which do not align.
NATO can tell a company that a capability is wanted across the alliance, yet commit none of its members to buying it. The EDIP can put money behind a related product, but only if enough of it is built and designed in the EU.
For a major manufacturer with a compliance team, that is a puzzle. For a mid-sized supplier weighing a new line, it is harder. Which signal would convince them to take out a loan for expansion? The safe answer is to build smaller, or wait.
The gap belongs to no one. Each system is coherent on its own. The risk of failure lives in the space between them, which no single body answers for — because the two don’t even share a membership. When the only link across that space is “staff-to-staff contacts,” and it breaks, each side can say with plausibility that the job was never theirs.
The cost is not split evenly either. A major manufacturer keeps a government-relations office, fluent in both regimes, while a supplier in Košice or Cracow files twice with no one to spare. Such fixed costs fall hardest on the smallest firms, the ones the EU and NATO both claim to want.
The case for hurrying Europe’s factories has already been convincingly made, and the two systems need to be made legible to each other before their routines harden.
That will mean a joint demand annex for both systems, mutual recognition of routine compliance filings, and one entry point for small- and medium-sized enterprises that qualify under each.
None of it needs a treaty, only for two secretariats to stop treating each other’s paperwork as someone else’s problem.
A factory that is hedging its bets doesn’t ramp up production. And Europe’s readiness is the cost of such hedging.
Europe has spent three years teaching itself to spend on defense again. It has not yet learned to avoid duplication of that spending.
Miro Sedlák is an associate research fellow at the Institute for Central Europe and a doctoral candidate in security and defense studies at the Armed Forces Academy of General M. R. Štefánik in Slovakia.
Europe’s Edge is CEPA’s online journal covering critical topics on the foreign policy docket across Europe and North America. All opinions expressed on Europe’s Edge are those of the author alone and may not represent those of the institutions they represent or the Center for European Policy Analysis. CEPA maintains a strict intellectual independence policy across all its projects and publications.
When Anthropic deemed Claude Mythos too dangerous to release, the only non-American given access to judge its safety was the UK’s AI Security Institute. Within a week, the British institute published an evaluation warning that Mythos could hack into previously secure critical infrastructure.
How to ensure the safety of AI models has become a pressing challenge. Governments around the globe do not want to depend on the companies’ own claims, or on classified assessments from the US government. OpenAI CEO Sam Altman has called for a US-led standard-setting forum, and Demis Hassabis from Google DeepMind has voiced support for the creation of a US standards body.
So far, this political momentum is creating a cacophony rather than solutions. Japan leads a G7 AI Safety project, the European Union is developing an AI Act that it hopes will become the “global benchmark,” and the US runs evaluations through the Commerce Department’s Center for AI Standards and, since June, a classified benchmarking process. The United Nations is getting in the game, too: its International Scientific Panel on AI risk recently released its own set of principles and standards.
National safety institutes aim to build governments’ technical capacity to check the risks of frontier AI models. The US, EU, Japan, Singapore, South Korea, Canada, France, Kenya, and Australia were founding members of the International Network of AI Safety Institutes, launched in 2024 alongside the UK. Since then, Germany, Brazil, Israel, and China have also established their own institutes.
Third-party testing is “a really important part of the AI ecosystem,” says Anthropic co-founder Jack Clark. These institutes can play an important role in safety evaluations because they have access to specific national security information that frontier labs do not. Yet if every government starts developing competing standards, companies could face a patchwork of overlapping evaluation regimes with confusing, fragmented standards. And complete AI safety represents a quixotic mirage. OpenAI’s new cybersecurity models recently went rogue, escaped a safe testing sandbox, connected to the Internet, and attacked Hugging Face, a digital library popular among developers.
Amid the rush for government oversight against such risks, the UK institute is out ahead. Born out of the world’s first major AI safety summit, convened at Bletchley Park in 2023, it poached top talent from Google’s London-based AI lab DeepMind and other leading labs. This helped build trust with companies. In recent months, it has reached agreements with OpenAI, Microsoft, Anthropic, and Google DeepMind, who have shared access to their frontier models for evaluation before deployment.
The Institute’s success stems from obtaining “political will early on, freedom to operate, funding, and attracting top talent,” says Herbie Bradley, a Cambridge PhD candidate who helped set up the institute and is now founding an AI startup in San Francisco.
The UK institute has uncovered major safety gaps in every leading AI model it has tested. Before OpenAI released its cutting-edge GPT-5 chatbot last year, the institute found more than a dozen vulnerabilities that would have allowed users to develop biological weapons, all of which were fixed before release.
The Institute has done “world-leading work” according to a recent assessment by the Ada Lovelace Institute, an independent research body. Governments, industry, and researchers depend on the Institute’s evaluations of more than 30 frontier models. Rather than keeping its methods and findings proprietary, the platform publishes them on its open-source evaluation platform Inspect.
Britain’s booming AI sector adds credibility. So far this year, British technology startups have raised over $14.5 billion in venture capital, more than all other major European markets combined. Britain’s Nobel Prize winners Geoffrey Hinton and Sir Demis Hassabis, founder of Google’s DeepMind, have developed much of AI’s basic science. Britain sits outside the EU’s AI Act, which critics say holds firms and their customers to burdensome compliance requirements.
Admittedly, the UK approach does not represent a silver bullet. The London institute lacks the power to impose decisions on governments or companies. It also does not cover the full range of prospective threats. Different AI risks require different expertise, which is why specialized private sector and non-profit analysts have emerged, such as METR, a research institute based in Berkeley that specializes in testing for autonomous replication, or Apollo Research, a start-up headquartered in London that focuses on deceptive and scheming behavior. Bradley is skeptical that any single third-party evaluator could set global standards.
But for now, the UK institute enjoys a unique position, respected both in Washington and Brussels. The partnership with the US government is, in Bradley’s words, “very robust,” built on Britain’s position inside the Five Eyes intelligence-sharing network. Bradley can even imagine safety warnings being shared with China for catastrophic risks, such as a model that could help build a biological weapon.
Anthropic’s Mythos and OpenAI’s rogue Hugging Face attack will not be the last AI scares. When the next crisis arrives, governments will need an independent appraisal. For now, the best place to conduct such a review is in London.
Marta Granados Hernández is a US Google Public Policy Fellow at the Center for European Policy Analysis and a master’s candidate at Georgetown University’s Master of Science in Foreign Service program, concentrating in Science, Technology, and International Affairs.
Bandwidth is CEPA’s online journal dedicated to advancing transatlantic cooperation on tech policy. All opinions expressed on Bandwidth are those of the author alone and may not represent those of the institutions they represent or the Center for European Policy Analysis. CEPA maintains a strict intellectual independence policy across all its projects and publications.
Tech 2030
A Roadmap for Europe-US Tech Cooperation
On July 12, three explosives-laden Unmanned Surface Vessels (USVs) motored into an enemy port, maneuvered past whatever defenses may have been in place, and blew up a drydock cradling a submarine undergoing maintenance.
If the USVs had been Ukrainian and the target had been Russian, the robot raid would have been old news.
But the 8-meter (26 ft) Saronic Technologies Corsair USVs belonged to US Central Command. And the target was a naval base in the Iranian port of Bandar Abbas. It was “the first time American forces have employed sea drones in combat operations,” CENTCOM stated.
In the same way, more countries, including the United States, are adopting the Shahed-style one-way aerial attack drones that both Russia and Ukraine fling at each other by the hundreds; more countries are also adopting the kinds of one-way USVs that Ukrainian forces have built their sea denial strategy around.
USVs are cheap and hard-hitting. But they’re no naval panacea. In rushing explosive robot boats into service, countries risk using them the wrong way. For all their many benefits, strike USVs aren’t one-for-one replacements for pricier anti-ship munitions. They’re complementary, not supplementary.
The concept of an explosives-laden, remotely controlled attack boat isn’t new. But the Ukrainian military honed the idea to a sharp point after losing most of its warships in the first days of Russia’s wider war on Ukraine starting in February 2022. By the following year, Ukrainian USVs including the 6-meter Sea Baby and the 5.5-meter Magura, both costing a few hundred thousand dollars per copy, were chasing down Russian warships on the Black Sea.
Three years later, the satellite-controlled USV victims include at least one corvette, a couple of landing ships, some patrol boats, a survey vessel and a tanker. Armed with remotely aimed guns, rockets, surface-to-air missiles, and even first-person-view aerial attack drones, the drone boats have shot down Russian helicopters and jets and harassed ground forces along the Black Sea coast, especially in Crimea.
In July, a Ukrainian USV even beached itself on the Kinburn Spit in southern Ukraine and landed a gun-armed ground robot: history’s first all-robot amphibious assault.
Given their low cost and high-profile kills, it’s no wonder USVs caught the attention of other countries. The US Navy isn’t lacking for traditional warships, but even it has found a niche in its force structure for explosive USVs. Now navies everywhere are rushing to field their own one-way explosive boats. Taiwan is practically rewriting its sea denial strategy to incorporate a large flotilla of USVs.
These late adopters should proceed with caution. Slow, easy to spot from the air and prone to getting lost amid heavy radio jamming, USVs are actually pretty easy for a prepared foe to defeat.
There were zero hard kills against Russian warships between late 2024 and late 2025 as the survivors of its Black Sea Fleet retreated to the anchorage in Novorossiysk in southern Russia, which is protected by physical barriers, aerial and sea patrols, and lots of sailors manning heavy machine guns. Ukrainian USVs finally started registering hits again as 2025 ground into 2026, but only because Ukrainian leaders made the deliberate and risky decision to escalate the Black Sea naval war by striking 183 dry cargo ships, tankers, and auxiliaries belonging to Russia’s unregistered commercial “shadow fleet” up to July 19. That move has triggered retaliatory Russian strikes on Ukrainian grain ships.
USVs cannot replace fast, accurate and low-flying anti-ship cruise missiles, which might cost five or six times as much per unit as a USV per unit, but which are much more survivable and pack much more destructive potential thanks to their combination of big warheads and kinetic energy.
It’s not for no reason that the majority of anti-ship strikes in America’s on-again, off-again war on Iran have been executed by air-launched cruise missiles or, in one chilling case, a torpedo fired by a lurking nuclear-powered attack submarine.
For all their early success on the Black Sea, USVs are still weapons of desperation. Or, at best, expedients that provide inexpensive munitions for bulking up a sea denial force. It’s telling that Ukraine itself is still investing billions of dollars in new anti-ship cruise missiles even as it leans hard into USVs.
That those American Corsairs could motor into Bandar Abbas and blow up a drydock says more about the state of Iranian coastal defenses after months of sporadic bombardment than it does about the potential for such unmanned vessels to rewrite naval doctrine.
David Axe is a journalist, author, and filmmaker in South Carolina. For 20 years, he has covered war for Forbes, Rolling Stone, The Daily Beast, The New York Times, The Washington Post, Vice, The Village Voice, Voice of America, and others. He has reported from Syria, Afghanistan, Iraq, Somalia, and elsewhere. His current focus is on covering Russia’s wider war on Ukraine.
Europe’s Edge is CEPA’s online journal covering critical topics on the foreign policy docket across Europe and North America. All opinions expressed on Europe’s Edge are those of the author alone and may not represent those of the institutions they represent or the Center for European Policy Analysis. CEPA maintains a strict intellectual independence policy across all its projects and publications.