Avoiding Digital Infrastructure and Content Weaponisation through Investment Screening

Author: Sara Pugliese, Associate Professor of EU Law, Coordinator of E-Reg Lab, Parthenope University of Naples

This blog is part of the CELIS-L&G special series.
All articles in Law & Geoeconomics are available free of charge via Brill using the access token LGEO4U until 31 December 2026. More details are available at the L&G page 
here.

Introduction

Digital infrastructures have become strategic assets in the blurred space between peace and war. In recent conflicts, data flows and digital infrastructures have been targeted through sabotage and hacking operations designed to disrupt essential services, destabilise civilian life, and disseminate pro-war propaganda.

Traditional intelligence studies distinguish operations targeting the integrity and functioning of infrastructures from those involving the theft of confidential data or the dissemination of false news and information. In the digital sphere, however, this distinction is less clear, since infrastructures and the content they carry are often difficult to separate.

The EU is intensifying its efforts to strengthen cybersecurity and counter disinformation. Yet countering hybrid attacks and safeguarding digital sovereignty also require attention to retaining European ownership of critical digital infrastructures, through careful scrutiny of investments.

This contribution - after thoroughly presenting the challenge of the weaponisation of digital infrastructures and services, and their broader regulatory framework - analyses the provisions of Regulation (EU) 2026/1386 on the screening of foreign investments in the Union concerning the protection of critical digital infrastructures and service providers, particularly online platforms, from investments potentially harmful to EU and national security or public order.

Digital Infrastructures, Services, and Contents in Current Conflicts: Regulation as a Sufficient Remedy?

Current conflicts are characterised by frequent recourse, both before and during combat, to forms of ‘hybrid’ attacks against digital infrastructure and services. Cyberattacks can be divided into two interrelated and often overlapping categories: sabotages directed against digital infrastructure and attacks targeting data and digital content, aimed at exposing sensitive and confidential data or disseminating false information.

As scholarship has noted, the growing offensive use of digital infrastructures and services results from the balance of power among States in the nuclear realm, which encourages low-intensity conflict through the ‘stability-instability paradox’. It is further enabled by technologically dominant powers’ awareness that cyberattacks can harm adversaries without creating systemic instability. Unlike conventional warfare, in which deterrence has maintained a degree of equilibrium among nuclear powers since the 1960s, such an outcome appears less likely in cyberspace because attacks are difficult to attribute, technologies are dual-use, and the ‘intensity’ or gravity of an attack is difficult to determine. Moreover, some authors emphasise the risk that excessive investment in warfare technologies could create a first-strike incentive. Attacks on the digital systems that manage essential services and infrastructures have increased with the advent of the Internet of Things.

Analysing the phenomenon is difficult because academic and research communities have not developed consistent, well-defined, methodologies. Nevertheless, some cybersecurity companies regularly produce reports and statistics and have developed state-of-the-art analytical tools to examine incident data. The data collected by these companies are also used by the European Union Agency for Cybersecurity (ENISA) to prepare its annual Threat Landscape reports. The latest report, published on 22 September 2026, which analyses 8,257 incidents recorded during the 2025 calendar year, shows that cyber operations affecting the European Union are increasingly shaped by geopolitical developments. The continuation of Russia’s war of aggression against Ukraine and the escalation of the conflict in the Middle East influenced both the selection of targets and the timing of malicious activity. Artificial intelligence is strengthening the connection between cyber operations and information manipulation. ENISA notes the growing use of AI-generated text, synthetic audio and video, multilingual content production and deceptive online personas. These tools reduce the cost of producing and distributing manipulative content, conceal its origin and enable campaigns to be tailored to national and local contexts. At the same time, AI is being integrated into cybercriminal and State-linked operational playbooks, particularly for phishing, reconnaissance, vulnerability discovery and post-exploitation.

The report provides compelling evidence that cyberattacks and cyberespionage are increasingly deployed as instruments of contemporary conflict. Their common purpose is to weaken resilience, obtain strategic advantage, influence public opinion and impose political costs on adversaries while remaining, in many cases, below the threshold that would trigger a conventional military response. Far from being separate actions, they function as complementary components of hybrid conflict. The two strategies are often combined in a single low-impact operation that produces no dramatic effects and attracts little public attention, while simultaneously compromising infrastructure and information integrity. Without sensationalism, such operations affect national security, the proper functioning of production and supply chains, the provision of essential services and supply of essential goods, as well as the protection of individual rights. This form of ‘low-profile’ warfare led some scholars to state, ironically, that ‘cyber war did not take place’. Nevertheless, practices such as ‘hack-and-leak’, in which an unauthorised actor steals and then publicly leaks sensitive data, are far from neutral in terms of protecting essential State interests and functions. This risk is growing with the advent of technologies capable of creating shallowfakes or deepfakes, which make it extremely difficult to distinguish real images from fabricated ones.

Fully integrated in the strategy of ‘hybrid’ conflict, propaganda and disinformation campaigns used as instruments of war puts to undermine the rival by shaping common sense and the frameworks through which facts are interpreted. For example, gender-based or migration-related disinformation have been used to discredit a rival’s regulation, policy choices, or ability to ensure citizens’ security and protect traditional values and ways of life. With the emergence of new media, particularly platforms that use tools such as profiling and recommender systems, dark patterns, AI, and deepfakes, the risk associated with disinformation has gradually shifted from content to design. This has given rise to the concept of cognitive security, which focuses not on the information environment but on information processes. These new sources of information and communication make it possible to transcend the boundaries within which State security has traditionally been guaranteed, moving activity into virtual spaces where regulation, enforcement, and surveillance are difficult to ensure. In the State of the Union Address pronounced on 16 September 2026, President von der Leyen urged to react to the

‘… disinformation and foreign interference seeking to divide us. Seeking to erode trust in our democratic fabric and free media. Election campaigns poisoned by foreign propaganda. Conspiracy theories built on viral deepfake videos. This is cognitive warfare”.

Indeed, the EU was quite active on the matter over the last years. Building on the examples of other International Organisations, the EU has adopted several instruments to strengthen cybersecurity. Inter alia, the 2019 Cybersecurity Act; the second  Directive on Security of Network and Information Systems of 2022 (NIS2 Directive) 2024 Cyber Resilience Act (“CRA”); the 2025 Cyber Solidarity Act.  This regulatory framework could be enriched by the adoption of the 2026 Proposal for a revised Cybersecurity Act, which is intended to enhance the security of the EU’s ICT supply chains, ensure that products reaching EU citizens are (cyber)secure by design, through a simpler certification process, and reinforce ENISA’s mandate.

The contribution of acts not specifically focused on cybersecurity should also not be underestimated. For example, acts designed to ensure the fair use and governance of data and to prevent unlawful access by third-country governments to non-personal data - the 2016 GDPR, the 2022 Data Governance Act, and the 2023 Data Act - represent the European approach to protecting information integrity in response to the re-nationalisation of information control through requirements that data be stored exclusively on domestic servers.

Alongside its cybersecurity legislation, the EU has adopted several acts that, although they do not specifically treat disinformation as a category of unlawful content, indirectly contribute to countering it, as 2022 Digital Services Act (DSA) or  2024 European Media Freedom Act. The AI Act and Digital Omnibus for AI also address deepfakes.

From the specific perspective of countering the strategic use of disinformation in warfare, the Foreign Information Manipulation and Interference (FIMI) framework, developed by the European External Action Service (EEAS), addresses coordinated and intentional manipulative behaviour by foreign State or non-State actors, often using proxies, that is intended to undermine democratic processes or the EU’s policy objectives. Notably, in 2015 the EEAS created the EUvsdisinfo task force to detect, analyse, and counter foreign disinformation campaigns. Through the 2022 Strategic Compass for Security and Defence, the EEAS definitively recognised hybrid threats - including manipulation of the information environment, attacks on and disruption of critical infrastructure, and electoral interference - as elements of the EU’s security strategy and of the Common Foreign and Security Policy.

Although the measures analysed above have produced some results, they remain sectoral and are not embedded in a coherent and well-defined strategy. Addressing cybersecurity and disinformation as forms of hybrid warfare requires an ecosystem-based approach, combining the protection of critical digital infrastructure, monitoring of digital-platform content and design, and preservation of digital sovereignty. This approach should form part of a clear and comprehensive strategy against hybrid threats. From this perspective, the business and ownership models of digital services cannot be overlooked.

Ownership and Investment Dynamics in the Digital Sphere: Regulation 2026/1386’s Potential Contribution to Cybersecurity and Information Integrity

Since the 1990s, digital infrastructures and assets have attracted the attention of cross-border operators both in intra-EU relations and on the global market, giving rise to so-called ‘digital FDI’. Intra-EU transactions are subject to competition rules, particularly Merger Control, whereas digital FDI is governed by international investment agreements (IIAs) and bilateral investment treaties (BITs), except in exceptional cases, such as certain blockchain-based assets, where decentralisation makes it difficult to identify the territory in which they are located. In 2025, the EU signed Digital Trade Agreements with South Korea and Singapore that affect bilateral investment by establishing rules prohibiting data localisation, protecting source code, banning customs duties on electronic transmissions, and preventing arbitrary licensing frameworks targeting foreign online service providers.

As data sharing and technology transfer increasingly became matters of national security, and disputes arose over whether restrictions on investment in the technology sector could be justified under the security exceptions contained in BITs (Devas v. India; Deutsche Telekom v India; Global Telecom Holding S.A.E. v. Canada; Huawei v. Sweden), digital FDI attracted the attention of FDI screening mechanisms in both the US and the EU.

Although Regulation 2019/452, which established the first EU framework for FDI screening, referred to cybersecurity in Article 4(1)(b) as a factor that Member States or the Commission could take into consideration when conducting a screening, it did not expressly mention digital infrastructures and services. Nevertheless, the annual investment screening reports reveal growing attention to cybersecurity and digital infrastructures and assets (see the Third Annual Report in 2023, the Fourth in 2024 and the Fifth in 2025). At the same time, the increasingly extensive application of EU digital regulation, particularly the DSA, has highlighted the strategic importance of digital service providers, especially online platforms and social media, for the EU’s security.

Consequently, the recent EU FDI screening reform through Regulation 2026/1386, which places greater emphasis on risk assessment (see Recitals 26 and 30), pays particular attention to investments in digital sectors that could undermine cybersecurity and information integrity. The Regulation introduces two categories of investment: investments that must obtain prior authorisation, referred to as the minimum scope and governed by Article 4(5); and investments likely to adversely affect security or public order, which must be screened by the host Member State on the basis of the factors listed in Article 19(1). Under Article 19(3)-(4), the European Commission must make available a risk-evaluation form that Member States may use to assess the elements listed in Article 19(1), and may directly conduct risk assessments relating to specific sectors, critical technologies, foreign investors, or Union undertakings. These provisions reflect the European Commission’s intention to centralise risk-assessment methods and standardise Member States’ practices.

The first category includes investments subject to prior authorisation where the Union target…

‘is active in (...) digital infrastructure sectors and is considered critical pursuant to a risk-based targeted assessment that takes into account national security and vital societal functions in light of the essential services provided by that Union target and that is performed by the Member State in which that Union target is established’.

With regard to the second category of investments, which are subject to mandatory screening, specific reference is made to their potential effects on…

‘a project or program of Union interest (...) the availability, including outside the Union as a result of the foreign investment, of critical technologies (...) and the protection and availability of intellectual property or other intangible assets; the security, integrity, resilience and functioning of a critical entity or critical infrastructure (...) as well as those of entities falling within the scope of Directive (EU) 2022/2555 (NIS2) (...) the protection of sensitive information, including personal data (…), in particular with regard to the ability of the foreign investor to access, control, and otherwise process such information; the freedom and pluralism of the media, including online and social media platforms that can be used for large-scale disinformation or criminal activities’.

The Regulation annexes also list projects or programmes of Union interest, such as the Digital Europe program, and technology areas relevant to risk assessments, with a specific mention to ‘secure digital communications and connectivity’ and ‘cyber security technologies’, inter alia. All these assets are directly or indirectly connected to the digital sphere and may have implications for cybersecurity and information integrity. Furthermore, the possibility under Article 20 of authorising investments subject to mitigation measures enables Member States to adjust investment plans and make them compatible with their strategic interests. Under Article 20(4), mitigation measures may include ‘conditions on access to sensitive technologies or information; ... implementation of cybersecurity protocols to protect against potential threats; an obligation to store and process specific data within the Union’, a form of EU ‘data re-nationalization’ strategy. Their contribution to countering cyberattacks and protecting information integrity is therefore evident.

Conclusion

By focusing on the strategic security and public order of the EU and its Member States rather than on distortions of competition and trade, the FDI screening in the EU occupies a distinctive position. It differs from Merger Control,  or other instruments aimed at contrasting foreign aggressive interferences in the EU internal market  - particularly the International Procurement Instrument, the Foreign Subsidies Regulation, and the Anti-coercion Regulation, although it shares the latter’s orientation towards ‘strategic autonomy’. FDI screening is better situated within the economic security strategy and should be interpreted alongside other EU measures, including dual-use export control, research and technology transfer, outbound investment screening, and research security. Together, these measures pursue EU digital autonomy and sovereignty by securing access to innovation, fostering socioeconomic growth and cohesion, reducing dependence on hostile providers, and strengthening resilience to cyberattacks and external aggressions to EU fundamental interests. Nevertheless, achieving these objectives depends on EU institutions and bodies’ ability of integrating them into a coherent strategic and governance framework that positions the EU as a driver of technological innovation.