Paper 19 · Infrastructure

Borrowed Eyes

Allied operations are foreign collection without operational doctrine that says so.

In 2003 the United Kingdom went to war in Iraq on intelligence it had not collected and could not verify. France held a different threat picture and dissented through Dominique de Villepin’s UN Security Council speech of 14 February 2003. France could dissent because France retained the independent collection and analysis capacity that British integration into Five Eyes had quietly consumed.

Each of us is spied on by our closest ally. We run on their stack. Their friends see more of us than we see of each other. Intelligence without sovereignty is dress-up. Sovereignty without counter-intelligence is fiction.

The build has three components: a sovereign technology stack (chips, cables, cloud, cryptography, analytical platforms) procured at intelligence-grade requirements; sovereign communications and post-quantum migration on the 2033 clock; and sovereign operational doctrine across federated national services that treats American and Israeli operations as foreign collection. European intelligence services are the anchor customers whose procurement funds it.

  1. The Architecture We Are Inside =================================

The post-war intelligence settlement was designed for alliance unity. European autonomy was not part of the design.

The UKUSA Agreement of 1946 formalised the English-speaking signals intelligence partnership immediately after the Second World War, when American collection capability had achieved decisive operational superiority. The five participants were the United States, United Kingdom, Canada, Australia, and New Zealand. The agreement explicitly excluded continental Europe.

France and Germany were not invited. Italy was not invited. The smaller European powers were not invited. The exclusion was a choice. It reflected which alliance architecture would carry the post-war intelligence settlement.[1]

The architecture distinguishes between two categories of partner. Second Party partners receive raw signals intelligence subject to minimisation rules. Third Party partners receive processed intelligence only. Second Parties are the original five members of UKUSA. All other countries are Third Parties.

The distinction is the operational fact most discussion of Five Eyes misses. Raw signals intelligence is uninterpreted intercept data. The recipient sees the original collection and conducts independent analysis on it. Processed intelligence is what the providing nation’s analysts have selected, interpreted, and packaged. Alternative interpretations have been filtered out.

Minority views within the providing nation’s intelligence community have been suppressed. Dissenting analysis does not appear in the processed product, because the providing nation’s analysts have already made their judgements before the product is shared.

For Third Party recipients, intelligence provision is interpretation provision. European governments understand threats as American intelligence understands them. The reason is structural. European governments have been systematically denied access to the information required for independent assessment.

This filter has shaped European threat perception for eighty years. When French intelligence officers need to understand a security threat in North Africa, they can access processed American intelligence. When German officials need strategic assessment of Russian intentions, they can request American analysis through bilateral channels.

They cannot access the raw intercepts that underlie American conclusions. They cannot independently assess whether American threat characterisation is accurate, whether American analysts have missed relevant information, or whether American threat perception has been influenced by American policy preferences.

There is a further fact about this architecture that is less widely known and operationally more striking. In approximately 2009, the National Security Agency signed a memorandum of understanding with the Israeli SIGINT National Unit covering the sharing of raw, unminimised signals intelligence.

The agreement was revealed in documents released by Edward Snowden and published in The Guardian on 11 September 2013. Its official title is the Memorandum of Understanding between the National Security Agency Central Security Service and the Israeli SIGINT National Unit Pertaining to the Protection of US Persons.[2]

The operational fact is that NSA shares raw signals intelligence with Israel that has not been processed to remove information on US persons or allied nationals. Five Eyes partners receive raw signals subject to legally binding minimisation rules and oversight.

Israel receives raw signals with minimisation handled internally under MOU terms that US privacy advocates have described as effectively unenforced.

This means the operational reality of signals intelligence access inverts the standard description of Five Eyes. The traditional account is that five English-speaking allies share signals while everyone else receives processed output.

The actual architecture is that five English-speaking allies share signals subject to legal protections, Israel shares signals with weaker protections, and everyone else receives filtered output.

For European communications collected by NSA, the implication is that European cabinet communications, European corporate communications, and European intelligence service communications routed through compromised infrastructure or intercepted at chokepoints are presumably accessible to Israeli SIGINT in raw form, while the European countries themselves see only what NSA chooses to share back.

This creates a structural information asymmetry that operates against European interests on every issue where US-Israeli alignment differs from European preference. Iran is the most acute current example. European deliberations about Iran policy are presumably visible to Israeli intelligence through this channel. Israeli deliberations are not visible to European intelligence at all.

The institutional mechanism that aggregates this for Europe is NATO. NATO has functioned as the de facto European intelligence community for eighty years. Through NATO channels, European policymakers have received synthesised threat assessment combining Five Eyes collection, selected allied national inputs, Israeli contributions where appropriate, and integrated American analysis.

The synthesis has happened in Washington. The product has been European decision-support delivered through alliance plumbing.

This worked while the alliance was unconditional. The 2025 Ukraine precedent revealed something specific. The capacity to withhold intelligence cooperation was always there. What changed is that withholding became a routine policy lever rather than an exceptional one.

Trump administration officials confirmed openly that intelligence-sharing was being used as transactional leverage against the Ukrainian government to compel acceptance of negotiation terms favourable to American geopolitical position.

The synthesis function has therefore become conditional. The original design served alliance alignment. It did that effectively for eighty years because European and American interests usually aligned. When the alignment ceases to be reliable, the architecture continues to function. The threat assessments continue to flow. The European decision-makers continue to consume them.

What changes is that the assessments now reflect interests that may diverge sharply from European interests. Europe has no architectural alternative.

  1. Dress Up ===========

European intelligence services are good. The DGSE produces excellent human intelligence across Africa, the Middle East, and Francophone networks, often superior to American assets in those theatres because of colonial-era continuity and language depth. The BND has serious technical capability in Eastern Europe and growing reach in the Middle East.

The Italian AISE has competence in Mediterranean and North African operations. The Spanish CNI works tightly across Latin American networks. The Dutch AIVD and Norwegian PST run focused operations of high quality at small scale. The capacity is real. The work is good.

The architecture is where the dress-up happens. The work itself is sovereign-quality.

The Direction Générale de la Sécurité Intérieure, the French domestic intelligence service, runs its analytical workflow on Palantir Gotham. The contract began in November 2015, signed in the immediate aftermath of the Paris terror attacks of 13 November 2015. DGSI faced an acute operational problem.

It needed to integrate French signals intelligence, human intelligence, and open-source material at operational speed to prevent additional attacks. Palantir provided the capability. The cost was structural dependence at the analytical layer.[3]

The technical architecture creates leverage that cannot be reversed through procurement decisions alone. DGSI personnel operate within Palantir’s system. They do not control the underlying code. Updates, patches, capability additions, and algorithmic changes flow through Palantir. The French government does not have source code access.

It cannot modify the software, fork it, or maintain it independently. The company itself was founded with capital from In-Q-Tel, the venture investment arm of the United States intelligence community, and remains structurally embedded in the American intelligence architecture, as the military layer of this series examines in detail.

The jurisdictional exposure is thorough. Palantir is subject to the Computer Fraud and Abuse Act, giving the United States government regulatory authority over how the software is used. Palantir is subject to FISA Section 702, which permits the National Security Agency to require data sharing from private technology companies.

Palantir is subject to Presidential Directive, meaning any United States President can require the company to modify how the software functions or what data it shares. Palantir is subject to export controls and sanctions. If the United States government sanctions a country or specific intelligence activity, Palantir must comply, regardless of what the DGSI needs.

The contract was renewed in December 2025 for a further three years. The renewal was deliberate. It was made after a decade of operational experience. The French government assessed the immediate operational value of Palantir Gotham as exceeding the strategic cost of dependence. This is precisely the kind of tactical assessment that produces strategic vulnerability.[4]

The same pattern holds across the rest of the European intelligence stack. Microsoft, Amazon Web Services, and Oracle operate in classified environments across multiple European services. American satellite imagery vendors supply European intelligence services with overhead collection. American artificial intelligence substrate is increasingly displacing European analytical workflows.

Each layer is American. The aggregate is intelligence services that perform sovereignty without exercising it. The work is sovereign-quality. The substrate is not.

This is what dress up means here. The architecture European services operate inside renders their work visible to others while preserving the appearance of sovereign capacity. The services themselves are competent. The French government can claim to operate sovereign intelligence. The DGSE collects sovereignly. The DGSI synthesises on Palantir.

The Palantir output is in some operational sense available to the company that owns the platform and to the United States government that has comprehensive jurisdictional authority over that company. Sovereignty in the deep sense ends where the platform begins.

  1. Fiction ==========

The dress-up problem affects intelligence work. The fiction problem affects everything else.

European counter-intelligence is the architecture that defends against foreign intelligence operations on European soil and against European leaders, institutions, businesses, and citizens. It exists. It has been competent against Russian and Chinese operations for decades. It has been structurally absent against American and Israeli operations because those have been treated as friendly.

The historical record is consistent. In 2012 to 2014, the National Security Agency, working with Danish intelligence, intercepted communications passing through Danish territory. The targets included Angela Merkel’s Chancellor’s office and Frank-Walter Steinmeier’s Foreign Ministry. When Danish intelligence discovered the operation in 2014, the surveillance continued.

It was redesigned through different channels. The diplomatic consequence was minimal. The United States government denied the operation. The German government, unable to prove the denial false without revealing sources and methods, accepted the denial.[5]

In 2015, German parliamentary inquiry revealed that the BND had been running NSA-supplied selectors against European companies and officials. The German service was operating as a collection asset against European industrial and political targets, with American direction. The selectors targeted European institutions and individuals across the previous decade.

The discovery produced political scandal. The architectural response was minimal.[6]

In 2020, joint investigation by Der Spiegel, the Washington Post, and Swiss broadcaster SRF revealed Operation Rubicon. The Central Intelligence Agency and the BND had jointly owned the Swiss cryptography company Crypto AG since the 1970s. Through that ownership, both agencies had read encrypted communications from over one hundred and thirty countries for decades, including European partners.

The decryption was systematic, sustained, and undisclosed to the affected governments. The operation continued until the 1990s for the BND and into the 2000s for the CIA.[7]

In 2021, joint reporting by Danmarks Radio and other European broadcasters revealed Operation Dunhammer. The Danish Defence Intelligence Service had operationally helped the National Security Agency tap undersea cables transiting Danish territory between 2012 and 2014, surveilling the leaders of Germany, France, Norway, and Sweden.

A European intelligence service had served as the operational asset enabling American surveillance of other European leaders.[8]

The pattern is consistent. Discovery, scandal, no architectural response. The institutional reaction has been diplomatic protest, investigative reporting, parliamentary inquiry, political turnover. The architectural reaction has been silence. The infrastructure that enabled each operation remained in place. The legal frameworks that permitted the operations remained in place.

The technical defences that would have prevented the operations were not built.

There is a further fact that completes the picture. The MOU between NSA and the Israeli SIGINT National Unit, examined in the architecture section, makes the counter-intelligence problem operationally specific. European communications travelling through American collection infrastructure are presumably accessible to Israeli SIGINT in raw form.

European deliberations on Iran, on Israel itself, on Middle Eastern strategy, on European Union trade policy with Israel-affected countries, are visible to a service that lobbies actively for outcomes that diverge from European policy preferences.

Sovereignty without counter-intelligence is fiction because the conditions of sovereignty include the capacity to deliberate without foreign observation. European cabinet meetings about Iran do not constitute sovereign Iran policy if the deliberations are visible to Israeli intelligence.

European industrial strategy on critical materials does not constitute sovereign strategy if the discussions are visible to NSA. European responses to American trade pressure do not constitute sovereign responses if the position-development is presumably visible to the party applying the pressure. The performance of sovereignty is what is happening at the formal level.

The substance has been hollowed out by a counter-intelligence failure that has been ongoing for sixty years.

The structural reason this has gone on so long is that European counter-intelligence has been doctrinally oriented against Russia and China. Russia and China are the threat actors. The United States and Israel are the allies. Allied operations have therefore been treated as either non-existent (the polite fiction) or unfortunate but tolerable (the operational reality). The doctrine has to adjust.

Allies have intelligence services. Allied intelligence services act on their state’s interests. Sometimes those interests cut against ours.

  1. Forever Wars ===============

Intelligence dependency has consequences. The clearest are the wars Europe has fought on intelligence Europe did not control.

Iraq is treated in the opening section. The British case for war rested on intelligence absorbed from American channels. France held a different threat picture and dissented through de Villepin’s Security Council speech.

The strategic outcome of the British decision was the destabilisation of the Middle East, the rise of the Islamic State, and a refugee flow that European countries spent the next decade absorbing. The wrong intelligence produced the wrong war. The pattern recurs.

Afghanistan extended the same pattern across two decades. NATO operation throughout, European personnel deployed throughout, European deaths throughout, billions in European costs. The strategic framing was American. The threat assessment was American.

The exit decision in 2021 was American, taken without consultation with NATO partners whose forces would have to withdraw alongside American forces. European governments learned of the withdrawal through diplomatic channels rather than through alliance deliberation.

Libya in 2011 looks superficially like a counter-example. France and the United Kingdom led the intervention. The strategic logic and intelligence picture were nonetheless American-shaped, and the post-intervention consequences fell disproportionately on Europe because American synthesis under-counted them.

The Sahel destabilisation that followed produced a decade of French military operations across Mali, Niger, and Burkina Faso, ending in the humiliating expulsions of 2022 to 2024. The migration flows that followed produced sustained pressure on Italian, Greek, and Spanish reception infrastructure.

American synthesis under-counts what falls on Europe because European costs are not American interests.

Iran is the live case. American posture toward Iran has hardened across the second Trump administration in ways that align closely with Israeli strategic preferences. American intelligence on Iran is the basis for any escalation framing. The 2024 to 2025 exchange of strikes between Israel and Iran was supported by American intelligence and air defence assets.

The next phase of escalation, if it comes, will draw on the same intelligence picture and will frame the response choices European decision-makers face.

European national positions on Iran have historically been more diplomatic. The E3 structure of France, Germany, and the United Kingdom anchored the JCPOA negotiations. The agreement collapsed when American policy changed. European policy at that point lacked the synthesis-level support to sustain a divergent path even when European views differed.

The same architecture will produce the same outcome on the next escalation point. The intelligence will arrive through American-Israeli synthesis. The threat picture will be set before European decision-makers see it. The decision space will be shaped before European publics learn what is at stake.

Maintaining a European position requires independent intelligence capacity to dissent from American-Israeli synthesis when that synthesis is wrong or self-serving. UK lost that capacity through Five Eyes integration. France retains it partially. Germany, Italy, Spain, and the smaller European states have had it limited by reliance on NATO and bilateral channels.

The architectural choice is whether to build the capacity now, before the next escalation point, or to absorb whatever synthesis arrives when the decision is forced.

The mechanism by which European policy is committed to wars Europe would not independently choose is the intelligence pathway. American threat assessment shapes European threat assessment because European synthesis is routed through American synthesis. Once the threat is shared, the response logic follows.

Europe arrives at the war because Europe arrives at the threat picture, and the threat picture has not been Europe’s to construct.

This is structural. The architecture commits European publics to wars European publics would not choose, through a mechanism that does not require coercion and is not visible as coercion. The commitment happens through the routine flow of threat assessment from one component of the alliance to another.

By the time the policy decision is made, the decision space has been shaped by the threat picture European decision-makers absorbed.

  1. What Sovereign Intelligence Requires =======================================

Intelligence without sovereignty is dress up. Sovereign intelligence is built through deliberate design and procurement. The build has three concrete components.

The first is the sovereign technology stack. The series has argued in detail for sovereign chips, sovereign cables, sovereign data centres, sovereign cloud, sovereign artificial intelligence substrate, sovereign payment infrastructure, sovereign cryptography.

Each layer is necessary for intelligence sovereignty because each layer is a vector of dependency when supplied by foreign vendors. Intelligence services running on European hardware, European cloud, European cryptography, European analytical software, European AI models are services with sovereign capacity.

Intelligence services running on Palantir, AWS, Microsoft, Oracle, and American cryptographic standards are services performing sovereignty on a substrate that the supplying state can require to share data, modify functionality, or terminate access. The stack is the substrate. The substrate is what determines whether the service is sovereign.

The second is inter-European secure communications. European intelligence services share with each other through infrastructure that often touches American hardware and American jurisdiction. When the BND shares with the DGSE, the data may transit American-supplied cables, route through American-managed exchanges, terminate on American-supplied servers, and use American cryptographic primitives.

The sharing is not sovereign. Sovereign inter-European communications means cables, exchanges, platforms, and protocols that European services can communicate through without American visibility. This is achievable infrastructure work. The cables already exist or can be built. The exchanges can be European. The cryptography can be European.

The political will to require this for inter-European intelligence sharing has not yet been mobilised.

The third is the operational doctrine that uses these capacities. National services remain national. Federation rather than unification. Federation distributes the attack surface, preserves national analytical diversity, and maintains the institutional cultures that produce capable services.

A unified European intelligence service would consolidate analytical lenses, create a single high-value target for adversary penetration, and require political consensus across twenty-seven member states that has never existed.

Selective cooperation between willing services on shared problems extends the model that has worked at small scale since 1976 in the Maximator group of France, Germany, the Netherlands, Belgium, Sweden, and Denmark.

The United Kingdom is the most acute case of intelligence dependency among European states. UK national services have world-class capability. UK signals intelligence through GCHQ is the deepest and broadest in Europe. UK human intelligence through MI6 has reach the continental services do not match. The dependency is structural. UK is a Second Party in Five Eyes.

UK intelligence flows preferentially to American partners. UK strategic autonomy on intelligence-sensitive policy questions has been demonstrably less than French strategic autonomy. The Iraq case shows what happens when an integrated service confronts a wrong American assessment. The UK left EU institutional cooperation through Brexit.

UK capability remains accessible to European partners through bilateral relationships and through NATO. It is not accessible to European intelligence sovereignty as such. The architecture has to work without UK at the institutional level, with UK as a closely cooperating non-member at the operational level.

These three components together produce sovereign intelligence. They do not require a European NSA. They do not require pan-European mass surveillance. They do not require a single European intelligence community. They require sovereign substrate, sovereign communication, and sovereign operational doctrine across federated national services.

  1. What Sovereign Counter-Intelligence Requires ===============================================

Sovereignty without counter-intelligence is fiction. The build is harder than building intelligence because it requires reorienting against actors that have been treated as allies for eighty years. The technical components are achievable. The doctrinal components require explicit political decision. The build has three components.

The first is doctrinal reorientation. European counter-intelligence services have to treat the United States and Israel as possible threat actors, not just as allies who occasionally exceed their authority. The historical record is sufficient. Operation Rubicon, Operation Dunhammer, the Merkel surveillance, the BND-NSA selectors, the NSA-Israel raw signals MOU.

The doctrine cannot continue to assume good faith from services that have demonstrated decades of operations against European institutions, leaders, and citizens. The reorientation requires acknowledging that allies operate intelligence services and that those services act on their state’s interests, which sometimes diverge from European interests.

Declaring the United States an adversary is not part of this requirement.

The second is technical and operational defence. The components are sovereign hardware, sovereign cryptography, sovereign communications infrastructure, and post-quantum migration on a timeline that meets the 2033 deadline.

Defence extends to European cabinet communications, parliamentary deliberations, intelligence service communications, and critical infrastructure operational technology against all foreign collection, regardless of source. The defences have to be designed assuming hostile capability from any state actor.

The current architecture assumes American operations are not happening, which is the assumption that has produced sixty years of successful American operations. Operationally, European counter-intelligence officers have to be permitted, instructed, and resourced to investigate American and Israeli operations when those operations are suspected.

The investigations have to produce consequences when they confirm operations. The consequences have to be communicated through diplomatic and operational channels in ways that establish that European counter-intelligence is not theatre.

The third is legal framework and political will. European governments need judicially enforceable standards for foreign intelligence operations on European soil. The standards have to apply to allied services as much as to adversary services. The current framework has no effective sanction against allied operations because the political will to invoke sanctions against allies has been absent.

If the National Security Agency conducts an operation on European soil that would constitute a criminal offence if conducted by Russian intelligence, the response has to be the same. The defence of European leaders’ communications is the test case.

The Merkel case revealed that the Chancellor of Germany could be surveilled at scale by an allied service through cables transiting an allied territory. The Dunhammer case revealed that this surveillance was operationally enabled by another European intelligence service. The cases produced no architectural change.

European leaders continue to communicate on infrastructure that is presumed compromised. Sovereign counter-intelligence requires this to change. The technical mechanisms exist. The political will to require them does not.

  1. The Anchor and the Clock ===========================

Sovereign intelligence and sovereign counter-intelligence are built on infrastructure that has to be procured, paid for, validated, and operationally tested. The build requires anchor customers whose demand is sufficient to fund the suppliers, whose requirements are demanding enough to validate the quality, and whose operational use establishes the equipment as serious.

The American intelligence community provides the demonstration of how this works. In-Q-Tel, the venture capital arm of the Central Intelligence Agency established in 1999, invested approximately two million dollars in Palantir at company foundation.

That capital, alongside parallel anchor procurement from American intelligence and defence customers, allowed Palantir to build to a market capitalisation of approximately two hundred and fifty billion dollars by the mid-2020s. The leverage ratio is one hundred and twenty-five thousand to one.

The intelligence community financed the construction of a strategic software supplier through a combination of equity investment and anchor procurement, with terms that ensured the company’s mission, governance, and technical architecture aligned with American intelligence requirements.

The same arithmetic applies in reverse. European intelligence services choosing to anchor European technology suppliers would produce the same effect at European scale. Sovereign chip procurement at intelligence-grade requirements would validate European fabrication. Sovereign cloud procurement at intelligence-grade security requirements would validate European data centre operators.

Sovereign analytical platform procurement at intelligence-grade workflow requirements would validate the European Palantir alternative the military layer of this series argues for. Without intelligence-grade demand, the European stack is built to commercial requirements that lower-stakes customers tolerate.

With intelligence-grade demand, the European stack is built to the security and capability standards that make it the default for everyone else who comes after.

The clock runs on quantum migration. The United States National Institute of Standards and Technology finalised the post-quantum cryptography standards in August 2024 after a multi-year evaluation process. The standards include ML-KEM for key encapsulation, ML-DSA for digital signatures, and SLH-DSA for hash-based signatures.

The White House has set deadlines of 2033 for classified communications and 2035 for sensitive civilian data. The migration cannot be conducted in parallel. Algorithm validation precedes implementation, which precedes testing, which precedes operational deployment, which precedes personnel training. The cumulative timeline is ten to fourteen years sequential.

If migration begins now, completion by 2033 is achievable. Each year of delay compresses the remaining timeline beyond what is feasible.

The cost of delay compounds. The National Security Agency operates UPSTREAM, a programme that intercepts encrypted communications transiting international cables and stores them in bulk. Communications encrypted today with current cryptographic standards are stored.

When quantum computers reach operational scale, currently estimated between 2030 and 2035, the stored communications become decryptable. Each year of delay means an additional year of European communications added to the recoverable archive. Delay is the accumulation of future cryptographic exposure.

There is a further point that the public discussion of post-quantum cryptography has not addressed. Europe cannot trust NIST. NIST is a United States government body. Algorithm selection in the post-quantum process was influenced by the National Security Agency, which has a documented history of attempting to influence cryptographic standards in ways that preserve American collection capability.

The Dual_EC_DRBG case in the previous decade established the pattern. Adopting NIST-finalised algorithms means trusting that this pattern has not repeated in the post-quantum process. That trust has not been earned and cannot be verified externally.

Sovereign cryptography requires sovereign standards. Europe has the institutional capacity. ETSI sets European telecommunications standards. ENISA develops European cybersecurity guidance.

National bodies including ANSSI in France, BSI in Germany, and academic cryptographic communities across the Netherlands, Belgium, Switzerland, and Italy have produced world-class cryptographic research for decades. The Belgian designers of AES, the European elliptic curve work, the German hash function research, the Swiss applied cryptography practice. The capacity exists.

The coordination at strategic level does not. Sovereign standards require European standards-setting at the strategic level, not just at the technical level. They require European cryptographic algorithms designed and validated by European bodies, with implementation, validation, and deployment infrastructure built deliberately rather than imported from American sources.

This is the work that meets the clock. Anchor customers funding the build. Sovereign standards setting the requirements. Sovereign cryptography implementing the requirements. Sovereign hardware running the cryptography. Sovereign cloud hosting the workloads. Sovereign analytical platforms processing the intelligence. Sovereign intelligence services consuming the platforms.

The architecture is integrated. The components have to be built together because they depend on each other. The sequence has to begin now because the deadline is fixed.

  1. The Choice =============

European politics is not American politics. Diplomacy where possible. Multilateralism with adversaries as well as allies. Civil liberties built into the architecture. No more forever wars. These are commitments held by European publics and expressed through European democratic institutions.

The architecture commits us to choices European publics do not share. Borrowed eyes show us threats interpreted through other priorities. Borrowed stacks make our decisions visible to actors who hold different values. Borrowed synthesis routes our policy toward alignments we did not vote for.

Sovereign chips, sovereign cables, sovereign cloud, sovereign defence are necessary. They protect European values when European intelligence decides what they are for. The work is parallel. Intelligence services anchor the sovereign stack by buying it.

We do not believe in forever wars. The architecture commits us to them. Building our own eyes is how we get to choose.

[1] British-United States Communication Intelligence Agreement (BRUSA, later UKUSA), signed 5 March 1946. Subsequently extended to Canada, Australia and New Zealand. Declassified 2010 by the National Security Agency and Government Communications Headquarters.

[2] Memorandum of Understanding between the National Security Agency Central Security Service and the Israeli SIGINT National Unit Pertaining to the Protection of US Persons, undated but operational from approximately 2009. Disclosed via documents released by Edward Snowden and published in The Guardian on 11 September 2013.

[3] Direction generale de la Securite interieure (DGSI), contract with Palantir Technologies for Palantir Gotham analytical platform, signed November 2015 following the Paris attacks of 13 November 2015. Reported in Le Monde and Mediapart.

[4] DGSI-Palantir contract renewal, December 2025, for an additional three-year term. Public reporting in Le Monde and L’Express.

[5] Forsvarets Efterretningstjeneste (FE) internal investigation 2014, leaked to consortium of Danish, Swedish, Norwegian, German and French broadcasters. Reported jointly by DR, SVT, NRK, NDR, Suddeutsche Zeitung and Le Monde, 30 May 2021. Surveillance targeted Angela Merkel, Frank-Walter Steinmeier, and other European leaders 2012-2014.

[6] Bundestag NSA-Untersuchungsausschuss (German parliamentary inquiry on NSA mass surveillance), proceedings 2014-2017. Final report published June 2017 documented BND use of NSA selectors against European companies and officials.

[7] ‘The intelligence coup of the century’, joint investigation by The Washington Post, Der Spiegel and SRF, 11 February 2020. Revealed CIA and BND joint ownership of Crypto AG, a Swiss cryptography company, from 1970 to 2018, through which the agencies read encrypted communications of more than 130 governments.

[8] Operation Dunhammer reporting by DR, SVT, NRK, NDR, Suddeutsche Zeitung and Le Monde, 30 May 2021. Revealed FE assistance to NSA in tapping undersea cables transiting Danish territory 2012-2014 to surveil European leaders.

Sign the Manifesto. The eight demands that follow from the case made in this paper and the twenty-seven others. Sign →