June 15, 2026 | Policy Brief

AI Is Outpacing NATO’s Hybrid Defense Playbook

June 15, 2026 | Policy Brief

AI Is Outpacing NATO’s Hybrid Defense Playbook

NATO just received a glimpse of how a blackout can quickly become a crisis.

At a three-day exercise in Bydgoszcz, Poland, NATO tested its ability to respond to a multi-domain crisis that combined cyberattacks on critical infrastructure with AI-generated disinformation campaigns. The exercise highlighted how adversaries can use AI to turn critical infrastructure disruptions into crises that undermine public trust and complicate the alliance’s coordinated response.

NATO’s Readiness Gap Is One of Coordination, Awareness, and Speed

The NATO-Ukraine Joint Analysis, Training and Education Centre (JATEC) hosted the exercise, during which NATO teams responded to simultaneous disruptions in the fictional state of Perantsa. Played by Ukrainian specialists, attackers from the fictional adversary of Karti caused power outages, flooding, and a banking system failure. They also deployed AI-generated social media campaigns designed to sow confusion and erode confidence in government institutions. One message read, “Perantsa can’t help, but Karti does.”

While the NATO teams won by a narrow margin, successfully defending critical infrastructure systems in two of three scenarios, the exercise exposed weaknesses in NATO’s preparedness for AI-enabled hybrid warfare. According to Lt. Col. Yvonne Rotter, director of the German Bundeswehr’s Centre for Digitalization, the Ukrainian teams demonstrated greater creativity in problem solving, stronger AI skills, and a faster operational pace.

Real-World Attacks Show How Quickly Disruption Can Spread

The exercise drew on practical lessons from Russia’s war against Ukraine, particularly how Moscow has used cyber operations to cause disruptions in critical services.

Hours before the full-scale invasion of Ukraine in February 2022, Russia launched a cyberattack on Viasat’s KA-SAT satellite network to knock out communications in Ukraine. In December 2023, Russia also attacked Ukraine’s largest telecom operator, Kyivstar, destroying core systems and disrupting service for roughly 24 million users. A year later, Russia struck Ukraine’s state registers, knocking offline for several days roughly 60 Ministry of Justice databases essential to records concerning birth, marriage, death, and real estate. Ukraine’s then-Deputy Prime Minister Olha Stefanishyna called the incident “the largest external cyberattack” on the country’s state registers in recent years.

JATEC’s exercise confirms that the challenge is no longer simply detecting and mitigating cyberattacks, but ensuring that allies can rapidly share information, align decisions, and maintain public trust while confronting simultaneous disruptions across cyber, physical, and information domains. Rotter observed that the NATO teams fell short of the level of coordination a real-world crisis would require, noting that government ministries often “work beside each other but not with each other” and “don’t always align their communication.” Because participants joined from Poland or remotely from their home countries, the exercise replicated the distributed coordination challenges allies would face in a real crisis. Their difficulty synchronizing responses across multiple time zones underscores the need for more frequent practice under these conditions. 

NATO Should Adapt Its Exercises for AI-Enabled Hybrid Warfare

The lessons from JATEC build on years of NATO efforts to strengthen collective cyber resilience through tabletop and live-fire exercises. NATO’s flagship Cyber Coalition has brought together more than 1,300 cyber defenders from NATO members, partner countries, and the European Union to test their collective response to cyberattacks on critical infrastructure. The NATO Cooperative Cyber Defence Centre of Excellence annually organizes the largest live-fire cyber defense exercise, with blue teams defending thousands of systems against real-time red team attacks.

To prepare for AI-enabled hybrid warfare, NATO should expand exercises that practice responses to joint critical infrastructure disruptions and AI-enabled public communications compromises. Ukraine’s sustained exposure to coordinated cyber and information campaigns makes it an essential source of insight, meaning that NATO should continue integrating its lessons into exercise design.

Given NATO’s recognition that China poses a security threat to the alliance, expanding exercise partnerships with Indo-Pacific partners — Australia, Japan, New Zealand, and South Korea — would enable NATO to incorporate lessons from that theater and test joint responses to not only Russian but also Chinese cyber and information threats.

Jiwon Ma is a senior policy analyst at the Center on Cyber and Technology Innovation (CCTI) at the Foundation for Defense of Democracies (FDD), where Nidhi Ummettala is an intern. For more analysis from the authors and CCTI, please subscribe HERE. Follow FDD on X @FDD and @FDD_CCTI. Follow Jiwon on X @jiwonma_92. FDD is a Washington, DC-based, nonpartisan research institute focusing on national security and foreign policy.