Why the answer to attribution-proof and autonomous aggression is not a better tripwire but a permanent framework of cooperation — and why the European Union already has the clause it needs
The defining security problem of the coming decade is not that Europe lacks a mutual-defence guarantee. It is that the most consequential forms of aggression Europe now faces are designed, with considerable sophistication, to fall beneath the threshold at which any mutual-defence guarantee can be invoked. The severed undersea cable, the drone incursion of uncertain origin, the cyber campaign routed through proxies, the sabotage that could be an accident, the autonomous system whose operator cannot be named — these are not failures of deterrence in the classical sense. They are deliberate exploitations of a structural feature of the collective-defence architecture: its dependence on a moment of attack and an agreed attribution. An adversary that can deny both has, in effect, disarmed the guarantee without firing a recognised shot.
The standard response to this problem is to ask how the tripwire might be adjusted — how NATO’s Article 5, the canonical collective-defence commitment, might be stretched, clarified, or lowered to catch aggression that currently slips beneath it. This essay argues that the standard response mistakes the nature of the problem. The difficulty with a threshold-based, attribution-dependent guarantee in the face of attribution-proof aggression is not that the threshold sits in the wrong place. It is that a threshold is the wrong instrument. Aggression engineered to be ambiguous cannot be reliably caught by any tripwire, however finely calibrated, because ambiguity is precisely what the tripwire cannot process. The answer is not a better trigger. It is a different kind of instrument altogether: a permanent, continuous framework of capability and cooperation that does not wait for a threshold to be crossed because it is already operating before the crossing, during it, and after it.
The central contention of this essay is that the European Union already possesses the legal basis for exactly such an instrument, that it is hiding in plain sight, and that it has been persistently misread — by Europe’s critics and by much of Europe itself — as a mere industrial-policy mechanism rather than as the strategic response to sub-threshold warfare that its structure makes possible. The instrument is Article 42(6) of the Treaty on European Union: the Permanent Structured Cooperation clause. This essay makes the case for reading Article 42(6) as a modern frame for a modern problem, and proposes a concrete three-pillar architecture for activating it to that end. Because the argument turns on a precise legal distinction that is frequently blurred, it begins by getting the treaty text exactly right.
I. What Article 42(6) says — and what it does not
Rigour requires beginning with the primary text and with a distinction that the essay’s argument depends upon and that careless usage routinely elides. Article 42 of the Treaty on European Union is the foundation of the Union’s Common Security and Defence Policy, and two of its paragraphs are frequently confused, including in serious commentary. They must be kept apart.
Article 42(7) TEU is the Union’s mutual-assistance clause — sometimes called its mutual-defence clause — and it is the EU’s nearest analog to NATO’s Article 5. Its text is a genuine collective-defence commitment: if a Member State is the victim of armed aggression on its territory, the other Member States are under an obligation of aid and assistance by all the means in their power, in accordance with Article 51 of the United Nations Charter. It derives from the mutual-defence clause of the old Western European Union, was invoked once — by France, following the November 2015 Paris attacks — and has otherwise received limited scholarly and operational attention. It is, for the purposes of this essay, the clause that this essay is not about.
Article 42(6) TEU is a different instrument entirely, and its exact words matter. It provides that “those Member States whose military capabilities fulfil higher criteria and which have made more binding commitments to one another in this area with a view to the most demanding missions shall establish permanent structured cooperation within the Union framework.” This is the legal basis of PESCO, activated in December 2017 and now encompassing twenty-six of the twenty-seven Member States, governed by Article 46 and Protocol No. 10. Its logic is not the logic of a defence trigger. It is the logic of a standing commitment: participating states bind themselves to develop military capabilities, to invest more and more intelligently in defence, and to cooperate structurally so that they are collectively able to conduct operations at the higher end of the military spectrum.
Epistemic status: Confirmed and verifiable against primary sources. The text of Article 42(6) and 42(7) TEU, the PESCO founding decision (Council Decision (CFSP) 2017/2315 of 11 December 2017), Protocol No. 10, and the France 2015 invocation of Article 42(7) are all matters of the public treaty and documentary record. The reading that follows — that 42(6) is better suited than a threshold-based guarantee to attribution-proof aggression — is the essay’s analytical argument, not a claim of the treaty text, and is developed and defended as such.
The distinction is the hinge of the whole argument, so it is worth stating its consequence plainly. Article 42(6) is not a mutual-defence clause and this essay does not claim that it is. It would be a category error to argue that a capability-cooperation framework can substitute for a defence guarantee, and no such claim is made here. The claim is subtler and, I will argue, more important: that for the specific class of threats that defeat defence guarantees by design — the attribution-proof, the sub-threshold, the autonomous — the relevant response is not a defence guarantee at all, and the capability-cooperation framework of Article 42(6) is structurally better matched to the problem than any adjustment of the guarantee could be. The comparison with Article 5 is therefore not a comparison of two clauses that do the same job. It is the argument that, for this class of threat, the job itself has been misconceived.
Two further points of primary-source detail fortify the foundation and pre-empt a reviewer’s objections. The first concerns what Article 42(6)’s “binding commitments” actually are. They are not rhetorical. Protocol No. 10 annexed to the Treaty, together with the founding Council Decision of December 2017, specifies concrete undertakings: to increase defence investment in real terms; to raise the share of spending devoted to defence research and technology and to collaborative capability projects; to bring defence apparatuses into closer alignment; and to make forces available for the Union’s most demanding missions. Participation is not a declaration of intent but an assumption of measurable obligations, whose fulfilment the Council assesses periodically. Whatever one concludes about how faithfully these obligations have been honoured — a question taken up among the objections below — the legal instrument is one of binding, assessable commitment, not of aspiration. That is what makes it a plausible foundation for a serious strategic architecture rather than a forum for coordination.
The second point concerns the relationship between the two paragraphs, because a careful reader will ask why, if Article 42(7) is the EU’s mutual-defence clause, the essay does not simply argue for its activation. The answer is instructive. Article 42(7) has been invoked exactly once — by France in November 2015 — and that single invocation revealed the clause’s limits as a response to sub-threshold aggression precisely because it required a qualifying event of unambiguous gravity, the coordinated Paris attacks, to trigger it. Article 42(7), like NATO’s Article 5 that it echoes, is a threshold instrument; it inherits the same dependence on a classifiable armed aggression and, in its case, on the further complication that its obligations sit uneasily beside member states’ NATO commitments and national constitutional constraints on the use of force. To argue for 42(7) against attribution-proof aggression would be to make the very error this essay diagnoses — reaching for a better tripwire. The essay’s choice of 42(6) over 42(7) is therefore not an oversight to be corrected but the deliberate consequence of its central claim.
II. Why the threshold model fails against attribution-proof aggression
To see why a standing capability framework is the right instrument, one must first see precisely why the threshold model is the wrong one for this class of threat — not weak, not in need of adjustment, but structurally mismatched. NATO’s Article 5 provides that an armed attack against one member shall be considered an attack against all. Its power, as observers across the strategic literature agree, lies in its clarity: the certainty of a collective response deters the contemplation of an attack. But that power is contingent on two conditions that attribution-proof aggression is specifically engineered to deny.
The first condition is the identifiable armed attack — a discrete event of sufficient gravity to register as an act of war. Hybrid and gray-zone aggression is designed to avoid producing such an event. It substitutes the cumulative for the discrete: a long campaign of sabotage, interference, and coercion, no single instance of which rises to the level of an armed attack, but whose aggregate effect is strategically decisive. NATO’s own documents have acknowledged this difficulty and left it deliberately unresolved. The 2014 Wales Summit made cyber defence part of collective defence; the 2016 Warsaw Summit held that hybrid warfare could in principle trigger Article 5; the 2021 Brussels Summit and the 2022 Strategic Concept affirmed that cumulative cyber and hybrid activities could reach the Article 5 threshold. But in each case the Alliance deliberately declined to specify what degree of cumulative effect, what level of attribution, or what political context would justify invocation — preserving the ambiguity as strategic flexibility, but thereby confirming that the threshold model has no settled answer to aggression pitched below it.
The second condition is attribution. Article 5 requires not merely that an attack occurred but that its author be identified with enough confidence to sustain a collective political decision. Attribution-proof aggression attacks this condition directly, through proxies, obfuscation, deniability, and false-flag technique. The strategic literature on the Article 5 threshold converges on a sobering conclusion: that vagueness, precedent, and political risk make invocation unlikely in exactly the ambiguous cases that adversaries now favour, and that the Alliance has consequently been driven to build a toolkit of responses below the threshold rather than to rely on the threshold itself. The drone incursions over NATO territory in 2025, the campaign of undersea-cable and infrastructure sabotage, and the integration of large-scale cyber and influence operations into conventional conflict all illustrate the same lesson: the tripwire is easiest to evade precisely when its invocation would matter most.
Three illustrative cases make the failure concrete, and each must be handled with explicit care about what is established and what is contested — a discipline this essay treats as non-negotiable given the subject. The first is the campaign of damage to undersea cables and pipelines in European waters over recent years. That such damage has occurred is confirmed; that some incidents involved vessels behaving suspiciously is documented; but attribution to a directing state has in most individual cases been officially characterised as suspected, investigated, or probable rather than conclusively established, and this essay does not assert a firmer attribution than the public record supports. That very gap between evident harm and provable authorship is the point: it is the condition attribution-proof aggression manufactures, and the condition under which a threshold guarantee cannot be invoked.
The second case is the series of drone incursions over European territory and sensitive sites during 2025, including over NATO members. The incursions are confirmed as events; their origin and directing authority have in a number of cases remained officially unattributed or contested, and again the essay labels them so deliberately. A collective-defence guarantee cannot respond to an aircraft whose operator cannot be named, and the incursions functioned — whether by design or not — as a demonstration of exactly that limit. The third case is the integration of large-scale cyber and information operations into the conduct of conventional conflict, documented by independent technical reporting in the context of the war in Ukraine. Here the pattern is different but the lesson is the same: hybrid instruments operate not only beneath the threshold in peacetime but alongside conventional force in wartime, targeting decision-making and societal resilience in ways a classify-and-attribute model struggles to process. In none of the three cases is the essay’s argument dependent on a contested attribution; the argument is, on the contrary, about what follows precisely when attribution cannot be established, which is the situation each case exemplifies.
Autonomous warfare sharpens both problems to a point. An autonomous system compresses the decision timeline below the speed at which a consensus attribution can be assembled; it obscures the chain of authorisation between the act and its author; and it blurs the line between a malfunction and an attack in ways that a threshold model, which must classify each event as attack or non-attack, cannot accommodate. The companion analysis of the legal architecture of autonomous weapons elsewhere in this volume shows how unsettled the attribution of an autonomous act remains even in the law of armed conflict. A collective-defence guarantee that requires a named author cannot function reliably against a mode of warfare specifically capable of denying one. The threshold model does not fail here because the threshold is set too high. It fails because the model asks a question — attack or not, and by whom — that this class of aggression is designed to render unanswerable.
III. Why capability cooperation is the matching instrument
If the defect of the threshold model is that it must wait for a classifiable, attributable event, then the matching instrument is one that does not wait — one that operates continuously, independent of any triggering moment, and that produces its strategic effect through standing capability and cooperation rather than through the promise of a reaction. This is precisely the structure of Article 42(6). Its value against attribution-proof aggression follows from three features of its design.
First, it is continuous rather than triggered. PESCO’s binding commitments — to raise defence investment, to develop capabilities jointly, to make forces available for the most demanding missions — operate at all times, not upon the occurrence of an attack. A framework that is always operating cannot be evaded by an adversary who denies a triggering event, because it has no triggering event to deny. The strategic effect of a dense, integrated, continuously developing set of European capabilities is present in the gray zone as much as in open conflict; it does not switch on at a threshold, and so cannot be switched off by staying beneath one.
Second, it is capability-oriented rather than response-oriented. The threshold model deters by promising a reaction; its currency is the credibility of that promise, which attribution-proof aggression erodes. Article 42(6) works in a different currency entirely: the actual, developed, jointly held capability to detect, attribute, withstand, and counter the full spectrum of sub-threshold aggression. The relevant capabilities — shared situational awareness across the maritime and cyber domains, resilient critical infrastructure, joint attribution capacity, rapidly deployable counter-hybrid and counter-autonomous forces — are exactly the kind of standing capability that a capability-development framework exists to produce, and exactly the kind that a defence guarantee, which produces nothing but a promise, does not.
Third, it is a coalition of the capable and willing rather than a consensus of all. Article 42(6)’s text is explicit that permanent structured cooperation is established by those Member States “whose military capabilities fulfil higher criteria” and which make “more binding commitments” — a deliberately differentiated, vanguard structure, not a lowest-common-denominator unanimity. This matters against attribution-proof aggression because the fatal weakness of a consensus-based trigger is that a single hesitant member, exploiting the very ambiguity the adversary has manufactured, can block collective action at the moment it is needed. A framework built on a committed vanguard does not depend on unanimous agreement that an attack has occurred, because it is not organised around agreeing that an attack has occurred. It is organised around a standing commitment that the vanguard has already made.
Taken together, these three features describe an instrument matched to the problem in the way the threshold model is mismatched to it. Where attribution-proof aggression exploits the need for a triggering event, Article 42(6) has no triggering event. Where it exploits the need for attribution, Article 42(6) builds the capability to attribute as one of its standing objectives rather than requiring attribution as a precondition of action. Where it exploits the need for consensus, Article 42(6) is structured as a differentiated commitment among the willing. The clause was not designed with hybrid and autonomous warfare in mind — it predates the sharpest form of the problem — but its structure answers that problem better than the instrument the debate reflexively reaches for. That is the sense in which Article 42(6) is a modern frame: not because it is new, but because its logic fits a threat the threshold model was never built to hold.
IV. Activating the frame: a three-pillar architecture
To argue that Article 42(6) is the right instrument is not yet to say how it should be used. PESCO as it currently operates is a portfolio of capability projects, valuable but diffuse, and not organised around the specific mission of countering attribution-proof and autonomous aggression. What follows is a proposal — the author’s own, offered as a concrete architecture rather than a reading of existing arrangements — for activating the frame to that end. It rests on three pillars, each corresponding to one of the structural features identified above and each addressing one of the ways the threshold model fails.
The first pillar is a standing attribution and situational-awareness capability, developed jointly under Article 42(6) and owned in common by the participating states. If the threshold model fails because attribution is contested and slow, the response is to make attribution a continuously developed, jointly held capability rather than an ad hoc political scramble after each incident. This pillar would fuse maritime, cyber, space, and electromagnetic surveillance into a shared European picture, with common technical standards for evidence and a standing mechanism for reaching collective attribution judgements at operational speed. Its purpose is not to lower a threshold but to dissolve the attribution problem that makes the threshold unusable — to ensure that when an undersea cable is cut or a drone crosses a border, the vanguard already possesses the jointly owned means to establish, credibly and quickly, what happened and who is responsible.
The second pillar is a resilience-and-continuity commitment: a binding undertaking among the participating states to harden the critical infrastructure, supply chains, and decision-making processes that sub-threshold aggression targets, and to guarantee mutual support in restoring them. If the threshold model fails because cumulative, deniable aggression never produces a single decisive attack, the response is to deny that aggression its cumulative effect — to build a European system that absorbs sabotage, cyber disruption, and infrastructure attack without strategic degradation, and that treats the resilience of one participant as the concern of all. This pillar converts the logic of mutual assistance from a post-attack obligation, as in Article 42(7), into a pre-attack commitment operating continuously under the capability framework of Article 42(6) — assistance not as a reaction to an armed attack that may never be declared, but as a standing feature of a jointly maintained system.
The third pillar is a rapid counter-hybrid and counter-autonomous capability: a differentiated, high-readiness force structure, developed by the capable vanguard, able to respond to sub-threshold and autonomous aggression with proportionate, attributable, and rapid action that does not require the invocation of a collective-defence guarantee. If the threshold model fails because consensus cannot be assembled at speed, the response is a vanguard that has pre-committed to act and pre-developed the means to act, within the differentiated structure Article 42(6) explicitly authorises. This is the pillar that most directly exploits the clause’s “higher criteria” and “more binding commitments” language: a coalition of the capable, bound in advance to a common posture, able to impose timely and coordinated costs on attribution-proof aggression without waiting for the unanimous determination that such aggression is engineered to prevent.
It is worth specifying what each pillar would concretely require, because the difference between a slogan and an architecture is the level of specification it can bear. The attribution pillar would build, as jointly owned PESCO capability, a persistent multi-domain surveillance and fusion capacity — seabed and maritime monitoring, space-based and electromagnetic sensing, and a shared cyber-forensic and evidentiary standard — coupled with a standing analytic cell empowered to issue collective attribution assessments at operational tempo rather than through the slow accretion of national positions. The resilience pillar would require binding minimum-hardening standards for designated critical infrastructure across participating states, pre-positioned mutual-restoration capacity, and stockpiled redundancy for the systems — energy interconnectors, subsea data and power cables, logistics corridors — whose disruption is the currency of cumulative aggression. The response pillar would require a differentiated high-readiness formation, drawing on the vanguard’s higher-criteria capabilities, with pre-agreed rules of engagement for proportionate counter-hybrid and counter-autonomous action and a standing political authorisation that does not require fresh unanimity at the moment of each incident. Each specification is demanding; none exceeds what Article 42(6)’s “higher criteria” and “more binding commitments” were written to authorise.
The three pillars are designed to interlock. The attribution pillar establishes what has happened; the resilience pillar ensures that what has happened does not accumulate into strategic defeat; the response pillar imposes costs that restore deterrence in a currency the threshold model cannot supply. None of the three requires an amendment to the treaties, a new institution, or the invocation of a defence guarantee. Each is an application of powers Article 42(6) already confers, redirected from the diffuse capability-project portfolio PESCO currently comprises toward the specific and urgent mission of countering the aggression that the collective-defence architecture cannot hold. The framework is a proposal for using an existing instrument well, not for building a new one.
Epistemic status: the three-pillar architecture is the author’s original proposal, presented as such. Its legal foundation — that Article 42(6) and Protocol No. 10 authorise differentiated, binding capability commitments among a vanguard of Member States — is confirmable against the primary sources. Its strategic claims — that this architecture would counter attribution-proof aggression more effectively than adjustments to the threshold model — are argued, not demonstrated, and would benefit from the scrutiny of a specialist in European security law. A named legal reviewer credited at the foot is recommended for this essay, per the essay brief and given its flagship status.
V. Objections, and the limits of the claim
A flagship argument earns its place by meeting its strongest objections rather than avoiding them, and there are three that deserve direct answer. The first is the category objection already anticipated: that Article 42(6) is a capability framework and Article 5 a defence guarantee, so that comparing them is comparing unlike things. The answer is that the comparison is deliberate and is the essay’s point. The claim is not that 42(6) does the same job as Article 5 better; it is that for attribution-proof aggression the job Article 5 does is the wrong job, and that the capability-cooperation instrument is the right one. Conceding that they are different instruments is not a weakness of the argument — it is the argument.
The second objection is that this proposal risks duplicating or undermining NATO, which remains the cornerstone of European collective defence. The answer is that it does neither, because it operates in the space NATO’s threshold model has itself acknowledged it cannot reliably cover. Nothing in the three-pillar architecture touches the Article 5 guarantee against a classifiable armed attack, which remains NATO’s domain and is not in question here. The architecture addresses the sub-threshold space that the Alliance’s own summits have repeatedly identified as unresolved, and it does so through an EU instrument precisely because the EU’s economic, regulatory, and infrastructural levers — examined elsewhere in this volume — are the levers most relevant to hybrid aggression, and are ones NATO does not possess. The relationship is complementary by construction: NATO holds the threshold; Article 42(6) holds the space beneath it.
The third objection is the most serious and must be conceded in part: that PESCO has, in practice, underdelivered — that its binding commitments have been unevenly honoured, its projects diffuse, and its strategic ambition modest, so that to rest a flagship argument on it is to rest it on a disappointment. This is true as a description of PESCO to date, and the essay does not deny it. But it is an argument about the use of the instrument, not about the instrument itself, and it cuts toward the proposal rather than against it. That Article 42(6) has been used diffusely and unambitiously is precisely why this essay proposes redirecting it toward a specific and urgent mission. An instrument that has underperformed because it lacked a focusing purpose is not refuted by a proposal to give it one. The gap between what Article 42(6) authorises and what PESCO has so far achieved is not a reason to abandon the clause. It is the space the argument occupies.
VI. The frame and the moment
The deeper claim of this essay is that Europe has been looking for its answer to sub-threshold and autonomous aggression in the wrong place — in the machinery of the tripwire, asking how the guarantee might be stretched to catch what is designed to evade it — when the answer lies in an instrument it already possesses and has consistently underused. The reflex to reach for the threshold model is understandable; it is the architecture the twentieth century built, and its clarity is genuinely powerful against the threat it was built for. But the threat has changed, and the defining aggression of this decade is engineered to defeat exactly the classify-and-attribute logic on which the threshold model depends. Against that aggression, the right response is not a finer tripwire. It is a standing framework of capability and cooperation that does not wait for a wire to be tripped.
Article 42(6) is that framework, hidden in plain sight and mislabelled as industrial policy. Read correctly, it is a modern frame for a modern problem: continuous where the threat is continuous, capability-based where the threat erodes the credibility of promises, and built on a committed vanguard where the threat exploits the paralysis of consensus. The three-pillar architecture proposed here — joint attribution, common resilience, and a rapid vanguard response — is one way to activate that frame, and it requires no new treaty and no new institution, only the decision to use an existing clause for the purpose its structure makes possible. The money and the rules shape the frontier, as this volume has argued; so too does the legal frame through which a continent organises its own defence. Europe’s most underrated security instrument is not a weapon or a guarantee. It is a clause it has been reading as something smaller than it is.
References
Primary and authoritative sources for this essay. Legal claims are confirmable against the EU treaties and PESCO documents; attribution of specific incidents is treated as contested where the public record is not conclusive.
Primary legal sources — EU treaty and PESCO
Treaty on European Union (consolidated version), Article 42, in particular Article 42(6) (permanent structured cooperation) and Article 42(7) (mutual assistance / mutual defence clause); and Article 46 (governance of PESCO).
Protocol (No. 10) on permanent structured cooperation established by Article 42 of the Treaty on European Union.
Council Decision (CFSP) 2017/2315 of 11 December 2017 establishing permanent structured cooperation (PESCO) and determining the list of participating Member States.
Council Recommendation of 14 November 2022 assessing the progress made by participating Member States to fulfil commitments undertaken in the framework of PESCO (2022/C 433/02).
European External Action Service (EEAS) and pesco.europa.eu, PESCO factsheets and documentation (26 of 27 Member States participating; binding commitments; Protocol No. 10 entry criteria).
Article 42(7) and the EU mutual-defence clause
European Parliament resolution of 21 January 2016 on the mutual defence clause (Article 42(7) TEU).
European Council on Foreign Relations, “Article 42.7: An Explainer.”
Clingendael Institute, “Uncharted and Uncomfortable in European Defence” (historical and legal context of Article 42(7); the France 2015 invocation; comparison with NATO Article 5).
Nordic Journal of European Law, “The EU’s Mutual Defence Clause: Legal and Strategic Considerations” (Article 42(7); ‘armed aggression’ vs ‘armed attack’; relationship to Article 51 UN Charter).
NATO Article 5, the threshold, and hybrid / gray-zone aggression
North Atlantic Treaty, Article 5 (collective defence).
NATO summit declarations (Wales 2014; Warsaw 2016; Brussels 2021) and the 2022 Strategic Concept on cyber and hybrid activities and the Article 5 threshold (case-by-case determination; deliberate ambiguity).
Center for European Policy Analysis (CEPA), “Blurred Borders: NATO Needs Answers to Hybrid Attacks” and “Using NATO’s Article 5 Against Hybrid Attacks” (the below-threshold toolkit; vagueness, precedent, and political risk as barriers to invocation).
Small Wars Journal, “From Tanks to TikTok: Adapting Article 5 for Graduated Responses to Hybrid Warfare,” 2025.
Analyses of the 2025 drone incursions over NATO territory and the undersea-cable / infrastructure sabotage campaign; and independent technical reporting on the integration of cyber and influence operations into conventional conflict. Attribution status is treated as contested where the public record does not conclusively establish a directing state.
