DATE
When AI Meets Irregular Warfare
Last week, Intercept CEO Joe McCann joined an international group of practitioners at the George C. Marshall European Center for Security Studies, contributing as an industry voice to Hybrid Threats & Cyber Security — Where AI Meets Security and Irregular Warfare. Around the table were leaders from the German armed forces, intelligence services, US Special Forces, and the cyber threat intelligence community — a rare cross-section of people who see the modern threat landscape from very different vantage points, and who increasingly find themselves describing the same problem.
That problem is the erosion of the line between war and peace.

For most of the last century, conflict had a recognisable shape. It had a beginning and an end, a front line, and a fairly clear distinction between combatant and civilian. Hybrid threats dismantle that clarity by design. Adversaries now operate persistently in the "grey zone" — below the threshold that would trigger a conventional military response, but with real strategic effect. Cyber intrusions, sabotage of physical and digital infrastructure, economic coercion, and information operations are combined and sequenced to achieve outcomes that once required tanks.
The point Joe returned to throughout the week is that this is not a future scenario. It is the operating environment today, and it does not stop at the borders of the states directly involved. Supply chains, critical national infrastructure, financial systems, and the private companies that run them are all part of the contested space — whether they have chosen to be or not.
Much of the discussion focused on who is behind this activity — and here the picture has become genuinely difficult to read. At one end sit nation-state actors: well-resourced, patient, and strategic, capable of pre-positioning in critical networks and waiting months or years for the moment that matters. At the other sit hacktivists: ideologically motivated, fast-moving, and often opportunistic, using cyber operations to make a political point.
What makes today's environment so challenging is that the line between the two is deliberately blurred. States increasingly operate through proxies and hacktivist personas, borrowing the deniability of grassroots activism to mask strategic intent. An attack that looks like an act of protest may be state-directed; a "spontaneous" campaign may be anything but. For defenders, attribution is no longer a technical footnote — it is central to understanding what an incident actually means and how to respond.

One of the most important shifts discussed at the Center was the growing centrality of Foreign Information Manipulation and Interference (FIMI). FIMI is a deliberately precise term. It focuses less on whether a piece of content is "true" or "false" and more on the behaviour behind it — the coordinated, often covert, and frequently state-backed manipulation of the information environment to degrade trust, inflame division, and shape decisions.
This matters because it reframes the target. In a FIMI campaign, the objective is not to breach a network or take down a service. It is to alter what a population believes, whom it trusts, and how it votes — to turn the openness of a democratic society into an attack surface.
Artificial intelligence has changed the economics of this entirely. What once required teams of people can now be produced at scale and at speed: synthetic personas, generated imagery and audio, and content tailored to specific communities and anxieties. The same AI capabilities that are transforming legitimate business are lowering the cost and raising the sophistication of manipulation. Defenders, in turn, are learning to use AI to detect coordinated inauthentic behaviour and surface the patterns a human analyst would miss. It is, increasingly, machine speed on both sides.
If FIMI is an attack on what we believe, operational technology (OT) security is about protecting the systems that keep the physical world running. OT is the technology behind power grids, water treatment, manufacturing lines, transport networks, and energy pipelines — the industrial control systems that most people never think about until they stop working.
For decades these environments were protected largely by isolation. That assumption no longer holds. As OT and IT converge and once-"air-gapped" systems are connected for efficiency and remote management, the attack surface has widened dramatically — and the consequences of compromise have moved from the digital to the tangible. A successful OT attack doesn't leak data; it can stop production, cut power, or endanger lives. That is precisely why critical infrastructure has become such an attractive target in hybrid campaigns: it sits at the intersection of strategic impact and public visibility, and it is exactly the kind of pressure point a grey-zone adversary looks for.

It would be easy to treat all of this as a specialist concern for governments and militaries. It isn't. The reason hybrid threats, FIMI, and infrastructure attacks are so effective is precisely that they exploit the things open societies value most — free expression, a free press, open markets, and reliable public services. The strengths of democracy are, from an adversary's perspective, vulnerabilities to be leveraged.
That is why the defence of these freedoms cannot be delegated entirely to the state. It depends on a broad coalition: governments setting the strategy, militaries and intelligence services holding the line, and the private sector — the companies that build, secure, and operate the digital and physical fabric of everyday life — playing an active role rather than a passive one. Protecting critical systems, hardening the information environment, and building genuine resilience are, in the end, part of the same project as protecting the values those systems exist to serve.
That is the work Intercept believes in, and it is why weeks like this one matter.
Our sincere thanks to the George C. Marshall European Center for Security Studies for convening such a thoughtful and candid discussion, and to every participant who shared their expertise and challenged the thinking in the room. The threats are evolving quickly — but so is the community determined to meet them.
Intercept is a Dublin-based managed security services provider working across cybersecurity, fintech, and aerospace. To talk to our team about hybrid threat resilience, OT security, threat intelligence, or security architecture, get in touch.