Normal view

Europe has the defense budget. The test now is delivery.

At this month’s NATO summit in Ankara, allies announced billions of dollars in new arms deals and reaffirmed their commitment to spend more on defense. European governments have made the pledge, and the money is real: European defense spending has doubled since 2019, and by 2030, European NATO member countries are projected to spend in excess of €800 billion a year, up €300 billion from 2025, with equipment spending alone nearly doubling.

But committing money is the easy part. The harder question is whether Europe’s defense industry can turn it into equipment fast enough to matter. Europe’s largest defense manufacturers’ order books now average more than five years for production, and some are closer to nine. Money is flowing in faster than industry can turn it into equipment. But a purchase order is not equipment that can be deployed on the ground and the air.

European countries have long duplicated capabilities rather than pooling them.

The bottleneck sits in the defense industrial system. Deterrence relies on the chain from funding to contracts, then through production, deployment into services, then rapid innovation in the field. Europe’s next goal comes after the spending promise. The continent fields six times as many weapons platforms as the United States, because countries have long duplicated capabilities rather than pooling them. Production ends up split across many small runs that never reach an efficient scale. Ukraine, under pressure, has shown how fast a defense system can move, adapting tactics in weeks and building drone detection networks from consumer electronics. Europe needs to catch up and then accelerate.

Four moves would help Europe accelerate.

The first is multi-speed procurement. Software-led systems such as drones and targeting improve in rapid cycles throughout their deployment and need procurement that can keep up. Israel’s Iron Dome started out as far less capable than it is today and improved continuously in service. European defense ministries have already set up high-speed procurement units with dedicated teams and greater risk tolerance. These need to become mainstream, rather than the exception.

Collaboration in procurement, maintenance and training brings costs down and delivery forward.

The second is military collaboration to reduce fragmentation. Collaboration in procurement, maintenance and training brings costs down and delivery forward. The Tempest project, where the U.K., Italy and Japan are jointly building a next-generation fighter, demonstrates the model: shared development costs that no single country could carry alone. Recent bilateral maritime agreements, and Romania’s use of EU funding to buy European while expanding production at home, show the same logic spreading.

The third is industrial consolidation, which is already underway and needs to move faster. Companies are driving it themselves. Airbus, Leonardo and Thales have agreed to merge their space divisions into a single joint venture with roughly €6.5 billion in revenue and 25,000 employees, and European defense mergers and acquisitions rose 35 percent year over year in the first half of 2025. McKinsey analysis finds that consolidation across key supply chain segments could unlock around €9 billion in annual synergies, more than the current equipment budgets of 24 of Europe’s 30 NATO members. The deepest opportunity sits below the big primes, among the thousands of tier two, three and four suppliers that still duplicate one another’s work. Europe can speed this up by harmonizing requirements, reducing national carve-outs and letting industry do the combining. Consolidation is only half the task. Europe also needs to build sheer capacity — more shipyards, more assembly lines, more of the physical plants that turn orders into hardware — and the capital to fund it. In several categories, Europe simply lacks enough places to build.

Real deterrence means difficult choices, and a public that understands the importance and the cost of security.

The fourth is regulatory unlocking. Full scale-up demands skilled workers retrained, accredited and security cleared from other industries; production sites with preapproved permitting; and alignment of export controls across European allies. These regulatory unlocks now need the same energy and focus as the funding commitment debate. 

Real deterrence means difficult choices, and a public that understands the importance and the cost of security. That conversation is only beginning in much of Europe. It must include the potential for “gray zone” cyber strikes on hospitals, arson at industrial sites, drones disrupting ports, undersea data cables cut — these have all occurred, but many citizens do not yet recognize this as having malicious intent.

The opportunity in getting it right is significant. McKinsey and GLOBSEC estimates indicate that every euro of spending on European-manufactured equipment generates two euros of revenue across the European supply chain, and an additional €165 billion a year in equipment spending could create up to 1.2 million jobs. The coming years will reveal how effectively Europe is able to scale up to protect its territory and citizens, and how much of the promised investment becomes lasting deterrence and European jobs. Getting there depends on the whole ecosystem — governments, industry and investors — moving together. Increased spending is important. Spending it effectively matters more.

Jonathan Dimson is a senior partner in McKinsey’s London office. Mikael Robertson is a senior partner in the Stockholm office.

Anthropic and OpenAI models tried to trick humans into poisoning code during safety testing

5 August 2026 at 05:25

Leading artificial intelligence models from Anthropic and OpenAI created fake online personas and tried to deceive human coders into abetting a cyberattack during a recent safety evaluation, the U.K.’s AI Safety and Security Institute disclosed Tuesday.

It marks the latest case in which a powerful AI system has attempted a digital attack on an unwitting third party without direct prompting during such an evaluation — heightening concerns the powerful technology is advancing too fast for responsible oversight.

The disclosure is likely to ignite fresh calls in Washington and Silicon Valley for more rigorous regulation of the AI industry, particularly over frontier models with advanced capabilities to detect and launch cyberattacks. It comes just days after similar testing mishaps involving some of the same models from OpenAI and Anthropic sparked urgent calls for new AI safety regulation and a push within Silicon Valley to slow the rapid pace of AI development.

Like its U.S. counterpart, AISI routinely conducts security evaluations to better understand what dangers both new and soon-to-be-released AI models pose to public health and safety. But even the digital security body said the actions it uncovered by Anthropic’s Claude Mythos 5 and ChatGPT 5.6 — the latest publicly released model from either AI lab — were unlike anything it had seen before.

“This is the first time AISI has seen deception of this severity that was targeted at a real person, unprompted, in the real world,” AISI said in a 35-page technical report accompanying a blog post Tuesday.

AISI said the malicious activity began on July 25. The AI safety evaluator detected it and launched an investigation on July 28, when it spotted “unusual data transfers” stemming from a cyber evaluation it was conducting on Mythos 5 and ChatGPT 5.6.

Overall, AISI determined that Mythos 5 and ChatGPT 5.6 took “autonomous, unsanctioned action on the live internet, targeting real people and organizations” during 10 of the 122 evaluations the research body conducted and isolated for review. The majority of those actions, it said, involved Mythos 5 and arose during a “single, sustained line of activity.”

In the most alarming incident it uncovered, Mythos 5 attempted a supply chain attack — a sophisticated technique often deployed by North Korean and Russian cyber operatives, in which hackers bury malware inside legitimate code.

To do so, Anthropic’s model created “multiple fake identities” on developer platform GitHub and used them to send messages “pressuring” an open-source software engineer to unwittingly introduce a bugged update into code widely available on the popular site, AISI said. When that effort failed, the AI “edited its earlier activity to appear harmless” and “considered adopting a fresh identity to continue,” AISI added, a sign the model was intent on repeating the ruse.

As part of the same effort, Mythos 5 also sent direct messages over GitHub to software engineers that contained malware.

In another sign of deceitful behavior AISI uncovered in its investigation, multiple AI agents it was testing appeared to communicate with one another about how to convince real engineers using GitHub to trust them. “One agent left public messages on GitHub offering collaboration with other agents working on the same challenge,” AISI wrote.

AISI’s blog and technical assessment make no mention of whether the models also attempted to exploit previously unknown software bugs — called zero-days — during the evaluation.

Last month, OpenAI disclosed that GPT 5.6 and another of its models escaped onto the open internet during what was supposed to be a controlled test, and then hacked another company in a first-of-its-kind, autonomous breach.

In response, Anthropic launched an investigation into whether any of its models took illicit action during recent testing and discovered Mythos 5 and two other models had hacked three organizations during tests dating back to April.

In a statement, an Anthropic spokesperson said they are “grateful” to AISI for their leadership and that this review underscores the need for “a broader conversation about how to safely evaluate increasingly capable AI agents.”

The spokesperson added: “As we shared after disclosing our own incident last week, the field needs stronger, shared standards for how evaluation environments are built and secured. We look forward to partnering with the UK AISI to learn more about this incident as we conduct our own investigation.”

An OpenAI spokesperson referred POLITICO to a blog post about the incident that went up Tuesday evening. “We are committed to working across the industry to strengthen shared practices for conducting high-risk evaluations safely, including convening stakeholders such as national AI institutes, independent evaluators, other AI labs, and other groups in the coming weeks,” the blog read.

AISI stressed in its blog that the malicious activity it disclosed Tuesday took place under “deliberately permissive conditions” so they could assess the safety risks posed by the two models. This included granting the models access to the internet, unlike the earlier incidents detailed by Anthropic and OpenAI.

AISI also noted the models were intentionally stripped of internal guardrails that block malicious behavior. AISI was only able to disable those controls because of its role testing Mythos 5 and ChatGPT 5.6.

Still, AISI said the incidents highlighted the need for greater monitoring of model behavior during testing, and tighter controls over their access to the internet.

The Trump administration is finalizing a voluntary framework under which AI labs would submit powerful models they want to release to the public for federal safety testing. But it has not yet made the framework public, and it includes no provisions for models AI labs are developing internally.

The incidents last month from OpenAI and Anthropic both involved models not intended for public release.

Some cyber experts say recent incidents highlight deeper questions around AI development, such as who is liable when AI systems break federal hacking laws.

“If any of these were human-originated, they would lead to clear and vigorous prosecution. I think it’s time for a serious discussion about updates to existing computer security law,” said Marc Rogers, a hacker and prominent cybersecurity expert.

France bolsters checks on ‘sensitive’ foreign investments

3 August 2026 at 12:37

PARIS — The French government will need to green light attempts by non-European investors to acquire more than 10 percent of shares in French companies “operating in a sensitive sector” and listed on a stock market outside the EU, Prime Minister Sébastien Lecornu said.

“Against a backdrop of heightened geopolitical tensions, we are strengthening oversight of foreign investments in sensitive sectors,” the French leader wrote on X on Sunday. “Our responsibility is twofold: to support the growth of French businesses while safeguarding our strategic interests.”

The threshold will apply to government-designated sectors including defense, critical infrastructure and key technologies.

Earlier this year, Lecornu asked three parliamentarians from his center-right coalition to report on France’s economic security. Obtained by POLITICO, the document called for a “radical change in posture” and urged the government to take “a holistic approach” to protecting strategic assets, securing critical supply chains, reducing dependencies and strengthening technological sovereignty.

In a press release on the threshold change, Lecornu’s office said the government would give its response on any proposed foreign investments within 10 days of notification to “avoid placing an undue burden on companies’ ability to raise capital in financial markets.”

The move is intended to “guard against opportunistic acquisitions by non-EU investors in French companies listed outside the EU that could pose risks to national security,” the statement noted.

France had previously set up a screening process for planned acquisitions of over 10 percent of shares in French companies listed on European markets during Covid-19, with the stated aim of “protecting strategic companies” in a time of crisis. The measure was later made permanent and is now being extended to French companies listed outside the EU.

The new rules will come into effect in the coming days.

Other EU countries, such as Germany and Spain, have similar foreign investment screening regimes that apply a 10 percent threshold to acquisitions in certain strategic sectors.

Paul de Villepin contributed to this report.

Europe’s ETS revision is an opportunity to strengthen maritime competitiveness

For Europe’s maritime sector—and beyond—the European Commission’s proposal to revise the EU Emissions Trading System (ETS) goes in the right direction and reflects much of what Cruise Lines International Association (CLIA) has consistently called for: a framework in which carbon pricing supports, rather than holds back, the maritime transition, strengthens Europe’s industrial competitiveness and preserves connectivity, including for outermost regions. The starting point is an encouraging one.

Nikos Mertzanidis, executive director, Europe, Cruise Lines International Association (CLIA)

The proposal matters because it is about far more than carbon pricing. Not that the sector shies away from that: cruise lines already comply with the ETS, in addition to port dues, passenger charges, tonnage-based taxes and value-added tax (VAT). Unlike traditional taxation, the ETS is designed to drive decarbonization. Its revision matters because, by reinvesting a greater share of maritime ETS revenues in infrastructure—ports, shore-side electricity, alternative fuels, bunkering and other facilities—Europe can help the maritime industry maintain its global leadership while accelerating the energy transition. That leadership is not a matter of prestige. It is a matter of European prosperity, jobs, skills, competitiveness and industrial capacity across the continent.

The cruise industry alone generates an annual economic impact of €64.1 billion in Europe and supports 445,000 jobs. It is also one of Europe’s industrial success stories, combining world-leading shipbuilding, advanced engineering and maritime innovation with high-value tourism. Behind those figures lies a shipbuilding story that few industries can match: 98 percent of the global cruise orderbook is built in European shipyards, from Fincantieri in Italy to Chantiers de l’Atlantique in France and the Meyer yards in Germany and Finland. There is €62.2 billion committed to ships on order through 2037. This investment sustains a vast ecosystem of engineering firms, technology providers and thousands of suppliers, keeping in Europe the skills and industrial capacity that other regions of the world are actively trying to attract.

By reinvesting a greater share of maritime ETS revenues in infrastructure—ports, shore-side electricity, alternative fuels, bunkering and other facilities—Europe can help the maritime industry maintain its global leadership while accelerating the energy transition.

That is why it is important to be clear about cruise’s role in Europe. Cruise is a key part of the maritime industry: we build ships, move people between ports and across seas, and help drive innovation and investment through one of the most advanced supply chains in Europe. Cruise should therefore be understood first and foremost as part of Europe’s maritime industrial ecosystem, combining maritime transport, advanced manufacturing and tourism in a way few sectors do. It is governed by an extensive regulatory framework alongside the rest of international shipping while supporting one of Europe’s most innovative maritime value chains.

Via Shutterstock

Cruise represents just a small fraction of the global fleet—less than one percent of commercial vessels—but it is consistently at the forefront of maritime’s transformation in ways that benefit the broader maritime sector. Decarbonization is our north star, and our experience shows that it advances fastest when it travels hand in hand with innovation. Done well, decarbonization is not only an environmental objective but also a driver of industrial modernization and European competitiveness. This is why cruise matters to Europe’s maritime future: the industry is helping to turn decarbonization ambition into industrial progress—investing more than €44 billion since 2022 in new ships designed to meet or exceed Europe’s environmental regulations to improve performance and advance the maritime transition.

The cruise industry alone generates an annual economic impact of €64.1 billion in Europe and supports 445,000 jobs. It is also one of Europe’s industrial success stories, combining world-leading shipbuilding, advanced engineering and maritime innovation with high-value tourism.

More than half of the capacity on order today is capable of using liquefied natural gas (LNG), which can reduce CO2 emissions by up to 20 percent compared with conventional fuels. And while LNG is not the end-game solution, it does serve as an important bridge to lower-emissions fuels like renewable and synthetic methane as these types of fuels become available at scale. Today, 57 percent of cruise ships on order are designed with multi-fuel capability, meaning their engines will be able to run on low and zero greenhouse gas fuels, when available at scale. In addition, more than 60 percent of the global cruise fleet can already connect to shore-side electricity where ports are equipped, allowing ships to switch engines off at berth and reduce emissions by up to 98 percent. By 2028, close to 75 percent of capacity will be shore-power-ready.

The environmental transition is broader than carbon reduction alone. Across the global fleet, 225 ships—80 percent of the fleet and 84 percent of passenger capacity—are outfitted with advanced wastewater treatment systems, with more than a third capable of meeting stricter Baltic Sea Special Area discharge standards. More than 94 percent of the reporting fleet produces freshwater onboard, and approximately 60 percent can meet their full onboard consumption needs. Together, the cruise sector’s advancements in environmental technologies and practices help reduce emissions, support responsible operations and lessen pressure on local infrastructure in the destinations cruise ships visit.

Europe leads the world in cruise shipbuilding, maritime innovation and the deployment of technologies that can help decarbonize shipping.

Via CLIA

None of this happens in isolation from the places we serve. Cruise itineraries are planned up to three years in advance, which makes cruise one of the most predictable forms of tourism and allows ports, destinations and operators to manage visitor flows together. The economic footprint is tangible and local: when a ship provisions in port, a single day’s order of fresh produce alone can be worth some €150,000 to local suppliers, before counting fuel, services, excursions and the wider activity a call generates. And because cruise ships connect islands, outermost regions and remote coastal communities—often where alternative transport links are limited—cruise can extend the tourism season and spread benefits well beyond the traditional hotspots.

The road ahead, through the European Parliament, Council and trilogues, will be long, and we will walk it constructively together with our members and institutions at every stage. But the compass is set. Europe leads the world in cruise shipbuilding, maritime innovation and the deployment of technologies that can help decarbonize shipping. By preserving that leadership and reinvesting the sector’s ETS contribution into maritime infrastructure, fuels and facilities, the ETS will not merely price emissions—it will help build the ports, fuels and ships of the future, preserving the competitiveness and global leadership of Europe’s maritime industry for decades to come.


Disclaimer

POLITICAL ADVERTISEMENT

  • The sponsor is Cruise Lines International Association (CLIA)
  • The political advertisement is linked to advocacy on The EU Emissions Trading System (ETS).

More information here.

❌