The Space Between Articles 4 and 5: NATO’s Threshold Conditioning Problem
NATO faces a growing challenge in the space between consultation and collective defence: deterring cumulative hostile activity without surrendering escalation control. SIB #010 proposes “Threshold Deterrence” as a collective response to Russia’s Threshold Conditioning.
SAGE Strategic Intelligence Brief #010
The Space Between Articles 4 and 5: NATO’s Threshold Conditioning Problem
28 September 2026
SAGE International Australia
Author: Dr John Bruni
Suggested Citation
Bruni, J. (2026). The Space Between Articles 4 and 5: NATO’s Threshold Conditioning Problem. SAGE Strategic Intelligence Brief No. 010. SAGE International Australia, 28 September 2026, Adelaide, South Australia
Executive Summary
Europe’s security problem is increasingly ill-served by a binary distinction between peace and war.
NATO itself describes Russian activity against Allies as an aggressive hybrid campaign encompassing sabotage of critical infrastructure, violence, border provocations, malicious cyber activity, electronic interference, disinformation, malign political influence and economic coercion. NATO also reports that hostile actions, including airspace violations, cyberattacks and sabotage, are increasing in frequency.
The central problem is therefore not whether every hostile act constitutes war. It is whether an adversary can repeatedly impose costs, test responses and alter the strategic environment while remaining below, around or ambiguously across the political threshold at which NATO agrees on collective action.
SAGE defines this process as Threshold Conditioning: the repeated use of coercive or hostile actions calibrated to alter an adversary’s perception of what constitutes an intolerable act, thereby expanding the aggressor’s freedom of action without triggering the defender’s predetermined escalation mechanism.
For NATO, the vulnerability lies in the space between Article 4 consultation and Article 5 collective defence.
Article 5 is not confined to conventional invasion. NATO states that a sufficiently serious cyber or hybrid attack may amount to an armed attack, and that a single or cumulative set of malicious cyber activities can, case by case, reach that level.
The difficulty is what NATO does collectively before that point.
Key Judgement
Russia is exploiting the politically contested space between NATO recognition of hostile activity and collective action under Article 5.
Repeated cyber operations, sabotage, electronic interference, political influence, border provocations, and other calibrated acts can condition Allied governments to absorb progressively greater hostility without a correspondingly greater collective response.
NATO should counter this through Threshold Deterrence: a standing Alliance mechanism that aggregates attributable hostile actions across members and domains and links their cumulative pattern to graduated collective consequences, while preserving North Atlantic Council political control and escalation flexibility.
Europe Is Neither Simply at Peace nor Conventionally at War
The proposition that Europe is already at war with Russia deserves serious treatment.
Russian hostile activity is not hypothetical. NATO and the European Union publicly describe persistent, coordinated Russian campaigns involving sabotage, cyber operations, critical-infrastructure disruption, information manipulation and political interference.
Yet describing this environment simply as interstate war can obscure an important strategic distinction. Russia and NATO are not engaged in sustained conventional combat against one another, and NATO governments retain powerful incentives to prevent hostile interaction from becoming direct Alliance–Russia war.
The more useful category is persistent adversarial confrontation.
Forms of warfare and coercion can occur without the parties entering the conventional politico-strategic condition normally associated with declared or recognised interstate war. This ambiguity is not incidental.
It creates strategic space that can be exploited.
Escalation Restraint Is Rational — and Exploitable
NATO caution should not be caricatured as weakness.
Russia is a nuclear-armed state. Any decision that transforms a contained incident into acknowledged direct NATO–Russia conflict carries expectations of retaliation, counter-retaliation and potentially nuclear escalation.
Governments therefore have rational reasons to preserve control over escalation.
Threshold Conditioning exploits that rationality.
After each hostile act, Allied governments must weigh attribution, severity, proportionality, Alliance unity and the consequences of escalation. The immediate preference will often be to contain the incident.
Repeated often enough, however, containment can generate precedent: behaviour once treated as exceptional becomes part of the accepted security environment.
The resulting danger is a ratchet effect.
Moscow does not need NATO to believe that Russia is peaceful. It needs individual acts to remain sufficiently bounded, deniable, dispersed or politically costly to answer that the Alliance repeatedly concludes that managing the latest incident is preferable to escalating the confrontation.
The Article 4–Article 5 Gap
Article 4 provides consultation when an Ally believes its territorial integrity, political independence or security is threatened.
Article 5 establishes collective defence following an armed attack.
Between them lies a broad political space in which hostile activity can be recognised without producing an agreed collective deterrent consequence.
NATO is not starting from zero. It already treats hybrid campaigns as patterns rather than wholly isolated events; it has agreed response options that can be taken individually and collectively; and its cyber doctrine explicitly recognises cumulative effects.
The conceptual gap is that this cumulative logic is not yet sufficiently developed into a cross-domain deterrence framework for persistent hostile activity below an Article 5 determination.
The operational problem can be stated simply:
The Alliance counter must not reset to zero after every incident.
Threshold Deterrence: Collective Deterrence by Accumulation
SAGE proposes Threshold Deterrence: a standing NATO policy framework under which attributable hostile actions against individual Allies are assessed not only as discrete incidents but as components of a cumulative campaign against the Alliance.
The purpose is not to create an “Article 5-lite”, an automatic tripwire, or a numerical formula in which a fixed number of incidents mechanically produces military retaliation.
Such a system would be strategically brittle, politically implausible and easily gamed.
Decisions must remain under North Atlantic Council political control and be taken case by case.
Instead, NATO should institutionalise collective assessment of cumulative hostile behaviour across domains.
Relevant indicators could include attribution confidence, frequency, severity, geographic spread, casualties, critical-infrastructure effects, repetition, evidence of central coordination, coercive intent and the relationship between apparently separate operations.
A Graduated Collective-Response Mechanism
1. Alliance aggregation.
A standing mechanism fuses national reporting and intelligence so the Alliance assesses sabotage in one Ally, cyber activity in another, electronic interference elsewhere, and political coercion for campaign-level relationships.
2. Collective attribution and assessment.
Where evidence permits, the Alliance establishes shared attribution confidence and a common assessment of cumulative strategic effect.
3. Threshold assessment.
The North Atlantic Council assesses whether the campaign is changing in frequency, severity, coordination or effect and whether Allied tolerance is itself being tested.
4. Graduated consequences.
NATO selects progressively stronger lawful responses across diplomatic, economic, intelligence, cyber, resilience and military domains. The response need not mirror the domain of the provocation.
5. Preserved ambiguity.
NATO should not publish a mechanical schedule specifying which act produces which response. Moscow should understand that repetition increases collective cost without being given a formula it can optimise against.
6. Article 5 remains distinct.
If the cumulative or individual effects amount to an armed attack, the existing Article 5 process remains available. Threshold Deterrence strengthens the space before that determination rather than replacing it.
Reversing the Learning Process
Threshold Conditioning is fundamentally interactive.
Repeated probes teach the aggressor about the defender’s tolerance, political cohesion and escalation aversion. If each probe produces an isolated, temporary response, the aggressor can learn where additional room for manoeuvre exists.
Threshold Deterrence seeks to reverse that learning process.
Persistent hostile activity should teach Moscow that repetition does not normalise the conduct; it increases the probability, breadth and cost of an Alliance-level response.
If Russia seeks to condition NATO into tolerating progressively greater hostility, NATO must condition Russia to expect progressively greater collective costs from repeated hostile activity.
This creates a complementary deterrent proposition.
Article 5 collectively deters armed attack. Threshold Deterrence would collectively deter cumulative coercive activity designed to avoid, manipulate or progressively redefine the conditions under which Article 5 might be invoked.
Risks and Constraints
Threshold Deterrence cannot eliminate the underlying dilemmas.
Attribution may remain uncertain. Allies will differ in threat perception and risk tolerance. A collective response can itself escalate a crisis. Russia may employ proxies, deliberately ambiguous incidents or other methods intended to fracture Alliance consensus.
An overly rigid framework could also encourage Moscow to operate just beneath published criteria.
These are arguments for political discretion, not strategic passivity.
The mechanism should therefore emphasise common situational awareness, cumulative assessment and credible options rather than automaticity.
The objective is to increase Moscow’s uncertainty about the cost of continued coercion while reducing Allied uncertainty about how persistent hostile activity will be assessed.
SAGE BOTTOM LINE
The debate over whether Europe is already “at war” with Russia is itself revealing.
The strategic problem does not depend on resolving that semantic question.
Russia can conduct forms of warfare, coercion and destabilisation while NATO governments retain rational incentives to avoid direct interstate war. That is precisely the environment in which Threshold Conditioning can operate.
Article 5 remains the cornerstone of collective defence against armed attack.
But deterrence cannot begin only when the Article 5 threshold is reached.
NATO requires a credible collective mechanism for the hostile campaign that precedes, surrounds and seeks to manipulate that threshold.
Threshold Deterrence provides that logic: hostile actions against individual Allies accumulate at Alliance level; repetition raises rather than lowers the expected collective cost; political discretion and escalation control are retained; and Article 5 remains available for circumstances in which an armed attack has occurred.
The counter does not reset to zero.
Sources
NATO — The North Atlantic Treaty, Articles 3–5
https://www.nato.int/docu/basictxt/treaty.htm
NATO — Statement by the North Atlantic Council on Recent Russian Hybrid Activities, 2 May 2024
https://www.nato.int/en/about-us/official-texts-and-resources/official-texts/2024/05/02/statement-by-the-north-atlantic-council-on-recent-russian-hybrid-activities
NATO — Vilnius Summit Communiqué, 11 July 2023
See especially paragraphs 64 and 66 on hybrid and cyber threats and cumulative malicious cyber activity.
NATO — Washington Summit Declaration, 10 July 2024
See paragraph 20 on Russia’s intensifying campaign of hostile actions against Allies.
NATO — Statement concerning Russian malicious cyber activities, 18 July 2025
SAGE International Strategic Intelligence Briefs are analytical products intended to contribute to informed discussion of international security. This brief does not represent the position of NATO, any Allied government or the European Union.
Disclaimer
SAGE Strategic Intelligence Briefs are produced independently and are intended to support informed discussion of geopolitical, defence, security and economic developments. Assessments reflect information available at the time of publication and may change as new information emerges.
About SAGE International Australia
SAGE International Australia is an independent strategic research and analysis organisation specialising in geopolitics, defence, national security, economic resilience and strategic foresight.
Through objective, evidence-based and non-partisan analysis, SAGE helps decision-makers understand risk, identify opportunity and prepare for future challenges.
For more information, visit: