Where Does Article 5 Begin? | Russia, NATO and the Hardening Grey Zone

A NATO Eurofighter operates over Lithuania as part of Baltic Air Policing. As drone incursions, sabotage, electronic interference and threats to critical infrastructure increase, NATO’s grey zone is becoming progressively more militarised.

SAGE Strategic Intelligence Brief #009

Where Does Article 5 Begin? | Russia, NATO and the Hardening Grey Zone

21 September 2026

SAGE International Australia

Author: Dr John Bruni


Suggested Citation

Bruni, John. “Where Does Article 5 Begin? Russia, NATO and the Hardening Grey Zone.” Strategic Intelligence Brief No. 009. SAGE International, September 2026, Adelaide, South Australia


Executive Summary

Article 5 of the North Atlantic Treaty is deliberately powerful but not mechanically automatic.

It states that an armed attack against one NATO member shall be regarded as an attack against all. NATO also makes clear that what constitutes an “armed attack” must be determined case by case, and that significant cyber or hybrid attacks may qualify.

That flexibility is necessary.

It also creates exploitable space.

An adversary seeking to weaken NATO does not need to begin with tanks crossing an Allied border. It can operate through actions that individually remain limited, deniable, ambiguous or reversible:

  • cyber intrusion;
  • GPS interference;
  • sabotage;
  • infrastructure reconnaissance;
  • incendiary attacks;
  • political interference;
  • airspace incursions;
  • maritime harassment;
  • uncrewed systems;
  • and covert operations against critical infrastructure.

The challenge emerges cumulatively.

Every individual incident can remain below the political threshold required for collective military retaliation. But collectively, repeated incidents can alter behaviour, impose costs, stretch security resources, normalise insecurity and test how much risk Allied governments are prepared to absorb.

This is Threshold Conditioning: the repeated use of actions individually insufficient to provoke major escalation, but cumulatively capable of changing the strategic environment.

Recent developments suggest the European grey zone is becoming harder. NATO aircraft have now destroyed an armed drone over Allied territory. Russian and NATO military aircraft and warships are operating in increasingly close proximity. Western forces are actively confronting Russian undersea operations near critical communications infrastructure.

European governments are constructing dedicated mechanisms to counter sabotage and drone threats.

And intelligence officials are publicly warning that Moscow may seek more consequential means of testing NATO cohesion. Those warnings remain assessments rather than proof of a specific imminent Russian plan, and Baltic officials themselves have cautioned against overstating the immediacy of the threat.

The danger therefore lies less in a deliberate Russian decision to launch general war than in the possibility that persistent grey-zone pressure generates a military incident whose escalation cannot easily be controlled.

Key Judgement

NATO’s confrontation with Russia is increasingly moving from deniable cyber operations, sabotage and electronic interference toward incidents involving armed systems, military interception and direct protection of critical infrastructure.

The significance is not that Russia is necessarily preparing an imminent conventional attack on NATO territory. Current evidence does not establish that. Rather, the Alliance faces an expanding spectrum of activity in which the distinction between peacetime competition and armed confrontation is becoming progressively harder to maintain.

In September, Italian Eurofighters operating under NATO’s Baltic air-defence mission shot down an explosive-carrying drone after it entered Lithuanian airspace from Belarus. Initial reporting suggested a Russian-origin Geran-type attack drone; subsequent Lithuanian assessment identified it as a Russian-used Gerbera and judged it most likely to have been intended for Ukraine rather than Lithuania. The incident nevertheless required NATO aircraft to use force over Allied territory against an armed unmanned system.

Days earlier, Reuters revealed that British, Norwegian and U.S. forces had disrupted a covert Russian undersea operation near Svalbard in which vessels belonging to Russia’s Main Directorate of Deep-Sea Research, GUGI, were reportedly practising the deployment of technology designed to disable subsea communications cables. No infrastructure was damaged, and Moscow denies conducting sabotage operations against NATO states.

These events sit within a broader pattern recognised by NATO itself. The Alliance now publicly describes Russia as conducting aggressive hybrid activity involving sabotage, violence, border provocations, malicious cyber operations, electronic interference and attacks against critical infrastructure. NATO also explicitly states that sufficiently serious hybrid attacks can, on a case-by-case basis, amount to an armed attack under Article 5.

The emerging strategic problem is therefore not simply whether Russia will invade NATO territory.

It is:

How much coercive activity can accumulate below the threshold of an obvious armed attack before NATO must impose meaningful costs?

This is the space in which Threshold Conditioning becomes strategically useful.

From Hybrid Pressure to Physical Interception

The Lithuania incident represents an important transition.

On the night of 14–15 September, a drone entered Lithuanian airspace from Belarus. Italian Air Force Eurofighters assigned to NATO’s Baltic air-defence mission intercepted and destroyed it near Pratkunai. Lithuanian authorities subsequently located the wreckage and neutralised an explosive device carried aboard.

Early reports described the aircraft as resembling a Geran-2 attack drone.

Lithuania’s president later said it was a Gerbera, a cheaper Russian-used uncrewed aircraft often employed as a decoy but also capable of carrying explosives. He said it was probably intended for Ukraine and may have deviated because of electronic warfare. Lithuania’s investigation remains open.

That distinction matters.

There is currently insufficient evidence to describe the incident confidently as a deliberate Russian attack on Lithuania. But strategically, intent is only part of the problem. An armed uncrewed aircraft entered NATO airspace. Alliance aircraft engaged it. Explosives were recovered from the wreckage.

The Ukraine war therefore produced an armed military interaction over NATO territory regardless of whether Moscow intended the drone to reach Lithuania. This demonstrates how increasingly dense military activity along NATO’s eastern frontier can create escalation pathways that do not require deliberate decisions by either side.

War can spill across thresholds accidentally.

The Baltic Is Becoming an Armed Contact Zone

The Lithuania interception was not isolated.

Around the same period, Denmark accused a Russian warship of firing flares near a Danish military helicopter operating over the Baltic. Russia disputed Denmark’s interpretation and in turn accused Danish helicopters of unsafe manoeuvres around Russian vessels.

The specific responsibility for such encounters is contested. The broader pattern is not. NATO and Russian military assets increasingly operate in close proximity across the Baltic and High North.

  • Aircraft intercept aircraft.
  • Warships monitor warships.
  • Electronic warfare distorts navigation.
  • Drones cross national boundaries.
  • Undersea vessels move around critical infrastructure.

This environment is fundamentally different from conventional peacetime military competition. It creates repeated opportunities for technical malfunction, misidentification, aggressive signalling or human error to generate an incident whose political meaning must then be determined under intense pressure.

The danger is therefore partly mechanical.

The more often armed systems interact, the more likely one interaction is to go wrong.

The Undersea Front

The Svalbard episode demonstrates the same strategic contest below the surface.

Reuters reported that earlier this year Britain, Norway and the United States detected and confronted Russian vessels associated with GUGI, Russia’s secretive deep-sea warfare directorate, near Svalbard.

Western officials said Russian submersibles were rehearsing technology designed to disable subsea cables, making attribution difficult. NATO allies tracked and confronted the vessels, preventing the exercise from being completed. No cables were damaged. Russia has consistently denied preparing or conducting sabotage against NATO infrastructure.

The location was strategically significant.

Two fibre-optic cables connect Svalbard with mainland Norway and carry large quantities of satellite data from SvalSat, an important satellite ground station.

Modern economies and militaries rely upon subsea infrastructure for:

  • communications;
  • financial transactions;
  • energy transmission;
  • internet connectivity;
  • military data;
  • and satellite ground links.

These cables are therefore civilian infrastructure with direct strategic value.

This makes them particularly attractive in grey-zone competition.

An adversary may impose significant disruption while retaining ambiguity over whether an incident was accidental, commercially caused, or deliberate.

That ambiguity complicates retaliation.

The Article 5 Problem

Article 5 remains one of the strongest deterrent commitments in international politics. But it was written for a strategic environment in which an armed attack was easier to imagine. NATO itself now acknowledges that the distinction has blurred.

The Alliance states that cyber and other hybrid operations can amount to an armed attack and may therefore trigger Article 5. NATO deliberately leaves the determination to political judgement on a case-by-case basis.

That avoids creating an exploitable numerical threshold.

But it creates another vulnerability.

An adversary can repeatedly ask:

How far is too far?

Cut one cable?

Jam one airport?

Fly one drone across a border?

Set fire to one warehouse?

Attack one railway junction?

Compromise one government network?

Individually, such actions may not warrant collective military action. The strategic danger appears when these incidents stop being exceptional and become part of normal European security conditions. That is where deterrence can erode without visibly collapsing.

Threshold Conditioning

Threshold Conditioning provides a useful framework for understanding this process. The objective need not be to cross the opponent’s red line. It may instead be to alter what the opponent considers normal. An action initially viewed as unacceptable occurs. The defender protests but limits its response.

The action happens again.

Then another form of coercion follows.

Over time, behaviour once considered extraordinary becomes part of the background operating environment.

The threshold has effectively moved. In the NATO context, this can work through accumulation:

  • airspace violations become expected;
  • GPS interference becomes routine;
  • suspicious infrastructure incidents become common;
  • military aircraft scramble repeatedly;
  • critical infrastructure requires permanent guarding;
  • governments absorb growing security costs.

No single episode transforms the strategic balance. The cumulative pattern does. This is why grey-zone activity should not be judged only incident by incident. The relevant unit of analysis is the campaign.

Russia’s Strategic Logic

Russia has strong incentives to operate in this space. A conventional military attack on NATO would carry extraordinary risks. It could activate collective defence against an Alliance possessing overwhelming aggregate economic and military power.

Hybrid coercion presents a different proposition.

It can:

  • impose costs;
  • test national responses;
  • gather intelligence;
  • disrupt support for Ukraine;
  • force NATO governments to divert security resources;
  • create political divisions;
  • and demonstrate vulnerability.

The important qualification is that not every suspicious incident in Europe can automatically be attributed to Russia. Hybrid-threat analysis is particularly vulnerable to attribution errors because the phenomenon is inherently ambiguous.

Credible deterrence therefore requires accurate attribution rather than treating every infrastructure failure, drone sighting or cyber incident as evidence of a centrally directed Russian campaign.

Overreaction can itself serve an adversary’s objectives.

NATO Is Already Adapting

The Alliance is not ignoring the problem.

NATO says Russia is conducting an aggressive hybrid campaign involving sabotage, violence, cyber activity, electronic interference and provocations along Allied borders.

Baltic Sea states are creating a joint drone-defence task force intended to accelerate information sharing and responses to uncrewed threats.

Finland is practising rapid boarding operations against vessels suspected of threatening subsea infrastructure and describes repeated damage to undersea systems as part of a new security normal.

At the EU level, Ursula von der Leyen has proposed a dedicated counter-hybrid playbook to coordinate responses to sabotage, cyber operations and drone incidents that fall below conventional military attack.

NATO’s newly updated resilience requirements similarly identify physical attack, sabotage, cyberattack, strategic dependencies and infrastructure restoration as central Alliance concerns.

The direction of travel is clear.

Civil security, infrastructure defence and conventional military deterrence are merging.

The Deterrence Dilemma

The fundamental policy problem remains unresolved.

If NATO responds forcefully to every ambiguous incident, it risks escalation based on uncertain attribution or accidental events.

If it responds too weakly, it risks teaching Moscow that activities below open armed attack carry little meaningful cost.

Effective deterrence therefore requires something more sophisticated than simply threatening Article 5.

It requires graduated consequences below Article 5.

These might include:

  • diplomatic measures;
  • sanctions;
  • intelligence exposure;
  • cyber responses;
  • law-enforcement action;
  • interception;
  • infrastructure protection;
  • maritime exclusion measures where lawful;
  • and visible military reinforcement.

The objective should be to deny an adversary a strategic sanctuary between “nothing happens” and “NATO goes to war”.

That middle space is currently where much of the competition is occurring.

The Risk of Miscalculation

The most dangerous scenario may not be a carefully planned Russian attack on NATO.

It may be an unintended sequence.

Imagine:

  • a Russian drone enters NATO airspace;
  • NATO fighters intercept;
  • the drone manoeuvres unexpectedly;
  • weapons are fired;
  • Russian personnel elsewhere respond;
  • another NATO state reinforces;
  • electronic warfare increases;
  • communications fail;
  • leaders have minutes to determine whether events are accidental or intentional.

At each stage, rational actors can take individually defensible actions. Collectively, they may produce escalation. The denser the grey zone becomes with armed platforms, the less forgiving that environment becomes.

This is the significance of the Lithuania incident.

An ambiguous violation required an unambiguous military response. The drone was destroyed.

The strategic question remained unanswered.

Implications for NATO

Five conclusions follow.

First, NATO should distinguish between the legal threshold for Article 5 and the practical threshold for imposing costs. Waiting until every hybrid campaign becomes an armed attack gives an adversary too much room to operate.

Second, attribution capabilities are themselves deterrent capabilities. Intelligence fusion, forensic investigation and rapid public disclosure make deniable operations harder to sustain.

Third, critical infrastructure must increasingly be treated as defence infrastructure. Cables, ports, logistics hubs, telecommunications systems and power networks sustain NATO military power.

Fourth, cheap drones require cheap and scalable defensive responses. Repeatedly using high-cost fighter aircraft and missiles against low-cost uncrewed systems produces an unfavourable economic exchange.

Fifth, escalation-management doctrine must treat accidents as seriously as deliberate aggression. NATO must be capable of responding firmly without automatically interpreting every armed incident as evidence of an intentional Russian attack.

Implications for Australia

This may appear primarily European.

It is not.

The broader lesson is directly relevant to Australia. A future Indo-Pacific adversary would have little reason to confine competition to conventional military targets.

Australia’s vulnerabilities include:

  • subsea communications cables;
  • ports;
  • fuel infrastructure;
  • satellite ground stations;
  • power networks;
  • logistics facilities;
  • cyber systems;
  • and northern defence installations.

Many could be pressured below the threshold of conventional armed attack.

Australia therefore needs a national deterrence concept that can operate across the space between routine law enforcement and full military conflict.

That means stronger coordination between Defence, intelligence agencies, police, cyber authorities, infrastructure operators and the private sector.

The European experience demonstrates that national resilience is not separate from deterrence.

It is increasingly one of its foundations.

Assessment

NATO is not currently facing clear evidence of an imminent Russian conventional invasion. Nor does the Lithuania drone incident establish a deliberate Russian attack on Allied territory. The more consequential development is structural. Europe is moving into a security environment in which hybrid coercion increasingly involves physical systems capable of causing casualties and infrastructure damage. The grey zone is becoming armed.

That raises the consequences of ambiguity. A cyber intrusion can often be investigated over days or weeks. A drone crossing a border carrying explosives may require a decision in minutes. A submarine operating beside a critical cable may need to be confronted before its purpose is known.

These situations compress decision-making while leaving intent uncertain.

That combination creates escalation risk.

SAGE Bottom Line

Article 5 may never be tested first by Russian tanks crossing NATO’s eastern frontier. Its credibility may instead be challenged through hundreds of smaller interactions occurring beneath the level traditionally associated with war.

  • A drone.
  • A cable.
  • A warehouse.
  • A navigation signal.
  • A border incident.
  • A cyberattack.

Each appears manageable.

Each remains below the threshold.

Until one does not.

The strategic challenge for NATO is therefore not simply to demonstrate that it will fight if Russia launches an armed attack.

It is to prevent persistent coercion below that level from gradually redefining what Europe is expected to tolerate.

Because deterrence can weaken without ever formally failing.

And Article 5 could be eroded long before anyone invokes it.

ENGAGE WITH STRATEGIC EXPERTISE

SAGE International Australia provides independent geopolitical, defence and strategic analysis to help organisations understand risk, identify opportunity and make better decisions in a rapidly changing world.

Engage

Get email updates from Sage

Subscribe