A Protocol Without a Trigger: What the EU Discussed on 28 September, and What It Did Not Decide
Baltic Security Monitor | Analytical Brief Security Watch: 28 September 2026, 20:00 (Europe/Tallinn)
The cycle at a glance
No composite OSINT indices were supplied for this run, so none are reconstructed here. The day's thesis: "no material update" is not the same as "no news." Ministers' first discussion of an Emergency Security Protocol is a marker for the coming months. The EU is asking aloud what its own response tool below the Article 5 threshold should look like. There is no answer yet, and the gap between question and answer is today's signal.
1. Emergency Security Protocol: a discussion, not a decision
EU defence ministers, meeting as the Foreign Affairs Council (Defence), held their first discussion of the proposed protocol for responding to hybrid attacks. Kaja Kallas said this was the first time the topic had been taken up, that not everyone spoke, and that she could not say whether a majority was for or against. Many states first want to understand what the mechanism would actually involve (Mezha/Ukrinform). Talks will continue at several levels, including ambassadors.
The idea is to fill the gap between routine consultation and collective defence. NATO's Article 4 provides for consultation, not an action plan. The EU protocol would cover tools member states could use against hostile acts that fall short of an armed attack and Article 5. It was floated earlier this month in the State of the Union address, alongside a proposed European Security Council (Epoch Times), and Kallas and Ursula von der Leyen are named as its sponsors (Euronews).
Kallas also stressed that the EU already has response tools, but governments must agree when to use them, and whether to act before an attack if intelligence points to one being planned.
BSM analysis: the operative word is "when." Sanctions, diplomatic measures and cyber tools exist. What is missing is a shared criterion that turns an "incident" into grounds for response. That is a political question, not a technical one, and it is where friction is likely. Frontline states (Estonia, Latvia, Lithuania, Poland, Finland) have an interest in a low threshold and pre-emptive action, while less exposed capitals will be more cautious. A second fault line is overlap with NATO: ministers were explicit that the mechanism should complement the Alliance, not duplicate its structures. Without a clear division of labour, the protocol risks becoming one more consultation format.
What to check next: an adopted text, a defined activation procedure, EU/NATO role allocation, funding, a first real use.
2. The sabotage warning: an intelligence assessment without detail
Kallas said EU intelligence indicates Russia is preparing further sabotage operations in Europe, aimed at dividing societies and pushing them to abandon support for Ukraine (Euronews, EU Today). No targets, locations or timing were disclosed. For BSM this remains an assessment, not an event: without corroborating detail it does not rise to MATERIAL.
Context matters, though. The warning came on the very day the EU discussed a response tool, and the political link is obvious. It strengthens the case of those pushing the mechanism, and it is also a reminder that intelligence warnings double as instruments of political mobilisation, so they deserve careful weighing.
3. What did not happen: no new Patriot pledges
Kallas urged states with available stocks to send Patriot interceptors to Ukraine. Afterwards she acknowledged that no new pledges were made. The Council agenda also covered Ukraine's air defence, EUMAM Ukraine, industrial cooperation and countering Russia's shadow fleet.
BSM analysis: the negative result is informative. With Russian strikes hitting Ukrainian civilian infrastructure, the gap between rhetoric and deliveries is structural, and it does not close through discussion of hybrid-response protocols.
4. Checked and set aside
- Vodafone Ukraine. Russia's claim of a strike on a Vodafone Ukraine data centre has no independent confirmation. Reuters attributes it specifically to the Russian Defence Ministry, and Vodafone Ukraine had not responded to a request for comment. The wider campaign against Ukrainian data centres, including the confirmed Kyivstar strike, was covered on 27 September. (Detailed analysis: BSM, 27 September.)
- Finland–Sweden QRA. Reports circulating today refer to the 24 September first joint operational identification mission over the Gulf of Finland, already covered by BSM. Official Swedish reporting says the Russian aircraft were in international airspace. Descriptions implying a Finnish airspace violation on that mission lack confirmation and should not be treated as a new incident.
Conclusion
Today is a good illustration of noise versus signal in hybrid security. Noise: an unconfirmed data-centre claim, and readings of a QRA mission that diverge from official data. Signal: the EU is building its own response mechanism below the threshold of armed aggression, and the first round showed that states have not yet agreed on basics, namely what the protocol covers and who decides on activation.
For the Baltic states this is a direct question. Hybrid pressure on their borders and networks is daily reality, so the speed and clarity of any future mechanism matter more than its name. BSM's next check: whether a text, activation criteria and a NATO division of roles appear.
Baltic Security Monitor (osint-baltic.com) — an analytical publication on security on NATO's northeastern flank. All OSINT coefficients are calculated by an automated indexing system based on open sources.