Yesterday this publication examined the claim that Ukraine turned a Russian air-defence unit against its own aircraft by attacking its identification layer — the software seam where sensor data becomes a targeting decision. We held that claim carefully, because it is single-sourced and unverified.

Today’s question doesn’t require it to be true.

It requires only that the concept be plausible — that a sufficiently well-informed adversary, with sufficient access to the software and hardware that an air-defence unit uses to decide friend or foe, could in principle corrupt that decision. And that question, stripped of any claim about Ukraine, has a very uncomfortable answer when applied to NATO at alliance scale.

Because NATO’s identification layer — the sensors, the networks, the radios, the drones, the counter-drone systems, the communications infrastructure that all of it runs over — has been built, for years, on equipment sourced from a country whose law compels its companies to cooperate with its intelligence services on demand.

That country is not a neutral supplier. China’s National Intelligence Law of 2017 is explicit: any Chinese entity — any company, any employee, anywhere — must assist national intelligence work when asked. There is no carve-out for foreign deployments. There is no judicial review. There is no refusal option. When Beijing asks Huawei for access, Huawei must provide it. When it asks DJI to report on who is flying what, DJI must report. The law doesn’t distinguish between Shenzhen and Stuttgart. It doesn’t distinguish between civilian and NATO.

The BARS Moscow story was one unit’s training video. This is thirty-two allies’ defence architecture.

Friendly Fire at Alliance Scale — ISR Briefing
AI Dispatch · ISR Briefing · 25 July 2026

Friendly fire at alliance scale: what Chinese equipment in NATO networks actually means

Yesterday: Ukraine may have turned a Russian unit’s identification layer against its own jet. Today’s question doesn’t require that to be true. It requires only that the concept be plausible — and then asks what it means when NATO’s own identification layer is built on equipment from a country whose law compels its companies to cooperate with intelligence on demand.

◆ China’s National Intelligence Law 2017 — the mechanism everything else rests on

Any Chinese entity — any company, any employee, anywhere — must assist national intelligence work when asked. No carve-out for foreign deployments. No judicial review. No refusal option. When Beijing asks Huawei for access, Huawei must provide it. The law doesn’t distinguish between Shenzhen and Stuttgart. It doesn’t distinguish between civilian and NATO. This is not theoretical. It is operational law.

The three-layer exposure — comms, drones, identification
1
Communications backbone
Belgium’s entire telecom infrastructure — including EU and NATO HQ mobile comms — previously ran on Chinese equipment. In Germany, Huawei runs ~60% of the 5G RAN; the mobile traffic of basically all NATO troops in Germany passes through Huawei-dependent networks (GMF). Eastern flank: Poland, Romania and others still rely heavily on Chinese gear with no near-term removal plan — the same states where a conflict would begin. June 2026: Trump administration pressing allies to use defence funds for replacement. Only ~60 of Europe’s ~100 mobile networks have “clean” status.
2
Drone & sensor supply chain
China controls ~90% of rare-earth processing, ~99% of drone battery cells, ~90% of permanent magnet production. CSIS assessment: F-35, Predator, Tomahawk, and Virginia-class sub propulsion all use Chinese rare-earth magnets. DJI had ~80% of the US commercial drone market. FCC banned new certifications Dec 2025. Yet: the majority of platforms on the Pentagon’s own Blue UAS approved list still contain Chinese-made motors. Oct 2025: China imposed magnet export controls — suspended until Nov 2026, reversible at will.
3
The identification layer — where it converges
Counter-drone systems with machine-vision identification are now standard NATO procurement — the same class as BARS Moscow’s Lys-2. If the sensor is Chinese LiDAR, the processor Chinese silicon, or the firmware has unexposed dependencies on Chinese toolchains, then the identification layer has an attack surface no amount of software security above it can close. You cannot audit a classifier running on hardware with undisclosed capabilities. And if the chip has a remote-management interface — the legal mechanism to use it already exists.
60%
Huawei share of Germany 5G RAN — all NATO troops’ mobile traffic
99%
Chinese battery cell manufacturing for drones
F-35
Predator · Tomahawk · Virginia-class — all use Chinese rare-earth magnets (CSIS)
Nov ’26
Chinese magnet export-control suspension expires — reversible at will
The BARS Moscow parallel — at two different scales
BARS Moscow (claimed)

Required weeks of prior reconnaissance — intercepted training videos, software analysis, decision-boundary mapping. Then manipulation of one unit’s identification decision to treat its own aircraft as a threat.

Chinese equipment in NATO (structural)

Requires no reconnaissance. The companies manufactured and installed the equipment. They have the source code, firmware, manufacturing tolerances, and update pipeline — the reconnaissance was completed before the adversary was even identified as one. A stronger position than what InformNapalm claims Ukraine achieved.

In BARS Moscow terms: the equivalent would be if Ukraine had designed and built BARS Moscow’s Lys-2 from the start. There would be no need to intercept the training videos. The trigger could be pulled whenever needed. That is the position China is already in.
The take

The question isn’t whether China will use this access. It’s whether NATO can afford to assume it won’t. Three things follow. Replacement is genuinely hard — banning without building the supply chain produces capability gaps, not security. The identification layer is where the exposure is sharpest — a Chinese motor is a supply-chain risk; a Chinese sensor or processor in an IFF system is an identification-layer risk, the same class the BARS Moscow story made visible. And the open-weight argument applies here — but stops short: open weights give you visibility into the classification model; they don’t give you visibility into the silicon it runs on. NATO has thirty-two members, each with its own procurement history. Together they’ve built an identification layer with distributed, unaudited, legally-accessible dependencies on a potential adversary. BARS Moscow required weeks of reconnaissance. The reconnaissance for NATO’s version was completed in the factory.

Sources: GMF (Belgium, Germany NATO troop comms, Poland/Romania flank); 3Gimbals, Bloomberg Jun ’26 (Huawei law, replacement push); Light Reading Jun ’26 (60/100 clean networks, NATO 5G plan); Stars & Stripes May ’26, CEPA May & Jul ’26, The Next Web May ’26 (F-35/Predator/Tomahawk CSIS finding, Blue UAS motor penetration, 90%/99% supply figures); Semantic Visions Apr ’26 (magnet controls, Nov ’26 suspension); Al Jazeera Jul ’26 (FCC swarming/IR drone ban); Atlantic Council Apr ’25 (supply-chain review call). BARS Moscow claim (prior ISR Briefing) remains unverified; used here as a conceptual analogue only. Not investment advice.
thorstenmeyerai.comin cooperation with vigilsar.com

Layer one: the communications backbone

Start with the most verified and most consequential fact in this analysis.

Belgium. Until recently, virtually all of Belgium’s telecommunications infrastructure — including the mobile communications used by the European Union institutions and NATO’s own headquarters administration — ran on Chinese equipment. Brussels is both the EU capital and the NATO political headquarters. The communications layer of the western alliance ran on kit built by a company legally obligated to cooperate with the intelligence services of a state that now calls itself a “comprehensive strategic partner” of the country that just lost a jet.

Germany. Huawei accounts for approximately 59–60% of Germany’s 5G radio access network — the base stations, antennas, and switches that carry mobile traffic. The German Marshall Fund’s assessment is unambiguous: mobile traffic of basically all NATO troops based in Germany passes, at some point, through a network reliant on Chinese technology. Germany hosts the largest concentration of NATO forces in Europe — American, British, German, Dutch, Canadian troops, their logistics, their command communications, their personal devices. It routes through Huawei at somewhere between half and two-thirds of its touchpoints.

The doomsday scenario analysts use to explain the risk isn’t invented: a conflict involving Taiwan triggers a need for NATO support; China preemptively orders Huawei to activate sleeper vulnerabilities implanted in basestation software across Germany and other NATO countries; a communications blackout follows. That scenario is explicitly fictional as a specific event. What is not fictional is the legal mechanism that would allow it. The Chinese government can issue the instruction. Huawei would be obligated to comply. The software is already in the networks.

Poland, Romania, and Eastern Europe. These are the states where a conflict would most likely begin — the NATO eastern flank, bordering Belarus, Russia, and Ukraine. Their telecommunications networks still rely heavily on Chinese gear. As of 2022, not one of them had a plan to ensure removal of untrusted vendors in the near term. Rules limiting further rollout accepted legacy Chinese equipment until mid-decade or longer. The alliance is hardening its forward positions while running its communications through infrastructure that is legally accessible to the adversary’s closest partner.

What’s being done. In June 2026, the Trump administration began pressing NATO allies to channel defence spending specifically toward Huawei replacement. Germany has a 2026 deadline for removing Huawei from its 5G networks, though three major operators (Deutsche Telekom, Telefónica Deutschland, Vodafone Germany) have sought a technical fix pairing Huawei radio equipment with alternative management systems — an approach its security critics consider insufficient and its defenders consider workable. Roughly 60 of Europe’s approximately 100 mobile networks now have “clean” status. The other forty do not.

The honest counter. Huawei has consistently denied that it provides backdoor access or would comply with illegal government orders. Removing Huawei from a network that’s 60% built on it is expensive, slow, and genuinely disruptive — Deutsche Bahn estimated costs north of €400 million and delays of five to six years for its slice alone. The three major German operators already run Huawei-free core networks; the debate is about the radio access layer. And China’s National Intelligence Law, while explicit in its obligations, has never been publicly shown to have produced a documented NATO intelligence breach via Huawei equipment. The risk is legal and structural, not demonstrated.

State it that way: not proven to have been exploited; legally positioned to be exploited on demand.

Klykon 2-Wire Earpiece for Yaesu Vertex VX-261 VX-230 VX-351 Radio

Klykon 2-Wire Earpiece for Yaesu Vertex VX-261 VX-230 VX-351 Radio

  • Wide Radio Compatibility: Compatible with various Yaesu models
  • Comfortable Fit: Includes replaceable medium earbuds
  • Durable Build: Kevlar-reinforced PU cable for longevity

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Layer two: the drone and sensor layer

Now move down from the communications network to the platforms making the targeting decisions — the layer that is directly analogous to BARS Moscow’s Lys-2.

The counter-drone systems NATO forces are deploying, and the drones themselves, have a Chinese component dependency that is not marginal. It is structural.

A December 2025 analysis confirmed what battlefield commanders already knew: Chinese inputs dominate five critical layers of the drone production stack — magnets, batteries, semiconductors, carbon fibre, and infrared sensors. In each category, non-Chinese alternatives either do not exist at scale or would take years to develop. The numbers are stark: China controls approximately 90% of global rare-earth processing, 99% of drone battery cell manufacturing, and around 90% of permanent magnet production for the electric motors that drive virtually all modern drones and counter-drone platforms.

The implications go beyond procurement. A separate CSIS assessment found that the F-35, Predator drones, Tomahawk missiles, and Virginia-class submarine propulsion systems all rely on Chinese rare-earth magnets. This is not about commercial convenience. This is about the weapons that NATO considers its most capable platforms depending on a supply chain that Beijing controls — and has already demonstrated its willingness to weaponize. China imposed export controls on permanent magnet materials in October 2025; a suspension was negotiated, running until November 2026. That suspension can be reversed at will.

DJI held approximately 80% of the US commercial drone market before the Federal Communications Commission halted new certifications for its products in late 2025. But the ban created a gap the domestic industry cannot fill at comparable scale or price. More revealingly: the majority of platforms on the Pentagon’s own Blue UAS approved list — the cleared list for government drone use — still contain Chinese-made motors. The United States built its own vetted-drone shortlist, and most of the drones on it run Chinese motors. The ban and the supply chain are pulling in opposite directions.

For NATO allies, the position is worse. The US at least has its Blue List, its NDAA restrictions, its FCC coverage list. Most European NATO members have no equivalent. They are procuring counter-drone systems — the exact class of platform at the centre of the BARS Moscow claim — from supply chains they have not audited at component level, running software they cannot inspect, on motors they source from a country whose export restrictions could cut them off on 30 days’ notice.

Police Drone & Pilot Detection Kit– Handheld Drone Detection & Tracking Tool | Real-Time Alerts for Law Enforcement, Event Security & Emergency Response | Portable Airspace Awareness Device

Police Drone & Pilot Detection Kit– Handheld Drone Detection & Tracking Tool | Real-Time Alerts for Law Enforcement, Event Security & Emergency Response | Portable Airspace Awareness Device

  • Real-Time Drone Detection: Detects drones via remote ID signals instantly
  • Portable & Compact Design: Handheld, lightweight, and easy to carry
  • Immediate Threat Alerts: Provides instant notifications for quick response

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Layer three: the identification layer specifically

Now connect the layers to yesterday’s thesis, because this is where the BARS Moscow story becomes alliance-relevant.

BARS Moscow’s vulnerability, per InformNapalm’s claim, was its machine-vision identification system — the software that decided whether something in its airspace was a Ukrainian drone or a Russian fighter. That software was observable through leaked training footage, analysable for its decision boundaries, and — if the claim holds — manipulable by an adversary who understood its parameters.

Counter-drone systems with machine-vision identification are now standard procurement across NATO. The Lys-2 is the Russian version; its analogues appear in British, German, French, American, Polish, and other allied force structures. They run target-recognition models trained to distinguish friend from foe by signature — radar cross-section, infrared profile, acoustic signature, visual pattern.

The question BARS Moscow raises for NATO is this: who built the sensors feeding that classification, who built the processor running it, and who wrote the firmware that initialises the classifier at boot?

If the sensor is a Chinese LiDAR unit, or the processor contains Chinese-origin silicon, or the firmware was developed by a team with unexposed dependencies on Chinese toolchains, then the identification layer has an attack surface that no amount of software security above it can fully close. You cannot sandbox a trusted-platform module that was never trustworthy. You cannot audit a classifier running on hardware with undisclosed capabilities. And if the chip has a remote-management interface — as many modern processors do — an adversary with the right access can influence the identification decision at a level the operator cannot observe.

This is not hypothetical in the way a foreign-intelligence attack on Huawei basestations is not hypothetical. The legal mechanism exists. The physical access to the supply chain exists. The documented presence of Chinese components in classified platforms exists — per the CSIS finding about the F-35’s magnets. The missing piece is evidence of deliberate exploitation. The missing piece could remain missing until the moment it matters.

ETHICAL HACKING MASTERY: The Complete Guide To Cybersecurity, Penetration Testing, And Network Defense

ETHICAL HACKING MASTERY: The Complete Guide To Cybersecurity, Penetration Testing, And Network Defense

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

The Huawei–BARS Moscow parallel

Put the two stories side by side without overstating the connection, because the parallel is instructive precisely where it’s imperfect.

BARS Moscow (claimed): a Ukrainian intelligence operation spent weeks studying a specific unit’s training procedures, software, and decision algorithms through intercepted footage and data. It allegedly used that knowledge to manipulate the unit’s identification decision — causing it to classify its own aircraft as a threat. The operation required prior knowledge of the target system’s behaviour; the reconnaissance preceded the effect.

Huawei / Chinese component supply chain (documented structural risk): China has prior knowledge of every system running its equipment, because its companies manufactured and installed it. It doesn’t need to intercept training footage — it has the source code, the firmware, the manufacturing tolerances, and the update pipeline. The reconnaissance is complete before the adversary is even identified as one.

In BARS Moscow terms: the equivalent would be if Ukraine had designed and built BARS Moscow’s Lys-2 from the start. There would be no need to intercept the training videos. The training would have been designed to create the vulnerability, and the trigger could be pulled whenever it was needed.

That is a stronger position than what InformNapalm claims Ukraine achieved. And it is the position China is already in with respect to significant portions of NATO’s communications, drone, and sensor infrastructure.

Inseego Wavemaker FX3100 Dual Sim 5G Router - for Business or Home, Dual-Band Wi-Fi 6, 64 Devices, 2X LAN/WAN Ports, USB-C 3.1,Enterprise Grade Security W/Le'Mak Cable Tie Kit

Inseego Wavemaker FX3100 Dual Sim 5G Router – for Business or Home, Dual-Band Wi-Fi 6, 64 Devices, 2X LAN/WAN Ports, USB-C 3.1,Enterprise Grade Security W/Le'Mak Cable Tie Kit

  • Fast 5G and LTE Speeds: Gigabit-class LTE & 5G connectivity
  • Supports 64 Devices: Dual-band Wi-Fi 6 for multiple devices
  • Versatile Use Cases: Mobile, failover, government, and education

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

The policy gap is documented and current

The US has moved faster than its allies and still has a supply-chain problem. The 2026 NDAA blocked federal agencies from procuring Chinese drones and critical components, the FCC halted new DJI certifications, and the administration is pushing NATO allies to fund Huawei replacement through their defence budgets. In March 2026, the FCC introduced a “Conditional Approvals” list for limited exemptions through end-2027. MP Materials is building a $1.25 billion rare-earth magnet campus in Texas — reaching full capacity in 2028, the same year the NDAA’s Chinese battery ban takes effect. The timelines barely fit.

Europe is further behind. The EU has set a target: by 2035, at least 60% of defence procurement should come from domestic sources, with drone manufacturing identified as a flagship priority. That’s a nine-year horizon on a problem the BARS Moscow story suggests could matter in nine days.

The Atlantic Council has called for an alliance-wide review of defence supply chain dependencies on China. As of this writing, that review hasn’t happened. NATO’s secure telecommunications requirements for 5G haven’t been updated. Poland, Romania, and other eastern-flank states still run Chinese gear.

The gap between the policy aspiration and the installed base is the vulnerability — and it’s structural rather than accidental. It was built over a decade of procurement decisions made when price was the criterion and supply-chain provenance was not yet a defence consideration.

The open-weight argument, applied here

Yesterday this publication argued that owning your model weights is the precondition for defending your identification layer. Today’s follow-on is sharper.

When your identification system runs on sensors manufactured by a potential adversary, the software-level argument for open weights applies — and then stops. You cannot open the black box of firmware running on hardware you didn’t build. Open weights give you visibility into the classification model. They don’t give you visibility into the silicon the model runs on.

This is why the supply-chain problem is structurally harder than the software-sovereignty problem. A European defence integrator who owns the weights of their target-recognition model and runs it on Chinese-manufactured chips is in a better position than one running a closed model on those chips — but not in a safe position. The threat surface extends below the software layer into hardware, into firmware, into the physical manufacturing of the components that read the sensors in the first place.

The full version of “own your stack” in a military context doesn’t end at the model weights. It ends at the foundry. Europe has neither the models nor the foundries at the scale its defence posture now requires. The TSMC fabs in Dresden won’t be online until 2027. The rare-earth processing capability is a decade behind China’s. The drone motor supply chain is 90% controlled by the country whose state partner just lost a jet to (allegedly) its own identification system.

The honest programme — and the one VigilSAR and Corvus ISR are built around — is to own every layer you can, close the dependencies you can close on a realistic timeline, and be explicit about which dependencies remain open and what risk each carries. That’s an engineering and procurement problem, not a slogan. It starts with the model weights. It doesn’t end there.

The take

The BARS Moscow story, true or not, describes a one-time operation against one unit. The Huawei and drone-supply-chain story describes a permanent structural position — pre-positioned, legally mandated, and embedded across NATO at every layer from the comms backbone to the chip in the sensor that tells the missile what it’s looking at.

The two risks are different in nature. An adversary with OSINT capabilities and patience can target a specific unit’s identification layer. An adversary that built the infrastructure has already targeted every unit simultaneously — and hasn’t needed to do anything at all to maintain that position. The access was established in procurement.

Three things follow.

First, the question isn’t whether China will use this access. It’s whether NATO can afford to assume it won’t. The legal mechanism exists. The intelligence law is unambiguous. The precedent of using supply-chain leverage — the magnet export controls, the drone certification ecosystem, the rare-earth embargo threat — is established and recent.

Second, replacement is genuinely hard. The costs are real, the timelines are long, and the domestic alternatives either don’t exist at scale or are years from capacity. Banning Chinese equipment in defence procurement without building the supply chain to replace it is a policy that produces capability gaps, not security. The American experience with DJI — 80% market share, ban issued, Blue UAS list mostly running Chinese motors anyway — is the cautionary template.

Third, the identification layer is where the exposure is sharpest, and where ownership matters most. A Chinese-made motor in a drone is a supply-chain risk. A Chinese-made sensor or processor in a friend-or-foe identification system is an identification-layer risk — the same class of risk the BARS Moscow story made visible. Start there. Not because the rest doesn’t matter, but because that’s the layer that turns a well-functioning defence system against the people it was built to protect.

NATO has thirty-two members. Each one made its own procurement decisions. Together, they’ve created an identification layer with distributed, unaudited, legally-accessible dependencies on an adversary. The BARS Moscow claim required weeks of reconnaissance. The reconnaissance for NATO’s version was completed in the factory.


Sources: Belgian telecom dependency on Chinese equipment (including EU and NATO administration mobile comms) and German NATO-troop mobile traffic through Huawei-dependent networks per German Marshall Fund of the United States (2021, 2022), confirmed by 3Gimbals (2025); Huawei’s ~59–60% share of Germany’s 5G RAN per Strand Consult via Fox News/Barclays estimates; China’s National Intelligence Law 2017 via 3Gimbals and GMF; US Trump administration pressure on NATO allies to use defence funds for Huawei replacement per Bloomberg (June 2026); Germany’s 2026 Huawei removal deadline and three-operator “management system” workaround approach, and the ~60/100 clean-network count for Europe per Light Reading (June 2026); Polish and Romanian eastern-flank reliance on Chinese gear with no near-term removal plan per GMF (2022); Deutsche Bahn €400M-plus cost estimate and five-to-six-year delay per The Register (2023); the doomsday scenario (explicitly fictional) per Light Reading (2024); F-35/Predator/Tomahawk/Virginia-class magnet dependency (CSIS assessment) and Pentagon Blue UAS Chinese-motor penetration per Stars and Stripes (May 2026); China’s dominance of rare-earth processing (~90%), drone battery cells (~99%), and permanent magnets (~90%), DJI’s prior ~80% US market share, FCC December 2025 certification halt and NDAA FY2026 federal procurement ban per CEPA (May and July 2026), AERONAUT.media (May 2026), The Next Web (May 2026), and SUASNEWS (December 2025); China’s October 2025 magnet export controls and November 2026 suspension per Semantic Visions (April 2026); EU 2035 60%-domestic-source target per CEPA; Atlantic Council supply-chain review call (April 2025); US FCC July 2026 proposed rules on swarming/infrared drone prohibitions per Al Jazeera. The BARS Moscow claim (prior ISR Briefing) remains unverified and Russia-contested; its use here is as a conceptual analogue, not a confirmed case. Not investment advice. Analysis and framing are the author’s.

You May Also Like

Candor as a Moat: A Critical Reading of Dario Amodei and Anthropic

Dario Amodei is the most articulate executive in artificial intelligence, and probably…

Liquid vs Air Cooling for 24/7 Inference Rigs

Disclosure: This article contains affiliate links, and as an Amazon Associate I…

Rent-and-Distill: How China Is Building World-Class AI Without the Hardware or the Research

By Thorsten Meyer, April 2026 – Thorsten Meyer AI For most of…

Public Trust in AI: Polls Show People Still Wary of AI Decisions

Keeping trust in AI fragile, polls reveal global skepticism shaped by concerns over bias, privacy, and fairness that demand further exploration.