Open by Design, Exposed by Default: Data Security and the Strategic Challenge of PLA Intelligentised Warfare
Maud Descamps
Key Takeaways
- What counts as relevant is being redefined by intelligentisation, where data quality determines AI effectiveness, making peacetime civilian data acquisition a form of military preparation.
- The establishment of ISF in April 2024 institutionalised the doctrinal shift of information gathering into intelligentisation.
- MCF creates legal pathways for access to civilian capabilities and information, rather than implying automatic espionage or data transfer.
- There is an aggregation problem as individual datasets may appear innocuous or commercially oriented, yet their combination can generate strategic value by enabling more comprehensive profiling, inference, targeting, or AI training.
- The EU’s principal gap is one of integration rather than absence: the EU already possesses instruments addressing cybersecurity, data protection, AI, investment screening, and research security, but these frameworks are not systematically connected around the cumulative military value that data can acquire through aggregation.
Introduction
China is undergoing a qualitative transformation in how it understands military power. The 2019 defence white paper marked the official elevation of intelligentised warfare(智能化战争, zhìnéng huà zhànzhēng) in China’s defence discourse, describing it as an emerging form of warfare driven by advances in AI, big data, cloud computing and other technologies. Its current modernisation phase, intelligentisation, treats data not as a by-product of military activity but as a strategic resource essential for AI-enabled decision-making. The April 2024 creation of the Information Support Force (ISF) reflects this shift by placing data integration and information support at the centre of joint operations. By overseeing the networks, communications, and information infrastructure through which data is collected and shared across the PLA (Pleople’s Liberation Army), the ISF provides a key institutional foundation for intelligentised warfare.
For Europe, the challenge extends beyond traditional defence concerns. China’s Military-Civil Fusion (MCF) framework deliberately links civilian and military technological ecosystems, allowing commercially acquired data, research outputs, and infrastructure information to contribute to broader national-security objectives. Individually, datasets such as geospatial information, logistics records, telecommunications metadata, or industrial data may appear benign. Aggregated and analysed at scale, however, they can reveal infrastructure dependencies, supply-chain vulnerabilities, and operational patterns with potential military value.
This challenge is becoming increasingly relevant as the European Union accelerates defence investment under initiatives such as Readiness 2030 and ReArm Europe. While these efforts seek to strengthen military capabilities, they also increase reliance on AI, cloud infrastructure, telecommunications networks, and digitally enabled civilian systems. The key question is therefore not only whether Europe is strengthening its military capabilities, but whether the civilian data ecosystems underpinning those capabilities are receiving comparable security attention.
Existing EU instruments addressing cybersecurity, data protection, investment screening, research security, and critical infrastructure provide important safeguards. Yet they do not consistently assess the cumulative military significance that can emerge when civilian datasets are aggregated across sectors. This brief identifies that gap and proposes policy responses.