Tuesday, September 22, 2026

Europe’s Undersea Sensor Race Has A Hidden Cost: Resolving The Alerts – Analysis


Image: ChatGPT

September 23, 2026

By Burak Oktenli


Key Takeaways:

After a Sept. 10 Reuters report on a disrupted Russian-linked operation near Svalbard and EU MARSEC EU 26 drills, plus Portugal’s REPMUS 26 uncrewed-system trials and NATO Task Force X-Arctic, the author says Europe is shifting from worrying about seabed cables to fielding sensors, drones, and procedures to watch them.

More detection is not the same as more knowledge: internal waves, tides, and dragged anchors can look like threats. A useful metric is resolution burden—how many contacts, analyst hours, and extra patrols it takes to settle two real incidents.

Interoperable pictures can multiply one sensor’s false alarm across five screens. Unresolved should stay a valid label. The advantage, the piece argues, goes to the network that can close cases without exhausting itself—not the one that rings the most alarms.


Europe is building more ways to detect suspicious activity around cables and pipelines. The next bottleneck may be the ships, analysts, environmental data and follow-up collection needed to determine which alerts actually matter.

Europe is rapidly building the machinery to watch what happens beneath its seas.

On September 10, Reuters reported that NATO allies had disrupted what Western officials described as a covert Russian operation near Svalbard involving technology intended to disable critical undersea cables. A week later, the European Union’s MARSEC EU 26 exercise practiced information sharing, coordinated decision-making, and vessel boarding around a simulated threat to underwater infrastructure.


The experimentation is continuing in Portugal. REPMUS 26 is bringing operational users, industry, academia, NATO organizations, and the European Defence Agency together around large-scale maritime uncrewed-system trials. NATO’s Task Force X-Arctic is using the exercise to continue testing integration and connectivity after maritime-sensor trials around Iceland earlier this year.

The direction is clear: Europe is moving from worrying about seabed infrastructure to building the sensor networks, unmanned systems and operational procedures intended to protect it.

That progress creates a less visible problem. The more successfully Europe detects anomalies underwater, the more anomalies somebody will have to resolve.
The alert is only the beginning of the bill

Finding something unusual near a cable is only the first step. A suspicious acoustic return, surface pattern, vessel maneuver, magnetic signature, or unmanned-system contact may justify attention. Turning that observation into a useful operational judgment can require comparison with shipping records, environmental information, additional sensors, another patrol, an underwater vehicle, analyst time, and sometimes physical inspection.


Each step consumes scarce capacity.

The ocean also produces ambiguity naturally. NASA has shown that subsurface internal waves can change sea-surface roughness strongly enough to appear in radar imagery. Tidal flow over submerged ridges can generate similar internal waves without any vessel or hostile activity being involved.

Human activity creates another layer of ambiguity. During Finland’s September maritime-security exercise, Reuters reported that authorities were preparing for sabotage involving divers or underwater drones while also noting that dragged anchors had been the most common explanation for recent damage incidents involving undersea infrastructure.

A damaged cable does not arrive with its cause attached. Neither does an anomalous sensor contact.
More detection can create more work

This produces an acquisition problem that ordinary detection metrics handle poorly.

Suppose one sensor architecture generates 100 suspicious contacts and eventually helps resolve two meaningful incidents. Another generates 20 contacts and identifies the same two. Their headline sensitivity may look similar. Their operational burden is not.

The first system consumes more analyst attention and follow-up collection. Patrol vessels may be redirected. Additional unmanned platforms may be tasked. Environmental data may need to be processed. Other intelligence requirements may wait.
The hidden variable is the resolution burden.

It can be measured. For every useful finding, how many candidates required investigation? How many analyst-hours were consumed? How much additional collection was necessary? How long did resolution take? How many contacts remained genuinely unresolved? How often did pursuing a false lead displace another mission?


Those figures do not replace probability of detection or false-alarm rate. They describe what happens after those familiar metrics reach the operations center.

That is increasingly important as sensing becomes cheaper and more distributed. Satellites, autonomous underwater vehicles, surface drones, hydrophones, radar, and commercial maritime feeds can generate more candidate information than a smaller surveillance architecture can comfortably absorb.

Detection can scale faster than interpretation.

Unresolved is a legitimate outcome

When follow-up capacity becomes scarce, organizations face pressure to turn ambiguity into a binary answer. A contact becomes benign or hostile. An unusual pattern becomes explained or unexplained. A suspicious vessel becomes responsible or cleared.

The ocean will not always cooperate.

Sometimes the available evidence supports only a narrower conclusion: the contact was unusual, additional collection was attempted, several ordinary explanations remain plausible, and the event cannot presently be resolved.

That outcome has operational value. It prevents a surveillance system from gaining apparent precision by forcing every observation into a category. It also preserves the event for comparison if another incident later supplies new evidence.

The same principle matters when coverage disappears. A contact detected once may move outside sensor coverage before another platform can examine it. Confidence during that gap cannot simply inherit the confidence of the original observation.

A useful surveillance picture needs to preserve what disappeared along with what was seen.

Interoperability can multiply ambiguity

Europe is placing considerable emphasis on interoperability. MARSEC EU 26 tested cross-border information sharing and a shared maritime picture. REPMUS is designed to integrate heterogeneous maritime systems in operational conditions. The European Defence Agency’s Critical Seabed Infrastructure Protection project is explicitly seeking an interoperable, AI-enabled underwater situational-awareness capability built from advanced sensors, autonomous systems, and resilient command-and-control networks.

That integration offers obvious benefits. It also changes the economics of a false alarm.

A dubious observation contained inside one national sensor system consumes local attention. The same observation distributed across an interoperable network can trigger investigation by several organizations unless its provenance, uncertainty, and dependencies travel with it.

Five screens displaying the same contact are not five independent observations when all five ultimately depend on one sensor.


The information architecture therefore matters as much as the sensor architecture. Operators need to know which observations are independent, which are copies, which environmental explanations remain open, and what additional evidence would actually resolve the contact.

The next bottleneck is resolution

Europe is unlikely to suffer from a shortage of sensors. The current investment cycle is producing satellites, autonomous vehicles, seabed systems, artificial intelligence, commercial data services, and increasingly sophisticated maritime command networks.

The harder constraint may become the capacity to convert their alerts into defensible conclusions at a sustainable cost.

That distinction matters particularly for undersea infrastructure because the consequences of interpretation extend beyond repair. A cable break can be an engineering failure, an accident, negligent maritime activity, or deliberate sabotage. Those possibilities carry very different diplomatic and security implications even when the physical damage looks similar.

The sensor cannot settle that question by becoming more sensitive. It can only provide evidence.

Undersea programs should therefore budget for resolution as deliberately as they budget for detection: analyst capacity, environmental characterization, follow-up collection, independent confirmation, and the ability to preserve unresolved cases without forcing a conclusion.

A sensor that generates intriguing candidates without a workable way to check them may move uncertainty from the ocean into the command center rather than reduce it.

Europe’s undersea advantage may belong less to the network that generates the most alarms than to the one that can resolve the most ambiguity without exhausting itself.


About Burak Oktenli
Burak Oktenli holds an MBA and a Master of Professional Studies in Applied Intelligence from Georgetown University. His research addresses the governance of authority in autonomous and AI-enabled systems, and his writing has appeared at the Modern War Institute at West Point, RUSI, RealClearDefense, RealClearMarkets, and Geopolitical Monitor. He is the author of Authority Architectures for Autonomous Systems, a ten-volume series on how authority in autonomous systems is delegated, monitored and recovered, at authority-architecture.me.
View all posts by Burak Oktenli →

No comments: