CONCEPTUAL ANALYSIS article

Front. Polit. Sci., 27 August 2026

Sec. Politics of Technology

Volume 8 - 2026 | https://doi.org/10.3389/fpos.2026.1897504

Models for incorporating counter-disinformation efforts into national security architectures

  • 1. Institute of Information and Communication Technologies, Bulgarian Academy of Sciences, Sofia, Bulgaria

  • 2. Research and Development and Innovation Consortium, Sofia, Bulgaria

Abstract

Disinformation, information influence, and cognitive warfare have become central national security concerns in the digital age. This article examines how democratic countries incorporate counter-disinformation efforts into national security architectures while preserving democratic freedoms, media pluralism, accountability, and public trust. It develops an analytical framework based on actor and task taxonomies, six conceptual institutional models, five governance dimensions, and national profiles of the Czech Republic, Estonia, Finland, France, Israel, Latvia, Lithuania, Norway, Poland, Romania, Sweden, Taiwan, Ukraine, the United Kingdom, and the United States. The study shows that democratic states do not converge toward a single model for countering disinformation. Instead, they organize counter-disinformation ecosystems through different combinations of distributed governmental coordination, specialized interagency mechanisms, dedicated agencies, embedded security functions, public-private partnerships, and societal or externally implemented arrangements. The article maps these approaches across five dimensions: centralization, specialization, obligations on non-state actors, enforcement orientation, and security-resilience framing. The findings suggest that national architectures are shaped not only by threat intensity but also by strategic culture, institutional inheritance, legal constraints, democratic norms, and state-society relations. The article contributes to research on disinformation, hybrid threats, democratic resilience, strategic communication, governance models, and institutional design by shifting attention from the content and effects of information to the organization of national response ecosystems. It also offers policymakers a framework for identifying design options and trade-offs suitable for democratic societies.

1 Introduction

When able to attack, we must seem unable; when using our forces, we must seem inactive; when we are near, we must make the enemy believe we are far away; when far away, we must make him believe we are near. Sun Tzu, The Art of War (1910, ch. 1, para. 19).

The use of deception, manipulation, and influence in conflict is as old as war. Yet, the expansion of digital communication ecosystems, social media platforms, algorithmic amplification, and artificial intelligence has fundamentally transformed the scale, speed, reach, and societal impact of informational influence. Contemporary information influence operations are no longer limited to supporting kinetic military campaigns. Increasingly, they are employed independently to shape perceptions of both decision makers and citizens, polarize societies, undermine trust in democratic institutions, influence electoral decisions, weaken alliances, and achieve strategic objectives and political ends without direct military confrontation.

Recent Russian practice illustrates this transformation. describes a Russian “5D strategy” that dismisses, distorts, distracts, dismays, and divides target audiences. Such campaigns aim not to persuade but to create confusion, mistrust, polarization, and institutional paralysis. Similar patterns appear in operations targeting elections, public responses during the COVID-19 pandemic, and support for Ukraine after 2022. Chinese information influence aimed at democratic societies, including Taiwan, has combined political messaging, social media amplification, economic pressure, and cognitive techniques (; Zhang, 2020), while Iran has used disinformation and influence operations against regional rivals, diaspora communities, and Western audiences (Tabatabai, 2020).

The Romanian presidential elections at the end of 2024 provide a recent example. shows how coordinated disinformation and foreign interference targeting the Romanian political process demonstrated both the sophistication of contemporary information operations and the vulnerability of democratic institutions.

Conceptual debates distinguish among misinformation, disinformation, and malinformation. Misinformation is false information shared without harmful intent; disinformation is deliberately false or misleading information disseminated to cause harm or achieve strategic objectives; and malinformation is genuine information used maliciously, often by taking facts out of context (Wardle and Derakhshan, 2017). The broader public discussion often uses the term “fake news,” though that term captures only part of the broader spectrum of manipulative information techniques. For brevity, this article uses the term “disinformation” to refer broadly to manipulative information-influence activities, and “counter-disinformation” to describe institutional responses to them.

Democratic approaches differ fundamentally from authoritarian information control. Russia, China, and Iran increasingly frame control over information as a matter of regime security, political sovereignty, and social stability rather than primarily as protection of democratic institutions or societal resilience. Russia’s 2000 Information Security Doctrine identified threats such as “the illegal use of special means to influence individual, group and public consciousness,” “the devaluation of spiritual values,” and “the decline in the spiritual, moral and creative potential of the population of Russia” (). Subsequent Russian strategic documents further expanded state-centered approaches to informational control, including the development of the so-called “sovereign internet,” restrictions on independent media, criminalization of online speech contradicting official narratives, and broader efforts to strengthen centralized state control over digital communication infrastructures (; ; ). Recent assessments indicate that Russia has continued to intensify digital censorship, online surveillance, and restrictions on evasion technologies such as VPNs ().

China’s “cyber sovereignty” similarly combines censorship, platform regulation, algorithmic control, surveillance, and coordinated information management within a broader political-security framework (; ; ; ). Recent assessments similarly emphasize the continued strengthening of centralized political control, information regulation, and technological self-sufficiency within China’s broader security architecture ().

Iranian approaches also combine online surveillance, censorship, cyber operations, and suppression of dissent as instruments of ideological control and regime protection. Iranian authorities have repeatedly restricted access to digital platforms, developed national information network initiatives, and used cyber and information operations both domestically and externally in pursuit of strategic objectives (; Tabatabai, 2020). Iran develops its National Information Network as a mechanism of achieving digital sovereignty while strengthening state control over internal information environments and online communication ().

These approaches differ fundamentally from democratic governance and remain outside the scope of this study. Democracies face a more complex challenge, i.e., how to counter malicious information influence while simultaneously preserving freedom of expression, media pluralism, democratic accountability, political competition, and public trust. Excessively centralized or coercive responses may undermine democratic legitimacy and resilience. Consequently, democratic counter-disinformation architectures must balance security imperatives with constitutional rights, the rule of law, and broader democratic norms.

From a policymaking perspective, this raises several governance questions: Which actors participate in national counter-disinformation efforts? What functions do they perform? How are tasks distributed among government, private actors, media, academia, and civil society? What coordination mechanisms integrate these activities into national security architectures? These questions shape debates on strategic communication (Zhao and Johansen, 2026), democratic resilience (Tagarev and Fluri, 2025), foreign information manipulation and interference (), hybrid threats (Wither, 2023), and capability development ().

Existing scholarship remains fragmented. Much work examines the technological, political, psychological, and societal dimensions of disinformation (Wardle and Derakhshan, 2017; ; ). Other strands address strategic communication, hybrid threats, information warfare, cognitive warfare, resilience, cybersecurity, and democratic vulnerability (; ; ; Wither, 2023). Less attention has been paid to how democratic states organize counter-disinformation efforts within national security architectures.

Comparative institutional analysis is particularly underdeveloped: existing studies rarely examine how democracies distribute responsibilities, coordinate state and non-state actors, and allocate counter-disinformation tasks within broader security and governance frameworks. This article addresses that gap by mapping models for incorporating counter-disinformation into democratic national security architectures. Rather than seeking one optimal arrangement, it designs an exploration space and maps governance modalities onto it. The central premise is that democracies do not converge toward one universal model; instead, they develop varying governance approaches shaped by strategic culture, institutional traditions, threat environments, and state-society relations.

The article contributes a comparative framework, actor and task taxonomies, six conceptual institutional models, and a five-dimensional governance space for analyzing democratic counter-disinformation architectures. The remainder of the article proceeds as follows. The next section outlines the methodological approach and explains the development of the analytical framework. The Results section presents the securitization trend, the actor and task taxonomies, policy and governance frameworks, six notional institutional models, the exploratory governance space, and selected national profiles. The Discussion section examines broader governance implications, limitations, and future research. The Conclusion summarizes the findings and reflects on their relevance for policymakers and researchers.

2 Methods

This study adopts a structured qualitative comparative approach to examine how democratic countries incorporate counter-disinformation efforts into national security architectures. It does not seek an optimal institutional arrangement; instead, it explores governance modalities through conceptual model construction, comparative institutional analysis, qualitative coding, and exploratory mapping of 15 national profiles.

The study first explores more than 14,000 publications and analytical reports addressing responses to disinformation, misinformation, malinformation, information influence, hybrid threats, strategic communication, resilience, cybersecurity, and related issues. The corpus showed a growing share of publications linking disinformation to national security, suggesting the securitization of information influence in academic, policy, and strategic discourse.

Securitization, associated with the Copenhagen School, describes processes by which political actors frame issues as existential security threats requiring exceptional attention and policy responses (). This article does not aim to analyze the securitization discourse, but uses this trend as contextual evidence for a turn toward exploring institutional and governance modalities.

The analysis proceeded in three stages. First, it developed six conceptual institutional models relying primarily on: distributed governmental coordination; specialized inter-ministerial1 coordination; a dedicated counter-disinformation agency; embedding the counter-disinformation function within broader security, cybersecurity, psychological defense, or hybrid-threat institutions; public-private partnership arrangements; and externally implemented or societal models involving academia, civil society, and business actors. In practice, countries often combine elements from several models.

Second, the study constructed an exploratory governance space along five dimensions: centralization; specialization; mandatory versus voluntary participation of non-state actors; enforcement versus compliance- and resilience-oriented approaches; and security-centric versus resilience-centric framing. These dimensions provide a structure for comparing national counter-disinformation architectures in democratic countries.

Third, the study purposively selected fifteen democratic cases that span the exploration space: Finland, Sweden, Norway, Estonia, Lithuania, Latvia, Czechia, Poland, Romania, the United Kingdom, the United States, France, Ukraine, Taiwan, and Israel. All these countries have approached counter-disinformation as an important policy issue, and respective documents are publically available. The selection reflects variation in strategic culture, threat exposure, governance traditions, geopolitical context, and approaches to information influence.

To support comparison, the study developed two-level taxonomies of actors and tasks involved in counter-disinformation governance. The initial structure emerged from the publication corpus and was refined through policy documents, institutional mandates, governmental strategies, and analytical reports from national governments, NATO, the European Union, ENISA, the NATO Strategic Communications Centre of Excellence, the European Centre of Excellence for Countering Hybrid Threats, think-tanks like RAND, HCSS, CSIS, and related institutions. This refinement added detail on coordination, hybrid-threat governance, psychological defense, foreign information manipulation and interference, resilience, and strategic foresight, following iterative taxonomy-design methods ().

Country profiles were coded through structured qualitative assessment rather than automated scoring. Publicly available policy documents, strategies, mandates, official statements, and analytical reports were reviewed to identify host frameworks, institutional arrangements, coordination mechanisms, actor roles, and functional responsibilities. Countries were then positioned along five ordinal dimensions. Scores from 1 to 5, including intermediate values where necessary, indicate relative positioning within the exploratory governance space rather than precise measurement; they serve as interpretive devices for comparison and visualization.

The approach reflects the study’s conceptual and exploratory character. It maps formal and declared governance architectures rather than implementation effectiveness. Informal coordination, classified practices, and implementation gaps are acknowledged as important but remain outside the scope of this article.

3 Results

3.1 Securitization of disinformation and information influence

Over the last decade, disinformation and related manipulation techniques have increasingly been examined not only as communication, media, or technological challenges, but also as issues of national security, democratic stability, and societal resilience. This shift reflects concern about hostile information operations, electoral interference, hybrid threats, manipulation of digital platforms and large language models, and information influence as an instrument of geopolitical competition below the threshold of conventional warfare.

To examine whether this development is reflected in the academic literature, the author conducted a bibliometric exploration of publications indexed in Scopus as of May 19, 2026. Using the search string (disinformation OR mis-information OR misinformation OR malinformation OR mal-information), the search identified 38,136 publications addressing disinformation-related issues. Narrowing the search to publications addressing responses to disinformation through the additional terms (counter OR response) reduced the corpus to 14,255 publications (included as Supplementary material S1). A further search combining these terms with “national security” identified 1,194 publications that explicitly link counter-disinformation to national security concerns.

While these publications still represent a small portion of the broader disinformation literature, their relative share increased substantially over time. As illustrated in Figure 1, the percentage of publications connecting counter-disinformation and national security more than tripled from the early 2010s till 2025. The trend is not strictly linear, but the overall direction is clear: studies examining responses to disinformation have increasingly migrated toward a security-oriented conceptualization and governance frameworks.

Figure 1

This development may be interpreted through securitization theory (). Issues previously treated mainly as public communication, media ethics, or information-quality concerns are increasingly framed as threats to democratic institutions, electoral integrity, social cohesion, critical infrastructure, and national sovereignty. At the policy level, this shift has incorporated disinformation into frameworks such as hybrid threats, cybersecurity, strategic communication, total defense, psychological defense, societal resilience, or foreign information manipulation and interference.

Notably, the growing securitization of disinformation did not produce convergence toward a single institutional response model. Democratic countries differ substantially in how they define the problem, distribute responsibilities, coordinate actors, and integrate governmental and non-governmental participation while balancing security and civil liberties. The increasing securitization of the issue, therefore, strengthened the importance of institutional and governance analysis rather than reducing variation in an attempt to optimize the democratic response to disinflrmation.

3.2 Identifying actors and tasks in counter-disinformation ecosystems

Incorporating the response to disinformation into national security and democratic resilience frameworks raises a practical question: how do democracies organize counter-disinformation ecosystems? Which actors participate, what tasks do they perform, and how are activities coordinated across government, private-sector, media, academic, and civil-society domains? Answering this requires tools that capture institutions, relationships, functional distributions, and governance arrangements.

Flat classifications proved insufficient because counter-disinformation ecosystems involve multiple actors that are, as a rule, multifunctional. The same actor may perform several tasks, while the same task may require a response by multiple institutions. Government communicators may conduct strategic communication, public awareness, interagency coordination, and crisis response; cybersecurity institutions may address hybrid threats, foreign information manipulation, and platform resilience in addition to technical cyber defense.

To address this challenge, the study developed two-level taxonomies of actors and tasks involved in democratic counter-disinformation governance. The initial stable version of the taxonomies emerged from qualitative coding of the 14,255 publications identified through the Scopus search on countering/ responding to disinformation. This literature-based stage emphasized recurring themes, including strategic communication, fact-checking, media literacy, civic resilience, platform governance, democratic protection, and public awareness. It also identified a broad range of participating actors, including governmental institutions, media organizations, digital platforms, civil-society actors, academic institutions, and international organizations.

The subsequent review of national policy documents, strategies, institutional mandates, and governance frameworks revealed that the literature-derived taxonomies did not fully capture the operational and institutional complexity of contemporary counter-disinformation architectures. Policy documents introduced additional categories and distinctions associated with hybrid-threat governance, foreign information manipulation and interference, psychological defense, resilience planning, strategic foresight, interagency coordination, intelligence support, election protection, and integration with cybersecurity and national-security institutions. As a result, the second-stage policy review refined and expanded both taxonomies, particularly at their second levels.

The resulting actor taxonomy includes governmental institutions, security and intelligence structures, defense organizations, regulators, media actors, technology companies, academic and research institutions, civil-society organizations, and international partners. The task taxonomy includes monitoring and detection, analysis and attribution, strategic communication, public awareness, media literacy, platform governance, resilience-building, interagency coordination, operational response, legal and regulatory measures, and international cooperation.

The taxonomies, presented in Tables 1 and 2, are analytical frameworks rather than exhaustive classifications. They provided analytical foundation for examining how democratic countries distribute responsibilities, integrate state and non-state participation, identify recurring institutional patterns, test the six conceptual models, and code national architectures across the five dimensions.

Table 1

Level 1Level 2
A1 Executive Coordination and National Security BodiesA1.1 National Security Councils
A1.2 Cabinet Offices/Prime Minister’s Offices
A1.3 Interagency Councils/Commissions
A1.4 Crisis Coordination Bodies
A2 Ministries and Government DepartmentsA2.1 Ministries of Foreign Affairs
A2.2 Ministries of Defence
A2.3 Ministries of Interior/Home Affairs
A2.4 Ministries of Justice
A2.5 Ministries of Education
A2.6 Ministries of Culture/Media
A3 Intelligence, Security, and Defense StructuresA3.1 Intelligence Agencies
A3.2 Counterintelligence Agencies
A3.3 Armed Forces
A3.4 Psychological/Information Operations Units
A4 Specialized Counter-Disinformation / Hybrid / Psychological Defense BodiesA4.1 Counter-Disinformation Centers
A4.2 Hybrid Threat Centers
A4.3 Psychological Defense Agencies
A4.4 FIMI/Foreign Interference Bodies
A5 Cybersecurity and Digital Governance BodiesA5.1 National Cybersecurity Agencies
A5.2 CERTs/CSIRTs
A5.3 Digital Governance Authorities
A6 Strategic Communication and Public Communication StructuresA6.1 Government Communication Services
A6.2 Strategic Communication Units
A6.3 Public Diplomacy Structures
A7 Electoral, Media, and Regulatory AuthoritiesA7.1 Electoral Commissions
A7.2 Media Regulators
A7.3 Data Protection Authorities
A8 Media, Platforms, and Technology CompaniesA8.1 Traditional Media
A8.2 Public Service Broadcasters
A8.3 Social Media Platforms
A8.4 Technology Companies
A8.5 Fact-Checking Organizations
A9 Civil Society, NGOs, and Volunteer NetworksA9.1 NGOs
A9.2 Media Literacy Organizations
A9.3 Civic-Tech Communities
A9.4 Volunteer Networks
A10 Academia, Think Tanks, and Research OrganizationsA10.1 Universities
A10.2 Research Institutes
A10.3 Think Tanks
A10.4 Independent Analytical Centers
A11 International and Multinational OrganizationsA11.1 NATO Structures
A11.2 EU Institutions
A11.3 ENISA
A11.4 Regional Centers of Excellence

Taxonomy of counter-disinformation actors.

Table 2

Level 1. Task groupLevel 2. Task category
T1 Monitoring and DetectionT1.1 Information Environment Monitoring
T1.2 Social Media Monitoring
T1.3 Threat Detection
T1.4 Campaign Identification
T2 Analysis and AttributionT2.1 Threat Analysis
T2.2 Narrative Analysis
T2.3 Actor Attribution
T2.4 Impact Assessment
T3 Early Warning and AlertingT3.1 Early Warning
T3.2 Public Alerting
T3.3 Interagency Alerting
T4 Strategic Communication and Public CommunicationT4.1 Strategic Communication
T4.2 Crisis Communication
T4.3 Public Information Campaigns
T4.4 Counter-Narratives
T5 Countermeasures and Operational ResponseT5.1 Debunking
T5.2 Takedown/Restriction Measures
T5.3 Operational Response
T5.4 Information Defense
T6 Regulation, Norm-Setting, and GovernanceT6.1 Legislation
T6.2 Regulation
T6.3 Codes of Conduct
T6.4 Policy Development
T7 Resilience and PreparednessT7.1 Societal Resilience
T7.2 Democratic Resilience
T7.3 Institutional Preparedness
T7.4 Psychological Resilience
T7.5 Total Defense/Comprehensive Security
T8 Education, Training, and Media LiteracyT8.1 Media Literacy
T8.2 Professional Training
T8.3 Public Education
T8.4 Exercises and Simulations
T9 Coordination and Information SharingT9.1 Interagency Coordination
T9.2 Public-Private Coordination
T9.3 International Coordination
T10 Research, Assessment, and EvaluationT10.1 Research
T10.2 Assessment
T10.3 Evaluation
T10.4 Lessons Learned
T11 International CooperationT11.1 NATO/EU Cooperation
T11.2 Bilateral Cooperation
T11.3 International Capacity Building
T12 Technology, Platforms, and CybersecurityT12.1 Platform Governance
T12.2 Algorithmic Transparency
T12.3 Cybersecurity Integration
T12.4 AI-Assisted Detection
T13 Foresight, Scenarios, and Strategic AnticipationT13.1 Strategic Foresight
T13.2 Scenario Development
T13.3 Horizon Scanning
T13.4 Strategic Anticipation

Taxonomy of counter-disinformation tasks.

3.3 Policy and governance frameworks for counter-disinformation

Counter-disinformation rarely appears as a fully stand-alone policy domain. It is usually embedded in broader policy and governance frameworks that shape how the problem is conceptualized, which actors become central, what tasks are prioritized, and how coordination is organized. This article treats these broader settings as host frameworks: they do not determine institutional design mechanically, but influence the range of plausible governance arrangements.

One important host framework is that of hybrid threats or hybrid influence. In this framing, disinformation is understood as one instrument within broader campaigns that may also involve cyber operations, political interference, economic pressure, intelligence activities, coercive diplomacy, corruption, lawfare, or societal destabilization. This framing usually strengthens the role of national security institutions, interagency coordination, and intelligence-informed analysis. The EU’s concept of foreign information manipulation and interference is closely related, although more specifically focused on exogenous threats and manipulative, intentional, and coordinated behavior in the information environment. FIMI therefore captures information-domain activities that may be part of broader hybrid campaigns without necessarily encompassing the full spectrum of non-informational hybrid tools.

A second group of frameworks links countering disinformation to cybersecurity, digital governance, and platform regulation. Here, the problem is framed partly as a vulnerability of digital infrastructures, online platforms, algorithmic amplification, and data-driven manipulation, involving cybersecurity agencies, platform operators, digital regulators, electoral-security bodies, and technology companies.

A third set emphasizes strategic communication, psychological defense, and democratic or societal resilience. Strategic communication frameworks place government communication and crisis communication near the center of the response. Psychological defense, as in Sweden, links countering disinformation to public morale, cohesion, and free opinion formation. Democratic and societal resilience emphasize media literacy, civic participation, institutional trust, public awareness, and society’s ability to withstand manipulation without excessive state control ().

Closely related, but institutionally distinct, are the frameworks of comprehensive security and total defense. Comprehensive security, most closely associated with Finland, integrates authorities, businesses, civil society, and citizens in safeguarding vital societal functions. Total defense, prominent in Nordic and Baltic contexts, emphasizes civil-military cooperation and preparedness across peace, crisis, and war. In both cases, countering disinformation is not treated as a separate function but as part of wider societal preparedness and the continuity of governance.

Host frameworks matter because they shape institutional choices. A hybrid-threat framework may favor interagency security coordination; cybersecurity may elevate the role of platform owners/operators and digital regulators; strategic communication may empower government communicators; psychological defense may justify a specialized agency; and comprehensive-security or total-defense frameworks may favor civil-military collaboration or distributed whole-of-society arrangements.

Thus, the taxonomies identify who may act and what they may do, while policy and governance frameworks help explain why democracies organize actors’ responsibilities and the performance of these tasks differently.

3.4 Institutional models for incorporating counter-disinformation efforts into national security architectures

Six conceptual institutional models were constructed from the actor and task taxonomies and policy-document review. They are theoretical governance constructs, not mutually exclusive empirical categories. Countries frequently combine elements from several models; the purpose is to identify recurring institutional logics and design options rather than rigidly classify each case. The models also serve as anchors allowing to position national architectures in the exploration space.

Model 1: distributed governmental coordination model. Counter-disinformation responsibilities remain distributed across ministries and agencies. At the same time, coordination is carried out through existing national security and cabinet-level structures, such as a National Security Council chaired by the President or the Prime Minister. This model preserves institutional continuity and allows sectoral actors to address disinformation within their areas of responsibility.

Model 2: specialized interagency coordination model. A dedicated coordination council, commission, or counter-disinformation task force brings together senior representatives of relevant ministries and agencies. It may be supported by a permanent administrative unit, often part of the cabinet. This model increases policy coherence without creating a dedicated ministry or a new operational agency.

Model 3: dedicated counter-disinformation agency model. A specialized governmental body performs a substantial share of counter-disinformation tasks and acts as a focal coordination institution. This model can increase visibility, expertise, and operational coherence, but may also generate new organizational rivalries, risks of over-centralization, or politicization if not carefully designed.

Model 4: embedded-function model. Counter-disinformation functions are incorporated into existing institutions with broader mandates, such as cybersecurity, countering hybrid threats, psychological defense, resilience, intelligence, or strategic communication organizations. This model benefits from established institutional capacity but may subordinate counter-disinformation to existing functions.

Model 5: public-private partnership model. Counter-disinformation responsibilities are implemented through structured cooperation among governmental institutions, private actors, platforms, media organizations, academia, and civil society. This model reflects the ecosystem character of the information environment and is particularly relevant where digital platforms and civic actors play central roles.

Model 6: externally implemented or distributed societal model. Counter-disinformation activities are largely carried out by non-governmental actors, such as academic institutions, civic-tech organizations, NGOs, and private organizations, with limited direct governmental involvement. This model may preserve democratic legitimacy and societal ownership, but may also suffer from weak coordination or limited authority.

These models represent institutional modalities rather than complete national systems. Figure 2 visualizes them as regions within a governance space structured by centralization and by the balance between state-centered and distributed multi-actor governance. Their positioning in the exploration space is visualized in Figure 2.

Figure 2

3.5 Constructing the governance exploration space

The six models above provide a conceptual vocabulary for institutional design, but national architectures vary along multiple dimensions. To capture this broader variation, the study constructs an exploratory governance space encompassing five analytical dimensions.

The first dimension is centralization versus decentralization. At one end, coordination and decision-making are concentrated in a central authority, agency, or national-security structure. At the other end, responsibilities are distributed across multiple institutions and sectors with limited central command.

The second dimension is specialized institutions versus distributed responsibilities. Some national systems rely on dedicated agencies, specialized units, or formally mandated bodies. Others embed counter-disinformation functions within existing ministries, communication services, cybersecurity bodies, regulators, media institutions, or civil society networks.

The third dimension is mandatory versus voluntary participation of non-state actors. Democratic counter-disinformation ecosystems cannot be effective without cooperation with platforms, media, academia, civil society, and business actors. The degree to which such participation is legally required, co-regulated, or entirely voluntary may vary considerably.

The fourth dimension is enforcement-oriented versus standards- and resilience-oriented approaches. Some systems emphasize legal measures, sanctions, content restrictions, takedowns, or operational countermeasures. Others prioritize professional standards, non-mandatory compliance with standards and recommended policies, transparency, media literacy, public communication, and societal resilience.

The fifth dimension is security-centric versus resilience-centric framing. Some countries frame disinformation primarily as a national security, hybrid threat, or foreign interference issue. Others emphasize democratic resilience, societal preparedness, civic participation, public trust, and institutional robustness.

These dimensions are not fully independent. Security-centric systems may also be more centralized, specialized, and enforcement-oriented. They are examined separately in this study because they represent different governance choices: a country may increase specialization without coercive enforcement, or strengthen coordination while preserving voluntary societal participation.

3.6 National counter-disinformation architectures

The following profiles apply the models and dimensions to analyze fifteen democratic country cases. The profiles are not intended as exhaustive national studies. Rather, they identify the dominant governance logic, the primary and secondary institutional models, the host frameworks, and the salient features of each case. The scores summarized at the end of this subsection should be read as ordinal qualitative assessments. They indicate relative positioning within the exploratory governance space and are used to support visualization of governance modalities, and not to rank countries.

3.6.1 Finland: comprehensive security and distributed societal resilience

Finland’s profile most clearly represents a resilience-centric, whole-of-society approach to countering disinformation. It is not organized around a dedicated counter-disinformation agency, nor does it treat disinformation mainly as a communication problem. Instead, counter-disinformation functions are embedded within the broader concept of comprehensive security, which serves as an overarching framework for protecting vital societal functions.

Finland’s Security Strategy for Society describes comprehensive security as an operating model in which “the vital functions of society are taken care of in collaboration between the authorities, business community, organisations and citizens” and which forms “the foundation of resilience in Finnish society” (). This core logic of the Finnish model is that security is not produced solely by the state, but through structured cooperation among public institutions, the private sector, civil society organizations, and citizens.

From the perspective of the models developed in section 3.4, Finland corresponds primarily to Model 1, with Model 5 elements, because responsibilities are distributed across public and societal actors and coordinated through established preparedness mechanisms. The strategy “does not define new tasks or responsibilities for actors” but reinforces existing distributed responsibilities; one example is the formation and sharing of situational pictures of broad-based influence ().

This model has several implications. First, Finland scores low on centralization: while coordination exists, implementation remains widely distributed. Second, counter-disinformation is not institutionalized as a separate field and, hence, it scores low on specialization. Third, non-state participation is extensive but mainly cooperative and culturally-based, rather than legally binding. Fourth, enforcement is not the dominant logic. The Finnish model emphasizes preparedness, public trust, media literacy, continuity of vital functions, and societal resilience rather than punitive intervention against information actors.

3.6.2 United Kingdom: strategic communication and distributed institutional coordination

The United Kingdom contrasts with Finland. It is not a frontline state and does not rely on comprehensive-security or total-defense concepts. Its approach combines strategic communication, intelligence-informed threat assessment, democratic protection, national resilience, and distributed coordination.

The RESIST framework, issued by the UK Government Communication Service and currently in version 3, is particularly important for understanding this approach. RESIST, a practical framework for building resilience to information threats, is designed to be “adaptive and interoperable” and comprises “a full process for building resilience to information threats” (). It guides the response by implementing a six-step process: Recognizing mis- and disinformation, early warning, Situational insight, Impact analysis, Strategic communication, and Tracking effectiveness.

The UK corresponds primarily to Model 1, with Model 2 elements through cross-government structures such as the Defending Democracy Taskforce, which addresses foreign interference, disinformation, and threats to democratic institutions (UK Government, 2022). Its distinctive feature is structured distributed capability under parliamentary oversight: more operationally organized than Finland, but less centralized and specialized than France or Ukraine.

3.6.3 Sweden: psychological defense and democratic resilience

Sweden combines societal resilience, psychological defense, and renewed security awareness after 2014 and especially after Russia’s 2022 invasion of Ukraine. The re-established Swedish Psychological Defence Agency aims to “identify, analyse and counter undue information influence” while safeguarding “the open and democratic society and the free formation of opinion” (Swedish Psychological Defence Agency, 2024).

Sweden corresponds primarily to Model 4, because counter-disinformation functions are embedded within a broader psychological-defense and societal-resilience framework. At the same time, important Model 1 elements remain through distributed responsibilities and interagency coordination. Sweden, therefore, occupies an intermediate position between resilience-oriented Nordic models and more explicitly security-operational approaches. The Swedish model is more specialized than Finland’s because psychological defense is institutionalized, but remains more decentralized and resilience-oriented than France or Ukraine.

3.6.4 Norway: total defense and societal preparedness

Norway incorporates counter-disinformation into total defense and societal preparedness, influenced by NATO membership, Arctic security concerns, and renewed attention to hybrid threats. Total defense emphasizes “mutual support and cooperation between the civil and military sectors” in managing crises and security threats (). Counter-disinformation functions are therefore distributed across security institutions, strategic communication structures, civil preparedness mechanisms, media actors, and educational initiatives rather than concentrated within a single specialized body.

Norway corresponds primarily to Model 1, with Model 5 characteristics through whole-of-society cooperation. Information resilience is embedded in civil preparedness and total defense rather than a dedicated counter-disinformation structure. The model remains decentralized, moderately specialized, cooperative rather than coercive, and close to the resilience-oriented region of the governance space.

3.6.5 Estonia: digital resilience and hybrid-threat governance

Estonia combines strong digital capabilities with a growing emphasis on hybrid threats, cybersecurity, and societal resilience. Its approach to counter-disinformation reflects both its experience with Russian information influence campaigns and its broader strategic orientation toward digital governance and cyber resilience.

The Estonian National Security Concept identifies information influence as part of a broader spectrum of hybrid threats directed against democratic institutions and societal cohesion (). Counter-disinformation functions are distributed across governmental communication structures, cybersecurity institutions, strategic communication capabilities, media initiatives, and civil society actors.

Estonia, therefore, corresponds primarily to Model 1, with secondary Model 4 characteristics due to the close integration of counter-disinformation with cybersecurity and hybrid-threat governance. Compared with Finland and Norway, Estonia places greater emphasis on security considerations and hostile foreign influence, reflecting its geopolitical exposure and experience with Russian information operations.

Its distinctive feature is the integration of digital governance, cyber resilience (), and resilience to hostile information influence within a relatively agile state architecture. Estonia demonstrates the importance of technological competence and digital capacity, and while resilience remains important, it is more security-aware and operationally oriented than Finland.

3.6.6 Lithuania: strategic communication and frontline hybrid-threat governance

Lithuania frames disinformation mainly through hybrid threats, strategic competition, and national security. Its threat assessments repeatedly emphasize Russian and Belarusian information operations as components of broader hostile influence activities (). Responsibilities are distributed across strategic communication, security institutions, defense organizations, media-monitoring capabilities, and public-awareness initiatives.

Lithuania corresponds primarily to Model 1, with Model 2 characteristics through cross-government coordination. Compared with Nordic resilience models, it places greater emphasis on threat attribution, strategic coordination, and operational response while remaining within democratic governance constraints. Thus, Lithuania occupies the more security-centric part of the governance space without moving toward highly centralized or coercive approaches.

3.6.7 Latvia: resilience under conditions of persistent information pressure

Latvia combines resilience-building with strong awareness of Russian information pressure. Historical experience, linguistic diversity, and proximity to Russia shape its approach. The National Security Concept emphasizes strengthening societal resilience against hostile propaganda, information and psychological influence, and protecting the democratic information environment (). Counter-disinformation functions are distributed among governmental communication structures, media regulators, security institutions, and civil-society actors.

Latvia corresponds primarily to Model 1, with Model 2 elements through strategic communication and interagency coordination. It is close to Lithuania and Estonia, but places somewhat greater emphasis on societal cohesion and media policy, positioning it between resilience-oriented and security-centric approaches.

3.6.8 Poland: strategic-security coordination and resilience building

Poland has increasingly incorporated counter-disinformation into broader national security, cybersecurity, and strategic communication frameworks, particularly following Russia’s aggression against Ukraine. Polish approaches emphasize both operational response to hostile information activities and strengthening societal resilience against foreign influence.

The National Security Strategy identifies information activities and disinformation as elements of hybrid threats directed against state institutions and social stability (). Poland corresponds primarily to Model 1, while also displaying significant Model 4 characteristics through the integration of counter-disinformation with cybersecurity and strategic security structures.

Compared with the Baltic states, Poland combines strong security framing with somewhat broader institutional distribution of responsibilities. Thus, Poland occupies a relatively security-oriented position in the governance space, while remaining institutionally plural rather than strongly centralized.

3.6.9 Romania: democratic resilience and emerging institutional adaptation

Romania’s approach remains less institutionalized than those of several frontline states, but concerns regarding foreign influence and information manipulation have clearly been on the rise in recent years. The Romanian presidential elections at the end of 2024 reinforced perceptions of disinformation as a national security challenge and a threat to democratic institutions.

Strategic documents increasingly link information influence to hybrid threats, cybersecurity, and democratic resilience. The architecture combines governmental communication, cybersecurity structures, intelligence institutions, media regulation, and European and NATO cooperation, but coordination appears less consolidated than in Lithuania or Poland.

Romania corresponds primarily to Model 1, with emerging Model 2 characteristics as coordination among security and governmental institutions increases. Romania appears to be moving from a relatively fragmented approach toward more structured coordination in the account of its growing awareness of foreign information influence, and occupies an intermediate position as awareness and coordination gradually increase.

3.6.10 Czechia: hybrid-threat coordination and institutional pragmatism

Czechia has developed a pragmatic, coordination-oriented approach shaped by hybrid threats, foreign influence, and democratic resilience. The centre against terrorism and hybrid threats, established within the Ministry of the Interior, was among the earliest European governmental structures explicitly addressing hybrid threats and disinformation. Czech strategic documents frame hostile information activities within broader hybrid-threat and democratic-security contexts ().

Czechia corresponds primarily to Model 2, because of the importance of specialized coordination mechanisms, while also retaining strong Model 1 characteristics through distributed institutional responsibilities. Compared with the Baltic States, the Czech approach appears somewhat less securitized and more administratively pragmatic.

3.6.11 France: state-centered coordination and information sovereignty

France approaches counter-disinformation through national security, information sovereignty, cybersecurity, and strategic state coordination. The General Secretariat for Defence and National Security, under the authority of the Prime Minister while related to the Presidency, coordinates inter-ministerial security and resilience policies, while the VIGINUM agency identifies and analyzes foreign digital interference operations.

France corresponds primarily to Model 4, because counter-disinformation is embedded within broader national-security and state-coordination structures, with Model 1 and selected Model 5 elements through distributed implementation and regulatory bodies such as VIGINUM and Arcom.2 Compared with the UK, France is more centralized and state-centric. Compared with Ukraine, however, it remains less operationalized and less wartime-oriented. Its distinctive feature is the integration of counter-disinformation into strategic autonomy and information sovereignty.

3.6.12 Ukraine: wartime coordination and operational counter-disinformation

Ukraine represents the most security-oriented case among the democratic countries examined in this study. Since 2014, and especially following Russia’s full-scale invasion in 2022, Ukraine has treated information influence and disinformation as integral components of ongoing hybrid war and closely aligned with kinetic warfare.

The Center for Countering Disinformation (CCD), established under the National Security and Defence Council of Ukraine, plays a core institutional role. CCD’s mission includes “countering disinformation, information terrorism and information manipulation” directed against Ukraine (). The institutional placement of the CCD under the National Security and Defence Council, chaired by the President, is significant because it embeds counter-disinformation within the highest level of wartime national security coordination.

Ukraine corresponds primarily to a combination of Model 1 and Model 3. The CCD provides a focal institutional capability for operational coordination, analysis, and strategic communication. Yet, multiple governmental and societal actors remain involved, cooperating through formal and informal mechanisms. The Security Service of Ukraine and the Cyber Police under the Ministry of Interior are responsible for exposing bot farms and networks and terminating their activities, including by blocking hostile Telegram channels and websites that spread hostile narratives. The Center for Strategic Communication3 under the Ministry of Culture and Strategic Communications is tasked with debunking myths, monitoring the information domain, and implementing counter-disinformation campaigns. All major TV channels have regular dedicated counter-disinformation programs. Numerous individual bloggers, professors, and former ambassadors actively reveal and debunk Russian disinformation. Accounting for the role of civil society actors, such as the Center for Democracy and Rule of Law4 and university-related organizations like StopFake5 makes the Ukraine case, already heavily securitized, also representative of the whole-of-society approach.

Ukraine demonstrates the strongest integration of counter-disinformation into wartime national security governance and, thus, it occupies the most security-centric position in the governance space, although important resilience and civil-society components remain visible.

3.6.13 Taiwan: civic resilience and distributed democratic defense

Taiwan combines national security awareness with civic participation, digital democracy, and societal resilience under sustained pressure from Chinese information operations. Its approach relies on cooperation among government, civic-tech communities, fact-checkers, digital platforms, and civil society. Rather than emphasizing centralized information control, Taiwan promotes rapid public communication, transparency, and participatory governance; Audrey Tang has described this as building immunity against disinformation rather than censorship (Tang, 2025).

Taiwan corresponds primarily to Model 5, with important Models 1 and 6 characteristics through governmental coordination mechanisms and autonomous civic actors. Compared with European frontline states, Taiwan places a stronger emphasis on civic-tech ecosystems, participatory governance, and distributed societal resilience. By integrating democratic participation and technological innovation into national resilience against information influence, Taiwan occupies a unique position in the governance space: strongly security-aware, yet simultaneously highly distributed and resilience-oriented.

3.6.14 Israel: security integration and strategic information management

Israel approaches disinformation and information influence primarily through broader national security, strategic communication, and information management frameworks shaped by persistent conflict conditions and high threat awareness. Compared with most European democracies, Israeli approaches are more strongly integrated with national security institutions with strategic, national-level coordination.

Capabilities are distributed across, cybersecurity, intelligence, and strategic communication structures. The country’s extensive experience with information operations, strategic messaging, and digital influence in conflict environments has contributed to a comparatively operational understanding of the information domain. After October 7, 2023, civic-tech initiatives contributed to the timely response to disinformation.6

Israel corresponds primarily to Model 6 because much of the visible counter-disinformation response is voluntary and informally coordinated among civil society and business actors, with Model 1 characteristics through distributed state implementation. It is a high-security case, less institutionally formalized than Ukraine but similarly reflects persistent security-oriented framing. Israel, therefore, occupies a relatively centralized, security-centric position within the democratic governance space while maintaining significant technological and societal innovation capacity.

3.6.15 United States: pluralistic governance and platform-centered coordination

The United States is the most plural and politically contested case. Responsibilities are distributed across federal institutions, cybersecurity agencies, intelligence organizations, election-protection mechanisms, local actors, platforms, civil society, and universities. The scale and diversity of the American information ecosystem make centralized approaches both politically difficult and institutionally fragmented.

The Cybersecurity and Infrastructure Security Agency describes strengthening resilience against foreign influence and disinformation targeting democratic institutions and elections as a core goal (), this is just one institutional example, while American debates on countering disinformation remain highly sensitive due to constitutional protections of free speech, political polarization, and concerns about governmental overreach.

The United States corresponds primarily to Model 5, with substantial Model 1 characteristics: decentralized, platform-centered, operationally capable, and shaped by constitutional limits on centralized information governance. Its distinctive feature is the coexistence of strong operational capabilities, especially in regard to the physical control of networks, with fragmented governance and extensive reliance on non-state actors.

3.7 Emerging governance modalities

The country profiles and dimensional scores reveal broad governance modalities without rigid classification. A resilience-oriented modality appears in Finland, Norway, and partly Sweden, where countering disinformation is embedded in societal preparedness, comprehensive security, total defense, or psychological defense frameworks.

A hybrid-threat and strategic-security modality is visible in Lithuania, Latvia, Poland, Romania, Czechia, and Estonia. These cases emphasize foreign interference, cyber vulnerabilities, and interagency coordination while remaining largely distributed rather than fully centralized.

An embedded state-security modality appears in France and Ukraine, with Israel as a related but more distributed high-security case. Expectedly, Ukraine is the strongest case of wartime operationalization, while France represents institutionalized state coordination and information sovereignty.

Pluralistic distributed governance is illustrated by the United Kingdom and the United States. Both combine government coordination, communication structures, regulatory mechanisms, platform governance, contributions by civil-society, and constitutional constraints. Still, the response of the United Kingdom appears more coordinated, while that of the United States is more decentralized and platform-centered.

Taiwan remains distinctive because it combines high threat exposure with low coercion, civic-tech participation, and distributed resilience. Its position shows that severe external pressure does not necessarily lead to centralized or enforcement-heavy design.

Figures 3, 4, 5 visualize national profiles in the exploration space and support the central claim: democratic counter-disinformation architectures occupy different regions of a multidimensional governance space, with choices being shaped by threat perception, institutional inheritance, and strategic culture.

Figure 3

Figure 4

Figure 5

4 Discussion

4.1 Democratic diversity rather than institutional convergence

The analysis suggests that democracies do not follow or converge towards a single institutional model for countering disinformation. Even as information influence is increasingly framed as a national security concern, responses remain diverse. Countries differ in threat framing, institutional empowerment, the creation of new bodies, roles of non-state actors, and ways of balancing security concerns with societal freedom and personal initiative.

This matters because securitization might be expected to produce convergence toward centralized, security-oriented models. The profiles suggest otherwise. Finland, Norway, and Taiwan combine high threat awareness with distributed and resilience-oriented governance. France, Ukraine, and Israel illustrate more security-centric approaches. The United Kingdom and the United States show pluralistic architectures, while Baltic and Central European cases occupy intermediate positions shaped primarily by hybrid-threat framing and proximity to Russia.

The implication is that democratic counter-disinformation architectures are contingent. They reflect threat severity, but also strategic culture, administrative tradition, legal constraints, political history, trust in formal institutions, and state-society relations. Policymakers from other countries should, therefore, ask not which institutional model is worth transferring, but which combination of arrangements fits the national security architecture and context while preserving democratic legitimacy.

4.2 Governance trade-offs and policy implications

The five dimensions represent governance trade-offs. Centralization can facilitate capacity building and improve coordination and accountability but may reduce flexibility and local initiative. Decentralized systems can mobilize societal resources and expertise, but require trust, mature formal and informal coordination mechanisms, and clear responsibilities.

Specialization can strengthen expertise and visibility, especially where hostile information influence is persistent or tied to broader security threats. Yet, it can also create silos, intensify institutional rivalries, and diminish the role of wider resilience or communication systems. Distributed responsibility better reflects the ecosystem nature of the problem, but risks fragmentation if coordination is weak.

Obligations on non-state actors are another trade-off. Stronger legal duties for platforms, media actors, and private entities may increase accountability, but can raise legitimacy concerns, encourage defensive compliance, or stifle legitimate expression. Voluntary and partnership-based models preserve pluralism while depending on the level of trust and incentives.

Enforcement-oriented approaches may be necessary against coordinated foreign interference, illegal content, or wartime information operations, but they cannot substitute for public trust, media literacy, transparency, and resilient institutions. Security-centric framing mobilizes resources but may over-securitize debate. Resilience-centric framing, on the other hand, protects legitimacy but may be slow under acute pressure.

Some dimensions may correlate: security-centric systems often display higher centralization, specialization, and enforcement. Nevertheless, they remained analytically distinct in this study because they represent different design choices. A country may specialize without coercive enforcement, or coordinate more strongly without alienating civil society and business actors.

4.3 Limitations

Several limitations should be acknowledged. First, the country profiles rely on publicly available policy documents, strategies, mandates, official statements, and analytical studies. These sources reveal formal architectures and declared priorities, but may miss informal coordination, classified arrangements, operational practices, institutional rivalries, or political bargaining.

A related limitation concerns the distinction between formal design and implementation. This article captures how countries formally conceptualize, organize, and justify counter-disinformation efforts. It does not systematically assess whether policies are implemented effectively, coordination works in practice, or mandates are adequately resourced. Operational practice may not fully correspond to declared strategies. Hence, the profiles should be read as assessments of formal architectures rather than actual practice and implementation performance (see Table 3).

Table 3

CountryPrimary modelSecondary modelDominant host frameworkSalient features
FinlandModel 1Model 5Comprehensive security/societal resilienceWhole-of-society governance; deeply institutionalized resilience culture
SwedenModel 4Model 1Psychological defense/societal resilienceInstitutionalized psychological defense integrated with democratic resilience
NorwayModel 1Model 5Total defense/societal preparednessDistributed resilience and civil-military cooperation
EstoniaModel 1Model 4Cyber resilience/hybrid threatsIntegration of digital governance and information resilience
LithuaniaModel 1Model 2Hybrid threats/strategic communicationStrong strategic-security framing and operational coordination
LatviaModel 1Model 2Hybrid threats/democratic resilienceSocietal cohesion under persistent information pressure
PolandModel 1Model 4National security/hybrid threatsSecurity-oriented modernization and strategic coordination
RomaniaModel 1Model 2Democratic resilience/hybrid threatsEmerging institutional adaptation and growing coordination
CzechiaModel 2Model 1Hybrid threats/democratic governanceSpecialized coordination with pragmatic distributed governance
FranceModel 4Model 1Information sovereignty/national securityCentralized state coordination and embedded security governance
UkraineModel 3Model 1Wartime national security/strategic communicationOperationalized counter-disinformation under conditions of war
TaiwanModel 5Model 6Civic resilience/democratic participationCivic-tech ecosystems and distributed societal resilience
IsraelModel 6Model 1National security/strategic communicationSecurity-integrated information governance under chronic threat
United KingdomModel 1Model 2Strategic communication/democratic protectionDistributed operational coordination and resilience frameworks
United StatesModel 5Model 1Democratic resilience/election protectionPlatform-centric pluralistic governance and constitutional constraints

Qualitative summary of national counter-disinformation architectures.

Second, the scores presented in Table 4 are structured qualitative assessments, not precise measurements. They position countries within an exploratory governance space rather than rank them or produce statistically validated indicators. Intermediate, non-integer scores reflect documentary triangulation and interpretive judgment on the relative positioning of national profiles.

Table 4

CountryCentralizationSpecializationNon-state obligationsEnforcement orientationSecurity orientation
Finland2221.51.5
Sweden34222.5
Norway2.52222
Estonia3322.53.75
Lithuania3.53.252.2534
Latvia3.2532.252.753.75
Poland3.53.252.53.254.25
Romania32.752.252.753.5
Czechia3.253.2522.753.5
France43.753.253.754
Ukraine44344.5
Taiwan2.2521.251.252
Israel33.5344.5
United Kingdom332.7533.25
United States2322.753.25

Quantitative assessment of national architectures along five dimensions.

Third, documentation varies across countries. Some cases are supported by accessible strategies and mandates, while others, including Israel and some rapidly evolving Central and Eastern European cases, are harder to assess solely from public sources.

Finally, the field is changing rapidly. Russia’s war against Ukraine, generative artificial intelligence, platform regulation, electoral interference, and shifting attitudes toward state intervention may alter national architectures quickly, as in the Romania case. The profiles should therefore be read as provisional current assessments of evolving systems.

4.4 Future research

The exploratory governance space developed here may support future quantitative and comparative clustering analysis of democratic counter-disinformation architectures. Ordinal country assessments could be used for clustering, dimensionality reduction, or other exploratory techniques to test whether the qualitatively identified modalities correspond to more stable empirical groupings.

Future studies could also examine institutional trajectories over time. For example, Ukraine, Taiwan, and Israel are especially relevant for studying wartime operationalization, civic-tech resilience, and democratic information governance under chronic security conditions.

Other scholars could complement this document-based analysis by reflecting on parliamentary inquiries, investigative reports, and conducting expert assessments of how formal architectures operate in practice, identifying implementation gaps, studying informal coordination mechanisms, and assessing institutional effectiveness.

Finally, research should examine how generative artificial intelligence, platform regulation, foreign information manipulation, and cognitive influence may reshape national architectures, and how democratic models differ from authoritarian information control systems without treating the latter as transferable alternative designs.

5 Conclusion

This article examined how democracies integrate counter-disinformation into national security architectures. It shifted attention from information content and effects to the institutional question of how response ecosystems are organized.

The article developed actor and task taxonomies, six conceptual institutional models, five governance dimensions, and fifteen national profiles. The models capture distributed governmental coordination, specialized inter-ministerial coordination, a dedicated agency, embedded functions, public-private partnerships, and externally implemented or societal arrangements. The five dimensions map variation in centralization, specialization, non-state obligations, enforcement orientation, and security-resilience framing.

The main finding is that democracies do not converge toward a single model. Their architectures reflect combinations of strategic culture, threat perception, institutional inheritance, legal constraints, democratic norms, and state-society relations. Finland, Sweden, France, Ukraine, Taiwan, the United Kingdom, and the United States illustrate different governance pathways, showing that democratic adaptation is not determined solely by threat intensity.

For policymakers, the framework identifies institutional design options and trade-offs rather than prescribing a universal solution. Centralization, specialization, enforcement, and non-state obligations can improve coordination but may also create risks for flexibility, legitimacy, civil liberties, and trust. Resilience-oriented and distributed models preserve democratic legitimacy but require coordination, trust, and sustained societal participation.

For researchers, the study offers conceptual infrastructure for comparative analysis of formal architectures, implementation gaps, longitudinal trajectories, and possible clustering of democratic responses.

The future architecture of democratic national security will depend not only on countering disinformation, but on designing governance systems that protect democratic societies without undermining the principles they defend.

Statements

Author contributions

TT: Writing – original draft, Writing – review & editing, Conceptualization, Formal analysis, Investigation, Methodology, Resources, Validation, Visualization.

Funding

The author(s) declared that financial support was received for this work and/or its publication. The work is supported by project no. BG16RFPR002-1.014-0014-C01 “Development Program with a Business Plan for the Laboratory Complex of Sofia Tech Park,” which is implemented under the “Research, Innovation and Digitalization for Smart Transformation” Program, co-financed by the European Union through the European Regional Development Fund.

Conflict of interest

The author(s) declared that this work was conducted in the absence of any commercial or financial relationships that could be construed as a potential conflict of interest.

Generative AI statement

The author(s) declared that Generative AI was used in the creation of this manuscript. The author used ChatGPT 5.5 for the following purposes: to sift through the titles and abstracts of 14,255 publications (see Supplementary material S1) and suggest amendments to the Actors and Tasks taxonomies developed by the author and, in another iteration, to review over 200 policy documents and analytical reports (see Supplementary material S2) as a basis for elaborating the final versions of the taxonomies presented in Tables 1 and 2, to provide the first draft of country profiles with their quantitative positioning on the basis of respective national policy documents, to draft the scatterplots presented in Figures 3, 4, 5, to refine the language of the author’s draft. Grammarly was used to refine the English grammar and style of the final draft of the manuscript. The author reviewed, verified, edited, and takes full responsibility for the final content, analysis, citations, and conclusions.

Any alternative text (alt text) provided alongside figures in this article has been generated by Frontiers with the support of artificial intelligence and reasonable efforts have been made to ensure accuracy, including review by the authors wherever possible. If you identify any issues, please contact us.

Publisher’s note

All claims expressed in this article are solely those of the authors and do not necessarily represent those of their affiliated organizations, or those of the publisher, the editors and the reviewers. Any product that may be evaluated in this article, or claim that may be made by its manufacturer, is not guaranteed or endorsed by the publisher.

Supplementary material

The Supplementary material for this article can be found online at: https://www.frontiersin.org/articles/10.3389/fpos.2026.1897504/full#supplementary-material

Supplementary Data Sheet 1

Publications addressing responses to disinformation, indexed in Scopus.

Supplementary Data Sheet 2

Official documents and analytical reports used in the study.

Footnotes

1.^Further down referred to as “interagency” bodies, while understanding that they involve representatives of ministries and other governmental administrative and security agencies.

2.^Arcom is the French regulatory authority for audiovisual and digital communication, with the mission, among others, to supervise “the means used by online platforms to protect audiences while guaranteeing freedom of expression,” “to protect all audiences on audiovisual and online media,” and conduct and share research. See Arcom, Our missions. Available online at https://www.arcom.fr/en/about-us/discover-institution (Accessed April 26, 2026)

3.^https://spravdi.org/en/

4.^https://cedem.org.ua

5.^https://www.stopfake.org/en/main/

6.^See, for example, the Civic Advocacy Center, https://www.israelispirit.org/en/home

References

Summary

Keywords

democratic resilience, governance models, hybrid threats, information influence, institutional design, strategic communication, whole-of-society approach, societal resilience

Citation

Tagarev T (2026) Models for incorporating counter-disinformation efforts into national security architectures. Front. Polit. Sci. 8:1897504. doi: 10.3389/fpos.2026.1897504

Received

01 June 2026

Revised

13 July 2026

Accepted

14 July 2026

Published

27 August 2026

Volume

8 - 2026

Edited by

Ilia Murtazashvili, University of Pittsburgh, United States

Reviewed by

Miroslava Pačková, University of Defence, Czechia

Trishana Ramluckan, University of KwaZulu-Natal, South Africa

Updates

Copyright

*Correspondence: Todor Tagarev,

Disclaimer

All claims expressed in this article are solely those of the authors and do not necessarily represent those of their affiliated organizations, or those of the publisher, the editors and the reviewers. Any product that may be evaluated in this article or claim that may be made by its manufacturer is not guaranteed or endorsed by the publisher.

Outline

Figures

Cite article

Copy to clipboard


Export citation file


Share article

Article metrics