Threat lists tell governments where to look. Horizon scanning helps them recognise when the list has become outdated.
Security institutions generally organise analysis vertically: by country, region, threat actor or functional portfolio. Emerging risks often move horizontally across those divisions, linking maritime security, energy, trade, technology, finance and the information environment.[
This draft uses horizontal scanning to describe a form of horizon scanning that deliberately crosses geographical, thematic and institutional boundaries. Horizon scanning is already an established method for collecting insights on emerging trends and weak signals, while the added adjective “horizontal” stresses the need to work across silos rather than only look ahead in time.
The autumn of 2026 has provided several illustrations. Drone incidents in northern Europe have crossed the boundaries between criminal activity, accident, intelligence operations and possible state action, while unconfirmed media reports alleged a possible threat from drones launched from merchant vessels in the Mediterranean; French and Italian officials publicly disputed or declined to confirm aspects of those reports, which is exactly why weak signals should be logged without being promoted prematurely into established fact.
The disruption of shipping through the Strait of Hormuz provides a less ambiguous example. Recent analysis described the 2026 Hormuz disruption as the largest physical supply disruption in the history of global energy markets, with effects on prices, shipping and European economic conditions that could narrow fiscal room for other priorities, including defence.
The usual objection is that broad scanning spreads analysts too thin. That risk is real, but concentrating collection exclusively on established threats creates the opposite danger: strategic surprise originating where no one was assigned to look, while good practice in the UK Futures Toolkit treats scanning as an organised and continuous exercise rather than an occasional brainstorm.
Scanning should therefore operate in three directions at once:
- Across time, from weak signals visible today to slow-moving demographic, technological and environmental change.
- Across space, because developments in the Red Sea, the Taiwan Strait or the Sahel can produce indirect effects in the Baltic and elsewhere in Europe.
- Across systems, including cyber, space, supply chains, finance and the information environment, especially where activity remains below established legal or political thresholds.
Analysts naturally connect developments that are close in time, geography and prior experience. Institutional structures reinforce this tendency because collection and assessment are usually organised within portfolios inherited from earlier strategies.
Yet distant factors may still belong to the same causal network. A conflict involving Iran can influence the war in Ukraine through drone technology, oil prices, sanctions enforcement, the allocation of air-defence systems and diplomatic alignments, while China-Russia ties connect dual-use components, finance and political cover to developments in both Europe and the Middle East.
The September 2026 extension of the US-China trade truce from November to 10 January 2027, including arrangements affecting rare-earth supplies, illustrates how a bilateral bargain can alter operating conditions for European industry within weeks.
The analytical task is therefore not simply to identify more events. It is to discover which events might be connected, through what mechanisms, and with what implications for decisions.
From scanning to a living hypothesis register
A more rigorous process can be broken into seven stages: scan for signals, connect possible relationships, formulate competing hypotheses, test those hypotheses against indicators, prioritise by policy relevance, escalate selected findings into decision channels, and audit what was judged, when and on what evidence.
The practical instrument for this work could be a living hypothesis register. Each entry should record the hypothesis itself, its policy relevance, supporting and contradicting evidence, source provenance and reliability, estimated probability and confidence, expected impact, diagnostic indicators, responsible analyst, next review date and any decisions likely to change if the assessment changes.
Digital tools can help, but only under disciplined controls. Language models and graph-based methods can reduce the cost of identifying candidate links across large volumes of multilingual reporting, yet generative AI can also produce plausible but false claims, reproduce bias and amplify misleading correlations if outputs are not checked against evidence.
The appropriate division of labour is simple: AI proposes, evidence supports, analysts judge and accountable officials decide. That principle matters because broad scanning otherwise risks generating noise, false positives, spurious correlations, confirmation cascades and even adversarially planted weak signals.
Hypotheses should also be reassessed regularly rather than treated as one-off forecasts. Probability, consequence, urgency, reversibility and information value answer different questions and should remain visible as separate dimensions instead of being collapsed into a single score.
What this means for Sweden and the EU
The answer is not necessarily a new agency. Sweden could begin with a limited cross-government pilot linking the Government Offices, the Swedish Defence Research Agency (FOI), the Armed Forces and relevant civilian agencies around two or three cross-domain problems over six months.
FOI already publishes horizon-scanning work, including scans of technologies relevant to the Swedish Armed Forces and a 2023 report on data analysis and AI covering prescriptive analysis, uncertainty management, explainability and systems perspectives.
A practical pilot should produce five outputs: a monthly weak-signals note, a quarterly cross-domain risk map, an auditable register of competing hypotheses, an alert when evidence crosses a pre-agreed decision threshold, and a final evaluation of analytical usefulness and cost.
At EU level, the goal should be a federated scanning network linking existing national and European capacities rather than another large central structure. Common metadata, confidence language and reporting formats would allow signals to travel across institutional boundaries without requiring all analysis to be centralised.
Forecasting research suggests that decomposition, probabilistic reasoning, training, teaming and aggregation can improve judgement, although gains vary by task and institutional setting. A disciplined scanning and hypothesis process would translate those lessons into routine analytical practice.
Strategic insurance is rarely glamorous. Its value becomes visible only when the unexpected occurs, and when institutions recognise it early enough to act.
Lars-Erik Lundin
