Cyber security

The case of the ‘Autistici/Inventati’ and the US sanctions targeting the infrastructure, not those responsible

4' min read

Translated by AI
Versione italiana

4' min read

Translated by AI
Versione italiana

On 26 August, the United States added the Italian collective Autistici/Inventati to the OFAC list of Specially Designated Global Terrorists. The measure, announced by the State Department and the Treasury, invokes Executive Order 13224, the same sanctions framework used against those who finance, assist or provide material, financial or technological support to terrorism.

The US objection is well known: A/I is alleged to provide digital services used by groups that Washington regards as violent or terrorist. Email, web hosting, mailing lists, blogs and tools designed to ensure anonymity and privacy are therefore classified as ‘technological support’.

Loading...

It is a disproportionate decision and, above all, sets a dangerous precedent. Not because every activity hosted by A/I should be considered legitimate, but because responsibility for a criminal offence should lie with the person who commits or organises it, not with a provider that offers infrastructure to thousands of users without any evidence of a deliberate and concrete contribution to a specific act of violence.

Autistici/Inventati has been active since 2001 and provides free email, hosting and publishing services to individuals, groups and associations with a clear anti-fascist, anti-racist, anti-sexist, anti-militarist and anti-capitalist political stance. The association has been formally recognised in Italia since 2018; according to figures cited by the US authorities, its infrastructure comprised 16,000 email accounts, 10,000 blogs, 5,500 mailing lists and 1,500 websites.

Those figures, however, are a problem with the measurement, not proof of it. Washington has indicated the overall volume of services, but has not disclosed how many email accounts, blogs or websites are attributed to individuals involved in the alleged misconduct, nor what A/I’s specific contribution was to each incident. Targeting 16,000 email accounts on the grounds that some users might use them unlawfully is a form of liability by association, not a detailed analysis.

A/I categorically rejects the classification. The collective states that it is made up of volunteers and digital activists and describes its activities as providing digital self-defence tools for individuals, groups and associations. Following the designation, it stated that the website had become inaccessible not because the servers had been shut down, but because the address enabling people to access them had ceased to function correctly.

Technical details matter. If a registry or DNS provider stops resolving a domain, the server may remain online and the data may remain intact, but for users, the service disappears. The DNS does not contain email or host blogs, but it is the global directory that links a name to a machine: removing it is tantamount to making the infrastructure invisible.

Sanctions do not apply solely to domains and online services. They freeze any assets under US jurisdiction, prohibit US individuals and companies from carrying out transactions with the designated entity, and may prompt non-US banks, registrars, service providers, cloud platforms and payment processors to sever ties to avoid the risk of secondary sanctions. General Licence 36 has set a deadline for terminating such relationships by 25 September 2026, but this does not lessen the pressure exerted on anyone who depends, even indirectly, on US financial and technological infrastructure.

This highlights a European issue that goes beyond the A/I case. An Italian organisation may comply with Italian laws, be based in Italia, have dealings with Italian banks and a largely European user base, yet remain subject to US decisions if it uses a .org domain, cloud services, a registrar, payments in dollars, card payment networks or platforms operating under US legal jurisdiction. Digital sovereignty is not just a buzzword for conferences when a domain, an email address or an account can be blocked on the other side of the Atlantic.

The point is not that anonymous or encrypted services can never be used for criminal purposes. Of course they can. Telegram has been used by extremist organisations for propaganda, recruitment and the dissemination of terrorist content; the US State Department reports, for example, that the Terrorgram Collective operates primarily through Telegram. Furthermore, in 2026, the Australian authority eSafety took action against Telegram for its alleged failure to remove terrorist content and footage of executions attributed to ISIS, following a lengthy investigation and reports from users.

Loading...

Yet Telegram was not included on the SDGT list simply because violent individuals have used the platform. Global platforms are required to remove content, cooperate, be transparent and comply with moderation obligations; the European system to combat online terrorist content, for example, focuses on monitoring, reporting and public-private collaboration.

The difference is not insignificant. If the criterion becomes ‘anyone who provides a tool that can protect the communications of criminals is an accomplice’, then encryption itself becomes suspect. Signal, Proton, Telegram, WhatsApp, email services, VPNs, cloud providers, forums, domain registrars, search engines and social networks all have one thing in common: they can be used for good or for ill by those who use them.

It makes no sense to treat an email inbox as evidence of complicity. A provider that receives a detailed request and refuses to cooperate with the competent authority may raise various issues. But sanctioning an entire provider – without a public trial, without a prior hearing and without transparently identifying the accounts involved – turns the infrastructure itself into a collective defendant.

The A/I case is not about endorsing its political ideas, nor is it about granting immunity to those who commit crimes. It concerns a simpler question: can a state take action against thousands of users, organisations and projects – including those unrelated to the alleged misconduct – simply because some of them may have used a platform unlawfully?

The answer should be no. The authorities must prosecute offences, seize evidence, identify those responsible and impose targeted obligations where there is concrete evidence. Shutting down or isolating an entire digital infrastructure, on the other hand, is easy. And that is precisely why it should not become the standard response.

* Cyber security and intelligence expert

Copyright reserved ©
Loading...

Brand connect

Loading...

Newsletter

Notizie e approfondimenti sugli avvenimenti politici, economici e finanziari.

Iscriviti