Codex Americana White Paper — September 2026
Western analysis of Russian hybrid attacks against NATO states usually starts with a simple model.
The Kremlin decides how far it wants to escalate. Russian military, intelligence, cyber, and proxy organizations execute that policy. NATO then attempts to deter Moscow without allowing the confrontation to become a direct Russia-NATO war.
That model is useful.
It may also be becoming incomplete.
Russia conducts hybrid warfare through compartmentalized military intelligence structures, covert networks, cyber actors, recruited proxies, and specialized military capabilities. Western research has documented an expanding campaign of Russian sabotage and subversion in Europe, much of it associated with the GRU directly or through recruited intermediaries. That structure gives Moscow flexibility and deniability, but it also creates distance between political intent and operational execution.
Most divergence inside such a system will be mundane: incompetence, excessive zeal, bureaucratic rivalry, poor intelligence, proxy error, or mistaken estimates of Western resolve.
But prolonged war creates a more dangerous possibility.
An officer, intelligence cell, handler, operational commander, or faction may eventually conclude that continued stability is becoming hostile to its own interests. Purge, prosecution, scapegoating, battlefield reassignment, institutional defeat, loss of patronage, or eventual regime failure may all become increasingly plausible outcomes.
Such an actor does not need to want Russia destroyed.
He does not even need to want Vladimir Putin overthrown.
He need only prefer disruption of the existing political-military equilibrium to its continuation—and believe that an externally generated crisis offers a plausible way to produce that disruption.
Under those conditions, deliberately increasing the escalation risk of an operation against a NATO member could become rational for the individual actor even while remaining profoundly irrational for Russia as a state.
This paper calls that mechanism provocation from below.
There is currently no public evidence establishing that a known Russian hybrid operation has been conducted for this purpose.
The argument is narrower:
Western escalation analysis should no longer assume that every Russian actor capable of provoking NATO necessarily shares Moscow's interest in preventing the consequences of that provocation.
1. The Coordination Trap
Authoritarian systems do not survive simply because everyone supports them.
They survive partly because opponents cannot safely discover who else is prepared to act.
Political economist Timur Kuran's work on preference falsification describes how publicly expressed loyalty can conceal very different private preferences. Michael Chwe's work on common knowledge explains the additional coordination problem: knowing that others agree with you is different from knowing that everyone knows that others agree—and knows that they may act.
Apply that problem to a military.
A Russian officer may believe that the war is being catastrophically mismanaged.
He may believe his formation is being consumed unnecessarily, that political leadership will eventually blame military subordinates for failure, that the present strategy cannot succeed, and that many other officers privately believe the same things.
But there is an obvious problem.
The question:
"Will you disobey with me?"
may itself be evidence of treason.
The result is a coordination trap.
Many people can privately prefer change while behaving publicly as though obedience remains universal. Everyone waits for evidence that somebody else will move first.
This distinction matters because the hypothetical provocateur does not necessarily need an external crisis to organize a conventional conspiracy.
He may need it to change the information environment.
Under ordinary conditions, military behavior is comparatively legible. Unexpected troop movements, delayed compliance, strange communications, or unexplained command activity attract attention.
During an external military crisis, abnormal behavior becomes normal.
Units move. Orders change. Communications overload. Air defenses reposition. Intelligence organizations compete for information. Emergency authorities appear. Commands may issue rapidly changing or contradictory instructions.
That creates something ordinary authoritarian control tries to prevent:
observable information about how other institutions and officers behave when obedience becomes costly.
The potential dissident may no longer have to ask whether another officer will obey.
He can watch.
2. Motive and Capability Must Exist in the Same System
This hypothesis fails immediately if the person with the strongest motive lacks any means to affect NATO.
A frontline battalion commander cannot normally decide to conduct sabotage in Germany.
The relevant population therefore has to be narrower.
It includes personnel with meaningful influence over operations capable of generating direct confrontation with a NATO member: overseas sabotage networks, cyber operations capable of producing serious physical effects, proxy handlers operating inside NATO states, and officers with meaningful targeting or release discretion over weapons or platforms capable of crossing or striking NATO territory.
The key word is discretion.
The actor does not need unilateral authority to "attack NATO."
He may need control over only one part of an already authorized operation:
the target;
the timing;
the method;
the proxy selected;
the intensity;
the interpretation of ambiguous orders;
or what superiors are told before and after execution.
Peter Feaver's principal-agent model of civil-military relations provides the general theoretical foundation: delegation does not eliminate divergent preferences between political principals and military agents, and obedience cannot simply be assumed.
Russian hybrid architecture extends that problem across even more layers of delegation.
The most plausible form of provocation from below therefore does not require a rogue officer secretly inventing an entire operation.
Moscow authorizes an operation.
The subordinate alters its escalation profile.
That is a much smaller step.
3. The Actor Does Not Need to Be Suicidal
The weakest version of this theory imagines a doomed colonel deciding to start World War III because he has nothing left to lose.
That is not necessary.
The actor's objective may be much narrower:
stop an offensive;
force withdrawal from an exposed position;
trigger a military leadership change;
damage a rival faction;
prevent his command from becoming the next scapegoat;
force negotiations;
escape prosecution;
avoid reassignment;
create an opportunity to defect;
encourage elite intervention;
or make continuation of the current strategy politically impossible.
At the extreme, the objective could be regime change.
But the general objective is simpler:
change the equilibrium.
That turns the motive into an expected-value problem.
Suppose an actor believes continued stability offers an increasingly bad set of probable outcomes: purge, defeat, prison, battlefield death, loss of position, or destruction of his faction.
Disruption may be extremely dangerous.
But disruption also creates options that stability does not.
For such an actor, disorder acquires option value.
He does not need to believe provoking NATO is safe.
He only needs to believe the status quo is becoming worse.
4. Why the Actor Might Expect a Bounded Western Response
Provocation from below becomes much less plausible if the actor expects his action to produce immediate general war between Russia and NATO.
That is not the necessary expectation.
The hypothesized gamble is instead:
increase the severity of an incident → produce a limited military retaliation by the affected NATO member → force an emergency Russian response → exploit resulting disequilibrium.
The actor is therefore gambling, perversely, on Western escalation control.
That belief would not emerge from nowhere.
Throughout the Ukraine war, NATO governments have repeatedly demonstrated strong incentives to support Ukraine, punish Russian behavior, and strengthen deterrence while simultaneously avoiding direct general war with Russia.
Even amid the expanding Russian hybrid campaign in Europe, NATO officials continue to distinguish aggressive hybrid behavior from an imminent conventional Russian attack on the Alliance.
A Russian insider therefore does not need to assume that escalation will remain bounded as a law of nature.
He need only infer that a bounded Western response is more probable than immediate unrestricted war.
He may be catastrophically wrong.
Threat analysis concerns what actors may believe, not merely whether their beliefs are correct.
5. The Second Requirement: Readable Disequilibrium
Motive and capability are not enough.
The Russian command system itself must be in a condition where external pressure produces something useful to the provocateur.
This is the second condition of the hypothesis.
A healthy command system confronted with limited retaliation may simply respond coherently.
Orders flow.
Units reposition.
Security services tighten control.
The regime mobilizes patriotic support.
Nothing important becomes uncertain.
Under those conditions, provocation from below probably fails.
Indeed, it may strengthen Putin.
The mechanism becomes more plausible only when the command system is already sufficiently degraded that emergency response produces readable disequilibrium:
contradictory instructions;
delayed compliance;
competing command behavior;
uncertain enforcement;
unexplained institutional hesitation;
or different units responding differently to the same political crisis.
This produces a useful distinction.
Low command degradation:
external retaliation → coherent response → stronger central control.
High command degradation:
external retaliation → observable divergence → new information about who will obey whom.
Caitlin Talmadge and James Quinlivan have documented the broader tradeoffs authoritarian governments face when structuring militaries around regime security and coup prevention. Parallel security institutions, information restrictions, politically driven command arrangements, and loyalty mechanisms can strengthen regime survival while reducing other forms of military effectiveness.
Provocation from below adds another possible consequence:
a system designed to prevent internal coordination may become unusually vulnerable when an external shock forces that system to reveal how its components actually behave under pressure.
6. Passive Noncompliance Matters More Than Open Rebellion
The provocateur does not necessarily need entire formations to declare rebellion.
That sets the coordination threshold unnecessarily high.
He may need something weaker:
a checkpoint that waits;
a commander who remains in barracks;
a security officer who demands clarification;
a unit that delays;
a regional authority that refuses to commit until the outcome becomes clearer;
a formation that chooses the least loyal interpretation of an ambiguous order.
In other words:
passive nonresistance may matter long before active defection begins.
This is one reason the Wagner mutiny deserves careful treatment.
Wagner's June 2023 rebellion is strong evidence against easy-collapse theories. An armed organization seized key facilities in Rostov-on-Don and began moving toward Moscow. The broader Russian military did not cascade into revolt. The rebellion ended rapidly and was followed by consolidation rather than regime breakdown.
That raises the threshold for this hypothesis.
It does not eliminate the mechanism.
The more interesting question for future historical reconstruction is not merely which Russian officers openly joined Wagner.
It is which institutions acted, which hesitated, which waited, and which did nothing.
An authoritarian coordination cascade does not necessarily begin when everyone announces rebellion.
It may begin when enough people discover that others are unwilling to defend the existing equilibrium.
7. The Strongest Counter-Mechanism: Rally Around the Flag
Any serious version of this hypothesis must confront the obvious objection.
Foreign attack can strengthen authoritarian governments.
A NATO strike could provide the Kremlin with precisely what it wants politically:
an external enemy;
justification for additional mobilization;
emergency powers;
expanded censorship;
preemptive arrests;
greater surveillance;
and renewed legitimacy for domestic repression.
The internal-security architecture designed to suppress disorder may remain largely untouched even while conventional Russian military assets suffer.
Therefore this paper does not predict:
NATO retaliation → Russian instability.
It predicts only that a sufficiently motivated actor may believe:
bounded NATO retaliation → command disruption → opportunity.
The actor may lose that gamble badly.
This distinction between belief and actual mechanism effectiveness is essential.
For threat assessment, the question is:
Could an escalation-capable actor plausibly believe the gamble might work?
For Western policy, the question is different:
Would our response actually create the disequilibrium he wants?
Those two questions should never be conflated.
8. Three Partial Historical Analogues
No historical episode duplicates the full scenario.
Several demonstrate individual components.
Mukden: Subordinates Manufacturing External Reality
The Kwantung Army's behavior around the 1931 Mukden Incident demonstrates that military subordinates can manipulate an international crisis to force policy choices upon their own government.
Japanese political authorities attempted to restrain expansion. Kwantung Army officers and sympathetic military actors created facts on the ground that progressively constrained Tokyo's available choices. Contemporary diplomatic reporting later described the Army's extraordinary independence from civilian control in Manchuria.
Mukden therefore supports a narrow proposition:
subordinate military actors can alter the external strategic environment in order to constrain their own political center.
It is primarily an analogue for factional escalation, not proof of the more extreme H3 mechanism.
Valkyrie: Emergency Activity as Political Cover
The July 20, 1944 conspirators did not attempt to provoke an external enemy.
Their relevance is narrower.
They repurposed an existing emergency mechanism—Operation Valkyrie—as the framework through which Reserve Army units could seize key institutions and arrest regime personnel while initially operating under ostensibly legitimate emergency authority.
The lesson is not that Valkyrie resembles a Russian NATO provocation.
It is that:
an emergency environment can give otherwise rebellious activity a temporarily legitimate operational appearance.
That is precisely one element required by the mechanism described here.
Wagner: A Failed Stress Test
Wagner demonstrates how difficult a genuine cascade remains.
A visible armed rebellion with substantial combat power did not produce widespread military defection.
That is significant counterevidence.
But it also directs attention toward the lower threshold this paper considers more important: passive behavior, hesitation, and uncertainty rather than immediate open allegiance to rebellion.
The three examples therefore demonstrate different pieces of the model.
None demonstrates the entire thing.
9. Four Competing Hypotheses
Provocation from below should never become an all-purpose explanation for strange Russian behavior.
A useful intelligence framework requires alternatives.
Rather than asking whether H3 is simply "true," analysts should compare at least four possible explanations.
H0 — Central Policy
The Kremlin knowingly authorized the actual escalation level and accepted its foreseeable consequences.
H1 — Ordinary Agency Loss
The operation exceeded expectations because of incompetence, excessive zeal, proxy error, bureaucratic incentives, bad intelligence, or mistaken assessment of Western resolve.
H2 — Factional Escalation
A Russian organization or faction deliberately exceeded central preferences in pursuit of its own institutional or policy goals.
This is the closest category to the Kwantung Army precedent.
H3 — Provocation From Below
An actor deliberately increased the escalation level at least partly because the resulting external response was expected to disrupt Russia's existing political-military equilibrium.
These categories are analytically distinct.
They may not be distinguishable in real time.
H2 and H3 are particularly difficult because the observable external act may be identical. The difference lies partly in motive.
That makes H3 an observability problem, not an inherently unfalsifiable proposition.
Intercepted communications, internal investigations, contradictory orders, or later documentary evidence could strongly favor or disfavor it.
But NATO cannot depend upon obtaining such evidence before responding to an ongoing attack.
10. What Evidence Would Make H3 More Plausible?
Generic Russian recklessness is insufficient.
More useful indicators would include combinations of the following:
Operational deviation: evidence that the executed target, timing, method, or intensity materially differed from what higher authority approved.
Immediate internal suppression: arrests, removals, investigations, or sudden reassignment inside the organization responsible for the incident.
Command contradiction: evidence that senior Russian authorities attempted to halt, reverse, contain, or disown operational behavior immediately after discovering its actual scope.
Network-specific escalation: unusually dangerous incidents repeatedly clustering around the same officers, handlers, units, or operational channels.
Self-harming target selection: repeated operations whose predictable strategic effect is so damaging to Russian interests that ordinary incompetence becomes progressively less persuasive.
Post-incident internal exploitation: unusual military movements, selective disobedience, delayed enforcement, elite maneuvering, or factional political activity immediately following the externally generated crisis.
Visible command degradation: increasing evidence that Russian institutions react inconsistently to rapidly developing security shocks.
Conversely, synchronized propaganda preparation, coordinated diplomatic positioning, cross-agency preparation, and evidence of precise central authorization would weigh strongly toward H0.
The framework is therefore probabilistic.
No single indicator proves H3.
11. Moscow Must Not Gain a New Deniability Loophole
There is an obvious danger in introducing this framework into Western analysis.
Russia could exploit it.
If NATO begins saying:
"Perhaps that attack wasn't really authorized by Putin,"
Moscow gains another reason to obscure its command architecture.
Every dangerous operation can suddenly be followed by:
"A subordinate exceeded instructions."
That cannot become a defense against state responsibility.
The central policy principle should therefore be:
Russian state responsibility for the proximate act is the baseline. Authorization depth affects how costs are imposed, not whether responsibility exists.
That distinction closes both sides of the trap.
A Russian state organization cannot conduct an attack and escape consequences simply because Western intelligence cannot reconstruct every internal order.
But NATO also does not have to pretend that Russian state responsibility proves Putin personally selected the exact target, method, and escalation level.
Those are different questions.
12. NATO Needs Two Clocks
A serious attack creates an immediate problem.
Intelligence reconstruction takes time.
Defense cannot.
Western response should therefore operate on two clocks.
The Immediate Clock
Stop the attack.
Protect allied territory and populations.
Neutralize continuing threats.
Preserve military options.
Communicate red lines.
Ensure that serious Russian-linked attacks are not cost-free.
The Forensic Clock
Determine which Russian organization conducted the operation.
Reconstruct authorization depth.
Determine whether execution differed from orders.
Identify factional interests.
Study internal Russian reactions.
Determine whether subsequent pressure should escalate, hold, change form, or pursue de-escalation.
The advantage of this system is that NATO does not need to solve H0 through H3 before defending itself.
The immediate response can be designed to remain robust across several possibilities.
Later intelligence informs what comes next.
13. The Decision Rule
The practical contribution of the framework can be stated simply.
Responsibility determines whether costs are imposed.
Authorization depth helps determine how those costs are imposed.
If Russian state responsibility and central authorization are both highly confident, conventional deterrence logic applies.
If Russian state responsibility is clear but internal authorization remains uncertain, uncertainty should influence the form, scope, and target of subsequent pressure—not create impunity.
At the same time, Western governments should avoid gratuitously producing generalized command chaos if the same deterrent objective can be achieved by disabling, exposing, isolating, sanctioning, arresting, or otherwise imposing costs on the externally relevant capability.
The principle is neither "always retaliate harder" nor "exercise restraint because somebody may have gone rogue."
It is:
Do not confuse uncertain intent with absent responsibility.
And:
Do not confuse state attribution with proof of unitary state control.
Conclusion
The central danger in Russia-NATO escalation is not necessarily that Vladimir Putin will decide that a direct confrontation with NATO is desirable.
It is that prolonged war may gradually erode the assumption that every Russian actor capable of provoking NATO shares Putin's interest in preventing that confrontation.
Most divergence will remain ordinary.
Orders will be misunderstood.
Proxies will overreach.
Services will compete.
Officers will pursue bureaucratic interests.
Operations will go wrong.
H3 requires something more specific.
It requires an actor condition:
someone with meaningful escalation capability prefers disruption of the existing equilibrium and believes bounded Western retaliation could help produce it.
And it requires a system condition:
the Russian command structure must be degraded enough that external pressure produces readable disequilibrium rather than merely disciplined adaptation.
Put together, the hypothesized pathway is:
war stress → overlap of motive and escalation capability → manipulation of an existing operation → bounded foreign retaliation → readable command disequilibrium → passive coordination or factional opportunity → attempted change in the internal equilibrium.
That sequence is not established fact.
It is a risk model.
But it exposes a potentially dangerous assumption buried inside conventional escalation analysis:
that asking "Why would Putin do this?" is sufficient to explain every Russian action.
As wars become longer and institutions become more stressed, the interests of the state, the regime, individual services, factions, and individual officers need not remain identical.
Western analysts should therefore add two questions whenever a Russian-linked operation appears unusually reckless:
Which Russian actor actually wanted this outcome?
And more importantly:
Who inside Russia benefits if it goes much further than Moscow intended?
Selected Sources and Intellectual Foundations
Timur Kuran, Private Truths, Public Lies: The Social Consequences of Preference Falsification (Harvard University Press, 1995). Kuran's work provides the foundation for understanding how concealed preferences can preserve apparently stable political equilibria.
Michael Suk-Young Chwe, Rational Ritual: Culture, Coordination, and Common Knowledge (Princeton University Press, 2001). Chwe develops the common-knowledge framework used here to distinguish private agreement from information sufficient for coordinated action.
James T. Quinlivan, “Coup-Proofing: Its Practice and Consequences in the Middle East,” International Security 24, no. 2 (1999). Quinlivan documents authoritarian strategies including parallel militaries, special loyalties, and internal-security institutions designed to reduce coup risk.
Peter D. Feaver, Armed Servants: Agency, Oversight, and Civil-Military Relations (Harvard University Press, 2003). Feaver's principal-agent model provides the broader framework for understanding divergence between civilian principals and military agents.
Caitlin Talmadge, The Dictator's Army: Battlefield Effectiveness in Authoritarian Regimes (Cornell University Press, 2015). Talmadge examines how authoritarian threat perceptions shape promotion systems, command arrangements, information management, and military effectiveness.
Seth G. Jones, “Russia's Shadow War Against the West,” Center for Strategic and International Studies (2025). Documents the expansion and organizational character of Russian sabotage and subversion against Western targets.
Kinga Redlowska, Marta Popyk, and Tom Keatinge, “Responding to Russian Sabotage Financing,” Royal United Services Institute (2026). Examines the continuing Russian sabotage campaign and the use of networks and intermediaries in European operations.
Historical documentation on the Kwantung Army and Japanese civil-military divergence is available in the U.S. State Department's Foreign Relations of the United States archive and subsequent historical scholarship.