1. Introduction
The ancient wisdom of Sun Tzu, that warriors must feign inability when able and distance when near, has found a new and vastly more powerful battlefield in the digital age. The expansion of social media, algorithmic amplification, and artificial intelligence has fundamentally transformed information influence from a supporting element of military campaigns into a standalone weapon of geopolitical conflict, one capable of polarizing societies, undermining democratic institutions, and shaping electoral outcomes without a single shot fired. As recent Russian “5D” strategies—which dismiss, distort, distract, dismay, and divide target audiences—and coordinated interference in the 2024 Romanian presidential elections demonstrate, contemporary disinformation campaigns seek not to persuade but to create confusion, mistrust, and institutional paralysis. This escalating threat forces democracies into a profound dilemma: how to counter malicious information influence while simultaneously preserving freedom of expression, media pluralism, and public trust, avoiding the authoritarian model of centralized information control embraced by Russia, China, and Iran. A new comparative study addresses this governance gap, moving beyond fragmented scholarship on the technological and psychological dimensions of disinformation to ask a crucial institutional question: how do democratic states actually organize counter-disinformation efforts within their national security architectures, and what recurring governance models emerge? Rather than seeking a single optimal arrangement, the research maps a five-dimensional governance space, revealing that democracies do not converge toward one universal model, but instead develop varying approaches shaped by strategic culture, institutional traditions, threat environments, and state-society relations.
2. The Securitization of Disinformation: From Media Ethics to National Security
The study’s bibliometric analysis, examining 38,136 Scopus-indexed publications on disinformation up to May 2026, confirms a dramatic shift in how the issue is framed. While only a small fraction of the broader disinformation literature explicitly links counter-disinformation to national security, that share has more than tripled since the early 2010s, signaling a clear securitization trend where issues previously treated as public communication or media-quality concerns are increasingly framed as threats to democratic institutions, electoral integrity, and national sovereignty. This shift has incorporated disinformation into policy frameworks such as hybrid threats, cybersecurity, strategic communication, total defense, psychological defense, and resilience planning. Yet the study’s critical finding is that this growing securitization has not produced institutional convergence. To analyze the resulting diversity, the authors developed two-level taxonomies of actors and tasks, refined through qualitative coding of over 14,000 publications and review of national policy documents. The actor taxonomy identifies eleven categories—from executive coordination bodies and intelligence structures to specialized counter-disinformation centers, cybersecurity agencies, media organizations, civil society, academia, and international partners—while the task taxonomy maps thirteen functional groups including monitoring, analysis, strategic communication, regulation, resilience-building, and international cooperation. Crucially, these host frameworks—whether hybrid-threat models favoring interagency security coordination, cybersecurity models elevating platform governance, or comprehensive-security models emphasizing whole-of-society preparedness—shape institutional choices in fundamentally different ways, explaining why a frontline state like Finland and a global power like the United States develop such divergent approaches to the same underlying problem.
3. Six Institutional Models: From Distributed Coordination to Societal Defense
From this analytical foundation, the research constructs six conceptual institutional models representing recurring governance logics. The first, the distributed governmental coordination model, preserves institutional continuity by leaving responsibilities across ministries while coordinating through existing national security councils and cabinet structures, as seen in Finland and Norway, where security is produced through structured cooperation between authorities, businesses, and citizens. The second model, specialized interagency coordination, creates dedicated councils or task forces supported by permanent administrative units to enhance policy coherence without establishing new operational agencies—exemplified by Czechia’s Centre against Terrorism and Hybrid Threats. The third, the dedicated counter-disinformation agency model, establishes a specialized governmental body as focal coordination institution, increasing visibility and expertise but risking over-centralization and politicization; Ukraine’s Center for Countering Disinformation, operating under the National Security and Defence Council, represents the most operational example of this approach. The fourth model, embedded-function, incorporates counter-disinformation into existing institutions with broader mandates, such as cybersecurity agencies, psychological defense organizations, or intelligence structures—the path taken by France with its VIGINUM agency integrated within national-security structures, and by Sweden’s re-established Psychological Defence Agency. The fifth, public-private partnership model, structured cooperation among government, platforms, media, academia, and civil society, reflects the ecosystem character of the information environment, and dominates the American approach through institutions like CISA. Finally, the externally implemented or distributed societal model places primary responsibility on non-governmental actors—academic institutions, civic-tech communities, and NGOs—preserving democratic legitimacy but risking weak coordination, as notably illustrated by Taiwan’s remarkable civic-tech response to Chinese information operations.
4. National Profiles: Mapping the Governance Landscape
The study’s analysis of fifteen democratic countries reveals distinct governance modalities rather than rigid classifications. A clear resilience-oriented modality emerges in Finland, Norway, and Sweden, where countering disinformation is embedded within comprehensive security, total defense, and psychological defense frameworks—characterized by distributed responsibilities, low centralization, and emphasis on societal preparedness, media literacy, and institutional trust rather than punitive enforcement. A second, hybrid-threat and strategic-security modality appears across Estonia, Lithuania, Latvia, Poland, Czechia, and Romania, where countries emphasize foreign interference, cyber vulnerabilities, and interagency coordination while remaining largely distributed; Lithuania and Poland exhibit stronger security framing due to their frontline exposure, while Romania, following its 2024 election interference, shows emerging institutional adaptation and increasing coordination from a previously fragmented base. An embedded state-security modality appears in France, Ukraine, and Israel: France represents centralized state coordination through its General Secretariat for Defence and National Security and information sovereignty doctrine; Ukraine demonstrates the strongest wartime operationalization, integrating counter-disinformation under the highest level of national security coordination through the Center for Countering Disinformation, with all major TV channels hosting dedicated counter-disinformation programs and civil society actors like StopFake playing vital roles; and Israel, shaped by chronic conflict and high threat awareness, presents a security-integrated approach with significant informal civil-society and business coordination that emerged strongly after October 7, 2023. Finally, pluralistic distributed governance characterizes the United Kingdom and the United States, combining government coordination, communication structures, platform governance, and constitutional constraints—though the UK appears more operationally coordinated through its RESIST framework and Defending Democracy Taskforce, while the US remains highly decentralized, platform-centered, and politically contested, with constitutional protections of free speech limiting centralized information governance.
5. The Taiwanese Exception and Governance Trade-offs
Taiwan occupies a unique position in the governance space, demonstrating that severe external pressure does not necessarily lead to centralized or enforcement-heavy design. Facing sustained Chinese information operations, Taiwan combines high threat awareness with low coercion, promoting rapid public communication, transparency, and participatory governance through an extensive ecosystem of civic-tech communities, fact-checkers, and digital platforms—building “immunity against disinformation rather than censorship” as described by Audrey Tang. This model illustrates broader governance trade-offs identified by the research: centralization facilitates capacity-building and accountability but reduces flexibility and local initiative, while decentralized systems mobilize societal resources but require mature coordination mechanisms and high levels of trust. Specialization strengthens expertise and visibility but can create silos and institutional rivalries, while distributed responsibility better reflects the ecosystem nature of the problem yet risks fragmentation. The question of non-state actor participation involves another trade-off: stronger legal duties for platforms and private entities may increase accountability but raise legitimacy concerns and potentially stifle legitimate expression, whereas voluntary partnership models preserve pluralism but depend on trust and incentives. Similarly, enforcement-oriented approaches may be necessary against coordinated foreign interference and wartime information operations but cannot substitute for public trust, media literacy, and resilient institutions, while security-centric framing mobilizes resources but risks over-securitizing democratic debate. The study’s quantitative assessments reveal that while security-centric systems often display higher centralization, specialization, and enforcement—as with Ukraine scoring highest on security orientation—these dimensions remain analytically distinct, and countries may specialize without becoming coercive or coordinate strongly without alienating civil society.
6. Implications, Limitations, and the Path Forward
The fundamental implication of this research is that democratic counter-disinformation architectures are contingent, reflecting threat severity but also strategic culture, administrative tradition, legal constraints, political history, and state-society relations. Policymakers should therefore ask not which institutional model is worth transferring, but which combination of arrangements fits their national security architecture and context while preserving democratic legitimacy. However, the study acknowledges several limitations: country profiles rely on publicly available documents and may miss informal coordination and operational practices; the distinction between formal design and implementation effectiveness remains unassessed; documentation varies significantly across countries, with some rapidly evolving cases like Israel difficult to evaluate from public sources alone; and the field is changing rapidly, with generative artificial intelligence, platform regulation, and shifting attitudes toward state intervention potentially altering national architectures quickly. The research opens several avenues for future investigation: quantitative clustering analysis of governance models, longitudinal studies of institutional trajectories, expert assessments of implementation gaps and informal coordination mechanisms, and examination of how emerging technologies and cognitive influence may reshape national architectures. Ultimately, the study provides a valuable framework for understanding how democracies navigate the complex tension between security imperatives and democratic norms in the information age, demonstrating that resilience, civic participation, and institutional trust may prove as important as enforcement and centralized coordination in countering the weaponized information environment—a finding that challenges both authoritarian information control and naive reliance on purely technological solutions, and one that will only grow in relevance as the information battlefield continues to evolve.



