
The legislation formalizes what France's DGSE and the CIA already do covertly — and it does so with more legal transparency than either. That creates a problem for NATO cohesion: once Germany's law is statute, every allied intelligence service faces domestic pressure to demand the same authorities, or to justify why they lack them.
The supply-chain sabotage provision is the sharp edge — component substitution and factory disruption are acts of economic warfare that, if discovered, would trigger sanctions or alliance fracture. Germany is betting that the 12-month declaration requirement and state-level targeting will contain escalation, but the mechanism assumes an adversary won't retaliate in kind against German industry.
Berlin has just legalized offensive cyber and sabotage operations as routine state tools — a move that resets expectations for what allied intelligence services can do to each other's supply chains and infrastructure.
The explicit legal framing (declaration requirement, 12-month reviews, target-state focus) creates a template other NATO members will adopt, converting ad-hoc covert action into statutory authority. Watch the Bundestag markup in September: if amendments narrow the supply-chain sabotage clause or tighten the 'equally effective outside Germany' language, the government is hedging against blowback from allies whose networks Germany might target.
Does the bill's 'equally effective outside Germany' language permit operations inside allied territory if the foreign threat is deemed to originate there — e.g., Russian GRU infrastructure on NATO soil? The article doesn't clarify this jurisdictional boundary.
Strategic intelligence, synthesized daily — with a public track record. Every call graded against what actually happened.