Autistici/Inventati was never playing against the United States. No charge was laid, no forum convened, no argument heard.

The collective learned of the designation from the press. No US authority had asked it to take anything down or to hand anything over. Italian authorities had made such requests between 2005 and 2009, and A/I had answered them through the courts: content was removed where a judge ordered it, while requests for user data produced nothing because no logs or subscriber identities had been kept.

A foreign authority does not normally have to ask the provider directly. There is a legal route for obtaining evidence across borders: mutual legal assistance. Italy used that route in 2010, when it sought access to A/I’s servers in Norway. The United States did not use it.

Instead, the designation changed the problem for everyone around A/I. The collective was operating inside a network in which the United States can attach a cost to other people’s choices.

This is a different kind of game.

Four kinds of player

Four kinds of player are enough to describe the game-theoretic mechanism. The designator chooses where to apply jurisdictional pressure, and how widely to draw the category. The designated collective chooses among continuing, adapting, litigating and dissolving. Intermediaries, each facing its own local decision, choose whether to maintain the relationship: a registry, a payment processor, a bank, a certificate authority, a transit provider, a hosting company. Successor providers sit downstream. They choose whether to accept displaced users, and whether doing so puts them next in line.

These players do not need to share an objective. The first player does not have to defeat the second directly. It can give the third a problem. The third can then solve its own problem by ending its relationship with the second.

The cost of the move is therefore exported. The designator does not have to bear it, and the intermediary does not have to agree with the reason for imposing it.

Nobody has to agree.

Wrong in one direction only

Public Interest Registry did not need to decide whether Autistici/Inventati was dangerous. The question facing an intermediary is different: what happens to the intermediary if it turns out to have been wrong? Whether PIR acted on any instruction from OFAC has not been established. The mechanism does not require that it did.

Ending the relationship has a known and limited cost: a registration lost, a customer lost, a service discontinued. Continuing costs very little if the feared exposure never materialises, but potentially far more if it does. The intermediary therefore does not need to believe that enforcement is likely. It needs only to assign the severe outcome some non-trivial probability, and to have no clear ceiling on the cost if that outcome occurs.

That is expected-loss reasoning under asymmetric exposure. It is not, by itself, formal dominance, and calling it dominance would claim more than the available payoffs establish.

For an intermediary with substantial US exposure, however, withdrawal can become the safer response across a wide range of beliefs about enforcement. The mechanism does not require the intermediary to know where the rule ends. Uncertainty about the boundary can itself widen the area in which exit looks prudent.

The European Council on Foreign Relations described the pattern in 2019, when the target was Iran. A lack of clarity about how the measures would be interpreted and enforced produced a high degree of overcompliance by European companies and banks, which preferred to cut ties rather than risk falling foul of a framework they could not map. OFAC answered European governments’ repeated requests for clarity slowly or inadequately.

There is then little reason to wait for clarification. Banca Etica did the opposite. It suspended the account first, then sent inquiries to the Ministry of Economy and Finance, the Italian Banking Association, Assopopolari and its external lawyers. It told the association the suspension would hold at least until the answers came back.

The customer bore the bank’s uncertainty for as long as it lasted.

Banca Etica published the calculation in plain form. Its statement records eight years of ordinary account relations, places the account in the medium anti-money-laundering band, condemns the use of OFAC listings for political ends, and announces the suspension anyway, while warning of the loss of card services and non-euro payments for its other customers and members. The same document contains both the stated preference and the revealed strategy. It also says the bank is costretta, forced, to raise the risk profile and suspend the account. A/I’s appeal answers that no Italian law requires a bank to freeze funds on a foreign designation.

Both statements hold only if the compulsion is a matter of risk rather than law. Technically, secondary sanctions do not make the underlying conduct unlawful in the same way as a prohibition: the conduct is sanctionable rather than prohibited. European law does compel, in the cases it covers: a 2024 directive makes the deliberate violation of Union restrictive measures a criminal offence. A/I appears on no EU list, so that compulsion was not available to describe what the bank did. That is what makes the move contestable: a choice, described by the player making it as an obligation.

The bank had already criticised the extraterritorial reach of US sanctions, including when they were applied to the UN Special Rapporteur Francesca Albanese. A prior public position did not remove the new constraint.

Alessandro Messina, formerly the bank’s director, argued that the bank could have dropped A/I from the Visa circuit while keeping other services running. If that reading is correct, the bank did not merely calculate whether the designation was justified. It calculated what position was safest given uncertainty about the consequences of remaining. A constrained optimum under asymmetric risk can sit well inside the boundary.

Coordination is the risk

There is a second game inside the first. European intermediaries might collectively prefer not to let a foreign designation determine their behaviour. If none could be isolated, the threat to any one of them would be reduced. Individually, however, each intermediary has reason to protect itself.

This resembles a coordination problem, except that the obvious solution, coordination among the exposed intermediaries, may itself create additional exposure. An agreement among European banks not to comply could draw an investigation of its own. The route out of the dilemma is hazardous in its own right. Each player then has an incentive to leave the cooperative arrangement before everyone else does.

The result is something that looks like coordination without coordination: each intermediary makes its own decision, using its own exposure, its own information and its own estimate of the downside. The decisions can point in the same direction without anyone having agreed that they should.

Unanimity, arrived at without a single meeting, and deniable by every participant.

Europe answers late

The EU Blocking Statute tries to change precisely the calculation an intermediary makes. The problem is that the two sides do not necessarily offer comparable losses.

The US threat can include exclusion from dollar clearing and other consequences that may be existential for an institution with substantial dollar exposure. The European response creates legal exposure inside Europe. That exposure is real, but it may be bounded, contestable and less immediately destructive to the institution’s ability to operate.

The Bank Melli judgment is relevant here because it leaves a European operator able to terminate a relationship without having to state its reasons, while allowing a national court to annul the termination if doing so is proportionate. The operator may then have to prove in court that it was not complying with the foreign measure.

The Blocking Statute therefore changes the calculation without necessarily reversing it. To reverse the calculation, the European counter-threat would have to make non-compliance at least as dangerous to the intermediary as compliance with the foreign measure. Constructing that position would expose European firms to substantial legal and economic risk.

Europe has acquired instruments with some outward reach of their own, but they are not the same shape. The EU framework has taken on an extraterritorial dimension since 2022, while its measures remain binding for EU operators only. Article 8a was inserted into Regulation 833/2014 by the fourteenth Russia sanctions package in June 2024. It obliges a European operator to use its best efforts to stop entities it owns or controls from undermining the measures. Europe binds the parent, and the parent answers for what it owns abroad.

That amendment also rewrote Article 8, requiring member states to provide penalties for infringements, criminal ones where appropriate. The obligation abroad and the penalties at home arrived together. The American mechanism works differently: the third party need not be ordered to withdraw. Its own exposure can make withdrawal the safer choice.

The problem is not that nobody has thought of a counter-threat. It is that the currencies in which the threats are denominated are different.

Hardened at the wrong layer

A/I had already survived several rounds of the obvious game. In 2004 the commercial host let police copy A/I’s disks and told the collective it had been an electrical fault. A/I found out a year later, from a footnote in a case file. In 2010 Norwegian police cloned the disks of a server holding 2,000 accounts, to establish that the logs A/I said it did not keep were in fact absent.

Each round selected for resilience at the layer under attack. Each also required an instrument: a prosecutor, a rogatory letter, somebody arriving at a building.

The designation required none.

Plan R* was one result: services distributed across jurisdictions, public-facing nodes replaceable, as little retained as possible, users told in writing not to trust the provider with their safety. That architecture is a response to a particular threat model.

The defended graph ran through server, network, filesystem and application. The designation walked a different graph: identity, financial relationship, service relationship, jurisdictional exposure. Nothing in the first graph needs to be attacked at any point in the second.

Two columns of four layers. On the left, the graph Autistici/Inventati defended: server, network, filesystem, application, each with the property Plan R* gave it. On the right, the graph the designation walked: identity, financial relationship, service relationship, jurisdictional exposure, each marked with the event that reached it between 26 August and 1 September 2026. The gutter between the columns is empty and its boundary is drawn as a broken line.

The joints attacked are controlled by neither the designator nor the target. The United States does not control an Italian cooperative bank. The bank did not agree with the United States and said so in public. The designation added a new constraint to the bank’s own optimisation problem. The bank then did the rest unaided.

An intermediary does not have to become an ally of the designator. It only has to decide the target is too dangerous to keep.

Where the users go

A/I dissolved on 6 September, and services ended on 18 September. That changes the question the system is answering. It stops being only whether the target survives. It becomes where the displaced population goes.

The designation did not arrive alone. The Federal Register notice records three organisations blocked on 26 August: Palestine Action in the United Kingdom, Autistici/Inventati in San Giuliano Terme, and Masar Badil across Brazil, Germany, Canada, Belgium and Spain. The notice gives each an organisation type. Palestine Action is a transnational terrorist group. Masar Badil is an advocacy organisation, designated for acting on behalf of the Samidoun Palestinian Prisoner Solidarity Network. A/I is data processing, hosting and related activities.

Palestine Action and A/I were designated under the same clause, in the same words: for having materially assisted, sponsored, or provided financial, material, or technological support for, or goods or services to or in support of, an act of terrorism.

The designation category is therefore not a kind of organisation. It is a relationship. A group that blockades a factory and a collective that runs mail servers can be added to the list by one sentence, and the sentence is about what was supplied to somebody else. A sentence that fits both will fit the next one. That is what a reusable template looks like from the outside. Whether it was built to be one is a different question.

Several objectives are consistent with the first move, and they diverge on what comes next. The objective could be eliminating this particular collective. It could be deterring comparable ones. It could be clearing providers out of jurisdictions where a US warrant cannot be enforced. It could be moving users into jurisdictions where a US warrant can. It could be establishing a reusable template. It could be raising the general cost of running privacy infrastructure outside US jurisdiction. Those hypotheses predict different subsequent moves.

Unlike intention, a move is observable.

Out of reach, then into reach

One version of the routing hypothesis appears in public commentary within two days of the designation. Kyle Shideler’s piece for The Federalist, republished by the Center for Security Policy on 28 August, anticipated a diaspora from A/I to comparable organisations, named Riseup in Seattle as a likely destination, and described the strategic trade directly. Relocation to a US entity would limit what State or Treasury could do, while placing the data within reach of the Justice Department.

That does not establish that Riseup was selected as a target. It establishes something narrower: at least one prominent policy commentator understood migration towards a US-jurisdiction provider as a strategically useful consequence of the first move.

The routing hypothesis therefore has two stages. Stage one removes a provider that cannot be served with US process, using an extraterritorial instrument that is diplomatically expensive and legally contested.Stage two places displaced users somewhere that warrants, gag orders and material-support statutes already reach. Under that hypothesis, designating the destination would disrupt the herding effect.

Movement commentary reads the sequence differently and treats Riseup as the next victim to be defended. The migration threads show displaced users heading there and encountering an invitation-only service, a restriction that predates the current episode.

Neither observation establishes the objective. Both are evidence about the game.

The defence is the evidence

A privacy provider has at least two broad configurations. It can retain data useful to an investigator and remain legally responsive when served with compulsory process. Or it can build the system so that useful data is unavailable to the provider in the first place.

Riseup has occupied both positions, and documented one transition between them. Its canary statement from February 2017 records compliance with two sealed FBI warrants, with the alternatives described as contempt, imprisonment for volunteers, or the end of the organisation. Personally encrypted storage followed, so that there would be less useful information to hand over next time.

That second configuration is broadly the one A/I had adopted. Two days after the designation, Noblogs was breached and the user database taken. The attacker obtained email addresses and hashed passwords. Not IP addresses. A/I did not keep them. The architecture limited what the breach could reveal.

Under the State Department fact sheet, however, that same design choice is presented as evidence of infrastructure intended to keep users anonymous, untraceable and beyond the reach of law.

The two games therefore become coupled. A provider improving its position on one axis moves along another axis at the same time, and may find that the improvement in one game worsens its position in the other.

There is no stable point at which the provider can simply hold still.

Evidence not yet in

The next moves are more informative than the case as first stated. A second European infrastructure provider on the list would be consistent with the category expanding. If displaced users continue moving towards American providers while no further European infrastructure provider is designated, that would be consistent with the herding hypothesis, although it would not prove it.

Pressure on Riseup, or on another provider inside US jurisdiction, would point towards a different hypothesis: that the infrastructure itself is the object and jurisdiction is only the route.

A penalty actually levied on a bank or registrar would be evidence that the threat is being carried through rather than merely displayed. A threat that is never exercised eventually becomes part of the furniture.

A court striking the designation down would provide evidence about the durability of the precedent, rather than about the intentions behind it.

OFAC has added no other European privacy provider between 26 August and 21 September. Twenty-six days of nothing is not yet a pattern.

Nobody left to sue

Shideler’s piece also anticipated litigation, describing the possibility of a carefully selected test case aimed at obtaining a sympathetic ruling. That expectation did not survive the eleven days. Dissolution removed the plaintiff along with the target, and a designation with nobody left to challenge it becomes a precedent that no court has examined.

The application filed at Pisa on 8 September tests whether an Italian bank may freeze funds on the basis of a foreign listing. It does not test the designation itself.

This creates an information problem. A test case might have required a US court to address whether hosting, political affinity and refusal to log could together constitute material support. It could also have failed, producing an answer less useful than the collective hoped for. With no test case, the question stays open, and an open question keeps the cost high for the next intermediary that faces the choice.

The collective therefore achieved something at the same time as it lost something. It ended its participation in the local game on its own terms, refusing to let the remaining damage propagate to the people standing nearby. It may also have removed the occasion on which the larger game would have been forced to reveal itself.

Whether that trade was worth making is not a number available to the model. The value of a favourable ruling that might never have arrived would have to be weighed against the certainty of the damage while waiting for it. Those are different kinds of payoff, and the collective was not the only player bearing them.

Dissolving was one of the four things the collective could do. The game-theoretic model scores it like any other move.

It was not a move.

Partially blind matrix

Payoffs and expected loss describe a bank rather neatly. They describe an institution that can price its exposure and decide what to do with the number. They describe much less well what disappears when the provider does.

A/I’s own published figures gave roughly 12,000 mailboxes, more than a thousand websites, over 3,000 blogs and around 3,000 mailing lists. Il Fatto Quotidiano put the totals higher on 7 September: over 16,000 encrypted mailboxes, around 10,000 blogs, more than 7,000 websites and hosting spaces, and thousands of mailing lists. The numbers differ between sources, and nobody will reconcile them now that the machines are off. The infrastructure was not a pile of interchangeable accounts.

A mailing list is the membership record, the archive of decisions and the only route to people who never supplied a phone number. A blog on Noblogs was publishing that existed nowhere else. The platform had been running since 2007, and what was on it is a primary archive.

An autistici.org or inventati.org address was, for some users, the recovery address for a bank account, government login or professional registration. Losing the mailbox is then not simply losing correspondence. It means losing the ability to prove identity to every other system that points at it.

Legal support, solidarity and advocacy networks lost published contact addresses. Journalists lost routes to sources. A journalist may now hesitate before contacting a source at an address named in a public statement as belonging to a sanctioned collective.

And there is another category that the game-theoretic model sees only as an externality: everyone who had a commercial relationship with A/I. The Treasury issued General Licence 36 specifically so those parties could wind down their dealings without being penalised for the dealing itself. Suppliers, the bank, the registry and the hosting partners all had to unwind their dealings. The licence is therefore a concrete measure of the blast radius.

The same principle has a less abstract precedent. When Karim Khan, the ICC chief prosecutor, was designated in February 2025 after seeking an arrest warrant for Benjamin Netanyahu, his accounts were frozen and his Microsoft-hosted mailbox stopped working. Microsoft first told a Commons committee that the decision had been the Court’s, then corrected the record: it had told the ICC that Khan’s access must be denied or it would end email for the entire organisation. The ICC denied his access, and later moved off Microsoft altogether. Microsoft’s president has separately denied that the company cut services to the Court at all.

The correction is the mechanism rather than a detail of it. Responsibility for the decision moved between provider and institution in public and on the record, while the designation never had to name the provider at all.

A mailbox is infrastructure.

The same designation can reach a prosecutor in The Hague and a squat’s newsletter in Pisa. The game does not require them to be equivalent. It only requires the intermediary to decide that keeping the relationship has become more expensive than ending it.

Update, 21 September

Hours after publication, Reuters and others reported that the administration has prepared sanctions against the International Criminal Court as an institution, not yet announced: US persons barred from providing the Court with money, goods or services without a Treasury licence, after a grace period of six to seven months. A/I had about a month. De Volkskrant adds that the Netherlands, which hosts the Court, is working out how to keep paying staff and protected witnesses, and has so far held back from pressing for the European blocking statute, for fear of escalating the conflict with the United States. A government weighing the cost of invoking the statute against the cost of escalation is the intermediary’s problem, one level up.

Further resources

The literature below is about states, banks and firms. The overcompliance mechanism and the dollar-clearing asymmetry transfer to a volunteer association running mailboxes. Nothing in it contemplates a target whose product is other people’s communications.

  • ECFR, Ellie Geranmayeh and Manuel Lafont Rapnouil, Meeting the challenge of secondary sanctions, June 2019, for overcompliance under a framework nobody can map, and for the ambiguity read as deliberate
  • SWP, Sascha Lohmann, Extraterritorial U.S. Sanctions, SWP Comment 5/2019, February 2019, for conduct that is sanctionable rather than prohibited; open-access copy at https://www.ssoar.info/ssoar/handle/document/61664
  • SWP, Barbara Lippert and Stefan Mair ( eds), With, Without, Against Washington: Redefining Europe’s Relations With the United States, March 2026, for chapter five on what happens if Washington weaponises Europe’s dependence on US technology
  • Clingendael, Floor Stoelinga, Kaspar Pucek and Rem Korteweg, Dealing with Third-Country Involvement in Sanctions Evasion, November 2025, for the European framework’s own extraterritorial dimension, from the standing Clingendael Sanctions Network https://www.clingendael.org/event/clingendael-sanctions-network
  • Clingendael, Coercive Extractivism https://www.clingendael.org/publication/coercive-extractivism-mechanics-trumps-transactional-approach-europe, for the mechanics of leveraging European dependencies to extract concessions
  • Bruegel, Jean Pisani-Ferry, Beatrice Weder di Mauro and Jeromin Zettelmeyer, How to de-risk: European economic security in a world of interdependence, May 2024, for why product-level dependencies cannot be identified reliably even with good data, so that missed dependencies and false positives are both inevitable
  • Bruegel, Maria Demertzis, De-dollarisation is all about de-risking, May 2024, for the currency as settlement infrastructure rather than as store of value
  • Bruegel, Francesco Papadia and Konstantinos Efstathiou, The international role of the euro, December 2018, for the extraterritorial reach of US rules as a function of the dollar’s international role