14 September 2026

The US Designates Italian Autistici/Inventati as a Global Terrorist

How US Sanctions Expose the EU’s Inability to Set the Terms for Its Own Infrastructure

On 26 August 2026, the US Department of State designated Autistici/Inventati (A/I), a volunteer-run Italian technology collective that has provided encrypted email and hosting to activist groups since 2001, as a Specially Designated Global Terrorist under Executive Order 13224. The designation freezes all A/I assets under US jurisdiction. After a wind-down deadline of 25 September, any US person or entity is prohibited from transacting with the collective. But the freeze itself is probably the least significant part of the measure. What matters is the compliance cascade it sets in motion: banks, payment processors, domain registrars, hosting providers, and certificate authorities that maintain any dollar-denominated nexus face obligations that make continued dealings with a designated entity commercially untenable. The effect is expulsion from the infrastructure of digital existence, without any court in Italy ever having issued a ruling.

Early commentary has correctly identified the de-risking mechanism at work. Beniamino Irdi, at the German Marshall Fund, observed that the designation targets infrastructure rather than operations, and that the real bite lies in preemptive severance by intermediaries. This is accurate, but it treats the designation as a standalone event. It was not. The A/I case is the first operational output of a policy architecture that was declared publicly, built over six months, and documented on primary US government sources throughout. That architecture, not the individual designation, is the problem European democracies need to engage with.

The Doctrinal Sequence

On 6 May 2026, the White House released its Counterterrorism Strategy (CT) for the second Trump term. The document places “Violent Left-Wing Extremists, including Anarchists and Anti-Fascists” at the same doctrinal level as al-Qaeda and the Sinaloa Cartel. The phrasing is an open list: “including” does not close the set. In the same month, the State Department convened the Counter Terrorism Law Enforcement Workshop, a practitioner-level forum with 14 countries, designed to build operational coordination below ministerial visibility before the political framework was announced. On 16 July, Secretary Rubio hosted the Ministerial on the Resurgence of Political Terrorism with 66 countries. Secretary Bessent used the occasion to commit the Treasury to pursuing enablers “however distant their jurisdictions”, a public articulation of extraterritorial financial enforcement against infrastructure providers. On the same day, the State Department announced visa restrictions targeting “Far-Left Terrorist and other aligned groups”, extending targeted conduct to “economic sabotage” (a term that does not appear in US counterterrorism statutory language under 18 U.S.C. § 2331) and explicitly aiming to disrupt networks “before they escalate to criminal action”. Six weeks later, A/I was designated as a global terrorist organisation. The gap between the CT Strategy and the designation was 112 days. No new authority, no new category, and no new executive order was required.

Governance by Friction

The most common misreading of the A/I designation is to assess it as a traditional sanctions case. A/I has no meaningful assets under US jurisdiction. The freeze is operationally marginal. But that is not where the enforcement happens. What the designation triggers is what I have elsewhere called governance by friction: the capacity to exclude an entity from the global services market through the compliance architecture of intermediaries, rather than through direct coercion. When Office of Foreign Assets Control (OFAC) places an entity on the Specially Designated Nationals (SDN) list, every node in the service supply chain recalibrates. Banks conducting dollar clearing must screen against the list. Foreign financial institutions face secondary sanctions if they facilitate significant transactions for the designated entity. Payment processors, registrars, hosting providers, and certificate authorities face a different but functionally equivalent pressure: any US-person nexus in their operations makes continued service a compliance risk that their counsel will not sign off on.

The anticipated result, and in prior OFAC enforcement the documented result, is that the entity loses its bank account, its domain, its payment processing, its hosting. Not because a court in its home jurisdiction examined evidence, but because the compliance logic of dollar-denominated infrastructure makes continued service commercially irrational for every intermediary in the chain. No Italian judge weighed the facts. No Italian prosecutor has publicly opened an investigation. No adversarial proceeding tested the designation’s basis. The enforcement operates through the architecture of incentives, outside any constitutionally bounded legal order.

Europe’s Structural Exposure

The question for European legal orders is not whether the EU will be asked to adopt the US designation. It is whether European adoption is necessary at all for the designation to take effect. On current infrastructure, it is not. Euro-denominated stablecoins authorised under MiCA have a combined market capitalisation below one percent of the dollar stablecoin market. The digital euro is years from deployment. Cross-border correspondent banking routes overwhelmingly through dollar clearing, where OFAC compliance is a precondition for access. A US designation against a European entity therefore produces extraterritorial enforcement effects without requiring any European legal act.

The EU has instruments that are formally designed to address this. Council Regulation 2271/96, the Blocking Statute, prohibits EU persons from complying with listed extraterritorial legislation, and its annex was updated in 2018 in response to reimposed US sanctions on Iran. But the Statute has never been effectively enforced in a comparable case. Its scope covers only regulations and decisions listed in the annex, which does not include the current US designation framework. And even if updated, the Statute places European companies in a bind between US sanctions exposure and EU non-compliance obligations without offering a workable path through the conflict. In practice, companies have consistently chosen dollar-clearing access over Blocking Statute compliance, and the Commission has never imposed penalties for that choice.

The CJEU’s jurisprudence offers partial but insufficient coverage. Kadi II (joined cases C-584/10 P, C-593/10 P and C-595/10 P) established due process and judicial review requirements for the EU’s own restrictive measures. More recently, in Jenec (Case C-81/24, June 2026), the Court held that a bank established in the EU may not refuse a basic payment account to a consumer solely on the basis of an OFAC listing; a refusal is permissible only after an individual risk assessment under EU anti-money laundering law. Jenec matters: it confirms that EU courts will scrutinise compliance decisions driven by third-country designations. But its scope is narrow. It applies to basic payment accounts for natural persons. A/I is an organisational entity. And even extended by analogy, Jenec addresses banking access alone. Domain registration, hosting, payment processing, certificate authorities, correspondent banking pressure, the rest of the supply chain through which governance by friction operates, remain untouched.

Together, the Blocking Statute, Kadi, and Jenec mark what European law currently offers. The instruments exist in principle. None of them, alone or combined, closes the gap between a US administrative determination and its self-executing effects on European soil.

What Is at Stake

Whether one agrees with the characterisation of A/I as a terrorist entity is a separate matter. Reasonable people hold different views on the risks of privacy infrastructure that is available to violent actors alongside journalists, activists, and dissidents. The constitutional question is different: whether an entity located in Europe, operating under European law, and composed of European citizens can be functionally excluded from economic and digital existence by an administrative determination of a foreign government, without European judicial process and without any institutional mechanism for review.

On current infrastructure dependencies, the answer is yes. Changing it requires extending Jenec’s individual risk assessment requirement beyond payment accounts to essential digital services: hosting, domain registration, payment processing. It requires a mechanism for reviewing the domestic effects of third-country designations on European entities, which does not currently exist. And it requires reducing the infrastructure dependencies that make foreign administrative determinations self-executing in Europe, from euro-denominated payment alternatives to European domain and certification services to a digital euro that provides clearing outside third-country compliance conditions.

None of this requires the EU to take a position on whether A/I is a terrorist entity. All of it requires the EU to take a position on whether its legal order can protect its own citizens from governance effects that travel through infrastructure it does not control. That is the question the A/I case has placed on the European agenda.


SUGGESTED CITATION  Perugini, Marco: The US Designates Italian Autistici/Inventati as a Global Terrorist: How US Sanctions Expose the EU’s Inability to Set the Terms for Its Own Infrastructure, VerfBlog, 2026/9/14, https://verfassungsblog.de/the-us-designates-italian-autistici-inventati-as-a-global-terrorist/.

Leave A Comment

WRITE A COMMENT

1. We welcome your comments but you do so as our guest. Please note that we will exercise our property rights to make sure that Verfassungsblog remains a safe and attractive place for everyone. Your comment will not appear immediately but will be moderated by us. Just as with posts, we make a choice. That means not all submitted comments will be published.

2. We expect comments to be matter-of-fact, on-topic and free of sarcasm, innuendo and ad personam arguments.

3. Racist, sexist and otherwise discriminatory comments will not be published.

4. Comments under pseudonym are allowed but a valid email address is obligatory. The use of more than one pseudonym is not allowed.