Three weeks ago on this blog I wrote about Autistici/Inventati, the Italian hacktivist collective that spent twenty five years running privacy first email, hosting and mailing lists for activists who wanted infrastructure that would not sell them out. I closed that piece with an open question about where the line sits between offering secure tools and being blamed for what people do with them. I did not expect an answer this fast, and I certainly did not expect it to arrive not from a courtroom but from a domain registry status flag and a compliance officer’s spreadsheet. This story is too important to let go after a single post, so I am back on it, because what happened to A/I in the weeks since is less a tale about one small Italian collective and more a live demonstration of how little sovereignty Europe actually has over the piece of the internet it thinks it owns.

In brief

  • On 26 August 2026 the US designated Autistici/Inventati a Specially Designated Global Terrorist, and by 6 September the collective had announced its shutdown.
  • The kill chain never touched an Italian courtroom: a serverHold flag on autistici.org placed by the US based Public Interest Registry, a closed PayPal gateway and a frozen Banca Etica account did the work.
  • An OFAC listing carries no freezing obligation under Italian law, as the UIF states explicitly, yet Banca Etica suspended the account anyway on a secondary sanctions risk calculation.
  • Autistici/Inventati filed an urgent injunction against Banca Etica at the Tribunale di Pisa on 8 September, asking for the account to be restored or the balance released.
  • The same chokepoints, from .org domains to Visa and Mastercard rails to US headquartered clouds under the CLOUD Act, sit under every layer of Europe’s digital stack.
  • France’s Linux migration and the EU Cloud Sovereignty Framework show the direction of travel, but the scale gap with US hyperscalers remains enormous.

Twelve days from a press release to a blackout

On 26 August 2026 the US Departments of State and the Treasury designated Autistici/Inventati a Specially Designated Global Terrorist under Executive Order 13224, giving the collective a wind down deadline of 25 September and warning that anyone who kept engaging with it risked exposure to secondary sanctions. What followed was a cascade of infrastructure failures that happened almost entirely outside Italy’s jurisdiction, without a single legal step along the way. Within days, one of A/I’s core domains became unreachable at the DNS level, its PayPal donation gateway was shut down, and its Italian bank account was frozen. On 6 September the collective announced it would shut down for good, explicitly to protect its roughly twenty thousand mailbox holders, twenty thousand blogs and thousands of mailing lists from further exposure, a sequence of events reconstructed in detail by TechRadar’s investigation into the case.

The domain failure is the detail worth sitting with. A/I’s own account, relayed by the same investigation, points to the Public Interest Registry, the US based nonprofit that operates the entire .org namespace, as having placed autistici.org into a serverHold status as a direct consequence of the sanctions, severing the mapping between the name and the servers behind it without touching a single physical machine. Nobody had to raid a data center in San Giuliano Terme. Nobody had to prove anything in front of an Italian judge. A single administrative decision, taken by an organization headquartered in Virginia and governed by US law, was enough to make a piece of Italian civil society vanish from the browsers of people who typed its name.

The reactions from digital rights organizations were sharp. EDRi, together with more than thirty other groups, described the designation as an attack on independent internet infrastructure and on the democratic integrity of the EU. The Electronic Frontier Foundation’s Jillian York told Italian broadcaster Rai News that the move effectively targets the messenger rather than anyone who committed an act of violence, since what the US government is really punishing is the freedom to host anonymously, not a specific crime. Harry Halpin, who runs the privacy focused Nym Technologies, drew the obvious lesson for anyone still building centralized privacy infrastructure: a government can take down centralized domains and bank accounts in a matter of days, so resilience now has to be designed in from the start rather than assumed. It is a hard thing to hear if you have spent a career, as I have, thinking about DFIR and OSINT in terms of servers, logs and jurisdictions that map neatly onto physical geography. A/I’s shutdown shows that the actual chokepoints are administrative, contractual and largely invisible until the day someone decides to pull the lever.

A blacklist that, legally, freezes nothing

The most instructive part of this story, and the one least reported outside Italy, is what happened at Banca Etica, the ethical bank where A/I had held its current account since 2018. On 1 September, six days after the OFAC designation, Banca Etica suspended all operations on the account, citing the risk of secondary sanctions that could theoretically cascade onto its own 130,000 customers through their Visa and Mastercard linked cards, as reported by il manifesto and Valori.it. The bank then moved toward closing the relationship outright and, according to A/I’s lawyer Fausto Gianelli, effectively froze the funds in a way that prevented the collective from even transferring its own donation money elsewhere, a move that pushed A/I to file an urgent injunction against Banca Etica at the Tribunale di Pisa on 8 September, asking either for the account to be reinstated or for the balance to be released to an account of its choosing, as detailed by Altreconomia and Byte.it.

Here is the part that gets lost in most of the coverage: an entry on the OFAC Specially Designated Nationals list does not, by itself, create a legal obligation for an Italian bank to freeze anything. Italy’s anti terrorism financing framework runs through EU regulations and the consolidated European sanctions list managed at the EU level, and Italy’s own Financial Intelligence Unit, the UIF at Banca d’Italia, states plainly on its website that while it circulates the OFAC list to support banks’ own monitoring, inclusion on that list does not carry a freezing obligation under Italian law, a distinction confirmed independently by legal analysis published on dirittobancario.it. What actually froze A/I’s account was not a legal duty but a risk calculation: US law allows secondary sanctions against foreign financial institutions that keep serving a designated entity, and no Italian bank wants to find out the hard way whether its own dollar clearing relationships would survive testing that theory. In other words, a piece of US foreign policy achieved, through the private risk aversion of an Italian bank, an outcome that Italian and European law never actually required. Sovereignty, in any meaningful sense, would have allowed an Italian bank to say no. Instead, Washington now holds a permanent standing invitation to reach into any European balance sheet it wants, kept open simply by making the cost of resistance high enough that compliance becomes the rational choice for anyone with shareholders, or in Banca Etica’s case, 130,000 ordinary account holders, to answer to.

The chokepoints nobody elected

Zoom out from A/I and the same pattern repeats at every layer of the stack that Europeans use every day without thinking about who actually controls it. Generic top level domains like .com, .org and .net are administered by US based registries operating under contracts with ICANN, itself a California nonprofit, which is exactly the mechanism that made autistici.org disappear on command. Card payments running through Visa and Mastercard, and increasingly cross border transfers touching correspondent banks with US dollar exposure, give Washington leverage over transactions that never cross an American border. And then there is the cloud, where the US CLOUD Act of 2018 allows American law enforcement to compel US headquartered providers to hand over data they control, regardless of where the servers physically sit, a conflict with GDPR that the Court of Justice of the EU has acknowledged since the Schrems II ruling and that has never been cleanly resolved, as summarized in a recent legal white paper on the CLOUD Act versus European data sovereignty.

The European Commission has finally started treating this as a structural problem rather than a compliance footnote. In April 2026 it awarded its first ever cloud contract, worth €180 million, using an explicit Cloud Sovereignty Framework that scores providers across eight criteria including legal jurisdiction and supply chain transparency, and by June it had presented legislation that would bar Amazon, Microsoft and Google from the most sensitive government workloads unless they meet ownership and control thresholds that a US parent company structurally cannot satisfy, as reported by TechTimes and CNBC. Even the hyperscalers’ own “sovereign cloud” offerings, AWS’s European Sovereign Cloud in Brandenburg, Microsoft’s Cloud for Sovereignty, Google’s T-Systems partnership in Germany, do not really solve the underlying problem, since the contested point is jurisdiction over the parent company rather than where the racks physically sit, a nuance well explained in Qovery’s 2026 map of EU sovereign cloud platforms. Critics have not been shy about calling some of these arrangements sovereignty washing, a compromise dressed up as independence.

Europe’s uneven march toward disentanglement

None of this is purely theoretical anymore, and here France offers the most concrete counter example to A/I’s fate. The French Gendarmerie has run its own Ubuntu based build, GendBuntu, since 2008, covering 97 percent of its computing estate by mid 2024 and saving an estimated two million euros a year in licensing costs, according to reporting by TechHQ. That two decade track record is precisely why, in April 2026, France’s Interministerial Digital Directorate ordered every ministry to submit concrete reduction plans by autumn 2026 across eight dependency categories, from operating systems to cloud infrastructure, with the desktop migration itself targeted for 2030. The directive builds on the January 2026 mandate to replace Microsoft Teams and Zoom with the domestically built La Suite Numérique across 2.5 million civil servant workstations by 2027, as covered by TheNextWeb. Public Accounts Minister David Amiel put it bluntly: the goal is to regain control of the country’s digital destiny, not to save money on licenses, though the savings help make the political case.

Germany’s Schleswig Holstein is running a similar transition on a smaller scale, and the broader EU sovereign cloud market, still under fifteen percent of total EU cloud spending according to Synergy Research Group data cited by Qovery, is starting to see real money move toward providers like OVHcloud, Scaleway, Hetzner and IONOS. The scale gap remains enormous: US hyperscalers are collectively investing around 600 billion dollars in cloud and AI infrastructure in 2026 alone, according to ASEE, so nobody should mistake a handful of ministry pilot programs and a €180 million procurement tender for parity. But the direction of travel has changed in a way it had not five years ago, driven less by idealism than by the accumulating weight of episodes exactly like Autistici/Inventati, where infrastructure that Europe assumed was neutral turned out to have an off switch located somewhere between Virginia and the US Treasury building.

What A/I’s disappearance really did was compress into twelve visible days a dependency that usually stays comfortably abstract, buried in terms of service nobody reads and jurisdiction clauses nobody negotiates. A small, donation funded, entirely legal Italian nonprofit ran on infrastructure that looked distributed and resilient until the moment someone in Washington decided otherwise, and then it turned out that a registry, a payment processor and a single bank’s risk committee were the only three switches that mattered. If that is true for a hacktivist collective with twenty thousand mailboxes, it is worth asking, calmly and without the melodrama this topic usually attracts, exactly how different the picture looks for a European ministry running its email on a hyperscaler, a hospital storing patient records in someone else’s data center, or a bank clearing payments through rails it does not own. I do not think anyone in Brussels, or in San Giuliano Terme, has a comfortable answer to that yet.

FAQ

Why did Autistici/Inventati disappear so quickly after the US designation?

No court ordered its shutdown. Within days of the OFAC designation the Public Interest Registry placed autistici.org in serverHold status, PayPal closed its donation gateway and Banca Etica suspended its account, so the collective shut down on 6 September to protect its roughly twenty thousand mailbox holders from further exposure.

Was Banca Etica legally obliged to freeze Autistici/Inventati’s account?

No. An OFAC listing does not carry a freezing obligation under Italian law, as the UIF at Banca d’Italia states explicitly. Banca Etica acted on a risk calculation about US secondary sanctions, which is why Autistici/Inventati filed an urgent injunction at the Tribunale di Pisa on 8 September.

What does the Autistici/Inventati case reveal about European digital sovereignty?

It shows that critical European infrastructure, from .org domains to payment rails and cloud services, depends on administrative chokepoints under US jurisdiction that can be activated without any European legal process, which is why the EU is now pushing its own Cloud Sovereignty Framework.