The Full Threat Surface
Four dimensions — geography, architecture, governance, adversarial intent — asked simultaneously about one system, and the governance gap no institution owns.
Since 7 July 2026, every new car and van registered in the EU must carry an infrared camera aimed at the driver's face - the Advanced Driver Distraction Warning (ADDW), specified under the General Safety Regulation. It tracks gaze, warns after 3.5 seconds' distraction above 50 km/h, and cannot be permanently turned off. The safety case is real (the wider package is projected to save 25,000+ lives by 2038) and the rule prohibits facial recognition. But the regulation mandates the hardware while leaving the data surface unanswered - retention, sharing, insurer and law-enforcement access - and the same automakers now installing it have already been documented collecting, sharing, and losing connected-vehicle data. The stronger concern is structural: the camera is always-on infrastructure, and the Commission has committed to further ADDW requirements by July 2027. My assessment: this is 'every box is governed, the space between is no one's job' arriving on the road. The camera cannot be turned off - and who benefits from what it sees, beyond the driver, is still being answered by the parties with the most incentive to answer it in their own favour.
Is there an industry ShinyHunters has not breached lately? Food distribution, healthcare, higher education, entertainment, telecoms, finance, the Council of Europe. Sysco: 61 million Salesforce records claimed on 16 June, published after the 18 June deadline, 2,691,852 confirmed on HaveIBeenPwned by 28 June. The question is not who they target. It is whether sector, size, and security budget are all secondary to one variable: whether an unrevoked OAuth token is sitting in your Salesforce connected apps or a 2023 code commit. My assessment: ShinyHunters is not a group you arrest but a brand and a playbook that outlive their operators — one industrialised technique (voice-phish an employee or scan GitHub for forgotten tokens, both bypassing passwords; enumerate the CRM; loop and exfiltrate; extort). The reason the industry keeps being surprised is not sophistication. It is that the monitoring is pointed at the boxes, and the attack happens in the space between them. Every box is governed — identity, exposure, data, software, AI, supply chain, governance. The space between is no one's job. That argument is now a book: The Wrong Map, reading cybersecurity as political economy across Susan Strange's four structures. Contributors welcome — especially the dissenters.
From a conference stage, Claus Balslev, head of digitalisation at Denmark's STAR labour-market agency, said the sentence everyone hedges around: if you put data in a US cloud, you share it directly with the US intelligence service. Then he acted on it, migrating STAR's systems off Microsoft and onto European cloud in roughly nine months, and saving money doing it. My assessment: the statement is not rhetoric, it is the precise legal architecture. The CLOUD Act attaches jurisdiction to the US entity, not the data; FISA 702 authorises bulk collection from US providers with no warrant and a gag order; RISAA (2024) extends reach toward the silicon itself; and the 12 June 2026 Fable/Mythos AI suspension proved Washington can switch off the capability globally by letter. Asked under oath before the French Senate in 2025 whether Microsoft could guarantee EU data is never sent to US authorities, Microsoft France's legal-affairs director answered: no. This is not a governance gap but a governance collision, two irreconcilable legal systems applied to the same data, which is why Safe Harbor, Privacy Shield, and soon the current framework all fall. Residency is where the bits sit; sovereignty is who controls access. STAR removed the last excuse, and the AI layer is the next Schrems ruling.
The United States and Iran are the ones signing the deal that ended the 2026 Iran war. Qatar and the UAE are the ones who actually made it possible. The UAE has unlocked $10B for Iran with $3B+ already delivered, in exchange for halted attacks and economic-intelligence cooperation. Qatar holds $6–12B in Iranian frozen assets under custody — the $6B from the September 2023 South Korea transfer, restricted to humanitarian use, never released after October 7. Tehran cannot access any of it without Doha. This is the first major US–Iran deal in fifty years not architected by the United States. The Full Threat Surface framework applied to the deal across four dimensions — physical geography (Hormuz, Al Udeid, the dual-track positioning), logical architecture (the three-layer financial mechanism), governance architecture (the ad-hoc enforcement coalition with no precedent), and adversarial intent (Iranian pragmatists vs hardliners, UAE $500B self-preservation, Qatar's strategic positioning, Trump's narrative needs, Israel's disruption vector). The predictive intelligence layer: four probability-banded scenarios across the oil path from current $80s through December 2027, mapped against Gulf fiscal break-evens (KSA $80, UAE $60, Qatar $45, Kuwait $70). The deeper question the diplomatic coverage is not asking: whether the Gulf states can sustain the mediation through the recession their own success helped to create.
The operational lesson of the Fable 5 and Mythos 5 suspension is not about whether the directive was justified. It is about what it demonstrated: every non-US enterprise running production AI workloads on a US-headquartered frontier model is, structurally, one letter away from an outage that no contract, no regional setting, and no sovereign cloud reseller can prevent. Anthropic had to “abruptly disable” both models for all customers globally to comply — within hours of receiving the 5:21pm ET letter. Three categories of exposure: hard-coded production dependencies, research collaborations with non-US personnel, and government / regulated-industry partnerships (TCS-50K-users-across-56-countries, DXC-banking, all in scope). The full threat surface framework now treats provider home jurisdiction as a primary variable. Single-provider risk is single-sovereign risk. The failover architecture that survives the next 5:21pm letter, with five cross-cutting controls (contract, cache, drill, audit, board), the sovereignty risk matrix across seven provider categories, and the action list for the next four working days under DORA, NIS2, the EU AI Act, and the Tech Sovereignty Package.
Part III of the Governance Gap trilogy. The class of risks where post-activation governance cannot reverse the consequences. Three thresholds: the Kessler cascade in LEO that becomes self-sustaining once triggered, the HNDL harvest already in progress against the Mosca inequality (15-year confidentiality data generated from 2020 onwards is already in the risk window), and the inference permanence where Yeagley’s behavioural model meets Q-Day content decryption. The 1,400-fold qubit reduction in three months. Google’s 2029 internal deadline. CNSA 2.0 in January 2027. DORA quantum risk monitoring active since January 2025. The governance gap that cannot be closed after the risk activates — because the activation itself changes the conditions under which governance is possible. The time to close it is before the activation. The Chokepoint Doctrine series, complete.
Part II of the Governance Gap trilogy. The operational requirement that follows from the strategic finding: every security architecture is built against the threat model that the current architecture was already adequate to detect — which means the threat operating in the governance gap is, by definition, the one your architecture cannot see. The four wrong questions enterprise security is organised to answer (compliance, breach, supply chain, incident response) and the right ones (adversarial view, inference, shared infrastructure, intersection) that the full threat surface framework requires. France Titres, Snowflake, Trellix, the NIS2 / NiS2 chemical-plant scenario — each as evidence the gap is operational, not theoretical.
Part I of the Governance Gap trilogy. The Chokepoint Doctrine series’ central finding, stated as its central thesis for the first time: no institution has the mandate, the expertise, and the authority to govern the full threat surface of any critical system simultaneously, and the adversary’s operational architecture is specifically designed to exploit the space between the institutions that cannot coordinate fast enough. The three wrong questions Western institutions are asking — What is the adversary doing? Which institution is responsible? How do we deter the adversary? — and the right questions that should replace them. The governance gap is the chokepoint. Everything the series has documented is a symptom.
You type NIS2 into your regulatory database. It returns two results: the EU cybersecurity directive that just took effect in Sweden, and nickel disulfide — a Group 1 human carcinogen. If you work in Swedish chemical manufacturing, both are now your problem simultaneously, governed by three different regulators with no coordination between them. This is the governance gap where the incident happens.
The Chokepoint Doctrine. Subsea cable infrastructure does not fit cleanly into any existing critical infrastructure mechanism. It falls between sectors, belongs to no single agency, and has no Tier-1 classification — yet it carries 95% of intercontinental data. The Iran war arrived into that governance gap at the worst possible moment.