In early October, Virtual Routes Co-Directors James Shires and Max Smeets contributed to a Study Visit on Cyber/ICT Security for National CBM 8 Points of Contact organised by the Organization for Security and Co-operation in Europe (OSCE), which took place in Zug and Zurich, Switzerland. The study visit brought together the national Points of Contact who serve as the OSCE’s network for cyber/ICT confidence-building measures (CBMs).
The week opened in Zug, alongside a meeting of the Informal Working Group and the 2026 OSCE Chairpersonship Conference, “De-escalation in cyberspace: mediation and preventive diplomacy”. It continued in Zurich with a two-day workshop on mapping the implementation of OSCE cyber/ICT CBMs, where Virtual Routes contributed to three sessions.
On 1 October, James Shires facilitated a scenario-based discussion on CBM 15 and emerging technologies, which focuses on critical infrastructure protection. The exercise centred on a fictional international cyber incident involving the adoption of insecure AI technologies. As the scenario unfolded through multiple stages, participants shared their views on how to mitigate the incident and co-ordinate the response. The format gave national CBM 8 Points of Contact a practical way to work through the questions they would face in a real crisis.
That afternoon, James also spoke on a panel on critical infrastructure protection. His remarks provided an overview of the OSCE’s Handbook on National Cyber Incident Classification, which he co-authored with Serge Droz last year.
On 2 October, James Shires and Max Smeets delivered the final presentation of the workshop: an overview of recent developments in frontier AI models and what they mean for cybersecurity. They opened with high-profile incidents of inadequate safeguards in testing cyber-capable models. They then placed these incidents in the context of three broader issues: the growing role of AI in vulnerability discovery and mitigation; the secure integration of AI into organizational networks and systems; and the use of AI, including agentic tools, for cybersecurity purposes beyond vulnerability research.
Virtual Routes thanks the OSCE Transnational Threats Department for organizing the study visit, and all participants for their engagement. We look forward to continuing our work with the OSCE and participating States to strengthen the implementation of cyber/ICT confidence-building measures.