The Swedish case, written for allied readers: war scenarios today and tomorrow, knowledge as defence infrastructure, factories that survive disconnection, reprogrammable assets, and a person-carried baseline — with a worked shelter-coverage computation as the evidence.
English · Read this paper in Svenska
Sweden 2030 — A Nation in Time
By Nicolas Waern, CEO — WINNIIO AB Published: August 2026 · ORCID 0000-0001-7970-2707 · CC BY 4.0
A whitepaper for Swedish decision-makers — on knowledge as defence infrastructure, twins as rehearsal ground, and the art of changing before you must. Nicolas Waern · Gothenburg, August 2026 · ORCID 0000-0001-7970-2707
1. Red slips in a tent on Gotland
Almedalen week 2026 — Sweden's annual political gathering on Gotland — and a seminar tent on population protection. The audience has been handed red and green slips, and the moderator asks the simplest question there is: do you know where your nearest skyddsrum (public shelter) is?
Red slips. Almost nothing but red slips.
Then the panel says something that should have brought the tent to its feet. Swedish shelters were once dimensioned against a 250-kilo bomb detonating outside the wall. A Shahed drone carries a warhead of roughly 60 kilos. "They will handle Shahed drones without any problem," said the head of population protection at the FOI seminar, Almedalen 2026. "They did their homework well back then."
So concrete from the twentieth century holds against the weapons of the 2020s. We built in time.
And in the next breath came the verdict: "The problem is that we do not have shelters in the right place today."
That is this entire document, in two sentences from the same stage. The asset exists, and it holds. The knowledge about the asset — where it is, who it covers, who it misses — is not where the decisions are made. The audience did not know where the rooms are. Nobody in the tent could put a number on the gap.
The system is moving, and that should be said. Air-raid alerts can now be pushed through a mobile phone, the legislator has opened up for skyddade utrymmen (designated protective spaces) — the entrances to the Västlänken rail tunnel, parts of the metro, cellars — and replacing the Rakel emergency radio system alone means 64,000 new modems (same seminar). But movement without a map is not direction.
So we put a number on the gap.
2. We did the arithmetic
We chose Karlstad. Not by accident — Karlstad is where Socialstyrelsen's (the National Board of Health and Welfare) joint exercise Resilient Care was held in the autumn of 2025, with international military personnel and flown-in casualty role-players (FOI seminar, Almedalen 2026). If any Swedish city ought to have this under control, it is that one.
We took open data: the shelter register and population statistics. And we built the smallest possible twin of the city's population protection — a model that can answer questions, instead of a report that describes them.
The answer: 69 percent of Karlstad's population live within 500 metres of a shelter.
31,832 people do not.
That is not an estimate. It is a reading out of a model built on real registers, and it can be run again tomorrow when the register changes. The map does not know everything — it does not know the condition of the rooms, whether the doors open, who uses a wheelchair. And accessibility is, in the panel's own words, what we have "completely missed" in the existing stock. But the map knows where the rooms are and where the people live. That is enough to turn a feeling into something you can decide from.
[FIGURE NEEDED — map: shelter coverage in Karlstad, 500-metre radii, covered and uncovered areas]
And now the uncomfortable question. If a simple twin on open data is enough to set the number for one city — why does the same number not exist for all 290 municipalities? [FIGURE MISSING — verify: run the same calculation nationally against the shelter register and report it per municipality.]
3. A nation in time
The Swedish title says two things at once, and I mean both. I tid — in time, as in before it is needed. I tiden — in time, as in past, present and future as one movement.
In time — as in before. The shelters were built in time: decisions in the 1930s and 40s, concrete poured right through the Cold War, and eighty years later the same concrete stops a Shahed. That is what "in time" buys you. Then we put the thinking down for almost thirty years, and that is what "too late" costs: we no longer know where our own infrastructure does any good.
In time — as in past, present and future as a single movement. A country that is in time does three things, continuously, in a loop. It absorbs what has happened: geometry, registers, sensor data, experience — before it disappears with the people who carry it. It emulates what is: an honest, living copy of the current state that people, systems and AI can read at the same time. And it simulates what may come: tomorrow's decisions get tested against the copy instead of against the citizens.
Then there is a fourth step, and it is what this document itself is: transcend. Lock the target state — Sweden 2030 — and count backwards to Monday's decision.
[FIGURE NEEDED — loop diagram: Absorb → Emulate → Simulate → Transcend, with the frame "in time / in the flow of time"]
Why the loop, and not one more inquiry? Because statistics explain yesterday, and only simulation survives tomorrow. A trend extrapolation is a curve fitted to a past that is not coming back. The United States historically averaged about nine weather disasters a year with damages above a billion dollars; in 2024 there were 27. In the 1980s one arrived every 82 days — now every twelfth (NOAA NCEI, 2024). The exception has become the operating mode. Sweden has its own markers, the wildfires of 2018 and storm Hans in 2023, and a system drawn for one crisis a season with repairs done at leisure is now being asked whether it holds for one every twelve days. That is not a rhetorical question. It is an architecture question.
4. Today — what Ukraine has already paid to teach us
Four lessons. All of them already paid for, in blood, by somebody else. We only have to read them.
The drones. The panel in Almedalen was clear: the threat picture has turned over several times between 2024 and 2026 alone. What was a major threat in the spring of 2025 is not any more; countermeasures develop as fast as the weapons, and the spectrum runs from Shahed to FPV (FOI seminar, 2026). The conclusion is not "buy system X". The conclusion is that whoever locks onto one threat loses to the next. The only thing that holds over time is the ability to change direction faster than the threat — reprogrammability, not gadget.
The mass-casualty events. FOI, commissioned by Socialstyrelsen, has built the MASK 2.0 tool and delivered it to all 21 regions: a modular scenario package plus software, NATO-aligned, built on collected data from civilian mass-casualty events in Ukraine. One preparedness manager on the panel called the tool "terrible, because all of a sudden it became fact, and concrete" — and observed that we are now "actually building a totalförsvar (total defence) out of knowledge and science, and not out of qualified guesses" (FOI seminar, 2026). Notice what MASK fundamentally is: a simulation on an emulation of reality. Sweden is already working exactly the way this document argues for — in one sector, against one threat. So why should the method stop there?
Decentralized care. "We survived because we were underground" — care in protected premises, in other locations, was nothing Ukraine planned for before the war broke out. "Civilian hospitals carry the burden of war", as a Ukrainian colleague of the panel put it. And the survival mechanism they pointed to was decentralization: autonomous units with a shared target picture that know where support is (FOI seminar, 2026). Sweden has the base plate — at the school attack in Örebro a bus, a helicopter and redirected ambulances stood ready twenty minutes after the alarm, according to the panel's own account. But the scale is a different matter: Region Värmland, 285,000 inhabitants and 8,000 employees, expects to need 2,000–3,000 civilian volunteers in its scenarios. "Where are they today? Well, we do not really know." That is not a resource gap. It is a knowledge gap.
The open APIs. Ukraine's armed forces opened APIs for the air picture. People who can program built apps. The population learned to read the air situation — "that knowledge is common property in Ukraine now" (FOI seminar, 2026). And the panel's most important subordinate clause was this one: decisions like that are easier to make in war than in peace. Read that sentence again. It means peace is our handicap — unless we decide to use it as a head start. Evacuation doctrine is knowledge too, not reflex: Ukraine evacuates on ministerial order and only where there is a risk of occupation; this autumn the Swedish county administrative boards begin their own evacuation planning (same seminar).
Underneath all of it, the infrastructure lesson. At worst roughly 65 percent of Ukraine's power grid was knocked out, and national roaming between the mobile operators was in place in about a week (ITU, 2023). In December 2023 the operator Kyivstar was taken down in a cyberattack that hit on the order of 24 million subscribers (CERT-UA, 2023). The cloud is no sanctuary, and the biggest node is still a node. Survival sat in the dispersal.
5. Tomorrow — the war on knowledge
The next attack on Sweden does not have to begin with something that explodes.
Knowledge as the target. An adversary who wants to stop Swedish supply or Swedish defence industry does not need to bomb factories. It is enough to make two or three people unavailable — recruited, pressured, or simply gone — if it is in their heads that the process knowledge lives. And the target list is not secret. It can be derived from a supply-chain map, a company registration and a LinkedIn search. Externalizing knowledge is therefore not an efficiency measure. It is attack-surface reduction: what sits in an owned, local artifact cannot be carried out through the door.
Disturbed time, disturbed position, disturbed power. You do not even need an enemy to see the vulnerability. In May 2024 came the Gannon storm, the first geomagnetic storm at the highest level in more than two decades (NOAA SWPC, 2024). High-accuracy GPS degraded down to roughly latitude 49°N for 15 to 20 hours (Yang, 2025). All of Sweden lies north of that line. And a 5G network needs GPS-borne timing accurate to around 240 nanoseconds (NIST TN 2189) — so the same disturbance attacks the power grid and the timekeeping at once, and the network that was supposed to report the fault falls with the fault. Power is the substrate everything else silently assumes: in the spring of 2025 roughly 15 gigawatts dropped out of the Iberian grid in about five seconds (Red Eléctrica/ENTSO-E, 2025). Everything was intact. Everything stood still. The requirement on the Swedish side is not exotic: holdover clocks and time sources independent of GNSS in critical infrastructure.
The twin as a target. Everything this document argues for — externalized knowledge, living models of reality — is itself valuable to an attacker. That objection is correct, and it has to be met with architecture, not with promises: classification per layer, crypto keys held locally, sharing through differential privacy and federated methods (Dwork & Roth, 2014) — and physical custody of the data. Because the law is unambiguous: the CLOUD Act gives US authorities the right to compel US providers to hand over data regardless of where in the world it is stored (Pub. L. 115-141, 2018). A contract does not protect you against another state's legislation; only architecture does. The software may well be open source. The data is sovereign. And do not forget the quietest form of attack: data can sit intact on servers the attack never reached and still be gone — because nobody can authenticate against them any more. The login is a front line too.
Harvest now, decrypt later. An adversary copying encrypted Swedish traffic today does not need to be able to read it today. Health data, network topologies, long-lived archives — everything that has to stay protected for fifty years but is encrypted with methods that may hold for ten is already collectable. A fifty-year secret behind a ten-year lock is not protection. It is a schedule. And the answer has existed since August 2024, when NIST ratified the post-quantum standards FIPS 203, 204 and 205. Post-quantum from the first byte in every new archive — and crypto-agility built in, so that the next shift does not require a rebuild.
6. The mechanisms
Knowledge is defence infrastructure — the invisible kind
What follows is a composite archetype, and it is expressly labelled as one. No single company — but no invention either. I have worked close to Swedish steel, and the pattern is the same almost everywhere.
A mid-sized Swedish steel fabricator. Certified welding, deliveries that other companies' production stands or falls with. Production planning lives in a spreadsheet. The spreadsheet is digital. The knowledge in it is not — the decision rules, the exceptions, the feel for which order may be moved and which one never may, all of it lives in the head of the person who built the sheet.
One single person understands the sheet. The same person carries the production plan for the next year and a half. If he leaves, gets sick, resigns — the plan walks out through the door with him. Ask any company at all what that person is worth, and the answer arrives after a silence.
Digital is not the same as externalized. That is perhaps the single most important distinction in this whole document. A file can be digital and still be nothing but tacit knowledge in digital clothing.
The underlying problem got its name in 1966: "we know more than we can tell" (Polanyi, 1966, p. 4). Nonaka and Takeuchi showed in 1995 that externalizing tacit knowledge is a process you can design — it does not happen by itself. And Cohen and Levinthal (1990) closed the most common objection, "we will just recruit our way out of it": absorptive capacity presupposes that something codified exists for the replacement to plug into. An organization with no externalized knowledge has nowhere to plug anyone in.
Now the defence-policy part. The total-defence bill (Prop. 2024/25:34) counts and reinforces physical assets: facilities, stockpiles, systems. The knowledge dimension — who can use the assets, how many can, what happens when they cannot — is missing as a planning quantity. But a factory whose machines survive and whose key people are gone stands just as still as a bombed factory. The difference is that the bombed one shows up in the statistics and gets rebuilt.
And the clock is running for entirely peaceful reasons. The American Welding Society's figure is that the average welder is around 55 (AWS). Nothing suggests Swedish workshops look any younger. The retirement wave is a slow mobilization of knowledge out of the country — without anyone crossing a border. Digital twin means, in this document, exactly this: externalizing what lives in heads, anchored to the place where the work happens, in an owned and persistent artifact that outlives any individual's exit. Scan the geometry first — it gives a shared spatial language and disarms the surveillance suspicion — and then hang the elicited knowledge on exactly the spot where it applies. The knowledge belongs where the work is.
One more thing, because it decides everything: the person whose knowledge is to be externalized is the only one who can do it. If she does not want to, absorption is zero whatever the tool — and she may have rational reasons not to want to, because tacit knowledge is bargaining power. The frame that works is inheritance, not extraction: her know-how should outlive her, with her as the author. No technology solves that. People sitting down with people solve it; the technology only makes the result durable.
The factory that can fall back
The chain is simple, and it does not cheat: externalization → encoded specifications → machines and skill models that keep running from the specifications when the people are called somewhere else. No magical autonomy is promised. But a factory cannot possibly fall back on knowledge that was never externalized.
And where the model runs matters. A welding model that can only run in a vendor's cloud, and not on the edge of the factory floor when the WAN link is down, is rented knowledge — the dependency has not gone away, it has changed address (cf. Satyanarayanan, 2017, on why the computation has to live near reality). The standards already exist: ISO 23247 for manufacturing twins, the Asset Administration Shell under IEC 63278-1 for portable asset representations. And the ambition level is allowed to be low. A digital shadow that only observes (Kritzinger et al., 2018) and actually gets used beats every full-scale twin that never gets finished. Deliberate under-ambition is an adoption strategy, not a compromise.
Assets that change mission
A parcel drone can carry insulin. The hardware is the same. What decides whether it does so in a crisis is three things you cannot improvise: an environment model calibrated for the right geography, authorization and triage logic built in advance, and a prepared regulatory pathway — EASA's U-space framework (Opinion 01/2021) allows for prepared exemption states, but only if somebody has prepared them. Conversion from peace to crisis is a knowledge and governance problem, solved beforehand or not at all.
Generalize that to every reprogrammable asset — drones, robots, machines, vehicles. An asset's wartime value is its modifiability without the vendor's permission: operating logic in open formats that the owner is legally and technically allowed to change. A proprietary asset you cannot reprogram is a peacetime asset. And the EU has already built half the incentive: the same lifecycle data that makes an asset convertible satisfies the requirements of the coming digital product passport (ESPR (EU) 2024/1781). Resilience requirements and regulatory compliance can pay for each other.
Then pooling. No single workshop justifies its own metal printer. A consortium that pools spare-part demand does — and at national level, distributed additive manufacturing is a reserve factory for spare parts on the day the import chains are cut. The arithmetic looks wrong right up until the cost of unplanned stoppages is counted in; reactive maintenance costs a factor of three to nine against planned (Mobley, 2002). And register capabilities, never drawings: a federated register of what each node can do — material, process, tolerance class — mobilizes national capacity without anyone handing over their IP. That industrial symbiosis works when the flows are real was shown at Kalundborg back in the nineties (Ehrenfeld & Gertler, 1997).
Food and the harvest window
Swedish berry and vegetable production hangs on seasonal labour that arrives inside a biologically locked window. Closed borders are a planning assumption in a total-defence context — and then the harvest rots or freezes. The collapse does not arrive as an explosion but as a biological fact, and that is exactly why it is one of the country's quietest preparedness problems.
But the blocker for autonomous harvesting is not the robotics. It is the missing formalized environment: a terrain model (the geodata base exists through the INSPIRE Directive, 2007/2/EC), a phenological crop model and machine parameters. Against that triad, autonomous platforms can plan routes, and an operator with little experience can make informed exception decisions. Honest limit, written out: this is decision support, not full autonomy. The difference between dependency and redundancy — not between human and machine.
The forest is the template. Mycorrhizal networks have redistributed nutrients and signalled stress between trees for hundreds of millions of years (Remy et al., 1994; Simard et al., 1997); one such network across 30 hectares of forest has been mapped as a coherent architecture (Beiler et al., 2010). The principles — redistribution, distress signalling, topologies that tolerate random losses — translate to networked food and industrial production. Functional principles, mind you, not structure. And the direction forward is called agroforestry: production systems where trees, crops and animals share land. The Swedish knowledge base there is, as far as I can judge, still thin — and inventorying it is itself a preparedness measure.
Sensing without surveillance
A distributed threat requires a distributed defence. Scaling up point defence — more radar, more central command — inherits centralization's fragility. Ukraine showed the other track: open APIs, apps, a population that learned to read the air picture (FOI seminar, 2026). Sweden has had the tradition for a long time in Hemvärnet (the Home Guard) and the voluntary defence organizations. What is missing is the digital successor.
Can it be built without building a surveillance state? Yes. But the answer is decided in the architecture, not in the policy document. Four choices:
1. Detect only. Observe and alert, never jam or engage. The human stands at the decision boundary. That keeps the system civilian, legal and extensible. 2. Mount on what is already there. Masts, street lighting, substations — infrastructure with existing permits. No greenfield. 3. Send derived objects, never raw data. Acoustic detection of drones at ranges beyond 150 metres is demonstrated in the research (Busset et al., 2015). The feature extraction on the node is in practice a privacy filter: the sound never leaves the node, only the detection object does. And the signal schema must be explicit about what it does not contain — no identity, no personal position, no process parameters. Architectural choices are constitutional decisions about what a system is able to know at all. 4. Reward contribution, govern it as a commons. Helium showed that private individuals will build infrastructure for rewards — on the order of 900,000 radio nodes by 2022 (Helium Foundation) — and showed in the same movement how token economies can degenerate. Take both lessons at once. And govern the shared part as a real commons: Ostrom's principles (Ostrom, 1990), compiled into software instead of into policy prose.
The reference state is half the defence. The Sandworm attacks on Ukraine's power grid (Greenberg, 2019) taught that cyber defence of physical infrastructure ultimately comes down to knowing what normal is — without a baseline there is nothing to alert against. An experienced operator's trained ear, hearing that the machine "sounds wrong", is an unsecured sensor: valuable and unbacked-up. Baseline it while it is still there.
Quantum — two clocks
The first clock is encryption's, and it has already struck. See section 5: post-quantum at archiving, not at retrofit (NIST FIPS 203/204/205, 2024).
The second is optimization's, and it should be allowed to run its course. Quantum optimization can explicitly represent real scheduling and network problems — but representation is not victory. Quantum goes into production the day it beats the classical challenger on the same problem instance, on wall-clock time, cost and reproducibility, disclosed openly. The requirement on Swedish procurers is therefore not "buy quantum" but "demand a benchmark": solver-neutral problem formats and mandatory disclosure. I co-chair the Digital Twin Consortium's working group for quantum technology, and that is exactly the position we argue there. No hype survives a benchmark.
The person-carried node — the patient tag 2.0
Soldiers carry identity tags. The civilian answer for 2030 is a person-carried, sovereign data node: your diagnoses, your medications, your context — readable locally, offline, at the point of care, shareable only through your consent. See how it fits with what is already being built: the MASK tool gives the regions the injury panorama at population level; the tag gives the carer the individual's context when the record systems are unreachable. The same architecture at two scales. Preparedness counts quantities — the node carries the person.
The principles are not negotiable, because they are architecture and not policy. Personal data is never shared; the experts come to the data, the data never goes to the experts. Local first, edge-native, sync later. All AI support explainable — retrieval from real sources, never generation out of thin air. And the need is not theoretical: WHO projects a global shortfall on the order of ten million health workers by 2030 (WHO). Care under that pressure needs patients who carry their own context.
We are building this as Life Atlas — life care rather than healthcare, because a person is more than their care encounters. The position is exactly this: five beta users. I write the figure out so you know precisely where it stands, and no further along than that. But the architecture — sovereign, person-carried, edge-native — is right regardless of who builds it. It should be a requirement in Swedish preparedness planning, not a product announcement.
7. The method — no simulation becomes history
Everything above hangs together through one and the same method: absorb, emulate, simulate. I have published it openly as SMILE (v6.4.3, DOI: 10.5281/zenodo.21757691). I developed it and I have a self-interest in it being used — read this section with that declaration in mind. The method is open precisely so that nobody has to buy anything from me to use it.
The core can be said briefly. Simulation works or fails depending on the emulation underneath it — planning data is full of holes and guesses, and a simulation on top of guesses inherits the guesses. The whole point is being able to try things out in a virtual copy of reality before doing them in reality. Today we do the opposite: act in reality first, and learn afterwards. Or not at all.
Reality is the dashboard — not the report about reality, and not the average of it. And a simulation never becomes history. That is the entire point of it. Karlstad can lose its power feed a hundred times in the model without a single person being affected, and walk into the real night with those hundred losses as accumulated experience. The sandbox absorbs the failures. Reality is spared.
But then the exercise has to actually be run, and run again. A failover path that has never been exercised is a hypothesis, not a capability. Hurricane Helene in 2024 did that lesson for us: 48.7 percent of the cell sites in the disaster area were down, voluntary cooperation between the operators was not enough, and the regulator had to mandate roaming (FCC, DOC-406055A1, 2024). Cooperation that is not rehearsed and contracted in peacetime does not materialize under load.
Why a shared model, and not one report per sector? Because the fragmentation is the root error. I have seen it in the automotive industry: a hundred or so data specialists, each responsible for their part of the truck, and nobody who saw that they were working with a truck.
Sweden runs the same risk in preparedness: every sector optimizes its part of the truck. A twin of reality is what Star and Griesemer (1989) called a boundary object — one and the same artifact that the welder, the preparedness coordinator, the defence planner and the regulator each read from their own side, without any of them needing the others' training. Build one structure that many read, instead of one report per audience.
Last: mark the seams. What is verified in this document has a source next to it. What is an illustration is marked as an illustration — the steel archetype in section 6 is one. The Karlstad figures are readings out of a living model, and the two missing figures are marked where they are missing. A preparedness document that hides its seams is marketing.
8. What has to happen
NATO membership (March 2024) made civil resilience a treaty obligation — Article 3 requires every ally to maintain its own capacity to resist armed attack. Prop. 2024/25:34 points out the direction to 2030. What is missing is the knowledge dimension and the time dimension. Because a digital twin commissioned in 2029 is not useful in 2029 — resilience is the product of the learning that managed to happen before the disruption. This capability cannot be built in a crisis. It is built before the crisis, which means now.
Seven decisions. All of them possible to take this autumn.
1. Introduce the knowledge audit. Two weeks, zero technology: which process knowledge is held by fewer than two people, which planning functions are one-person systems, what cannot be reconstructed from the documentation? One sentence is enough as a procurement and supervisory question: "If your three most important people are unavailable tomorrow — how long before you can deliver again?" No twin funding without a completed audit. 2. Make the partition test an acceptance criterion in public procurement. Does the readable model of the operation survive simultaneous loss of network and power at the node? "There is a cloud backup" fails — the path there is what went down. The test is local, binary and falsifiable, and it replaces the whole misframed debate about cloud versus local: the real design axis is reachability under partition. 3. Post-quantum from the first byte in every new public archive — health data, network topologies, defence-adjacent registers (NIST FIPS 203/204/205). Plus crypto-agility as a requirement, so that the next shift does not require a rebuild. 4. Demand open formats and the right to change. No critical asset is procured without the owner being legally and technically able to reprogram its operating logic without the vendor's consent. AAS conformance (IEC 63278-1) demonstrated, not promised. Exit data in open format within a contracted recovery time. 5. One annual partition exercise per essential service. The descent through degraded states must be rehearsed, not theoretical. And the exercise is documented in the twin so that the next exercise starts where the last one ended — project memory instead of project amnesia. 6. Open the APIs before the war does it. Ukraine took the decision under a burning war; the panel in Almedalen observed that such decisions are harder in peacetime. Take them anyway, and start with the harmless: shelter registers, coverage maps, exercise data. Detect-only architecture and explicit exclusion schemas take the edge off the surveillance objection — and make the voluntary part buildable. 7. Demand benchmark and weighting on every AI and quantum claim. An average can hide exactly the errors worth fixing, and a system optimizing against a flattering mean will confidently repair the wrong things. Every vendor claim lands with a baseline, a measurement method and a weighting — otherwise it does not land at all. Physics does not care what the models claim anyway.
9. Change before you must
Concrete from the last century stops a Shahed today because people in the 1930s and 40s changed before they had to. They did not have the Shahed drone in front of them. They did not need it. They built against a class of threat, in open, robust margins, and eighty years later it pays off in a seminar tent on Gotland.
Back to the red slips. The audience got homework from the moderator: go home and find out where your shelter is. Good homework. Your homework — you who are reading this in agencies, in regions, in the armed forces and in industry — is bigger: put numbers on your own gaps before somebody else does it for you. We put a number on Karlstad: 69 percent within 500 metres, 31,832 outside. The same question can be put to every municipality, every region, every factory, every supply chain. Ask it.
And do it in time. The knowledge that carries this country is retiring, logging out and being forgotten — every day without externalization is a day of silent disarmament. The good news is that the opposite is also silent. An audit here. A map there. One rehearsed failure state. One opened dataset. None of these measures requires a new billion-scale appropriation; they require a decision about order — impact first, data last, and reality as the dashboard rather than the report about it.
I will happily show the Karlstad map to anyone who wants to see it. The method is open and free; take it. And I will happily accept being told I am wrong on some point — that is how this is meant to be read. Look for the error. Say it out loud. Make it better.
Sweden has been in time before. It is time to be in time again — and this time to stay in the flow of it.
Nicolas Waern Gothenburg, August 2026 ORCID 0000-0001-7970-2707
Sources
Seminar and own data
- FOI seminar on population protection, Almedalen week 2026 (transcript held by the author): shelter dimensioning 250 kg / Shahed warhead approx. 60 kg; "not shelters in the right place"; designated protective spaces; air-raid alerts via SE Alert; Rakel replacement, 64,000 modems; MASK 2.0 (FOI on commission from Socialstyrelsen, all 21 regions, NATO-aligned); "We survived because we were underground"; "Civilian hospitals carry the burden of war"; Ukraine's open air-picture APIs; Ukrainian evacuation doctrine; Region Värmland (285,000 inhabitants, 8,000 employees, 2,000–3,000 volunteers); the Örebro response; Resilient Care, Karlstad, autumn 2025; the accessibility shortfall.
- The Karlstad model: the author's smallest-possible twin on open data (the shelter register and population statistics). Reading of August 2026: 69% of the population within 500 m of a shelter; 31,832 people outside.
- The Amity Codex quotations: verbatim extracts from recorded working meetings, May–July 2026 (the author's transcripts).
Law and policy
- Prop. 2024/25:34, Totalförsvaret 2025–2030.
- Sweden's accession to NATO, March 2024; North Atlantic Treaty, Article 3.
- CLOUD Act, Pub. L. 115-141 (2018).
- ESPR (EU) 2024/1781 (digital product passport); INSPIRE Directive 2007/2/EC; EASA U-space, Opinion 01/2021.
Standards and technology
- NIST FIPS 203/204/205 (ratified August 2024); NIST TN 2189 (approx. 240 ns timing requirement in 5G).
- ISO 23247 (digital twins in manufacturing); IEC 63278-1 (Asset Administration Shell).
- Kritzinger et al. (2018) — the digital model/shadow/twin taxonomy; Satyanarayanan (2017) — edge computing; Dwork & Roth (2014) — differential privacy; Busset et al. (2015) — acoustic drone detection >150 m.
Events and empirical record
- NOAA NCEI (2024): 27 billion-dollar disasters in 2024 against a historical average of about 9; interval 82 → 12 days.
- NOAA SWPC (2024): the Gannon storm, the first G5 storm in more than two decades; Yang (2025): GPS degradation to approx. 49°N for 15–20 hours.
- Red Eléctrica/ENTSO-E (2025): Iberian peninsula, approx. 15 GW lost in approx. 5 seconds.
- ITU (2023): at worst approx. 65% of Ukraine's power grid knocked out; national roaming in approx. one week.
- CERT-UA (December 2023): the Kyivstar attack, approx. 24 million subscribers.
- FCC DOC-406055A1 (2024): Hurricane Helene, 48.7% of cell sites down; mandated roaming.
- Greenberg (2019), Sandworm — the cyberattacks on Ukraine's power grid.
- Helium Foundation: approx. 900,000 nodes by 2022.
Knowledge theory and organization
- Polanyi (1966), The Tacit Dimension, p. 4.
- Nonaka & Takeuchi (1995), The Knowledge-Creating Company.
- Cohen & Levinthal (1990), "Absorptive Capacity".
- Star & Griesemer (1989) — boundary objects.
- Ostrom (1990), Governing the Commons.
- Ehrenfeld & Gertler (1997) — Kalundborg's industrial symbiosis.
- Mobley (2002) — reactive versus planned maintenance, factor 3–9.
- Remy et al. (1994); Simard et al. (1997); Beiler et al. (2010) — mycorrhizal networks.
- American Welding Society — average welder age approx. 55 (USA).
- WHO — global shortfall of approx. 10 million health workers by 2030.
Method
- SMILE v6.4.3, DOI: 10.5281/zenodo.21757691 (concept DOI: 10.5281/zenodo.20175405). Author: Nicolas Waern, ORCID 0000-0001-7970-2707.
Where this goes next
Want this applied to your organisation?
One call is enough to know if we're a fit.