Skip to content
WINNIIO
← Insights

An essay on the infrastructure that appears on no balance sheet: knowledge held in heads, the factory that has absorbed itself, assets that can change mission, and the baseline in your own pocket. Written from the Swedish case, argued for any nation.

English · Read this paper in Svenska

Sweden at War — What the Spreadsheet Cannot See

By Nicolas Waern, CEO — WINNIIO AB Published: August 2026 · ORCID 0000-0001-7970-2707 · CC BY 4.0


A seminar tent on Gotland, during Almedalen (the annual political week on Gotland). The subject is population protection, and the conversation sounds the way those conversations always sound. Assessments. Assumptions. Words like "probably" and "in the longer term". The audience has been handed red and green slips, and the moderator asks the simplest question there is: do you know where your nearest skyddsrum (public shelter) is? Almost nothing but red slips goes up. Nobody in the room can put a number on how far the protection actually reaches. Nobody knows. But the data exists. MSB's (the Swedish Civil Contingencies Agency) shelter register is open, anyone can download it. So are SCB's (Statistics Sweden) population grids. So we downloaded both and did the arithmetic — afterwards, at home, not in the tent. No inquiry, no consultation round, no "we will come back to you". The answer, for Karlstad: 69 percent of the population live within 500 metres of a shelter. 31,832 people do not. At the same seminar one of the preparedness managers said something else, about FOI's (the Swedish Defence Research Agency) new mass-casualty tool MASK 2.0. Translated from the Swedish: "all of a sudden it became fact, and concrete." He meant it as praise. I heard it as a diagnosis — and as exactly what is missing in the shelter question: an answer out of reality instead of an assumption. Three words, "it became fact", should not be remarkable at one of the sharpest research institutes in the country. That they are says something. We have grown used to planning on assumptions while the data sits there waiting. Nobody is to blame — the working method has settled over a whole country. Assumption → inquiry → consultation round → new assumption. The loop rarely closes against reality. [FIGURE NEEDED — map from the Karlstad analysis: shelter coverage calculated on MSB's open data] Now do the same thing again. The same arithmetic, all 290 municipalities. [NUMBER MISSING — national shelter coverage, verify against MSB's register.] And then do it for everything else that totalförsvar (total defence) rests on. Spare parts. Food. Workshop capacity. How much of Swedish preparedness planning is built on figures somebody calculated out of reality, and how much is built on assessments inherited from document to document? I do not know. Nobody knows. That is the finding.

The man with the spreadsheet

Sweden joined NATO in March 2024. The total-defence bill — Prop. 2024/25:34, the direction for 2025–2030 — counts what can be counted: units, materiel, appropriations, stockpiles, shelters. Assets. And those are the right things to count. But that is only one of the two dimensions.

Because I have spent the last few years inside the reality that is supposed to be defended — factories, buildings, telecom networks — and there is a second infrastructure in there. It appears on no balance sheet. It cannot be put in a warehouse. And it carries just as much weight as the concrete.

At a manufacturer it is often one single person who understands the spreadsheet. The same person carries the production plan for the next year and a half. If he leaves, gets sick, resigns — the plan walks out through the door with him. What is that person worth? Nobody has done the sum.

That is not a special case. It is the normal case. Time after time, in operations I have walked into, there is a spreadsheet that in practice is the production, and one person who is the only one who can read it. The file sits on a server and looks digital. But the rules for how a late delivery is weighed against a finished order, which exceptions apply to which customer, why that particular sequence works — that lives in a head. Digital is not the same as externalized. The entire digitalization debate trips over that distinction.

Michael Polanyi put words to it back in 1966: "we know more than we can tell". Nonaka and Takeuchi showed in 1995 that tacit knowledge can be externalized into something an organization actually owns. The knowledge about knowledge has been there for decades, in other words. But it has not reached Swedish defence planning. The bill hardens the asset dimension. The knowledge dimension is not mentioned.

And an adversary has already worked this out. You do not need to bomb a factory whose capability sits in three heads. It is enough that the three are not there. Recruited. Threatened. Sick. Mobilized to something else. The target list can be assembled from a supply-chain map, a company registration and a LinkedIn search. A factory where the machines are still standing but the knowledge is gone is as knocked out as a bombed one — except that the bombed one gets help rebuilding, because that damage is visible.

Put the question inside your own organization: if your three most important people are unavailable tomorrow, how long before you can produce again?

No Swedish procurement asks that question today. Every single one should.

The factory that has absorbed itself

So what do you do about it? The word everybody reaches for is digital twin, and I use it myself. But most of what is sold under that name is 3D graphics for the trade-show booth. So let me define what I mean, because in wartime the difference is not cosmetic.

A digital twin worth the name is the operation's externalized memory. You start with the geometry — scan the site as it actually looks, not as the drawing claims. The scan gives everybody a shared room to point into, and it measures surfaces, not people, which takes the edge off the surveillance fear. Then the knowledge is anchored where it belongs. The machine's history at the machine. The supplier dependencies at the material flow. The experienced operator's rules of thumb at the station where they apply. The knowledge lives where the work happens.

Built that way, the twin becomes something other than documentation. A factory that has absorbed its own knowledge, its own history and its own supply chains can warn: this component is deviating from its baseline, this supplier is the only source of this steel, this decision is usually taken like this and nobody authorized is on site. And in the longer run it can decide, inside limits people have set.

Take a Swedish steel subcontractor. What I am describing is a composite archetype, no single firm — but anyone who has moved around Swedish industry will recognize it. Certified welders whose judgments have never been written down. Production planning in a spreadsheet with a single reader. Supplier relationships that live in a phone's memory. A subcontractor in chains that end in defence materiel, without ever thinking of itself as defence industry.

Now a thought experiment — labelled as one, nothing that has happened. Mobilization. Key people are called up. In the factory with no externalized memory, no alarm goes off. No machine stops. But decisions that took minutes start taking days, exceptions get handled wrong, the margins shrink quietly. And because nothing visibly breaks, nobody reacts until the deliveries fail to arrive. Silent degradation is the grey-zone threat model. There is no alarm for an eroding margin.

The same factory with an externalized memory has a staircase to fall down instead of a cliff. The specifications are machine-readable. The baselines are documented. The prioritization logic is encoded. The robot cells keep running on what has been externalized, and the people still there make informed decisions with systems that can explain themselves. Full autonomy? No. A fallback ladder to autonomy, built in peacetime. But the condition cannot be negotiated away: a factory can only fall back on knowledge that was externalized at some point. A clever AI system in a vendor's cloud does not count — the dependency has only changed address. Knowledge that cannot run locally when the link is broken is rented knowledge.

Assets that can change mission

The same logic applies to everything that flies, drives and carries.

A parcel drone can in principle fly insulin out to a cut-off island in the archipelago. The hardware is already capable. And still the conversion fails on the day it is needed, for three reasons that have nothing to do with hardware: the environment model is calibrated for the wrong geography, the prioritization and authorization logic was never built, and the regulatory framework — EASA's U-space framework (Opinion 01/2021) shows the way — was never prepared for the exemption. Crisis conversion is a knowledge and governance problem. It is solved in advance or not at all.

That is where the real definition of a reprogrammable asset sits: open formats, local control and the right to change. A drone fleet whose operating logic the owner is legally and technically allowed to rewrite can change mission in hours. A proprietary asset that needs the vendor's approval for every change is a peacetime asset, whatever it cost. The formats for describing assets portably already exist — asset administration shells under IEC 63278 are one example. What is missing is the requirement in the procurement.

Then the food. The Swedish berry harvest hangs on seasonal workers who come from outside, into a window that biology decided. Closed borders is an event every preparedness planner counts on — and the harvest does not negotiate. If the berries ripen and nobody picks them, they freeze or rot. The collapse does not arrive as an explosion but as a biological fact.

Here too, the blocker is not the robotics. What is missing is the formalized environment: a terrain model of the property, a phenological model of the crop's cycle, the machine's own parameters. Against that triad, autonomous platforms can plan routes, and an inexperienced operator can make informed exception decisions. Decision support first, autonomy later — I claim no more than that. But the difference between dependency and redundancy is built in exactly that model. Farmers who fly drones over their own fields are building it already, field by field, and they own their own environment model the day it is needed for something bigger.

And lift your eyes from the field. The forest has been running decentralized supply for hundreds of millions of years (Remy et al. 1994). Simard and colleagues showed in 1997 that trees redistribute resources to each other through mycorrhizal networks — not because some central node decided it, but because the architecture rewards it. Agroforestry is the same design principle moved into food production: trees and crops in the same landscape, more harvests per hectare, more species sharing the risk. More nodes, more routes, no single harvest month that can be knocked out.

Four legs, its own head

Under the cities lie culverts, tunnels, switchgear and heating substations that no human being has time to walk through. In a crisis they are supposed to be inspected more often, with fewer people. Four-legged robots of the Spot type already do the job in industry. But the interesting part is not that they walk. The interesting part is where the intelligence sits.

An inspection robot carrying its model locally keeps working when the network is gone. It knows what normal sounds like and looks like, because the baseline is externalized and rides along in the payload. It comes back and says: this deviates. A hundred such robots are a hundred independent heads — not a hundred terminals pointed at a cloud that may not answer. Decentralized intelligence sounds like a buzzword right up until the network disappears. Then it is the difference between a capability and a subscription service.

The same pattern scales to people. Ukraine showed that civil sensing works: ordinary people's phone reports, fused into tracks for incoming drones and robots, where the latency decides what the warning is worth. That is the logic of Hemvärnet (the Home Guard) and the voluntary defence movement in digital form. The incentives can be built too — Helium got private individuals to put up on the order of 900,000 radio nodes by 2022 (Helium Foundation), with rewards tied to a proof of actual contribution. A national sensing capability does not have to be a budget line, in other words. It can be a market with a proof system.

But on one condition only: privacy through architecture, not through promise. The node listens locally and only derived detection objects leave it — never raw audio, never raw image. The system detects and warns; people decide. The architecture determines what the system is able to know at all, and that choice is a constitutional question written in code. It should be settled before the first node goes up, not after the first scandal.

Decentralization is not an opinion

One afternoon in April 2025 roughly 15 gigawatts fell out of the Iberian power grid in about five seconds (Red Eléctrica; ENTSO-E). Everything was still standing. Nothing worked. No enemy was required — only a system built as if disturbance were the exception.

And the exception has been abolished. The US disaster database counted 27 billion-dollar disasters during 2024, against a long-run average of about nine; the interval has gone from one every 82 days in the 1980s to one every 12 days (NOAA NCEI). A system designed for one such event per season, repaired at leisure, now meets one every twelfth day. Degraded operation is now the operating mode the architecture has to hold.

Ukraine is the proof in a war environment. At worst about 65 percent of the power supply was knocked out, and national roaming between the operators was standing within roughly a week (ITU 2023). At the same time the attack on Kyivstar in December 2023 — around 24 million subscribers affected (CERT-UA) — showed that not even a large operator's core is a sanctuary. During Hurricane Helene in the US, 48.7 percent of the cell sites in the affected areas were down at worst, and roaming between operators had to be ordered into existence by the FCC. Voluntary interoperability does not hold under load. It has to be contracted, rehearsed and inspected in advance.

So to the Swedish reflex answer: "the data must stay in Sweden." Wrong axis. A cloud region and a municipal server hall are both a single place. The decisive question is a different one: can the people who need the readable model of reality reach it when the network is fragmented? Reachability under partition — that is the design axis. And sovereignty is architecture, not policy. The CLOUD Act of 2018 gives US authorities the right to demand data from US providers regardless of where in the world it is stored. No contract protects against that. Only physical and legal custody does. The software may happily be open source from all over the world — the data is sovereign.

There is also a quieter substrate: time. In the spring of 2024 came the first geomagnetic storm at the highest level in more than two decades (NOAA SWPC). High-accuracy GPS degraded down to roughly latitude 49°N for 15–20 hours (Yang 2025) — all of Sweden lies north of that line. And 5G networks need GPS-borne timing accurate to around 240 nanoseconds (NIST TN 2189). One and the same storm attacks the power grid and the timekeeping at once. Holdover clocks and time sources with no GNSS dependency belong in every Swedish infrastructure procurement.

So this is what I believe, and I said it long before it became defence policy: every nation, every municipality, every company and every person will have their own AI models, their own agents and their own data. Your own context is the most important thing you own.

Decentralization is the key. Not because it is a beautiful principle, but because every alternative creates a point that can be knocked out, bought up or switched off.

Quantum: the lock and the list

Two things about quantum technology can be said without hype. Only two.

The first is the lock. Today we encrypt archives meant to survive for fifty years with mathematics that has a best-before date. Whoever copies encrypted Swedish health data or grid topology today does not need to be able to read it today — harvest now, decrypt later is a storage strategy, not a theory. The answer already exists: NIST ratified the post-quantum standards FIPS 203, 204 and 205 in August 2024. What remains is one sentence in every public procurement: post-quantum encryption from the first byte in every archive that is going to live longer than ten years. Retrofitting is the expensive route. For what has already been copied it is no route at all.

The second is the list — the optimization problems. Network planning, scheduling, logistics: combinatorics where quantum machines may one day contribute. One day. Quantum optimization goes into production the day it beats the best classical solver on the same problem instance — on wall-clock time, cost and reproducibility, openly disclosed. Not a day earlier. I co-chair the Digital Twin Consortium's quantum working group, and this is my entire quantum position: representation is not victory, the benchmark is. That requirement belongs in the procurement too: every AI and quantum claim ships with benchmark, baseline and weighting method.

The citizen's counterpart

Everything so far has been about factories, fields and networks. But the smallest node in totalförsvar is a human being. And today she is planned for as an object — somebody to be informed, evacuated, supplied.

Turn it around. Give her a counterpart.

Think of Be My Eyes, the app where a sighted person lends their eyes to a blind one, and move the idea to crisis and war. What follows is a target picture, not a product description: a neighbour lends their judgment, a retired nurse lends her eye, and an AI counterpart mediates — a counterpart that knows what is normal for you specifically, because you carry your own baseline. Resting heart rate. Medications. Blood values. What is normal for you, not for a population average. Encrypted, on your own device, post-quantum secured from the first byte. Personal data should never be shared. Ever. The experts come to the data; the data does not leave you.

The sociologists Star and Griesemer described something in 1989 that they called boundary objects: one and the same artifact that several worlds can read without any of them giving up their own. That is exactly what a personal baseline becomes in a crisis. You read it as reassurance. The paramedic reads it as triage. The municipality's crisis staff read it as an aggregated situational picture, without ever seeing the individual. One artifact, many readers, nobody who owns you.

That is what Life Atlas is meant to be: the citizen's own AI counterpart. Life care rather than healthcare — the whole life, not only the care episodes. Edge-native, local first, every component replaceable. And for honesty's sake: we are at the beginning. A handful of beta users, an architecture and a direction. I also have a self-interest in every paragraph of this text, because I build systems like these. Count on that as you read. And do please count for yourself.

Reality is the dashboard

What ties together the shelters in Karlstad, the spreadsheet in the factory, the drone that changes mission, the robot with its own head, the quantum lock and the baseline in your pocket?

That we plan on the plan instead of on reality. Statistics explain yesterday; they do not survive tomorrow. A simulation works or fails depending on the emulation underneath it. Planning data is full of holes — it is guesses, never seasonal, only mathematical. And it does not hold.

Emulate before you simulate. Scan what is actually standing there. Measure what actually happens. Externalize what is actually known. Then, and only then, simulate: run the attack against the emulated factory, run the partition against the emulated municipality, run the border closure against the emulated harvest. A fallback route that has never been exercised is a guess. Guesses do not carry the weight of a war.

Reality is the dashboard. Not the report about reality, not the average of it — reality itself, readable.

Is this a technology question? No. The technology has been there for several years. What is missing is the requirement. Six clauses, ready to write into the next procurement:

1. Edge-native operation. The system works without a connection to anybody else's cloud. 2. The partition test as acceptance test. Does the readable model survive simultaneous loss of network and power at the node? "There is a cloud backup" is a fail — it was the path there that went down. 3. Post-quantum encryption from the first byte in every archive that is going to live longer than ten years (FIPS 203/204/205). 4. Open formats and the right to change. Operating logic in formats the owner is legally and technically allowed to reprogram, and all data out of the system in open format within a contracted time. 5. Benchmark duty. Every AI and quantum claim ships with benchmark, baseline and weighting method. 6. Knowledge continuity. The supplier reports which processes are carried by fewer than two people, and how they are being externalized.

And one more thing, which costs no technology at all: a two-week knowledge audit in every essential operation. Which decisions can only one person take? Which planning function is in practice a one-person system? What cannot be reconstructed from the documentation? Every municipality, every agency and every subcontractor can start that audit on Monday.

It is late in Gothenburg as I write this. Too long? Probably. But then do the opposite of believing me: assume I am wrong about everything, and do the arithmetic yourself. The data is open. That was what happened in the seminar room at FOI — a question met reality, and it became fact. Let that be the method instead of the exception.

This text is the front porch. Behind it stand two whitepapers: one Swedish on the knowledge dimension in total defence, one English on the architectural choices a nation has to be able to sign. Both build on methodology that is openly published (SMILE v6.4.3, DOI 10.5281/zenodo.21757691). If you want the Karlstad arithmetic run for your own municipality, your factory or your association — get in touch. The door is open.

Change before you must.

— Nicolas Waern, Gothenburg

Where this goes next

Want this applied to your organisation?

One call is enough to know if we're a fit.

Book a call
Digital twin specialists

Nobody brings the full stack of digital twin competence — organizational, global, change management, technology strategy, and a NASA JPL-derived method — the way we do. We bring the best people together for a company faster than anyone else, and we implement it with them.

The decisions are being made either way. The only variable is whether you find out afterwards.

Scoping workshop from €4,500, credited in full against the project. See how scoping works