Maritime domain awareness, the ability to know what is happening at sea and to understand what it means, has been redefined over the past three decades. The concept itself has not changed much on paper: the International Maritime Organization still defines it as the effective understanding of anything associated with the maritime domain that could affect the security, safety, economy, or environment of a state or region.
What has changed is everything beneath that definition: the volume of traffic to be watched, the tools available to watch it, the ownership of those tools, and the nature of the threats hiding within the noise. The maritime security challenge of 2026 bears little resemblance to that of the mid-1990s and treating maritime domain awareness (MDA) as a continuation of Cold War naval surveillance, rather than as a fundamentally new problem set, is a strategic error with real operational consequences.
The challenge is also behavioral. A vessel’s reported position and identity are only part of the picture; the operational question is whether its movements, transmissions, and interactions are consistent with its declared activity. “Going dark” should therefore be treated as a cue for further investigation, not as proof of illicit conduct. Maritime domain awareness must connect tracking with behavioral analysis, using multiple sources to distinguish routine activity from potential concealment or deception.
This matters because the instinct in defense planning is to solve maritime awareness gaps with more of the same: more patrol aircraft, more surface combatants, more national radar sites. That instinct made sense in a bounded, state-centric world. It makes considerably less sense in a world where the ocean is crowded with tens of thousands of vessels a navy will never own a sensor pointed at, where identity itself has become a contested, manipulable data field, and where the actors generating risk are as likely to be a sanctioned tanker or a civilian-flagged militia boat as a warship.
MDA has shifted from a sensor-coverage problem to a data-fusion and behavioral-analysis problem, and the institutions, acquisition strategies, and workforce models built for the old problem are increasingly mismatched to the new one.
The Baseline: A Bounded, State-Centric Problem
Thirty years ago, maritime awareness was largely a state-owned, platform-dependent activity. Navies and coast guards built their picture of the sea through organic sensors — maritime patrol aircraft, surface combatants, submarines, coastal radar chains, and national intelligence collection. The Cold War model was built around counting and tracking a known, finite set of adversary platforms: Soviet submarines, surface combatants, and the merchant vessels used as intelligence collectors. The maritime domain itself was vast, but the set of actors that mattered to national security was comparatively small, symmetric, and state-based. A watch officer’s job, in effect, was to find and classify a known type of needle in a haystack whose size changed slowly.
Merchant shipping, by contrast, was largely invisible to security establishments unless a vessel entered a monitored strait or approached a coastline under active surveillance. There was no global, persistent, unclassified means of tracking commercial traffic. A ship’s location, identity, and behavior were known chiefly to its owner, its flag state, and whichever coast guard happened to be nearby at a given moment. This was a bounded problem in large part because global trade itself was smaller and structurally simpler. Global seaborne trade volumes have roughly tripled since 1990, rising from about four billion tons loaded to well over twelve billion tons today, while world container throughput grew from thirty-six million TEU in 1980 to nearly 850 million TEU by the early 2020s. Fewer ships, less complexity in ownership and flagging, and a narrower set of state adversaries meant that platform-centric, nationally-owned surveillance was, for its era, adequate to the task but it was never elegant, never complete, but manageable against a finite number of hulls and airframes.
That baseline is worth stating plainly because so much of the current debate over maritime security acquisition still implicitly assumes it holds. It does not, and the reasons why are not a single technological disruption but three distinct, mutually reinforcing forces that broke the old model roughly simultaneously.
Three Forces That Broke the Old Model
(1) The scale and opacity of global shipping outgrew national surveillance capacity
The sheer growth of maritime traffic changed the nature of the problem before any adversary did. The global container fleet alone expanded from roughly 4.5 million TEU of capacity in 2000 to over 33 million TEU by 2025, with the number of vessels rising from about 2,600 to nearly 7,500. Add the tanker fleet, the dry bulk fleet, the fishing fleet, numbering in the hundreds of thousands of vessels worldwide, and the general cargo and roll-on/roll-off fleets, and the scale of what a comprehensive maritime picture would need to encompass becomes clear.
No coast guard or navy, however well-resourced, can maintain a comprehensive picture of a domain this size using organic sensors alone. A frigate can occupy one piece of ocean at a time; a maritime patrol aircraft can sweep a corridor for a few hours before returning to base. Neither scales to a global merchant fleet numbering in the tens of thousands of hulls, let alone the artisanal and small-craft traffic that dominates numerically in many contested waters. Awareness, in other words, had to become a data problem before it could be addressed as an intelligence problem. The bottleneck moved from “can we get a sensor there” to “can we ingest, correlate, and make sense of what tens of thousands of platforms are broadcasting, or failing to broadcast, at any given moment.”
(2) Identity and location became technically knowable and technically fakeable
The introduction of the Automatic Identification System, mandated under the IMO’s SOLAS convention in 2002 and required fleet-wide by the end of 2004, was the first structural break with the old model. For the first time, a large share of the world’s merchant fleet was continuously broadcasting its own identity, position, course, and speed. This was transformative: a technology built for collision avoidance and safety of navigation became, almost as a side effect, the first genuinely global layer of maritime transparency.
The second break came when that signal moved to space. The first AIS-detecting nanosatellite flew in 2008, and by 2017 satellite-based AIS had matured into a persistent, near-real-time global tracking service. Overnight, in historical terms, a cooperative safety signal became the backbone of global maritime surveillance, available not just to states with national collection systems, but to any commercial or academic actor with the money to buy the feed. Shipping insurers, port authorities, environmental researchers, journalists, and open-source analysts all gained access to a global tracking picture that a generation earlier had been the exclusive province of naval intelligence.
But a cooperative signal is also, definitionally, a signal that can be switched off, falsified, or spoofed, and the same three decades that gave the world persistent tracking also gave bad actors persistent means to defeat it. AIS spoofing and “dark” transits or vessels that disable or falsify their transponders to mask identity, position, or both are now a well-documented and extensively studied evasion technique, prompting a parallel industry in synthetic aperture radar (SAR), radio-frequency (RF) geolocation, and electro-optical detection designed specifically to find the ships that do not want to be found. Awareness and evasion have been locked in a continuous technical race ever since AIS became mandatory, and it is that race — not the original safety technology in isolation that constitutes the actual substance of modern MDA. Every advance in cooperative tracking generates a corresponding advance in non-cooperative detection, and every advance in detection generates more sophisticated evasion tradecraft in turn. This is not a problem that gets solved and stays solved; it is a competitive dynamic that must be managed continuously.
(3) Commercial capability displaced the state monopoly on maritime intelligence
A state-owned constellation of patrol aircraft and warships has been supplemented, and in important respects superseded, by a commercial architecture of small-satellite operators. A cluster of commercial providers now supply persistent SAR imaging, RF geolocation, and AIS correlation services once the exclusive preserve of national intelligence agencies. Maritime analytics firms such as Windward fuse these commercial data streams — AIS, SAR, RF, and behavioral analytics — to detect vessels that have gone dark, identify anomalous loitering or ship-to-ship transfer patterns tied to sanctions evasion or illegal fishing, and flag identity manipulation at machine speed.
This is not an incremental improvement on the old model; it is a structural inversion of it. Governments are now often consumers of commercially generated maritime intelligence rather than its sole producers, and the practical ceiling on MDA is increasingly set by data fusion and analytic tradecraft rather than by the number of hulls or airframes a navy can put to sea. The organizations best positioned to lead on MDA are not necessarily the ones that own the most sensors, but the ones that can most effectively integrate sensor feeds they do not own into an actionable picture, a fundamentally different competency than the one naval staffs were built around, favoring organizations comfortable with public-private partnership and continuous software integration over ones built around platform acquisition cycles measured in decades.
From “Seeing” to “Understanding”: The Rise of Sub-Threshold Threats
The technology shift would matter less if the threat picture had stayed simple. It has not. The last decade in particular has populated the maritime domain with actors and behaviors that the 1990s framework was never built to characterize, because they are deliberately designed to stay below the threshold of open conflict and inside the seams of jurisdiction and attribution.
Russia’s response to Western sanctions produced a so-called shadow fleet of aging tankers, estimated by different trackers at anywhere from roughly 1,000 to over 3,000 vessels depending on methodology, representing an estimated seventeen to nineteen percent of the world’s tanker capacity, that move sanctioned crude while manipulating flags, ownership records, and AIS signals to frustrate identification. This fleet did not exist in any meaningful form before 2022 and has grown roughly thirtyfold in three years — a pace of adversary adaptation no static architecture, built around slowly changing Cold War order-of-battle assumptions, can plausibly keep up with.
In the South China Sea, China’s People’s Armed Forces Maritime Militia has conducted hundreds of documented incidents of harassment, blocking, and ramming against neighboring states’ vessels since 2012, using ostensibly civilian fishing boats as an instrument of state coercion that deliberately complicates naval response and legal attribution. A militia vessel that looks, on radar and even on AIS, indistinguishable from an ordinary trawler is precisely the actor a platform-classification model is poorly equipped to characterize, because the relevant question is not what the vessel is but what it is doing, and on whose behalf.
In the Red Sea, a non-state armed group has, since late 2023, used missiles and uncrewed systems to threaten commercial shipping on one of the world’s most important trade arteries, a capability and intent a 1990s coastal-defense threat model would not have anticipated from that kind of actor at all. The case is instructive because it collapses categories MDA planners have traditionally kept separate: it is simultaneously a maritime security problem, a counter-terrorism problem, an air and missile defense problem, and a freedom-of-navigation problem, and no single service or sensor architecture owns all four pieces of it.
In the Baltic Sea, a series of at least eleven undersea cable and pipeline incidents in fifteen months prompted NATO to stand up a dedicated multinational patrol mission, Baltic Sentry, to protect infrastructure that did not exist as a maritime-security concern a generation ago. And in the Black Sea, Ukraine has used a fleet of low-cost uncrewed surface vessels to drive a conventional navy from its own coastal waters and is now adapting those platforms into launch systems for attack drones, demonstrating that a state without a traditional navy can generate a maritime effect older threat models would have reserved for blue-water fleets.
None of these cases is a conventional military confrontation in the Cold War sense. Each exploits the same structural weakness: an MDA architecture built to identify and count known state platforms is poorly suited to characterizing intent among ambiguous, deniable, or non-state actors operating inside civilian shipping lanes and behind the legal protections civilian status confers. The core analytic task has shifted from “seeing” or locating a vessel to “understanding” or determining whether a vessel’s owner, cargo, route, and behavior indicate sanctions evasion, gray-zone coercion, smuggling, or hostile intent. That is a fusion and behavioral-analytics problem, not a sensor-coverage problem, which is why data fusion and pattern-of-life analysis, rather than additional patrol assets, have become the leading edge of maritime security investment.
Pattern-of-life analysis has become central for a specific reason. A vessel that goes dark for six hours in open ocean is not automatically suspicious; ships lose AIS signal for entirely innocent reasons. A vessel that goes dark for six hours specifically while transiting a known ship-to-ship transfer zone, having previously exhibited a pattern of similarly timed disappearances correlated with a change of registered owner, is a different matter entirely. Distinguishing the two requires a historical baseline, machine-assisted anomaly detection across large populations of vessels, and human analytic judgment applied at the point where the algorithm flags something worth a closer look, a fundamentally different workflow than the Cold War model of a watch officer classifying a discrete contact.
The Persistent Vulnerability Beneath the Waterline
The MDA problem has also expanded vertically, into the undersea domain, in ways the 1990s framework barely addressed. Fiber-optic cables and pipelines now carry the overwhelming majority of the world’s data traffic and significant volumes of energy, yet they sit largely unmonitored on the seabed, identifiable from public charts and vulnerable to any vessel dragging an anchor or deploying a submersible asset. The Baltic Sea incidents illustrate that critical infrastructure protection is now inseparable from maritime domain awareness, requiring persistent surface and subsurface monitoring of an environment conventional AIS and radar cannot see into at all. Surface tracking tells an analyst where a vessel was; it does not tell an analyst what that vessel dragged behind it or dropped over the side.
This is a second and distinct MDA gap layered atop the surface-traffic gap, and closing it will require sensors, tradecraft, and legal authorities that are still being built. Attribution is the hardest part of this problem. Determining that a cable was cut is comparatively straightforward; determining that a specific vessel’s anchor caused the damage, and that the damage was deliberate rather than the result of poor seamanship or heavy weather, requires a chain of evidence combining AIS or satellite tracking, seabed forensics on the break itself, and often signals or human intelligence on intent, none of which any single sensor or agency possesses in full. The undersea layer is likely to remain the least mature part of the MDA architecture for some time, because it cannot be addressed by simply extending existing surface-tracking approaches; it requires investment in a largely separate sensing and analytic discipline.
Institutional and Acquisition Implications
If the diagnosis above is correct that MDA has become a data-fusion and behavioral-analytics discipline layered on a sensor-collection discipline, not replacing it several implications follow for how governments organize, staff, and buy for maritime security.
First, the workforce implication is real and underappreciated. An organization built to train watch officers to classify discrete contacts against a known adversary order of battle is not automatically equipped to train analysts who can interrogate a fused, multi-source, commercially generated dataset for anomalous behavior across tens of thousands of vessels. The skills involved, data science, behavioral analytics, an understanding of shipping economics and flag-state practice, and the judgment to know when an algorithmic flag warrants escalation, sit closer to those of a financial-crimes investigator than a traditional naval intelligence officer.
Second, continuing to measure maritime security investment primarily in hulls, airframes, and radar sites will produce a force well-equipped for a threat picture that no longer exists. Organic sensors are not obsolete, a warship on scene still has authorities, weapons, and physical presence no satellite feed can replicate, but the marginal dollar spent on data fusion and analytic tradecraft is, for a wide range of current problems, likely to generate more actionable awareness than the marginal dollar spent on an additional patrol platform.
Third, public-private integration needs to be treated as a core institutional competency, not a supplementary arrangement. Commercial providers of SAR, RF, and AIS correlation services are not a stopgap until governments rebuild organic capacity; in most plausible futures they are a permanent, growing part of the architecture, because the economics of small-satellite constellations and software analytics favor continuous commercial iteration over the multi-decade acquisition cycles navies typically operate on. Governments that treat these providers as long-term integration partners will out-perform those that treat them as occasional vendors.
The Core Argument
Maritime domain awareness has not simply become “more difficult” over the past thirty years. It has become a categorically different discipline. The scale of global shipping outran what any navy’s organic sensors could cover. A cooperative identification signal, AIS, created both the first global tracking layer and a permanent evasion incentive, locking awareness and evasion into a continuous technical race. Commercial space and analytics companies displaced state intelligence agencies as the primary generators of maritime data, forcing governments to become integrators and customers of an architecture they no longer own outright. A widening cast of state and non-state actors, sanctioned tanker operators, maritime militias, armed non-state groups, and uncrewed-system operators, learned to exploit the seams of jurisdiction, attribution, and civilian cover that a platform-counting model was never designed to penetrate. And the domain itself has expanded vertically, into an undersea infrastructure layer the surface-tracking architecture cannot see into at all.
The practical consequence is that maritime security today is won or lost in data fusion, behavioral analytics, and public-private intelligence architecture rather than in hull counts or patrol hours. Any policy or acquisition approach that still frames the challenge as “more ships, more planes, more radar” is answering a version of the problem that stopped existing sometime in the last fifteen years. The states, alliances, and companies that recognize this shift earliest and reorganize their workforce, acquisition priorities, and public-private relationships accordingly will close the gap between what needs to be known about the maritime domain and what is, in practice, known. Everyone else will keep buying yesterday’s answer to a question the sea has already stopped asking.
Bibliography
International Maritime Organization, “Maritime Domain Awareness,” https://www.imo.org/en/ourwork/security/pages/maritime-domain-awareness.aspx
Statista, “Total Volume of Global Sea Trade,” https://www.statista.com/chart/24527/total-volume-of-global-sea-trade/
Port Economics, Management and Policy, “World Container Throughput,” https://porteconomicsmanagement.org/pemp/contents/part1/maritime-shipping-and-international-trade/world-container-throughput/
Vector Logistics Group, “Container Fleet Expands Eightfold in 25 Years,” https://vectorlogisticsgroup.com/container-fleet-expands-eightfold-in-25-years/
International Maritime Organization, “Automatic Identification Systems (AIS),” https://www.imo.org/en/ourwork/safety/pages/ais.aspx
Windward, “Looking Beyond AIS,” https://windward.ai/blog/looking-beyond-ais/
S&P Global, “Shadow Fleet Expands to Maintain Sanctioned Oil Flows,” https://www.spglobal.com/energy/en/news-research/latest-news/crude-oil/090325-factbox-shadow-fleet-expands-to-maintain-sanctioned-oil-flows
Reuters, “Shadow Tanker Fleet Grows More Slowly as Western Sanctions Target Russian Oil,” https://www.reuters.com/business/energy/shadow-tanker-fleet-grows-more-slowly-western-sanctions-target-russian-oil-2025-08-13/
RAND Corporation, research report on China’s Maritime Militia, https://www.rand.org/pubs/research_reports/RRA2954-1.html
Small Wars Journal, “Beyond Swarming,” https://smallwarsjournal.com/2026/02/16/beyond-swarming/
NATO, “NATO Launches Baltic Sentry to Increase Critical Infrastructure Security,” https://www.nato.int/en/news-and-events/articles/news/2025/01/14/nato-launches-baltic-sentry-to-increase-critical-infrastructure-security
Defense News, “11 Baltic Cables Damaged in 15 Months, Pushing NATO to Boost Security,” https://www.defensenews.com/global/europe/2025/01/28/11-baltic-cables-damaged-in-15-months-pushing-nato-to-boost-security/
Atlantic Council, “From Cloud to Kill Zone: How Ukraine Rewired Naval Warfare,” https://www.atlanticcouncil.org/in-depth-research-reports/report/from-cloud-to-kill-zone-how-ukraine-rewired-naval-warfare/
Defense News, “Ukraine Is Launching Strike Drones From Everything, Including Black Sea Robo-Boats,” https://www.defensenews.com/global/europe/2026/07/01/ukraine-is-launching-strike-drones-from-everything-including-black-sea-robo-boats/
Coming in the first quarter of 2027:
Available now:
