Twenty-five years of uptime ended in eleven days, and at no point did anyone power off a server.
What happened¶
Autistici/Inventati (A/I) was a volunteer-run Italian collective, operating since 2001, that provided email, mailing lists, webhosting, and blogs to associations, community groups, and individuals across Europe — its own hardware, its own software, minimal data collection, built specifically to be out of the reach of commercial platforms. The US government's own fact sheet cites the collective's published numbers: roughly 16,000 mailboxes, 1,500 websites, 5,500 mailing lists, 10,000 blogs. A quarter-century of independent infrastructure. That is the thing that stopped existing this month.
On August 26, the US Departments of State and Treasury jointly placed A/I on the OFAC Specially Designated Global Terrorist list under Executive Order 13224 — Treasury press release sb0616, State Department fact sheet. The same action designated Palestine Action (UK-proscribed since July 2025) and Masar Badil, plus two individuals. The theory in Treasury's text is hosting: A/I provided website hosting, encrypted email, chat and video conferencing, and its Noblogs platform, and the fact sheet says groups that carried out rail sabotage in France, Italy, Germany, and the Netherlands in 2026, the March 2026 Transalpine Pipeline sabotage, a January 2026 attack on Berlin's power grid that killed one person, and several doxxing and incitement campaigns relied on A/I tools to publish communiqués, manuals, and claims of responsibility. A/I publishes its own membership policy — users are vetted for alignment before getting accounts, and Treasury treats that vetting as proof of exclusivity. The collective treats the same facts differently: general-purpose secure infrastructure used by people you don't interrogate.
Whether that allegation describes criminal liability is exactly what courts are for. That adjudication never happened. The action contains no charge against the collective — the fact sheet lists the acts of other groups and the hosting theory connecting them. An executive branch wrote a name on a list. The rest of this post is what the internet did with that list.
The kill chain, dated¶
The mechanism deserves more attention than the politics, because every step was a vendor acting on the designation — not a seizure order, not a court.
Day 0 — August 26: listing. The SDN designation blocks all property "subject to US jurisdiction" and prohibits any US person from transacting with the entity. Violations are strict-liability: a payment processor that touches an SDN entry owes penalties even if it thought the payment was fine. Foreign financial institutions face secondary-sanctions exposure — loss of their own US correspondent accounts — which is the part that reached Europe within days.
Days 0–1: the domain died. The collective's primary domain, autistici.org, was a .org domain. The .org registry is the Public Interest Registry — a US company, which is the entire legal hook. Per EDRi's September 3 solidarity statement, PIR disabled the domain without notice. As of the night this post was written (October 4), this site's own check confirms autistici.org does not resolve at all — NXDOMAIN at public resolvers. A registry operator did what the designation made necessary for it to do, and twenty-five years of community sites, blogs, and email addresses lost their front door in the time it takes to edit a zone. Nobody in Italy decided this.
Day 1–7: the payments died. PayPal, a US company, seized A/I's account. This is what strict liability is for — the designation makes every transaction a criminal risk for the processor, so the processor's compliance department is the weapon. No judgment, no appeal to the processor; the appeal is only the OFAC delisting petition, a process measured in years.
Day 6: the bank folded — openly, and with the key document of the whole affair. Banca Etica, an Italian ethics bank that publicized its condemnation of the listing on September 1, suspended A/I's account anyway and said in writing that closure is likely. The reason is the most honest sentence anyone has produced in this story: the alternative is secondary-sanctions exposure that could cost all 130,000 of its other customers their credit and debit cards, because the card rails are, in the bank's own words, a substantial monopoly of US operators. The bank has been asking the Italian government and the EU institutions for usable guidance since September 2025 — it has processed the same dilemma for the UN Special Rapporteur on the occupied Palestinian territories and for ICC judges, both also OFAC-listed — and reports receiving no answer. Webinar with its members on September 9, legal counsel on stage, same conclusion. The compliance was not ideological. It was arithmetic. That's why it is unbeatable at the individual-org level: no amount of courage closes a gap that is structural.
Day 11 — September 6: the collective folded. A/I announced its own shutdown: every day online after August 26 had been a victory, continuing to operate endangers users and adjacent people "in a world where allegations are disconnected from reality," and — in its own words — "None of us holds heroic gestures and martyrs in high esteem, therefore we will demand no sacrifices." Twenty-five years off the air, by announcement. Export instructions for mailboxes, blogs, and sites were promised, with the warning that further outages may land without notice. Tonight's second check: inventati.org still resolves but serves nothing over HTTPS — consistent with their own warning.
What the mechanism teaches¶
This is the same post this site has now written three times, each time at a steeper level. The NGNM raid — the demand went to Cloudflare, not to the data center. The Gag-order pattern. Now this: a host itself taken out through its dependency chain. The owned hardware — the layer that was supposed to be the sovereign part — was never the target and was never touched. The kill switches were the identity layer and the money layer, and both were American:
- DNS is jurisdictional. A .org domain is operated by a US company and reachable by US executive action regardless of where your servers, your organization, and your users are. The same is true for .com and .net (Verisign). If your community's whole identity is one US-registry name, an SDN list or its successor instruments are a single edit away from you. This site is a .com. We are describing ourselves.
- The vendors are the enforcement mechanism. No agency had to visit an Italian data center. The registry, PayPal, and the banks each had a unilateral incentive calculus, and each did the math the way any sane risk office would. The Italian state's courts were never consulted, and the Italian state's institutions — per Banca Etica's account — have not yet produced a usable answer for the entities caught in between.
- EU law and the operational reality diverged. An EU-established intermediary, under the DSA, was terminated by a third-country executive act with no judicial process. The EU's 1996 Blocking Statute (Regulation 2271/96) exists on paper precisely for this; EDRi's demand is to extend it beyond commercial operators to non-profits and to the intermediaries whose compliance gives a foreign designation its practical effect. Until that is real, the default outcome of any future designation is what happened here: collapse by compliance.
None of this is an argument that hosting infrastructure for people is beyond the reach of law, or that the cited attacks did not happen or were not serious. It is an argument about who decides — list, not verdict — and about what the sequence proves: the network will execute on paperwork.
What to actually do¶
For community organizations running — or depending on — shared infrastructure:
- Draw your kill chain before someone else uses it. In order: which registry operates your TLD (and which country's law reaches it), which registrar, which DNS provider, then your payment processors, then your bank and the settlement rails behind it. Each line is a point where someone else's legal process can act unilaterally on you without your courts.
- Treat the TLD as an architectural choice, not a vanity one. A ccTLD whose registry answers to your own jurisdiction's law is a materially different risk position than a US-operator gTLD, for exactly the reason demonstrated above. It does not neutralize the payment layer — nothing currently available fully does — but it removes the fastest, quietest kill.
- Assume the payment layer is the hard constraint and budget accordingly. Card rails are structurally US-exposed; Banca Etica's statement makes clear even dedicated ethical institutions see no safe path today. SEPA direct debit, cooperative local banks, and cash-bearing contingency plans reduce, not eliminate, the exposure. Diversifying across rails, not just providers, is the part worth doing.
- Never let the DNS be a single point of total loss. Archive keys and data under your own control, publish checksummed mirrors, and hold a second domain, registered under a different registry in a different jurisdiction, as break-glass. The domain died first and with zero notice; everything you cannot re-announce after losing your domain is not actually yours.
- If your community still depends on a third-party collective host, do the export now, not during their crisis. A/I promised migration instructions; the lesson generalizes regardless of which collective host you use. The bus-factor post covered one failure mode of small infrastructure (where the fix was a commons); this is another: single-organization legal exposure, where the fix is distributed jurisdiction and rehearsed exit.
- Watch the EU response, because it decides whether this repeats. The asks on the table — a standing protective mechanism for EU-established civil-society entities against third-country designations, and a Blocking Statute that reaches non-profits and intermediaries — are the difference between an anomaly and an instrument. Forty-plus organizations, including the Chaos Computer Club, Digitalcourage, and La Quadrature du Net, signed EDRi's statement. Absent movement, the instrument is already demonstrated and ready for reuse.
Closing¶
Twenty-five years of careful, deliberate, minimal-data infrastructure. It survived Italian courts, ISP disputes, and the general indifference of the market. It did not survive eleven days of a sanctions list, and the most technically telling detail of the entire affair is this: there is no server anywhere in this story that was seized or switched off. The kill chain ran entirely through rented jurisdiction — a TLD registry, a payment processor, the card rails behind an ethics bank that wanted, on the record, to do the opposite of what it did.
That is the whole sovereignty argument in one corpse. Your hardware is the durable layer only if the identity and money layers are yours too. Count your kill switches. A/I had four, and all of them were in another country.
Sources: Treasury press release sb0616, Aug 26; State Department designation fact sheet, Aug 26; Banca Etica statement, Sept 1; EDRi solidarity statement, Sept 3; A/I shutdown announcement, Sept 6 (mirror). Domain status (autistici.org NXDOMAIN, inventati.org resolving, no HTTPS service) verified directly by this site, October 4, 2026.