AxiLayer AI crestAxiLayerAI
Industries · Global Defense & National Security

AI Assurance for Defense & National Security

Autonomy, ISR, battle management, cyber defence and generative staff assistants are being fielded faster than any defence ministry can test them, while acquisition rules, alliance principles and multilateral norms all now demand evidence of human judgment, tested envelopes and controlled technology. AxiLayer AI and AxiSentinel™ give primes, defence-tech vendors and government programmes across the United States, NATO and the European Union, the United Kingdom, the UAE and GCC, and Asia-Pacific independent, continuous TEVV and compliance evidence, including fully air-gapped and classified deployment. This is an assurance and compliance practice: we evaluate and evidence AI systems; we do not develop weapons.

10 Nov 2025
CMMC Phase 1 live in new US defence contracts
58
States endorsing the Political Declaration on military AI
5% by 2035
NATO defence-spending pledge, The Hague, June 2025
166 to 3
UN General Assembly vote on autonomous weapons, 2 Dec 2024
Air-gapped
Classified deployment via the .axibatch format
What Changed in 2026

The eighteen months that gave defence AI budgets, contract clauses and a deadline

Between May 2025 and November 2026, defence AI governance moved on three fronts at once: acquisition rules made cyber and AI evidence a condition of contract, alliance and national budgets made autonomy the fastest-growing spend line, and the multilateral track set an explicit deadline. Each front asks for the same thing, proof.

13 to 16 May 2025 · United States & the Gulf
Export controls are reshaped, and the US-UAE AI Acceleration Partnership is signed
On 13 May 2025 the Bureau of Industry and Security rescinded the AI Diffusion Rule two days before its compliance date, replacing the three-tier framework with guidance on advanced-computing ICs and diversion prevention. On 16 May 2025 Washington and Abu Dhabi established the US-UAE AI Acceleration Partnership, a day after unveiling the planned 5GW UAE-US AI campus in Abu Dhabi. In November 2025, Commerce authorised exports to the UAE's G42 and Saudi Arabia's Humain of up to 35,000 Nvidia GB300-class chips each, conditioned on rigorous security and reporting requirements. The compliance model has shifted from tiered denial to security-conditioned approval: demonstrable, ongoing evidence of controlled access is now the operating condition of the licence itself, and ITAR and EAR licensing still governs most defence AI transfers to the region.
24 to 25 June 2025 · NATO & Europe
The Hague summit commits Allies to 5% of GDP by 2035, and the money is already moving
All Allies except Spain committed to 5% of GDP by 2035, 3.5% for core defence plus 1.5% for resilience, infrastructure and innovation, with a review in 2029. It lands on top of NATO's revised AI Strategy of 10 July 2024, which directs an Alliance-wide AI testing, evaluation, verification and validation (TEV&V) landscape built on DIANA-affiliated test centres, and the Data and AI Review Board's responsible-AI certification work. On the EU side, the White Paper for European Defence Readiness 2030 (19 March 2025) and the ReArm Europe plan mobilise up to €800 billion, with AI, quantum, cyber and electronic warfare named among seven priority capability areas. The European Defence Agency reported EU-27 defence spending of €418 billion in 2025, up 20%, with €454 billion projected for 2026.
14 August 2025, January 2026 · United States
The Pentagon becomes the Department of War and rewires its AI enterprise
On 14 August 2025 the Deputy Secretary of Defense realigned the CDAO under the Under Secretary of Defense for Research and Engineering; in September 2025 the department adopted the Department of War designation; and in January 2026 it issued an Artificial Intelligence Strategy built around seven Pace-Setting Projects, launched GenAI.mil to bring secure large language models to roughly three million personnel, and placed DIU and the Strategic Capabilities Office under the CTO. The FY2026 NDAA (P.L. 119-60, signed 18 December 2025) carries nearly triple the AI provisions of its predecessor, and the FY2026 budget includes a $13.4 billion dedicated AI and autonomy line, the first year it is tracked standalone. Through all of it, DoD Directive 3000.09 (25 January 2023) remains the binding rule: autonomous and semi-autonomous weapon systems must allow commanders and operators to exercise appropriate levels of human judgment over the use of force.
10 November 2025 · United States
CMMC becomes a contract clause, then pauses at Phase 1
The 48 CFR acquisition rule (published 10 September 2025) took effect on 10 November 2025, putting DFARS 252.204-7021 into new solicitations: Phase 1 requires CMMC Level 1 and Level 2 self-assessments in SPRS as a pre-award condition, with continuous-compliance affirmation, on top of the 32 CFR programme rule in force since 16 December 2024 and the long-standing DFARS 252.204-7012. On 13 July 2026 the Department of War paused the move to Phases 2 to 4 while a CMMC Reform Task Force reviews the programme, but Phase 1 remains fully in force and NIST SP 800-171 is being enforced through self-assessments and government-led checks in the interim. Any contractor whose AI pipeline touches CUI needs that evidence current regardless of which phase ultimately applies.
4 February, 20 November 2026 · The multilateral track
REAIM 3 adopts a Plan of Action as the UN's autonomous-weapons deadline arrives
The third REAIM summit (A Coruña, Spain, 4 to 5 February 2026) produced a Plan of Action, following Seoul 2024's Blueprint for Action, though with the United States no longer actively engaged, having voted against the October 2025 UN resolution on responsible military AI it once championed. The CCW GGE on LAWS negotiated its rolling text through a 2 to 6 March 2026 session and delivers its final report to the Seventh CCW Review Conference, 16 to 20 November 2026 in Geneva, the forum the UN Secretary-General and ICRC president, in a renewed joint statement of 25 August 2026, call the clearest path to a legally binding instrument by the end of 2026. Behind it sits UNGA Resolution 79/62 (2 December 2024), adopted 166 to 3 with 15 abstentions, and a 42-state declaration of readiness to negotiate. Binding or not, the direction of evidence expectations is unambiguous.
Acquisition, alliance and multilateral tracks are converging on the same three questions: can you evidence that a human exercised judgment, that the system stayed inside its tested envelope, and that controlled technology stayed controlled? Those are assurance questions, and they are answerable only with independent, continuous records.

The assurance gap

Adoption is outrunning the capacity to test it. GAO found federal AI use cases nearly doubled from 571 in 2023 to 1,110 in 2024, while its reviews of the DoD AI workforce (GAO-24-105645) echo the National Security Commission on AI's finding that the talent deficit, above all in test and evaluation, is among the greatest impediments to AI readiness. NATO's Alliance-wide TEV&V landscape is still being assembled. And the Replicator dispute, thousands of systems declared fielded in August 2025, hundreds counted by the Congressional Research Service, shows what happens when capability claims outrun independent evidence. That gap is precisely what a continuous, third-party evidence chain closes.

Who this page is for

  • Prime contractors and systems integrators
  • Defence-tech and autonomy startups
  • C2, ISR and battle-management software vendors
  • Drone and uncrewed-systems manufacturers
  • Defence agencies and ministries
  • Intelligence community programmes
  • Allied and GCC defence buyers
  • Exporters of dual-use, export-controlled AI

Everything here is defensive: testing, evaluation, governance and compliance of AI already in or entering service. AxiLayer AI does not design, develop or advise on weapons.

Federal Vendor Profile

CAGE 20JV1 · UEI CB76ENDLMUC9 · SAM.gov active for all award types. AxiSentinel supports air-gapped and classified deployment via the .axibatch format.

Government Profile
Global Coverage

Every framework that touches a defence AI system, by region

A single autonomy stack can simultaneously face a 3000.09 senior review in the United States, NATO's Principles of Responsible Use in a coalition deployment, JSP 936 in a UK programme, an Article 36 legal review before fielding, ITAR licensing on export and a sovereign air-gap requirement in the Gulf. Each regime wants different evidence in a different format. This is the coverage map.

United States
Department of War / DoD, CDAO, and the acquisition rulebook
CMMC Phase 1 liveDoDD 3000.09 binding

The world's largest defence AI buyer now runs an AI-first innovation enterprise on one side and a contract-clause compliance regime on the other. Vendors must satisfy both.

  • DoD Directive 3000.09 (25 January 2023), autonomous and semi-autonomous weapon systems must be designed to allow appropriate levels of human judgment over the use of force, with rigorous verification and validation and senior-level review before formal development and again before fielding for covered systems. Still the operative policy in 2026.
  • Responsible AI, the DoD AI Ethical Principles (February 2020) and the RAI Strategy and Implementation Pathway (June 2022) with the CDAO's RAI Toolkit; the CDAO realigned under USD(R&E) on 14 August 2025, followed by the January 2026 Department of War AI Strategy, seven Pace-Setting Projects and GenAI.mil.
  • CMMC 2.0, 32 CFR programme rule effective 16 December 2024; 48 CFR acquisition rule effective 10 November 2025; DFARS 252.204-7012 and -7021; Phase 1 self-assessments in SPRS as a pre-award condition; Phases 2 to 4 paused 13 July 2026 pending the CMMC Reform Task Force, with NIST SP 800-171 enforced meanwhile (Revision 3 published May 2024, assessments still tied to Revision 2).
  • FedRAMP and DoD Impact Levels, IL4/IL5 for CUI-hosting cloud AI, IL6 for classified; air-gapped enclaves for the programmes that never touch shared infrastructure at all.
  • FY2026 NDAA (P.L. 119-60, 18 December 2025), nearly triple the AI provisions of FY2025, a Title XV AI subtitle, prohibitions on covered foreign-adversary AI systems, and AI pilot programmes; a $13.4 billion dedicated AI and autonomy budget line.
  • Autonomy at scale, Replicator 1 fielding declared achieved August 2025 (CRS counted hundreds fielded with thousands on contract); Replicator 2 counter-sUAS first award 11 January 2026.
AxiSentinel coverage: 3000.09 human-judgment evidence · CUI-safe monitoring for CMMC · TEVV evidence chain · IL-aligned air-gapped deployment
NATO & European Union
NATO AI Strategy, DIANA, the AI Act boundary and the EDF
AI Strategy rev. Jul 2024ReArm €800B

NATO sets the responsible-use baseline for 32 Allies; the EU funds the industrial base while its AI Act draws a military exclusion line that is narrower than most vendors assume.

  • NATO AI Strategy (2021, revised 10 July 2024), six Principles of Responsible Use: lawfulness, responsibility and accountability, explainability and traceability, reliability, governability, and bias mitigation, extended in 2024 to generative AI and AI-enabled disinformation.
  • Alliance-wide TEV&V landscape, the revised strategy directs its build-out on DIANA-affiliated test centres, with the Data and AI Review Board developing a responsible-AI certification standard (work under way since February 2023) and the NATO Innovation Fund backing dual-use deep tech.
  • The Hague summit (24 to 25 June 2025), 5% of GDP by 2035 (3.5% core + 1.5% resilience and innovation), review in 2029: the procurement forcing function for AI-enabled capability across the Alliance.
  • EU AI Act Article 2(3), systems placed on the market or used exclusively for military, defence or national-security purposes are excluded, but dual-use systems and civilian-security uses fall in scope, with penalties up to €35M or 7% of turnover; the Digital Omnibus (in force 27 July 2026) moved Annex III obligations to 2 December 2027. Classifying which side of the line each system sits on is now a documented, defensible exercise.
  • European Defence Readiness 2030, White Paper of 19 March 2025 and ReArm Europe: up to €800 billion including the €150 billion SAFE instrument, with AI, quantum, cyber and electronic warfare among seven priority capability areas; the European Defence Fund financing collaborative AI R&D; EDA-reported EU-27 spending of €418 billion in 2025 rising to a projected €454 billion in 2026.
  • National frameworks, France's ministerial defence AI ethics committee and its dedicated defence AI agency AMIAD (2024); Germany's emphasis on meaningful human control in the GGE debates.
AxiSentinel coverage: PRU-aligned traceability · TEVV artefacts for DIANA-style test regimes · Article 2(3) boundary classification · coalition interoperability evidence
United Kingdom
MOD, JSP 936, Dstl and the AI Security Institute
JSP 936 Nov 2024

The UK is the first ally to turn defence AI ethics into a numbered directive with auditable "musts", which makes it the clearest preview of where allied assurance expectations are heading.

  • JSP 936 Part 1: Dependable AI in Defence (Directive, 13 November 2024), governance, development and assurance duties across the full AI lifecycle, spanning quality, safety and security; independent analysis counts 151 "must" and 121 "should" requirements. Part 2 guidance remains in development, suppliers must evidence compliance against the directive now.
  • Defence AI Strategy (June 2022) and the Ambitious, Safe and Responsible policy, five ethical principles (human-centricity, responsibility, understanding, bias and harm mitigation, reliability) overseen with advice from the MOD's AI ethics advisory panel.
  • Dstl and the Defence AI Centre, the research and experimentation backbone for testing AI-enabled capability, including AUKUS trial participation.
  • AI Security Institute, the UK's frontier-model evaluation body (renamed from AI Safety Institute in February 2025), whose national-security-focused evaluations increasingly inform defence-relevant model assurance.
  • International posture, a Political Declaration endorser and CCW participant favouring non-binding measures; Article 36 legal reviews of new weapons, means and methods remain a standing UK obligation.
AxiSentinel coverage: JSP 936 "must" evidence mapping · lifecycle assurance artefacts · human-oversight and reliability records for MOD programmes
United Arab Emirates & GCC
EDGE, Tawazun, GAMI, SAMI, and the US technology-transfer perimeter
US-UAE Partnership May 2025GAMI 50% by 2030

The Gulf is building sovereign defence AI at speed, and every step of it runs through US export-control and security-assurance conditions. Localisation plus tech transfer equals a compliance-evidence market.

  • US-UAE AI Acceleration Partnership (16 May 2025), framework commitments on protection of US technology, alongside the 5GW UAE-US AI campus in Abu Dhabi; November 2025 Commerce approvals for G42 (up to 35,000 Nvidia GB300-class chips) conditioned on rigorous security and reporting, continuous evidence of controlled access is the licence's operating condition.
  • EDGE Group, 42 new systems unveiled at Dubai Airshow in November 2025; the EDGE-Anduril joint venture (announced November 2025) to design and produce autonomous systems in the UAE, beginning with the Omen autonomous air vehicle, 50 confirmed for UAE acquisition.
  • Tawazun Council, defence acquisition and the Tawazun Economic Program (offsets and localisation), the Al Selmiyyah defence industrial free zone, and 2025 localisation projects with MBDA including AI-enabled systems.
  • Saudi Arabia, GAMI reports military-spending localisation of 24.89% at end-2024 against the 50%-by-2030 Vision 2030 target; SAMI launched SAMI Autonomous Company (February 2026) and is collaborating with NVIDIA on an AI defence lab in Riyadh; SDAIA's national AI Risk Management Framework (July 2026) supplies the horizontal governance layer.
  • Qatar, Barzan Holdings as the defence-technology acquisition and investment arm.
  • The compliance burden, ITAR and EAR licensing on defence AI transfers, security-conditioned chip approvals, offset obligations with AI content, and sovereign, air-gapped deployment requirements for classified and national workloads.
AxiSentinel coverage: sovereign in-country deployment via AXI-Node · export-control boundary evidence · localisation and offset compliance artefacts · air-gapped .axibatch operation
Asia-Pacific
AUKUS Pillar 2, Japan MOD, Korea's Defense AI Center, India's iDEX
AUKUS Pillar 2 trialsKorea AI Act Jan 2026

The Indo-Pacific is institutionalising military AI four different ways at once: trilateral interoperability, formal ethics directives, dedicated R&D centres and startup pipelines.

  • Australia & AUKUS Pillar 2, the first trilateral AI and autonomy trial (Upavon, UK, 2023) demonstrated collaborative swarming with live in-flight model retraining and AI-model interchange between the three nations; Exercise Autonomous Warrior 2024 ran roughly 30 capabilities at scale; a trilateral algorithm now improves P-8 anti-submarine information sharing. Model interchange between allies is an assurance problem before it is an engineering one.
  • Japan, the Ministry of Defense's first Basic Policy on AI utilisation (2 July 2024), followed in June 2025 by responsible-AI guidelines for defence R&D that prohibit development of fully autonomous lethal systems and mandate legal, policy and technical review of high-risk projects; the 2026 defence white paper elevates AI and cyber.
  • Republic of Korea, the Defense AI Center (April 2024, Agency for Defense Development, ~110 staff) under Defense Innovation 4.0, focused on manned-unmanned teaming and battlefield awareness; the AI Framework Act in force 22 January 2026 adds a national high-impact regime around it.
  • India, iDEX has awarded roughly 650 contracts (~US$344 million) across 50+ technology categories; DISC-14 and ADITI 4.0 (launched 2026) put 107 problem statements to industry, with autonomous swarms and defence AI among ADITI's 30 strategic technologies.
  • Israel and Singapore, both Political Declaration endorsers with active defence AI programmes and export markets that inherit end-user assurance expectations.
AxiSentinel coverage: coalition model-interchange evidence · human-oversight records for Japan/Korea regimes · per-market TEVV packs for export programmes
International Norms & Export Controls
Political Declaration, REAIM, UN GGE and GA, Article 36, ITAR/EAR, Wassenaar
58 endorsing statesCCW RevCon Nov 2026

None of this layer is a contract clause, yet it defines what "responsible" means in every allied procurement, and export-control law makes parts of it very binding indeed.

  • Political Declaration on Responsible Military Use of AI and Autonomy, launched February 2023 at REAIM The Hague, now endorsed by 58 states; ten measures including auditable methodologies, rigorous testing and assurance across the lifecycle, and safeguards against unintended behaviour, effectively an international TEVV expectation.
  • REAIM summits, The Hague (February 2023), Seoul (September 2024, Blueprint for Action), A Coruña (4 to 5 February 2026, Plan of Action), with the GC REAIM commission's "Responsible by Design" report (September 2025) translating declarations into practice.
  • UN General Assembly, first LAWS resolution December 2023 (152 to 4 to 11); Resolution 79/62 (2 December 2024) adopted 166 to 3 to 15; informal consultations in New York, 12 to 13 May 2025, with 96 states participating.
  • CCW GGE on LAWS, rolling text negotiated through 2024 to 2026 (session 2 to 6 March 2026); final report due at the Seventh Review Conference, 16 to 20 November 2026; the UN Secretary-General and ICRC renewed their call for a legally binding instrument by end-2026 on 25 August 2026.
  • Article 36, Additional Protocol I, the standing legal-review obligation for new weapons, means and methods of warfare: the point where TEVV evidence meets international humanitarian law.
  • Export controls, ITAR and the USML for defence articles; EAR and the CCL for dual-use AI and compute; the Wassenaar Arrangement's dual-use lists; the AI Diffusion Rule rescinded 13 May 2025 in favour of guidance plus security-conditioned approvals, with model-weight controls still under active policy debate.
AxiSentinel coverage: Declaration-measure evidence mapping · Article 36 review support records · export-boundary and end-user assurance documentation
Coverage

Defence & national-security AI use cases we cover

Each use case below carries a specific governing instrument, a specific evidence expectation and a specific review gate. AxiSentinel is configured per use case and per programme, in your environment, at your classification level, rather than shipped as one fixed pipeline.

ISR & sensor fusion
NATO PRU traceability and reliability; CUI/classified data handling under CMMC and Impact Levels; drift monitoring across sensor modalities.
Targeting-support & decision aids
DoDD 3000.09 appropriate human judgment; documented human-in-the-loop evidence; IHL proportionality and distinction support records.
Autonomous & uncrewed systems (air/land/sea)
3000.09 senior review; JSP 936 lifecycle assurance; Article 36 legal review; tested operating envelope with field-drift evidence.
Swarming & collaborative autonomy
AUKUS-style model interchange and in-flight retraining demand provenance and revalidation evidence per model version.
C2 & battle-management AI
NATO interoperability and governability principles; coalition releasability; explainability records for command decisions.
Electronic warfare & spectrum AI
Adaptive behaviour outside test conditions is the core risk; envelope monitoring and anomaly reporting are the evidence.
Cyber defence AI
CMMC and NIST SP 800-171/172 alignment; FY2026 NDAA cyber provisions; autonomous-response oversight evidence.
Logistics & predictive maintenance
The most-fielded defence AI class; drift and data-quality monitoring keep low-risk systems from silently becoming operational dependencies.
Intelligence analysis & OSINT AI
Source provenance, confidence calibration and analytic-tradecraft standards; IC-grade audit trails at classification.
GenAI & LLM staff assistants
GenAI.mil-class deployments; hallucination, leakage and prompt-injection guardrails with CUI-safe logging.
Wargaming & simulation AI
Validity evidence for synthetic adversaries; documented limits so simulation outputs are not over-trusted in planning.
Training & synthetic data
Data provenance and poisoning defence; JSP 936 data-quality duties; evidence that synthetic distributions match operational reality.
Space domain awareness
Sensor-fusion AI for tracking and conjunction warning; performance-envelope evidence for high-consequence, low-signal decisions.
Base security & force protection
Biometric and surveillance AI; civilian-security uses can fall inside the EU AI Act despite the Article 2(3) military exclusion.
Counter-UAS
Replicator 2's focus; engagement-decision oversight, false-target rates and rules-of-engagement conformance evidence.
Personnel & readiness analytics
Fairness and privacy obligations survive the military exclusion; bias-testing evidence for selection and readiness models.
Procurement & supply-chain risk AI
FY2026 NDAA foreign-adversary AI prohibitions; provenance screening of models and components entering the supply chain.
Dual-use, export-controlled models
ITAR/EAR boundary classification; end-user and end-use assurance; security-conditioned approval evidence for GCC transfers.
Mission planning & course-of-action tools
Decision-support with command accountability; explainability and override records aligned to PRU governability.
Test ranges & digital twins
The TEVV infrastructure itself needs assurance: twin-fidelity evidence and test-to-field traceability for every certified envelope.
For Investors

Defence is where assurance is mandated, funded and under-supplied

Defence buyers do not need persuading that testing matters, TEVV is written into their directives. What they lack is capacity: independent evaluators who can work at classification, inside the wire, continuously. That scarcity, not marketing, is the commercial thesis.

$19 to 29B
Military AI market by 2030
Research-house estimates for 2030 range from roughly $19 billion to $29 billion at 13 to 20% CAGR, with broader aerospace-and-defence AI estimates above $43 billion, scope definitions differ, so ranges are presented rather than points.
5% by 2035
NATO spending pledge, June 2025
3.5% core plus 1.5% resilience and innovation across 31 committing Allies, reviewed in 2029; EDA reports EU-27 defence spending of €418 billion in 2025, up 20% year on year.
$13.4B
FY2026 US AI & autonomy budget line
The first year AI and autonomy is tracked as a standalone US defence budget line, alongside an FY2026 NDAA carrying nearly triple the AI provisions of FY2025.
10 Nov 2025
CMMC in contracts, recurring by design
Phase 1 self-assessment and continuous-affirmation duties attach at award and persist through performance; the July 2026 pause of later phases changes the timetable, not the evidence obligation.
58
Political Declaration endorsing states
Ten measures including auditable methodologies and lifecycle testing, a non-binding instrument that functions as the de facto responsible-AI floor in allied procurement.
36 to 51%
AI governance market CAGR to 2030
Consistent across research houses even where absolute levels diverge; monitoring and auditing already the largest functionality share, defence adds the highest-barrier, highest-stakes segment of that market.

The commercial logic, stated plainly

The honest risk picture

Market figures are drawn from third-party research houses whose scope definitions differ materially; ranges are presented rather than point estimates. Regulatory and policy descriptions are summaries for orientation, not legal advice. This page describes assurance, testing and compliance services only; AxiLayer AI does not develop weapons or operational capabilities. Nothing on this page is an offer to sell securities.