Modulos Named in the Inaugural Gartner® Magic Quadrant™ for AI Governance PlatformsRead the

Press Release

Industries / Defense and national security

AI governance for defense and national security

Article 2(3) of the EU AI Act excludes AI placed on the market exclusively for military purposes. Dual-use and civilian lines stay in scope, and export licensing and procurement audits carry no carve-out at all.

01Dual-use

The export control authority

Before export a required licence precedes shipment

02Procurement

The customer as regulator

At bid governance evidence is scored before award

03AI Act

The market surveillance authority

2 Dec 2027 Annex III obligations apply, per the adopted Digital Omnibus

The desk

Who can knock, and with what

Each entry lists the authority, its mandate and legal basis, the documents it can request, and the clock it runs on.

Desk 01Dual-use

The export control authority

The national authority in your member state that licenses exports of dual-use items under Regulation (EU) 2021/821. In the US, the Bureau of Industry and Security holds the equivalent desk.

Export authorisation for dual-use items, a list that includes certain AI software and technology. A required licence precedes export, and catch-all controls can attach to items outside the control list: the Article 5 cyber-surveillance catch-all received Commission guidelines in October 2024, with the first annual implementation report in January 2025. On the US side, BIS rescinded the AI Diffusion Rule in May 2025 with a replacement policy in development, so the exportable envelope for model weights and AI-enabled systems is still moving.

What they can ask for

  • The classification of the item against the dual-use control list
  • End-use and end-user documentation supporting the licence application
  • Records of export transactions, kept for the statutory retention period
  • The internal compliance programme, where a global export authorisation relies on one

The clock

Before export
a required licence precedes shipment
Case by case
catch-all controls can attach to unlisted items when the authority informs the exporter
Desk 02Procurement

The customer as regulator

Ministries of defense, NATO procurement bodies, and the US DoD. Not a statutory supervisor, but the contract makes their frameworks binding.

Defense procurement enforces AI governance frameworks through the contract. Alliance programs carry the NATO AI Strategy, revised July 2024, and its six Principles of Responsible Use. US autonomy programs carry DoD Directive 3000.09, reissued January 2023, which requires appropriate levels of human judgment over the use of force and senior review for certain autonomous weapon systems. The US defense supply chain carries CMMC 2.0 through DFARS clauses, phasing into contracts over three years since 10 November 2025. NATO PRUs and DoDD 3000.09 are commitments and directives, not EU law. Their enforcement mechanism is award and audit, not fines.

What they can ask for

  • Evidence against the six Principles of Responsible Use on alliance programs
  • Senior-review artefacts and lifecycle test and evaluation records under DoDD 3000.09
  • CMMC assessment status and DFARS clause flow-down through the subcontract chain
  • ISO/IEC 42001 or equivalent management-system evidence where RFPs reference it

The clock

At bid
governance evidence is scored before award
At audit
assessments and program reviews run on the customer's schedule
Desk 03AI Act

The market surveillance authority

The market surveillance authority designated by your member state under Regulation (EU) 2024/1689, with powers over in-scope AI regardless of the type of entity.

High-risk AI under Regulation (EU) 2024/1689. Article 2(3) excludes AI placed on the market, put into service, or used exclusively for military, defense, or national-security purposes. Recital 24 keeps the carve-out narrow: a system placed on the market for an excluded and a non-excluded purpose falls back into scope, and so does a military-only system later re-used for civilian purposes. The same company's civilian-facing systems answer in full, and HR and recruitment AI is named high-risk under Annex III. Under the adopted Digital Omnibus, those duties apply from 2 December 2027.

What they can ask for

  • The technical file for in-scope systems, on request under Article 74
  • The scoping record behind an Article 2(3) exclusion, showing the use is exclusively military
  • Data governance, human oversight, and logging evidence for Annex III systems
  • The conformity assessment behind the CE marking

The clock

2 Dec 2027
Annex III obligations apply, per the adopted Digital Omnibus
15 days
serious incident report under Article 73, from awareness

The evidence has to hold where the AI Act does not reach

Article 2(3) removes an EU legal obligation from exclusively military systems. It does not remove the audience. The same systems face the procurement audit and the export licence application, and those desks ask for much of the same evidence: an inventory with recorded scope decisions, test and evaluation results, senior-review sign-offs, supplier and end-user documentation. Modulos keeps that evidence as one governance graph, where a control written once earns credit across the AI Act where it applies and NATO PRUs, DoDD 3000.09, ISO/IEC 42001, and CMMC 2.0 where it does not. Scope is decided per system, recorded once, and defensible at whichever desk asks first.

01 Dual-use02 Procurement03 AI ActOne evidence record

Dates that matter

10 Nov 2025

Final DFARS rule effective; CMMC 2.0 phases into DoD contracts over three years

2 Dec 2027

Annex III duties for dual-use and civilian lines, HR and recruitment AI included, per the adopted Digital Omnibus

The use-case docket

Six recurring defense use cases, compressed to their EU AI Act gates. The out-of-scope rows still answer to the procurement desk, and dual-use rows to the export control desk.

Lethal and semi-autonomous weapon systems (LAWS)

Out of scope of the EU AI Act under Article 2(3) when used exclusively for military purposes. Governed by DoDD 3000.09, NATO PRUs, and the Political Declaration: senior-level review, lifecycle T&E, and deactivation capability are baseline expectations.

Out of scope (Art. 2)

Targeting decision support and ISR fusion

Out of scope when use is exclusively military. NATO PRUs and allied doctrine on meaningful human control still apply, and the governance evidence is operationally essential.

Out of scope (Art. 2)

HR, recruitment, and talent AI used by ministries and primes

High-risk under Annex III point 4, employment and worker management. Conformity, documentation, and bias-testing duties apply independently of the military carve-out.

High-risk (Annex III)

Dual-use civilian products of defense primes

In scope: a mixed-purpose system falls back in under Recital 24. The gate depends on intended use, most often Annex III. Chapter V GPAI duties sit separately on the model provider.

High-risk (Annex III)

Generative AI in classified and cleared environments

Out of scope when exclusively national security. NSM-25-style frameworks, NATO PRUs, and classified information-handling rules govern instead; Chapter V still sits on the model provider upstream.

Out of scope (Art. 2)

Predictive maintenance, logistics, and sustainment AI

No gate when advisory and not a safety component of a weapons system. NATO PRUs and ISO/IEC 42001 still provide the governance template.

No AI Act gate

Related regulations

Go deeper on the regimes that apply to this sector:

Not sure where you stand?

The risk calculator classifies your likely EU AI Act role and puts a number on your exposure in about three minutes.

Run the risk calculator

Frequently asked questions

Does the EU AI Act apply to defense AI?

Article 2(3) excludes AI systems placed on the market, put into service, or used exclusively for military, defense, or national-security purposes, regardless of the type of entity. Recital 24 keeps the exclusion narrow. A system placed on the market for an excluded and one or more non-excluded purposes falls back into scope, and a military-only system later re-used for civilian, law-enforcement, or humanitarian purposes falls in as well. Most dual-use, enterprise, and civilian product lines of defense organisations remain fully in scope.

What are NATO Principles of Responsible Use for AI?

The six Principles of Responsible Use, endorsed in the 2021 NATO AI Strategy and restated in the revised strategy of July 2024, are Lawfulness; Responsibility and Accountability; Explainability and Traceability; Reliability; Governability; and Bias Mitigation. They apply across NATO AI adoption and are expected of Allied vendors and partners.

What does DoD Directive 3000.09 require?

DoDD 3000.09, reissued 25 January 2023, governs autonomy in weapon systems. It requires appropriate levels of human judgment over the use of force, establishes a senior-review process for certain autonomous and semi-autonomous weapon systems, and codifies testing, evaluation, verification, and validation expectations across the lifecycle.

What is the Political Declaration on Responsible Military Use of AI?

The Political Declaration on Responsible Military Use of Artificial Intelligence and Autonomy was launched at REAIM in The Hague in February 2023. It is non-binding but politically significant, with 58 endorsing states as of late 2024. Signatories commit to auditability, defined uses, lifecycle testing and evaluation, senior-level review for high-consequence applications, and the ability to deactivate deployed AI systems.

Is ISO/IEC 42001 relevant for defense organisations?

Yes. ISO/IEC 42001 (December 2023) is the first AI management-system standard and is framework-agnostic. It gives defense organisations an audit-grade structure that aligns with NATO PRUs, NIST AI RMF, and the non-excluded portions of the EU AI Act. Regulators and customers are starting to reference it as an evidentiary baseline.

How does CMMC 2.0 interact with AI governance?

The CMMC 2.0 program rule (32 CFR 170) took effect 16 December 2024, and the final DFARS rule, effective 10 November 2025, phases it into DoD contracts over three years. DoD estimates roughly 338,000 defense industrial base contractors and subcontractors in scope at full phase-in. CMMC governs cybersecurity maturity, not AI, but AI governance controls around supply chain, vendor assessment, and incident response overlap heavily with CMMC practices, so running both in one governance graph avoids duplicated evidence.

How does Modulos help defense organisations?

Modulos gives defense primes, ministries, and mission integrators a single governance graph where NATO PRUs, DoDD 3000.09, NIST AI RMF, ISO/IEC 42001, the dual-use portion of the EU AI Act, the Political Declaration, NIS2, DORA, and CMMC 2.0 share controls and evidence. You inventory AI systems, classify military versus dual-use scope, run senior-review and lifecycle T&E workflows, and generate auditable documentation without duplicating effort across programmes.

See the governance graph on a dual-use program

A demo walks through the three desks with a dual-use or enterprise use case. The quiz classifies your role and risk exposure in about three minutes.