Industries · Defense and national security
Annex III duties for in-scope civilian AI apply from 2 December 2027AI governance for defense and national security
Article 2(3) of the EU AI Act excludes AI placed on the market exclusively for military purposes. Dual-use and civilian lines stay in scope, and export licensing and procurement audits carry no carve-out at all.
What you need to know
- The military carve-out is narrower than it looks. Article 2(3) of the EU AI Act excludes AI used exclusively for military, defense, or national-security purposes, but Recital 24 pulls mixed-purpose and later re-used systems back into scope. HR and recruitment AI used on the civilian side can still land in Annex III point 4, subject to the Act's ordinary scope and filters.
- The customer regulates through the contract. Alliance programs carry the NATO AI Strategy, revised July 2024, and its six Principles of Responsible Use; US autonomy programs carry DoD Directive 3000.09. Where the solicitation carries them, governance evidence is scored at bid and checked at audit.
- Export licensing carries no carve-out at all. A required licence precedes export of listed dual-use AI under Regulation (EU) 2021/821, and catch-all controls can attach to unlisted items when the authority informs the exporter.
- CMMC 2.0 is phasing into DoD contracts. The final DFARS rule took effect on 10 November 2025 and phases in over three years, with roughly 338,000 defense industrial base contractors and subcontractors in scope at full phase-in.
- The evidence has to hold where the AI Act does not reach. Scope decisions, senior-review sign-offs, test and evaluation records, and supplier documentation form the evidence base for the procurement audit and the export licence application once they live in one governance graph.
The use-case docket
Six recurring defense use cases, compressed to their EU AI Act gates. The out-of-scope rows still answer to the procurement desk, and dual-use rows to the export control desk.
Lethal and semi-autonomous weapon systems (LAWS)
Out of scope of the EU AI Act under Article 2(3) when used exclusively for military purposes. Governed by DoDD 3000.09, NATO PRUs, and the Political Declaration: senior-level review, lifecycle T&E, and deactivation capability are baseline expectations.
Targeting decision support and ISR fusion
Out of scope when use is exclusively military. NATO PRUs and allied doctrine on meaningful human control still apply, and the governance evidence is operationally essential.
HR, recruitment, and talent AI used by ministries and primes
Annex III point 4 covers employment and worker management, subject to the Article 6(3) filters. For civilian use outside the Article 2(3) exclusion, conformity, documentation, and bias-testing duties apply in full.
Dual-use civilian products of defense primes
In scope: a mixed-purpose system falls back in under Recital 24. The gate depends on intended use, most often Annex III. Chapter V GPAI duties sit separately on the model provider.
Generative AI in classified and cleared environments
Out of scope when exclusively national security. NSM-25-style frameworks, NATO PRUs, and classified information-handling rules govern instead; Chapter V still sits on the model provider upstream.
Predictive maintenance, logistics, and sustainment AI
No gate when advisory and not a safety component of a weapons system. NATO PRUs and ISO/IEC 42001 still provide the governance template.
Who can knock, and with what
The gates above are the EU AI Act's classification; each desk below asks on its own legal basis. Open a desk for the mandate, the documents the authority can request, and the clock it runs on.
01Dual-useThe export control authority
The national authority in your member state that licenses exports of dual-use items under Regulation (EU) 2021/821. In the US, the Bureau of Industry and Security holds the equivalent desk.
Export authorisation for dual-use items, a list that includes certain AI software and technology. A required licence precedes export, and catch-all controls can attach to items outside the control list: the Article 5 cyber-surveillance catch-all received Commission guidelines in October 2024, with the first annual implementation report in January 2025. On the US side, BIS rescinded the AI Diffusion Rule in May 2025 with a replacement policy in development, so the exportable envelope for model weights and AI-enabled systems is still moving.
What they can ask for
- The classification of the item against the dual-use control list
- End-use and end-user documentation supporting the licence application
- Records of export transactions, kept for the statutory retention period
- The internal compliance programme, where a global export authorisation relies on one
- Before export
- a required licence precedes shipment
- Case by case
- catch-all controls can attach to unlisted items when the authority informs the exporter
02ProcurementThe customer as regulator
Ministries of defense, NATO procurement bodies, and the US DoD. No statute puts them at your door, but the contract makes their frameworks binding.
Defense procurement enforces AI governance frameworks through the contract. Alliance programs carry the NATO AI Strategy, revised July 2024, and its six Principles of Responsible Use. US autonomy programs carry DoD Directive 3000.09, reissued January 2023, which requires appropriate levels of human judgment over the use of force and senior review for certain autonomous weapon systems. The US defense supply chain carries CMMC 2.0 through DFARS clauses, phasing into contracts over three years since 10 November 2025. NATO PRUs and DoDD 3000.09 are alliance policy and an internal US directive; they reach suppliers through procurement and programme terms. Enforcement runs through contract award and audit.
What they can ask for
- Evidence against the six Principles of Responsible Use on alliance programs
- Senior-review artefacts and lifecycle test and evaluation records under DoDD 3000.09
- CMMC assessment status and DFARS clause flow-down through the subcontract chain
- ISO/IEC 42001 or equivalent management-system evidence where RFPs reference it
- At bid
- governance evidence is scored before award
- At audit
- assessments and program reviews run on the customer's schedule
03AI ActThe market surveillance authority
The market surveillance authority designated by your member state under Regulation (EU) 2024/1689, with powers over in-scope AI regardless of the type of entity.
High-risk AI under Regulation (EU) 2024/1689. Article 2(3) excludes AI placed on the market, put into service, or used exclusively for military, defense, or national-security purposes. Recital 24 keeps the carve-out narrow: a system placed on the market for an excluded and a non-excluded purpose falls back into scope, and so does a military-only system later re-used for civilian purposes. The same company's civilian-facing systems answer in full, and HR and recruitment AI is named high-risk under Annex III. Under the Digital Omnibus, now in force, those duties apply from 2 December 2027.
What they can ask for
- The technical file for in-scope systems, on request under Article 74
- The scoping record behind an Article 2(3) exclusion, showing the use is exclusively military
- Data governance, human oversight, and logging evidence for Annex III systems
- The conformity assessment behind the CE marking
- 2 Dec 2027
- Annex III obligations apply, per the Digital Omnibus, now in force
- 15 days
- serious incident report under Article 73, from awareness
The regimes overlap where the controls live
The defense-relevant frameworks in the library are the EU AI Act, ISO/IEC 42001, and the NIST AI RMF. A control written once, for a scoping record or a lifecycle test regime, is reused by each framework that shares it, and the same evidence supports NATO PRU and procurement audits that sit outside the library.
Framework library v1.0.32
Frequently asked questions
Does the EU AI Act apply to defense AI?
Article 2(3) excludes AI systems placed on the market, put into service, or used exclusively for military, defense, or national-security purposes, regardless of the type of entity. Recital 24 keeps the exclusion narrow. A system placed on the market for an excluded and one or more non-excluded purposes falls back into scope, and a military-only system later re-used for civilian, law-enforcement, or humanitarian purposes falls in as well. Most dual-use, enterprise, and civilian product lines of defense organisations remain fully in scope.
What are NATO Principles of Responsible Use for AI?
The six Principles of Responsible Use, endorsed in the 2021 NATO AI Strategy and restated in the revised strategy of July 2024, are Lawfulness; Responsibility and Accountability; Explainability and Traceability; Reliability; Governability; and Bias Mitigation. They apply across NATO AI adoption and are expected of Allied vendors and partners.
What does DoD Directive 3000.09 require?
DoDD 3000.09, reissued 25 January 2023, governs autonomy in weapon systems. It requires appropriate levels of human judgment over the use of force, establishes a senior-review process for certain autonomous and semi-autonomous weapon systems, and codifies testing, evaluation, verification, and validation expectations across the lifecycle.
What is the Political Declaration on Responsible Military Use of AI?
The Political Declaration on Responsible Military Use of Artificial Intelligence and Autonomy was launched at REAIM in The Hague in February 2023. It is non-binding but politically significant, with 58 endorsing states as of late 2024. Signatories commit to auditability, defined uses, lifecycle testing and evaluation, senior-level review for high-consequence applications, and the ability to deactivate deployed AI systems.
Is ISO/IEC 42001 relevant for defense organisations?
Yes. ISO/IEC 42001 (December 2023) is the first AI management-system standard and is framework-agnostic. It gives defense organisations an audit-grade structure that aligns with NATO PRUs, NIST AI RMF, and the non-excluded portions of the EU AI Act. Regulators and customers are starting to reference it as an evidentiary baseline.
How does CMMC 2.0 interact with AI governance?
The CMMC 2.0 program rule (32 CFR 170) took effect 16 December 2024, and the final DFARS rule, effective 10 November 2025, phases it into DoD contracts over three years. DoD estimates roughly 338,000 defense industrial base contractors and subcontractors in scope at full phase-in. CMMC governs cybersecurity maturity and says nothing about AI, but AI governance controls around supply chain, vendor assessment, and incident response overlap heavily with CMMC practices, so running both in one governance graph avoids duplicated evidence.
How does Modulos help defense organisations?
Modulos gives defense primes, ministries, and mission integrators a single governance graph where NATO PRUs, DoDD 3000.09, NIST AI RMF, ISO/IEC 42001, the dual-use portion of the EU AI Act, the Political Declaration, NIS2, DORA, and CMMC 2.0 share controls and evidence. You inventory AI systems, classify military versus dual-use scope, run senior-review and lifecycle T&E workflows, and generate auditable documentation without duplicating effort across programmes.
See the governance graph on a dual-use program
Talk to an expert
A demo walks through the three desks with a dual-use or enterprise use case: scope decisions recorded per system, senior-review workflows, and the evidence trail a procurement audit expects.
Request a demo →Keep exploring on your own
The risk calculator classifies your likely EU AI Act role in about three minutes, and the EU AI Act primer goes deeper on the Article 2(3) carve-out and the Annex III gates.