AI governance for defence, security, and critical national infrastructure — under partial EU AI Act exemptions, national security frameworks, and emerging responsible-AI-in-defence principles.
The regulatory picture
The regulatory landscape for AI in defence is distinctive. It is not just the EU AI Act — it is the EU AI Act read together with sector-specific supervision, standards, and case law. A defensible AI compliance posture in this sector engages with all of the following:
- EU AI Act (Art. 2 exclusions) — Systems developed or used exclusively for military, defence, or national security purposes fall outside the Act. Dual-use systems do not — and the boundary is where much of the practical work sits.
- UK Defence AI Strategy and Ambitious, Safe, Responsible principles — The MOD’s five ethical principles for AI in defence — the reference framework for UK defence AI.
- NATO Principles of Responsible Use — Alliance-level guidance on AI in military contexts.
- JSP 936 (UK MOD) — Emerging MOD policy on dependable AI in defence.
- US DoD Directive 3000.09 — Autonomy in weapon systems — the reference document even for non-US programmes.
- CNI regulation and NIS 2 — AI in critical national infrastructure operators sits alongside the Network and Information Systems regime.
Where AI is being used
The AI systems most commonly deployed or being procured in defence:
- ISR (intelligence, surveillance, reconnaissance) analytics
- Predictive maintenance for platforms
- Logistics optimisation
- Cyber defence and threat detection
- Simulation, training, and mission planning
- Command decision support
- Autonomy in unmanned platforms (with distinctive governance considerations)
Recommended pathway
A six-programme sequence for professionals building AI governance capability specifically for defence. Delivered as individual enrolments or as a cohort licence.
Foundations of AI for Non-Technical Professionals
Common baseline across capability, legal, and safety functions.
EU AI Act Foundations
Understand the Article 2 exclusions and where they end.
AI Governance for the Enterprise
The governance architecture principles apply; the specifics are adapted for defence context.
AI Risk and Assurance
Risk assessment against Ambitious, Safe, Responsible and JSP 936 expectations.
AI Incident Response
Because defence AI incidents carry distinctive severity and disclosure considerations.
Third-Party AI Risk
For the AI supplied by primes and sub-tier vendors in complex defence supply chains.
A representative scenario
A UK defence prime is developing an AI-enabled ISR analytics capability for MOD, with dual-use derivatives intended for civil critical national infrastructure customers. The programme is exempt from the EU AI Act for its military use but in scope for its CNI use. Ambitious, Safe, Responsible applies to the military use. Both use cases must share as much of the governance stack as possible while preserving the distinctions the regulatory regimes require. The SAAII Defence pathway builds that dual-track governance capability.
The sector overlay
The Defence overlay adds sector-specific worked examples (Art. 2 boundary cases, Ambitious Safe Responsible mapping, dual-use governance patterns) and a sector-specific assessment brief to every relevant programme. Delivered under enhanced information handling appropriate to defence audiences.
Ready to build defence AI capability at scale?
Request a briefing to discuss cohort licensing, the sector overlay, and pathway design tailored to your organisation.
Request a briefing → or write to teams@thesaaii.com