Use-case guide
AI in Defense & National Security
Defense AI lives in its own regulatory universe — partly governed by the same AI laws that cover everyone else, partly by export controls (EAR/ITAR, EU dual-use regulation), and partly by national-security carve-outs that exempt some uses but expose others. The EU AI Act includes a national-security carve-out (Article 2(3)) but it's narrower than industry expected. The US, UK, and allies have all issued separate frameworks (NDAA-driven RAI guidance, MOD JSP 936, NATO AI strategy) that operate parallel to civilian AI law. The combination produces tight margins for error: get the export classification wrong, and a software update becomes a criminal act.
For: Defense primes, government acquisition, intelligence community contractors, dual-use AI startups, export-control counsel
What's at stake
The EU AI Act national-security carve-out is narrow
Article 2(3) excludes AI systems 'placed on the market, put into service, or used, with or without modification, exclusively for military, defence or national security purposes' — but ONLY for those exclusive purposes. Dual-use systems are still in scope. The 'exclusively' word does a lot of work.
Export controls treat AI as controlled tech
The US EAR / ITAR, the EU Dual-Use Regulation (2021/821), and the Wassenaar Arrangement all now explicitly catch AI software, model weights, and certain training-data sets under controlled categories. Cloud APIs into adversary territory are deemed exports.
Autonomous-weapons frameworks are coalescing
The UN CCW LAWS process, DoD Directive 3000.09 (Autonomy in Weapon Systems, updated 2023), and UK MOD JSP 936 each require human-on-the-loop / appropriate-level-of-human-judgment for lethal force. Non-compliance is a crime, not a fine.
Procurement requires Responsible-AI certifications
The US DoD CDAO Responsible AI Strategy and Implementation Pathway requires capability owners to document responsibility, equitability, traceability, reliability, governability. FAR/DFARS clauses are flowing this down to primes and to subs.
Regulations that apply
EU AI Act (Article 2 carve-outs)
LawNational-security exemption is narrow and only for exclusively-defence uses. Any dual-use system stays in scope. Member-state national-security agencies have additional discretion under the EU treaties.
Where in the text: Article 2(3); Annex III §6 (law enforcement).
EU Dual-Use Regulation (2021/821)
LawAI software, model weights, and training data sets are increasingly within the EU's controlled-export categories under category 5.2 (information security) and emerging Category 4 controls.
Where in the text: Regulation (EU) 2021/821, Annex I categories 4 + 5.
US EAR + ITAR (defense-specific AI controls)
LawAI software for defense end-uses is on the US Munitions List (USML) under ITAR. Dual-use AI compute, training data, and weights fall under EAR. End-use checks apply to cloud-AI deliveries.
Where in the text: 15 C.F.R. Part 774 (EAR CCL); 22 C.F.R. § 121 (USML).
DoD Directive 3000.09 + CDAO RAI Strategy
GuidelineAutonomy in weapon systems requires appropriate levels of human judgment. RAI principles must be flowed-down through procurement to all DoD AI capabilities.
Where in the text: DoDD 3000.09 (2023); DoD CDAO RAI Strategy and Implementation Pathway (2022).
Do
- ✓Classify every AI capability against export-control schedules at design time — assume controlled status until proven otherwise. The fines and personal liability for missed classification are severe.
- ✓Document human-judgment architecture for any system that could plausibly be used in a kinetic context, even if you don't believe yours can be.
- ✓Run a separate RAI review track that maps to DoD CDAO principles for US contracts, and to NATO AI Strategy for allied work — the criteria overlap but aren't identical.
- ✓Treat training-data provenance as classified information adjacent — adversary contamination of data has been documented and is the active topic of red-team exercises.
- ✓Establish a software supply-chain attestation process (SBOM, model card, dataset card) that meets both DFARS cybersecurity requirements and the EU Cyber Resilience Act for any dual-use export.
Don't
- ✗Don't deploy or even demo an AI capability to a non-cleared customer without confirming the export classification first — particularly for cloud-hosted APIs.
- ✗Don't rely on the EU AI Act's national-security carve-out for dual-use systems — auditors and member-state authorities read 'exclusively' literally.
- ✗Don't develop autonomous-engagement features for kinetic platforms without a documented human-judgment review chain — this is the active line that current frameworks draw.
- ✗Don't share model weights with allied partners under a research MOU without checking the licence chain against export law.
- ✗Don't bring open-source LLM-derived components into a classified environment without an independent provenance review; supply-chain attestation in classified work has stricter rules than commercial.
Also worth knowing
If you're a US defense prime: the DoD's RAI implementation timeline pushes RAI flow-down into FAR/DFARS solicitations over 2025-2026 — start asking your subs now. If you're an EU defense vendor: the European Defence Fund's RAI principles plus the EU AI Act dual-use treatment require dual compliance. NATO's AI Strategy provides a useful third reference but isn't binding by itself. For dual-use startups: the Outbound Investment regime (US) and the inbound FDI screening (EU) regulations now have explicit AI-focused triggers.
Want a tailored answer?
The wizard takes your jurisdiction, AI use case, and data types and gives you the top-3 regulations to focus on — in 60 seconds.
Start the wizard →Educational guide. Not legal advice. For specific compliance decisions, consult qualified counsel in the relevant jurisdiction.
Note: this guide was drafted with AI assistance — Anthropic Claude.