GuideDefense

What AI can do in a defense factory without a byte leaving

Defense SMEs don’t use AI because nobody wrote the rules. The rules take one afternoon to write, starting from information classification, and they become software when know-how and rules live in one place. The four-step method, with a filled-in example, and the four questions your NIS2 questionnaire will ask your software supplier.

Raffaele ZarrelliAI Architect & Founder, Yempik·September 15, 2026·7 min read
In summary
  • In more than one supply-chain company we have met, until a few months ago AI use was left to individual responsibility: no written rules, tools chosen by whoever used them.
  • The regulatory frame is tighter than it looks: NIS2 with the May 31 and October 31, 2026 deadlines, the AI Act that excludes military uses but not the same company’s management uses, export control that also covers technical data, AQAP standards that demand traceability.
  • The method is four steps: four information classes with the allowed tools for each, a management charter written by managers, one company-owned place for know-how and rules, a first document process.
  • Your company’s NIS2 questionnaire will ask the software supplier for clauses, evidence, second-tier dependencies, and replaceability. It pays to pick the one who arrives with the answers ready.
The starting point

Until a few months ago it was the Wild West

In more than one supply-chain company we have met, until a few months ago the use of artificial intelligence was left to individual responsibility. A technical office uploaded a specification into a free tool to get the clauses summarized. A quality manager asked an assistant to rewrite a non-conformity. Nobody had decided what could and could not be done, so everyone decided alone, with whatever account they had. The same companies had impeccable procedures on materials and on paper: the hole was only in software.

The reason defense SMEs don’t use AI, or use it in hiding, has little to do with technology. Nobody wrote the rules. And as long as the rules are missing, the only prudent answer a manager can give is “no,” which in practice means “yes, but without my knowing.” In the German sample of BearingPoint’s aerospace and defense survey, with Italy in the same study, only 7% of executives list artificial intelligence among their priorities and 44% name silos as the main barrier. The reason, more than lack of interest, is the lack of a perimeter to use it in. Annalisa Alberti of Rheinmetall Italia said it at the Manufacturing Forum: whoever doesn’t think about the smart factory “risks taking a step backwards.” The perimeter is the first step, and it takes one afternoon to draw.

Without written rules, a manager’s “no” to AI means “yes, but without my knowing.”

The regulatory frame

Ten lines of rules that apply to you too

Four texts are enough to understand the perimeter. The NIS2 directive, transposed in Italy by Legislative Decree 138/2024, requires essential and important entities to govern supply-chain security: the list of relevant ICT suppliers was due by May 31, 2026, security measures must be in place by October 31, 2026, and the FAQ of the national cybersecurity agency says plainly that “contract clauses alone are not enough.” The supply-chain requirements fall on suppliers: whoever sells software to a defense company ends up on that list.

The AI Act excludes from its scope systems used exclusively for military, defense, or national security purposes. The same company, though, also uses AI to read contracts, manage staff, and select suppliers: those uses stay inside the regulation, with the literacy and transparency obligations that come with it. Export control on dual-use items, Regulation 2021/821, also covers technology and technical data: a model that receives a drawing and returns a specification is handling controlled material. And the AQAP standards that NATO customers require from suppliers demand traceability of what was done, by whom, and on what basis.

A note on company tools. The “enterprise” data protection of products such as Copilot, described in Microsoft’s documentation, applies to ordinary company data and to the EU data boundary; it does not make a tool fit for classified information, and the documentation itself does not claim so. The Ministry’s 2026 AI and Defense Strategy points the same way: open architectures against lock-in, an initial year devoted to data consolidation, an explicit role for mid-sized defense technology companies.

The method

Four steps, one afternoon for the first

The first step is to classify information into four classes: public, internal, restricted, classified. The first two cover most of the daily work; the other two already have procedures and locked cabinets. Each class is matched with a class of tools: for public and internal, company tools with data protection and EU data residency; for restricted, only tools running inside the company perimeter; for classified, no AI tool until a specific authorization exists. The grid fits on one page and is filled in with management, in one afternoon.

The four classes and the allowed tools
ClassWhat it containsAllowed toolsExample use
PublicWebsite, catalogs, press releases, training offers.Company tools with data protection and EU data residency, company account.Rewriting a product sheet for the website.
InternalProcedures, ordinary email, unsigned offers, meeting minutes.As above, with the operations log on and no training on the data.Summarizing a public specification and checking it against procedures.
RestrictedDrawings, bills of materials, non-conformities, contracts, supplier and customer data.Only tools running inside the company perimeter: self-hosted or dedicated cloud, log mandatory.Classifying a non-conformity and drafting the customer reply.
ClassifiedInformation with a security classification and export-controlled material.No AI tool without a specific written authorization.None.

When in doubt. Information whose class is unknown is treated as restricted, and the owner is asked before it is used.

The grid is filled in with management in one afternoon. The first two classes cover most of the daily work; the other two already have procedures and locked cabinets, and AI follows the same rules.

The second step is the management charter: rules written by those who manage, not by IT. Ten signed lines that say what is allowed for each class, who approves a new tool, where the operations log ends up, how often it is reviewed. It is the document the NIS2 questionnaire and an AQAP audit will ask you to produce, and the first one an external consultant would ask you to write. The 30-day plan in AI governance for SMEs is the general version of this charter; here the difference is that classes matter more than departments.

The third step is the one place where know-how and rules live, owned by the company: procedures, decision rules with their source, recurring specifications, closed non-conformities and why. From there any model works, with an operations log, and swapping the model tomorrow costs nothing because the context stays yours. It is the company brain applied to a factory: the question “whose is it” has a forced answer when the data is restricted. The method to build it on files is the same as for any company; only where the files live changes.

The fourth step is the first process: a document one, not production. Specifications to read and compare with the company’s capabilities, non-conformities to classify and close with a customer reply, batch traceability to rebuild. These are processes with high volumes, internal or restricted data, and a result you can verify in weeks. Production, the bill of materials, and planning come later, once the operations log has shown that the perimeter holds.

The filled-in example

What a management charter looks like, on one page

Vertesa is a fictional company: precision mechanics, 120 people, components for aiming systems sold to two European primes. We use it as an example because no real client data can appear in this piece. Its management charter, filled in with the method above, is this.

Filled-in example · fictional company

Management charter on the use of artificial intelligence

Vertesa · precision mechanics · 120 people

  1. 1

    Every piece of company information belongs to one of the four classes in the grid: public, internal, restricted, classified. The class decides the tool, not the department.

  2. 2

    For the public and internal classes only approved company tools are used, with a company account, data kept in the EU, and the operations log on.

  3. 3

    For the restricted class only tools running inside the company perimeter are used. No drawing, bill of materials, or non-conformity enters an external tool.

  4. 4

    For the classified class no artificial intelligence tool is allowed without written authorization from management and the security officer.

  5. 5

    A new tool enters use only after management approval, with the maximum allowed class written next to its name.

  6. 6

    The company’s know-how and rules live in one place, owned by the company. Tools work from there and leave a trace of what they read and produced.

  7. 7

    Every AI output based on restricted material is reviewed by a named person before it leaves the company.

  8. 8

    When the class is in doubt, the information is treated as restricted and someone asks. This charter is reviewed every three months.

Approved by management · quarterly reviewOwner: first and last name
Vertesa is a fictional company used as an example: no real client data appears on this page. The rules are written without product names, because they have to survive a change of tool.

Three things to notice. The rules are written in plain language, without product names, because they have to survive a change of tool. Every rule has an owner with a first and last name, omitted in the example. And there is a line for doubt: when you don’t know which class a piece of information belongs to, you treat it as restricted and ask. It is the line that closes the Wild West.

The questionnaire

What your NIS2 questionnaire will ask a software supplier

If your company is a NIS2 entity, or your prime is, the supplier questionnaire will come, and for AI software it will ask four questions. Which contract clauses cover security, incidents, and termination. Which evidence shows the measures actually exist: certifications, logs, tests. Which second-tier dependencies sit behind it, that is where the models run and who provides the infrastructure. And how replaceable the supplier is: what stays with the company if the contract ends.

The four questions for the software supplier
01Clauses

What it really asks
Which contract clauses cover security, incident handling, subcontracting, and termination of the service.

Ready answer
A contract with security obligations, incident notification deadlines, no training on the data, and an exit clause with data return.

02Evidence

What it really asks
Which proof shows the measures actually exist, beyond the clauses: certifications, logs, tests.

Ready answer
An operations log the customer can consult, security test results, a documented access management procedure.

03Second-tier dependencies

What it really asks
Where the models run, who provides the infrastructure, in which jurisdiction the data sits, and who else touches it.

Ready answer
A list of subcontractors with role and country; models run inside the company perimeter or on a dedicated EU cloud.

04Replaceability

What it really asks
What stays with the company if the contract ends: data, rules, configurations, accumulated know-how.

Ready answer
Context and rules in company-owned files, open formats, a model swap that loses nothing.

The Italian cybersecurity agency’s FAQ says contract clauses alone are not enough: that is why the second question weighs as much as the first.

The four questions are also a selection criterion. A supplier who arrives with the answers ready, data inside the perimeter, an operations log, and context owned by the customer, saves you the time of the questionnaire and, above all, does not leave you with a brain rented inside a product you don’t control. That is why the first piece of this series argued that the software defense needs must be sovereign; the third, on the invisible supply chain, takes the same principle out of the factory, to the suppliers.

Frequently asked questions

AI and restricted information, in practice

Does the AI Act apply to a defense company?

The regulation excludes systems used exclusively for military, defense, or national security purposes. The same company’s management uses, contracts, staff, suppliers, administration, stay inside the regulation, with literacy and transparency obligations. That is why the management charter distinguishes information classes, not departments.

What does NIS2 require from a defense SME and its suppliers?

The directive, transposed by Legislative Decree 138/2024, requires essential and important entities to govern supply-chain security: a list of relevant ICT suppliers by May 31, 2026 and security measures by October 31, 2026. The national cybersecurity agency’s FAQ specifies that contract clauses alone are not enough: evidence is needed. An AI software supplier ends up on the list and receives the questionnaire.

How do you classify information to use AI in a company?

Into four classes: public, internal, restricted, classified. Each class is matched with a class of allowed tools: company tools with data protection and EU data residency for the first two, only tools inside the company perimeter for restricted, no tool without specific authorization for classified. When in doubt, the information is treated as restricted. The grid fits on one page and is filled in with management in one afternoon.

Is an “enterprise” AI tool suitable for restricted data?

It depends on the class. The enterprise data protection of cloud products applies to ordinary company data and to the EU data boundary; it does not make the tool fit for classified information, and vendor documentation does not claim so. The restricted class needs tools running inside the company perimeter; the classified class allows no tool without specific authorization.

What is the management charter on AI use?

A one-page document, written and signed by managers rather than IT, that says what is allowed for each information class, who approves a new tool, where the operations log ends up, who reviews the outputs, and how often it is updated. It is the document the NIS2 questionnaire and an AQAP audit ask you to produce.

Which process should a defense factory start from?

A document process, not production: specifications to read and compare with the company’s capabilities, non-conformities to classify and close, batch traceability to rebuild. High volumes, internal or restricted data, a result verifiable in weeks. Production, the bill of materials, and planning come later, once the operations log has shown that the perimeter holds.

Transparency

Sources

  1. [1]Agenda Digitale, “NIS2 e fornitori: cosa prevedono le FAQ ACN sui contratti”. www.agendadigitale.eu
  2. [2]Cybersecurity360, “Direttiva NIS2 e supply chain: i nuovi requisiti per la catena di fornitura”. www.cybersecurity360.it
  3. [3]EUR-Lex, Regulation (EU) 2024/1689 on artificial intelligence (AI Act). eur-lex.europa.eu
  4. [4]EUR-Lex, Regulation (EU) 2021/821 on the control of exports of dual-use items. eur-lex.europa.eu
  5. [5]Microsoft Learn, “Enterprise data protection in Microsoft 365 Copilot”. learn.microsoft.com
  6. [6]Agenda Digitale, “Strategia IA e Difesa 2026: cosa cambia per imprese, filiere e sovranità tecnologica”. www.agendadigitale.eu
  7. [7]BearingPoint, “European defense sector faces a major digital execution gap”. www.bearingpoint.com
  8. [8]Startupbusiness, Manufacturing Forum 2026, Annalisa Alberti (Rheinmetall Italia). www.startupbusiness.it
Transparency note

This page is written by Raffaele Zarrelli, founder of Yempik, with editing done with Claude. It is the second piece in the series on AI for the defense factory and supply chain. Vertesa is a fictional company: the management charter is a filled-in example, not a client document, and the episodes in the first paragraph are told without names. Regulatory sources are linked in the text; the piece describes a working method and is not legal advice.

Download the classification grid, on one page.

The four classes, the allowed tools for each, and the line for doubt. Fill it in with management in one afternoon. If you then want to compare it with us, write to us: we sell nothing on the first call.