Sector

AI consultancy for defence

Defence AI has one hard constraint before any other: the data does not leave the estate, and often the network cannot reach the internet at all. We build air-gapped inference on hardware inside your perimeter, hardened to DISA STIG and CIS Level 2, with the Secure by Design evidence an accreditor will accept.

The constraint

Why defence AI programmes stall

Almost every commercial AI product quietly assumes a route to the internet. It assumes a licence server it can reach, a registry it can pull images from, a telemetry endpoint it can post to, and a vendor who can push a model update. Remove those and a great deal of the market simply stops working.

That is the actual constraint in defence and it is not negotiable. At SECRET and above there is no egress; on a segregated OFFICIAL-SENSITIVE network there may as well not be. A programme that discovers this after selecting a platform has usually lost a year, because the dependency on connectivity is architectural rather than configurable.

Assurance is the second constraint. MOD Secure by Design moved the burden onto the delivery team and its suppliers: you are expected to hold a live security case, evidence controls continuously, and be able to state the current risk position rather than point at a one-off accreditation from three years ago.

The third is the supply chain. Def Stan 05-138 and DEFCON 658 put your supplier’s own controls in scope, and model weights or container images of uncertain provenance are a supply-chain question before they are a technical one.

Where it works

What actually earns its place here

Ordered roughly by how quickly they get approved. The first item on this list is usually the right first project, precisely because it is the least contentious.

01

Doctrine, policy and JSP retrieval

Querying doctrine, JSPs, standing orders and unit-level instruction with citation to the governing paragraph. Non-operational, high volume, and measurable against a held-out set: usually the correct first build.

02

Collected material triage

Summarisation, translation and entity extraction across large volumes of collected and open-source material, prioritising analyst attention rather than substituting for analytical judgement.

03

Engineering and sustainment support

Retrieval across maintenance manuals, fault histories and supply data, so a technician reaches the right procedure and the right part number without three systems and a phone call.

04

Requirement, bid and contract analysis

Extraction and comparison across requirement sets, ITTs and contract schedules. Unglamorous, frequently unclassified, and often the fastest payback in the portfolio.

The gate

What your assurance function will ask for

We build so that this evidence is a by-product of delivery rather than a document assembled under pressure afterwards. It is markedly cheaper that way, and considerably more likely to be accurate.

  • A Secure by Design security case, maintained through delivery rather than written at the end
  • NCSC CAF contributing-outcome commentary covering the AI platform itself
  • DISA STIG and CIS Level 2 scan output, with every deviation justified in writing
  • Model, container and dependency provenance, with hashes recorded at the air-gap boundary
  • A documented offline sustainment path for models, images, signatures, licences and CVE feeds
  • Logging and audit sufficient to reconstruct any individual inference after the fact
  • A cross-domain transfer procedure agreed with the accreditor before build, not after

Questions from this sector

Can you genuinely work fully air-gapped?

Yes, and we treat it as the default rather than an option bolted on afterwards. Every dependency is mirrored inside the boundary: model weights, container images, package repositories, the GPU driver and CUDA stack, the licensing service and the vulnerability feed. The interesting design question is never whether it can run offline, it is what sustainment looks like in year three, and that gets settled before anything is procured.

What clearance do your people hold?

Tell us the clearance level and any facility requirement in the first conversation and we will tell you plainly whether we can meet it as we stand, and where we would need to work alongside a cleared partner or inside your own staff. We would rather lose a piece of work than be vague about this, because being vague about it wastes months of somebody’s programme.

Do you build to STIG or to CIS?

Both, and they are not interchangeable. DISA STIG findings are the baseline for the operating system, container runtime and Kubernetes; CIS Level 2 is the benchmark profile. We reconcile the two into a single hardened image built from code and scanned before handover. Where they conflict, or where a control genuinely breaks GPU scheduling or driver operation, the deviation is recorded with its compensating control rather than quietly dropped.

Are open-weight models acceptable in a defence context?

Provenance is the question, not openness. An open-weight model whose artefacts you have hashed, scanned and hold locally is far easier to reason about than a hosted model that changes without notice. What matters is that you know exactly which artefact is running, that it cannot change underneath you, and that you could rebuild the entire deployment from your own mirror with the wire cut.

Start with a straight answer

A 30-minute call, no pitch deck. Tell us what you are trying to do and we will tell you whether AI is the right tool, what it would take, and what it would cost, or that you should not bother.