Binders won’t stop bullets: When military AI can’t say ‘no’

.

Congress does this often: it passes a law directing an agency to solve a hard problem, and then the real work, the part that determines whether the law means anything, happens quietly inside the executive branch months later.

A provision of last year’s defense authorization act is a clear case. Section 1513 of the Fiscal Year 2026 National Defense Authorization Act directs the Department of War to build a framework governing the cybersecurity of the artificial intelligence systems it buys, folding it into existing acquisition rules and the Cybersecurity Maturity Model Certification program. A first status report to Congress was due in mid-June. The deadline has now passed, and the question that matters is no longer whether the Department will report, but what the framework underneath the report actually does.

The statute names the risks it wants addressed: adversarial tampering, supply chain compromise, data theft, and AI-specific vulnerabilities. That list is really a catalog of the ways an adversary can corrupt a system without ever breaching a firewall. A rival does not need to steal the software when it can poison a sensor feed, spoof an identification signal, or nudge a model toward a decision its operators never intended. Congress was right to treat these as security problems rather than performance quirks. The difficulty is that the tools the law points to were built for a different kind of technology.

The framework is meant to rest on established government standards for cybersecurity and AI trustworthiness. Those standards are necessary, and none of them was written for a system that acts on its own. A risk-management framework tells you which properties a system should have. It does not place a gate in the decision loop that can refuse an unsafe action at the instant the action would occur. The accreditation model that governs federal technology checks a system before it is fielded and revisits it periodically. An autonomous system makes consequential choices continuously, in conditions no pre-deployment review fully anticipated. Between the paperwork that certifies a system and the behavior it exhibits under fire lies a gap the statute gestures at, but existing practice does not close.

This administration’s instinct on artificial intelligence has been to strip away processes that slow the technology down; President Donald Trump rescinded the previous administration’s sprawling AI executive order in his first week in favor of speed and American dominance in the field. That instinct is right, and it raises the stakes for getting the remaining governance correct what oversight stays must be built into the machine itself, running at machine speed, rather than stacked in binders that slow procurement without restraining behavior.

In practice, that means three things, each aimed at a risk the law names. Inputs should be verified before a model is allowed to act on them, so that a spoofed sensor reading or a manipulated image is rejected at the boundary rather than propagated into a decision. Time-critical actions should carry a built-in pause for human judgment, so that a system that cannot resolve a high-stakes choice safely within its window escalates or aborts rather than proceeding; this is the operational form of the Pentagon’s own standing requirement that humans retain appropriate judgment over the use of force. And every consequential decision should be written to a tamper-evident record, so that oversight bodies, including Congress, can reconstruct after the fact what a system was permitted to do and why.

None of this is a brake on the technology; it is what lets the government adopt autonomy without importing risks it cannot see. The alternative, certifying these systems the way earlier software was certified and trusting that a clean evaluation predicts battlefield behavior, is precisely the assumption the statute’s risk list warns against. An accreditation produced in benign conditions is a claim about the test environment, not about the contested one where the system will operate.

CHINA’S ‘OPEN SOURCE’ AI ISN’T A GIFT — IT’S A TROJAN HORSE

There is a strategic dimension too, and it cuts in the administration’s favor. Competition with China is increasingly a contest over whose autonomous systems can be trusted to operate at speed without losing the thread of human intent. A power that fields ungoverned autonomy may look faster until the first time one of its systems acts on a corrupted input and cannot be stopped. Building the enforcement in, rather than asserting it in a policy document, is what converts a compliance mandate into an actual battlefield advantage.

The June report is a milestone, not a finish line, and Congress retains the harder job: asking not whether the Department produced a framework, but whether that framework can refuse an unsafe action in the moment, and whether it leaves a record that oversight can read. A law is only as good as its implementation. If the Pentagon builds the enforcement into the machine, this administration will have done something its predecessors only wrote about and made an AI law mean exactly what it says.

Burak Oktenli is an independent researcher on the governance of authority in autonomous and AI-enabled systems. He holds an MBA and a Master of Professional Studies in Applied Intelligence from Georgetown University, and his writing has appeared at the Washington Examiner, the Modern War Institute at West Point, RUSI, and RealClearDefense.

Related Content