The Pentagon is cutting red tape — and setting a legal minefield for AI contractors

.

Three weeks from now, the War Department owes Congress a report that could matter far beyond the Pentagon. Section 1512 of the fiscal 2026 defense authorization law requires a comprehensive review of how the department secures artificial intelligence and machine-learning systems, with findings due by Aug. 31. The law asks for current practices, identified gaps, commercial runtime-security options, alignment with industry frameworks, and recommendations for additional authorities or resources.

That deadline arrives at an unusually useful moment. President Donald Trump signed Executive Order 14409 on June 2 to accelerate AI-enabled cyber defense while explicitly rejecting the idea that security requires a new licensing regime for AI development. Then, on July 13, the Pentagon suspended Phase II of the Cybersecurity Maturity Model Certification program, which had been scheduled for Nov. 10, and launched a review aimed at reducing compliance burden while preserving cybersecurity. The administration has therefore set a clear direction: move faster, cut bureaucracy, and keep the security requirement real.

The Aug. 31 report should be judged against that standard. A useful review will identify which AI-security controls actually change operational risk, which can be measured continuously, and which should become enforceable contract terms. The risk is that the review translates the new technology into familiar compliance language and leaves program managers with another checklist that says little about what happens when a model is manipulated at runtime.

Congress already gave the department the structure for the next step. Section 1513 requires a risk-based security framework for AI systems acquired by the Pentagon. It directs the department to cover supply chain risks, data poisoning, adversarial tampering, unintended exposure, continuous monitoring, and incident reporting. It also tells the Pentagon to extend or augment existing cybersecurity frameworks, including CMMC, and to amend the Defense Federal Acquisition Regulation Supplement or take similar action so that covered contractors must implement the resulting practices.

The most important words in that section are easy to miss. The rules are supposed to be narrowly tailored, calibrated to the specific AI technology and the contractor’s role, and designed with the cost of slowing development in mind. That is exactly the balance the Trump administration says it wants. Suspending CMMC Phase II gives the Pentagon an opportunity to avoid recreating a certification bureaucracy around AI while still imposing requirements that can be tested and enforced.

For AI systems, those requirements should focus on evidence. A contractor developing or hosting a model for defense use should be able to show which data and model artifacts are protected, who can change them, how anomalous access is detected, what happens when a system receives manipulated input, whether runtime controls can restrict an unsafe action, and which telemetry survives for investigation. The standard should distinguish a security claim from proof that the control actually worked under test.

This is where contractor exposure becomes concrete. The Justice Department already uses the False Claims Act against government contractors that knowingly misrepresent cybersecurity compliance. In June, defense contractor Logzone agreed to pay more than $500,000 to resolve allegations that it knowingly failed to comply with Navy cybersecurity requirements. Earlier cases have involved multimillion-dollar settlements. Once AI-specific cybersecurity duties become contractual requirements, knowingly false representations about those controls can create the same kind of risk under existing law.

That does not mean every AI failure becomes fraud. The False Claims Act has a knowledge-and-materiality structure, and cybersecurity settlements remain highly fact-specific. The point for contractors is simpler: if the Pentagon turns Section 1513 into contract language, AI-security assertions will no longer live only in slide decks and technical white papers. They may sit behind certifications, invoices, and claims for payment that the government can examine later.

The Pentagon is already building the institutional machinery around this problem. The fiscal 2026 law required the department’s AI sandbox task force to brief congressional defense committees by Aug. 1 on its goals and objectives. Trump’s June national security AI memorandum separately emphasized robustness, controllability, accountability, incident response, and secure access to advanced models. These efforts all converge on the same question: how does the government know that the security properties attached to an AI system survive deployment?

OPINION: A HIDDEN LEGAL GLITCH IS UNDERMINING TRUMP’S AI AGENDA

The Aug. 31 report should answer that question in operational terms. Congress should look for a short list of controls that can be demonstrated, monitored, and audited; a clear plan for converting the highest-value controls into procurement requirements; and a way to scale obligations with the sensitivity of the model and mission. Contractors, meanwhile, should assume that future AI-security claims will need evidence behind them.

The administration is right to resist regulation that slows American AI without buying real security. The same principle should govern defense acquisition. Defense acquisition should avoid another compliance layer that measures how well a company completes paperwork. The Pentagon can use the Aug. 31 report to identify contract terms that make the most important security claims testable and tell Congress how it plans to get there.

Burak Oktenli is an independent researcher based in Washington, D.C., focusing on authority, assurance, and governance in autonomous and AI-enabled systems. He holds a bachelor’s degree in computer science and engineering from the University of South Florida and a master’s, and he is completing a Master of Professional Studies in Applied Intelligence at Georgetown University. His analysis has appeared in RealClearDefense, the Washington Examiner, the Modern War Institute at West Point, the Royal United Services Institute, and Articles of War.

Related Content