The deliberate carve-out
Article 2(3) of the EU AI Act explicitly exempts AI systems developed or used for military, defence, and national security purposes. This isn't an oversight — it reflects the division of powers between the European Union and its member states. Defence remains firmly in national hands, and the EU's legislative competence doesn't extend to regulating how member states equip their armed forces.
But as an analysis by Geopolitical Monitor — covered this week by Caliber.Az — makes clear, calling this a simple "loophole" misses the point. The real question isn't whether civilian AI rules should be stretched over military systems. It's this: when an AI-enabled system developed under one country's rules is connected to another's command architecture, how do you know it will behave the way everyone expects?
The funding trail tells the story
You can trace the confusion through the EU's own defence funding instruments. Each one treats AI safeguards differently — and the pattern isn't encouraging.
| Instrument | Status | Lethal autonomous weapons restriction |
|---|---|---|
| European Defence Fund (EDF) | Active | Excludes funding for systems operating "without meaningful human control" over target selection and engagement |
| EDIRPA (European Defence Industry Reinforcement through common Procurement Act) | Expired end of 2025 | Applied similar restriction to EU-supported joint procurement |
| SAFE (Security Action for Europe) | Active | No explicit exclusion — Belgium formally expressed regret over this omission when the Council adopted SAFE |
The trajectory is telling. EDF said no to killer robots without human oversight. EDIRPA said the same — then expired. SAFE, the newer and larger instrument, dropped the language entirely. Belgium noticed. Not everyone else did.
The "lifecycle break"
Geopolitical Monitor names the core issue a "lifecycle break". A human-control requirement might determine whether a project qualifies for R&D funding or a procurement grant. But once the system is built, certified under one nation's rules, and plugged into a multinational operation — those initial conditions can evaporate.
The practical consequences are easy to picture. Two allied countries have AI systems that need to share sensor data and threat assessments. Country A's system requires explicit human authorisation for any engagement recommendation above 85 % confidence. Country B's threshold is set at 70 %. When they operate together, whose rule applies? What if the systems disagree about what human oversight actually means?
This isn't theoretical. European militaries are investing heavily in AI-assisted C4ISR — command, control, communications, computers, intelligence, surveillance, and reconnaissance. The French Ministry of Defence runs an AI roadmap. Germany's Bundeswehr has its own AI strategy. The UK (though outside the EU, still a key NATO ally) established its Defence AI Centre. None of them share a common testing standard for fielding AI-enabled combat systems.
NATO has principles — but not a test suite
NATO allies adopted responsible-use principles for AI back in 2021 and revised its AI strategy in July 2024. The commitments cover lawfulness, responsibility and accountability, explainability and traceability, reliability, governability, and bias mitigation. The revised strategy calls for common standards, assessment templates, and an Alliance-wide testing and validation environment.
Those are the right words. But principles aren't a certification framework. They don't tell a national procurement office what evidence to demand before integrating an AI system into a multinational operation. They don't specify what happens when one ally's AI flags a target that another ally's system would have ignored.
This is the difference between having a rulebook and having a referee. NATO's principles are a rulebook — a good one. What's missing is the referee who can verify that national systems actually follow the same rules before they're plugged into allied networks.
Four pieces of a solution
The Geopolitical Monitor analysis proposes a European military AI fielding-assurance framework — narrow enough to respect national sovereignty, concrete enough to be testable. It identifies four requirements:
1. Authorisation boundary. Specify which consequential actions require human approval and identify the official or role authorised to provide it. No ambiguity about what "meaningful human control" means for a given system.
2. Runtime governability. The AI system must be constrainable, suspendable, or returnable to a safe mode if data quality degrades, communications fail, mission conditions shift, or operator confidence drops. An off-switch that multiple parties agree exists and knows how to use.
3. Tamper-evident traceability. Record what the system recommended or initiated, which data and rules informed the action, who authorised it, and whether a human override occurred. An audit trail that works across national boundaries.
4. Pre-agreed conflict rule. When national restrictions or operating conditions conflict during multinational operations, the system must demand renewed human authorisation rather than defaulting to whichever system acts first. No automatic escalation by ambiguity.
This framework wouldn't require the EU to dictate national defence decisions. It would instead provide a common assurance layer — a way for European and NATO forces to verify that AI-enabled systems meet mutually understood safety thresholds before deployment alongside allied units.
What this means for Europe
For European defence companies — from large primes like Airbus Defence & Space and Thales to the growing ecosystem of defence AI startups — the absence of a common fielding standard creates fragmented regulatory requirements. A system certified for use by the French armed forces may need entirely separate validation for integration with German or Polish forces. That costs time and money, and in a security environment where the threat picture can change in hours, delay is a vulnerability.
For EU policymakers, the SAFE omission is a clear signal. When the EU's newest and largest defence procurement instrument drops language about meaningful human control that its predecessor contained, the question isn't whether anyone noticed — Belgium did. The question is whether the omission was intentional, and if not, whether there's political will to fix it.
For the broader AI governance conversation, this gap highlights a structural tension. The EU has positioned itself as the world's regulatory leader on AI — but the one domain where AI carries the highest stakes remains outside its framework. That's constitutionally correct under current treaties. It doesn't make the operational problem go away.
One practical path forward might be an EU-NATO joint working group specifically tasked with developing a military AI certification standard — not a new treaty, but a technical interoperability agreement with verification mechanisms. The technical expertise exists. The political will is the open question.
Why doesn't the EU AI Act cover military AI?
Defence policy is a national competence under EU treaties. The EU can coordinate and fund joint defence projects through instruments like EDF and SAFE, but it cannot legislate how member states equip their armed forces. Article 2(3) of the AI Act reflects this constitutional boundary — it's not a loophole but a deliberate carve-out based on the division of powers.
What's the difference between EDF, EDIRPA, and SAFE?
The European Defence Fund (EDF) is a long-term EU budget instrument funding collaborative defence R&D and capability development. EDIRPA was a short-term emergency instrument created after Russia's 2022 invasion of Ukraine to boost joint procurement — it expired at the end of 2025. SAFE (Security Action for Europe) is its successor, a larger financing mechanism that explicitly supports AI and advanced technology procurement but dropped EDIRPA's language excluding lethal autonomous weapons without meaningful human control.
Does NATO have rules for military AI?
NATO adopted responsible-use principles for AI in 2021 covering lawfulness, accountability, explainability, reliability, governability, and bias mitigation. Its revised 2024 AI strategy calls for common standards and an Alliance-wide testing environment. However, these are principles and strategic goals — not a concrete certification framework that national authorities can use to test AI systems before integrating them into multinational operations.