Defence subcontractors, AI and the two-way assurance problem
Artificial intelligence changes information leakage from the loss of stored data to the continuing release of organisational reasoning.
AI will become an increasingly important part of the Defence supply chain. The organisations that benefit most will be those that can use it. But can they do so without losing control of customer information, engineering knowledge or intellectual property?
Artificial intelligence is becoming useful across the Defence supply chain. It can help subcontractors prepare tenders, analyse faults, improve technical writing and work through engineering problems.
Useful answers require providing a lot of context. Employees may enter requirements, test results, rejected options and specialist corrections. Over time, they may disclose more than a few documents. They may reveal how their organisation thinks, how a customer makes decisions and how a technical problem is solved.
A fundamental problem is how to use it productively while keeping customer information, engineering knowledge and emerging intellectual property securely under control.
The central question is whether members of an organisation are authorised to provide information to an AI service, and are they entitled to use and rely on what the AI service gives them in return?
Paying for AI does not necessarily settle the issue.
A paid AI service may offer better performance and more features. That does not automatically mean the information entered into it is actually protected.
Prompts, uploaded files, corrections, emphasis, formulae, and usage information may still be stored, reviewed by third parties at the provider and used to improve the service. The relevant question is what the provider has agreed to do with the information and whether those protections are supported by the service terms and settings.
Enterprise services often provide stronger safeguards. They may limit reuse, reduce retention, restrict staff access, separate customer information and provide better activity records. These features can be valuable, but they still do not answer a separate question:
Was the organisation permitted to place the information in the service in the first place?
Technical protection and permission are two different things.
Technical safeguards govern what happens after information enters an AI service.
Authorisation determines whether the information may be entered at all.
For a Defence subcontractor, permission may depend on the subcontract, customer instructions, Defence requirements, security classification, data-location rules, approved-system arrangements and customer consent.
A service may be technically secure but still be unauthorised for certain information. An authorised use may still be poorly protected if the wrong account, settings or service level is used.
These issues are connected, but they are not the same.
Two bodies of knowledge may be exposed
A Defence subcontractor commonly holds two overlapping bodies of knowledge.
The first belongs to Defence, a prime contractor another customer or supplier. It may include drawings, specifications, schedules, test data, acceptance criteria, operational constraints and commercial information.
The second belongs to the subcontractor. It may include manufacturing methods, specialist techniques, diagnostic processes, lessons learned, design improvements and trade secrets.
During delivery, these bodies of knowledge are often combined. An engineer may apply proprietary expertise to a customer problem. A commercial manager may combine customer requirements with the subcontractor’s pricing logic.
An AI service can therefore receive customer information and the subcontractor’s own intellectual property in the same exchange.
The organisation may protect the original document while quietly giving away the reasoning that makes it valuable.
The risk is larger than uploading a file
Serious disclosure can occur without anyone uploading a complete design package.
A sequence of prompts may disclose tolerances, materials, failure points, unsuccessful repairs, interface limits, test outcomes and rejected solutions. Individually, each item may appear harmless. Together, they can reveal how a system works, where it is weak and how decisions are made.
This can happen during ordinary work. There may be no malicious employee or obvious data transfer. Information may be released gradually through routine questions and corrections.
Unless AI use is deliberately governed, the organisation may not know what was disclosed or be able to reconstruct it later.
The second half of the problem: what comes back
The risk does not end with protecting what goes into the AI service.
AI may contribute to a design, calculation, report, maintenance method, test procedure or manufacturing solution that is later provided to a prime contractor or Defence.
Before using that output, the subcontractor should establish who owns the inputs and outputs, whether the AI provider keeps any rights, whether the result may draw on other people’s work and IP, and whether the required rights can be passed to the Defence or the prime.
The output must also be checked for accuracy. AI can produce errors, omissions, invented sources or conclusions that sound confident but are wrong. Engineering judgement cannot be transferred to software. Accountable personnel must remain responsible for reviewing, testing and approving material used in a Defence deliverable.
This is the two-way assurance problem.
The organisation must control what it provides to the AI service and establish whether it can lawfully, safely and confidently use what comes back.
AI providers form part of the supply chain
Defence information may move from Defence to a prime contractor, then to subcontractors, consultants, software providers and cloud services.
When an AI provider receives customer information, it becomes another participant in that supply chain.
Its standard terms may not match the subcontractor’s obligations for confidentiality, security, ownership, incident reporting, deletion or overseas processing. The service should therefore be assessed with the same discipline applied to any other external organisation receiving customer information.
Strong controls must be put in place to protect proprietary knowledge, reduce dispute risk, support DISP obligations and strengthen confidence with prime contractors.
Prohibition alone will not work
AI prohibition by itself is unlikely to stop use where employees see clear productivity benefits. Without an approved and practical alternative, activity may move to personal accounts, mobile applications, browser tools or other unmanaged services.
A credible approach combines restriction with enablement. Employees need clear rules, approved services, controlled accounts, practical training, review pathways and a simple way to report mistakes. Higher risk uses should receive additional approval, contract review and technical or engineering verification.
The approved option must also be useful. If it creates too much friction, employees will look for shortcuts.
What good looks like
A mature subcontractor should be able to explain which AI services are approved, what information may be entered, how customer and proprietary information is protected, how supplier terms are reviewed, how AI-assisted outputs are checked and how incidents are handled.
The organisation does not need to claim that AI is risk-free. It needs to show that the risks are understood, controlled and supported by evidence.
If it cannot confidently answer where its information is being shared, which AI services are being used or whether those services are authorised for Defence information, it has identified an assurance gap.
Put AI to work—securely
AI will become an increasingly important part of the Defence supply chain. The organisations that benefit most will be those that can use it without losing control of customer information, engineering knowledge or intellectual property.
SecureSupply can help Defence suppliers assess current AI use, review contractual and information-security obligations, identify governance gaps and put practical, Defence Industry Security Program-aligned controls in place.
The final question is not whether AI is useful. It is whether the organisation can prove that its use is authorised, controlled and defensible and whether organisational knowledge is not being quietly converted into some AI service’s commercial asset?
Discuss your DISP, IRAP or security obligations.
We move from first conversation to active engagement in two to three weeks.