The Pentagon Has Two New AI Mandates Due This Fall. Here's the Gap Neither GRC Tool Closes.

Two converging DoD AI mandates this fall — one gap the compliance dashboard can't close.

By Containment.ai Research  ·  Published August 21, 2026  ·  Product status: Trust page →
One control plane, three moments of risk. The same deterministic discipline governs three boundaries: the human prompt (AI Chat Firewall, between an employee and the AI provider), the agent action (Agent Governance, between an agent and a tool or system), and the mission boundary (Mission Authorization Gateway, between an AI system and an edge, domain, or OT environment). All three run intercept, canonicalize, evaluate, enforce, audit.
FIG. A — ONE ENFORCEMENT LAYER, THREE MOMENTS OF RISKCONTAINMENT.AI

Two deadlines are converging on defense-AI operators this fall, and neither one is satisfied by adding another compliance dashboard.

The First Mandate: NDAA §1513 — CMMC for AI

The National Defense Authorization Act for Fiscal Year 2026 contains a provision — Section 1513 — that directs the Department of Defense to develop and implement a framework addressing the cybersecurity and physical security of artificial intelligence and machine learning technologies (AI/ML) acquired by the Pentagon. Section 1513 also directs DoD to incorporate that framework, once developed, into the Defense Federal Acquisition Regulation Supplement (DFARS) and the Cybersecurity Maturity Model Certification (CMMC) program, so that contractors developing, deploying, storing, or hosting AI/ML for DoD comply with it.

If that sounds familiar, it should. CMMC itself began with a provision in the FY2020 NDAA and took years to finalize — and many contractors found themselves unprepared even with that long runway. The lesson defense contractors learned then — don't wait until the framework is published to build the capability it will require — applies directly here.

The framework is meant to address AI/ML-specific security risks. As summarized by counsel tracking the provision, that includes supply-chain vulnerabilities such as data poisoning, adversarial tampering, and unintentional data exposure, and it is to be informed by established standards including the NIST Special Publication 800 series. It applies to "covered" AI/ML — defined broadly to include source code, model weights, and the methods, algorithms, data, and software used to develop the system — and must be built as "an extension or augmentation" of existing DoD cybersecurity frameworks, including CMMC.

Section 1513 does not set an implementation deadline for the framework itself. It instructs DoD to create a plan establishing implementation timelines and milestones and to provide a status update to Congress by June 16, 2026. That status update is the first observable signal of how fast this moves.

The Second Mandate: NSPM-11 — Autonomy in Weapon Systems, Updated

On June 5, 2026, the White House issued National Security Presidential Memorandum 11 (NSPM-11), "Artificial Intelligence in the National Security Enterprise." Within it is a 90-day directive: the Secretary of War must issue an update to DoD Directive 3000.09 on Autonomy in Weapon Systems — in the memorandum's words, "to account for the rapidly evolving capabilities of AI systems," and "to ensure the deliberate adoption of AI systems that respect the chain of command and operational authorities."

Ninety days from June 5 is approximately September 3, 2026. That update is due within weeks.

The memorandum's four policy pillars — adoption, adaptation, assurance, and accountability — return repeatedly to one theme: AI systems adopted for national security must be, in its terms, "reliable, robust, steerable, and controllable," and commanders must "remain responsible and accountable" as those capabilities evolve. The update to Directive 3000.09 is where that principle has to become operational for autonomous and semi-autonomous systems.

The Gap Both Mandates Expose

Here is what neither mandate fully specifies, but what both assume: that an enforcement boundary exists between the AI system and the consequences of its actions.

The NDAA AI/ML security framework is meant to be folded into CMMC assessments. CMMC, as currently structured, measures whether controls exist — it evaluates posture at a point in time. That works well for network segmentation, access control, and data handling. It works less well for AI systems that generate novel outputs at inference time, because the risk isn't the configuration of the model — it's the runtime action the model takes.

Similarly, NSPM-11's chain-of-command language implies that an AI system operating in an autonomous or semi-autonomous role should remain legible to — and interruptible by — human commanders. But legibility and interruptibility are not properties you can audit retrospectively. They have to be enforced at the moment of action, before the action completes.

This is the distinction between monitoring and enforcement. Monitoring tells you what happened. Enforcement determines what is allowed to happen, inline, before it does.

What a Deterministic Enforcement Layer Actually Does

A defense AI system operating under the NDAA §1513 framework and an updated DoD Directive 3000.09 needs a component that does three things:

  1. Evaluates every action against an authorization policy before execution — not after, not in a batch review, but inline at the moment the agent proposes the action.
  2. Generates a cryptographically signed receipt for each decision — permit, deny, or clamp — that is durable, tamper-evident, and auditable by an assessor, a commander, or a CMMC Third-Party Assessment Organization (C3PAO).
  3. Operates deterministically, not probabilistically — the same input against the same policy produces the same decision, every time, in a way that can be explained, tested, and verified.

This is what the Mission Authorization Gateway is built to do. It sits at the enforcement layer — between the AI agent and the environment it acts on — and applies policy before consequences. The signed receipt is the audit artifact a framework built on CMMC will expect assessors to inspect. The deterministic policy evaluation is what gives chain-of-command language operational meaning in an AI-assisted decision cycle.

The Practical Question for Defense Programs Now

The NDAA §1513 framework timeline is not yet set — DoD was instructed to deliver its implementation-plan status update to Congress by June 16, 2026, and the framework itself will take time to finalize. Contractors who waited for CMMC finalization to begin preparation found themselves behind.

The NSPM-11 update to DoD Directive 3000.09, however, is due within weeks. When it publishes, it will shape — for the modern AI-agent era — what "respect the chain of command" means for an autonomous system operating with an AI reasoning layer. Programs that have already instrumented an enforcement boundary will be positioned to demonstrate it. The ones that have only monitoring dashboards will be explaining why retrospective visibility satisfies a forward-looking autonomy requirement.

In most cases, it won't.


Containment.AI builds the Mission Authorization Gateway — a deterministic, signed-receipt enforcement layer for AI systems operating in defense, aerospace, and safety-critical environments. See how the gateway architecture works →.

READY TO CLOSE THE GAP?
Deterministic AI governance for regulated and mission environments.
Request a 30-minute Boundary Review → Apply to the Design Partner Program → Keep controlled data out of public AI →