How gap in European Union's AI Act could complicate matters on battlefield
The European Union’s AI Act has established the world’s first comprehensive legal framework for governing artificial intelligence, placing a strong emphasis on compliance, risk management, fundamental rights, health and safety. Yet systems used exclusively for military, defence or national security purposes fall outside its scope, leaving Europe without a common EU framework for regulating AI deployed on the battlefield.
The exclusion is deliberate and rooted in the division of powers between the European Union and its member states. However, an analysis by the Geopolitical Monitor publication argues that describing it simply as a loophole in the EU’s flagship AI legislation risks pointing policymakers toward the wrong solution.
Rather than extending a civilian market regulation wholesale into the military sphere, the outlet suggests that the more immediate challenge is determining what evidence should be required before an AI-enabled military system moves from development and procurement into national service and, ultimately, multinational operations.
NATO allies have already established responsible-use commitments covering lawfulness, responsibility and accountability, explainability and traceability, reliability, governability and bias mitigation. NATO’s revised AI strategy also calls for common standards, assessment templates, review procedures, an Alliance-wide testing and validation environment and greater interoperability between allied AI systems.
These measures provide an important foundation, but they do not amount to a single fielding-assurance framework that national authorities can use to test and recognise AI systems when they cross allied borders.
According to the journal's analysis, the EU’s defence funding mechanisms highlight the problem. The European Defence Fund excludes funding for lethal autonomous weapons that operate without meaningful human control over decisions to select and engage human targets. The European Defence Industry Reinforcement through common Procurement Act, or EDIRPA, applied a similar restriction to EU-supported joint procurement, but expired at the end of 2025.
The EU’s newer Security Action for Europe, or SAFE, financing instrument explicitly supports joint procurement in artificial intelligence and other advanced technologies. However, its legal framework does not repeat EDIRPA’s explicit exclusion concerning meaningful human control. Belgium formally expressed regret over that omission when the Council adopted SAFE.
The Geopolitical Monitor explains that, hence, the result is not an absence of legal or ethical safeguards. International humanitarian law, national weapons reviews, NATO principles and individual programme requirements continue to apply.
The deeper problem is what the outlet describes as “a lifecycle break.” A human-control requirement may determine whether a system qualifies for a particular grant or temporary procurement programme without becoming a common, testable condition for the same system once it is deployed, upgraded, connected to other national systems or operated under multinational command.
This creates difficulties when AI systems developed and certified under different national rules begin interacting within a shared military architecture. Allied countries may disagree over which decisions require direct human authorisation, what level of confidence is sufficient for an automated recommendation, how quickly an operator must be able to intervene or what information an audit trail must retain. As a result, technical interoperability between allied systems could develop faster than mutual confidence in the rules governing the authority embedded within those systems.
Solutions moving forward
The Geopolitical Monitor argues that a European military AI fielding-assurance framework should be narrow enough to respect national sovereignty while being sufficiently concrete to allow systems to be tested before deployment.
It identifies four key requirements.
First, an authorisation boundary should specify which consequential actions require human approval and identify the official or role authorised to provide it.
Second, runtime governability should ensure that a system can be constrained, suspended or returned to a safe mode if data quality, communications, mission conditions or operator confidence deteriorate.
Third, tamper-evident traceability should record what the system recommended or initiated, which data and rules informed the action, who authorised it and whether a human override occurred.
Fourth, a pre-agreed conflict rule should apply during multinational operations. Where national restrictions or operating conditions conflict, the system should require renewed human authorisation rather than automatically following whichever system acts first.
According to the analysis by the publication, such a framework would not require the EU to take over national decisions on military AI. Instead, it could provide a common assurance layer that allows European and NATO forces to operate AI-enabled systems together while preserving national authority over their use.
The challenge for Europe, therefore, may be less about bringing military AI under the EU AI Act and more about ensuring that systems operating beyond its scope remain subject to clear, testable and mutually recognised safeguards before they are deployed alongside allied forces.
By Nazrin Sadigova







