A targeting-support algorithm, a logistics-optimization model, and a predictive-maintenance system for a fleet of aircraft all count as "AI" under most regulatory definitions. Only one of them looks like a battlefield decision. But all three carry the same underlying governance question: how do you prove, to an auditor, a program office, or your own leadership, that the system behaves the way you designed it to behave, and that someone is accountable when it doesn't?
That question is what ISO/IEC 42001:2023 was built to answer. Like every ISO management system standard, its designation carries its own edition year in the name, the same convention used for ISO/IEC 27001:2022 and ISO 9001:2015, so the "2023" is not a marketing claim but part of the standard's formal reference number, checkable directly against ISO's own catalogue listing for ISO/IEC 42001. The standard defines requirements for an AI management system, or AIMS, that an accredited certification body can audit against and formally certify, not a policy document an organization simply writes for itself. What makes it unusually relevant to defense and national security work is not that it was written with military applications in mind. It wasn't. It's that the AI regulation most contractors watch closely, the EU AI Act, explicitly declines to cover this space, leaving a governance vacuum that ISO 42001 is well positioned to fill.
Why Defense AI Sits Outside the Usual Regulatory Frame
Article 2(3) of the EU AI Act, Regulation (EU) 2024/1689, excludes AI systems developed or used exclusively for military, defense, or national security purposes from the Act's scope entirely, regardless of which entity operates them. This isn't a narrow carve-out for a handful of weapons systems. It's a categorical exclusion for the entire domain. If you're a contractor building AI for the Department of Defense, an intelligence agency, or an allied ministry of defense, the regulation driving AI compliance conversations everywhere else in the economy simply doesn't apply to your work.
That sounds like less work. In practice, it's more exposure, not less. Defense primes and subcontractors still answer to program offices that want documented risk management, to oversight bodies like the DoD Inspector General and the Government Accountability Office, and to a contracting environment where CMMC 2.0 already requires third-party verification of security controls. The absence of an AI-specific regulatory floor means each program office, each prime, and each service branch has been left to define its own expectations. ISO 42001 gives contractors a common, internationally recognized structure to point to instead of building a bespoke governance framework from scratch for every contract.
I've seen this pattern before in other regulated spaces I work in, pharmaceutical manufacturing and food safety among them: when a hard regulatory backstop is missing, buyers default to whatever credible, independently verifiable framework exists. Right now, for AI, that's ISO 42001.
What the Department of Defense Already Expects
The DoD didn't wait for ISO to publish a standard. On February 24, 2020, it adopted five AI Ethical Principles:
- Responsible
- Equitable
- Traceable
- Reliable
- Governable
Three of those principles map closely onto ISO 42001's structure:
| DoD Principle | ISO 42001 Structure |
|---|---|
| Traceable | Documentation and record-keeping under clause 7.5 |
| Governable | Management review and continual improvement in clauses 9 and 10 |
| Reliable | Operational controls in clause 8 and Annex A controls on system verification and validation |
DoD Directive 3000.09, "Autonomy in Weapon Systems," updated January 25, 2023, requires that autonomous and semi-autonomous weapon systems be designed to allow commanders and operators to exercise appropriate levels of human judgment over the use of force. That's a directive requirement, not a suggestion buried in a policy memo, and it's precisely the kind of control that ISO 42001's Annex A.9 (system impact on individuals and society) and the clause 6.1.4 AI system impact assessment are designed to force an organization to document before deployment rather than after an incident.
The Chief Digital and AI Office, established in 2022 to consolidate the DoD's AI, data, and digital modernization efforts, has been pushing responsible-AI requirements down through acquisition guidance since. Contractors who can point to an ISO 42001 certificate arrive at that conversation with a documented management system already in place, rather than trying to reverse-engineer one against a specific solicitation's requirements six weeks before a proposal is due.
Where ISO 42001 Maps Onto Defense Program Requirements
ISO 42001 organizes its requirements the way every ISO management system standard does: context of the organization (clause 4), leadership (clause 5), planning (clause 6), support (clause 7), operation (clause 8), performance evaluation (clause 9), and improvement (clause 10), backed by controls organized into themes in Annex A. For defense applications, a handful of clauses do most of the work.
Risk and impact assessment. Clause 6.1.2 requires an AI risk assessment process, and clause 6.1.4 requires an AI system impact assessment that considers effects on individuals and groups potentially affected by the system. For a defense AI application, "affected parties" isn't an abstract compliance category. It's warfighters relying on a decision-support tool, civilians in an operational environment, and allied partners operating alongside U.S. systems. Documenting that assessment with the rigor clause 6.1.4 demands gives a program office something concrete to review, rather than a contractor's verbal assurance that the system was "tested."
Data governance. Annex A.6, data for AI systems, is where I'd tell a defense contractor to spend the most implementation time. Military and intelligence AI systems are built and trained on data with classification markings, provenance chains, and access restrictions that most commercial AI teams never have to think about. The Annex A.6 requirements around data provenance and quality dovetail directly with existing classification-handling procedures, but very few contractors have actually connected the two documentation trails. When they're separate, an auditor, or an inspector general, has to take it on faith that the classified-data handling process and the AI governance process are actually talking to each other.
Supplier oversight. Annex A.7 covers third-party and supplier relationships, which matters enormously in a defense supply chain built on primes, subcontractors, and component suppliers who may each touch a different stage of an AI system's lifecycle. CMMC 2.0's program rule, codified at 32 CFR Part 170 and effective December 16, 2024, already requires many contractors handling controlled unclassified information to undergo third-party assessment against the 110 controls in NIST SP 800-171 at Level 2. ISO 42001's Annex A.7 doesn't replace that requirement, but it gives contractors a natural place to fold AI-specific supplier due diligence into a security posture they're already building for CMMC.
ISO 42001 Compared to the Other Frameworks Already in Play
Defense contractors are rarely choosing ISO 42001 in isolation. They're deciding how it fits alongside frameworks they already have to satisfy.
| Framework | What it governs | Defense relevance | Certifiable? |
|---|---|---|---|
| ISO/IEC 42001:2023 | AI management system: risk, lifecycle, accountability | Fills the gap left by the EU AI Act's military exclusion; maps to DoD's five AI principles | Yes, third-party certification |
| NIST AI RMF 1.0 (Jan. 2023) | AI risk management via four functions: Govern, Map, Measure, Manage | Widely referenced in federal AI guidance; voluntary framework, not an audit standard | No, self-assessment |
| DoD Directive 3000.09 (updated Jan. 2023) | Human judgment over autonomous weapon system use of force | Mandatory for covered autonomous/semi-autonomous weapon systems | No, policy directive |
| CMMC 2.0 (32 CFR Part 170, eff. Dec. 16, 2024) | Cybersecurity controls for handling CUI | Mandatory for contractors handling covered defense information | Yes, third-party assessment at Level 2/3 |
| EU AI Act (Reg. 2024/1689) | Risk-based AI regulation across the EU market | Excludes military/defense/national-security AI (Art. 2(3)) | N/A for this domain |
The honest answer to "which one do we need" is usually more than one. NIST AI RMF gives you a risk taxonomy and a shared vocabulary; ISO 42001 gives you the auditable management system that turns that vocabulary into evidence a certification body will actually sign off on. Those overlaps and gaps are worth mapping against your specific contract requirements before deciding how many of these frameworks to carry at once. Our ISO 42001 vs. NIST AI RMF vs. EU AI Act comparison works through that decision in more detail.
The Classification Problem Nobody Talks About
Here's the part of this that most AI governance content skips entirely, because it doesn't come up outside defense and intelligence work: how do you run an internal audit, a required element of ISO 42001 clause 9.2, against a system whose training data, model weights, or operational logs are themselves classified?
The standard doesn't dictate a specific mechanism for this, which is the right design choice. ISO 42001 requires that internal audits be conducted by people who are objective and impartial to the area being audited, and that audit findings be reported to relevant management under clause 9.2.2. It does not require that every auditor hold the same clearance as the system's operators, and it does not require unredacted evidence to leave a secure facility.
In practice, this means structuring the AIMS documentation in two layers:
- An unclassified management-system layer that a certification body's auditor can review directly: policies, procedures, risk methodology, and governance records.
- A classified evidence layer that internal, cleared personnel review and attest to, with that attestation feeding into the unclassified audit trail.
Getting this split wrong in either direction creates real problems. Over-classify the AIMS documentation itself, and you can't get third-party certification at all, because the certification body's auditors can't review evidence they're not cleared to see. Under-classify it, and you've created a spillage risk in the name of ISO compliance. The organizations that handle this well treat the classification boundary as a design constraint on the management system from day one, not a problem to solve after the fact.
Dual-Use Systems Complicate the Picture
Very few AI systems in the defense space are purely military. A satellite-imagery classification model built for a defense customer may run on the same underlying architecture as a commercial remote-sensing product. A predictive-maintenance model for military aircraft engines may share code and training methodology with a civil-aviation version. This dual-use reality means the EU AI Act's Article 2(3) exclusion doesn't automatically cover everything a defense contractor builds.
The exclusion applies to systems developed or used exclusively for military, defense, or national security purposes. A system built for dual civil and military application, or later repurposed from a military program into a commercial offering, can fall back under the EU AI Act's general scope depending on how and where it's deployed. Contractors operating in this dual-use space need to know which regulatory regime applies to which version of their product, and there are more of these contractors every year as commercial AI vendors pick up defense work. ISO 42001 becomes the connective tissue: a single AIMS can support both a fully exempt military variant and an EU-Act-covered commercial variant, without forcing the contractor to maintain two entirely separate governance programs. Our EU AI Act overview covers the dual-use scoping question in more depth.
What Certification Actually Signals to a Program Office
A program office reviewing a proposal doesn't have the bandwidth to independently verify a contractor's internal AI governance claims. What they can verify is whether a contractor holds a certificate from an accredited certification body, issued against a recognized international standard, with a defined surveillance audit cycle. That's the practical value ISO 42001 certification delivers in a source-selection or contract-oversight context: it converts an unverifiable claim, "we govern our AI responsibly," into a verifiable fact: "we hold ISO 42001 certification, audited on a recurring surveillance cycle by an accredited certification body."
It's worth being honest about what certification does not do. It does not certify that a specific model will perform correctly in a specific operational scenario, and it does not substitute for the test-and-evaluation processes the DoD already requires for AI-enabled systems before fielding. What it certifies is the management system around the AI: the risk assessment process, the change control, the incident response, the supplier oversight, that makes safe, well-tested outcomes more likely and more demonstrable when something does go wrong.
Contractors weighing whether the investment makes sense should run that calculus themselves. It differs meaningfully between a pure defense supplier and one with commercial AI exposure, for the dual-use reasons discussed above.
Getting Started Without Overbuilding
The temptation with any new management-system standard is to build the most elaborate version possible on the first pass. For defense contractors, I'd push in the other direction. Start with a gap analysis against the clauses that map most directly to requirements you already have to satisfy:
- Clause 6.1.2 risk assessment, against your existing system safety process.
- Annex A.6 data controls, against your existing classification-handling procedures.
- Annex A.7 supplier controls, against your existing CMMC subcontractor flow-down requirements.
Where the overlap is genuine, document it once and reference it twice, rather than building parallel documentation trails that will drift apart within a year. Our AI risk assessment process is a reasonable place to start that gap analysis, and our implementation guide walks through the sequencing from there.
Frequently Asked Questions
Does the EU AI Act apply to U.S. defense contractors building AI for the Department of Defense? No. Article 2(3) of Regulation (EU) 2024/1689 excludes AI systems developed or used exclusively for military, defense, or national security purposes from the Act's scope, regardless of the developer's or operator's location.
Is ISO 42001 certification mandatory for defense contractors? No contracting regulation currently mandates ISO 42001 certification the way DFARS clauses mandate CMMC compliance. It's a voluntary certification that gives contractors a documented, auditable way to demonstrate AI governance to program offices and oversight bodies in the absence of a defense-specific AI regulation.
How does ISO 42001 relate to the DoD's five AI Ethical Principles? The DoD's principles, responsible, equitable, traceable, reliable, and governable, adopted February 24, 2020, describe outcomes. ISO 42001 provides the management-system structure, risk assessment, documentation, internal audit, and management review, that an organization can use to demonstrate it's actually achieving those outcomes rather than just stating them as values.
Can a certification body audit an AIMS that includes classified systems? Yes, but it requires deliberate documentation design. The unclassified layer of the management system, policies, procedures, risk methodology, is reviewed directly by the certification body's auditors. Classified evidence is reviewed internally by cleared personnel whose attestations feed the audit trail the certification body relies on.
Does ISO 42001 replace CMMC 2.0 requirements? No. CMMC 2.0, under the program rule at 32 CFR Part 170 effective December 16, 2024, governs cybersecurity controls for handling controlled unclassified information. ISO 42001 governs AI-specific risk and lifecycle management. They address different risks and can be implemented as complementary, not competing, programs.
Getting the scope right, and the classification boundary right, is where most defense AI governance programs stall before they start. If you're weighing how ISO 42001 fits alongside your existing DoD compliance obligations, contact us to talk through where your program actually sits.
Last updated: 2026-08-27
Jared Clark
Principal Consultant, Certify Consulting
Jared Clark is the founder of Certify Consulting, helping organizations achieve and maintain compliance with international standards and regulatory requirements.