Fielding Centaur
Challenges and opportunities for UK military autonomous capability acquisition
Executive summary
The United Kingdom intends to field autonomous and AI-enabled military systems, and early signs are encouraging. This paper tests UK strategic ambition with a thought experiment: evaluating how a complex, cross-domain autonomous capability would likely fare within the Ministry of Defence (MOD) acquisition system.
We introduce Centaur: a hypothetical cross-domain capability for autonomous wide-area surveillance and strike, drawing air, sea and land systems, sensors, AI, command and effects into one human-machine system directed by forward teams. We step Centaur through the UK acquisition system and compare it with how Ukraine and Israel develop capability under wartime conditions, to forewarn of pitfalls and signpost catalysts for the acquisition community.
Our central judgement is that a Centaur-like acquisition would likely fail, and would do so beyond the early conceptual stages. The UK can identify needs, fund early exploratory work, create promising prototypes, buy useful off-the-shelf systems, run trials, write policy, and field discrete capabilities. The most likely failure point lies later, in integration: a Centaur-like capability is not a set of platforms; it depends on the connection of platforms, sensors, data, autonomy, weapons, legal authority, logistics, training and command into one system that must then be altered at the pace of an adapting adversary. MOD’s record of delivering complex, integrated capability is poor, and reforms intended to fix it remain unproven. The most plausible outcome is programme failure with pockets of limited success inside it: useful components, demonstrators and limited fielding, but not the joined, persistent, adaptive system envisaged, with the integrated whole decomposed into separately governed programmes and deferred because no single authority owns the budgets and decisions needed to hold it together.
The AI governance layer compounds rather than resolves this. The law of armed conflict, owned by an existing professional community, is the foundational governing framework; the AI policy bookshelf often imports ill-suited civilian ideas, describes problems without resolving them and remains too high-level to operationalise test and assurance methods.
Ukraine and Israel show ways through, neither copyable wholesale: Ukraine creates consequence through front-line demand and rapid feedback; Israel connects development, users and mission through a cohesive integrating layer and culture. Both show the binding problem is not autonomy itself but the institutional ability to turn autonomous components into combat power.
Britain’s challenge, then, is not to purchase standalone autonomous platforms or to write more ethics policy. It is to enhance the military system quickly enough to connect technology, people, law, logistics, authority and operational learning so autonomy becomes combat power rather than another collection of impressive platforms.
Introduction
The United Kingdom (UK) intends to field autonomous and AI-enabled military systems. Each service has published strategies and made progress towards building systems. The UK Ministry of Defence (MOD) has crafted AI and autonomous-systems governance documents, stood up new units and established a range of demonstrator initiatives. MOD has engaged in training and technology exchange that leverages Ukraine’s wartime experience.
This paper explores the challenges and opportunities that lie ahead for MOD, using a hypothetical autonomous warfare concept, Centaur. We analyse Centaur against MOD’s acquisition model, drawing upon the UK’s historical record and insights from ongoing conflicts to forewarn of pitfalls and signpost catalysts for the acquisition community seeking autonomous systems for strategic advantage.
We focus on four topics to set the background to this study:
-
Existing service ambition and plans for autonomous systems, including autonomous kinetic strike platforms.
-
MOD acquisition reform, within the constraints of the Equipment Plan (EP) and the acquisition process.
-
Ukrainian and Israeli capability development and adaptation under wartime conditions.
-
Emerging AI governance policy.
The Centaur concept
Centaur is a cross-domain (air, sea and land) human-machine system for autonomous wide-area surveillance and effect. It is enabled by AI-powered sensing, targeting and strike, built on a range of cooperative autonomous platforms, payloads and weapons. It is directed by decentralised teams working within command intent, with goals, targets and rules of engagement built into the design. It draws on organic intelligence, surveillance, target acquisition and reconnaissance (ISTAR) and weapons, can cue external weapon systems, and consumes external intelligence feeds subject to information-sharing permissions. It is envisaged primarily as a wide-area border-protection capability, but can also conduct offensive operations in high-threat conflict by establishing adaptive kill zones and supporting long-range sabotage and precision-strike operations. It is supported by a resilient, survivable logistics trail.
In practice Centaur is defined by what the whole system achieves. It senses persistently and opportunistically from many sources, with tasking and fusion at the edge under denied communications. It moves at machine speed from sensor to target to action to effect. It is sustained by a resilient supply chain and tightly-coupled training and adaptation that keep it effective as the adversary changes. Its advantage rests on speed (the sense-decide-act loop run fast), range (organic reach across wide geographies), persistence (the ability to operate, without disruption, for long periods of time), and integration (maximal collaborative exchange for operational effect). Denied communications, radio-frequency hardening and system security are assumed throughout as engineering conditions, not afterthoughts.
Centaur is imagined in two related settings: UK and NATO border protection. The UK scenario emphasises the reactive over the proactive, and the defensive over the offensive. It is primarily a maritime and air challenge against sabotage, covert action and coercive presence (shadow-fleet tankers, hostile warship activity, drone incursions, seabed cable interference, satellite-navigation jamming), where the posture is reactive but not passive: not force projected from the coastline, but force used decisively against, say, a submarine interfering with undersea cables. In contrast, the NATO eastern flank holds a similar protective mission but includes a much more significant land component, and, crucially, the escalation-critical risk of high-intensity, cross-domain conflict against a battle-hardened adversary. These are two distinct operating environments, but the gap between them narrows as conflict moves closer to the homeland. These scenarios are analytical stress cases, not proposed UK rules of engagement or legal authorities; their purpose is to expose the acquisition, integration and assurance burden of autonomous operation across the boundary between persistent competition and armed conflict.
Why this concept?
Centaur is an ambitious yet natural extension of emergent service concepts, notably the Army’s Robotics and Autonomous Systems (RAS) approach,[1] the RAF’s Autonomous Collaborative Platforms (ACP) strategy,[2] and the Royal Navy (RN) hybrid fleet.[3] It is a joint concept demanding dynamic, seamless integration across domains, platforms, command, sensors and effects: for example, a submarine-launched drone that delivers an uncrewed ground vehicle to shore, which in turn launches a low-observable surveillance drone. Specifically, Centaur was designed to:
-
Stress UK technology, engineering and integration readiness.
-
Stress inter-service and cross-government collaboration.
-
Stress MOD acquisition at a time of rising fiscal challenge and political uncertainty.
-
Stress NATO alliance linkages.
Defence acquisition: UK, Ukraine & Israel
This section sets out our models of UK, Israeli and Ukrainian defence acquisition, as the basis for our subsequent analytical judgements on likely trajectory and leverage opportunities.
The system the UK would use
MOD acquisition is dominated by the EP.[4] The EP is the outermost construct for MOD capability acquisition: a costed ten-year portfolio of what defence intends to buy and support. Every year, each front-line command builds up a submission that is judged affordable (or not) against a fixed budget. The EP is not itself a probability model: while acquisition planning uses ranges and confidence assumptions to represent uncertainty, the EP requires each programme to be expressed as an annual budgetable figure within a fixed envelope. For low-risk, conventional or simple programmes this is workable. For complex, high-risk or novel systems, where costs cannot be known with confidence early on, the modelled range is collapsed into a committed point that can harden into a baseline before the underlying uncertainty has been retired.
Within the EP sits the formal acquisition lifecycle: concept, assessment, demonstration, manufacture, in-service, disposal (CADMID), with formal approval gates. The lifecycle has evolved: CADMID was extended to CADMID/T to recognise termination, and is now being revised again through CADMIR, which replaces disposal with refresh to reflect a more circular approach to capability.[5] Where this paper uses these terms, it refers to the formal MOD acquisition process as it stood at the time under discussion; the historical record examined here was delivered under CADMID and CADMID/T, and that is the lifecycle against which Centaur is stepped through. Managed and executed by Defence Equipment and Support (DE&S), this is the mechanism that converts funding and plans into fielded kit, platforms and systems for the military. DE&S employs roughly 12,500 civilian and military personnel and manages a comprehensive and detailed process, from requirements definition through test and evaluation to cost modelling. It includes cost controls and assurance processes intended to constrain cost and manage risk, but its incentives are principally organised around approvals, affordability and delivery against programme baselines rather than continuous price competition. Capability is intended to be delivered not as equipment alone but across the defence lines of development (training, equipment, personnel, infrastructure, doctrine, organisation, information and logistics) so that kit, systems and platforms can be used, supported and maintained, transported, and ultimately fielded for battle-winning advantage.
MOD acquisition machinery is undergoing another period of reform. A new Integrated Procurement Model (IPM)[6] and a segmented operating model have been introduced. DE&S is mid-transition to a functional structure, all within a newly established National Armaments Director (NAD) group.[7] This is a wholesale reorganisation across MOD. It consolidates several bodies under a single director and a single investment budget, and is governed by a new senior body comprising the NAD, the Chief of the Defence Staff (CDS), the Permanent Under-Secretary (PUS) and the Chief of Defence Nuclear (CDN). A related instrument, the Integration Design Authority (IDA) within Strategic Command, is the part of the reform aimed most directly at system-level coherence: MOD describes it as providing “Integration as a Service,” advising and assuring project-level requirements to deliver integrated effects. That advisory and assurance role is the point: on its published remit it shapes and challenges requirements rather than controlling programme budgets, operational-release decisions or delivery obligations, a distinction that matters for the analysis that follows.[7] In practice, DE&S alone is an organisation of that size, where culture is set by staff members who have lived through many waves of reform: Smart Acquisition, the Gray report, Levene, even DE&S itself being established as a bespoke trading entity.
Despite seeming bureaucratic sophistication, MOD procurement has a long-standing track record of expensive failure. A recent set of examples includes: Watchkeeper, an Army surveillance-drone programme that ran years late, cost far more than planned, and delivered limited operational utility;[8] Ajax, an armoured vehicle programme that ran years late, exceeded its budget and exposed its crews to harmful vibration and noise;[9] and Nimrod, a maritime patrol aircraft programme that was scrapped after immense expense, including airworthiness failure.[10] Sadly, such examples have not been cherry-picked and are not isolated. The EP, and DE&S delivery, have been criticised repeatedly by external reviewers: the now-familiar National Audit Office charge of being unaffordable, alongside external reviews pointing out catastrophic failures and waste.[4]
This review is not intended to open old wounds or to insult the acquisition community; its defenders would rightly point to the distinctive bureaucratic and technical complexity of UK military procurement. The goal is to establish an empirically grounded model of acquisition that avoids an optimism bias and anticipates patterns of failure as well as examples of success.
Looking to more recent autonomy programmes, several positive indicators have been observed. While too small and early to declare the historical pattern broken, there is some evidence for cautious encouragement. The instincts on display are better than the old way. The RN bought its Rattler uncrewed surface vessels quickly, through a route it called a departure from normal procurement, and ran five of them in a 72-hour demonstration escorting warships off Scotland.[11] The Royal Air Force (RAF) has put StormShroud into operational service.[2] These programmes favour cheap, attritable, single-purpose systems (StormShroud is built so that combat loss, while undesirable, is acceptable) derived from commercial technology, explicitly informed by Ukraine, and run through new vehicles deliberately placed outside the main acquisition machine: a Disruptive Capabilities and Technology Office, a Fleet Experimentation Squadron, the Defence AI Centre (DAIC).
Encouraging signs from trials or small-scale deployments are not the same as a reformed acquisition institution fielding cross-service capability based on cutting-edge autonomous technology quickly and within constrained budgets. Watchkeeper and Ajax had impressive demonstrations too; defence innovation organisations showcased high-technology demonstrators throughout the period. Such indications are not to be confused with true capability-readiness. So while encouraging signs have been observed, caution is warranted: the language used in the reporting is key. “Proof of concept,” “demonstration,” “trial,” “experimental vessel” are all words for not-yet-capability. StormShroud’s entry to service is a stronger example, and should be credited as the most mature data point, without neglecting the readiness questions the announcement skips: how many, at what availability, with what sustainment, and to what end, given that it is a single electronic-warfare type.
Two observations matter. First, the systems demonstrated are non-lethal or human-piloted: the Rattlers were remotely controlled by two-person crews, and StormShroud blinds radars rather than selecting and striking targets. Second, they are single-domain, cheap, attritable, and have been routed around the main acquisition system. As such, they have yet to touch upon the most challenging and complex parts of each service concept, nor the key challenges of the hypothetical Centaur: cross-domain integration, long-range sustainment, the assurance and testing of a complex system, and live-fire testing of new operating and command concepts.
Finally, a cautionary note, relating to the bias toward optimism that is endemic in MOD acquisition: the volume and tone of publicity around autonomous systems, versus the thinness of fielded, integrated, sustained capability, is itself part of the record: rhetoric running ahead of delivery, this time in this period’s high-technology outfit. This risks being gloss that provides evidence for the thesis of institutional challenge, not evidence against successful reform. MOD’s record of delivering complex, integrated capability is poor. The reforms now under way are too recent to demonstrate that they have changed this baseline, and it is this baseline model that is used in our analysis.
WarDev: capability development while fighting a war
Having considered the suboptimal record of MOD capability development and acquisition through peacetime and the relatively secure period of expeditionary warfare, we turn to two nations conducting warfare for national survival: Ukraine and Israel.
Ukraine at war: Spiderwebs, Sea Babies and Flamingos
Ukraine, under invasion, has endured, fought and innovated to build a system driven by concrete, urgent operational need: route vulnerability; enemy signals that cannot yet be geolocated; jamming drone communications to stem the loss of life; building missiles to extend the fight into Russia’s once-safe rear. With US and NATO advice, support and materiel, and domestic ingenuity it has married combat need to an agile build-test-modify-employ cycle and turned it into a nationwide industry, most strikingly in drones. From roughly ten makers before 2022, Ukraine has built an ecosystem of more than 500 by 2025, with Ukrainian reporting and external accounts placing output in the millions annually; the Ministry of Defence planned to purchase around 4.5 million FPV drones in 2025.[12]
The mechanism matters as much as the volume. Through the integrated Brave1 and DOT-Chain Defence marketplaces, front-line units select drones and other equipment directly from approved manufacturers while the Defence Procurement Agency handles contracting, payment and delivery; units earn “Army of Drones” points for confirmed battlefield effect and spend them on further equipment, with delivery averaging about nine days; the marketplace is integrated with Brave1 Market and the Army of Drones Bonus programme.[13] The soldier, airman or sailor is now effectively the head procurement officer: money flows to what works under fire rather than to incumbency or contract position, and battlefield-effect data and front-line feedback reach producers continuously, so a counter to a new Russian electronic-warfare method can reach the front in days or weeks instead of the years a Western change-request takes. Governance is not absent here; it is fused into the combat-learning loop, and its test is whether it improves effect and adaptation speed.
This wartime footing carries its own risks. Ukraine entered the war with long-standing corruption problems (the reason its independent anti-corruption agencies exist, and a standing condition of its EU-accession path), and large, fast military procurement has created new opportunities for corruption. In August 2025 those agencies charged officials, including a sitting lawmaker, over a scheme that bought drones and electronic-warfare systems at inflated prices, with kickbacks of up to 30%.[14] The case surfaced days after an attempt to curb the agencies’ independence triggered the largest protests since the 2022 invasion and prompted EU warnings over accession.[15] Large, fast procurement under wartime conditions carries an internal security and legitimacy cost for the government, military and supply base.
Sustainment in this model works differently, because Ukraine reduces the long-term sustainment burden for many attritable systems rather than removing it. Cheap systems are fielded straight to the front, repaired by operators rather than through long support contracts, and often consumed or replaced, rather than sustained. The result is no decades-long support tail and no legacy lock-in for that tier.[16] The burden does not vanish: the supply chain, repair, batteries, payloads, training, software, electronic-warfare resilience, transport and factory survival all remain sustainment, and remain demanding under fire. But where the West holds small numbers of exquisite platforms for thirty years and inherits the obsolescence that follows, Ukraine’s rapid turnover blunts it; four years in, the base has sharply reduced its import dependence, cutting the share of Chinese components from near-total in 2022 to about 38% by 2025, and has kept producing through sustained Russian strikes on its factories.[17] What looks from a Western vantage like an absence of lifecycle management is, for the attritable tier, the design: capability is treated as consumable.
That decentralised model has a cost in consistency, and Ukraine’s own response is instructive. By late 2024 its units were operating more than 250 different drone types of uneven quality, and in December 2024 the government imposed a formal certification gate, requiring documentation before a drone could be bought.[12] It addressed the quality problem but created another: timelines lengthened, and control of the documentation became a point of extraction and delay, slowing urgent deliveries to the front. The fix was not to abolish the gate but to build a faster channel alongside it: the DOT-Chain Defence marketplace, launched in mid-2025, letting units order directly from approved suppliers.[18]
The model is based on a feedback mechanism that rewards performance, tempo and cost-effectiveness directly: the front line itself, mediated by a system in which the user is the customer and money follows demonstrated effect. The user holds the purchasing decision, and continuous performance data feeds back to producers. Wartime necessity supplies the pressure and the volume; the marketplace supplies the mechanism. The UK cannot reproduce the pressure, but it can choose to build some of the mechanism.
Israel at war: Lions, gun turrets and traffic-camera intelligence
Israel runs its own model again, neither Ukraine’s decentralised wartime swarm nor MOD’s programme bureaucracy. It is small, intelligence-led, and built around a strong central body that drives development, with an unusually tight loop between users, industry and academia.
At its centre is MAFAT, the Directorate of Defense Research and Development, inside the Ministry of Defense.[19] It anchors national defence R&D: it coordinates the major programmes with the three primes (Rafael, Elbit Systems and Israel Aerospace Industries), funds specialised research in universities and government labs, and channels money to startups and small to medium enterprises (SMEs). It is deliberately small and military-staffed: around a thousand people, roughly three-quarters serving officers and soldiers. In January 2025 it stood up a dedicated AI and Autonomy Administration to centralise and accelerate that work across all branches, drawing IDF technology units, academia, industry and startups into one structure.[20]
The defining feature is the tightness of the development loop, and the willingness to bypass normal process to keep it tight, underpinned by high levels of trust and cultural alignment. The Iron Dome itself was driven through against strong opposition by MAFAT’s long-serving head, who skirted army contracting regulations to secure early financing and later characterised the directorate’s speed of decision in days, not years: “we got the funding in two days.”[21] Development runs through joint teams that put industry engineers, MAFAT and IDF end-users in the same room; the programme to build the next-generation IDF battlefield-digitisation array (the fifth-generation “Tzayad” Digital Ground Army), for instance, is structured explicitly as a joint development team of Elbit, MAFAT and the IDF Ground Forces, and its companion border-defence track is built around compressing the sensor-to-shooter loop with AI-managed, high-volume target detection.[22] The user is not a distant requirement-setter or an abstract systems-engineering notion; the user is in the build.
Underneath sits a talent model few Western peacetime forces could replicate. Universal conscription lets the IDF screen an entire cohort and route the highest-aptitude recruits into elite technical units (Unit 8200 for signals intelligence, Talpiot and Unit 81 for hardware R&D) that serve as both operational units and, in effect, the country’s premier engineering schools.[23] Service is short, so the units optimise for rapid learning; alumni carry both the skills and the operational problem-set into industry and startups, and many return as reservists, keeping the civilian and military bases continuously cross-fertilised. Israel’s defence-technology base, its intelligence apparatus and its commercial technology sector draw on the same pool of people, who have often worked in all three.
What the integrating layer produces can be seen in recent operations, which fuse human networks, sensing, data and effect around a single operational need rather than around an off-the-shelf platform. Operation Rising Lion, Israel’s June 2025 strikes on Iran, opened from within: over months, drone parts and precision munitions were smuggled into Iran and pre-positioned near air-defence and missile sites, then activated in concert with the air campaign.[24] The cyber and intelligence side of the same apparatus enabled Israel’s Operation Roaring Lion, its part of the coordinated US-Israeli strikes of February 2026 (the US operation was designated Epic Fury). In Roaring Lion, the Iranian supreme leader was killed in the opening salvo, after long intelligence preparation built a precise pattern of life: among the methods reported, Israeli intelligence harvested footage from Iran’s traffic cameras and used AI to parse vast quantities of video, fusing it with signals intelligence and human sources to fix the time and place of a meeting of senior officials.[25] The mechanism is notable in its own right: the continual AI-enabled processing of large volumes of hacked surveillance-video streams, turning a cheap and ubiquitous sensor not built for the purpose into precise targeting by fusing it rapidly with other intelligence around one objective. That is sensing, data fusion, intelligence, targeting and effect brought together around a specific operational aim, which is what the integrating layer exists to do. None of this is an off-the-shelf platform; each is an integration achievement, which is what the Israeli system exists to produce.
The independence this model confers is selective, and chosen. In the air, Israel is heavily dependent on the United States for combat aircraft, tankers, helicopters and advanced aerial munitions.[26] On land it is far more sovereign, designing and building the Merkava main battle tank and the heavy vehicles derived from it; in missile defence it co-develops and co-funds with Washington; and it has substantial domestic capability in cyber and signals intelligence. Israel appears to retain unusually strong domestic control over selected integrating layers (sensors, electronics, command systems, autonomy, intelligence fusion and mission design) even where it depends heavily on the United States for major platforms and munitions. The financial dependency is structural: US assistance runs at around $3.8 billion a year, historically around 20% of the defence budget, with the grant “buy American” by design.[26] The recent wars exposed the gaps: shortages of interceptors and munitions Israel could not make at home drove a NIS 350 billion, decade-long indigenisation programme announced in December 2025.[27] The pattern is one of domain-by-domain trades: buying the air power it does not build, building what it can on land and in cyber, and concentrating national effort on the talent and integration layers.
Israel’s distinctive national history and continuous high-threat security context have produced an equally distinctive system of defence capability development. Three institutional features characterise it: an empowered, cohesive directorate owning the development loop end to end; joint, high-trust, collaborative user–industry teams aligned to impact over contracts, with success as the default unit of work; and a talent pipeline treated as national infrastructure.
The MOD AI governance bookshelf
Centaur’s autonomous nature places it squarely in scope of the growing body of MOD policy on artificial intelligence: the Defence AI Strategy (2022); its policy statement, Ambitious, Safe, Responsible (2022), which set out five ethical principles;[28] the binding regime, Joint Service Publication 936, Dependable Artificial Intelligence in Defence (current version November 2024);[29] the Defence AI Playbook (2024);[30] and an annual Responsible AI Senior Officers’ report, the most recent being Laying the Groundwork (October 2025).[31] This section sets out our understanding of the additional, or new, forms of experimentation, trials, testing, validation, verification, certification and assurance required to comply with MOD AI and autonomy governance. In doing so, we also present our understanding of where the “bookshelf” risks introducing needless complexity, confusion or burden. Note that we are not concerned with applications of AI within MOD as an employer or other non-combat considerations that may fall under wider civilian legislation.
Autonomous weapons, AI governance and the UK law of armed conflict. The essential basis for UK military use of force is the UK’s law of armed conflict, set out for the armed forces in the Manual of the Law of Armed Conflict and administered through the MOD’s legal service and the appropriate review bodies and legislation.[32] Formal MOD legal standards, references and guidelines govern operations; AI and autonomy governance does not displace or supersede them. The military legal community already carries the duty, responsibility and expertise to interpret and apply the law within existing operations, and novel systems should reinforce this legal capability. AI and autonomy governance should ensure that any new framework empowers, educates and enables legal advisers and commanders, with the appropriate information and tools to discharge their existing obligations when taking responsibility for systems that can decide and act faster than human teams. The corpus correctly anchors itself in the law of armed conflict and the Article 36 review, though JSP 936 flags its own immaturity in its cover note, declaring the document to be “the aiming point or ideal end state,” with its supporting tools (model cards, assurance question sets, the ethics framework) still in development as “minimum viable products.”[29] The 2025 report is titled Laying the Groundwork and states that implementation is “at a formative stage.”[31] Two official documents, a year apart, agree that the regime which would govern Centaur’s AI is not yet built.
New considerations beyond the law of armed conflict. The AI governance bookshelf introduces a new layer of considerations beyond core legal concerns. Its five principles (human-centricity, responsibility, understanding, bias and harm mitigation, reliability) are operationalised through JSP 936, which requires each project to appoint a Responsible AI Senior Officer, conduct an ethical risk assessment, define the system’s operating environment, maintain model and data records, build a safety case, and re-assure the system after changes that affect its behaviour.[29] The organising idea is that compliance is determined not by what a system does but by how it is built: there is no list of permitted or prohibited capabilities, and each case is judged on the choices made across its lifecycle. Meaningful human control is named as the foundation, achieved through “context-appropriate human involvement”. The policy statement is explicit that this may mean “some form of real-time human supervision, or control exercised through the setting of a system’s operational parameters”, including in weapons which identify, select and attack targets.[28]
Pinning down “meaningful human control”. As a collection, and notwithstanding that provision, the bookshelf imagines appropriate control as human approval of machine decisions and actions. JSP 936 devotes a section and its subsections to human/AI teaming, human-centred design and function allocation. Only a single clause is offered on higher levels of autonomy, a note that they “typically reduce the potential for human decision-making within the control loop and this must be considered”. Kinetic effects are one of two applications meriting “special attention”. The document reiterates the MOD commitment that there must always be human involvement achieving meaningful human control “over the operation and effects of the autonomous system”, but does so in a footnote.[29] We note that the concept of command intent is not explicitly referenced in the JSP. This model does not match the existing practice, in which military personnel decide and act on their own initiative while complying with a commander’s intent and rules of engagement: commanders set intent and issue rules but do not adjudicate every single engagement, every single target, every single shot. Professionalism, discernment and skill are trained into the service members who apply force. An autonomous system disrupts this not by removing a commander’s approval but by replacing that familiar, trained and evaluated cognitive capacity with an opaque, unfamiliar and poorly understood artificial neural network: the machine is seen to think, to reason and to decide. The central question, then, is what the machine equivalent is of the safeguards that ensure compliance with rules of engagement and the professional judgement trained into service personnel. The corpus brushes against the answer with control “through the setting of a system’s operational parameters”, the closest analogue to rules of engagement, but treats it as a settled alternative when it is in fact the whole problem:[28] the matter of creating and operating such system parameters. Whether they can be written precisely and completely enough for a machine to apply against an adversary who adapts; who may set or change them once an operation is under way; and who is accountable when the encoded judgement fails. Perhaps unsurprisingly, the Army’s own doctrine sees this more clearly than the central policy does. Its Robotics and Autonomous Systems approach frames the issue as trust, to be “optimised rather than simply maximised” (too much leaves operators relying on a system they do not fully understand, too little wastes the machine’s advantage), and sets it in a chain: soldiers must trust machines, military regulators must trust soldiers to set the permissions, and society must trust the regulators.[1] That is a sharper account of the control problem than the policy corpus offers, and it is telling that it comes from the operational community rather than the centre. Yet even there the hard edge is left unresolved. The document’s own illustration of a future engagement shows an armed uncrewed ground vehicle with “engagement authorised” against a target carrying a stated collateral-damage estimate, and never says who authorised the engagement, how the proportionality judgement was reached, or where the human sat in the decision.[1]
New considerations for testing, verification, validation, assurance and acceptance. This is the one area where AI governance could earn its keep on top of the law of armed conflict, and it is where the corpus has the most to say. What it says is not addressed to the hardest case. Conventional acceptance rests on an assumption that breaks for these systems: that behaviour is fixed at the point of acceptance. A system is tested against a specification, passes, is fielded, and behaves in service as it did on the range; the safety case is made once and holds. A learning or adaptive autonomous system violates this on three counts. Its behaviour space is too large to test exhaustively: no trials programme can enumerate the situations an open-world system meets against an adapting adversary, which is the Playbook’s “hostile environments that might differ significantly from training” stated as an acceptance problem rather than a caption.[30] It may change after acceptance: the adaptation Centaur requires happens within operations, not merely between them or through an infrequent update schedule, so the system that was assured is not necessarily the system that is deployed, and the safety case acquires a shelf life. And its behaviour is emergent and not always interpretable: the reason a system acted as it did cannot always be reconstructed, which breaks assurance and accountability at once. The substantive additions to test and acceptance are therefore not refinements of the existing model but departures from it: methods to bound and characterise a behaviour envelope rather than enumerate cases; continuous or in-service assurance rather than one-time acceptance, at a tempo the approval chains can actually sustain; interpretability sufficient for a legal adviser to interrogate a decision after the fact; and a means to specify and then verify operational parameters, so the authorised envelope can be shown to hold. These are hard and unsolved. But this is precisely the contribution a defence AI-governance regime could make that the law does not: not another ethical principle, but the test and assurance methods that would let the existing legal and targeting community see what an autonomous system will do and show why it did it. The bookshelf does address assurance, but generically. JSP 936 requires behaviour to be bounded by constraints that “may be geospatial, temporal, or functional”, requires verification and validation after update to test for catastrophic forgetting and model drift, and states that where assurance risk cannot be tolerated, AI must not be adopted.[29] These are dependable-software requirements, and they would apply in the same terms to a logistics model. None is addressed to the question a Centaur poses: what makes a set of parameters an adequate substitute for the trained judgement of the person who would otherwise authorise the engagement. On that, the corpus offers special attention and a referral. Maritime autonomy programmes now running provide a concrete example of how the existing maritime-safety regime is the relevant governor rather than AI ethics: the international collision-avoidance rules, the industry code of practice for autonomous surface ships, the control architecture for mission planning.[33]
A flawed wholesale lift of a civilian conception of AI ethics. The bookshelf introduces AI ethics as a concern for MOD development and use of AI and autonomous systems. Much of the intellectual apparatus has been imported, unchanged, from civilian AI ethics: the principles were developed with the Centre for Data Ethics and Innovation, a body whose remit is trustworthy commercial and public-sector data use.[28] In that domain, the focus is on bias, on discrimination, and on minimising negative harms to people who might be affected by such bias: a loan inappropriately denied, a face incorrectly matched on police cameras. The primary concern is the bias and fairness of data, algorithms and models across population groups and protected characteristics. These are not the primary considerations for lawful military force. What it requires is accuracy, precision and known error bounds: whether the system reliably distinguishes a combatant from a civilian, whether proportionality can be assessed in a measured and lawful way, and whether it can provide evidence for review, audit and learning. Computer vision models may operate within recruitment processes or in a targeting chain; while the technology is common, rightly the governing law is not. The civilian frame addresses its own question at length and does not perform that translation.
Meta-governance that may confuse rather than illuminate. More telling is how much of the corpus is governance of governance. The senior officers’ report is, in large part, a report about the architecture for overseeing AI: officers nominated, assurance statements submitted, communities of practice convened, frameworks tailored. It is explicit about the limits of the senior role it describes. Responsible AI Senior Officers, it states, “are not responsible for technical delivery, system-level assurance, or direct operational deployment”; they “do not act as developers, testers, or certifiers”; the role is “strategic and facilitative, not operational or technical.”[31] The technical assurance, the part that determines whether a learning system behaves safely, is delegated downward to senior responsible owners and subject-matter experts, and managed at the local level. The accountable seniors govern; the hard technical work sits with delivery teams and specialist authorities below them. Whether that distributed model can produce a coherent acceptance case for a system spanning several programmes and authorities is the unresolved question.
Descriptive, not prescriptive: admiring the problem. Hard problems are often identified and then left as an exercise for the reader. The Defence AI Playbook (fourteen pages, written to interest industry) reaches its most challenging case in its final example, autonomous resupply, and states the challenge exactly: autonomous navigation “poses significant challenges for Test, Evaluation, Verification and Validation,” because “we must be confident that they will behave as expected, even in hostile environments that might differ significantly from training.”[30] That single sentence is the central difficulty of fielding any learning system that acts in the world. The document states it as a caption and offers nothing toward it; the senior officers’ report likewise lists “Assuring Complex AI Applications” as a heading and moves on.[31] This is what is sometimes called admiring the problem: describing a difficulty with growing sophistication, building structures to oversee thinking about it, and never proposing a concrete way through. The reading is shared by the House of Commons Defence Committee, which in January 2025 examined the UK’s ability to develop and field defence AI and reached the same conclusion in its own terms: a “say-do gap” between the department’s rhetoric and what it delivers.[34] The Committee judged the Defence AI Strategy clear on priorities but thin on specific, measurable actions, and cited expert evidence that its objectives were too vague to judge progress against. One witness told it that what the policy rewards is marketing, pitches that are, in his phrase, “PowerPoint deep”, rather than fielded capability; others pointed to the mismatch between how often AI features in ministerial speeches and the very small number of AI contracts the department has placed.
Summary. Our assessment of the AI governance bookshelf, read for a Centaur concept, is this: the law of armed conflict, owned by an existing professional community, is the overriding governing framework, and it does not need a parallel ethical edifice beside it. AI governance that augments proven structures with a new ability to characterise, understand and predict the performance of AI and autonomous systems would be a significant enabler for accountable decision-makers. Essential AI governance that mandates the testing, evaluation, verification, validation and assurance tools and techniques that prove readiness may also hold utility for commanders and legal advisers in defining the rules of engagement and commander’s intent within which an autonomous system may act. The current bookshelf sits at too high a level to shed light on how any of that is to be achieved.
Assessment: Centaur’s expected UK trajectory
This section sets out our expectation of a Centaur acquisition, stage by stage through the UK lifecycle. It synthesises the analysis in Annex A, where each step is set against the Ukrainian and Israeli comparators, and forms the basis for the trajectory described below.
We assess that the Centaur capability would likely fail to materialise, and would do so past early conceptual stages. The UK can identify the operational need, fund early exploratory work, create promising prototypes, buy useful off-the-shelf systems, run trials, write policy, and field discrete capabilities. The likely failure point lies later: when platforms, sensors, data, autonomy, weapons, legal authority, logistics, training, test infrastructure and operational command must become one fighting system, and must then be altered at the pace of an adapting adversary. The UK record suggests that this is where Centaur would begin to fragment and ultimately unravel.
Centaur would likely begin as a major cross-service requirement. Its scope would draw it into the EP, formal approval gates and several existing programme structures before the system’s architecture, operating concept, assurance burden and lifetime costs were mature. The Department can model uncertainty, but the annualised planning figure the EP requires can acquire the status of a commitment before the uncertainty beneath it has been retired. The need is not in doubt; the risk is that a Centaur-scale requirement is fixed as a large programme while the hardest unknowns are still open.
The next risk is decomposition. Centaur is not a platform; it is a system that depends on the connection of platforms, sensors, command systems, data fusion, weapons, operators, doctrine, logistics, legal authority and assurance. In the UK, those elements would most plausibly be developed through separately governed programmes and authorities, each with its own budget, assurance route, supplier relationships and programme rhythm. Each can be run competently in isolation, and the incentives reward exactly that: a programme is judged on delivering its own component to its own gate, not on whether the components arrive aligned in time, interface and configuration. The connective work (interoperability, the data fabric, communications bearers, shared autonomy standards, inter-service responsibilities and command processes) would be at risk of fragmentation because no single authority owns the budgets, release decisions and delivery obligations needed to keep it aligned, and programme incentives pull against it. Joint assurance would be especially vulnerable to falling between multiple budget-holders. MOD would likely make visible progress on components and limited integration, yet the integrated whole that constitutes Centaur would likely be held in prolonged delay, the concept narrowed over time, partially fielded as separate components, or eventually terminated after substantial sunk cost. On its published remit, the Integration Design Authority advises, but does not own the budgets whose alignment integration requires, and an advisory body cannot compel a set of programmes to move together when their separate incentives pull them apart.
Recent autonomy programmes show that this outcome is not inevitable. The RN’s Rattler trials and the RAF’s StormShroud fielding demonstrate useful instincts: commercial technology, attritable systems, experimental units and faster routes outside the normal machinery. But they do not yet demonstrate a cross-service, cross-domain, autonomous kinetic and adaptive capability. They are evidence that the UK can field elements of Centaur. They are not yet evidence that it can field Centaur.
The decisive test arrives in service, and it is the one the governance bookshelf names but does not resolve. A learning or adaptive autonomous system cannot be accepted once and assumed to remain unchanged. It must be tested against an operating environment that shifts, adversaries that adapt, and software that may be altered repeatedly. A conventional platform is normally accepted against a defined configuration, with assurance revisited through controlled upgrades and modifications. A learning or frequently updated autonomous system weakens that assumption, because the system assured at one point may not be behaviourally identical to the system deployed a month later. For Centaur to work, assurance, operational release, airworthiness or equivalent platform approval, security accreditation, test access and configuration control would have to move together, at the tempo of the change, against an adversary altering its electronic-warfare and tactics on a similar cycle. Each of those functions today sits with a different authority, on a different timescale, through a different process. Unless they can be made to operate as one fast loop, the operational need to iterate in weeks will collide with institutions organised to validate change through separate and sequential routes, and the system will either freeze at its last assured state or drift ahead of its assurance. This is the acceptance problem set out in the governance section, encountered now as a delivery problem rather than a policy one, and it is the single hardest join in the whole concept.
The likely outcome is therefore programme failure with pockets of limited success inside it: useful platforms, data tools, demonstrators, and perhaps individual operational systems, an uncrewed sensor, an electronic-warfare platform, a limited AI fusion tool, a trialled maritime system, but not the integrated, persistent and rapidly adaptable Centaur capability initially envisaged. The contrast is instructive, with one distinction held firmly. The Israeli case is an intelligence achievement, and the vital part is not access alone but the analysis: continuous, high-volume AI-enabled processing of video that turns raw feeds into a targeting fix. Hacking cameras and processing the footage at nation-level volume may be the work of national intelligence, rather than fielded military systems. Assuming so, Centaur would consume such an intelligence feed as one of its external inputs. What the case shows about Centaur’s own integrating problem, though, is the same in kind: turning large, low-value sensor streams into a precise targeting result by fusing them fast with other intelligence around one objective. Where the UK risks fielding an AI fusion capability as an isolated tool, the Israeli system produced an integrated result precisely because one authority owned the connection of sensing, data, intelligence and effect. Ukraine and Israel show different ways of avoiding that outcome. Ukraine creates consequence through performance, demand and rapid feedback. Israel appears better able to connect technical development, operational users and mission need through a cohesive integrating layer. Neither model can simply be copied. Both show, however, that the binding problem is not autonomy itself. It is the institutional ability to turn autonomous components into adaptive combat power.
The question is therefore not whether the UK can acquire autonomous systems. It is whether it can organise acquisition, assurance, testing, industrial capacity and operational learning so that those systems become a coherent fighting capability before the threat has moved on.
Findings
Here we present specific judgements from our analysis.
Our analysis of the MOD’s historical acquisition record identifies that:
-
MOD would be unlikely to achieve the cross-domain integration Centaur requires without a delivery authority that owns the critical joins.
-
MOD would likely be able to create a series of impressive standalone demonstrators and platforms.
-
MOD is likely to face delays across multiple areas, blocking capability development on weaponised autonomous platforms.
-
MOD’s policy and governance apparatus likely to impose a “governance of governance” compliance burden, while being essentially reactive to on-the-ground advances.
-
MOD would likely face constraints in manufacturing capacity and volume economics that challenge the feasibility of cheap, attritable platforms.
-
MOD would likely face pressure to acquire US (and potentially Ukrainian or Israeli) autonomous capability over UK-developed and UK-produced capability.
Our comparative analysis of Ukrainian and Israeli wartime capability development has indicated the following areas for advancement, achievable outside wartime conditions:
-
Unified purpose, user as customer. Inspired by both Israel and Ukraine, MOD should exercise its power as sole customer to displace extractive incumbent suppliers unwilling or unable to join a revitalised, capable coalition. It should nurture a supply base built on success, excellence and track record, not on document-level bid compliance.
-
Competition is not duplication. MOD too often commits early to a single supplier for a capability, resulting in years locked into the relationship with little leverage to impose consequences when the supplier fails or underdelivers. Sustaining competition between two or more suppliers throughout a capability’s life, rather than awarding a single years-long monopoly contract, requires strong integration and sharp market engagement, but buys resilience, reduces dependence, creates incentives for through-life performance and sustains a stronger supply base. Both Ukraine and Israel embody this. Ukraine’s marketplace is the clearest form: success breeds demand and failure pushes a supplier out, continuously, so position is earned by current performance rather than held by an old contract. Israel sustains several primes alongside startups, universities and technical units within a directed ecosystem rather than creating dependency on a single national champion.
-
Capability as consumable. MOD must learn to treat some systems previously regarded as high-grade platforms as disposable, attritable and replaceable consumables. This means an emphasis on operator-repair rather than global supply and sustainment models where possible, with some systems treated as more RDEL than CDEL.[35] Being able to operate in the consumable cycle while still developing and sustaining advanced, exquisite systems would be a step forward.
-
A gate plus a fast channel. Ukraine’s answer to the quality-versus-speed tension was not to abolish its certification gate but to build a faster authorised channel alongside it. The same pattern applies to assurance: a way to keep standards without strangling tempo. This has similarities to MOD’s urgent operational requirement (UOR) process running alongside the formal CADMID/T process; this two-channel approach should be established as a mainstream idea, not an op-by-op exception.
-
Increased authority at the working level. Both Israel and Ukraine push decision authority down: Ukrainian units order directly from approved suppliers against demonstrated effect, and MAFAT secures and commits funds in days rather than years. Speed of capability comes less from new process than from delegating the decision and reusing proven components.
-
An empowered directorate that owns the loop, and selective sovereignty. Israel’s MAFAT is small, cohesive and owns the development loop and the integrating layer end to end; its independence is a deliberate portfolio of trades: buy what you cannot match, build what you can, concentrate national effort on the layers that compound. That is a direct answer to the pressure to buy foreign: the response is not sovereignty in everything, but a considered choice of where to be sovereign, anchored on the integrating layer. The newly established NAD group is the natural home for this integrating authority: the capability integrator with binding authority that Defence requires, and a critical enabler of future capability generation. Realising that opportunity will mean granting it genuine authority over the joins, and overcoming the institutional inertia that has slowed previous reforms; but the structure now exists to make integration someone’s explicit responsibility rather than a gap between programmes. It is too early to judge these reforms, and so early enough for this opportunity to be seized.
-
The user in the build, and talent as infrastructure. MOD should encourage and embrace the connections, relationships and shared experiences of its large “alumni” network, and use it to engage across the nation into education, industry and academia. Combined user–supplier–acquirer teams, with front-line users in the room, surrounded by a network of people with shared experiences and motivations and feeding into a broad talent pipeline, would establish institutional habits that enable high-trust, high-speed decision-making and action.
Conclusion
Our analysis is not a counsel of despair. The UK has conceptual thinking in place, backed up by practical experimentation and technology development across three services. Recent MOD efforts have demonstrated improved instincts for rapid development and fielding of unmanned and autonomous platforms. MOD operates from a highly capable command-and-legal base, and a genuine, if immature, body of AI policy. What remains is the arduous work of innovation, manufacturing and integration of real autonomous systems; building the supply base and enablers upon which they rest; and building the highly adaptive operating units to exploit them.
We encourage an embrace of more ground-up learning to catalyse rapid, incremental advances: not on single platforms or with handfuls of participants, but the larger, fleet-scale experimentation the RN has begun to model. Experimentation should be opened to innovative suppliers offering novel technology, selected for participation in long-running trials, incentivised by the prospect of substantial programmes but sustained by credible levels of R&D funding in the meantime. MOD should encourage sustained, patient investment in the early-stage companies that bring talent, commitment and drive to the sector, building an intellectual and advanced-technology base. It should explore ways to build ahead, in particular investing in the regional redevelopment of manufacturing skills, facilities and sites, to ensure the UK can build the technology it innovates.
Integration is not a residual activity to be traded away as programmes advance. It is the enabling condition that turns capable components into autonomous capability and is essential to delivering Centaur-like systems to the battlefield.
Britain’s challenge is not to purchase autonomous platforms or to write an ethics policy for them. It is to build a military system able to connect technology, people, law, logistics, authority and operational learning quickly enough that autonomy becomes combat power rather than another collection of impressive demonstrations. “From a nation of shopkeepers to a nation of drone-builders” might not be a bad slogan for building our future without the failures of the past.
References
-
British Army, The British Army’s Approach to Robotics and Autonomous Systems, 2022. https://www.army.mod.uk/media/15790/20220126_army-approach-to-ras_final.pdf
-
Royal Air Force, Autonomous Collaborative Platforms Strategy, 2024; and RAF, “StormShroud arrival marks the future of UK Air Combat Power,” 2 May 2025 (StormShroud, the RAF’s first Autonomous Collaborative Platform, entering operational service). https://www.raf.mod.uk/news/articles/stormshroud-arrival-marks-the-future-of-uk-air-combat-power/
-
Ministry of Defence, Strategic Defence Review 2025: Making Britain Safer, Secure at Home, Strong Abroad, June 2025; and Royal Navy statements on the hybrid fleet and Atlantic Bastion / Atlantic Strike / Atlantic Shield, 2025. https://www.gov.uk/government/publications/the-strategic-defence-review-2025-making-britain-safer-secure-at-home-strong-abroad
-
National Audit Office, The Equipment Plan 2023 to 2033, HC 315, Session 2023–24, December 2023, assessing the EP as unaffordable, with a reported funding shortfall of £16.9 billion; see also successive annual Equipment Plan affordability assessments. https://www.nao.org.uk/reports/equipment-plan-2023-to-2033/
-
Ministry of Defence, CADMID to CADMIR. https://www.gov.uk/government/publications/sustainable-circular-economics-for-defence-concept-note/sustainable-circular-economics-for-defence-concept-note—2#cadmid-to-cadmir
-
Ministry of Defence, Integrated Procurement Model: Driving pace in the delivery of Military Capability, policy paper, 28 February 2024. https://www.gov.uk/government/publications/integrated-procurement-model-driving-pace-in-the-delivery-of-military-capability
-
On the National Armaments Director Group (stood up 31 March 2025) and the wider reform: Ministry of Defence, “Major defence reforms launched, with new National Armaments Director to tackle waste and boost industry,” 2024, https://www.gov.uk/government/news/major-defence-reforms-launched-with-new-national-armaments-director-to-tackle-waste-and-boost-industry; and The Defence Industrial Strategy: Making Defence an Engine for Growth, 2025. On the Integration Design Authority specifically, and its advisory and assurance character: Ministry of Defence (Strategic Command), “The launch of the Integration Design Authority,” 2023, which describes the IDA as providing “Integration as a Service… advising and assuring project level requirements to deliver integrated effects,” https://www.gov.uk/government/news/the-launch-of-the-integration-design-authority; and Ministry of Defence, “Widespread reforms to transform delivery of kit to UK’s armed forces” (the Integrated Procurement Model), 28 February 2024, https://www.gov.uk/government/news/widespread-reforms-to-transform-delivery-of-kit-to-uks-armed-forces.
-
House of Commons Defence Committee scrutiny of the Watchkeeper programme; programme cancellation announced by the Ministry of Defence, 20 November 2024 (£1.35 billion, 54 WK450 air vehicles, eight crashes; out-of-service date subsequently extended to March 2027). Representative reporting: Army Technology, “Watchkeeper life ends in new wave of UK defence cuts,” 21 November 2024. https://www.army-technology.com/news/watchkeeper-life-ends-early-in-new-wave-of-uk-defence-cuts/
-
National Audit Office, The Ajax Programme, HC 1142, Session 2021–22, 11 March 2022 (£5.522 billion firm-price contract; £3.167 billion spent and 26 vehicles delivered at December 2021; noise-and-vibration trial suspensions); and Committee of Public Accounts, Armoured Vehicles: the Ajax Programme, Session 2022–23, June 2022. https://www.nao.org.uk/reports/the-ajax-programme/
-
Charles Haddon-Cave QC, The Nimrod Review: An Independent Review into the Broader Issues Surrounding the Loss of the RAF Nimrod MR2 Aircraft XV230 in Afghanistan in 2006, HC 1025, 28 October 2009; the Nimrod MRA4 maritime patrol aircraft was cancelled in 2010 after roughly 14 years and more than £3 billion. https://www.gov.uk/government/publications/the-nimrod-review. On the cancellation of the Nimrod MRA4 in 2010 after a fourteen-year procurement history and expenditure exceeding £3.4 billion, see National Audit Office, Ministry of Defence: The Major Projects Report 2011, HC 1520-I, Session 2010–12, https://www.nao.org.uk/wp-content/uploads/2011/11/10121520-I.pdf.
-
Royal Navy, “Flotilla of uncrewed boats shadows warships in milestone Royal Navy trials,” October 2025; the Rattler USVs were developed by SYOS Aerospace with the Disruptive Capabilities and Technology Office and the Fleet Experimentation Squadron. Representative reporting: USNI News, “Royal Navy Puts Rattler Unmanned Surface Vessels to the Test,” 6 November 2025. https://news.usni.org/2025/11/06/royal-navy-puts-rattler-unmanned-surface-vessels-to-the-test
-
On Ukrainian drone production volumes and the certification of drone types: approximately 2.2 million UAVs of various types produced in 2024 (against an initial target of around 1 million), with output projected to exceed 4.5 million in 2025, of which over 2 million FPV drones. OSW Centre for Eastern Studies, “Game of Drones: the Production and Use of Ukrainian Battlefield Unmanned Aerial Vehicles,” 14 October 2025, https://www.osw.waw.pl/en/publikacje/osw-commentary/2025-10-14/game-drones-production-and-use-ukrainian-battlefield-unmanned. The same commentary records that Ukrainian units were operating more than 250 different UAV models, and that regulations introduced in December 2024 required suppliers to obtain certification against defined technical standards, which extended procurement timelines and made purchases conditional on possession of the required documentation, with attendant corruption risk. The 2.2 million 2024 figure is attributed to President Zelensky (see also Forbes, “4.5 Million Drones Is A Lot Of Drones,” 12 March 2025). On the 2025 FPV procurement plan specifically, see Dan Peleschuk and Anastasiia Malenko, “Ukraine to Sharply Raise Purchases of Home-Produced FPV Drones in 2025,” Reuters, 10 March 2025, reporting a Ministry of Defence plan to purchase around 4.5 million FPV drones during 2025. On the state-run marketplace through which these volumes are procured, see reference 13.
-
Ukraine’s state-built defence-technology marketplace: the Brave1 cluster (Ministry of Digital Transformation) and the DOT-Chain Defence system operated by the Defence Procurement Agency (DOT), under which front-line units select equipment and the agency handles contracting, payment and delivery, with a reported average order-to-delivery time of around nine days. Ministry of Defence of Ukraine statements, Ministry of Defence of Ukraine, “95% of Drones Procured for the Defence Forces are Ukrainian-Made,” 2026, which records an average order-to-delivery time of nine days and 485,000 UAVs and other items delivered through DOT-Chain Defence in the first five months of 2026, https://mod.gov.ua/en/news/95-of-drones-procured-for-the-defence-forces-are-ukrainian-made; and Maria Varenikova, reporting on Ukraine’s drone marketplace for The New York Times, 2026. See also the Brave1 portal, https://brave1.gov.ua/.
-
National Anti-Corruption Bureau of Ukraine (NABU) and the Specialised Anti-Corruption Prosecutor’s Office (SAPO), charges announced 2 August 2025 over a scheme to procure drones and electronic-warfare systems at deliberately inflated prices, with kickbacks of up to 30% of contract value; six people charged, including a sitting lawmaker. Reuters, “Ukraine charges six people, including lawmaker, in drone procurement scheme,” 2 August 2025, https://www.reuters.com/business/aerospace-defense/ukraine-says-it-uncovers-major-drone-procurement-corruption-scheme-2025-08-02/; and CNN, “Ukraine says it uncovers major drone procurement corruption scheme,” 2 August 2025, https://www.cnn.com/2025/08/02/europe/ukraine-corruption-drone-scheme-latam-intl.
-
Reporting on the July 2025 legislation curbing the independence of NABU and SAPO, the resulting protests (the largest since the 2022 invasion) and EU accession concerns, and the parliament’s 31 July 2025 reversal restoring the agencies’ independence. The Kyiv Independent, August 2025, https://kyivindependent.com/ukraines-anti-corruption-agencies-uncover-bribery-scheme-involving-lawmaker-officials-soldiers/; and contemporaneous Reuters and CNN reporting.
-
On Ukraine’s operator-repair and consumable-capability model for attritable systems, and its contrast with the Western through-life support model: on front-line and operator-level repair, mobile repair workshops and reduced reliance on external suppliers, see Modern War Institute, “Innovating Under Fire: Lessons from Ukraine’s Frontline Drone Workshops,” 25 March 2025, https://mwi.westpoint.edu/innovating-under-fire-lessons-from-ukraines-frontline-drone-workshops/. See also the production and procurement reporting at references 12, 13, 17 and 18.
-
On Ukrainian defence-industrial localisation and the reduction of reliance on Chinese components. Most drones used by Ukrainian forces in the first year of the full-scale invasion relied almost entirely on Chinese-made components; by 2025 the share of Chinese parts had fallen to about 38%, on data from the Ukrainian Council of Defense Industry and the Snake Island Institute cited in the reporting below. By early 2026 Ukraine reported assembling drones with no Chinese-sourced components in specific product lines, with domestic production of flight controllers, radio modems and video-transmission systems; localisation as assessed by the Lviv-based IRON defence-technology cluster stood at roughly 85% for frames and structural components but only about 14% for cameras and 12% for engines, indicating that dependence persists in the most advanced subsystems. Kyiv Post, “Ukraine Cuts Reliance on Chinese Drone Components,” 11 March 2026, https://www.kyivpost.com/post/71701; and, for the IRON cluster localisation figures, Yuriy Gorodnichenko, Viktor Koziuk and Ilona Sologoub, “Inside Ukraine’s Game-Changing Drone Industry,” Project Syndicate, carried in the Taipei Times, 12 July 2026, https://www.taipeitimes.com/News/editorials/archives/2026/07/12/2003860601.
-
On Ukraine’s procurement reform and the DOT-Chain Defence marketplace as a faster, data-driven channel. Operated by the Defence Procurement Agency (into which the State Logistics Operator was merged on 1 January 2026), the platform lets front-line units select equipment directly, with the agency handling contracting, payment and delivery; procurement is weighted toward demonstrated combat effectiveness, and the reform established a funding model allocating roughly 80% of spending to systems with proven operational effectiveness and 20% to testing new technologies. The share of drones procured through the platform has risen from about 7% of FPV drones in 2025, with the Ministry of Defence targeting up to 70% of drone procurement, and “conventional” purchases now monitored against DOT-Chain data to flag orders of models the front does not want. Ukrainska Pravda, “Less Corruption, More Competition: How Ukraine Is Building a Digital Arms Procurement System Now Being Adopted by NATO,” 1 May 2026, https://www.pravda.com.ua/eng/articles/2026/05/01/8032647/; on the DPA/DOT merger and the digitisation of the procurement flow, Janes, “Ukraine Showcases New Procurement System with UAV Acquisition Changes,” 2026, https://www.janes.com/defence-intelligence-insights/defence-news/air/ukraine-showcases-new-procurement-system-with-uav-acquisition-changes. On the 80/20 funding split and delivery volumes through the platform, see also The Defense Post, “Ukraine Receives Nearly Half a Million Drones, 95% Sourced Domestically,” 23 June 2026, https://thedefensepost.com/2026/06/23/ukraine-half-million-drones/.
-
Israel Ministry of Defense, Directorate of Defense Research and Development (DDR&D, known by its Hebrew acronym MAFAT): institutional overview, including its role bridging the IDF, academia, established defence industries and startups, and its place alongside other MAFAT directorates such as the Merkava and Armored Vehicle Directorate and the “Homa” Missile Defense Directorate. Yaakov Lappin and others, “Israel’s defense-tech revolution: How MAFAT is shaping the evolution of Israeli warfare,” The Jerusalem Post, December 2025, https://www.jpost.com/defense-and-tech/article-881440; and Israel Defense, “Israel’s Ministry of Defense and IDF Launch New Directorate for AI and Autonomy,” January 2025, https://www.israeldefense.co.il/en/node/63986.
-
Israel Ministry of Defense, AI and Autonomy Administration, inaugurated 31 December 2024 and announced 1 January 2025, operating under the DDR&D (MAFAT) and bringing together IDF technological units, academia, defence industries and startups; described by IMOD Director General Maj. Gen. (Res.) Eyal Zamir as the IMOD’s first new administration in over two decades, with Head of DDR&D Brig. Gen. (Ret.) Dr Daniel Gold setting its mission. Israeli Ministry of Defense announcement, reported in “Israeli MoD establishes AI and Autonomy Administration,” European Security & Defence, 6 January 2025, https://euro-sd.com/2025/01/major-news/41924/imod-ai-and-autonomy-admin/; and Janes, “Israel’s Ministry of Defense creates AI and Autonomy Administration,” January 2025.
-
On Brig. Gen. (Res.) Dr Daniel (“Danny”) Gold, head of MAFAT, the development of Iron Dome over institutional resistance, and the directorate’s speed of decision: reporting and interviews including The Jerusalem Post, “Israel’s defense-tech revolution: How MAFAT is shaping the evolution of Israeli warfare,” December 2025, https://www.jpost.com/defense-and-tech/article-881440. The characterisation of decision speed (“we got the funding in two days”) is drawn from Anna Ahronheim, “Israel’s MAFAT Head on US Iron Dome Fears: We Trust Our American Friends,” The Jerusalem Post, 30 September 2021, https://www.jpost.com/israel-news/israels-mafat-head-on-us-iron-dome-fears-we-trust-our-american-friends-680604.
-
Elbit Systems, “Elbit Systems Secures Over $100 Million in Contracts to Advance Digital Warfare and Border Defense Capabilities for the Israel Ministry of Defense,” February 2026, stating that the fifth-generation IDF digitisation array (the “Tzayad” Next Generation Digital Ground Army programme) is “carried out through joint development teams comprising Elbit Systems, DDR&D at the Ministry of Defense, and the IDF Ground Forces.” https://www.elbitsystems.com/news/elbit-systems-secures-over-100-million-contracts-advance-digital-warfare-and-border-defense. See also, for the roughly $40 million in December 2024 DDR&D–Elbit drone and autonomous-system contracts, Janes, “Israel’s Ministry of Defense creates AI and Autonomy Administration,” January 2025.
-
On the IDF’s elite technical units (including Unit 8200, Talpiot and Unit 81) and the conscription-based technical-talent pipeline that feeds Israel’s defence-technology ecosystem, with the army effectively performing the role universities such as Stanford or MIT play elsewhere: Sophie Shulman, “Israel’s elite military units built a tech powerhouse. Now the state wants a share,” Calcalist (CTech), 27 May 2026, which records that the role played in the United States by universities such as Stanford or MIT is in Israel effectively played by the army, https://www.calcalistech.com/ctechnews/article/rypq9w4lmx. See also Israel Defense, “The Impact of IDF’s Elite Tech Unit on the Israeli Ecosystem’s Development,” 2 April 2025; and The Jerusalem Post, December 2025, https://www.jpost.com/defense-and-tech/article-881440. On Talpiot specifically, MAFAT’s oldest elite programme, established in 1979 after the 1973 Yom Kippur War exposed a gap between research and development and operations in the field, and on the pipeline as national infrastructure (MAFAT’s Military R&D head: “everything starts with human capital”), see Dean Shmuel Elmas, “Study: IDF Talpiot Program Excels in Producing Entrepreneurs,” The Jerusalem Post / Globes, 24 April 2026, https://www.jpost.com/defense-and-tech/article-894053.
-
Reporting on Operation Rising Lion, Israel’s strikes on Iran beginning 13 June 2025, including the smuggling and pre-positioning of explosive drones and precision weapons inside Iran ahead of the air campaign: Nectar Gan and others, “Netanyahu says Israel launched Operation Rising Lion,” CNN, 13 June 2025, https://www.cnn.com/2025/06/12/middleeast/israel-iran-strikes-intl-hnk; and, for the operational analysis, Center for Strategic and International Studies, “Ungentlemanly Robots: Israel’s Operation Rising Lion and the New Way of War,” 2025, https://www.csis.org/analysis/ungentlemanly-robots-israels-operation-rising-lion-and-new-way-war.
-
Reporting on the coordinated US-Israeli strikes of 28 February 2026 (Israel’s Operation Roaring Lion and the US Operation Epic Fury) and the death of Supreme Leader Ali Khamenei: NPR, “Iran’s supreme leader, Ayatollah Ali Khamenei, has been killed,” 28 February 2026, https://www.npr.org/2026/02/28/nx-s1-5730158/israel-iran-strikes-trump-us. On the intelligence preparation, including the hacking of Tehran’s traffic cameras over a period of years with their images encrypted and transmitted to servers in Israel, the building of a pattern of life around Khamenei and his security detail, and the fusion of Unit 8200 signals intelligence, Mossad human assets and social network analysis across billions of data points, see Mehul Srivastava, James Shotter, Neri Zilber and Steff Chávez, “Inside the Plan to Kill Ali Khamenei,” Financial Times, 2 March 2026, https://www.ft.com/content/bf998c69-ab46-4fa3-aae4-8f18f7387836. On the underlying capability, the use of artificial intelligence to parse millions of hours of video collected by thousands of cameras in order to find and surveil targets, including language-based search over video and the isolation of behavioural patterns rather than objects, see Mehul Srivastava and Christopher Miller, “New AI Espionage Powers Trigger Putin Camera Scare,” Financial Times, 7 June 2026, https://www.ft.com/content/6f4d806c-eb22-4c32-8352-b82692d30e9f.
-
US security assistance to Israel under the 2016 ten-year Memorandum of Understanding (fiscal years 2019–2028): $3.8 billion per year, comprising $3.3 billion in Foreign Military Financing and $500 million for missile defence, with FMF required to be spent on US defence products (phasing to 100% by FY2027) and historically about 20% of Israel’s defence budget. US Department of State, “Ten-Year Memorandum of Understanding Between the United States and Israel,” 2016; Council on Foreign Relations, “U.S. Aid to Israel in Four Charts,” October 2025, https://www.cfr.org/articles/us-aid-israel-four-charts; and Israel Policy Forum, “U.S. Security Assistance and the Israeli Budget,” May 2026.
-
Israel’s defence-indigenisation initiative announced December 2025: some NIS 350 billion over a decade to strengthen the domestic arms industry, prompted by wartime difficulty procuring munitions and interceptors (from artillery shells to Iron Dome’s Tamir interceptors) largely sourced from abroad. Israel Policy Forum, “U.S. Security Assistance and the Israeli Budget,” May 2026, https://israelpolicyforum.org/2026/05/11/u-s-security-assistance-and-the-israeli-budget/.
-
Ministry of Defence, Ambitious, Safe, Responsible: Our Approach to the Delivery of AI-enabled Capability in Defence, June 2022. https://www.gov.uk/government/publications/ambitious-safe-responsible-our-approach-to-the-delivery-of-ai-enabled-capability-in-defence
-
Ministry of Defence, JSP 936: Dependable Artificial Intelligence (AI) in Defence (Part 1: Directive), Version 1.1, November 2024. https://www.gov.uk/government/publications/jsp-936-dependable-artificial-intelligence-ai-in-defence-part-1-directive
-
Ministry of Defence, Defence Artificial Intelligence Playbook, 2024. https://www.gov.uk/government/publications/defence-artificial-intelligence-ai-playbook
-
Ministry of Defence, Laying the Groundwork: Responsible AI Senior Officers’ Report 2025, October 2025. https://www.gov.uk/government/publications/laying-the-groundwork-responsible-ai-senior-officers-report-2025
-
Ministry of Defence, The Manual of the Law of Armed Conflict (JSP 383), Joint Service Publication 383. https://www.gov.uk/government/collections/jsp-383
-
International Maritime Organization, Convention on the International Regulations for Preventing Collisions at Sea (COLREGs), 1972 (as amended), and the non-mandatory International Code of Safety for Maritime Autonomous Surface Ships (MASS Code), adopted at Maritime Safety Committee MSC 111, May 2026; and Maritime UK / UK Maritime Autonomous Systems Regulatory Working Group, Maritime Autonomous Surface Ships: UK Industry Conduct Principles and Code of Practice (Version 8, 2025). https://www.gov.uk/government/news/global-cooperation-brings-breakthrough-on-first-international-maritime-autonomous-surface-ships-mass-code
-
House of Commons Defence Committee, Developing AI Capacity and Expertise in UK Defence, Second Report of Session 2024–25, HC 590, 10 January 2025. https://committees.parliament.uk/publications/46217/documents/231330/default/
-
HM Government / Ministry of Defence, MOD Departmental Resources 2025, 2025, for the distinction between resource (RDEL) and capital (CDEL) departmental expenditure limits. https://www.gov.uk/government/statistics/defence-departmental-resources-2025/mod-departmental-resources-2025
Annex A: Acquisition comparative analysis grid
This annex presents the detailed assessment data as the core evidence base for the study. A single notional Centaur is “stepped through” MOD’s standard major-programme acquisition lifecycle (CADMID/T: Concept, Assessment, Demonstration, Manufacture, In-Service, Disposal/Termination, with Initial and Main Gates).
The UK lifecycle is the focus of our analysis, against which our models of the Ukrainian and Israeli approaches are compared. Differences in approach are captured either as things the comparators do not do (“no equivalent” entries) or as new rows representing things they do but MOD does not. The core of the analysis is the “UK most plausible move” column, which presents our central judgement on what we would expect from our baseline MOD model.
Claims are tagged for what they rest on: [O] Observed in the public record; [I] Inference from a specific historical case; [P] Proposition, our judgement on the overall record; [C] Close call, finely split.
Concept
| Step | UK most plausible move | Ukraine / Israel | Judgement |
|---|---|---|---|
| Recognise the need | Top-down requirement-setting frames a Centaur-scale system less readily than bottom-up routes frame component needs. | Ukraine pulls individual capabilities into being from front-line demand; Israel coheres around priority missions. | The need is not in doubt; framing a unified, Centaur-scale requirement is the weaker point. [O] need recognised; [C] how the system requirement is framed. |
| Buy or build | A genuine buy-US-versus-build-sovereign fork, on which neither path alone builds the development capability of interest. | Ukraine builds from components; Israel makes deliberate domain-by-domain sovereignty trades. | [C] the UK fork by design; [O] comparator approaches; [P] neither UK path alone suffices. |
| Initial Gate | A real decision point that can slow or stop a programme; whether reform makes it faster is unproven. | No equivalent formal gate. | [O] the gate; [C] the reform effect. |
Assessment
| Step | UK most plausible move | Ukraine / Israel | Judgement |
|---|---|---|---|
| Cost the programme | MOD models cost as a range, but the EP still requires an annualised figure against a fixed budget, so the range is collapsed to a budgetable point that can harden into a commitment before uncertainty is retired; assurance compliance is one area especially exposed to under-booking. | Neither comparator appears to rely on an equivalent early annualised whole-life planning figure in the channels considered. | [O] ranges modelled yet an annualised figure required; [P] it hardens into commitment and under-books the compliance line. |
| Set the requirement | Deepest risk is specifying against a threat that will have moved by fielding; lighter iterative requirements are right in principle but the incentives driving over-specification are reported untouched. | Ukraine re-specifies continuously against current combat; Israel revises around the operational need. | [O] record and requirement; [C] whether reform lightens the burden. |
| Engage the market | A concentrated supplier base; assurance overhead plausibly compounds it by favouring incumbents able to carry the compliance load. | Ukraine draws on a broad, churning supplier ecosystem; Israel couples a few primes to startups and units. | [O] market structure; [P] incumbency-favouring effect; [C] whether reform overcomes it. |
| Main Gate | Both a major decision and a major delay point; its demand for early high confidence rewards optimism bias and over-specification. | No equivalent single investment gate. | [O] structure; [I] optimism-bias effect; [C] the reform. |
Demonstration
| Step | UK most plausible move | Ukraine / Israel | Judgement |
|---|---|---|---|
| Fund through demonstration | Weak penalty for non-delivery plus annual budgeting work against the multi-year stability iteration needs. | Ukraine funds against demonstrated effect; Israel sustains priority programmes through one authority. | [O] record; [C] whether the 10-year plan changes incentives or restructures them. |
| Integrate the system | The UK most plausibly decomposes Centaur into separately governed programmes, leaving the integrated whole the part most likely to be deferred (the Integration Design Authority advises but does not own). | Israel achieves mission-level coherence by close coupling; Ukraine by bottom-up, domain-specific integration. | [O] the cases; [P] the decomposition mechanism applied to Centaur; [C] whether the IDA changes the outcome. |
| Assure the AI element | Necessary assurance, with likely drag when the obligation lands across dispersed programmes, authorities and release routes. | Israel’s close coupling can narrow the separation between development, test, use and revision; equivalence to the UK regime at Centaur scale is not established. | [O] the regime; [P] the drag and the institution-shaped reading. |
Manufacture
| Step | UK most plausible move | Ukraine / Israel | Judgement |
|---|---|---|---|
| Prove against the threat | The UK can and does conduct live fire, with sovereign ranges and Ukrainian red-teaming available; the gap is the frequency, resourcing and exploitation of these for armed-autonomous proving against an adapting adversary, not the absence of facilities. | Ukraine proves continuously under combat; Israel proves against live operational use. | [O] estate, exercises, red-teaming; [P] the constraint is institutional, not physical. |
| Certify for service | Certifying a learning autonomous system across several domain authorities is one of the most consequential collisions with the iterate-in-weeks ambition. | Ukraine’s answer, a faster authorised channel built alongside its certification gate rather than in place of it, is the single most instructive data point for keeping assurance without freezing iteration. | [O] the requirements and Ukraine’s channel; [C] the exact scope of Ukraine’s gate. |
| Produce at volume | Real high-end production capacity, but not the dispersed, high-throughput base for attritable mass. | Ukraine has built exactly that base; Israel is now building toward it. | [O] the UK base and Ukraine’s volume; [I] the attritable-mass gap. |
In-service
| Step | UK most plausible move | Ukraine / Israel | Judgement |
|---|---|---|---|
| Bring into use | Controlled introduction has historically meant slow first use. | Ukraine fields straight to the front; Israel fields fast around the mission. | [O] the practice; [C] whether a minimum-deployable-capability approach accelerates it. |
| Iterate in service | Continuing-assurance obligations plausibly slow iteration unless assurance, release authority, testing and configuration control run at the tempo of software and operational adaptation: the central reform-versus-governance tension, and the inverse of Ukraine’s core advantage. | Ukraine iterates continuously; Israel revises rapidly through the owning authority. | [P]; weight against other iteration constraints unresolved. |
| Sustain | Whole-life support fits the enduring parts of Centaur (command, data, sensing) but works against the attritable parts that need replacing rather than sustaining; the assurance burden recurs across the whole life. | Ukraine replaces rather than sustains; Israel mixes both by design. | [O] the model and requirement; [P] the enduring-versus-attritable fit. |
Disposal / termination
| Step | UK most plausible move | Ukraine / Israel | Judgement |
|---|---|---|---|
| Terminate or dispose | The termination record (large sunk cost booked late, weak consequence) is the disposal-stage face of the delivery problem; for Centaur the risk is a multibillion-pound termination after years. | The attritable-drone logic that makes disposal a non-issue for Ukraine does not transfer to a high-value integrated system. | [O] the UK termination instances; [I] the comparator handling. |
Cross-cutting (outside the lifecycle model)
| Theme | UK most plausible move | Ukraine / Israel | Judgement |
|---|---|---|---|
| Consequence for non-delivery | Observed consequences have not consistently altered supplier, programme or institutional behaviour; consequence is inconsistent rather than absent, and the AI regime adds assurance accountability, not delivery accountability. | Ukraine’s selection imposes consequence directly; Israel’s central authority carries it. | [I] the deepest structural finding; [C] the reform’s effect on behaviour. |
| Sustained competition and reallocation of demand | Tends to commit to a single supplier early, then has no standing way to sustain competitive pressure or move demand to a better performer once committed. | Ukraine runs continuous competition through its marketplace, where demand follows current performance; Israel keeps several primes and startups in play around its directorate. | [O] for the comparators; [I] the UK early-monopoly tendency and the absence of a through-life competitive mechanism. |
| Push through a lifecycle vs pull toward a mission | Standing machinery treats Centaur as something to push through a lifecycle; pulling capability toward an immediate need is exceptional (the Urgent Operational Requirement). | Pulling toward a mission is routine for both comparators. | [O] the UK exceptional route and comparator practice; [I] a durable difference in mode. |
What the grid shows. Centaur will not fail because the UK cannot buy a platform, write a policy, run a trial, or generate a piece of assurance evidence; the record shows it can do each. The binding constraints cluster at the joins: framing a system rather than component requirement; holding cost uncertainty open instead of collapsing it to an early commitment; integrating a whole that is decomposed into separately governed programmes; certifying and then re-certifying a learning system at the tempo its iteration needs; producing attritable mass; and imposing consequence for non-delivery. These are the points the comparators handle differently (Ukraine through front-line selection and a fast channel beside its gate, Israel through one authority owning the integrating layer), and they are where the paper’s recommendations apply.