VERIK / V003 / 17 APR 2026
DronesDefense

America's Drone Strategy Has a Governance Problem Too

A recent Iron Triangle column in The Cipher Brief described the Drone Dominance Program's supply chain as a structure built on Chinese components and patriotic press releases. The diagnosis is correct as far as it goes. While the Pentagon fixates on the hardware supply chain (neodymium, flight controllers, brushless motors) it is ignoring a dependency just as dangerous, and far less visible: the governance infrastructure for the autonomous systems those drones are becoming.

The airframes on order are not just drones. They are autonomous decision-making agents. No sovereign infrastructure currently exists to prove those agents acted within the authority a commander assigned them.

From Ammunition to Autonomy

The column correctly identifies that reclassifying drones as Class V ammunition represents a philosophical shift from quality to mass. The deeper shift is not about quantity. It is about cognition. The same Drone Dominance Program that demands 150,000 airframes by Phase IV also demands Automatic Target Recognition, electronic warfare resilience, and fiber-optic tethering for autonomous operations. These are not features of ammunition. They are features of autonomous agents, systems that perceive, decide, and act with diminishing human involvement at each generation.

The Small Wars Journal recently published a maturity framework for disciplined autonomy in sUAS that makes the trajectory explicit: by 2035, "humans define intent; AI executes." The OODA loop does not just compress. It delegates. And once lethal authority is delegated to machines, the question is no longer "did the program build enough drones?" but "can it prove each one acted within the scope of authority a commander assigned?"

Right now, the honest answer is no.

The Accountability Gap Is Already Here

International humanitarian law requires distinction, proportionality, and precaution. These principles assume a human making a decision. When an AI system selects and engages a target, current legal frameworks cannot reliably attribute responsibility to any specific person, not the programmer, not the operator, not the commander. The Lieber Institute at West Point calls this the accountability gap, and over 120 countries have endorsed negotiations toward an international treaty on autonomous weapons systems precisely because the gap is widening faster than law can follow.

The accountability gap is not only a legal abstraction. It is an engineering problem. And the engineering community's current answer, audit logs, is dangerously insufficient.

Audit logs are mutable, after-the-fact records generated by the system they are supposed to monitor. In adversarial scenarios, they become contested artifacts. Salt Typhoon demonstrated that even tier-one carriers' internal logging infrastructure can be silently compromised for years. If a state-level adversary can live inside telecommunications systems undetected, what confidence should a commander have that the action logs of an autonomous weapons system were not tampered with between the moment of engagement and the moment of review?

The Pentagon's answer, as of February 2026, is to ask AI vendors to promise they will behave. The Anthropic-DoD dispute showed exactly how well that works. When the Department of Defense demanded unrestricted "any lawful use" language that could permit lethal targeting without meaningful human authorization, Anthropic walked away. OpenAI rushed to fill the gap in what its own former robotics lead described as a deal where "the policy guardrails were not sufficiently defined." Meanwhile, DoD Directive 3000.09, the governing policy for autonomy in weapons systems, has produced no public evidence of how many autonomous systems have been reviewed under its framework.

Contractual guardrails are not governance. A promise from a vendor is not proof of compliance. And an audit log from the system that executed the strike is not evidence that the strike was authorized.

The Missing Infrastructure Layer

NIST recognized this gap in February when it launched the AI Agent Standards Initiative, the most consequential federal action yet on autonomous AI governance. The quiet message beneath the press release is significant: autonomous AI systems present identity, authorization, and security challenges that existing frameworks were not built to handle. NIST is signaling that agent identity, authorization scoping, and activity verification will transition from technical best practices to compliance obligations.

NIST is describing the problem, not building the infrastructure. The actual requirement, and the strategic vulnerability, is a mechanism that produces independent, tamper-evident proof that an autonomous agent acted within its authorized scope at the moment of action. Not a log reviewed after the fact. Not a vendor's contractual promise. Not a periodic audit that says a control was operating over a six-month window. Proof. At the moment of decision. Signed cryptographically. Verifiable by any authorized party without trusting the system that generated it.

This is the governance equivalent of what the column calls "picks and shovels." The drone attracts the funding. The evidence infrastructure that makes the drone's actions legally defensible, operationally accountable, and strategically auditable does not.

A Supply Chain Problem by Another Name

The parallel to the column's hardware argument is almost structural. Just as 150,000 NDAA-compliant airframes cannot be manufactured because domestic rare-earth processing was surrendered, 150,000 autonomous agents cannot be governed because the governance infrastructure was never built. The hardware supply chain is throttled by neodymium bottlenecks and patriotic red tape. The governance supply chain does not exist.

Just as waiving NDAA compliance on hardware components would fund Chinese manufacturing at the expense of domestic industrial capacity, cutting corners on governance infrastructure would create systems that cannot be audited, cannot be defended in legal proceedings, and cannot produce the evidence that international humanitarian law requires when lethal decisions are delegated to machines.

The CNSA 2.0 timeline sharpens the constraint. NSA mandates that all national security systems must support post-quantum cryptographic algorithms by 2027 and complete migration by 2035. Every governance record, every authorization proof, every chain-of-custody artifact for autonomous weapons systems that is signed with classical cryptography today has an expiration date. Classical-signature records produced now face a specific structural risk: adversaries with sufficient quantum computing resources will eventually be able to forge or repudiate those records. The evidentiary foundation of accountability collapses retroactively.

Quantum-safe governance infrastructure is not a nice-to-have. It is a precondition for any autonomous system whose actions may be subject to legal review in 2040 or 2050, which is to say, all of them.

The Willow Run Precedent

During World War II, Ford did not just build B-24s at Willow Run. Every aircraft had a paper trail, inspection records, quality certificates, chain-of-custody documentation, that proved it was built to specification. The evidence infrastructure existed alongside the production infrastructure because nobody would put a crew in an unverified bomber.

The Drone Dominance Program is on track to field autonomous systems that make lethal decisions without a crew onboard. The evidentiary case for governance infrastructure is not weaker. It is stronger. The parallel that does not hold is the one that matters: the Willow Run production line came online with the paper trail already in place. The autonomous system line is coming online without one.

What Remains on the Table

The Phase 1 observation is that the Drone Dominance Program's supply chain review has focused on components and skipped the evidence layer. What remains open:

Every step in the current review chain assumes that the layer producing governance evidence is trustworthy. Salt Typhoon demonstrated in telecommunications what that assumption is worth against a state-level adversary. The pattern generalizes.

The governance artifact is retained. The governance function is not.