NSPM-11 AI Compliance for Defense Contractors: 2026 Guide
National Security Presidential Memorandum 11 (NSPM-11), signed June 5, 2026, created binding AI security and contract compliance obligations for every company in the defense industrial base that builds, supplies, or operates AI systems for national security missions. NSPM-11 does not replace CMMC. It overlays four distinct AI compliance tracks on top of existing CMMC, NIST, and DFARS requirements, and a single program that misses the intersection can trigger termination for cause under a new "pattern of conduct" authority.
This guide explains what NSPM-11 actually requires, how it intersects with CMMC and the FY2026 NDAA, what the DoDD 3000.09 revision means for autonomous systems programs, and gives program managers and CISOs a concrete 30-60-90 day action plan.
Key Takeaways
- NSPM-11 creates four contractor obligations: AI system control clauses, supply chain vetting, conduct-based contract termination triggers, and training mandates.
- DoD suspended CMMC Phase 2 third-party assessments on July 13, 2026, but underlying NIST 800-171 controls remain in force. The suspension is a grace window, not a waiver.
- The FY2026 NDAA Section 1513 AI/ML framework is the most likely enforcement vehicle for NSPM-11's security obligations, flowing through DFARS and CMMC updates.
- DoDD 3000.09's 90-day revision deadline (around September 3, 2026) sets new test, evaluation, verification, and validation requirements for autonomous systems programs.
- False Claims Act exposure is real: federal AI contract value grew from $356 million (FY2022) to $4.6 billion (FY2023), and misrepresentation of AI system integrity or compliance certifications creates qui tam liability.
- The National Security AI Council's 120-day deadlines (around October 3, 2026) trigger multi-vendor onboarding process updates across DoD, IC, and DHS that affect how contractors propose and price AI solutions.
What NSPM-11 Is: Four Pillars for CISOs and Program Managers
NSPM-11 rescinds the Biden-era NSM-25 and reorganizes national security AI policy around four named pillars:
Adoption. The national security enterprise must identify where AI can enhance operational effectiveness and remove procurement barriers. The memo directs "deep, proactive partnerships with industry" to ensure the government can rapidly access frontier models from multiple vendors simultaneously, ending single-vendor dependency.
Adaptation. Agencies must integrate commercial and open-source AI from multiple suppliers and share solutions across classification levels. This pillar drives the 120-day deadline for updating multi-vendor onboarding procurement processes.
Assurance. All adopted AI must be reliable, controllable, steerable, and fault-resistant. NSPM-11 explicitly defines "controllability" as the ability to monitor a system's operation and outcomes and take corrective action as needed. Section 4(c) names protection against malicious distillation attacks as a required security posture, reflecting research showing malicious behavior can be embedded directly into a model's computational graph and bypass conventional security scans.
Accountability. No commercial entity may prevent use of, disable, degrade, or materially modify an AI system "without Federal Government knowledge and approval." This pillar contains the contract termination authority and the control clause obligations that create direct risk exposure for contractors.
The DoD FY2026 AI budget of $13.4 billion, the largest single-year U.S. defense AI investment in history, gives these pillars substantial financial gravity.
What Changed from NSM-25
NSM-25 emphasized governance-first procurement, embedded bias-mitigation conditions, and tolerated single-vendor AI dependencies. NSPM-11 takes a speed-over-caution posture. The shift matters for contractors in three specific ways.
First, the prohibition on single-vendor dependencies means proposal strategies that relied on locking government customers into a proprietary AI stack are now contract risks, not competitive advantages. Proposals should demonstrate multi-vendor interoperability.
Second, NSM-25 required AI adoption to protect "human rights, civil rights, civil liberties, privacy, and safety" as structural conditions. NSPM-11 replaces that with explicit prohibitions against AI that censors speech, embeds ideological bias, or enables unauthorized surveillance. The legal exposure is now about conduct, not process.
Third, NSM-25 had no explicit contract termination authority tied to a vendor's corporate behavior outside the contract. NSPM-11 Section 3(b) does.
The White House fact sheet characterized NSM-25 as having "burdened American AI adoption with ideological mandates and fostered dangerous single-vendor dependencies."
The Four Contractor Obligations in Plain English
1. AI System Control Clauses
Section 3(b) requires, "through contractual clauses or other means," that no commercial entity possesses the capability to prevent use of, disable or degrade, or materially modify without federal government knowledge and approval any AI system government personnel depend on for missions. This is not aspirational policy. It is already live in the classified-network AI agreements DoD signed with eight vendors in May 2026: SpaceX, OpenAI, Google, Nvidia, Reflection, Microsoft, Amazon Web Services, and Oracle.
For prime contractors, this creates a flow-down obligation. The AI model provider, fine-tuning shop, or AI infrastructure subcontractor upstream of the delivered system must contractually agree to the same terms. Assessing whether your upstream model providers will sign these clauses before the solicitation drops is a pre-award risk item, not a post-award cleanup task.
2. Supply Chain Vetting
The Assurance pillar combined with FY2026 NDAA Section 818 requires contractors to affirmatively vet AI components across the supply chain. The NSA's AI Security Center has a 120-day mandate to develop private-sector partnerships for securing AI technologies, which will generate vetting guidance for contractors. In practice, this means a contractor delivering an AI-enabled system must be able to identify and document: which foundation models or AI components are embedded; the provenance and ownership chain of those components; and whether any component originates from or has material involvement of adversary-nation entities.
Fluet Law's analysis of NSPM-11 notes that "early supply chain mapping and documentation will be increasingly important to demonstrate compliance" well before RFP stage.
3. Conduct-Based Contract Termination
NSPM-11 directs agency heads to terminate contracts, either for default or for convenience, with companies that have "repeatedly demonstrated a pattern of conduct" inconsistent with the memo's pillars. The four conduct categories that activate this authority:
- Attempting to limit or prevent the government's use of AI products
- AI systems that censor speech
- AI systems that embed ideological bias
- AI systems that enable unauthorized surveillance
4. Training Requirements
NSPM-11 calls for "expanded training and enhanced security in collaboration with the private sector." OPM has a 120-day mandate (around October 3, 2026) to stand up an AI National Security Strategic Reserve: a bench of non-governmental AI experts available for federal national security efforts. Expect training requirements on AI controllability, steerability, and adversarial AI threat concepts to appear in Statements of Work for AI-enabled programs, particularly those touching the intelligence community or autonomous systems.
NSPM-11 and CMMC: What the Phase 2 Pause Actually Means
DoD suspended CMMC Phase 2 third-party C3PAO assessments on July 13, 2026, citing untenable cost burdens on small businesses. The suspension does not affect:
- Underlying NIST SP 800-171 Rev. 2 control requirements for CUI protection
- Existing DFARS 252.204-7012 flow-down obligations
- AI system control clause requirements now flowing from NSPM-11
The more significant intersection is forward-looking. FY2026 NDAA Section 1513 directs DoD to develop an AI/ML cybersecurity framework and incorporate it into DFARS and CMMC. This is the most likely enforcement path for NSPM-11's AI security requirements. Ward & Bradel characterize the enforcement trajectory: "For defense and national security contractors, the most likely path from policy to enforcement will not be a brand-new AI compliance regime, but rather the incorporation of AI-specific security and assurance expectations into familiar frameworks, especially CMMC, NIST, and related controls."
Contractors who treat the CMMC pause as license to deprioritize AI security posture are building technical debt that will accelerate remediation costs when the framework update arrives. For background on existing CMMC security requirements, see our CMMC AI security guide for defense contractors.
NSPM-11 and the FY2026 NDAA: Four Key Intersections
The FY2026 NDAA adds four AI-relevant obligations alongside NSPM-11:
Section 1513 (AI/ML Framework): DoD must develop a cybersecurity and physical security framework for AI and machine learning systems the Pentagon acquires. The framework must cover model performance standards, testing procedures, security requirements, and alignment with DoD ethical AI principles, then be incorporated into DFARS and CMMC. A congressional status update was due June 16, 2026.
Section 1534 (AI Sandbox): Directs SECDEF to create isolated AI testing environments. Contractors participating in pilot programs or Other Transactions Authority agreements tied to this section gain early exposure to DoD's TEVV methodology before it becomes contract-mandated.
Domestic Sourcing (Sections 834, 835, 818): DoD must eliminate reliance on adversary nations for optical glass, optical systems, and computer displays by January 1, 2030. Section 818 supply chain provisions extend affirmative vetting for AI vendor ownership and control. According to King & Spalding's FY2026 NDAA analysis: "Solicitation language and pre-award questions are likely to probe sourcing strategies and domestic alternatives earlier in the procurement process. Early supply chain mapping and documentation will be increasingly important to demonstrate compliance."
False Claims Act Exposure: DOJ has flagged AI compliance misrepresentation as an active FCA enforcement area. Misrepresenting AI system integrity, cybersecurity certification status, or model accuracy in a federal proposal or contract creates qui tam liability, including for subcontractors who do not hold the prime contract directly. The DOJ revised its Justice Manual on September 18, 2026 with procedural changes affecting FCA defense.
DoDD 3000.09: The Autonomous Systems Watch List
NSPM-11 Section 3(c) directed the Secretary of Defense to update DoDD 3000.09 ("Autonomy in Weapon Systems") within 90 days of June 5, 2026, placing the deadline around September 3, 2026. Annual reviews are required thereafter. The explicit mandate is to "eliminate unnecessary barriers to rapid deployment" of autonomous systems.
The original DoDD 3000.09 (2012, revised 2023) required humans to remain in the loop for lethal force decisions. The revision is expected to loosen those thresholds for AI-enabled weapons, swarms, and autonomous platforms. CSIS has noted "confusion remains widespread" about how the revised policy will define the autonomy threshold.
Contractors building AI-enabled weapons, autonomous vehicles, surveillance platforms, or decision-support systems in contested environments should:
Senator Ruben Gallego's June 12, 2026 letter to the Pentagon specifically asked how unintended-harm risks to U.S. personnel and allies are being addressed. Contractors should expect DoD to embed risk-of-harm documentation requirements into the revised test and evaluation process.
30-60-90 Day Contractor Action Plan
Days 1 to 30: Contract and Subcontract Review
- Audit all active contracts and task orders for AI and autonomous systems scope. Identify those touching national security agency customers.
- Identify every AI component, model provider, and AI-enabled subcontractor in the delivery chain.
- Check existing contract vehicles for the presence or absence of AI system control clauses. Flag gaps for legal review.
- Brief program managers on the conduct-based termination authority in NSPM-11 Section 3(b). Establish a product-change notification protocol for any updates that could limit, degrade, or modify government-facing AI behavior.
Days 31 to 60: Supply Chain Documentation
- Build an AI Bill of Materials for each AI-enabled deliverable. Document foundation model provenance, fine-tuning data sources, and third-party component ownership chains. See our AI Bill of Materials enterprise guide for methodology.
- Assess upstream model providers against adversary-nation involvement criteria under FY2026 NDAA Section 818.
- Secure contractual flow-down rights and waiver options with AI subcontractors before they become negotiating points under contract pressure.
- Brief IR&D and capture teams on NSPM-11's multi-vendor interoperability expectations. Proposals that demonstrate single-vendor dependencies now carry additional evaluation risk.
Days 61 to 90: Security Posture and Training
- Run a TEVV gap analysis for autonomous and AI-enabled programs against the four Assurance properties: reliable, controllable, steerable, and fault-resistant.
- Conduct adversarial AI threat modeling for each AI system in scope. Specific threat classes flagged by NSPM-11 include malicious distillation attacks and conduct-based degradation scenarios.
- Initiate training for program managers, CISOs, and AI system operators on NSPM-11 controllability and steerability obligations, ahead of OPM's October 2026 training mandate formalization.
- Review the revised DoDD 3000.09 when published. Update test plans for autonomous programs accordingly.
What an AI Security Assessment Covers for DIB Contractors
BeyondScale's AI security assessment maps your current AI posture against NSPM-11, CMMC, and FY2026 NDAA obligations in a single engagement. The assessment covers AI system control clause readiness, supply chain provenance documentation, adversarial threat coverage in TEVV plans, and identification of AI components that may trigger adversary-nation sourcing reviews.
The Crowell & Moring NSPM-11 analysis identifies the Accountability pillar as "the most immediately relevant element for government contractors." That pillar is also the least mature in most defense contractor AI governance programs we assess, because it requires legal review, security engineering, and program management to work from the same model inventory.
Start with a Securetom scan to get an immediate inventory of your externally visible AI attack surface before the full assessment.
Conclusion
NSPM-11 is not a soft policy directive. Its AI system control clauses are already live in classified-network contracts. Its conduct-based termination authority has no grace period. The CMMC Phase 2 pause buys time on third-party audits but not on the underlying security obligations, which are about to get harder when the FY2026 NDAA AI/ML framework is incorporated into DFARS.
The contractors who will manage this cleanly are the ones treating NSPM-11 compliance as a program management problem, not a legal one. That means supply chain documentation before the RFP drops, TEVV plans that cover adversarial AI scenarios, and control clauses in place with every upstream model provider before a contract modification forces the issue.
Start your NSPM-11 readiness review at securetom.com/scan.
Check your AI endpoint against these findings
SecureTom runs a free quick scan on any AI endpoint in about a minute. No signup needed.




