Skip to content
A controlled-access area seen from above: an employee carrying binders walks through a heavy security door with a card reader.

NOTHING LEAVES YOUR PERIMETER

Your bid team can use AI.

Your team runs tender work, export-control documentation and project reporting on systems that stand where your security analysis says they may stand. You own them at handover, and our access ends there.

THE MARKET

A hundred new suppliers, two rulebooks

Sweden's defence appropriation for 2026 is 175 billion kronor, up eighteen per cent on the year before, according to the budget bill for 2026. The Swedish Defence Materiel Administration (Försvarets materielverk, FMV) contracted 145 new suppliers during 2025, by its own annual report for that year.

Somewhere in that number is a company like yours: established in its own craft, new to this sector, and suddenly operating under rules written for a different kind of risk.

Two misunderstandings tend to arrive with the opportunity. The first is that defence work is exempt from the AI rules, so the classification question can wait. The second is that the AI tools that served the civilian side of the business will serve here too.

The first is half true in the most expensive way. The second fails at the first classified document.

This page is about both.

SOVEREIGNTY

Sovereignty is the design brief

Start from the hard fact. Under the Clarifying Lawful Overseas Use of Data Act (CLOUD Act) and Section 702 of the Foreign Intelligence Surveillance Act (FISA 702), American cloud providers can be compelled to disclose data regardless of where the data centre stands.

For information classified as konfidentiell (confidential) or higher under Swedish protective security rules, that excludes the platforms most AI runs on: the large American cloud providers, and with them the public AI services and external language models normally deployed on them.

A joint report from the Swedish Armed Forces (Försvarsmakten) and the Swedish Security Service (Säkerhetspolisen) described American cloud services as a false sense of security. A European data centre does not change the law it answers to.

The Armed Forces' own cloud strategy sets the bar for the protected zone: operations run by security-vetted Swedish personnel, with no foreign insight. Whether or not you sell to them, that is the standard your Swedish customers' security organisations read from.

So data sovereignty is not a constraint to work around. It is the design precondition. Systems we design for this sector stand where your security analysis says they must stand, on your premises or under Swedish control, built on your data.

And at handover, our access ends. We have no partner programmes with American cloud providers to defend. Elsewhere we call that independence. Here it is a prerequisite.

OUR POSITION

Most consultancies sell you their continued presence. In this sector, our departure is part of the security design.

THE EXEMPTION

The exemption follows the purpose, not the industry

The EU AI Act exempts systems placed on the market or used exclusively for military, defence or national security purposes. Read that the way a regulator will: exclusively, and regardless of the type of entity.

The exemption attaches to each system's purpose. It does not attach to your industry, your ownership or your badge at the gate.

Inside a defence company, the split looks like this. The guidance system: exempt. The recruitment screening that helps hire the engineers who build it: high-risk under the same regulation.

Software that monitors the performance of cleared personnel: high-risk. Biometric verification at the gate, one to one: outside the high-risk list. Biometric identification across a database, one against many: high-risk. Emotion recognition in the workplace: prohibited outright.

Then the asymmetry that catches suppliers in particular. A system marketed for both military and civilian use falls inside the regulation. A civilian system that a military customer adopts falls outside it. For a supplier serving both markets, the product sheet is a legal document.

Most of what you run is exempt or out of scope. A defined set is not. Proving which is which, system by system, in writing your board and your customer's security organisation can both hold, is the job.

DELIVERY

Few hands. By design.

In defence engagements, access is kept deliberately narrow: the named senior who scopes the work delivers it, and no one else is added without your approval. Not a rotation, not a bench. Security vetting is individual. Every subcontractor is approved by you. Every additional person with access is additional exposure. Few hands is not a gap in this offering. It is a property of it.

That caps how many defence clients we take on at once, and we will not pretend otherwise. We think the cap is exactly as it should be.

We come prepared for the procedure this sector runs on in Sweden: the Swedish Protective Security Act (säkerhetsskyddslagen), security vetting of the individual, the protective security agreement (säkerhetsskyddsavtal) in place before any access, and the discipline that classified and unclassified work never share a system.

That discipline covers our own methods too. We can answer, for any engagement, exactly which tools touched your material. Ask everyone that question.

And the boundary we hold in every sector takes its absolute form here: AI as decision support, never as operations. We do not build weapons systems. We do not build targeting systems. We do not build anything that watches, aims or fires.

What a defence supplier needs from AI day to day is less cinematic and more valuable: tender and bid work under FMV's procedures, export-control and compliance documentation, project reporting, test data and logs turned into decision bases, and training for staff who cannot run half their questions through public tools.

The unglamorous work is where the hours are. The classification boundary is where the design starts.

WHERE TO START

Where to start

01

Classify the portfolio.

The exemption memo: every system, the dual-use question answered in writing, the high-risk set identified.

02

Assess under sovereignty constraints.

An AI Readiness Assessment scoped to your perimeter: what may run where, what never leaves, what to build first.

03

Build inside the perimeter.

Implementation on infrastructure you control, transferred at handover. You own the system, you run it, and no external party keeps access.

04

Train the people who cannot use public tools.

Leadership sessions from us; breadth through AIUC, our education arm.

05

Get a second opinion.

On the AI your prime contractor or group headquarters is proposing, from an adviser with nothing in the deal.

PROOF

References, such as this sector allows

We delivered an assignment at Saab's management conference. We work for public institutions including the Riksdag Administration (Riksdagsförvaltningen), and for private-sector clients in regulated industries.

You will notice fewer names here than on our other pages. That is not the evidence failing. That is how evidence behaves in this sector.

QUESTIONS

Before you assume the exemption covers you.

The EU AI Act's exemption covers systems placed on the market or used exclusively for military, defence or national security purposes, not your company as a whole. Recruitment, workforce monitoring and other internal systems sit under the ordinary rules, and a product marketed for both military and civilian use falls inside the regulation entirely. The high-risk requirements for Annex III apply from 2 December 2027. The answer is a classification, not an assumption.

A system marketed for both military and civilian use falls inside the EU AI Act in full, while a civilian system that a military customer adopts falls outside it. For a supplier serving both markets, the product sheet is therefore a legal document. The classification should be settled before the high-risk requirements for Annex III apply from 2 December 2027.

At a defence supplier, public AI services are often usable in the unclassified zone, and pretending otherwise only drives the use underground. The boundary follows your information classification under the Swedish Protective Security Act: which security classes may meet which tools, and what runs only inside your own perimeter. In most sectors, unsanctioned AI use is a governance gap. At a defence supplier it is an unauthorised disclosure.

Ampliro works under protective security agreements, and in defence engagements the named senior who scopes the work delivers it, which is what makes the procedure workable: vetting under the Swedish Protective Security Act is of the individual, approval of every subcontractor is yours, and the agreement is in place before any access is given. We arrive knowing the sequence rather than learning it on your invoice.

A first contract in the defence supply chain starts with the inventory you already owe: your security analysis under the Swedish Protective Security Act on one side, your AI use on the other, and the line between them stated explicitly. The AI literacy duty in Article 4 of the EU AI Act has applied since 2 February 2025, so the inventory is late rather than early. It is a short engagement with a long shelf life.

Start the conversation

One conversation, no deck, no delegation. Bring the system you are unsure about, or the contract you just signed. If your AI question turns out to be a security question first, we will say so, and tell you what order to solve them in.