Agentic AI in Defence: What European Militaries Are Testing

Agentic AI in Defence: What European Militaries Are Testing

Agentic AI in defence means software agents built on large language models that plan a multi-step task, call other tools and data sources, and act inside a military workflow with a human approving the result. In Europe it is real but early: NATO runs Palantir’s Maven Smart System at SHAPE and two joint force commands, France’s AMIAD signed a three-year framework with Mistral AI in December 2025, the UK created a Rapid AI Delivery Taskforce in June 2026, and the Bundeswehr is launching its own document assistant on a sovereign GPU cloud. Almost everything else is a prototype, a field trial or a funded research project.

Key facts (as of September 2026)

  • NATO’s NCIA bought Maven Smart System NATO on 25 March 2025 after a six-month procurement; SHAPE, JFC Brunssum and (from May 2026) JFC Norfolk use it for intelligence fusion, planning and decision support.
  • France notified a three-year framework agreement to Mistral AI on 16 December 2025, steered by the defence AI agency AMIAD and hosted on French infrastructure.
  • The UK MOD signed a strategic partnership with Palantir on 18 September 2025 (up to £1.5 billion of Palantir investment) and a £240.6 million enterprise agreement on 30 December 2025; TF RAID followed on 10 June 2026.
  • The Bundeswehr rejected Palantir for its military cloud and AI project on 28 April 2026 and is testing German and French alternatives; SearchGPT and a Virtual Document Assistant launch in 2026 on a sovereign AI infrastructure with 27 GPUs across three data centres.
  • Thales tested its LLM-and-agent based HexaForce command platform at NATO CWIX 2026; Hensoldt’s MDOcore has passed a first functional prototype test; Helsing raised US$1.8 billion in July 2026 at an US$18 billion valuation.
  • Governance rests on NATO’s six Principles of Responsible Use, the UK’s JSP 936 and the EU AI Act’s Article 2(3) military exclusion, which leaves member states to regulate defence AI themselves.

What agentic AI actually is, and what it is not

Classic military machine learning is a single model trained for one task: classify a radar track, flag an anomaly in engine data, translate a document. Older automation follows fixed rules written by an engineer. An agentic system starts from a goal expressed in ordinary language, decomposes it into steps, and calls tools (a search index, a database, a planning solver, another model) and reads the results before deciding what to do next. The model at the centre is usually a large language model, and the “agent” is the loop of planning, tool use and self-checking wrapped around it.

The reason militaries care is mundane. Staff work is document work: an intelligence cell reads hundreds of reports a day, a logistics branch reconciles spreadsheets against maintenance logs, a planning team drafts orders that must cite the right annexes. An agent that can retrieve, cross-reference, summarise and draft, then hand a checked product to an officer, attacks exactly that backlog.

What it is not matters just as much. None of the European programmes described below hands an agent authority over the use of force; the public documents are consistent that the tools support understanding, planning and administration, and a person remains accountable for the decision. NATO’s Science and Technology Organization published a paper in February 2026 that treats military agentic AI as a security problem in its own right, proposing an “Agent-Guard” that translates mission constraints into formal policies and checks every action before an agent executes it.

Where NATO and national headquarters are already using it

The most visible case is NATO’s own. On 25 March 2025 the NATO Communications and Information Agency finalised the purchase of Palantir’s Maven Smart System NATO for Allied Command Operations, in a six-month procurement SHAPE called one of the fastest in its history. SHAPE’s announcement listed the applications plainly: large language models, generative and machine learning tools for intelligence fusion, battlespace awareness, planning and faster decision-making, in use within 30 days. By March 2026 Janes reported it installed at SHAPE and JFC Brunssum, with JFC Norfolk due by the end of May 2026. Vice Admiral James Morley of JFC Norfolk said NATO was still “at the foothills of understanding what it can do”.

The same platform is being pushed into the back office of exercises. NATO Allied Command Transformation’s Beacon Project “AI in Audacious Training” passed to the Joint Warfare Centre in Stavanger in January 2026. Its target is the Main Events List and Main Incidents List scripting behind every large NATO exercise, one of the most labour-intensive parts of exercise design. JWC staff saw a Maven Smart System demonstration in January 2026, and a minimum viable product is to be tested during STEADFAST DUEL in October 2026. It is a textbook agentic use case: read the scenario, generate candidate injects, structure the data, let the planner choose.

Here the money tells the story in London. The UK Ministry of Defence signed a strategic partnership with Palantir on 18 September 2025 under which the company will invest up to £1.5 billion in the UK, base its European defence business in London and create up to 350 jobs, with the MOD describing up to £750 million of opportunities with UK Defence over five years. A contract notice published on 23 January 2026 then confirmed a follow-on enterprise agreement worth £240.6 million, signed on 30 December 2025 and running from 1 April 2026 to 31 March 2029, awarded directly under the defence and security exemption for “data analytics capabilities supporting critical strategic, tactical and live operational decision making”. On 10 June 2026 the Defence Secretary added a Rapid AI Delivery Taskforce (TF RAID), reporting to the Chief of the Defence Staff, exempt from standard financial controls and briefed to process intelligence data and integrate AI into military planning.

France chose the sovereign route and a local champion. The Ministry of the Armed Forces notified a framework agreement to Mistral AI on 16 December 2025, announced on 8 January 2026, giving the armed forces, ministry directorates, the CEA, ONERA and the naval hydrographic service SHOM access to Mistral’s models, software and services for three years. AMIAD, the ministerial defence AI agency created in 2024, steers the deal; its director Bertrand Rondepierre called it a major step for the ministry’s generative AI capabilities. It builds on a cooperation agreement signed in March 2025, hosting stays on French infrastructure, and the public description covers translation, document analysis and operational support. The ministry has not published user numbers or a list of deployed agents.

Germany: a sovereign stack first, then the applications

Berlin’s 2026 story is a refusal. On 28 April 2026 Vice Admiral Thomas Daum, inspector of the Cyber and Information Domain Service, told Handelsblatt that he did not see Palantir being used for the Bundeswehr’s planned military cloud for data processing and AI. His reasoning was about access, not capability: allowing industry employees onto the national data holdings, as happens with NATO’s Maven installation where company staff operate the system, was “unthinkable” for now. The dpa report of the same day said the Bundeswehr had picked three companies to evaluate instead, Almato of Stuttgart, the Berlin start-up Orcrist and Chapsvision of Paris, with testing over the summer of 2026 and a contract award targeted for the end of the year.

Underneath that decision sits infrastructure that was already being built. According to a September 2026 report in Europäische Sicherheit & Technik, the Bundeswehr’s IT provider BWI and the Hamburg firm Kubermatic have a sovereign, cloud-native AI platform in productive operation: as of April 2026 it ran nine models on 27 physical GPUs across three data centres, supported five live use cases, and is designed so that sensitive data and AI capability stay under Bundeswehr control even in tactical field operations. An enterprise-wide language model gateway is on the roadmap. That is the plumbing an agentic layer needs, built deliberately without a foreign hyperscaler.

The applications are modest. The Bundeswehr’s AI project page lists two generative tools launching in 2026: SearchGPT, an intranet search engine that answers questions about regulations and documentation with citations, and the Virtual Document Assistant, which translates, summarises and part-automates the drafting of new documents inside Bundeswehr workflows. Further down the maturity ladder sit Hubitus, a Luftwaffe tool that searches Eurofighter technical documentation to answer engineering support questions, and a navy predictive-maintenance project that reads ship sensor data to forecast dock time. Both are listed as in development. The Uranos KI reconnaissance platform for the brigade in Lithuania, approved in December 2025 for delivery from mid-2027, is sensor fusion rather than an agent.

Industry has read the signal. Hensoldt unveiled its MDOcore software suite on 11 November 2025 as a “universal translator” that fuses sensor and effector data across domains and adds an AI assistant that takes voice and text commands; the company said a first functional prototype with multi-domain fusion and AI-supported evaluation had been tested. It paired MDOcore with Schwarz Digits’ Stackit cloud in March 2026 and signed a memorandum with IBM Germany in May 2026. A Bundeswehr order has not been announced. Helsing, which raised US$1.8 billion in a Series E on 13 July 2026 at an US$18 billion valuation, belongs to the same sovereignty argument, though its public German contracts are for strike drones and electronic-warfare software rather than staff agents; Helsing Explained: Europe’s Defence AI Firm, Drones, Funding covers that portfolio, and How AI Is Changing Electronic Warfare in Europe: Cognitive EW the Eurofighter work.

The European vendor map and the sovereignty fight

Three kinds of company compete for European defence agent work, on different terms. The first is the American incumbent. Palantir holds the NATO ACO contract, the UK enterprise agreement and a London base for its European defence business; its weakness in Germany is its strength elsewhere, an operating model in which company engineers sit inside the customer’s data. The second group is the European foundation-model builders. Mistral AI now has the French framework. Aleph Alpha, once Germany’s flagship model company, agreed in April 2026 to be absorbed by Canada’s Cohere in a deal valued at roughly US$20 billion, with Schwarz Digits leading a US$600 million round and the German government positioned as an anchor customer; the combined company keeps dual headquarters and sells PhariaAI as an on-premises orchestration layer for government users.

The third group is the primes, who are adding agents to command software they already sell. Thales launched HexaForce on 17 September 2026, a multi-domain command and control platform that it says uses large language models and agentic AI from its cortAIx accelerator to automate the analysis and prioritisation of military, open-source and civilian data streams. Thales tested it at NATO’s CWIX 2026 interoperability exercise and calls it available for deployment; no customer has been named. It competes with Indra’s Nimbus combat cloud, which went through a naval test at REPMUS 2026, and with Hensoldt’s MDOcore. A wider survey of who builds what is in Europe’s Defence AI Companies: Who Is Building What in 2026, and the funding side of the start-up scene in European Defence Tech Startups: Who Funds Them and Who Buys.

That is where the industrial bottleneck starts. Agents are only as useful as the data and tools they can reach, and in European defence those sit behind classification boundaries, in legacy systems, and increasingly on sovereign clouds built to keep hyperscalers out. The Bundeswehr’s BWI platform, France’s national hosting for Mistral and the Hensoldt-Stackit pairing all point the same way: the model may be commercial, but the runtime must be national or at least European. Microsoft and Google market sovereign-cloud arrangements in Europe, but no European defence ministry has publicly named either as the host for an agentic decision-support system. The practical cost is integration time, because every agent has to be wired to each ministry’s own document stores and those integrations do not travel between countries.

The EU funds the research layer rather than buying products. On 15 April 2026 the European Commission said the 2025 European Defence Fund call would put €1.07 billion into 57 projects, among them DIALOG-AI (live tests of operational generative AI), LLM Secret (sovereign and trusted large language models for European defence), MIDAS (middleware for defence AI dialogue systems), RHESIS (privacy-preserving human-AI dialogue for explainable defence applications) and AI-SHIELD (secure human-AI interaction at the edge). Those are LAB-stage by definition. The European Defence Agency’s contribution is methodological: its Trustworthiness for AI in Defence white paper of 9 May 2025 recommends an end-to-end evaluation framework for general-purpose AI in mission planning, threat analysis and decision support, and says large language models must be tested for hallucination and bias before they advise a planner.

Programme and product map

The table below classifies the named European efforts on this site’s maturity scale. Most land between PROTOTYPE and LIMITED DEPLOYMENT. Only the NATO installation and the UK’s licensed analytics estate are in daily use at headquarters level, and even there the agentic features are the newest and least documented part of the stack.

Programme / productCountry / organisationUse caseVendor(s)StatusLatest milestone
Maven Smart System NATONATO ACO (SHAPE, JFC Brunssum, JFC Norfolk)Intelligence fusion, planning, decision supportPalantirLIMITED DEPLOYMENTJFC Norfolk delivery by end May 2026 (Janes, Mar 2026)
AI in Audacious Training (Beacon Project)NATO ACT / JWC StavangerExercise scenario and MEL/MIL inject generationPalantir MSS toolsetPROTOTYPEMVP test at STEADFAST DUEL, Oct 2026
MOD Palantir Enterprise AgreementUK MODData analytics for strategic and live operational decisionsPalantir UKOPERATIONAL (analytics estate)£240.6m, signed 30 Dec 2025, runs to Mar 2029
Rapid AI Delivery Taskforce (TF RAID)UK MOD / CDSFast fielding of AI for intelligence processing and planningMultiple, incl. UK SMEsPROCUREMENTLaunched 10 Jun 2026
Mistral AI framework agreementFrance, Ministry of the Armed Forces / AMIADGenerative AI for staff work, translation, document analysisMistral AIPROCUREMENT / early rolloutNotified 16 Dec 2025, three years
SearchGPT and Virtual Document AssistantGermany, Bundeswehr / BWIIntranet search, summarising, draftingBWI, Kubermatic (platform)LIMITED DEPLOYMENT2026 launch on sovereign AI cloud (ESUT, Sep 2026)
Hubitus; navy predictive maintenanceGermany, Luftwaffe / MarineEurofighter technical Q&A; ship maintenance forecastingNot disclosedPROTOTYPEListed “in development” (Bundeswehr.de)
Military cloud and AI projectGermany, CIR / BWIData processing and AI platform for operationsAlmato, Orcrist, Chapsvision under testPROCUREMENTPalantir rejected 28 Apr 2026; award targeted end 2026
MDOcoreGermany, HensoldtMulti-domain data fusion with AI assistantHensoldt, Schwarz Digits, IBMPROTOTYPEFunctional prototype tested (Nov 2025); IBM MoU May 2026
HexaForceFrance, ThalesMulti-domain C2 with LLM and agentic analysisThales cortAIxFIELD TRIALTested at NATO CWIX 2026; launched 17 Sep 2026
EDF 2025 AI projects (DIALOG-AI, LLM Secret, MIDAS, RHESIS, AI-SHIELD)EU / European CommissionSovereign LLMs, dialogue systems, trustworthy human-AI interactionConsortia (EU and Norway)LABSelected 15 Apr 2026, €1.07bn across 57 projects
AI-supported decision support, MAIN assistantTürkiye, HAVELSANCommand decision support; maintenance assistantHAVELSANDEMONSTRATORShown at IDEF, Istanbul, Jul 2025

Türkiye appears once in that table because there is a verified public fact. HAVELSAN showed AI-supported decision support systems and multi-domain command architectures at IDEF in Istanbul in July 2025, alongside a maintenance assistant called MAIN integrated into its ADVENT combat management system. Whether any of it has entered Turkish service as an agentic product has not been published, so it stays a demonstrator here.

Governance: who is allowed to let an agent act

Europe regulates defence AI through three overlapping layers, none written with agents in mind. The EU AI Act excludes from its scope any AI system placed on the market or used “exclusively for military, defence or national security purposes, regardless of the type of entity carrying out those activities”, under Article 2(3). That leaves defence ministries with national law, international humanitarian law and their own policy. The EDA’s TAID white paper is the closest thing to a common European standard, and it is voluntary, offered “without raising any commitment or obligation” on member states.

NATO fills part of the gap. Its six Principles of Responsible Use, restated in the July 2024 revised strategy that also told the Alliance to adopt generative AI promptly where it can be done responsibly, are lawfulness, responsibility and accountability, explainability and traceability, reliability, governability and bias mitigation. Governability is the one that bites for agents: it requires that AI applications can be disengaged or deactivated when they behave unexpectedly, easy for a classifier and much harder for a system that has already called a dozen tools on the way to a draft. The February 2026 STO paper is the technical response to that principle.

The UK has the most detailed national rulebook. JSP 936, published on 13 November 2024, is the MOD’s principal policy framework for dependable AI, directing governance, development and assurance across the AI lifecycle with “the right level of human oversight”. The June 2026 TF RAID announcement added an AI Expert Advisory Group on top of the existing Ethics Advisory Panel. The picture is less tidy on the ground. The House of Commons Defence Committee’s report of 10 January 2025 found a “say-do gap” between ministers’ speeches and what the department fielded, and quoted Faculty AI’s evidence that progress in large language models had already made some assumptions of the 2022 Defence AI Strategy obsolete.

Germany’s approach is procedural rather than doctrinal: Daum’s refusal to let vendor staff near national data is a governance decision as much as a procurement one, and the BWI platform’s design goal of keeping AI capability under Bundeswehr control in the field is the same principle in hardware. France has placed the decision inside AMIAD, one agency that both buys the models and sets the rules. Across all three, the agent drafts and the officer signs. Whether that rule survives an operational headquarters that wants outputs faster is the question the next two years of field trials will answer.

Frequently asked questions

What is agentic AI in defence?

Agentic AI in defence refers to software agents, usually built on large language models, that take a goal in plain language, break it into steps, call tools such as databases, search indexes and planning software, and produce a checked result for a human to approve. European militaries currently apply it to intelligence document processing, staff drafting, exercise design and maintenance support, not to decisions about the use of force.

Which European militaries are using agentic AI today?

NATO’s Allied Command Operations runs Palantir’s Maven Smart System at SHAPE, JFC Brunssum and JFC Norfolk. The UK MOD holds a £240.6 million Palantir enterprise agreement and launched a Rapid AI Delivery Taskforce in June 2026. France’s AMIAD has a three-year framework with Mistral AI from December 2025. The Bundeswehr is launching SearchGPT and a Virtual Document Assistant on its own sovereign AI cloud in 2026.

Is Palantir’s Maven Smart System operational in NATO?

It is in limited deployment. NCIA finalised the purchase on 25 March 2025 and SHAPE said it would be in use within 30 days. By March 2026 it was installed at SHAPE and JFC Brunssum, with JFC Norfolk scheduled to receive it by the end of May 2026. NATO commanders have described themselves as still learning what the system can do, and the Bundeswehr declined to adopt it for national use in April 2026.

Does the EU AI Act regulate military AI?

No. Article 2(3) of the EU AI Act excludes AI systems used exclusively for military, defence or national security purposes, whatever entity operates them. Defence AI in Europe is instead governed by national policy such as the UK’s JSP 936, NATO’s six Principles of Responsible Use, international humanitarian law, and voluntary guidance such as the European Defence Agency’s 2025 Trustworthiness for AI in Defence white paper.

Which European companies build agentic AI for defence?

Palantir supplies NATO and the UK. Mistral AI holds the French defence framework. Cohere agreed in April 2026 to absorb Germany’s Aleph Alpha with Schwarz Digits as lead investor. Thales launched the agent-enabled HexaForce command platform in September 2026, Hensoldt is prototyping MDOcore with Schwarz Digits and IBM, and Helsing raised US$1.8 billion in July 2026, though its German contracts are for drones and electronic warfare rather than staff agents.

Sources

Related Posts