This week’s Defence & Security AI stories reveal a sector in acute regulatory tension: autonomous weapons are being fired in live tests and deployed at scale while Congress, the EU, and the White House race to write rules for what they can legally do. The gap between operational reality and governance frameworks has never been wider — or more consequential.

Top story: Anduril’s AI drone wingman fired a live missile autonomously over the Mojave Desert — the first weapons-employment test of its kind for the US Air Force’s Collaborative Combat Aircraft programme.


US Air Force AI Drone Fires Live Missile Autonomously in Historic Test

DefenseScoop · Generative AI

The US Air Force announced that Anduril’s YFQ-44A Fury drone conducted a live-fire test, autonomously launching an AIM-120 air-to-air missile at a simulated digital target over secluded Mojave Desert airspace. The Air Force called the event ‘operational validation’ that the Collaborative Combat Aircraft can execute weapons autonomously within pilot-defined parameters — a significant step toward fielding over 150 robotic wingmen by the end of the decade. For defence practitioners, the test marks the shift from autonomous drones as surveillance tools to autonomous drones as weapons-employment platforms, raising immediate questions about human oversight and rules of engagement.

https://defensescoop.com/2026/07/15/air-force-live-fire-test-missile-anduril-cca-drone/

Pentagon Pauses Cyber Compliance Programme Amid AI Autonomy Policy Rewrite

Fluet Law · Regulation

On 13 July 2026, the Department of Defense paused implementation of parts of its Cybersecurity Maturity Model Certification (CMMC) programme, while a June White House National Security Presidential Memorandum simultaneously directs the Pentagon to rewrite its decade-old autonomous weapons directive (DoDD 3000.09) within 90 days. The result is a rapidly shifting compliance landscape for thousands of defence contractors, with AI-specific cybersecurity and governance rules being rewritten at speed even as systems go live. Practitioners should note the September 2026 deadline for the autonomy directive revision, which will directly determine what operational contexts AI-powered kill-chain systems can legally be deployed in.

https://fluet.law/autonomy-decoded-where-innovation-meets-shifting-regulation-for-government-contractors-providing-autonomous-ai-enabled-capabilities-to-u-s-national-security-agencies/

House Armed Services Panel Moves to Identify and Bar Adversary AI From Pentagon

Inside Defense · Regulation

The House Armed Services Committee has directed the Pentagon to develop department-wide procedures for identifying AI companies whose products should be barred from defence contracts, building on the FY2026 NDAA’s existing ban on DeepSeek and High Flyer AI systems. The move extends the national-security perimeter around AI supply chains, treating adversary-linked models as potential vectors for espionage and sabotage — a compliance burden that now flows through to all subcontractors in the defence industrial base. UK and European firms bidding on US defence contracts or partnering with American primes must audit their AI tooling stack or risk disqualification.

https://insidedefense.com/