Paper Walls for Living Code
Fifty years after Matt Jaffe drafted missile software on paper, private tech firms write battlefield code, raising fears of adversary sales and catastrophic leaks.
As commercial algorithms increasingly direct national defense, statutory export bans and isolated cloud architectures determine whether critical military secrets stay protected or fall to foreign powers.
Key facts
- In 2007, ITT Corporation received a $100 million penalty for unauthorized retransfers of night-vision technology to China, an enforcement action a Wikipedia entry described as the most notable.
- Any cyber incident must be reported to the Department of Defense within 72 hours of discovery, satisfying the requirement to rapidly report such incidents.
- According to Gregory Kausner, private-sector dollars account for nearly 90 percent of U.S. research and development funding today, whereas the federal government bankrolled two-thirds of that funding in 1964.
- The Department of Defense estimates a proposed rule would increase required foreign ownership, control, or influence reviews from roughly 2,500 classified contractors to nearly 40,000 companies by expanding requirements to certain unclassified contracts.
The Full Story
The Cold War Code
In the mid-1970s, an RCA systems engineer named Matt Jaffe sat down to map out software for the Navy's Aegis combat system. It was the era of the rigid waterfall specification, where engineers drafted requirements documents, mailed them off, and received a single review meeting lasting only a few hours. Military technology was built step-by-step under the direct thumb of the government, engineered slowly by traditional contractors for a world divided by the Cold War.
Today, a new generation of commercial software firms like Palantir and Anduril are moving code directly into the armed forces at startup speed. That shift prompted a listener to ask: when venture-backed, for-profit companies build the digital backbone of the military, what actually stops them from turning around and selling their capabilities to rivals like Russia or China? And if a private contractor suffers a cyber breach, does it completely expose the nation's military secrets?
It matters because software and autonomous algorithms now shape defense advantages, raising the urgent question of who holds the keys when commercial tools go to war. We are tracing how Cold War safeguards meet modern code, separating legal myths from real cybersecurity risks.
The answer starts with a dense legal cage forged during the exact era Matt Jaffe was writing code. Between 1975 and 1976, President Gerald Ford established the Committee on Foreign Investment in the United States, and Congress passed the Arms Export Control Act to create the International Traffic in Arms Regulations. Those rules were engineered to ensure that existential concern over Soviet exploitation would legally bar private firms from transferring critical military capabilities abroad.
Yet the money powering innovation has flipped entirely. While government-steered Foreign Military Sales reached 118 billion dollars, private industry now funds nearly 90 percent of all American research and development rather than federal defense accounts. To understand how that private software remains boxed in, we have to look directly at the statutory walls that stop a commercial tech vendor from cutting a deal with Beijing or Moscow.
The Legal Iron Curtain
The statutory wall begins with a bedrock rule: private defense contractors do not own the right to export military capability. Under the Arms Export Control Act, the State Department's Directorate of Defense Trade Controls administers the International Traffic in Arms Regulations, covering weapons, defense services, and technical data on the United States Munitions List. For countries like China, federal regulations establish an explicit policy of denial, meaning any license application to sell military-grade systems or defense services to Beijing or Moscow is denied outright.
Stepping around those rules brings severe criminal and financial consequences. In 2007, ITT Corporation was hit with a landmark 100 million dollar penalty for the unauthorized retransfer of night-vision technology to China. Enforcement also reaches individuals directly: Chi Mak was prosecuted and sentenced to over two decades in federal prison after an attempted illegal export of munitions list items to China. Alongside these criminal trade penalties, contractors handle classified and controlled data under rigorous defense accountability, including a seventy-two-hour tripwire requiring companies to report cyber compromises directly to defense authorities.
For dual-use technologies that have both commercial and military applications, the Commerce Department steps in. Under the Export Administration Regulations, the Bureau of Industry and Security uses the Entity List to restrict exports to foreign organizations deemed risks to national security, extending controls across foreign direct products built with American software. Pentagon procurement rules sharpen that divide: a Defense Department final rule taking effect on October 24, 2025, bars contracting officers from awarding consulting contracts to firms that advise covered Chinese or Russian state bodies without an approved conflict-of-interest mitigation plan.
These controls bind the entire defense industrial base rather than singling out software firms like Anduril or Palantir. Yet preventing diversion remains an ongoing challenge across sprawling commercial supply chains. A documented 2022 analysis examined foreign components recovered from Russian weapons and identified over two-thirds of the 450 items as originating in the United States, showing how commercial parts can leak through global distributor networks even under strict trade controls. But what happens if an adversary doesn't try to buy the software, but tries to buy the company itself?
The Ownership Gatekeepers
Buying into the company does not bypass the law. If an adversary cannot purchase defense software directly, federal investment screening steps in to stop them from acquiring it through board seats, venture capital funding, or corporate buyouts. Under statutory authorities rooted in the 1988 Exon-Florio amendment and expanded in 2018 by the Foreign Investment Risk Review Modernization Act, the Committee on Foreign Investment in the United States scrutinizes foreign transactions. Regulations extend that oversight to non-controlling investments granting access to critical technologies or sensitive data, empowering the president to suspend, block, or force foreign divestment from any deal deemed a national security threat.
For contractors working on classified defense programs, the shield goes further. Under federal regulations, the Defense Counterintelligence and Security Agency enforces Foreign Ownership, Control, or Influence rules whenever a foreign entity possesses the power to direct company decisions in ways that could compromise contract performance or classified data. A business flagged for foreign influence cannot hold a facility security clearance. To retain eligibility, the company must fully resolve the concern, using binding mechanisms such as voting trusts, proxy agreements, or electronic communication plans that enforce technical and logical network separation from foreign affiliates, or face outright revocation of its clearances.
Because commercially derived systems are now being fielded in large quantities faster than legacy defense acquisition pipelines can manage, the government is expanding this net. In 2026, the Department of Defense issued a proposed rule that extends foreign ownership reviews to unclassified contractors and subcontractors on covered defense awards exceeding 5 million dollars.
By the Pentagon's own estimates, that single change would expand mandatory foreign influence reviews from approximately 2,500 classified contractors to nearly 40,000 commercial companies across the industrial base.
Direct hardware and telecommunications links are barred just as strictly. Procurement regulations explicitly prohibit the Department of Defense from acquiring Munitions List items or specialized commercial control list items from Chinese military companies across any tier of contracting. In parallel, Section 889 rules banned agencies in August 2019 from procuring covered gear from five designated Chinese telecommunications and surveillance firms, followed by an August 2020 rule barring agencies from contracting with any company that uses their equipment. That closes the door on foreign sales and corporate buyouts. But what about the listener's second fear: what happens if a contractor gets hacked?
The Fortress in the Cloud
The short answer to the listener’s fear of a single, catastrophic hack is that defense systems are not built like a house with one front door. A breach inside a private contractor’s corporate office does not hand an intruder the master key to the armed forces. An intrusion at a single vendor does not mean that all military networks or data spill out with it. Defense agencies rely on layered cybersecurity to protect systems and infuse resilience into operations, ensuring an incident at the commercial perimeter hits immediate structural barriers.
When it comes to answering who holds the keys to sensitive operational data, the military answers with strict physical and cryptographic walls. Proponents of modern defense platforms emphasize that classified workloads are isolated inside specialized environments like Department of Defense Impact Level 6. Under these standards, the entire cloud infrastructure must be dedicated and completely physically separated from non-government tenants, linked directly and exclusively to the military's classified SIPRNet enclave. Further rules impose strict U.S.-citizenship mandates on any cloud personnel permitted to manage the infrastructure, ensuring that operational military data never sits on a shared commercial server.
Commercial technology providers must clear standardized federal baselines before touching these workloads. Under Department guidance dating back to December 2014, the Federal Risk and Authorization Management Program serves as the required baseline for defense cloud acquisitions. In the commercial software sector, for instance, Palantir Federal Cloud Service has maintained a certified FedRAMP High Class D authorization under Rev5 standards since November 19, 2024, demonstrating that private software vendors must undergo continuous third-party assessment and rigorous control vetting to operate within federal missions.
Inside those environments, the architecture works to ensure that an intruder who compromises a single endpoint cannot move across the wider military. The Department of Defense targets fiscal year 2027 to implement a department-wide Zero Trust framework designed to reduce the attack surface and quickly contain adversary actions. Industry advocates note that tools like software-defined perimeters, granular data tagging, and encryption of data both at rest and in transit restrict lateral movement and stop broad exfiltration. Security researchers have likewise demonstrated on-demand enclaves that enforce access at the level of individual records rather than entire repositories, isolating breaches at the source.
Yet if modern cloud architecture is designed to contain intrusions, why is there such a fierce debate over whether commercial software helps or hurts military cybersecurity?
Agile Speed vs. Supply Chain Shadows
The debate turns on whether welcoming private tech into defense networks fixes old digital vulnerabilities or opens dangerous new ones. On one side, federal watchdogs point to a track record of contractor slip-ups. When the Department of Defense Inspector General audited compliance with mandatory digital safeguards, it found that none of the assessed defense contractors consistently met required security controls. Over a three-year period, more than a hundred contractors reported nearly 250 security incidents to the defense cyber center, including one case where classified military information spilled across unclassified commercial clouds and webmail, sitting unprotected for almost two years.
Those risks multiply when software moves down the industrial supply chain. A Government Accountability Office report noted that while defense officials had mapped prime and major subcontractors for three-quarters of the F-35 fighter's 40,000 parts, they had identified less than 10 percent of lower-tier suppliers. Commercially available digital illumination tools tested by the Air Force proved only 60 to 70 percent accurate, leaving military buyers blind to obscure foreign components buried in commercial software and hardware.
When code is shared across thousands of autonomous platforms, that blindness carries catastrophic potential. The Congressional Research Service warned that replicating identical software across an entire fleet means a single overlooked flaw can disable multiple combat systems at once. History shows how dangerous automated interfaces can be when supervisory controls fail. In March 2003, automated radar misclassification led a Patriot missile battery to shoot down a British Tornado in Iraq, killing two crew members, while human factors researcher John Hawley later observed that humans are very poor at meeting the monitoring demands of automated supervisory control. In 2017, touchscreen steering confusion bypassed human-centered design on the USS John S. McCain, ending in a collision that killed 10 Navy sailors.
The other side argues that modern commercial software teams eliminate precisely these catastrophic delays. During the evacuation from Kabul, when the military coordinated over 2,600 flights to airlift 120,000 people, the Air Force agile coding team Kessel Run hit intermittent loading issues. Instead of waiting years for a formal update cycle, the team incorporated direct operator feedback and deployed a tested software fix with a new user-approved feature in 12 hours. Lieutenant General Greg Guillot credited that software as a reliable, adaptable tool during an urgent historic operation.
That operational agility breaks cleanly from the rigid waterfall specification models of the 1970s. As former RCA systems engineer Matt Jaffe recalled of building the Aegis combat system, engineers drew documents on paper and received only brief reviews from the Navy, an approach where designing effective human interfaces was nearly impossible. Today, defense procurement rules under DFARS mandate verified compliance with NIST standards through the Cybersecurity Maturity Model Certification framework, holding commercial vendors to verifiable safeguards rather than paper promises.
The Boundary Lines
The plain answer to our listener begins with the law. Commercial defense contractors like Anduril and Palantir cannot simply sell their technology to Russia or China, because federal export regulations enforce an explicit policy of denial for defense articles and services destined for those countries. Violating those statutes triggers criminal prosecutions, corporate debarment, and catastrophic penalties—such as the landmark 100 million dollar fine levied against ITT Corporation in 2007 for unauthorized night-vision data transfers to China. Furthermore, the federal government maintains the legal authority to deny or revoke a contractor's facility security clearances under Foreign Ownership, Control, or Influence rules if foreign influence threatens classified work.
Nor does a single contractor breach expose the entire military apparatus. Operational classified data is cordoned off in dedicated environments like Impact Level 6, which Microsoft notes operate as closed, self-contained enclaves connected exclusively to SIPRNet. Proponents of modern network architecture emphasize that software-defined perimeters enforce strict access boundaries that prevent the lateral movement necessary for large-scale data exfiltration. And if an intrusion does occur, the legal system enforces that seventy-two-hour tripwire: contractors must report cyber incidents within 72 hours of discovery to the DoD Cyber Crime Center, which immediately transmits encrypted incident alerts to the affected military contracting officers.
There remains one genuine uncertainty in the public discussion. While defense startup executives often voice ideological alignment with western democracies, the documented record contains no verified corporate charters or binding founding pledges from Palantir or Anduril that legally bar them from dealing with adversaries outside federal law. Their restraint is grounded not in corporate sentiment, but in federal statutes and expanding administrative scrutiny—such as the Department of Defense's 2026 proposed rule estimated to extend foreign-ownership oversight from roughly 2,500 classified contractors to nearly 40,000 companies across the commercial industrial base.
Fifty years ago, Matt Jaffe drew up software requirements for Aegis in a rigid waterfall specification document on paper, sending it to the Navy for brief reviews in a world where, as former defense official Gregory Kausner noted, fear of Soviet exploitation forged our modern export control architecture. Today, venture-backed defense firms deploy and patch code at cloud speed. Yet even as the software changes overnight, the Cold War legal framework remains the unyielding boundary keeping American defense technology securely under government control.
Timeline
Congress enacted the Arms Export Control Act during the Cold War, establishing the statutory basis for ITAR to strictly regulate foreign transfers of U.S. defense articles.
Read more: en.wikipedia.orgITT Corporation was assessed a landmark $100 million penalty for the unauthorized transfer of ITAR-controlled night-vision technology to China.
Read more: en.wikipedia.orgFIRRMA and the Export Control Reform Act became law, permanently expanding CFIUS national security reviews and dual-use export controls.
Read more: cfius.gov, en.wikipedia.org, congress.gov, cfius.govThe DoD Inspector General published an audit exposing 248 contractor cyber incidents and a two-year classified information spill on unclassified systems.
Read more: dodig.milThe Air Force agile software unit Kessel Run delivered rapid software fixes within 12 hours while directing 2,627 flights during the Kabul evacuation.
Read more: tnsr.org, jeffreyjding.github.ioPalantir Federal Cloud Service – Supporting Services received FedRAMP High Class D certification under Rev5 baseline security standards.
Read more: fedramp.govA DoD final rule took effect barring contracting officers from awarding consulting contracts to firms advising entities in China or Russia without an approved mitigation plan.
Read more: sanctionsnews.bakermckenzie.comThe Department of Defense proposed expanding mandatory foreign ownership and influence reviews from roughly 2,500 classified contractors to nearly 40,000 unclassified defense firms.
Read more: bakerlaw.com
In this story
- Category
- Topics
- Organizations
- Places
Connections
- ITAR restricts and governs the transfer and export of defense articles and technical data used in DoD defense programs.
- CFIUS conducts interagency reviews of foreign investments that could threaten U.S. national security and defense contractor independence.
- FOCI requirements enforced by DCSA safeguard DoD classified programs and covered unclassified contracts from foreign influence.
- Palantir maintains FedRAMP High and DoD cloud certifications to host and process defense workloads.
- ITAR maintains an explicit policy of denial regarding the export of Munitions List defense items and technical data to China.
Sources
- 32 CFR § 117.11 - Foreign Ownership, Control, or Influence (FOCI). | Electronic Code of Federal Regulations (e-CFR) | US Law | LII / Legal Information Institute — www.law.cornell.edu
- Foreign Ownership, Control or Influence — www.dcsa.mil
- CFIUS Laws and Guidance | CFIUS — www.cfius.gov
- Part 225 - FOREIGN ACQUISITION | Acquisition.GOV — www.acquisition.gov
- Anduril CEO Calls for Reset of U.S. Arms Export Controls - The Export Practitioner — exportprac.com
- Regulatory Friendly Fire: How ITAR Undermines the Alliance It Was Built to Protect — warontherocks.com
- New DoD Rule Targets Consulting Services Contractors that Also Work With the Governments of China or Russia, State Sponsors of Terrorism, or Certain Sanctioned Entities - Global Sanctions and Export Controls Blog — sanctionsnews.bakermckenzie.com
- FOCI for (Almost) Everyone: DoD Proposed Rule Would Extend FOCI Requirements to Unclassified Contractors and Subcontractors Performing Contracts Exceeding $5M | BakerHostetler — www.bakerlaw.com
- Primary PDF document — www.armed-services.senate.gov
- Primary PDF document — www.hsgac.senate.gov
- Primary PDF document — www.congress.gov
- Directorate of Defense Trade Controls - Wikipedia — en.wikipedia.org
- 22 CFR § 126.1 - Prohibited exports, imports, and sales to or from certain countries. | Electronic Code of Federal Regulations (e-CFR) | US Law | LII / Legal Information Institute — www.law.cornell.edu
- FAQs | CFIUS — cfius.gov
- International Traffic in Arms Regulations - Wikipedia — en.wikipedia.org
- Export Administration Regulations - Wikipedia — en.wikipedia.org
- 252.204-7021 Contractor Compliance With the Cybersecurity Maturity Model Certification Level Requirements. | Acquisition.GOV — www.acquisition.gov
- 252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting. | Acquisition.GOV — www.acquisition.gov
- Committee on Foreign Investment in the United States - Wikipedia — en.wikipedia.org
- Subpart 204.75 - CYBERSECURITY MATURITY MODEL CERTIFICATION — www.acquisition.gov
- PGI 204.73 -SAFEGUARDING COVERED DEFENSE INFORMATION AND CYBER INCIDENT REPORTING | Acquisition.GOV — www.acquisition.gov
- Subpart 4.19 - Basic Safeguarding of Covered Contractor Information Systems | Acquisition.GOV — www.acquisition.gov
- Primary PDF document — www.acquisition.gov
- Supply Chain Security Strategy — www.dla.mil
- Machine Failing: How Systems Acquisition and Software Development Flaws Contribute to Military Accidents - Texas National Security Review — tnsr.org
- GAO-26-108630, TELECOMMUNICATIONS: Better Information Sharing Needed to Ensure Compliance with Foreign-Sourced Equipment Prohibitions — files.gao.gov
- Primary PDF document — jeffreyjding.github.io
- Understanding the errors introduced by military AI applications | Brookings — www.brookings.edu
- Lethal Autonomous Weapon Systems: Issues for Congress - EveryCRSReport.com — www.everycrsreport.com
- Audit of Protection of DoD Controlled Unclassified Information on Contractor-Owned Networks and Systems DODIG-2019-105 > Department of War > DoW OIG Reports — www.dodig.mil
- Department of Defense Impact Level 6 - Azure Compliance | Microsoft Learn — learn.microsoft.com
- Data Pillar — www.nsa.gov
- Palantir Federal Cloud Service – Supporting Services (PFCS-SS) | FedRAMP Marketplace — www.fedramp.gov
- Department of Defense Releases Zero Trust Strategy and Roadmap > U.S. Department of War > Release | U.S. Department of War — www.war.gov
- Palantir FedStart and the FedRAMP Path | BD Emerson — www.bdemerson.com
- [2510.09494] The Data Enclave Advantage: A New Paradigm for Least-Privileged Data Access in a Zero-Trust World — arxiv.org
- Software-defined perimeter - Wikipedia — en.wikipedia.org
Published · Reporting as of