JSP 936 has been mandatory in Defence since November 2024, yet MOD's own October 2025 implementation review confirms most organisations are still at a foundational stage. The gap isn't awareness of the regulation. It's understanding what independent AI ethical assurance actually requires. Platform vendors can't provide it.


The Regulation That Rewrote the Rules

In November 2024, the Ministry of Defence published JSP 936 (Dependable Artificial Intelligence in Defence), v1.1. It is not guidance. It is not a framework organisations can choose to adopt. It is a directive, mandatory on all MOD component organisations, that flows to every contractor and AI developer operating within the Defence AI supply chain.

JSP 936 requires three things of every organisation deploying AI in a Defence context.

A Responsible AI Senior Officer (RAISO) must be nominated. This is a named, accountable individual, not a governance committee, not a policy team, not an AI strategy document. A person responsible for ensuring AI systems operate within JSP 936's requirements.

Statements of AI Ethical Assurance must be produced. Not once. At each deployment milestone. Covering all AI-enabled systems. Auditable. Independent.

An Independent Ethics Assurance Mechanism must be established for large, high-ethics-risk programmes. The independence requirement is precise: the assurance cannot be provided by the same organisation that built or runs the AI system.


Five Principles. One Gap.

JSP 936 defines five mandatory ethical principles that every AI system must demonstrate compliance with:

  1. Human-Centricity: AI supports human decision-making; it does not replace it.
  2. Responsibility: Accountability is clear from AI recommendation to operational decision.
  3. Understanding: AI outputs can be explained to operators, managers and auditors.
  4. Bias and Harm Mitigation: Systematic error and discriminatory outcomes have been identified and addressed.
  5. Reliability: AI performance is monitored, drift is tracked, and thresholds are maintained over time.

Each principle requires evidence. Not a policy statement that an organisation values human oversight, but documented proof that specific AI outputs, in their operational context, satisfy each principle. And that proof must be produced by someone independent of the system that generated those outputs.


What MOD's Own Review Found

In October 2025, the "Laying the Groundwork" RAISO Report, the first MOD-wide review of JSP 936 implementation, was published. Its findings were candid.

Implementation is at a foundational and formative stage. The groundwork is being laid, but gaps remain, specifically in skills, data management and governance integration. The current framework relies heavily on self-reporting and internal reviews.

This is 11 months after JSP 936 came into force.

The report does not name programmes or suppliers. But the implication is clear: most Defence AI implementations do not yet have a functioning, independent AI ethical assurance process in place.


The Gap Most Suppliers Are Missing

The AI governance market in Defence has moved quickly. Platform vendors now offer governance tooling. IBM's watsonx.governance covers EU AI Act and ISO 42001 compliance, provides AI Factsheets, and monitors model drift. These are real capabilities.

But watsonx.governance is IBM's assurance of IBM's platform. The same logic applies to any platform vendor's governance layer. Self-assurance of the platform that hosts the AI cannot satisfy JSP 936's independence requirement, no matter how mature the tooling. Platform-level compliance and independent programme-level assurance are two different things. Neither can satisfy JSP 936's independence requirement for the MOD-wide programme assurance statements that each in-scope organisation must produce. An AI vendor self-certifying the ethical compliance of its own AI outputs is not what JSP 936 means by independence.

This is the gap most Defence AI suppliers are missing, not because they don't take governance seriously, but because platform-level compliance and independent programme-level assurance are two different things. The first is the vendor's responsibility. The second belongs to an organisation with no stake in the platform outcome.


What Good Looks Like

For large AI-enabled programmes, particularly those deploying predictive maintenance, condition monitoring or agentic AI on safety-critical assets, JSP 936 compliance requires a structured, recurring process:

  • An independent third party maps each AI capability against the five ethical principles
  • Evidence is produced at each Minimum Deployable Capability (MDC) gate, not as a one-off exercise at programme inception
  • That evidence is auditable: traceable, version-controlled, defensible in a RAISO review
  • The process repeats as the programme evolves, covering new capabilities as they are deployed

This is not a light-touch governance overlay. It is a programme-lifecycle commitment. And for most current Defence AI deployments, it is not yet in place.


The Window Is Open. It Will Not Stay Open.

JSP 936 is mandatory now. The RAISO function is being built across MOD. The Defence AI Centre's assurance framework, including the AI Model Arena for independent model evaluation, is operational. As this infrastructure matures, the window for ad hoc compliance closes.

The 2025 Strategic Defence Review commits MOD to an accelerated shift towards AI and autonomy across all domains. Every major MOD organisation has now appointed a RAISO. The UK AI Action Plan targets 10 million workers upskilled in AI by 2030, a target that extends directly into Defence workforce planning. The governance architecture is being built at pace, and the suppliers operating within it will be expected to keep up. The capability gap is sharpest where the assurance provider cannot be offshore. SC-cleared practitioners on shore are increasingly a procurement precondition, not an upgrade.

The question for every programme deploying AI in Defence is not whether JSP 936 applies. It does. The question is whether the independent assurance mechanism is in place, and if not, who is going to build it before the window closes. Programmes that establish that architecture now will have a defensible compliance position as scrutiny grows. Those that wait will be retrofitting governance under time pressure.

If the RAISO asked tonight, who is producing our next Statement of AI Ethical Assurance, and from which side of the vendor boundary, would the answer be defensible?


Next 90 days for programme directors

  • Identify whether the current assurance provider has a commercial or delivery stake in the platform being assured. If they do, the assurance does not satisfy JSP 936's independence requirement.
  • Commission the first Statement of AI Ethical Assurance against a live Minimum Deployable Capability gate, not against contract award. The recurring evidence trail starts with a working programme milestone.
  • Stand up the Independent Ethics Assurance Mechanism before the governance architecture matures. Retrofitting assurance into a live deployment costs more and defends less than building it in from the next gate.

Key Takeaways

  • JSP 936 has been mandatory since November 2024 and applies to all MOD component organisations and their supply chains
  • Three core requirements: RAISO nomination, auditable Statements of AI Ethical Assurance, Independent Ethics Assurance Mechanism for large programmes
  • MOD's October 2025 RAISO Report confirmed implementation is still at a foundational stage, with gaps in skills, data management and governance integration
  • Platform-level governance (watsonx.governance, ISO 42001) does not satisfy JSP 936's independence requirement for programme-level assurance statements
  • Assurance evidence must be produced at each programme milestone, recurring, auditable, independent, not once at contract award

Brainwave Asset Intelligence advises Defence and regulated sector organisations on AI governance, data readiness, and enterprise asset management. Our SAFE-AI Control Framework maps directly against JSP 936's five ethical principles for AI deployments on enterprise asset management, IWMS and CAFM platforms, platform-agnostic and independent of the delivery vendor. Brainwave Asset Intelligence delivers with SC-cleared practitioners on shore, a capability unavailable through offshore-delivered advisory models and increasingly a precondition of sensitive Defence AI engagements.

Follow Brainwave Asset Intelligence for regulated sector intelligence.


Sources and further reading


LinkedIn Post

JSP 936 has been mandatory in Defence since November 2024.

MOD's own implementation review, published October 2025, found that most organisations are still at a foundational stage.

That is 11 months after the regulation came into force.

JSP 936 requires every MOD component organisation to nominate a Responsible AI Senior Officer, produce auditable Statements of AI Ethical Assurance and establish an Independent Ethics Assurance Mechanism for large programmes.

The independence requirement is specific. An AI vendor cannot independently assure its own AI outputs. That responsibility sits with a third party who has no stake in the platform outcome.

For programmes deploying predictive maintenance, agentic AI or AI-driven condition monitoring on safety-critical Defence assets, this is not a future compliance requirement. It is a current one.

The question every programme director should be asking: is our independent assurance mechanism in place?

If the answer is uncertain, that is the gap JSP 936 was designed to close. This is the work Brainwave Asset Intelligence exists to do. Follow for more or message directly to discuss your programme.

→ Our latest article covers what JSP 936 requires, what MOD's own review found, and what independent AI ethical assurance actually looks like in practice.


Twitter / X Thread

Tweet 1 (hook): JSP 936 has been mandatory in UK Defence since November 2024.

MOD's own implementation review, published 11 months later, found most organisations still at a foundational stage.

Here's what the regulation actually requires, and why most Defence AI suppliers can't satisfy it. 🧵

Tweet 2: JSP 936 (Dependable AI in Defence) is a directive, not guidance.

It applies to every MOD component organisation and flows to every contractor and AI developer in the Defence supply chain.

No opt-out.

Tweet 3: Three mandatory requirements:

(1) A named Responsible AI Senior Officer, a person, not a committee

(2) Auditable Statements of AI Ethical Assurance at each deployment milestone

(3) An Independent Ethics Assurance Mechanism for large, high-ethics-risk programmes

Tweet 4: Five ethical principles must be evidenced:

→ Human-Centricity → Responsibility → Understanding → Bias & Harm Mitigation → Reliability

Not stated as policy. Evidenced. Independently. At each programme gate.

Tweet 5: The independence requirement is where most suppliers fall short.

Platform governance tooling is excellent, but a platform vendor cannot independently assure its own AI outputs.

The assurance must come from outside the delivery team. That's what "independent" means.

Tweet 6: October 2025 RAISO Report confirmed: implementation is still foundational across MOD.

Gaps in skills, data management and governance integration.

Most current Defence AI deployments do not yet have a functioning independent assurance process.

Tweet 7: For large programmes deploying predictive maintenance, agentic AI or AI-driven condition monitoring, this is a current, recurring requirement. Not a future one.

JSP 936 evidence must be produced at each Minimum Deployable Capability gate throughout the programme lifecycle.

Tweet 8: The window for building this architecture properly is now.

As MOD's AI governance infrastructure matures, retrofitting compliance into live deployments under time pressure will be far harder and more expensive.

The question: is your independent assurance mechanism in place?

Full article: [link]