The apparent conflict arrives quickly: one July 2026 directive tells defense supply chain teams to use AI to find vulnerabilities, bottlenecks, and single points of failure; the NDAA tells contractors that certain AI cannot be used at all. Read carelessly, that sounds like a mandate colliding with a ban. Read as a contracting workflow, it is more direct: use AI, but be able to prove where the AI came from, what it depends on, who controls it, and whether it is excluded from the Covered AI restriction.
The July 20, 2026 Executive Order says the “Department of War” shall use artificial intelligence to assist in identifying vulnerabilities, bottlenecks, and single points of failure in the defense supply chain, and it also requires contractors to produce indentured Bills of Materials tracing components to raw material origin.[1] The FY2026 NDAA’s Section 1532, as described in January 2026 analyses of the enacted law, prohibits Department of Defense contractors from using Covered AI developed by DeepSeek, High Flyer, or entities domiciled in or subject to foreign control from China, Russia, North Korea, or Iran, with coverage extending to 20% indirect ownership and “successor AI.”[2][3]

That is not an instruction to choose between supply chain illumination and AI exclusion. It is an instruction to make the illumination defensible. A contractor that uses AI to map a supplier network but cannot document model provenance, API dependencies, dataset sources, ownership exposure, or successor-tool continuity has solved the visibility problem while creating a contract compliance problem.
The Controlling Workflow Is Bigger Than Tool Selection
The first mistake is to treat the EO as a supply chain operations item and the NDAA as an IT security item. Inside a defense industrial base company, the same bid, renewal, subcontract review, or government data call will eventually pull both threads into one file. The supply chain team will be asked what the supplier network looks like. The contracts team will be asked what was certified. The security team will be asked what tools touched controlled or sensitive data. Procurement will be asked whether a supplier, parent, beneficial owner, or manufacturing source changes the answer.
The practical sequence is not complicated, but it is unforgiving:
| Compliance Action | What It Produces | Why It Matters |
|---|---|---|
| Use AI-assisted supply chain mapping | A structured view of suppliers, dependencies, bottlenecks, and single points of failure | The EO makes AI-assisted vulnerability identification a directive, not a mere innovation option |
| Build the indentured Bill of Materials | Component-level lineage down to raw material origin | The supply chain map must be traceable enough to support procurement and contract review |
| Vet mapped entities and dependencies | Financial, foreign ownership/control/influence, and manufacturing/supply risk findings | The EO identifies these categories as required vetting dimensions |
| Verify AI provenance | Evidence that models, datasets, APIs, ownership chains, and successor tools do not create Covered AI exposure | The NDAA ban applies to the AI stack used to perform the work |
| Prepare for CMMC-for-AI alignment | A certification-ready control file for AI supply chain security | The NDAA directs the AI security framework toward implementation as an extension or augmentation of CMMC |
The table looks linear because audits prefer linear artifacts. In practice, these steps feed each other. A Bill of Materials can expose a supplier requiring deeper ownership review. A supplier data source can reveal that an AI enrichment vendor relies on an API dependency that has to be screened. A model replacement can raise the successor AI question even if the front-end application name has not changed.
The EO Turns Visibility Into a Production Data Obligation
An ordinary supplier list will not carry this burden. The EO’s indentured Bill of Materials requirement pushes the contractor toward a layered data structure: end item, assemblies, subassemblies, components, subcomponents, materials, and raw material origin.[1] That matters because AI-assisted mapping is only useful if the records it ingests can be reconciled back to contract, purchasing, engineering, and supplier representations.
The word “indentured” should change how companies assign the work. This is not just a dashboard exercise. Someone has to decide how supplier names are normalized, how subsidiaries are linked, how part numbers connect to purchase orders, how manufacturing locations are distinguished from corporate headquarters, and how raw material origin is captured when the prime does not buy the material directly. AI can accelerate matching, clustering, anomaly detection, and dependency discovery, but it does not remove the need for a record that a contracting officer, auditor, or internal certifier can follow.
The EO also identifies three risk-vetting categories: financial, foreign ownership/control/influence, and manufacturing/supply.[1] Those categories belong in the workflow at the start, not as after-the-fact labels. If a supply chain model flags a fragile sole-source supplier but the underlying file cannot support a foreign control review, the work is incomplete for this environment. If the model detects concentration in a manufacturing geography but the company cannot tie the finding to specific assemblies or raw material dependencies, the visibility may be interesting without being contract-useful.
The NDAA Makes the AI Stack Part of the Supply Chain
Section 1532 changes the compliance question from “Does this AI tool work?” to “Can we use this AI tool in covered defense work?” The ban described in the January 2026 analyses is not limited to a named model sitting visibly in a user interface. It reaches AI developed by specified companies, entities domiciled in or subject to foreign control from named countries, ownership chains reaching 20% indirect ownership, and successor AI.[2][3]
That breadth is why a simple vendor questionnaire will not be enough for higher-risk uses. A contractor using AI to illuminate its supply chain has to look at the application, embedded models, fine-tuning sources, third-party APIs, hosted inference providers, data enrichment vendors, ownership structure, and replacement models introduced during product updates. The successor AI language is especially operationally important because it prevents compliance from freezing at the name of a tool on the day it was approved.

For a government contracts lead, the hard part is not writing “no Covered AI” into a policy. The hard part is knowing what evidence supports the statement six months later, after a vendor has changed a model endpoint, acquired a data provider, replaced a subcontracted development team, or added a new enrichment source. In this setting, provenance is not a procurement preference. It is the documentary bridge between the EO’s AI mandate and the NDAA’s exclusion rule.
What a usable provenance file should cover
- The AI application name, vendor, version, deployment environment, and approved defense supply chain use case.
- The model developer, model family, hosted inference provider, fine-tuning arrangement, and any embedded or downstream model dependencies.
- Dataset and enrichment sources used for supplier matching, ownership screening, risk scoring, entity resolution, and raw material tracing.
- Ownership and control review for the AI vendor, material subcontractors, API providers, and relevant parent or investor structures.
- Change-control evidence showing how model replacements, product updates, acquisitions, and successor tools are reviewed before continued use.
- Contract mapping showing which programs, solicitations, subcontracts, or data environments the tool is allowed to touch.
This file should not live only with IT security. It should be usable by contracts, supply chain, procurement, and the business owner of the AI-enabled mapping process. The person signing or supporting a contract certification needs the record in the language of permitted use, excluded use, supplier exposure, and version control.
DLA Shows Feasibility, Not a Safe Benchmark
The Defense Logistics Agency is the useful precedent here because it shows that government-facing AI supply chain work is already operational, not theoretical. DLA reporting in March 2025 described an AI Center of Excellence with more than 55 production models, including Bid Data Analytics that screened 43,000 vendors and flagged more than 19,000 high-risk suppliers.[5] A November 2025 Nextgov/FCW interview with DLA’s chief information officer referenced the same 55-model and 200-use-case figures, but did not update them.[6]
Those numbers are best treated as directional proof of concept. They show the scale of AI deployment the government already considers feasible in defense logistics, but they should not be converted into a 2026 benchmark for contractor maturity. A prime contractor with a different supplier base, different technical data rights, different subcontract flowdowns, and different commercial tool stack cannot borrow DLA’s count of models as evidence that its own process is ready.
The better lesson is narrower and more useful: AI-assisted supplier screening can operate at meaningful scale in the defense logistics environment. That supports the EO’s premise that AI can help identify supply chain risk. It does not answer whether a contractor’s chosen model, dataset, enrichment provider, or ownership chain survives the NDAA’s Covered AI review.
Waiver Timing Moves the Work Into FY2026
The January 1, 2027 waiver shift is the calendar item that should keep this from becoming a late-2026 paperwork scramble. King & Spalding’s January 2026 analysis states that waivers under 10 U.S.C. 4872 will effectively end on January 1, 2027, except where contractors submit formal mitigation plans with strict timelines, creating an 18-month window for supply chain transformation.[3]
That date does not mean every contractor will have final agency procedure in hand before it has to act. It means the company should be able to show a controlled transition: which AI tools are in use, which tools are barred from covered work, which uses are still under review, which suppliers are being remediated, and which mitigation plans have owners and dates. A contractor waiting for final CMMC-for-AI details before inventorying its AI stack is preserving ambiguity in the one place auditors are least likely to reward it.
CMMC-for-AI Is Not Final, but the Direction Is Clear
The NDAA directs the AI security framework toward implementation as an “extension or augmentation” of CMMC, according to Freshfields and WilmerHale analyses.[2][4] That is an enforcement path, not a complete procedure. Contractors should not describe current controls as certified under a final CMMC-for-AI regime before rulemaking exists. They can, however, prepare the artifacts that such a regime is likely to test: inventory, access control, provenance, supplier review, system change management, incident handling, and contract scoping.
The distinction matters. Overstating certainty creates its own compliance risk. A company can say it is aligning its AI supply chain controls to the NDAA-directed CMMC extension path. It should be more careful about claiming that it has met final CMMC-for-AI requirements before those requirements are issued.

For FY2026 planning, the control design should already assume that AI used for defense supply chain logistics will be examined in the same practical way other contract-sensitive systems are examined: what is it, who approved it, what data does it touch, what dependencies does it have, what changed, and what evidence supports continued use. The CMMC-for-AI path simply gives that examination a likely certification channel.
Questions Contractors Should Resolve Before the Next Bid or Renewal
The most useful readiness exercise is not a general AI strategy workshop. It is a contract-facing reconciliation meeting with supply chain, procurement, IT security, legal, and program operations in the same room. The agenda should follow the audit trail.
- Which AI tools are currently used to identify suppliers, score supplier risk, enrich entity records, trace materials, summarize supplier disclosures, or prepare supply chain reports?
- Which of those tools touch defense contract data, controlled technical information, supplier proprietary data, or information used in a certification?
- Can each tool be tied to a current provenance file covering model origin, dataset sources, APIs, ownership/control review, and successor-tool monitoring?
- Can the company produce an indentured Bill of Materials at the depth required for the relevant program, including raw material origin where required?
- Are financial risk, foreign ownership/control/influence risk, and manufacturing/supply risk captured as separate review fields rather than blended into a generic supplier score?
- Do contracts and procurement teams know which AI tools and data sources are prohibited from use in covered defense work?
The answer does not have to be perfect on the first pass. It does have to be owned. A supply chain illumination program that cannot name its AI dependencies is not ready to carry an NDAA representation. An AI governance inventory that does not connect tools to supplier mapping, Bill of Materials construction, and risk vetting is not ready to satisfy the EO’s operational demand.
Where Ambiguity Still Matters
There are still unresolved implementation questions. The EO uses “Department of War,” a naming convention contractors should verify against their own contracting chain before copying into internal procedure.[1] Earlier commentary on House and Senate NDAA drafts is less useful than the January 2026 analyses addressing the final enacted version, especially for Section 1532 details.[2][3] The CMMC-for-AI extension has direction but not final rule text.[2][4]
Those uncertainties justify monitoring, not delay. Contractors do not need final rulemaking to inventory AI tools. They do not need agency FAQs to separate approved AI uses from prohibited or unreviewed uses. They do not need a final assessment guide to preserve evidence showing who developed a model, what data sources it uses, which APIs it calls, and whether a supplier-risk result can be traced back to records that procurement and contracts can defend.
The safer FY2026-FY2027 posture is to treat the EO and NDAA as one funnel. Use AI to map the defense supply chain. Build the indentured Bill of Materials with enough structure to survive review. Vet financial, foreign ownership/control/influence, and manufacturing/supply risk as distinct categories. Then prove that the AI used to perform that work is not Covered AI, is governed through change control, and is ready to be placed into the emerging CMMC-for-AI certification path.
References
- Securing America’s Defense Supply Chains and Ensuring Domestic Acquisition of Critical Materials, The White House, July 20, 2026.
- AI Supply Chain and Security analysis, Freshfields, January 2026.
- FY 2026 NDAA analysis, King & Spalding, January 2026.
- What the NDAA Means for AI and Cybersecurity, WilmerHale, December 2025.
- DLA.mil news articles on AI Center of Excellence and Bid Data Analytics, DLA.mil, March 2025.
- Interview with CIO Roberts, Nextgov/FCW, November 2025.
Comments
Join the discussion with an anonymous comment.