Reading time: about 9 minutes
If you join the defence supply chain, sooner or later you will handle classified data, and that changes the rules for using AI. The short answer is that public AI is out by definition, not out of caution. Classified information may not be processed in a system without security accreditation, and no public model has that accreditation or can obtain it. This is not a matter of a better privacy policy or a pricier licence. It is a requirement of the classified-information law that you either meet or you drop out of the contract. This piece shows what each of the four Polish clearance clauses means for an AI system, what certificate the company itself must hold, and where to start. A starting point that reveals nothing is a 10-minute readiness mini-audit.
Why this is now a subcontractor's problem, not just a prime's
Poland plans to spend 4.8% of GDP on defence in 2026, a record of about 200 billion zloty, and is already the largest relative defence spender in NATO (Notes from Poland, 2025). That flow does not stop at a handful of large arms plants. It cascades down to hundreds of subcontractors: machining shops, electronics, part makers working to a drawing, service firms and IT integrators.
The moment a mid-sized manufacturer starts making a part to a drawing marked with a clause is the moment it comes under the classified-information regime. A technical drawing, a specification, correspondence about parameters: if they carry a clause, they are classified information and follow the same rules as a document in a registry office. For a company that used to think about AI like any manufacturer, that is, "I'll drop the spec into a model to speed up the quote", this is a hard wall. The same operation that in a civilian plant is merely a shadow AI risk is, on classified data, a breach of the law.
The four clauses and what they mean for an AI system
Polish law defines four classification clauses: "restricted", "confidential", "secret" and "top secret". Whether a given IT system may process information of a particular clause is decided by ICT security accreditation, set out in chapter 8 of the Classified Information Protection Act.
The line falls at one crucial place. A system meant to process "restricted" information is accredited by the head of the organisation, by approving the security documentation (art. 48(9)). But a system for "confidential" information or higher is accredited solely by the ABW or the SKW, confirmed by an ICT system security accreditation certificate (art. 48(3) and (5)), issued for a fixed term of no more than 5 years (art. 48(2)). On top of that comes documentation: a special security requirements document with a risk assessment, and secure operation procedures (art. 49).
For an AI system this has a simple but merciless consequence: a model that is to work on classified data must be part of the accredited system. Not "connected to", not "integrated with", but covered by the same accreditation. The table below shows what each clause forces.
| Data clause | Who accredits the system | What the company must hold | Public cloud AI |
|---|---|---|---|
| Restricted | Head of the organisation, by approving documentation | Security documentation, a controlled environment | Excluded |
| Confidential | ABW or SKW, accreditation certificate (up to 5 years) | Industrial security certificate, security docs and procedures | Excluded |
| Secret | ABW or SKW, higher requirements and zones | Industrial certificate, personnel clearances | Excluded |
| Top secret | ABW or SKW, strictest requirements and isolation | Full regime, strict access control | Excluded |
The right-hand column never changes, and that is the whole point. There is no clause at which a public cloud model becomes admissible. What changes is only how strict the regime is on the system you are allowed to build on your own premises.
Classified data has to stay inside an accredited system. The path out to a public model is closed by definition.
Industrial security certificate: what the company must hold
Accreditation covers the system, but to process information of "confidential" clause or higher under a contract at all, the company itself must hold an industrial security certificate, issued by the ABW or the SKW. And here is the detail that decides whether AI on classified data is even possible for you.
The certificate comes in three degrees. First degree confirms full capability to protect classified information, including processing it in the company's own IT systems. Second degree confirms capability but excludes processing in the company's own IT systems. Third degree excludes processing even on the company's premises. In other words: an AI system running on your hardware and processing classified data requires a first-degree certificate. A company with a second-degree certificate can be in the supply chain, but it will not process classified information in its own IT, and therefore will not run local AI on that data.
Validity matters too. A certificate for "top secret" is valid for 5 years, for "secret" 7 years, and for "confidential" 10 years. The degrees are not tied to a specific clause; they are two separate axes: the degree says how deeply the company may process, the clause how sensitive the data is. For "restricted" an industrial certificate is usually not required, but the system still has to be accredited internally.
Why public AI is out by definition
Put plainly: classified information may be processed only in a system with valid accreditation. A public cloud model neither has nor will obtain an accreditation certificate from the ABW or the SKW, because it is not a system under your control whose documentation and configuration can be assessed. Add the jurisdiction issue: data in a foreign provider's cloud is subject to foreign law, including mechanisms such as the US CLOUD Act, which for classified information is irreconcilable with the requirement to retain control over access.
That barrier does not disappear with a pricier licence. A public vendor's enterprise tier improves the contract and logical isolation, but the data still leaves your perimeter and lands in a system that holds no Polish ICT security accreditation. In the eyes of the law that is still moving classified information outside a system authorised to process it. Price does not change the classification.
What AI on classified data has to satisfy
The way the industry approaches AI on classified information comes down to a handful of requirements that must be met together, not selectively:
- Full locality. The model and the data run on accredited hardware, in an isolated environment, with no connection to a public API. The model weights are on site, not behind an external interface.
- An accredited system, not a bolt-on. The AI is part of a system described in the special security requirements document and covered by secure operation procedures, not a service wired alongside it.
- Access control and clearances. Only people with the right personnel security clearance, and after training, may reach classified data, and the system enforces and records this.
- An audit trail. Who accessed what and when must be reconstructable from logs on your side, because you answer to the inspection.
- The ability to freeze state. Model and stack versions are controlled and reproducible on your side, without changes imposed from outside on a vendor's schedule.
These are architecture requirements, not marketing features. By their nature only a local deployment, on your own infrastructure, designed for accreditation from the start, satisfies them. For the wider case of when such a deployment makes sense beyond defence, see on-prem AI in manufacturing: when it fits, and when it doesn't.
Where to start
Before you talk tools, it is worth sorting out four things. First, establish which clauses will actually appear in your contracts, because the whole regime follows from that. Second, check whether and which degree of industrial security certificate you will need, and how long it takes to obtain, because that is months, not days. Third, map which processes you genuinely want AI to support and whether they touch classified data, or whether the classified part can be separated from the unclassified one. Fourth, only then design the system, so that accreditation is a design assumption rather than a later patch.
If you want to start with a rough readiness check that reveals nothing sensitive, the readiness mini-audit takes 10 minutes and leaves no data behind. For more on how to think about sovereignty and vendor control in procurement, see Poland's sovereignty test and AI vendors, and our view of the sector is on the AI for defence page.
If you would rather talk through a specific case, 30 minutes with a founder is no pitch and no request for anything classified, just a conversation about what the path to an accreditable deployment looks like.
Frequently asked questions
What is classified data in the defence supply chain?
It is classified information marked with one of four clauses: "restricted", "confidential", "secret" or "top secret". In the supply chain it most often appears as technical drawings, specifications and correspondence about product parameters. The clause, not the topic, is what makes a document subject to classified-information protection.
Can I use ChatGPT or Copilot for classified data?
No. Classified information may be processed only in a system with valid ICT security accreditation, and a public cloud model has no such accreditation and will not obtain one. This applies to enterprise tiers too, because the data still leaves the accredited perimeter.
Who accredits an AI system for processing classified information?
A system for the "restricted" clause is accredited by the head of the organisation, by approving the documentation. A system for "confidential" or higher is accredited by the ABW or the SKW, which issues an accreditation certificate valid for no more than 5 years.
What certificate does a company need to run local AI on classified data?
To process information from the "confidential" clause upward in its own IT systems, a company needs a first-degree industrial security certificate. Second and third degree exclude processing in the company's own IT, so they will not allow local AI on that data.
Where do I start preparing?
Start by establishing which clauses will appear in your contracts and checking which degree of certificate you will need and how long it takes to get. Only then design the system, so that accreditation is a design assumption from the outset rather than a later fix.
