EU AI Act Article 50 live 2 Aug 2026 — C2PA passport ready | Get yours →
DEFONEOS × MOD × DI

MOD Defence Intelligence AI Deep-Dive Pack

Sovereign AI governance of UK MOD Defence Intelligence — military intelligence assessment, threat analysis, open-source intelligence (OSINT) fusion, Five Eyes interoperability, counter-intelligence, geospatial intelligence (GEOINT). 12 entry points × 8 transformation priorities × 6 MCPs. Audit-grade. Signed. UK-sovereign.

12
Entry Points
8
Transformation Priorities
6
MCP Servers
6
Red Lines

📋 12 Entry Points

Threat Assessment

Threat Assessment — Priority Intelligence Requirements

PIR-driven intelligence cycle. Threat actor profiling — state, non-state, hybrid. Capability and intent assessment. Indicators and warnings (I&W). Centre of gravity analysis. Red team/alternative analysis. Intelligence preparation of the battlefield (IPB). Modelling and simulation. Scenario planning. Threat evolution tracking.

OSINT

Open-Source Intelligence — Collection, Verification, Fusion

OSINT collection from public sources — media, social, academic, commercial. Verification and confidence scoring. Multi-source fusion. Automated collection pipelines. Geospatial tagging. Temporal analysis. Attribution confidence. Linguistic analysis. Dark web monitoring. OSINT-to-classified integration pathway. GCHQ/NCA cooperation.

GEOINT

Geospatial Intelligence — Satellite, Mapping, Terrain

Satellite imagery analysis — commercial and classified. Terrain modelling. Change detection. Facility monitoring. Order of battle mapping. Maritime domain awareness. Air defence network mapping. Infrastructure vulnerability assessment. Digital elevation models. Integration with Dstl geospatial tools. AUKUS GEOINT sharing.

SIGINT

Signals Intelligence — Communications, Electronic, Cyber

Communications intelligence (COMINT). Electronic intelligence (ELINT). Cyber intelligence. Signal characterisation. Emitter geolocation. Network analysis. Encryption assessment. GCHQ partnership. Five Eyes SIGINT sharing. Legal authorisation framework — IPA 2016. Bulk data powers oversight. Warrant management.

Counter-Intelligence

Counter-Intelligence — Insider Threat, Espionage, Sabotage

Insider threat programme. Personnel security vetting — DBS, SC, DV. Anomalous behaviour detection. Counter-espionage. Counter-sabotage. Security compromise assessment. MoD security policy enforcement. Protective security — physical, personnel, cyber. Threat from hostile intelligence services (HIS). MI5 coordination.

Five Eyes

Five Eyes Interoperability — US, CA, AU, NZ, UK

FVEY intelligence sharing agreements. Classification and handling — UK EYES ONLY, FVEY, NATO. Releasability rules. Technical interoperability — STANAG, NITF. Joint intelligence centres. Combined analysis. AUKUS Pillar II technology sharing. UKUSA Agreement compliance. Caveat management. Allied intelligence fusion.

HUMINT

Human Intelligence — Source Operations, Agent Handling

Source recruitment and handling. Agent running. Clandestine reporting. Source validation. Agent welfare. Risk assessment for agent operations. SIS coordination. DI HUMINT support to military operations. Human terrain analysis. Cultural intelligence. Interrogation (lawful). Detainee intelligence exploitation. J2 operations.

MASINT

Measurement and Signature Intelligence

Technical collection — radar, acoustic, seismic, nuclear, chemical, biological. Signature databases. Weapons testing detection. Environmental monitoring. Nuclear detonation detection. Missile telemetry. Underwater acoustics. Dstl MASINT support. Five Eyes MASINT fusion. AUKUS advanced sensing cooperation.

Disinformation

Disinformation and Influence — MDM, Info Ops, Narrative

Misinformation, disinformation, and malinformation (MDM) detection. State-sponsored influence campaigns. Social media manipulation. Narrative analysis. Attribution of hostile influence. Counter-narrative operations. Media monitoring. Strategic communications support. Information operations (InfoOps). Cognitive warfare assessment. DSIT coordination.

Production

Intelligence Production — Assessment, Briefing, Dissemination

Intelligence assessment and synthesis. Analytical confidence grading. Key judgements. Strategic assessments — JIC. Operational intelligence briefings. Tactical intelligence products. Time-sensitive intelligence (TSINT). Dissemination management — need-to-know, releasability. Intelligence cycle management. Quality assurance. RED TEAM challenge.

Data

Data Governance — Classification, Handling, Audit

Classification management — OFFICIAL, SECRET, TOP SECRET. Handling restrictions. Data-at-rest encryption. Data-in-transit protection. Audit trail management. Information management policy. Access control — need-to-know, clearances. Legacy data migration. Cross-domain solution management. Data retention and destruction. GDPR exemption status for intelligence.

Parliamentary

Parliamentary Oversight — ISC, Ministerial, Accountability

Intelligence and Security Committee (ISC) oversight. Ministerial accountability. Annual report contributions. Special adviser briefings. Written ministerial statements. FOIA exemption — s.23, s.24. Investigatory Powers Commissioner oversight. Tribunal proceedings. Public interest immunity. War crimes investigations. ICC cooperation.

⚡ 8 Transformation Priorities

1. AI-Assisted OSINT Fusion

Automated OSINT collection and triage — NLP extraction, entity resolution, confidence scoring. Multi-source fusion engine. Cross-lingual analysis for 50+ languages. Social network graph analysis. Temporal pattern detection. Anomaly alerting. Analyst-in-the-loop validation. Target: 10x OSINT processing throughput, 80% reduction in analyst time on collection/processing vs analysis.

2. GEOINT Automation

AI-powered satellite imagery analysis — object detection, change detection, facility monitoring. Automated order-of-battle updates. Terrain analysis automation. Maritime anomaly detection. Air defence network mapping. Integration with commercial satellite constellations (Maxar, Planet, BlackSky). Target: Daily automated GEOINT reports for 200+ priority sites, change detection within 4 hours of imagery collection.

3. Threat Prediction Engine

Predictive threat modelling — capability development trajectories, intent indicators, I&W pattern recognition. Scenario generation from geopolitical signals. Early warning automation. Red team AI. Alternative analysis generation. Confidence calibration. Target: 72-hour advance warning for 80% of geopolitical crises, automated PIR fulfilment for routine requirements.

4. Insider Threat Analytics

Anomalous behaviour detection — access patterns, data movement, communication anomalies. Personnel security risk scoring. Continuous evaluation replacing periodic review. Privacy-preserving analytics. False positive reduction. Human-in-the-loop adjudication. Target: 90% detection of insider threat indicators before compromise, 50% reduction in false positive investigations.

5. Disinformation Defence

Real-time MDM detection — bot network identification, narrative tracking, source attribution. Automated counter-narrative generation. Influence campaign mapping. Social media monitoring at scale. Cognitive warfare indicators. Interagency coordination with DSIT, FCDO, Home Office. Target: MDM detection within 2 hours of campaign launch, automated attribution confidence above 75%.

6. Cross-Domain Intelligence Sharing

Secure cross-domain solution — SECRET to OFFICIAL sanitisation automation. Releasability management — FVEY, NATO, AUKUS, bilateral. Automated classification review. Caveat enforcement. Technical interoperability with allied systems (STANAG compliance). Target: Automated sanitisation of 60% of intelligence products for broader dissemination, classification review time from days to hours.

7. Analyst Augmentation

AI co-pilot for intelligence analysts — automated briefing preparation, evidence synthesis, confidence assessment. Hypothesis testing support. Link analysis automation. Pattern of life analysis. Document exploitation (DOMEX) automation. Target: Analyst productivity doubled — analysis time per assessment reduced 50%, briefing preparation automated for routine products.

8. Parliamentary Intelligence Assurance

Automated ISC reporting — intelligence activity summaries, legal compliance metrics, oversight evidence packs. Ministerial briefing generation. FOIA exemption evidence. IPCO compliance tracking. Public interest immunity preparation. Target: Quarterly automated ISC evidence packs, real-time legal compliance dashboard for ministerial oversight.

🔧 6 MCP Servers

OSINT

mod-di-osint-mcp

Open-source intelligence collection pipeline — media monitoring, social media, academic, commercial databases. NLP entity extraction. Cross-lingual processing. Confidence scoring. Source reliability assessment. Geospatial tagging. Temporal analysis. Dark web monitoring. Verification workflow. OSINT-to-classified pipeline integration.

GEOINT

mod-di-geoint-mcp

Satellite imagery analysis — object detection, classification, change detection. Terrain modelling. Order-of-battle mapping. Maritime domain awareness. Facility monitoring. Digital elevation model management. Commercial satellite integration (Maxar, Planet). Automated reporting. Multi-sensor fusion. Historical imagery comparison.

Threat

mod-di-threat-mcp

Threat assessment engine — PIR management, capability/intent analysis. Indicators and warnings pattern recognition. Threat actor profiling. Scenario generation. Red team alternative analysis. Predictive modelling. Centre of gravity assessment. Threat evolution tracking. Intelligence preparation of the battlefield. Confidence calibration.

Counter-Intel

mod-di-counter-intel-mcp

Insider threat detection — access pattern analysis, data movement monitoring, communication anomaly flagging. Personnel security risk scoring. Continuous evaluation workflow. Counter-espionage indicators. Security compromise assessment. Vetting status tracking. Anomalous behaviour reporting. MI5 coordination interface.

Production

mod-di-production-mcp

Intelligence assessment authoring — structured analytical techniques, confidence grading, key judgements. Briefing preparation automation. Dissemination management — releasability, classification, caveat. Quality assurance workflow. RED TEAM challenge integration. Time-sensitive intelligence routing. Multi-format output — PDF, HTML, secure message.

Analytics

mod-di-analytics-mcp

Intelligence cycle metrics — collection gap analysis, analytical production rates, PIR fulfilment tracking. Analyst workload monitoring. OSINT processing throughput. GEOINT coverage assessment. Threat assessment frequency. Dissemination timeliness. ISC reporting metrics. Five Eyes contribution rates. Quality assurance scores.

🚫 Red Lines (Never Crossed)

🤝 5-Step Engagement Model

1
Discovery: Map Defence Intelligence analytical production pipeline. Assess OSINT collection capacity. Benchmark GEOINT processing throughput. Profile Five Eyes interoperability requirements. Identify analyst workload bottlenecks. Map classification and dissemination workflows.
2
Governance Design: Deploy DEFONEOS MCP servers for Defence Intelligence. Configure OSINT fusion, GEOINT automation, threat assessment engines. Establish cross-domain sharing workflow. Design counter-intelligence analytics framework. Integrate with GCHQ SIGINT and SIS HUMINT pipelines.
3
Pilot: 90-day pilot across DI analytical teams and Joint Intelligence Centre. Measure analyst productivity, OSINT processing throughput, assessment quality. Collect analyst, commander, and oversight feedback. Benchmark against current DI production capacity.
4
Scale: Roll out across Defence Intelligence. Integrate FVEY/AUKUS sharing systems, GCHQ SIGINT, SIS HUMINT. Deploy across all service intelligence branches (Naval, Army, Air Force). Parliamentary reporting integration. ISC oversight automation.
5
Assure: Continuous audit-grade intelligence governance. Real-time production monitoring. Collection gap analysis. Analyst workload balancing. Parliamentary evidence generation. IPCO compliance tracking. Annual intelligence effectiveness evaluation.
DEFONEOS OWEM RFQ | Article 50 Passport