GATEKEEPER Sierra-Alpha Contact
Soldiers at ruggedised computers inside a command post Human in the Loop — the phrase shown partly obscured by a field of vertical bars

Sierra-Alpha · Concept study · Dual-use · Munich

GATEKEEPERHardwired edge AI for ethical weapons release

A dedicated edge-AI building block that acts as an incorruptible gatekeeper: it enforces human release authority in hardware before any effector can be engaged, and delivers a real-time, AI-based damage forecast so that a proportionate, IHL-compliant decision remains possible under extreme stress.

HITL enforced in hardware CDE at the tactical edge Designed against AOP-52 §4.1.11

01 The problem

Release decisions in a fraction of a second, without a reliable basis

Employing weapons in military engagements and in high-risk police operations demands decisions within a fraction of a second. Four deficits compound one another.

  1. 01

    Autonomy risks

    Software-driven autonomous systems (LAWS) carry the risk of erroneous escalation, emergent AI behaviour, or manipulation through cyber attack. The EU AI Act explicitly names data poisoning, model poisoning, adversarial examples and model evasion as attack classes.

  2. 02

    Situational awareness under stress

    In complex environments — urban warfare, densely populated areas — the human operator under extreme stress often lacks the situational awareness needed to grasp the consequences of a release.

  3. 03

    Unclear proportionality

    If it remains open what collateral damage would be caused to people, to critical infrastructure or to cultural property, the result is either unlawful engagements or operational paralysis. Doctrine itself concedes that collateral damage estimates are perishable and do not capture unknown transient personnel.

  4. 04

    Blurred accountability

    Where AI can bypass the human in the loop at the software level, accountability under international law becomes diffuse. One documented case: a release-bypass doctrine that remained active after reverting to tactical mode and could only be corrected by changing the computer programs.

Sources: DDG 51 Class Advisory 02-92; CJCSI 3160.01; Regulation (EU) 2024/1689.

02 The solution

Two inseparable functions on an isolated hardware layer

The human makes the final decision — the module ensures that decision rests on transparently computed consequences, and that without it no circuit to the effector is ever closed.

Gloved hand on a physical arming switch

A · Gatekeeper

The incorruptible gatekeeper

It physically enforces human-in-the-loop release before the circuit to an effector is closed. Release is a positive act: no authenticated release, no circuit. The resting state is de-energised.

  • Authorisation cryptographically bound to device and firmware
  • No software path to override the interlock
  • Withdrawing the arming signal returns the system to the unarmed state
Macro shot of the ruggedised hardware module with visible relay interrupters

B · Evaluator

The intelligent evaluator

Before a "go" can be given, the module processes sensor data from electro-optics, radar and lidar in real time and returns an immediate, visualised damage forecast — in milliseconds rather than minutes.

  • Collateral damage forecast for people, critical infrastructure and cultural property
  • Fall trajectories and debris footprint for kinetic intercepts
  • Continuous re-assessment instead of a single snapshot
A weapon selector lever resting on the S position for safe, with the A position for armed beside it. A silicon die is etched into the receiver below the pivot, connected to it by a conductor trace, above a trigger and trigger guard.
Safe by default The selector rests on S. Inference runs continuously in the die below the pivot and feeds the gate, but it cannot move the lever: the path from silicon to firing circuit is broken by design, and only an authenticated human act closes it. A is reachable — never automatic.

03 How it works

The signal chain from sensor to physical interlock

Five stages. The act of release sits between forecast and effector — not beside it.

01

Sensors

Electro-optics, radar, lidar, RF. Multi-sensor fusion as the input layer.

02

Edge inference / CDE

Collateral damage forecast and fall trajectory, on board, in the millisecond range.

03

Visualised forecast

Graduated risk display, designed to counter automation bias.

04

Authenticated human release

A positive, device-bound signed act of release. Without it, the chain ends here.

05

Physical interlock to the effector

Two independent energy interrupters in the firing circuit. De-energised as the default state.

The interlock override is deliberately not placed under the control of any computing system — see regulatory tailwind.

04 Applications

Three channels, one release mechanism

The need extends beyond purely military scenarios. For the civil and law-enforcement variant, a separately placed-on-the-market product line is foreseen.

Quadruped robot and unmanned ground vehicle with a soldier operating a tablet

Channel 01

Defence & multi-domain operations

Integration into the weapons of main battle tanks, air defence, UAV/UCAV and unmanned ground systems built by major prime contractors. The interlock partitions the assurance problem: a frequently retrained AI function is bounded by a rarely changed, certified monitor.

Laser effector engaging a drone over a city at night

Channel 02

Counter-UAS in urban areas & critical infrastructure

Protecting airports, energy infrastructure and metropolitan areas. Predicting fall and debris scenarios secures the proportionality of an intercept — kinetic, laser or jammer.

Aerial view of a city under a cyan protective dome

Channel 03

Homeland security & police

Special operations units and border security, where lethal and non-lethal means alike must withstand the strictest legal scrutiny. Signed release and forecast logs generate exactly the records Art. 12 of the EU AI Act requires.

05 Market environment

Moderate in volume, unambiguous in demand dynamics

All figures are taken from the accompanying market study. Publisher spreads in this segment are considerable; absolute levels are indicative, growth rates more robust.

6.64 → 20.31

USD bn · global counter-UAS, 2025 → 2030

MarketsandMarkets · CAGR 25.1%

0.9 → 6.2

USD bn · AI-enabled C-UAS, 2025 → 2030

MarketsandMarkets Outlook 2030 · CAGR 48.7%

≈ 16

EUR bn · German counter-drone investment through the end of the decade

tagesschau/NDR, 16 June 2026

≈ 188

USD m · Germany, counter-drone systems for critical infrastructure, 2026

Fortune Business Insights, 2026

226 / 145

Drone incidents in German aviation, full-year 2025 / first half of 2026

DLR, 3 June 2026 · Zeit, 15 July 2026

32 – 80

EUR m · cumulative SOM for a module supplier through 2033 (EUR 8–15 m annual run rate)

Market study, bottom-up from unit volumes

Counter-UAS: total market and AI-enabled sub-segment, 2025 → 2030

Published data points for 2025 and 2030 only — no interpolated intermediate years.

Source: MarketsandMarkets, Counter-UAS Systems Market and MarketsandMarkets, C-UAS Outlook 2030. The publisher spread for the same nominal market in the same year runs up to 6.6×; a single publisher is deliberately shown here.

Demand drivers in Germany and the EU

In 2025, 226 drone incidents were reported in German civil aviation, 116 of them involving full or partial closures at 25 commercial airports, with minimum damage of around EUR 60 m and up to EUR 160 m including network effects (DLR). A further 145 disruptions to air traffic followed in the first half of 2026, 90 per cent of them in the airport environment (Zeit); the Federal Criminal Police Office recorded more than 1,000 suspicious drone flights over Germany in 2025 (DW). On the budget side stand the Bundeswehr drone action plan with roughly EUR 16 bn through the end of the decade (tagesschau/NDR) and a Federal Police counter-drone unit with more than 130 posts and over EUR 100 m for 2025 and 2026 (Table.Media). At EU level, the Action Plan on Drone and Counter-Drone Security published on 11 February 2026 names Horizon Europe, EDF, EDIP and SAFE as funding channels (DG DEFIS), while the European Drone Defence Initiative is backed by EUR 6 bn and Eastern Flank Watch is to reach full operational capability by the end of 2028 (EPRS).

06 Regulatory tailwind

The certification grammar for this approach already exists

Four independent regimes make purely software-side enforcement either non-compliant, harder to evidence, or ineligible for funding.

Regulatory anchors and their implication for a hardware approach
Standard / legal actSpecific anchorWhy this argues for hardware
AOP-52 Ed. B v1
STANAG 4452 §4.1.11
"The override of the interlocks shall not be controlled by a computing system." In addition, §4.5.4/4.5.5 require a safety kernel in non-overwritable memory that cannot be corrupted, misdirected, delayed or inhibited by any other program. For the override function, a software solution is not compliant with the alliance standard applied by the national NSAA. No certified silicon or C-UAS vendor references this standard.
MIL-STD-1901A §5.2.3.2 At least two independent energy interrupters, each controlled by its own safety feature; withdrawing the arming signal automatically returns the firing circuit to the unarmed state. This describes the gatekeeper architecture almost verbatim. Two interrupters are a physical construct, not a logical one.
EDF Regulation (EU) 2021/697
Art. 10(6)
Actions for the development of lethal autonomous weapons "without the possibility for meaningful human control" are ineligible for funding — explicitly without prejudice to early-warning systems and defensive countermeasures. The word "possibility" is operative: a switchable software HITL is a weaker answer before an independent ethics assessor than a gate whose absent override path can be demonstrated analytically. That makes the module an eligibility enabler rather than a compliance cost.
EU AI Act (EU) 2024/1689
Art. 2(3), Recital 24
Art. 2(3) fully exempts systems placed on the market exclusively for military, defence or national security purposes; Recital 24 pulls in any system also placed on the market for civil or law-enforcement purposes. Two separately marketed product lines instead of a single SKU is a design decision, not a legal footnote. It is built into the concept from the outset.
EU AI Act
Art. 12 / 14 / 15
Automatic event logging (Art. 12), a stop function returning the system to a safe state and awareness of automation bias (Art. 14), robustness against data and model poisoning plus technical redundancy (Art. 15). For the police variant this maps almost mechanically: the inhibit line as the stop into a safe state, signed release logs as logging, the independent safety island as the second channel.
DoDD 3000.09
(reissued 25 Jan 2023)
Requires appropriate levels of human judgement over the use of force, explicitly names supply-chain infiltration as a failure class, and at the same time calls for rapid reprogrammability of autonomy algorithms. Reprogrammability is operationally necessary and hostile to assurance. The hardware monitor resolves the contradiction by bounding the unassured function — precisely the pattern ASTM F3269-21 legitimises for run-time assurance.

Primary sources: AOP-52 Ed. B v1, MIL-STD-1901A, Regulation (EU) 2021/697, Regulation (EU) 2024/1689, DoDD 3000.09.

07 White space in the market

The core capability is unoccupied in the public product space

Finding of the market study across 36 manufacturer and C-UAS pages plus 30 silicon, IP and rugged-computing pages.

  1. A

    No vendor publicly documents a hardware-side firing-circuit interlock

    Every documented HITL mechanism sits at the software or C2 workflow level: a release in the operator UI, a mode switch in a battle management application, a keystroke, or a doctrinal setting. The strongest published formulation in the market is decision support, not a physical gate.

  2. B

    Market communication runs in the opposite direction

    Leading vendors position an "autonomous shooter", a "fully automated chain of action" as an alternative to man-in-the-loop, decision support "to minimise the operator's role", and swarm interception "with no human involvement". Hardware-enforced HITL is therefore both a white space and a market-education task.

  3. C

    No CDE tool operates in real time at the tactical edge

    The fastest documented runtime in the entire corpus is five to ten minutes for a Bugsplat run, against at least four hours when reaching back to an analysis centre. That is three to four orders of magnitude beyond what a C-UAS engagement timeline allows. CDE remains a discipline of certified analysts with reach-back connectivity.

  4. D

    Debris and fall-trajectory prediction for urban intercepts is the cleanest unoccupied field

    It is absent from every manufacturer product, every CDE tool and the peer-reviewed literature. Civil ground-risk modelling for UAVs is transferable. A credible third party adds that a collateral damage estimate remains a snapshot and that there is no standard procedure to verify whether anything has changed since.

Sources: Seattle Times, 26 Feb 2003; CNA, February 2022; BAE Systems; Rheinmetall; Hensoldt; Thales.

08 Team & unfair advantage

Operational field experience, dual-use ecosystem, procurement literacy

Founder · Initiator

Arne Eilers

Munich


  • Lieutenant Colonel (Reserve), multi-domain operations
  • Working at BASED, a European defence and dual-use platform

Credibility in this highly regulated market rests not on technical expertise alone but on operational understanding. Experience as a Lieutenant Colonel in the reserve in multi-domain operations demonstrates a deep grasp of tactical decision processes under stress and of the demands of real deployment scenarios. Combined with access to the European dual-use ecosystem and an understanding of complex military procurement, this creates a moat against purely technology-driven teams.

Status of the venture

The venture is at concept and application stage. There is no company, no pilot contract and no capital raised to date. We are looking for:

  • Technical co-founders — chip design and FPGA, in particular safety-island and root-of-trust architectures on certifiable COTS components.
  • Safety certification expertise — DO-254, MIL-STD-882E, AOP-52 evidence towards a national munitions safety authority.
  • Pilot partners — airport operators, public-sector requirement owners in critical infrastructure protection, and research partners for sensor fusion, effects modelling and trusted execution.

09 Contact

A conversation about technology, certification or piloting

For investors, programme managers, funding bodies and prospective co-founders. The full market study — competitive mapping, patent landscape, market figures, regulation and red-team analysis — is available on request.


Market study on request · English or German · Munich, European Union