The Short Answer
DoW Instruction 8430.01, "Accelerated Mission Software," was signed August 31 and took effect September 8, 2026. It bars non-public department information from any generative AI service that does not reside on DoW information systems and is not approved β a hosting rule, not only a training rule. It sets no "days, not years" deadline. With ibl.ai you own all the code and the data, so the platform runs inside your perimeter.
The instruction is being summarized as a training-data restriction with a speed mandate attached. Both halves are looser than the document.
What is DoWI 8430.01, and when did it actually take effect?
It is a 37-page instruction from the Office of the DoW Chief Information Officer, approved August 31, 2026 by DoW Chief Information Officer Kirsten A. Davies, effective September 8, 2026.
Two naming points matter before anything else.
It is a DoW instruction, not a DoD one. Executive Order 14347, signed September 5, 2025, authorized "Department of War" as a secondary title; Department of Defense remains the statutory name, since only Congress can change it.
And it is an instruction β policy with assigned responsibilities and procedures β not a memo or a directive. It applies across the software lifecycle to acquisition and non-acquisition programs regardless of dollar value.
One scope carve-out is easy to miss. Software funded under Budget Activities 1 through 4 β basic research through advanced component development and prototyping β is excluded until it transitions into acquisition or operational use.
Much of its weight sits on evidence. Software on department networks must be backed by machine-readable evidence of component composition, build integrity and application security, which travels with the code as a deliverable.
Software factories are directed to share that evidence so authorizing officials can grant reciprocity, rather than repeating an assessment another organization already performed.
The phrase people are quoting is verbatim, in the Purpose: the issuance establishes policy for software management "to maximize lethality in an era of software-defined warfare."
It is also not new this week. DefenseScoop covered it on September 14, and Air & Space Forces Magazine the same day.
Does DoWI 8430.01 really require commercial solutions first?
Not in that order. The priority sequence is more specific, and for an AI vendor it is the more interesting fact.
Paragraph 1.2.a.(4) directs components to "Prioritize using existing software, components, frameworks, and platforms; open-source software; and commercial-off-the-shelf (COTS) and software-as-a-service (SaaS) solutions before developing or acquiring new capabilities."
Reuse comes first. Open source comes before commercial. Section 2 is blunter still: "leverage freely licensed open-source software before buying commercially supported open source or proprietary offerings."
Where "commercial solutions" does appear is in contracting. Paragraph 3.8.a.(2) makes Commercial Solutions Openings and Other Transactions the default solicitation approaches for the software acquisition pathway β a vehicle preference, not a build-versus-buy preference.
The same paragraph attaches a condition vendors should read twice: "Sufficient intellectual property and data rights are required to enable long-term operation, maintenance, modification, and cybersecurity of DoW software capabilities."
That is a rights requirement, not a hosting arrangement. It composes with the instruction's treatment of software and its artifacts "as enterprise assets, not program-specific property," and with the reuse mandate under Public Law 118-187.
It also establishes a DoW Enterprise Digital Arsenal and directs components to default to enterprise reuse.
The rights clause is scoped to operation, maintenance and modification β not inspection, not escrow. Those are the three verbs a vendor's absence would otherwise block.
A repository is only useful if the government also holds the build instructions, dependencies, test data and configuration history needed to act on what it finds. That is the difference between possessing a copy of the code and operating it without the original vendor.
How does DoWI 8430.01 connect to the SHARE IT Act?
8430.01 is an implementation step for a statute that is already two years old.
The SHARE IT Act, Public Law 118-187, was signed on December 23, 2024.
It requires agencies to store custom-developed code and key technical artifacts in repositories, make them discoverable to federal employees, and secure sufficient rights for government-wide access, reuse and modification.
The law set the obligation. The instruction tells defense programs how to meet it, which is why its rights language names operation and modification rather than gesturing at "access."
Buyers reading the rights clause as a 2026 development are a cycle late. The contracting posture changed in 2024, and 8430.01 is the enforcement mechanism arriving.
What does DoWI 8430.01 say about generative AI and non-public data?
Paragraph 3.6.b.(1) is the one that changes vendor architecture, and its actual wording is stricter than the shorthand circulating about it.
Non-public DoW information β "including code, configuration scripts, infrastructure definitions, schematics, or documentation" β "may not be entered into or processed by generative AI applications or services unless those applications or services reside on DoW information systems and are approved for useβ¦"
The test is where the service runs. Not whether the vendor promises to discard the prompt, and not whether the model is fine-tuned on it.
The no-training guarantee is a separate, additional requirement, in 3.6.d.
Approved AI applications must "Provide contractual guarantees that government data and user prompts are not shared or used for training any public or DoW-external models," and must "Allow for auditing and monitoring of their use by designated authorities."
So the popular framing β non-public data banned from external AI models β collapses two requirements into the weaker one. A zero-retention contract on a vendor-hosted endpoint does not satisfy 3.6.b.(1), because the service still does not reside on department systems.
Two further provisions land on the same vendors. AI-generated code "will be considered unverified input," and its use "does not absolve the developer or the government of responsibility for the resulting work product."
Human review is mandatory at the sharp end. Components must "implement a risk-based review that, at a minimum, requires human review and approval for AI-generated changes to security- or safety-critical functionality."
And teams must record the "models, versions, and significant datasets used to generate or test software," in an evidence package "analogous to the SBOM" β model provenance a closed managed service cannot always produce.
Does DoWI 8430.01 set a "days, not years" delivery deadline?
No. The instruction contains no numeric delivery interval β not days, not weeks, not months.
What it does instead is structural, and more binding than a slogan.
Paragraph 3.8.a.(1) makes the software acquisition pathway established in DoDI 5000.87 "the DoW's preferred process for the rapid and iterative delivery of software capabilities," and directs programs to use it "as the preferred pathway for all DoW software acquisition."
Components must "Operate secure, automated CI/CD pipelines," treating those pipelines "as critical infrastructure that must be authorized, monitored, and protected." Section 3 requires "frequent deployment of working software as the primary mechanism for refining requirements."
The "days, not years" number appears to come from commentary rather than the document.
Rise8 CEO Bryon Kroger, quoted by Air & Space Forces Magazine, argues for updates "multiple times a day" β an industry position on where the department should get to, not a requirement it has imposed.
What does DoWI 8430.01 mean for AI vendors selling to defense?
The qualification line moved from contractual to architectural, and it will move the same way for the regulated buyers who follow defense procurement.
A vendor can now hold a perfect data-processing agreement β zero retention, no training, full audit rights β and still be unable to touch non-public DoW code, schematics or infrastructure definitions, because the service does not run on department systems.
This is the same conclusion the department reached from a different direction.
Pentagon chief digital and AI officer Cameron Stanley has described the approach as pursuing multiple LLMs into "the appropriate government-owned environments" β the context behind why Claude was pulled from sensitive work for two unrelated reasons.
Read together, the posture is consistent: run the model where the government controls the environment, and keep enough rights to operate and modify the software afterwards.
For anyone selling into this, the qualifying checklist is short:
- The platform installs and runs entirely inside the customer's accreditation boundary.
- The customer can substitute a different model without a vendor change order.
- The deployment can produce the model-and-dataset record 3.6.f asks for.
- The customer can read the code that handles the data.
That is what sovereign AI for regulated organizations frames as data, model and operational sovereignty. DoWI 8430.01 is the first issuance we have seen require all three in one document.
Is the Pentagon requiring model independence from AI vendors?
Not in this instruction. The posture exists, but it comes from a different place, and conflating the two produces a claim that does not survive checking.
In May 2026 the department expanded its classified AI work to eight companies amid a dispute with one of the major model providers.
On May 7, 2026, Under Secretary of War for Research and Engineering Emil Michael said the department would "never again β¦ be single-threaded with any one model".
That is a stated procurement posture from a named official. It is not a clause in 8430.01, and a proposal that cites it as one is citing the wrong document.
It is still the clearest evidence of why concentration risk is a live procurement concern. A dispute between a department and one provider became an availability problem because the dependency was singular.
What should a government AI buyer ask a vendor after DoWI 8430.01?
Six questions, each tied to a paragraph the buyer can quote in a solicitation. None of them is a preference; each restates something the instruction already requires.
| Question | Clause | What a compliant answer looks like |
|---|---|---|
| Where does the service itself reside? | 3.6.b.(1) | The application or service runs on DoW information systems and is approved for use in accordance with DoDI 8500.01 and DoDI 8582.01 β not a remote endpoint with a good retention policy. |
| Is the no-training term contractual, and is use auditable? | 3.6.d | A contractual guarantee that government data and prompts are not shared or used to train any public or DoW-external model, plus auditing and monitoring of use by designated authorities. |
| Can you produce the model and dataset record? | 3.6.f | A maintained record of models, versions and significant datasets used to generate or test software, delivered inside the software evidence package, analogous to the SBOM. |
| What intellectual property and data rights come with the award? | 3.8.a.(2) | Rights sufficient to enable long-term operation, maintenance, modification and cybersecurity of the capability β named in the contract, not implied by a support plan. |
| Is what you deliver reusable beyond this program? | 3.2.f.(1)β(2) | Software and its artifacts treated as enterprise assets, not program-specific property, with source code, documentation, APIs, schemas and SBOMs discoverable and reusable with unlimited rights, or government purpose rights as a second alternative. |
| Where does this offer sit in the priority order? | 1.2.a.(4) | An honest placement against reuse existing software, open source, or COTS and SaaS before building new. |
Two of these get answered badly often enough to be worth flagging.
The residency question gets answered with a retention policy. Paragraph 3.6.b.(1) does not ask what happens to the prompt afterwards. It asks where the application or service resides.
The reuse question gets answered with an integration roadmap. Paragraph 3.2.f.(2) asks for something narrower and harder to retrofit: the artifacts themselves, discoverable and reusable across the department, with the rights attached.
It is also worth reading 3.6.b.(1) as two conditions rather than one. The service has to reside on DoW information systems, and it has to be approved for use under DoDI 8500.01 and DoDI 8582.01.
A vendor that can install inside the boundary has answered the first half. The authorization is still work the program has to do, and a deployment that makes that work harder is a real cost to weigh.
One more clause sets the tone for the whole list. Paragraph 3.6.a.(2) says AI-generated code "will be considered unverified input," and that using it "does not absolve the developer or the government of responsibility for the resulting work product."
Accountability does not transfer with the subscription. That is why these six questions ask for evidence a buyer can hold and inspect, rather than assurances a vendor can restate.
What is not on the list matters as much. The instruction does not require model independence, source code delivery from a vendor under a perpetual license, a transcript of every AI interaction, or PIV/CAC authentication.
Those four requirements appear in circulating summaries. Searched against the 37-page text, none of them is in it β 3.6.d asks that use be auditable and monitorable, which is a weaker and more specific thing than a per-interaction audit trail.
An independent analysis of the instruction reaches the same conclusion: it addresses neither sovereign AI, on-premise specifics, nor model independence.
Asking only for what 8430.01 says makes the evaluation shorter and the answers checkable.
Why does a per-seat hosted AI subscription struggle with DoWI 8430.01?
Because 3.6.b.(1) tests where the service resides, and a vendor-hosted subscription resides on the vendor's systems by construction.
That is a fact about the deployment model, not a complaint about any particular product's terms.
A per-seat AI subscription can carry zero retention, no training on customer data, and full audit rights, and still fail the residency test. None of those terms move the service onto DoW information systems.
It is worth being exact about what such terms do satisfy, because the two requirements are constantly collapsed into one.
A zero-retention endpoint with audit rights can meet 3.6.d: the contractual guarantee that government data and user prompts are not shared or used for training public or DoW-external models, and the allowance for auditing and monitoring of use by designated authorities.
But 3.6.d is a condition on services that are already approved. 3.6.b.(1) is what decides whether non-public information may go into them at all. Clearing the second does not clear the first.
The licence shape runs into a different paragraph. 3.7.b.(3) directs components to "meter usage, reconcile entitlements to deployments, remediate over- and under-licensing, plan and fund true-ups, reharvest unused licenses, and rationalize duplicative products."
Per-seat subscriptions are the object that paragraph was written about. Seats bought and not used are exactly the waste it exists to recover, and headcount-priced AI generates them faster than most software does.
3.2.f.(1) adds the structural version of the same point: treat software and its artifacts "as enterprise assets, not program-specific property." A subscription scoped to one program's roster is program-specific spend, and it does not become an enterprise asset when the next program needs it.
None of this bans SaaS. Paragraph 1.2.a.(4) lists SaaS among the things to prefer over building new.
Paragraph 3.7.b.(4) then sets out how to buy it β FedRAMP authorization appropriate to the information impact level, government data rights, export in non-proprietary formats, and termination and exit assistance.
The constraint is narrower and sharper than "no SaaS." Commercial SaaS is available to the department right up to the moment non-public DoW information has to go into it.
How does ibl.ai deploy for defense and regulated buyers?
By putting the whole platform inside the customer's boundary, which is what 3.6.b.(1) now demands.
With ibl.ai you own all the code and the data.
The platform ships as full source code under a perpetual license and runs on the customer's own infrastructure, so prompts and non-public artifacts never leave the accreditation boundary.
It is model-agnostic across any LLM and switchable without re-platforming, usage-based with no per-seat pricing, and it can deploy anywhere β your own cloud, on-premise, GovCloud, or a fully air-gapped network with no outbound connectivity.
For government deployments the architecture is configurable for IL4/IL5 workloads, supports NIST 800-53 controls across the stack, and binds authentication to PIV/CAC.
The auditing requirement in 3.6.d is met by inspection rather than assurance: the code that handles the data is yours to read. 1.6M+ users across 400+ organizations run the platform this way, including NVIDIA, MIT, and Syracuse University.
ibl.ai is family-owned and operated from New York, NY.
Related reading: sovereign AI, defined for regulated organizations β the data, model and operational sovereignty framing this instruction now requires in one document Β· why Claude was pulled from sensitive work for two unrelated reasons β the migration that preceded it Β· why federal agencies need sovereign AI infrastructure β the same architecture argument across civilian agencies Β· how sovereign AI became procurement policy in France and Nigeria β the same lesson abroad: sovereignty is decided in the contract, not the press release.
Sources: all quoted paragraph text from DoW Instruction 8430.01, "Accelerated Mission Software," effective September 8, 2026; the August 31 approval by Kirsten A. Davies and the AI-assisted development provisions also via DefenseScoop, September 14, 2026; the reuse and cadence context and the Bryon Kroger quote from Air & Space Forces Magazine, September 14, 2026; the SHARE IT Act's signing date and obligations from Morrison Foerster; the eight-company expansion from DefenseScoop, May 1, 2026 and the Emil Michael quote from Defense One; the secondary-title status of "Department of War" from Executive Order 14347, September 5, 2025.