NDAA Section 1513 and the Physical Security of AI: The 2026 Standards-Compliance Briefing on the DoD AI/ML Security Framework, the DFARS and CMMC Integration, and What “CMMC for AI” Means for Physical Security Buyers
The first federal statute to fold the physical security of AI/ML into defense procurement, routed through DFARS and CMMC, and what it means for physical security AI buyers and vendors.
For the first time, a federal statute folds the physical security of artificial intelligence into defense procurement law. Section 1513 of the FY2026 National Defense Authorization Act directs the Department of Defense to build an AI/ML security framework and wire it into DFARS and CMMC. Three numbers frame what changed.
The phrase that should stop every physical security AI buyer is four words long, and it is buried in the text of the year's defense policy law: "cybersecurity and physical security." Section 1513 of the National Defense Authorization Act for Fiscal Year 2026 directs the Department of Defense to develop a framework addressing the cybersecurity and physical security of the artificial intelligence and machine learning technologies the Pentagon acquires, and then to fold that framework into the Defense Federal Acquisition Regulation Supplement (DFARS) and the Cybersecurity Maturity Model Certification (CMMC) program. It is the first time a federal statute has treated the integrity of an AI model itself as a procurement-grade security requirement, on par with the way the government already protects controlled unclassified information.
This briefing is written for security directors, procurement officers, and AI vendors who need to understand what Section 1513 actually says, why a defense-acquisition provision matters far beyond the defense industrial base, and how the convergence of model security and physical security reshapes the questions buyers will ask before signing a multi-year contract. The reasoning that DoD applies to a targeting model or a logistics model applies with equal force to a computer vision model watching a perimeter. When the government decides that the data an AI was trained on, the weights it carries, and the supply chain it traveled through are security-relevant, that decision does not stay inside the wire.
What Section 1513 actually requires
Section 1513 is short, but it is structurally significant because it converts a set of AI security concepts that have lived in voluntary frameworks into a procurement mandate. The provision instructs the Department of Defense to develop and maintain a framework that addresses the security of AI and machine learning systems acquired by the department, and it is explicit that the framework must cover both the cybersecurity and the physical security of those systems. According to the FY2026 NDAA text and the Congressional Research Service analysis of the cyber and AI provisions in the FY2026 NDAA, the framework carries several defining features.
It applies to "covered" AI/ML and all of its components. The statute defines the protected object broadly. It is not just the running application. It is the source code, the model weights, and the methods, algorithms, data, and software used to develop the AI/ML. In other words, Section 1513 treats the training pipeline as part of the attack surface, not merely the deployed inference endpoint. For a physical security vendor, that means the dataset used to teach a model what a firearm looks like is itself now a security-relevant artifact in the eyes of the government's most influential buyer.
It targets the specific failure modes of machine learning. The framework is designed to address AI/ML-specific risks: data poisoning, where attackers contaminate the training data so a model misclassifies, generates biased output, or carries a hidden trigger; adversarial tampering, where attackers deliberately compromise hardware, software, data, or processes; and unintentional data exposure, where sensitive data leaks through misconfiguration or handling errors. These are not generic IT risks. They are the threat surface that is unique to systems that learn.
It is built on existing standards, not invented from scratch. The framework is to be informed by established cybersecurity standards, including the NIST Special Publication 800 series, and must be implemented as an extension or augmentation of existing DoD cybersecurity frameworks, including CMMC. This is the connective tissue that links Section 1513 to the documentation architecture IntelliSee has covered previously in its NIST AI Risk Management Framework briefing. The government is not asking vendors to learn a new vocabulary. It is asking them to apply the vocabulary they should already know to a new object: the model.
It carries a near-term reporting deadline. Section 1513 does not impose an implementation deadline on the framework itself, but it instructs DoD to create a plan establishing implementation timelines and milestones, and to provide a status update to Congress by June 16, 2026. That date is the first observable signal of how fast this moves. The history here is instructive: CMMC began as a provision in the FY2020 NDAA and took roughly five years to finalize, only recently coming into effect across the defense industrial base. Many contractors found themselves unprepared even with that long runway. Section 1513 starts the same clock for AI/ML.
A model is not just software. It is a supply chain.
Most AI security discussion fixates on cybersecurity: prompt injection, model exfiltration, network hardening. Section 1513 deliberately adds physical security alongside it, and the addition is not rhetorical. Model weights live on physical media. Training data moves through physical facilities and human hands. Inference appliances sit in physical racks that can be accessed, swapped, or tampered with. An adversary who cannot breach the network may still be able to corrupt the training pipeline at a contractor's facility, substitute a poisoned model file during transit, or compromise the edge device where inference runs. By naming physical security explicitly, Congress signaled that the integrity of an AI system depends on controls that reach all the way down to the room where the hardware lives. For physical security AI vendors specifically, this is a striking inversion: the technology that protects the room is now itself subject to the question of who can access the room it runs in.
"CMMC for AI": how a procurement framework becomes a market standard
The reason Section 1513 matters to buyers who will never sell to the Pentagon is the mechanism it uses. By directing DoD to amend DFARS and to augment CMMC, Section 1513 routes its requirements through the single most consequential procurement lever in the United States. CMMC is a unified assessment model for defense contractors handling regulated data; it was finalized in autumn 2025 and is expected to apply to the entire defense industrial base. Bolting AI/ML security requirements onto that structure means that any entity developing, deploying, storing, or hosting covered AI/ML for DoD becomes a "covered entity" obligated to implement the framework's best practices.
The downstream effect is what analysts have started calling, half as shorthand and half as warning, "CMMC for AI." Given the size and scope of DoD procurement, contracting provisions like this routinely escape the national-security sector and become de facto commercial standards. The pattern is well established. NDAA Section 889's camera supply-chain prohibitions, which IntelliSee analyzed in its Section 889 supply-chain compliance briefing, started as a federal acquisition rule and rapidly became a procurement baseline that hospitals, universities, and commercial property operators now apply to their own camera purchases regardless of whether they hold a single federal contract. The same gravitational pull operates here. Once DoD requires model-provenance documentation, dataset-integrity attestation, and adversarial-robustness evidence from AI vendors, those expectations will migrate into commercial RFPs, insurance underwriting questionnaires, and enterprise vendor-risk reviews.
There is a built-in friction that buyers should understand. The statute requires DoD, when creating new DFARS regulations, to conduct a cost-benefit exercise weighing the benefit of new security requirements against the cost of slowing AI/ML development and deployment. That balancing test is the reason the framework is not instantaneous, and it is also the reason vendors have a window to get ahead of it. The requirements that survive the cost-benefit analysis will be the durable ones, and they are knowable in advance because they map to risks that already have NIST guidance behind them.
How Section 1513 travels from defense policy law to your next RFP
The five-stage path by which an AI/ML security mandate becomes a de facto commercial standard.
FY2026 NDAA Section 1513 mandates a DoD framework for the cybersecurity and physical security of acquired AI/ML.
DoD builds the framework on the NIST SP 800 series as an augmentation of CMMC. Status update due to Congress June 16, 2026.
Framework amended into DFARS and folded into CMMC. "Covered entities" must implement it to win DoD AI/ML work.
As with Section 889, requirements escape defense and become baseline expectations in commercial and critical-infrastructure buying.
Model provenance, dataset integrity, and adversarial-robustness evidence become standard line items in vendor evaluation.
The executive order that arrived the same month
Section 1513 did not land in isolation. On June 2, 2026, the President signed Executive Order 14409, "Promoting Advanced Artificial Intelligence Innovation and Security," published in the Federal Register on June 5, 2026 (91 FR 34565). Read alongside Section 1513, the executive order reveals a coordinated federal posture: the legislative branch is hardening AI procurement, and the executive branch is hardening AI deployment, and both are doing it on the same timeline.
The order's operative provisions are worth reading precisely because they show where the government draws its lines. It directs the Committee on National Security Systems and the Department of War to prioritize cyber defense of their information systems within 30 days. It instructs the Department of Homeland Security, through CISA, to issue Binding Operational Directives that expedite cyber defense of civilian federal systems and extend defensive tooling to operators of critical infrastructure, naming rural hospitals, community banks, and local utilities specifically. It creates an AI cybersecurity clearinghouse under the Treasury to coordinate vulnerability scanning and patch distribution in voluntary collaboration with industry.
The order's centerpiece, in Section 3, establishes a voluntary framework under which AI developers may submit models to determine whether they meet the threshold of a "covered frontier model," and, if so, provide the federal government with access for up to 30 days before release to other trusted partners. Critically, Section 3(c) bars the order from being construed to authorize any mandatory governmental licensing, preclearance, or permitting requirement for developing or releasing AI models. The architecture is voluntary by design. That distinction matters: where Section 1513 uses procurement leverage to make AI security effectively mandatory for anyone who wants DoD business, EO 14409 uses incentives and access to encourage frontier developers to cooperate without a licensing regime.
The convergence point for physical security buyers. Most physical security AI vendors do not build frontier models, so EO 14409's frontier-model provisions will not bind them directly. But the order's emphasis on supply-chain integrity, vulnerability coordination, and critical-infrastructure protection sets the policy weather. Combined with Section 1513's procurement teeth, it establishes a federal expectation that AI systems deployed in consequential environments carry demonstrable security provenance. A computer vision platform protecting a substation, a federal building, or a defense contractor's facility now operates inside that expectation whether or not it ever submits a model to NSA.
What model-security requirements mean for physical security AI specifically
Physical security AI occupies an unusual position in this landscape. It is not frontier AI, and most of it never touches a classified system. But it is AI that makes consequential, real-time decisions in physical environments, and it is increasingly procured by exactly the buyers Section 1513 and EO 14409 are designed to protect: defense contractors, critical-infrastructure operators, and federal facilities. That makes the model-integrity question concrete rather than abstract.
Consider the three statutory failure modes through the lens of a computer vision detection platform. Data poisoning is not a theoretical risk for a model trained to recognize weapons; an adversary who could corrupt the training set could, in principle, teach a model to systematically miss a particular firearm configuration or to misfire on benign objects, degrading the very capability the buyer paid for. Adversarial tampering reaches the inference appliance itself, the physical box where detection runs, which is why the platform's deployment architecture, whether inference happens on a hardened on-premises appliance or in an opaque cloud, becomes a security question and not just a latency question. Unintentional data exposure is where the privacy-by-design architecture pays a compliance dividend: a platform that performs no facial recognition, stores no video, and collects no protected information has a dramatically smaller exposure surface than one that retains identifiable footage.
This is the throughline connecting Section 1513 to IntelliSee's prior vendor due-diligence analysis: the questions a sophisticated buyer should already be asking about a vendor's claims and platform risk are the same questions Section 1513 will eventually formalize as procurement requirements. The buyers who treat model provenance and deployment architecture as evaluation criteria today are simply early to a standard the federal government is in the process of writing.
The Three Section 1513 Failure Modes, Translated to Physical Security AI
| Statutory Risk (§1513) | What It Means for a CV Detection Platform | The Buyer's Verification Question |
|---|---|---|
| Data Poisoning | Corrupted training data could make a model systematically miss a threat class or generate false alerts, silently degrading detection performance. | How is the training dataset sourced, validated, and protected against contamination? Can the vendor attest to dataset integrity? |
| Adversarial Tampering | Compromise of the inference hardware, model file, or processing pipeline, including during transit or at the physical edge device. | Where does inference run, who can physically access it, and how are model weights protected on the appliance? |
| Unintentional Data Exposure | Sensitive footage or identifiable data leaking through misconfiguration, storage, or handling errors. | What does the platform store and transmit? Does it perform facial recognition or retain video? What is the actual exposure surface? |
How Section 1513 connects to the standards stack buyers already track
Section 1513 does not stand alone in the regulatory architecture. It sits on top of a stack of standards and procurement rules that physical security buyers have been navigating for several years, and its significance is partly in how it consolidates them. The NIST AI Risk Management Framework supplies the conceptual backbone the DoD framework will lean on. The CMMC program supplies the assessment-and-certification machinery. NDAA Section 889 already established the precedent that camera and component supply chains are procurement-relevant. Section 1513 extends that logic one layer deeper, from the hardware that captures the image to the model that interprets it.
For buyers, the practical effect is consolidation of what used to be separate diligence tracks. A procurement officer evaluating a physical security AI platform for a defense-adjacent facility increasingly needs a single coherent answer that spans hardware provenance (Section 889), documentation and governance (NIST AI RMF), and now model integrity and physical security of the AI itself (Section 1513). Vendors who can present that as one story, rather than three disconnected compliance postures, will move faster through procurement. The platforms most exposed are those that have treated AI security as a marketing claim rather than an architectural commitment, because Section 1513's eventual DFARS language will ask for evidence, not assertions.
Why anti-terrorism designation and AI-security provenance reinforce each other
IntelliSee holds DHS SAFETY Act Full Designation as a Qualified Anti-Terrorism Technology, the framework analyzed in the SAFETY Act briefing. SAFETY Act review already scrutinizes the reliability and deployment integrity of a security technology as a condition of designation. Section 1513 approaches the same platform from the model-security direction, asking about training data, weights, and supply-chain integrity. For a buyer in a high-consequence environment, the two regimes are complementary lenses on the same underlying question: can this system be trusted to perform as claimed when it matters, and can that trust be documented? A vendor that satisfies both is positioned for the convergence of liability protection and procurement compliance that defense-adjacent buyers are starting to require in a single evaluation.
What security directors and procurement teams should do now
The framework is not final, and the DFARS language does not yet exist. That is precisely why the period between the June 16, 2026 status report and the eventual rulemaking is the right time to prepare rather than react. Several moves are available to buyers and vendors regardless of the framework's final shape, because they map to risks that are already well-defined.
Add model-integrity questions to vendor evaluation now. The three Section 1513 failure modes translate directly into RFP language: ask vendors how training data is sourced and protected, where inference runs and who can access it, and what the platform actually stores and transmits. These questions are answerable today and will only become more central.
Treat deployment architecture as a security decision. The edge-versus-cloud question, which IntelliSee examined in its edge versus cloud inference briefing, is no longer only about latency and bandwidth. Under a Section 1513 lens, where the model runs determines who can tamper with it. On-premises inference on a hardened appliance presents a materially different physical-security posture than inference in an opaque third-party cloud.
Map the vendor's existing compliance posture to the emerging framework. A vendor already aligned to NIST AI RMF documentation, already SAFETY Act designated, and already operating a privacy-by-design architecture is most of the way to what Section 1513 will require. Buyers should ask vendors to show that mapping rather than to make a general claim of "AI security."
Watch the June 16 status report and the DFARS docket. The status update to Congress is the first concrete signal of timeline and scope. The subsequent DFARS rulemaking, with its mandatory cost-benefit analysis, will reveal which requirements are durable. Buyers planning multi-year contracts should build flexibility for the framework's arrival into their procurement language.
Frequently asked questions about NDAA Section 1513 and AI physical security
What is NDAA Section 1513 in plain terms?
Section 1513 of the National Defense Authorization Act for Fiscal Year 2026 directs the Department of Defense to build a framework addressing the cybersecurity and physical security of the artificial intelligence and machine learning technologies it acquires, and to fold that framework into the Defense Federal Acquisition Regulation Supplement (DFARS) and the Cybersecurity Maturity Model Certification (CMMC) program. It is the first federal statute to treat the security of an AI model itself, including its training data and weights, as a procurement-grade requirement. DoD must provide a status update on its implementation plan to Congress by June 16, 2026.
Does Section 1513 apply to my company if we do not sell to the Department of Defense?
Not directly. Section 1513's requirements bind "covered entities" that contract with DoD to develop, deploy, store, or host covered AI/ML. However, because DoD procurement standards historically diffuse into the broader market, much as NDAA Section 889's camera supply-chain rules became a commercial baseline, the model-security expectations Section 1513 creates are likely to appear in commercial RFPs, insurance underwriting, and enterprise vendor-risk reviews over time. Buyers and vendors outside the defense industrial base should treat it as a leading indicator of where the market is heading.
Why does Section 1513 mention physical security if AI is software?
Because an AI system is more than running code. Its training data, model weights, and inference hardware all exist in the physical world, where they can be accessed, swapped, or tampered with. An adversary who cannot breach a network may still corrupt a training pipeline at a facility, substitute a poisoned model file in transit, or compromise an edge device. By naming physical security explicitly, Congress recognized that an AI model's integrity depends on controls reaching down to the physical room where its hardware and data live.
How is Section 1513 different from the NIST AI Risk Management Framework?
The NIST AI RMF is a voluntary, consensus-based framework that provides guidance for managing AI risks. Section 1513 is a statutory mandate that directs DoD to build a binding procurement framework, and it explicitly draws on the NIST Special Publication 800 series as a foundation. In short, NIST supplies the vocabulary and the conceptual structure; Section 1513 gives a subset of it procurement enforcement through DFARS and CMMC. They are complementary rather than competing, and a vendor aligned to NIST AI RMF documentation is well positioned for what Section 1513 will require.
How does Section 1513 relate to Executive Order 14409 signed in June 2026?
They are parallel federal actions on the same timeline. Section 1513 (legislative) hardens AI procurement through DFARS and CMMC. Executive Order 14409, "Promoting Advanced Artificial Intelligence Innovation and Security" (91 FR 34565, signed June 2, 2026), hardens AI deployment through a voluntary frontier-model evaluation framework, an AI cybersecurity clearinghouse, and CISA directives. The executive order explicitly avoids creating any mandatory licensing requirement, while Section 1513 uses procurement leverage to make AI security effectively required for DoD vendors. Together they signal a coordinated federal posture on AI security.
What should a physical security AI vendor do to prepare for Section 1513?
Align to the failure modes the statute names. Document how training data is sourced and protected against poisoning, harden the inference architecture against tampering and clarify where the model runs and who can access it, and minimize the data-exposure surface through privacy-by-design choices such as performing no facial recognition and storing no video. Mapping an existing NIST AI RMF posture and any DHS SAFETY Act designation to the emerging framework will position a vendor ahead of the eventual DFARS rulemaking.
When will Section 1513 requirements actually take effect for contractors?
No firm date exists yet. Section 1513 requires DoD to deliver an implementation-plan status update to Congress by June 16, 2026, but it does not set a deadline for the framework itself, and the subsequent DFARS rulemaking must include a cost-benefit analysis weighing security benefits against development-speed costs. The CMMC precedent is instructive: it began in the FY2020 NDAA and took roughly five years to take effect. Contractors should monitor the status report and the DFARS docket rather than wait for a single effective date.
Continue the research
This briefing covers the statutory architecture and market implications of NDAA Section 1513 for physical security AI. For deeper reading on the connected pieces of the compliance and procurement stack:
- NDAA Section 889 and FAR 52.204-25 supply-chain compliance briefing — the camera-supply-chain precedent that shows how a defense-procurement rule becomes a commercial baseline.
- The NIST AI Risk Management Framework standards-compliance briefing — the documentation architecture the Section 1513 framework is built to extend.
- AI physical security vendor due-diligence market analysis — the buyer-side verification questions Section 1513 will eventually formalize.
- Edge versus cloud AI inference technology briefing — why where the model runs is now a security decision, not just a latency one.
- How IntelliSee works — the on-premises, privacy-by-design detection architecture that maps to the Section 1513 failure modes.
More intelligence like this
New IntelliSee research drops monthly at most. Subscribe and get the next sector playbook, technology briefing, or threat intelligence report in your inbox the day it ships.
Request a Risk Assessment
Talk to an IntelliSee security specialist. No sales pitch — a structured conversation about your environment, your threat profile, and whether computer vision is the right fit.
Request a Risk Assessment