The market for military AI is a market for lemons — and the Pentagon knows it
The FY2026 NDAA requires the Pentagon to build a standardized AI model assessment framework, not complete until 2028. The immediate exclusion of Chinese vendors is not just a stand-alone national security measure: it is the second-best solution to an information asymmetry problem Akerlof formalized back in 1970.
The FY2026 NDAA, whose conference report was unveiled on December 7, 2025, creates within the Department of Defense (DoD) a "standardized AI model assessment framework," led by the Chief Digital and AI Officer: operational by June 1, 2026, but with assessments not fully completed until January 1, 2028 — a 19-month gap. In the same bill, the exclusion of AI systems from named Chinese companies (DeepSeek, High Flyer) applies within 30 days for the DoD and 60 days for the intelligence community. Two instruments, two radically different speeds, for one stated goal: securing the AI supply chain of the U.S. defense establishment.
This gap is not mere bureaucratic delay. It illustrates a classic economic problem, formalized by George Akerlof in his 1970 founding paper on the "market for lemons" (low-quality used cars): when a buyer cannot directly observe a good's quality before purchase, and only the seller holds that information, the market tends to collapse toward the low end — good sellers withdraw because they cannot credibly signal their quality, leaving only the worse ones. The only remedy is building credible verification or signaling instruments: warranties, third-party certification, reputation observed over time.
The market for AI models in sensitive applications displays this exact information asymmetry, arguably to a greater degree than a used car: neither the source code, nor the training data, nor latent biases, nor potential backdoors in a model are observable to an institutional buyer before operational deployment. The DoD can no more "pop the hood" on a foundation model than a private buyer can audit a used car's engine in a few minutes in a parking lot.
By creating a standardized assessment framework, the legislature is building precisely the verification instrument that Akerlof's theory identifies as the solution: a shared test protocol, common metrics, a trusted third party (the Chief Digital and AI Officer) certifying observed quality. But such an instrument cannot be built in a single quarter: safety and performance criteria must be defined, test protocols designed and empirically validated, evaluators trained, and the existing stock of already-deployed models processed. Hence the delay to 2028.
While this direct verification mechanism matures, the legislature falls back on a crude but fast-to-apply proxy: the vendor's nationality. Economically, this is a perfectly rational second-best trade-off — absent a first-best instrument (direct quality verification), a filter that is cheap to check but weakly informative about actual product quality beats no filter at all. The reasoning has a structural limit, though: the absence of a nominative exclusion is no substitute for quality certification. A vendor not on the list isn't "verified" — it is simply not excluded, and that is not the same thing until 2028.
This mechanism extends beyond the U.S. case and beyond the defense sector alone. Since August 2, 2026, the EU AI Act has imposed compliance obligations on providers of high-risk AI systems — a category that covers parts of critical energy and industrial infrastructure. But the capacity for independent, large-scale auditing of these systems remains, as in the United States, under construction: the regulation creates the obligation before the verification ecosystem is fully operational, reproducing the same sequence — the rule precedes the instrument that would allow it to be finely enforced.
For aerospace, defense, and energy manufacturers selling or considering AI systems in sensitive applications, the lesson is twofold. First, don't confuse the absence of a ban with a certification of quality: the margin of doubt remains wide open until the assessment framework is complete. Second, any company investing now in its own model documentation, traceability, and internal audit capability is positioning itself ahead of what will de facto become the new standard for access to defense procurement markets — well before the law formally requires it of everyone.

Analysis by
Cardan-AI Intelligence
Our research and analysis unit, dedicated to applied AI for business, industry and regulatory compliance.
Let's talk about your next competitive edge
A 30-minute conversation to identify your most profitable AI use cases.
