The President directed the strengthening of America’s physical defense supply chains for raw materials and equipment. We must also secure our Nation’s Critical Data Supply Chain that feeds the Arsenals of Freedom.
The most dangerous vulnerabilities confronting a nation are often those it fails to recognize until a crisis exposes them. Executive Order 14415, Securing America’s Defense Supply Chains and Ensuring Domestic Acquisition of Critical Materials, addresses a long-standing vulnerability by directing the Department of War to illuminate supply chains that sustain American military power, including a complete indentured Bills of Materials tracing components, parts, equipment, software, and material through every tier of the supply chain and back to their origin. It is a timely and critical initiative.
Yet it secures only half the battlefield.
The Order focuses on steel, titanium, microchips, rare earth minerals, and the industrial base that transforms them into military capability. But every modern defense system depends upon something just as indispensable: trusted, verifiable, and fit-for-purpose data.
Critical data and tokens for information dominance now flow through the armed forces with the same strategic importance as fuel, ammunition, and replacement parts. However, if that information is corrupted, incomplete, biased, misleading, outdated, or stripped of context, even the most sophisticated weapon system can become extraordinarily expensive monuments to misjudgment.
The Weaponization of Data
America’s adversaries understand this. They need not destroy a missile system if they can quietly corrupt the information upon which it depends. A manipulated maintenance record can ground aircraft at the wrong moment. Poisoned logistics data can send critical supplies to the wrong location. A fabricated intelligence report can redirect surveillance. Biased training data can cause an AI-enabled system to misclassify a legitimate target, overlook a threat, or fail in the operational environment.
The systems may continue to function, creating the illusion that all is well. By the time commanders discover the data corruption months after the exploitation, the operational consequences may already be irreversible.
Furthermore, as consequential data passes through prime contractors, subcontractors, cloud providers, commercial data services, and software vendors, visibility steadily diminishes. Sensitive information crosses international boundaries, resides under competing legal jurisdictions, and moves through systems operating under uneven security standards. Chain of custody is lost.
Compounding this vulnerability is the rapid integration of artificial intelligence into military operations. The expanded use of the War Data Platform, Maven Smart System, and the Department of Energy’s Genesis mission to scale AI advantages for national security must have parameters set within a strategic knowledge infrastructure to confirm trusted sources, track chain of custody, and manage AI outputs.
Securing the Data Supply
Traditional data cybersecurity is largely organized around confidentiality, integrity, and availability. Yet comparatively little attention has been paid to the provenance, integrity, and chain of custody of the data moving through those same systems. A record can be confidential, available, cryptographically authentic, unaltered, and fully traceable—and still be false.
That omission should concern policymakers every bit as much as a single-source foreign supplier, a broken chain of custody for pagers, or a compromised semiconductor plant.
Security protects data; it does not automatically establish the truth or operational validity of what the data represents.
That distinction matters because data does not move directly from collection to decision. It is selected, transmitted, cleaned, labeled, translated, combined, filtered, summarized, modeled, and interpreted. At every stage, assumptions and uncertainty may be introduced. The relevant object of protection is therefore not simply a file or database. It is the entire data-to-decision chain by which observation leads to orientation, which then informs decisions and actions.
Every transfer creates an opportunity for manipulation, corruption, or subversion.
Adversaries need not breach a fortified network if they can quietly compromise information once it leaves that protected environment. Like the childhood game of telephone, small, nearly imperceptible changes introduced during transmission can accumulate until the final recipient acts upon information that no longer reflects the truth.
In modern warfare, where speed increasingly determines deterrence and operational success, protecting the provenance and integrity of critical defense data in transit is every bit as important as protecting the physical assets that carry it.
The Department’s Cybersecurity Maturation Model Certification (CMMC) was built with this in mind, but with techniques and processes overwhelmed by advancing technologies. The Department of War was correct to pause the program as the costs to the Defense Industrial Base (DIB) far exceeded the limited return. Modern technologies are now capable of providing both the DIB and the warfighters they serve, with more effective data protection at a fraction of the cost of CMMC implementation.
Innovative solutions enable a federated verification layer embedded throughout digital infrastructure, establishing Data Provenance, Trusted Information Dominance, and a secure
Critical Data Supply Chain as foundational pillars of national defense rather than only satisfying administrative compliance obligations.
The Imperative for a Strategic Knowledge Infrastructure
The new demand is Data Provenance—verifiable evidence showing where mission-critical data originated, which organizations and systems handled it, what material transformations it underwent, and whether its integrity and context were preserved from collection through operational use. Just as manufacturers trace the provenance of aircraft components or ammunition, the Department of War must trace the provenance of information upon which critical military decisions depend.
Executive Order 14415 provides the right starting point. Trusted Information Dominance must include securing data supply chains feeding the AI Arsenal against physical, cyber, and economic subversion through Critical Data Supply Chain mapping and illumination. The Secretary of War should treat raw materials and critical data with the same urgency to achieve trust, assured access, and control of intelligence analysis, logistics, autonomous capabilities, and military AI.
A National Data Supply Chain Mapping Initiative must extend to the defense industrial base. Military organizations and defense contractors at every tier must document where mission-critical data originates, how it moves, who handles it, where it is stored, and how its integrity is maintained. Every transfer should be traceable. Every significant modification should be recorded. Every repository should maintain a verifiable chain of custody.
Defense acquisition policy should likewise require standardized Data Bills of Materials documenting the origin of mission-critical data, the processing it has undergone, the organizations responsible for handling it, and any foreign participation in its management. Data Provenance should become as fundamental to defense acquisition as quality assurance is to weapons manufacturing.
The Department and the defense industrial base should adopt commercial technologies to preserve evidence of origin, transformation, custody, and authorized use across structured and unstructured data, including video, audio, documents, sensor feeds, databases, and AI outputs. Certain mechanisms should include cryptographic signatures, trusted timestamps, secure metadata, content credentials, tamper-evident logs, hardware-backed attestations, robust watermarking, independent corroboration, and validation testing. These capabilities should also enforce data use restrictions and ensure that only authenticated information is ingested into AI systems, allowing trust to travel with the data wherever it moves.
Innovative solutions exist today at an affordable cost.
These requirements must extend into the sprawling networks of subcontractors, software firms, cloud providers, commercial data brokers, model developers, allies, and service companies. Accountability that stops at the first tier is accountability in name only. Every participant entrusted with high-consequence defense data should commit to quality assurance, provenance, and authorized use.
Oversight must also become continuous rather than episodic. Periodic inspections cannot detect evolving threats to data integrity. Continuous monitoring, routine verification, and immutable audit records must become standard practice wherever defense data is collected, stored, processed, or shared.
America has long understood that secure logistics sustain military power. In the age of artificial intelligence, Trusted Information Dominance will belong to the nation that can verify, trace, and trust its mission-critical data. To secure the Arsenals of Freedom while neglecting the integrity of the data guiding them is to armor the warrior while blinding his eyes with the fog of war. Victory on the battlefield depends not only on the strength of our weapons, but on the nation’s ability to secure trust in the data that informs every military decision.
About Author:
HON Lucian Niemeyer served as a former Air Force engineer, U.S. Senate Armed Services Committee staffer, Assistant Secretary of Defense, and White House official on National Security priorities.
Sue Ghosh Stricklett is an attorney, author, and national security law expert specializing in export controls, emerging technologies, and strategic competition.