Frequently Asked Questions

Quick answers to common questions about our defence AI governance services.

Security Clearance & Access

What security clearances are required to work with Terranova?

+

Most of our engagements support clients with Secret, Top Secret, and TS/SCI clearances. Some unclassified work is available. We handle classified briefings and operate secure facilities. During the initial consultation, we'll discuss your specific clearance requirements and access levels needed for your engagement.

Can unclassified organizations work with Terranova?

+

Yes. While we specialize in supporting classified defence programmes, we offer unclassified AI governance consulting for unclassified defence and government organizations. Contact us to discuss unclassified engagement options.

Compliance & Standards

What is CMMC Level 3 and why is it important for AI systems?

+

CMMC (Cybersecurity Maturity Model Certification) Level 3 requires advanced security controls for systems handling CUI (Controlled Unclassified Information). When AI systems are trained on or handle classified defence data, CMMC L3 compliance becomes critical. We help integrate AI-specific security requirements into your CMMC implementation.

How long does CMMC + AI compliance certification take?

+

Timelines vary based on your current security posture and organizational size. Typically, achieving L3 certification with AI governance integration takes 6-12 months. We provide a detailed assessment and roadmap during the initial engagement.

What is DSRB approval and is it required?

+

DSRB (Defence Science Review Board) approval is required for autonomous systems, particularly those with independent decision-making authority. DSRB review assesses ethical frameworks, strategic implications, and operational feasibility. While not all AI systems require DSRB approval, we help determine the requirements for your specific application.

Autonomous Systems & Ethics

What is the 7-Layer Governance Stack?

+

Our 7-layer framework provides comprehensive governance across: (1) Policy & Strategy, (2) Technical Architecture, (3) Operational Procedures, (4) Ethical Framework, (5) Legal & Regulatory, (6) Intelligence & Assurance, and (7) Kinetic Operations. This ensures AI systems are governed across all aspects from development through operational deployment.

Can autonomous systems make lethal decisions?

+

This is a complex policy question addressed through the DSRB review process. Current U.S. policy requires meaningful human control over lethal decision-making. Our governance frameworks ensure that any autonomous system operates within defined authority constraints with proper human oversight, regardless of the type of decision being supported.

Engagement & Services

What does an initial security briefing cover?

+

Our security briefings are customized based on your organization's needs. Typical topics include: AI governance frameworks, DSRB review requirements, CMMC + AI compliance pathways, red teaming methodologies, and governance implementation roadmaps. Briefings typically last 2-4 hours and are held at your facility or ours depending on clearance requirements.

How do you handle classified information?

+

We operate secure, air-gapped facilities for handling classified information. Our team is TS/SCI cleared with the ability to handle up to Top Secret/SCI material. All work with classified information follows DoD security protocols and facility requirements. We'll discuss your specific security requirements during the engagement planning phase.

What is red team testing and why is it important?

+

Red teaming involves adversarial testing of your AI systems to identify vulnerabilities before operational deployment. Our red teams simulate nation-state level threats, testing for adversarial examples, model poisoning, supply chain attacks, and operator misuse scenarios. This identifies and helps mitigate risks before systems enter combat or operational use.

General Questions

Why is AI governance important for defence?

+

AI systems in defence contexts make critical decisions affecting national security and potentially lives. Proper governance ensures these systems are safe, ethical, legally compliant, technically sound, and strategically aligned with national defence policy. Without governance frameworks, AI systems risk failure, misuse, vulnerability to adversarial attack, and strategic instability.

How does Terranova align with allied defence standards?

+

We design governance frameworks aligned with NATO STANAG 4658 and other allied standards for AI interoperability. This enables multi-national AI operations and information sharing while maintaining security and policy compliance across allied defence organizations.