
TIAKI›Memorandum›Asset Class Coverage›Vertical 03
Vertical 03
Tactical Unmanned Aerial Systems - Manufacturers
Secures airframe component provenance by pinning silicon UIDs (ECIDs) at goods-in to signed foundry manifests — satisfying UK MoD Secure by Design gating, EU EDIP 35% sovereign-content and design-authority tests, ITAR-Free continuous attestation for sovereign export integrity, and the Cyber Resilience Act / NIS2 attestation regime, with CSDDD flow-down handled as a downstream financial consequence.
€26.0 Bn
Total Addressable Market
38%
Indicative Premium Uplift
381 bps Sovereign Tracking Risk Premium (blended)
Capital-Cost Compression
5 sec
Operational & Risk Heartbeat
Thesis
Secures airframe component provenance by pinning silicon UIDs (ECIDs) at goods-in to signed foundry manifests — satisfying UK MoD Secure by Design gating, EU EDIP 35% sovereign-content and design-authority tests, ITAR-Free continuous attestation for sovereign export integrity, and the Cyber Resilience Act / NIS2 attestation regime, with CSDDD flow-down handled as a downstream financial consequence.
Frontline Paradox
Operators log up to 80% of First-Person View (FPV) drone losses as "Russian Electronic Warfare." Yet today, there is zero cryptographic hardware and firmware forensics deployed into UK or EU drone component supply chains. State actors are exploiting this blind spot. A conservative attrition forecast indicates that 20–25% of these losses are likely latent upstream software and hardware poisoning introduced through unverified grey-market supply lines — failures that look, fly and fail like jamming.
Attrition Forecasting
The 20–25% projection is anchored in verified industrial baselines:
- ·The 20% counterfeit and un-attested chip saturation rate flagged by the U.S. Bureau of Industry and Security in grey-market aerospace supply chains.
- ·The 21% of critical-infrastructure firmware vulnerabilities discovered only via out-of-band binary analysis, not vendor-declared manifests.
Combat Multiplier
TIAKI's provenance architecture isolates these firmware anomalies before final line assembly and flight — neutralising the 20–25% of attrition attributable to supply-chain compromise. This moves the frontline mission success rate, materially increasing efficacy and combat output from the same asset footprint.
The provenance gap is the drone-sector equivalent of recent upstream supply-chain compromises: software backdoors such as the XZ Utils incident analysed by Palo Alto Networks Unit 42 (2024), and hardware/firmware tampering at the manufacturing and logistics layer documented by Cisco Talos (2024). In both cases the adversary did not attack the deployed system directly; they poisoned the trusted upstream component so the failure would appear downstream as an operational malfunction.
Quantified Asset-Class Sizing
| Total Addressable Market (TAM) | €26.0 Bn |
| Serviceable Addressable Market (SAM) | €7.2 Bn |
| Serviceable Obtainable Market (SOM) · 2026 | €0.223 Bn |
| SOM Target Capture · 2030 | 8.5% (€0.612 Bn) |
| Compounded Annual Growth Rate | 28.7% |
| Macro Drivers | STANAG 4671 · ITAR-Free (22 CFR §120–130) · Cyber Resilience Act · EDIRPA · EDIP Art. 3ma · NIS2 |
Regulatory Anchor & Price Premium Analysis
| Core Regulatory Anchor | UK MoD Secure by Design (ISN 2023/09) · EU EDIP Reg. 2025 (35% sovereign-content + design-authority) · Cyber Resilience Act (Reg. 2024/2847) · NIS2 (Dir. 2022/2555) · CSDDD (Dir. 2024/1760) as downstream flow-down consequence |
| Current Market Baseline | Grey-spec, un-attested defence hardware exposed to Secure-by-Design rejection, EDIP market-access exclusion and CRA/NIS2 attestation gaps |
| Indicative TIAKI Premium Uplift | 38% |
| WACC Compression | 381 bps Sovereign Tracking Risk Premium (blended) |
Defining the assembly floor as a Cryptographic Invariant Network hashes silicon nodes and firmware signatures at the moment of integration. This delivers the evidence stack that UK MoD Secure by Design now gates procurement against, satisfies the EU EDIP 35% sovereign-content and design-authority thresholds required for EU market access, and produces the continuous product-level attestation the Cyber Resilience Act and NIS2 demand. CSDDD Article 27 supplier flow-down is then handled as a downstream financial consequence rather than a primary compliance driver — preserving the €22.8 M NPV value-creation case through revenue access first, capital-cost compression second.
Figure reflects TIAKI E2E test-run output for this vertical and sits inside the 80–450 bps platform corridor (platform-weighted base ≈ 265 bps) disclosed in the Board Memo (see Memorandum § Z.3 WACC Sensitivity and § Z.4 Evidence Index).
Continuous ITAR-Free Sovereign Certification
TIAKI positions ITAR-Free status not as a pricing lever but as a sovereign risk compliance gate. For EU and UK tactical UAS primes, ITAR contamination — a single US-origin component, firmware library, or cryptographic module embedded in the airframe — triggers US State Department re-export jurisdiction under 22 CFR §120–130. That jurisdiction, once attached, is effectively permanent: it converts a sovereign European platform into a US-controlled export, subject to Foreign Military Sales licensing, end-user certification, and unilateral shutdown risk.
The compliance burden is binary. A manufacturer is either proven ITAR-Free at the silicon and firmware layer — with a continuous, cryptographically-signed evidence trail — or it is exposed to retrospective re-classification during any tender audit, sovereign end-user review, or export-licence renewal. There is no middle ground and no retrofit remedy.
TIAKI's Provenance Guardian (Agent #01), Production-Truth Sentinel (Agent #12), and Trust ROI Engine (Agent #17) collectively deliver continuous ITAR-Free attestation anchored to patent filings PROV-006 and PROV-007:
- Agent #01 · Provenance GuardianPins every silicon UID (ECID) captured at goods-in against signed foundry manifests, flagging any component whose origin, mask-set, or packaging step touches ITAR-controlled jurisdiction.
- Agent #12 · Production-Truth SentinelMonitors the live MES, firmware-flash, and flight-test telemetry stream for cryptographic library drift, embedded US-origin IP blocks, or third-party module substitutions that would re-contaminate the airframe post-certification.
- Agent #17 · Trust ROI EngineConsolidates the evidence into a signed Trust ROI attestation consumable by UK MoD, EDA, and national defence-procurement authorities as a first-pass compliance artefact — settlement-gated at the FSE listing layer.
The commercial consequence is market access, not margin uplift. ITAR-Free certification is the price of admission to sovereign EU/UK defence tenders under EDIP Article 3ma (35% sovereign-content test), UK MoD Secure by Design procurement gating, and the emerging EDIRPA joint-procurement framework. Manufacturers without continuous, machine-verifiable ITAR-Free evidence are structurally excluded from the sovereign-priced tier of the market — regardless of technical performance.
Cryptographic Governance Topology
- Factory Telemetry · Component Silicon IDs / Automated Optical Inspection
- TIAKI Core · Source-of-Truth Ledger / Supply Chain Immunity Layer
- Firmware Hash Verification & Grey-Zone Drift Check
- eIDAS-Grade HSM · Secure Production Batch Key Signature
- Independent Auditor Node · NATO QA / STANAG Attestation
- Regulator Read-API · MoD Procurement Ledger / FSE Sovereign Integrity Tier
Nodes 1–4 execute autonomously within the 5-second operational heartbeat (paper <3s, physical <800ms). Nodes 5–6 are human-audited and digitally signed. No regulator receives raw telemetry — only the signed attestation hash.
Capital Compression Mechanics
Legacy corporate reporting in defence drones operates on a retrospective 12-to-18-month audit lag dominated by unsigned PDFs and consultant assessments. That delay creates a structural blind spot in which data-smoothing, double-counting, and undetected regulatory breaches compound into balance-sheet liability.
TIAKI replaces this with an immutable infrastructure enforcing information symmetry at a 5-second tick: hardware-inferred ingestion, immediate cryptographic pinning inside eIDAS-grade HSMs, and continuous divergence adjudication by the 17-agent ecosystem against 1,550+ verified data sources.
For Tier-1 lenders and underwriters, this transforms volatile physical operations into a deterministic financial asset class — eradicating litigation reserves under CSDDD and SFDR Article 9, collateralising provenance, and compressing secondary spreads.
The 381 bps Sovereign Tracking Risk Premium (blended) reduction in defence drones WACC is not a qualitative discount; it is a mathematically justified adjustment to legacy risk premiums, shifting the capital-cost curve permanently in favour of sovereign-aligned operators.
Sources & Methodology
- ·UK MoD Secure by Design (ISN 2023/09, live since Jul 2023)
- ·EU European Defence Industry Programme (EDIP) Regulation 2025 — 35% sovereign-content + design-authority tests
- ·EU Cyber Resilience Act (Regulation 2024/2847) — product-level cyber attestation
- ·EU NIS2 Directive 2022/2555 — operator-level cyber obligations
- ·STANAG 4671 (NATO UAS Airworthiness)
- ·EU CSDDD Directive 2024/1760 — Art. 27 supplier flow-down (downstream financial consequence)
- ·Wassenaar Arrangement Munitions List
- ·22 CFR §120–130 — US International Traffic in Arms Regulations (ITAR), re-export jurisdiction and end-user controls
- ·US State Department DDTC — Directorate of Defense Trade Controls, commodity jurisdiction determinations
- ·EU EDIP Regulation 2025/2643, Article 3ma — Sovereign-content and design-authority tests for defence procurement
- ·Unit 42 / Palo Alto Networks — Threat Brief: Vulnerability in XZ Utils Data Compression Library (CVE-2024-3094), March 2024
- ·Cisco Talos Intelligence — "Are hardware supply chain attacks 'cyber attacks?'", September 2024
- ·TIAKI Patent Filings PROV-006 & PROV-007 — Silicon-UID provenance pinning and continuous production-truth attestation
- ·TIAKI 1,550+ verified sovereign and institutional data sources
TIAKI is architected to meet the evidentiary criteria of the above frameworks. Final classification rests with the appointed regulator and counterparty auditor. See Scope & Limits Disclosure.
