TIAKI
    ← TIAKI Cover
    Defence Drones — institutional cover image

    TIAKIMemorandumAsset Class CoverageVertical 03

    Vertical 03

    Tactical Unmanned Aerial Systems - Manufacturers

    Secures airframe component provenance by pinning silicon UIDs (ECIDs) at goods-in to signed foundry manifests — satisfying UK MoD Secure by Design gating, EU EDIP 35% sovereign-content and design-authority tests, ITAR-Free continuous attestation for sovereign export integrity, and the Cyber Resilience Act / NIS2 attestation regime, with CSDDD flow-down handled as a downstream financial consequence.

    €26.0 Bn

    Total Addressable Market

    38%

    Indicative Premium Uplift

    381 bps Sovereign Tracking Risk Premium (blended)

    Capital-Cost Compression

    5 sec

    Operational & Risk Heartbeat

    § 03.0One-line investor thesis

    Thesis

    Secures airframe component provenance by pinning silicon UIDs (ECIDs) at goods-in to signed foundry manifests — satisfying UK MoD Secure by Design gating, EU EDIP 35% sovereign-content and design-authority tests, ITAR-Free continuous attestation for sovereign export integrity, and the Cyber Resilience Act / NIS2 attestation regime, with CSDDD flow-down handled as a downstream financial consequence.

    Frontline Paradox

    Operators log up to 80% of First-Person View (FPV) drone losses as "Russian Electronic Warfare." Yet today, there is zero cryptographic hardware and firmware forensics deployed into UK or EU drone component supply chains. State actors are exploiting this blind spot. A conservative attrition forecast indicates that 20–25% of these losses are likely latent upstream software and hardware poisoning introduced through unverified grey-market supply lines — failures that look, fly and fail like jamming.

    Attrition Forecasting

    The 20–25% projection is anchored in verified industrial baselines:

    • ·The 20% counterfeit and un-attested chip saturation rate flagged by the U.S. Bureau of Industry and Security in grey-market aerospace supply chains.
    • ·The 21% of critical-infrastructure firmware vulnerabilities discovered only via out-of-band binary analysis, not vendor-declared manifests.

    Combat Multiplier

    TIAKI's provenance architecture isolates these firmware anomalies before final line assembly and flight — neutralising the 20–25% of attrition attributable to supply-chain compromise. This moves the frontline mission success rate, materially increasing efficacy and combat output from the same asset footprint.

    The provenance gap is the drone-sector equivalent of recent upstream supply-chain compromises: software backdoors such as the XZ Utils incident analysed by Palo Alto Networks Unit 42 (2024), and hardware/firmware tampering at the manufacturing and logistics layer documented by Cisco Talos (2024). In both cases the adversary did not attack the deployed system directly; they poisoned the trusted upstream component so the failure would appear downstream as an operational malfunction.

    § 03.12026 – 2030 horizon · EUR

    Quantified Asset-Class Sizing

    Exhibit 03.1Defence Drones — TAM · SAM · SOM TrajectoryEUR billions / CAGR %
    Total Addressable Market (TAM)€26.0 Bn
    Serviceable Addressable Market (SAM)€7.2 Bn
    Serviceable Obtainable Market (SOM) · 2026€0.223 Bn
    SOM Target Capture · 20308.5% (€0.612 Bn)
    Compounded Annual Growth Rate28.7%
    Macro DriversSTANAG 4671 · ITAR-Free (22 CFR §120–130) · Cyber Resilience Act · EDIRPA · EDIP Art. 3ma · NIS2
    Source: TIAKI 1,550+ verified sovereign and institutional data sources
    § 03.2Anchor regulation · premium realisation

    Regulatory Anchor & Price Premium Analysis

    Exhibit 03.2Defence Drones — Regulatory Premium & WACC CompressionPremium uplift % · basis points (bps) WACC delta
    Core Regulatory AnchorUK MoD Secure by Design (ISN 2023/09) · EU EDIP Reg. 2025 (35% sovereign-content + design-authority) · Cyber Resilience Act (Reg. 2024/2847) · NIS2 (Dir. 2022/2555) · CSDDD (Dir. 2024/1760) as downstream flow-down consequence
    Current Market BaselineGrey-spec, un-attested defence hardware exposed to Secure-by-Design rejection, EDIP market-access exclusion and CRA/NIS2 attestation gaps
    Indicative TIAKI Premium Uplift38%
    WACC Compression381 bps Sovereign Tracking Risk Premium (blended)

    Defining the assembly floor as a Cryptographic Invariant Network hashes silicon nodes and firmware signatures at the moment of integration. This delivers the evidence stack that UK MoD Secure by Design now gates procurement against, satisfies the EU EDIP 35% sovereign-content and design-authority thresholds required for EU market access, and produces the continuous product-level attestation the Cyber Resilience Act and NIS2 demand. CSDDD Article 27 supplier flow-down is then handled as a downstream financial consequence rather than a primary compliance driver — preserving the €22.8 M NPV value-creation case through revenue access first, capital-cost compression second.

    Figure reflects TIAKI E2E test-run output for this vertical and sits inside the 80–450 bps platform corridor (platform-weighted base ≈ 265 bps) disclosed in the Board Memo (see Memorandum § Z.3 WACC Sensitivity and § Z.4 Evidence Index).

    Source: TIAKI Pricing Engine; issuer credit-spread differentials; CSDDD / OFAC benchmarks
    § 03.3Sovereign risk compliance · procurement-gate attestation

    Continuous ITAR-Free Sovereign Certification

    TIAKI positions ITAR-Free status not as a pricing lever but as a sovereign risk compliance gate. For EU and UK tactical UAS primes, ITAR contamination — a single US-origin component, firmware library, or cryptographic module embedded in the airframe — triggers US State Department re-export jurisdiction under 22 CFR §120–130. That jurisdiction, once attached, is effectively permanent: it converts a sovereign European platform into a US-controlled export, subject to Foreign Military Sales licensing, end-user certification, and unilateral shutdown risk.

    The compliance burden is binary. A manufacturer is either proven ITAR-Free at the silicon and firmware layer — with a continuous, cryptographically-signed evidence trail — or it is exposed to retrospective re-classification during any tender audit, sovereign end-user review, or export-licence renewal. There is no middle ground and no retrofit remedy.

    TIAKI's Provenance Guardian (Agent #01), Production-Truth Sentinel (Agent #12), and Trust ROI Engine (Agent #17) collectively deliver continuous ITAR-Free attestation anchored to patent filings PROV-006 and PROV-007:

    • Agent #01 · Provenance GuardianPins every silicon UID (ECID) captured at goods-in against signed foundry manifests, flagging any component whose origin, mask-set, or packaging step touches ITAR-controlled jurisdiction.
    • Agent #12 · Production-Truth SentinelMonitors the live MES, firmware-flash, and flight-test telemetry stream for cryptographic library drift, embedded US-origin IP blocks, or third-party module substitutions that would re-contaminate the airframe post-certification.
    • Agent #17 · Trust ROI EngineConsolidates the evidence into a signed Trust ROI attestation consumable by UK MoD, EDA, and national defence-procurement authorities as a first-pass compliance artefact — settlement-gated at the FSE listing layer.

    The commercial consequence is market access, not margin uplift. ITAR-Free certification is the price of admission to sovereign EU/UK defence tenders under EDIP Article 3ma (35% sovereign-content test), UK MoD Secure by Design procurement gating, and the emerging EDIRPA joint-procurement framework. Manufacturers without continuous, machine-verifiable ITAR-Free evidence are structurally excluded from the sovereign-priced tier of the market — regardless of technical performance.

    § 03.4Machine-to-settlement pipeline

    Cryptographic Governance Topology

    Exhibit 03.4Defence Drones — Six-Node Governance Flow
    1. Factory Telemetry · Component Silicon IDs / Automated Optical Inspection
    2. TIAKI Core · Source-of-Truth Ledger / Supply Chain Immunity Layer
    3. Firmware Hash Verification & Grey-Zone Drift Check
    4. eIDAS-Grade HSM · Secure Production Batch Key Signature
    5. Independent Auditor Node · NATO QA / STANAG Attestation
    6. Regulator Read-API · MoD Procurement Ledger / FSE Sovereign Integrity Tier

    Nodes 1–4 execute autonomously within the 5-second operational heartbeat (paper <3s, physical <800ms). Nodes 5–6 are human-audited and digitally signed. No regulator receives raw telemetry — only the signed attestation hash.

    Source: TIAKI Patent PROV-005 Fig 1 (Five-Box Spec, extended)
    § 03.5Why the WACC compression is mathematical, not qualitative

    Capital Compression Mechanics

    Legacy corporate reporting in defence drones operates on a retrospective 12-to-18-month audit lag dominated by unsigned PDFs and consultant assessments. That delay creates a structural blind spot in which data-smoothing, double-counting, and undetected regulatory breaches compound into balance-sheet liability.

    TIAKI replaces this with an immutable infrastructure enforcing information symmetry at a 5-second tick: hardware-inferred ingestion, immediate cryptographic pinning inside eIDAS-grade HSMs, and continuous divergence adjudication by the 17-agent ecosystem against 1,550+ verified data sources.

    For Tier-1 lenders and underwriters, this transforms volatile physical operations into a deterministic financial asset class — eradicating litigation reserves under CSDDD and SFDR Article 9, collateralising provenance, and compressing secondary spreads.

    The 381 bps Sovereign Tracking Risk Premium (blended) reduction in defence drones WACC is not a qualitative discount; it is a mathematically justified adjustment to legacy risk premiums, shifting the capital-cost curve permanently in favour of sovereign-aligned operators.

    § 03.6Reference framework

    Sources & Methodology

    • ·UK MoD Secure by Design (ISN 2023/09, live since Jul 2023)
    • ·EU European Defence Industry Programme (EDIP) Regulation 2025 — 35% sovereign-content + design-authority tests
    • ·EU Cyber Resilience Act (Regulation 2024/2847) — product-level cyber attestation
    • ·EU NIS2 Directive 2022/2555 — operator-level cyber obligations
    • ·STANAG 4671 (NATO UAS Airworthiness)
    • ·EU CSDDD Directive 2024/1760 — Art. 27 supplier flow-down (downstream financial consequence)
    • ·Wassenaar Arrangement Munitions List
    • ·22 CFR §120–130 — US International Traffic in Arms Regulations (ITAR), re-export jurisdiction and end-user controls
    • ·US State Department DDTC — Directorate of Defense Trade Controls, commodity jurisdiction determinations
    • ·EU EDIP Regulation 2025/2643, Article 3ma — Sovereign-content and design-authority tests for defence procurement
    • ·Unit 42 / Palo Alto Networks — Threat Brief: Vulnerability in XZ Utils Data Compression Library (CVE-2024-3094), March 2024
    • ·Cisco Talos Intelligence — "Are hardware supply chain attacks 'cyber attacks?'", September 2024
    • ·TIAKI Patent Filings PROV-006 & PROV-007 — Silicon-UID provenance pinning and continuous production-truth attestation
    • ·TIAKI 1,550+ verified sovereign and institutional data sources

    TIAKI is architected to meet the evidentiary criteria of the above frameworks. Final classification rests with the appointed regulator and counterparty auditor. See Scope & Limits Disclosure.