Operational notes Observatory

Twenty-five years on the same boundary: who decides what crosses between the classified and the open network

7 min read

Wrought-iron hinges on a two-leaf wooden door, black and white photograph
Hinges decide which way a door opens, and they stay fitted long after the people who chose them.

The artificial intelligence model you are adopting almost certainly sits outside your restricted zone, and that choice contains a second one that never reaches the minutes: every useful piece of data will have to cross a boundary device, and whoever builds that device decides what passes and in which direction. On 23 September a large European administration put a duration on that dependency: twenty-five years.

One release, one duration, no figure

The text is Airbus’s and carries the dateline “Paris, France, 23 September 2026”. France’s Direction générale de l’armement has awarded the group, through its subsidiary Airbus Cybersecurity SAS, the PARACOM contract for the security gateways on the networks of the Ministry of the Armed Forces and Veterans’ Affairs. The object is not the delivery alone: “Following a competitive tender, the agreement covers the end-to-end design development, production, and long-term operational maintenance of the gateways”.

What the device is for sits in one line: “PARACOM will be approved and certified to cover a range of data exchanges between ‘secret’ and ‘unclassified’ levels”. It is the piece that stands between networks of different classification and filters what crosses them. Versions run from a data-centre rack to a self-contained unit for a command post, and on to uses “such as surface vessels, submarines, aeroplanes, helicopters or drones, or on board armoured vehicles and land vehicles”. The value is not published; nor is the number of units.

One detail weighs more than the announcement. François Lombard, Director of Connected Intelligence at Airbus Defence and Space, states: “Since 2013, we have supplied French land forces with gateway solutions”. The tender was won by the party that already held that boundary.

The competition lasts a day, the contract lasts a generation

There is nothing to contest in the procedure: the tender took place, and that is exactly why the case teaches buyers something. Competition is exercised once; the outcome binds for twenty-five years, which is two or three generations of information systems.

Whoever buys a boundary device buys three things at once, and the invoice shows one. The first is the hardware. The second is the rule: what may cross, in which format, in which direction — and who holds the right to change it when the threat changes. The third is approval: a device of this kind counts only while an authority certifies it for those levels, and the certification attaches to the product, not to the function. Changing supplier is not changing a supply: it means reopening a certification and reinstalling on ships, submarines, aircraft and vehicles already delivered. Operational maintenance inside the same contract closes the circle: whoever wrote the rule is also the party that updates it for the whole term.

Italy keeps the same requirement in a footnote

The useful comparison is not with France: it is with what Italy has already put in writing. The Defence strategy on artificial intelligence — «IA e DIFESA», 2026 edition, approved in Rome on 16 January 2026 — asks on page 17 for a cloud approach in two configurations at once, «nella duplice configurazione class e unclass». The interconnection between the two worlds is not in the body of the text: it is in footnote 15, and it is in the future tense. «In prospettiva, per massimizzare le potenzialità offerte dall’IA, occorrerà individuare soluzioni tecnologiche atte a interconnettere in maniera bidirezionale i due domini “classificato” e “non classificato” in modo sicuro» (technological solutions will have to be found to interconnect the two domains bidirectionally and securely).

On the same page the document is blunt about where computing must sit: on a proprietary infrastructure, «presso una infrastruttura di computazione proprietaria», with modularity and isolation of the training, test, release and production environments, and physical and cyber security requirements «tali da soddisfare anche esigenze classificate» — enough to meet classified needs as well. On page 13 it sets down the capability to keep its own AI systems running «anche in assenza di supporto esterno in contesti ad alto rischio»: without external support, in high-risk settings.

It hands itself the antidote on page 49: adopt the Modular Open System Approach, which «obbliga i contraenti a progettare sistemi le cui componenti siano interoperabili, sostituibili e aggiornabili con hardware/software prodotti da fornitori diversi» — components interoperable, replaceable and upgradable with hardware and software from different suppliers — because it «riduce il rischio di “vendor lock in”». That holds for radios and sensors. On the boundary component it is the hardest thing to obtain, because there the constraint is not the connector: it is the certification.

Four lines to put in the specification, beforehand

The rule kept separate from the device. The filtering policies must be your own artefact, exportable and readable, not a configuration living only inside somebody else’s product.

The right to change, with fixed timings. Write down within how many days a new rule enters service and who approves it. Without that number your security keeps the cadence of someone else’s roadmap.

Approval as an object of the contract. On which levels it is granted, by which authority, with what expiry, and at whose cost the renewal falls when the product evolves.

An exit tested, not promised. An exit strategy never executed is a paragraph, as in an audit that took issue with that line. And inside Italy’s national cyber security perimeter a supply like this does not close with a signature: it goes to the CVCN before the tender.

Why a closed system

Because the gateway exists for one reason only: the system that needs the data sits on the wrong side. Every useful function placed outside the perimeter turns an analysis problem into a border-traffic problem, and border traffic is bought, certified and maintained for decades. If model, weights and archive sit inside, the amount of boundary you have to buy collapses.

Because the boundary that remains should be kept narrow and poor. A closed installation on open-weight models passes rare, controlled updates rather than continuous outbound queries: it is the difference between a door that opens twice a year and one left ajar.

Because continuity must not depend on a right to be served. The Italian strategy asks for systems that keep running «anche in assenza di supporto esterno»: that is a property of the architecture, not a clause. It is obtained by owning the stack — supervised machines, weights in house, an operator in command — rather than renting it.

The two axes, applied to this case

Complying. The control we put into service is a living register of boundary components: for each one, the entity you signed with, the levels on which approval is granted and its expiry, who may change the rules and how fast, and the date of the last exit test. Dated and inspectable, not an opinion filed away.

Deciding. The same installation holds plants, archives, management systems, sensors and documents in a single operating model, on which AI agents execute decisions with an operator in command — for large companies, defence, public administration and healthcare. On-premise on self-contained machines, or a dedicated cloud with a data centre in Italy supervised by us, always with shared management: you need not already employ people who administer AI models.

Could you say, for your own boundary device, who may change the filtering rules and how quickly? Half an hour with one of our engineers is enough to start.

What we do not know

We do not know the value of the contract, the number of gateways, how many bids arrived or the award criteria: the release says only that a tender took place. The primary source is the winner’s own text, not an instrument of the contracting authority: the positions reported are those of Airbus, we collected no statement from the DGA, and no allegation is in play — this is a properly awarded contract. We found no European notice: a full-text search on TED for the programme name is approximate, because the engine is fuzzy, and no hit concerns it; in defence publication is not always due, so the absence proves nothing. Approval is in the future tense in the release as well — “will be approved and certified” — and we do not know which authority will grant it. On the Italian side, footnote 15 states a prospective requirement: we do not know whether equivalent Italian supplies already exist, because awards in this field may go unpublished.

Sources