Operational notes Observatory

Leonardo DRS buys Raft for $450 million: who controls the mission software

8 min read

River barrage seen from above, metal sluice gates open and water falling down the spillways, in black and white
Water gets through, but only where the gates allow it: that is how US law regulates a foreign-owned subsidiary.

On 28 July 2026 Leonardo DRS (Nasdaq: DRS) announced a definitive agreement to acquire Raft LLC, a mission software company founded in 2018 and headquartered in McLean, Virginia, in an all-cash transaction valued at $450 million. The same day Leonardo S.p.A. issued an inside-information release from Rome describing Leonardo DRS as “Leonardo’s (71.38% held) US listed subsidiary”. Read from Italy, the obvious conclusion is that an Italian group has bought defence AI capability. The accurate conclusion is different, and it is written in the filings Leonardo DRS makes with the SEC: that software is built and stays inside a perimeter governed by the US defence department, and the Italian majority shareholder cannot direct it.

The facts as announced

  • What is being bought: Raft supplies “open-architecture mission software, specializing in multi-domain data fusion and artificial intelligence” for US government and defence customers. Its own site lists three products: Raft Data Platform, Raft AI Mission System, Raft Application Platform.
  • The price: $450 million, all cash, subject to customary post-closing purchase price adjustments.
  • The funding: cash on hand and borrowings under Leonardo DRS’s revolving credit facility. No new equity, no paper.
  • The timing: closing expected in Q4 2026, subject to “regulatory approvals and other customary closing conditions”. Which approvals is not stated.
  • The company’s own estimates: a tax benefit over the next 15 years, present value calculated at roughly $50 million; the deal is expected to be accretive to Adjusted Diluted Earnings Per Share — a non-GAAP measure the company defines in the same release — in the first full year of ownership.
  • The quotes: John Baylouny, president and chief executive of Leonardo DRS, says customers “increasingly require integrated hardware, software, data and autonomy to support mission outcomes”. Shubhi Mishra, founder and chief executive of Raft: “Our open-architecture platform was built to integrate across systems, not lock customers in.”
  • What is not disclosed: Raft’s revenue, headcount, backlog, or the multiple paid. Neither the Leonardo DRS release nor the Leonardo S.p.A. one contains them.

Who Raft is, according to the federal register

Press releases describe; the US federal awards register measures. On USAspending.gov, adding up the prime contracts awarded to RAFT LLC between 2018 and 30 July 2026 — excluding framework vehicles — gives about thirty awards worth roughly $320 million in total obligations. More than 85% of that comes from two customers: the US Air Force and USTRANSCOM, the transportation command. The largest are Cloud CITI 2.0 (about $50.9m, 2021-2025), the ENDOR programme (about $35.9m, from 2022) and a lot described as “ABMS CBC2 Comms Broker” (about $34.6m, from 2023); Platform One, the US defence DevSecOps environment, and Unified Platform also appear. The remainder, under $50 million, comes from civilian agencies: the Consumer Financial Protection Bureau, offices of the Department of Health and Human Services, the General Services Administration.

Two practical readings. Raft is not an arms supplier: it supplies software infrastructure, data integration and development platforms inside military programmes. And its customer base is almost entirely American and federal. A company built that way does not carry a catalogue that moves continent when the shareholder changes.

The part the releases leave out: the proxy agreement

For that you need the one document that talks about control rather than strategy — the Form 10-K annual report Leonardo DRS filed with the SEC on 27 February 2026. It states that US Holding, wholly owned by Leonardo S.p.A., holds “approximately 71%” of DRS’s voting power; that the Italian state beneficially owns “approximately 30.2%” of Leonardo’s voting power; and that as a result DRS is “deemed to be under FOCI” — foreign ownership, control or influence — under the NISPOM, and “deemed to be controlled by a foreign government by certain U.S. regulatory authorities”.

To keep its security clearances and work on classified programmes, that status has to be mitigated. The instrument is an amended and restated proxy agreement with the defence department — named in the filings as “the U.S. Department of War, also known as the U.S. Department of Defense” — which expires in March 2030. The 10-K sets out what it does:

  • shares held by US Holding and indirectly by Leonardo are voted by proxy holders who must be independent of the group, cleared, and members of the board, and whose appointment is subject to DCSA approval;
  • it restricts the ability to share facilities and personnel with, and to receive certain services from, Leonardo S.p.A. or its other subsidiaries;
  • the board must maintain a government security committee;
  • meetings, visits and communications with the parent that are not routine business visits are regulated;
  • an annual compliance report goes to the DCSA and the company is subject to periodic FOCI audits. The 10-K adds, in its own words, that DRS has “at times been found to not have strictly complied” with the agreement or the relevant security requirements, without being sanctioned to date.

The majority shareholder keeps “certain limited, enumerated consent rights”, among them material mergers and acquisitions and the incurrence of debt. Whether this transaction falls inside that perimeter neither release says, and the Rome statement goes no further than calling it aligned with group strategy. What the agreement rules out in any case is that a shareholder’s approval should translate into use of the acquired technology. The company writes it plainly in its risk factors: the restrictions on communications, facilities, personnel and services mean DRS “cannot benefit from the full range of synergies and cost savings typically enjoyed by a majority-owned subsidiary”. On a material breach or a failure to renew, the department may novate the classified contracts to another company at DRS’s expense, terminate them, revoke the facility clearance, or suspend or debar the company from US government contracting.

What this means for buyers in Europe

That a software capability bought in the United States by a European group does not thereby become available in Europe. Three filters sit in between: the proxy agreement covering classified information, US export control — ITAR and EAR, which Leonardo DRS lists among its own risk factors — and the contract terms with the federal customers who paid for the development. It is the same mechanism, reversed, as export controls used as negotiating leverage: share ownership is a balance-sheet fact, operational availability is a licensing fact.

Then there is the part that applies to anyone buying software, defence or not. “Open architecture” and “not lock customers in” are seller’s statements, not clauses. They become testable only when the contract names the formats, the interfaces, the exportability of data and trained models, and what happens if the supplier changes owner halfway through a multi-year programme. The same rule as with badly written procurement requirements: what is not written down and measurable does not exist.

What to do now

  1. Separate signing from closing. The agreement is definitive; the transaction is not. Closing is expected in Q4 2026 and the regulatory approvals are unspecified. Until then Raft is an independent supplier with its own contracts and commitments.
  2. Ask which legal entity signs and which one delivers. Not “the group’s technology”, but: who is the counterparty, in which jurisdiction, under which governing law, with which export authorisations already granted. For a subsidiary under a proxy agreement the answers differ from the parent’s.
  3. Put the change-of-control clause in the contract. Continuity of support, price protection, an exit right with data export: those are the three things an acquisition can quietly change.
  4. Test openness, do not take the word for it. Documented formats, published interfaces, exportable data, ontology and model weights. If it cannot be tested at acceptance, it is marketing.
  5. Know which layer you are buying. A model, an integration platform and a managed service are three different dependencies with three different exits. We have set out how we reason about ownership of the stack in Hardware and open-weight models.

The underlying point is that the sovereignty of a system is not read in the share register: it is read in the authorisations, the contracts and the physical place where the data is processed. That is why a dedicated AI system should be delivered in two ways, never one alone: on-premise in the customer’s own environment, or CSIDIA’s dedicated cloud — an environment reserved for a single customer, accessed through a dedicated VPN, with a data centre in Italy staffed directly by us. Either way the perimeter is verifiable before signature, not after. It is the criterion behind the method, not any supplier’s catalogue.

Assessing a supplier controlled by a foreign group, or a technology subject to export control? Half an hour with one of our specialists to read the constraints before the requirements are written.

Sources