AI Regulation in Ukraine’s Defence Sector
Ukraine has no single AI law that comprehensively regulates defence AI systems. Companies developing, supplying or deploying AI solutions for Ukrainian defence customers are nevertheless subject to existing rules on export control, defence procurement, cybersecurity, critical infrastructure, state secrets, personal data, intellectual property and product liability. Since March 2026, Ukraine has also operated a specific experimental regime for military-purpose goods involving AI technologies.
This article is intended for foreign defence-tech manufacturers, AI developers, technology suppliers, investors, and legal and compliance teams assessing projects with Ukrainian defence customers or entering the Ukrainian defence market.
1. Status of AI Legislation in Ukraine
2. Policy Framework: AI Concept and Action Plan
3. Sectoral Laws Governing AI in Defence
4. Export Control and International Technology Transfers
5. Classifying AI Products as Military or Dual-Use Goods
6. Defence Procurement: AI Systems under Ukrainian Law
7. Cybersecurity and Critical Infrastructure Obligations
8. State Secrets and Classified Information
9. Personal Data Protection and Automated Decisions
10. Intellectual Property in AI Systems and AI-Generated Content
11. Liability for AI Systems and Defective Products
12. EU AI Act: Implications for Foreign Suppliers
13. Autonomous Systems, Human Oversight, and IHL
14. Sanctions and Counterparty Due Diligence
15. Practical Compliance Checklist
Frequently asked questions
How DLF Can Help
1. Status of AI Legislation in Ukraine
As of 4 September 2026, Ukraine has no dedicated AI law in force that comprehensively regulates AI. Cabinet of Ministers of Ukraine Order No. 457-r of 9 May 2025 “On Approval of the Action Plan for Implementing the Concept for Artificial Intelligence Development in Ukraine for 2025–2026” provides for the development and submission of draft AI legislation in Q4 2026. This is a planning deadline for legislative work, not a date on which a future AI law will automatically enter into force.
Ukraine has signed the Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law (CETS 225). Article 3(4) of the Convention expressly states that matters relating to national defence fall outside its scope. The Cabinet of Ministers’ announcement on Ukraine’s signature of CETS 225 is available on the Government portal.
Separately from any future general AI law, Cabinet of Ministers of Ukraine Resolution No. 310 of 12 March 2026 “Certain Issues of Implementing an Experimental Project for the Development of Military-Purpose Goods in the Field of Artificial Intelligence Technologies and Determining Specific Features of the International Transfer (Export) of Such Goods” has been in force since 13 March 2026. It launched a two-year experimental project for defence AI and provides specific mechanisms for access to certain software and intellectual-property assets within that project.
2. Policy Framework: AI Concept and Action Plan
Cabinet of Ministers of Ukraine Order No. 1556-r of 2 December 2020 “On Approval of the Concept for Artificial Intelligence Development in Ukraine” sets policy priorities for AI development, including defence and cybersecurity applications and decision-support systems. The Concept is a policy instrument: it directs public authorities but does not itself create a separate permit regime for private AI companies.
The 2025–2026 action plan includes work on AI cybersecurity recommendations and measures supporting the use of AI in defence. For a supplier, however, the applicable legal requirements depend not only on these policy documents but also on sectoral statutes, Cabinet resolutions, rules of the relevant regulators and the terms applicable to the specific defence project.
Resolution No. 310 is particularly relevant where a project falls within the experimental regime for military-purpose AI goods. Within that regime, the Ministry of Defence may provide eligible participants with contractual access to specified software and other intellectual-property assets. A company should therefore determine at an early stage whether the project falls within this special framework.
Related article: New model for defence innovations procurement in Ukraine
3. Sectoral Laws Governing AI in Defence
Depending on the system’s functions, the customer, the data processed and the nature of the technology transfer, several legal regimes may apply at the same time.
| Regulatory regime | When it may apply | Main legal instrument |
|---|---|---|
| State export control | International transfers of software, technology or military/dual-use goods | Law of Ukraine “On State Control over International Transfers of Military-Purpose Goods and Dual-Use Goods” |
| Defence procurement | Procurement of goods and services by state defence customers | Law of Ukraine “On Defence Procurement” |
| Cybersecurity and information protection | Deployment in public authorities, military formations or systems processing state resources or restricted information | Law of Ukraine “On the Fundamental Principles of Cybersecurity of Ukraine” and security-authorisation rules |
| Critical infrastructure | AI used at critical infrastructure facilities | Law of Ukraine “On Critical Infrastructure” |
| State secrets | AI processing information constituting a state secret | Law of Ukraine “On State Secrets” |
| Personal data | AI processing personal data or supporting automated decisions | Law of Ukraine “On Protection of Personal Data” |
| Intellectual property | Rights in software, models, data and computer-generated non-original objects | Law of Ukraine “On Copyright and Related Rights” |
| Product liability | Damage connected with defective tangible products incorporating AI | Law of Ukraine “On Liability for Damage Caused by Defects in Products” |
4. Export Control and International Technology Transfers
International transfers are governed by the Law of Ukraine “On State Control over International Transfers of Military-Purpose Goods and Dual-Use Goods” No. 549-IV of 20 February 2003. The regime covers not only tangible goods but also controlled technology and technical assistance.
Article 1 defines military technology as special information in any form necessary for the development, production or use of military-purpose goods. AI software, a model, technical documentation or another intangible component may therefore be controlled technology if its functions and the relevant control-list entry bring it within the scope of the law.
Ukrainian law uses the terms permit and conclusion, rather than the generic term “licence”. Both permits and conclusions may be single, general or open.
| Type of permit or conclusion | Maximum validity |
|---|---|
| Single | up to 1 year |
| General | up to 3 years |
| Open | up to 3 years |
Where no additional interagency coordination is required, the statutory maximum review periods are up to 45 days for export or re-export of military-purpose goods, up to 30 days for export or re-export of dual-use goods and certain temporary transfers, and up to 15 days for imports and transit. Where interagency coordination is required, the period may extend to 90 days.
The filing route depends on the transaction. In a typical import into Ukraine, the Ukrainian participant handles the principal Ukrainian export-control formalities, but the law allows a single permit or conclusion to be issued to a foreign entity in certain statutory cases.
A Ukrainian permit does not replace export-control requirements in the country of origin. EU suppliers may need to assess Regulation (EU) 2021/821; German suppliers should also consider the AWG/AWV, while US suppliers may need to assess the EAR and ITAR.
5. Classifying AI Products as Military or Dual-Use Goods
Classification depends on technical characteristics, software functions, end use, end user and the relevant control-list entry. The mere use of AI does not, by itself, make a product a military-purpose item.
The List of Military-Purpose Goods is attached to Cabinet of Ministers Resolution No. 1807 of 20 November 2003, while the relevant dual-use lists form part of the procedure approved by Cabinet of Ministers Resolution No. 86 of 28 January 2004, as amended. These control lists are published in Ukraine’s official legal database. For complex AI systems with mixed functions, a supplier should nevertheless obtain specialist classification advice or seek guidance from the SSEC before contracting or transferring the technology.
The company should also determine whether Resolution No. 310 applies. Its experimental defence-AI regime does not remove the need to identify correctly the product, technology, type of transfer and applicable authorisation requirements.
Related article: Supplying Defence Products in Ukraine
6. Defence Procurement: AI Systems under Ukrainian Law
Procurement by state defence customers is governed by the Law of Ukraine “On Defence Procurement” No. 808-IX of 17 July 2020 and secondary legislation, including special wartime rules.
The Defence Procurement Law expressly includes the development and implementation of information systems, information and analytical systems, and telecommunications systems, as well as cybersecurity and cyberdefence systems, within the concept of defence services. An AI solution may therefore fall within the Law because of its function even though the statute does not use “AI system” as a separate legal category.
Article 7 expressly provides for state and interagency testing of samples of weapons, military and special equipment. Depending on the product, an AI solution may also be subject to codification, admission to operation, acceptance into service or customer-specific requirements; these must be determined for the particular product and state customer.
During martial law, the special rules for defence procurement approved by Cabinet of Ministers of Ukraine Resolution No. 1275 of 11 November 2022 also apply. Sensitive and classified procurements are subject to additional rules on procedure and access to information.
7. Cybersecurity and Critical Infrastructure Obligations
Cybersecurity
The Law of Ukraine “On the Fundamental Principles of Cybersecurity of Ukraine” No. 2163-VIII of 5 October 2017 provides the general cybersecurity framework for public authorities, military formations, critical infrastructure operators and other entities specified by law.
Ukraine’s information-security framework changed materially in 2025–2026. Cabinet of Ministers of Ukraine Resolution No. 712 of 18 June 2025 introduced a security-authorisation procedure for information, electronic communications, information-communication and technological systems. The applicable protection and authorisation route for a particular system depends on the system category, the information processed and the customer.
Existing CIPS attestations and special sectoral procedures may remain relevant for particular systems or transitional cases.
Since 16 January 2026, SSSCIP supply-chain security requirements for suppliers, based on the risk associated with the supplied goods, works and services, have also been in force. They apply to suppliers serving owners or administrators of systems processing state information resources, official information or state secrets, and to suppliers serving critical information infrastructure. Foreign defence-tech suppliers should therefore assess supply-chain security separately from product cybersecurity.
Critical Infrastructure
The Law of Ukraine “On Critical Infrastructure” No. 1882-IX of 16 November 2021 governs categorisation, registration and protection of critical infrastructure. Its scope covers sectors that may include defence, information services, electronic communications, energy, transport and other areas designated under Ukrainian law.
Following categorisation, the applicable requirements cover entry of the object in the Register of Critical Infrastructure Objects, preparation and approval of a security passport, and protection planning. The specific procedure and deadlines for the operator are determined by the general passporting rules and any applicable sectoral regulations.
Ownership, control and sanctions restrictions must be reviewed separately. A foreign AI supplier should conduct due diligence on its ultimate beneficial owners, key subcontractors and supply chain before contracting for a critical-infrastructure project.
8. State Secrets and Classified Information
The framework is established by the Law of Ukraine “On State Secrets” No. 3855-XII of 21 January 1994. Defence AI systems may process information concerning weapons, military R&D, command systems, mobilisation or operational planning, and other information classified as a state secret under Ukrainian law.
An organisation conducting activities involving state secrets must hold the relevant permit from the Security Service of Ukraine (SBU). As a general rule, security clearance for state secrets is granted to Ukrainian citizens under the statutory procedure. Foreign nationals and stateless persons may be granted access only in exceptional cases on the grounds provided by law.
The technical requirements for the information system depend on the data category and the applicable technical and cryptographic protection regime. There is no single universal “AI certificate”. The requirements of the SBU, the State Service of Special Communications and Information Protection of Ukraine (SSSCIP), and the customer must be determined for the specific system and environment.
9. Personal Data Protection and Automated Decisions
The Law of Ukraine “On Protection of Personal Data” No. 2297-VI of 1 June 2010 applies to automated processing. Data subjects have the right to know the mechanism of automated processing and the right to protection against an automated decision that has legal consequences for them.
For AI systems used for screening, assessment, access decisions, identification or other individual decision-making, the supplier and customer should identify the legal basis for processing, data categories, retention periods, access rights and security controls.
Article 7 contains special rules for certain sensitive categories of personal data and exceptions, including processing connected with statutory operational-search or counter-intelligence tasks and counter-terrorism. These exceptions apply only in the circumstances provided by law and do not exempt defence-AI projects from the other requirements of Ukrainian personal-data legislation.
10. Intellectual Property in AI Systems and AI-Generated Content
The Law of Ukraine “On Copyright and Related Rights” No. 2811-IX of 1 December 2022 distinguishes human-created works from non-original objects generated by a computer program.
Human-authored software may receive copyright protection. Article 33, by contrast, provides a sui generis right for non-original objects generated by a computer program. Right holders may include persons holding proprietary rights in the relevant computer program or persons authorised to license it; a contract may provide for a different allocation of the right.
The sui generis right lasts 25 years, calculated from 1 January of the year following the year in which the object was generated. Article 33 links entitlement to proprietary rights in, or licensing authority over, the relevant computer program; it does not establish a “substantial investment” criterion.
For defence contracts, Cabinet of Ministers of Ukraine Order No. 342-r of 10 April 2026 “On Approval of the Intellectual Property Management Policy in the Defence-Industrial Complex of Ukraine” is also relevant. It requires state defence customers and relevant defence-industry entities to address intellectual-property issues and the allocation of rights in defence contracts and other agreements.
Resolution No. 310 may create additional licensing arrangements for access to software and IP assets where proprietary rights are held by the State represented by the Ministry of Defence within the experimental project. IP ownership in a specific defence-AI project is determined by the applicable law, the origin of the underlying technology, the special regulatory regime and the contract, rather than by a general presumption in favour of either the developer or the State.
Training data require a separate review. If model training uses copyrighted works, databases, confidential information or third-party data, the legal basis for that use should be identified, including any required licence, permission or contractual terms.
11. Liability for AI Systems and Defective Products
The Law of Ukraine “On Liability for Damage Caused by Defects in Products” No. 3390-VI of 19 May 2011 establishes a special producer-liability regime for defective products. It includes a three-year limitation period running from the point when the injured person knew or should have known of the damage, defect and producer, and a ten-year long-stop period from the placing of the product on the market.
The Law does not contain a dedicated regime for standalone software or AI as an independent digital product. For a software-only AI solution, the application of this special product-liability regime depends on the product structure and the circumstances of the damage.
For defence AI, contracts should allocate risk expressly: warranties, testing obligations, incident notification, defect handling, model updates, version control and liability caps where legally permitted. General Ukrainian Civil Code rules may apply in parallel depending on the basis of the claim.
12. EU AI Act: Implications for Foreign Suppliers
The Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (EU AI Act) is not part of Ukrainian domestic law and does not apply merely because an AI system is used in Ukraine.
In the circumstances specified in the Regulation, its rules may also apply to entities outside the EU. In particular, the Regulation covers providers placing AI systems or models on the EU market, deployers located in the EU and, in specified cases, providers or deployers in third countries where the output produced by the AI system is used in the EU.
Article 2 and the recitals exclude AI systems that are placed on the market, put into service or used exclusively for military, defence or national-security purposes. If the same system is placed on the market or used for one or more non-excluded purposes as well, its defence use alone does not remove it from the scope of the EU AI Act.
An EU establishment therefore does not, by itself, mean that every export to Ukraine is automatically governed by the EU AI Act. Suppliers should analyse their role, the market on which the system is placed, the actual intended purpose, where its output is used and the applicable transition dates for the relevant category of system.
13. Autonomous Systems, Human Oversight, and IHL
The concept of “meaningful human control” is used in the international debate on autonomous weapon systems. Ukrainian law does not impose a universal requirement for such control across all autonomous weapon systems. Their use must nevertheless comply with international humanitarian law (IHL).
Ukraine is a party to the Geneva Conventions and applicable Additional Protocols. The use of AI in hostilities remains subject, among other rules, to the principles of distinction, proportionality and precautions in attack. Questions of individual or command responsibility depend on the applicable international-law rules and the facts of the particular decision or operation.
CETS 225 does not add a separate layer of regulation for national defence because Article 3(4) expressly excludes matters relating to national defence from the Convention’s scope.
14. Sanctions and Counterparty Due Diligence
The Law of Ukraine “On Sanctions” No. 1644-VII of 14 August 2014 provides for different types of special economic and other restrictive measures. Their legal effect depends on the specific sanction, the relevant decision of the National Security and Defence Council of Ukraine (NSDC) and the Presidential decree giving effect to it.
Before a defence or technology agreement is signed, suppliers should screen their own company, ultimate beneficial owners, key counterparties, intermediaries and distributors against current official sanctions information. This is a transaction-specific exercise because sanctions lists and the measures attached to particular persons can change.
Export control and sanctions should be analysed separately. Transfers connected with Russia or Belarus are subject to specific Ukrainian restrictions, while the supplier’s home-country sanctions and export-control regimes may impose additional requirements.
15. Practical Compliance Checklist
- Classify the product. Determine whether the AI solution is a military-purpose good, a dual-use good or controlled technology.
- Identify the type of transfer. Establish whether an SSEC permit or conclusion is required, who should apply and which form of authorisation applies.
- Check the defence-AI experimental regime. Determine whether Resolution No. 310 applies and whether Ministry of Defence software or IP assets are involved.
- Analyse the defence procurement route. Confirm the customer’s status, procurement regime and any product-specific codification, testing or admission requirements.
- Run a cybersecurity review. Determine the applicable security-authorisation route, the status of any existing CIPS attestation and supply-chain security requirements.
- Check the state-secrets regime. Determine whether an SBU permit, personnel security clearances or other lawful access arrangements, and specific information-protection measures are required.
- Review personal-data processing. Identify the legal basis, categories of data, access, retention and any legally consequential automated decisions.
- Allocate IP contractually. Address rights in software, models, training data, computer-generated outputs and modifications.
- Allocate liability. Cover warranties, testing, cybersecurity incidents, defects, updates and remediation or recall procedures.
- Complete sanctions screening and home-country compliance review. Screen counterparties and separately assess the EU AI Act, EU Dual-Use rules, AWG/AWV, EAR/ITAR and other applicable regimes.
Frequently asked questions
Does Ukraine have a law governing AI in the defence sector?
Ukraine has no single AI law. Defence AI is regulated through existing sectoral legislation, while a specific two-year experimental project for military-purpose AI goods has been in force since March 2026. The Government’s action plan calls for the development and submission of general draft AI legislation in Q4 2026.
Does the EU AI Act apply to AI systems supplied to Ukraine?
Not automatically. The EU AI Act’s territorial scope, the company’s role and the system’s intended purpose must be assessed. Systems placed on the market, put into service or used exclusively for military, defence or national-security purposes are excluded. Where the same system also has a non-excluded purpose, a separate EU AI Act analysis is required.
What export control permits are required to transfer AI software to a Ukrainian defence customer?
The need for an SSEC permit or conclusion depends on the classification of the goods or technology, the type of international transfer, end use and counterparties. Ukrainian law provides for single, general and open permits or conclusions. Complex AI systems should be classified before the contract is signed or the transfer begins.
What cybersecurity obligations apply to AI systems in Ukrainian state agencies and the Armed Forces?
The applicable requirements include the general cybersecurity and information-protection framework and, where relevant, security authorisation of the system. CIPS may remain relevant to specific systems or existing attestations, but it is not a universal requirement for every AI deployment. SSSCIP supply-chain security requirements may also apply to suppliers.
Who owns the IP in AI-generated content produced under a defence contract?
Article 33 of the Copyright Law provides a sui generis right for non-original objects generated by a computer program. As a general rule, right holders may include persons holding proprietary rights in, or licensing authority over, the relevant program; a contract may provide for a different allocation of the right. Defence contracts should also take account of the 2026 defence-industry IP policy and, where relevant, the special regime under Resolution No. 310.
Can a foreign company supply AI solutions to Ukrainian critical infrastructure operators?
Yes, provided the applicable procurement, export-control, sanctions, cybersecurity and information-protection requirements are met. The specific project requires review of the critical-infrastructure status, ownership structure, supply chain and any Ukrainian or home-country authorisations.
How DLF Can Help
DLF attorneys-at-law advises foreign defence-tech companies, AI developers, manufacturers and investors on projects with Ukrainian defence customers. We assist with identifying the applicable procurement procedures and participation requirements, reviewing and documenting intellectual-property rights, structuring supply terms and other contractual matters, and assessing export-control, cybersecurity, state-secrets, sanctions and liability requirements.
Iurii Dynys, Counsel, Attorney-at-law — DLF attorneys-at-law
Contacts: +380 44 384 24 54, info@dlf.ua.
This material is for general information only. Application of the approaches described depends on the circumstances of each case and requires separate legal assessment.
