Every conversation we have with a defence or policing counterparty arrives at the same question within about ten minutes: what does the system do on its own, and what does it never do on its own? The answer determines everything downstream — the procurement route, the legal review, the authorisation model, and whether the deployment is politically survivable.
Two different things get called autonomy
The first is autonomous delivery: getting a capability to a location without a human in the loop. A trigger fires, the best-placed station launches, the platform navigates to the coordinate, holds station and streams what it sees. No pilot, no dispatcher, no queue.
The second is autonomous action: the system deciding, by itself, to do something that affects a person. These get discussed as if they were the same technical question. They are not. The first is an engineering problem about navigation and readiness. The second is a question about authority, and it does not have an engineering answer.
Autonomy should compress the distance between a decision and its effect — never replace the person making it.
Why the delivery half is worth solving
The operational gap in almost every security estate is not detection. Cameras, fence-line sensors and alarm panels generate more detections than anyone can act on. The gap is verification and presence: minutes pass before something physically reaches the point, and in those minutes the situation resolves itself in whatever direction it was already heading.
- A patrol takes eight to fifteen minutes to reach a remote perimeter section
- False alarms consume the same response budget as real ones
- Personnel are committed to a contact nobody has actually seen yet
- Evidence of what happened is reconstructed afterwards, if at all
Removing the human from dispatch fixes all four. It does not remove anyone from the decision — it gets the decision-maker a picture while the decision still matters.
Why the action half should stay closed
Once a system can act on a person without an authorising officer, three things become impossible to guarantee: that the action was proportionate, that it was lawful under the rules applying to that site, and that anyone can be held responsible for it afterwards.
We treat that boundary as architectural rather than configurable. Deployment is autonomous. Intervention requires an authorised officer, with the authorisation recorded against their identity, and — for sensitive actions — a second officer approving independently. There is no setting that turns this off, because a setting that can be turned off is a setting that will be turned off under pressure.
What this costs us
It costs speed at the margin. A fully autonomous system could act half a second faster than one that waits for a human. In exchange, the deployment is reviewable, the evidence holds up, and the officer who authorised the action can explain why.
For the customers we build for, that trade is not close. Systems that operate near people earn their place by being accountable, not merely by being fast.