Approval boundaries determine architecture
Classification, export controls and system authorisations constrain where information may go. A cheaper provider is irrelevant if the route is prohibited.
Defence organisations could answer administrative and acquisition questions inside an approved environment before considering metered inference. This thesis models an unclassified pilot, not an authorised classified deployment or an operational decision system.

SIPRI's 2025 Trends in World Military Expenditure report put global military spending at $2.887 trillion in 2024, up 9.4% in real terms. That increase strengthens the case for disciplined support spending, but it does not quantify demand for AI routing.
NATO's June 2024 defence-expenditure estimates projected that 23 of its 32 allies would meet or exceed spending of 2% of GDP that year. This was a contemporary estimate, not a final outturn, and it illustrates the breadth of national procurement environments.
The US Government Accountability Office's 2024 Weapon Systems Annual Assessment examined 95 major programmes with nearly $2.4 trillion in planned investment. That programme scale creates substantial document and assurance work without making automated military judgement appropriate.
Classification, export controls and system authorisations constrain where information may go. A cheaper provider is irrelevant if the route is prohibited.
Acquisition teams navigate requirements, contract clauses and assurance records across repositories. Finding the controlled source is often more useful than generating a new explanation.
Administrative assistance must remain separate from command, targeting and weapons employment. Human accountability cannot be delegated through a routing decision.
Each application is a real workflow, mapped to the tier that could answer it. The waterfall tries the cheapest trustworthy source first and only pays a frontier model when the expected value clears the gate.
Personnel teams could reuse approved explanations of routine administrative policy. An unresolved question would not justify sending restricted material to an external model.
Acquisition staff could find relevant wording across authorised records. Contracting officers and legal advisers would retain interpretation and approval authority.
Programme teams could assemble existing evidence without exporting source files. The system would not infer that missing evidence means a requirement has been satisfied.
Teams could draft action lists from material cleared for the selected processing environment. Staff would check commitments, ownership and omissions before circulation.
Programme analysts could compare documented cost, schedule and supplier-risk scenarios. The workflow would exclude targeting, weapons employment and autonomous operational decisions.
A thesis, not a case history. The assumptions are stated so you can replace them with your own numbers — which is exactly what a pilot does in week one.
Ledger rates are the vendors’ own published list prices: $0.0150 per premium question and $0.00065 per fast question at 1,500 input / 700 output tokens.
At published vendor prices this thesis models $8,492 of avoided annual inference spend — $9,000 down to $509, a 94.4% reduction — before the excluded costs above.
Where NIST SP 800-171 requirements apply to controlled unclassified information, access restrictions, masking, provider blocks and maximum-tier clamps would run before routing, while Enterprise Search would stay inside the approved perimeter. Receipts would show exact inference cost, configured premium baseline cost, savings and what stayed private, with access to receipts also controlled.
For ITAR-controlled technical data under 22 CFR Parts 120–130, the organisation would define permitted users, locations and processing environments before enabling a workflow. Provider routing would not substitute for an export authorisation, and Open Models would be user-picked only within policy.
A deployment would need assessment and any required authorisation under applicable frameworks such as DoD Instruction 8510.01 and NIST SP 800-53, whether using Qua Cloud, customer VPC or an air-gapped environment. No classified authorisation is claimed, and Pro Models would remain unavailable unless both policy and the expected-value gate permit them.
Market figures come from the publishers below. Qua savings are modelled from the vendors’ published list prices — they are not customer results.