Industry thesis

Keep sensitive knowledge inside approved boundaries

Defence organisations could answer administrative and acquisition questions inside an approved environment before considering metered inference. This thesis models an unclassified pilot, not an authorised classified deployment or an operational decision system.

Industry thesis — modelled, not deployed. Figures are potential savings.
$2.887tnGlobal military spending in 2024SIPRI, 2026
2.9%Real military spending growth in 2025SIPRI, 2026
All 32NATO allies now meeting the 2% benchmarkNATO, 2026
~$2.4tnPlanned investment across 106 programmesUS Government Accountability Office, 2025
Abstract artwork representing defense & national security workflows
Defense & national security — the cheapest trustworthy source answers first; frontier reasoning is paid for only when it earns its price.
Where the money goes today

Defense & national security: the cost of asking

SIPRI's 2025 Trends in World Military Expenditure report put global military spending at $2.887 trillion in 2024, up 9.4% in real terms. That increase strengthens the case for disciplined support spending, but it does not quantify demand for AI routing.

NATO's June 2024 defence-expenditure estimates projected that 23 of its 32 allies would meet or exceed spending of 2% of GDP that year. This was a contemporary estimate, not a final outturn, and it illustrates the breadth of national procurement environments.

The US Government Accountability Office's 2024 Weapon Systems Annual Assessment examined 95 major programmes with nearly $2.4 trillion in planned investment. That programme scale creates substantial document and assurance work without making automated military judgement appropriate.

Three pressures

What makes this industry different

Approval boundaries determine architecture

Classification, export controls and system authorisations constrain where information may go. A cheaper provider is irrelevant if the route is prohibited.

Programme evidence remains fragmented

Acquisition teams navigate requirements, contract clauses and assurance records across repositories. Finding the controlled source is often more useful than generating a new explanation.

Autonomy needs explicit limits

Administrative assistance must remain separate from command, targeting and weapons employment. Human accountability cannot be delegated through a routing decision.

Five applications

How Qua would run inside defense & national security

Each application is a real workflow, mapped to the tier that could answer it. The waterfall tries the cheapest trustworthy source first and only pays a frontier model when the expected value clears the gate.

Approved workforce policy answers

Resolves at Personal Knowledge~15,000 questions/month

Personnel teams could reuse approved explanations of routine administrative policy. An unresolved question would not justify sending restricted material to an external model.

Potential saving — 90–100% of query spend.
  • Check information markings, user access and maximum-tier policy.
  • Match the question to a verified, current unclassified workforce answer.
  • Return the cached answer and receipt; hold unresolved questions within permitted routes.

Acquisition clause applicability lookup

Resolves at Enterprise Search~15,000 questions/month

Acquisition staff could find relevant wording across authorised records. Contracting officers and legal advisers would retain interpretation and approval authority.

Potential saving — 80–100% of query spend.
  • Apply programme entitlements, export-control rules and provider blocks.
  • Check verified answers, then retrieve applicable contract and acquisition clauses.
  • Return cited source passages and a receipt within the approved perimeter.

Programme assurance evidence retrieval

Resolves at Enterprise Search~10,000 questions/month

Programme teams could assemble existing evidence without exporting source files. The system would not infer that missing evidence means a requirement has been satisfied.

Potential saving — 80–100% of query spend.
  • Restrict access by programme and information handling requirements.
  • Check verified references, then search controlled assurance records.
  • Return evidence identifiers and source passages with a privacy-and-cost receipt.

Unclassified supplier meeting summaries

Resolves at Fast Models~7,500 questions/month

Teams could draft action lists from material cleared for the selected processing environment. Staff would check commitments, ownership and omissions before circulation.

Potential saving — 80–95% of query spend.
  • Confirm release eligibility, mask identifiers and block unapproved providers.
  • Check reusable minutes and retrieve the approved meeting material.
  • Use a permitted Fast Model only for residual summarisation and issue a receipt.

Unclassified acquisition risk comparison

Resolves at Pro Models~2,500 questions/month

Programme analysts could compare documented cost, schedule and supplier-risk scenarios. The workflow would exclude targeting, weapons employment and autonomous operational decisions.

Potential saving — 0–20% of query spend.
  • Validate input eligibility and enforce environment-specific provider restrictions.
  • Check approved analyses and retrieved programme evidence for a sufficient answer.
  • Use an allowed Pro Model only when expected value clears the gate and record a receipt.
The modelled ledger

What the same year of questions could cost

A thesis, not a case history. The assumptions are stated so you can replace them with your own numbers — which is exactly what a pilot does in week one.

xAI Grok 4$3.00 in · $15.00 out / 1M tokensxAI published API pricing
xAI Grok 4 Fast$0.20 in · $0.50 out / 1M tokensxAI published API pricing
OpenAI GPT-5.5$5.00 in · $20.00 out / 1M tokensOpenAI published API pricing
Google Gemini 3.7 Flash$0.20 in · $0.80 out / 1M tokensGoogle AI published pricing

Ledger rates are the vendors’ own published list prices: $0.0150 per premium question and $0.00065 per fast question at 1,500 input / 700 output tokens.

Modelled annual comparison
  • Workload: 50,000 questions/month for 12 months, at 1,500 input and 700 output tokens per question.
  • Published list prices, not estimates — premium baseline xAI Grok 4 at $3.00/$15.00 per 1M tokens = $0.0150/question.
  • Cheap metered tier xAI Grok 4 Fast at $0.20/$0.50 per 1M tokens = $0.00065/question.
  • Terminal-tier mix: 80% verified or in-perimeter, 15% Fast Models, 5% Pro Models. Rows exclude Qua fees, retrieval infrastructure, integration and human review.
WorkloadFrontier-onlyWith Qua
Verified answers and in-perimeter search480,000 annual questions resolved with no external model call.$7,200$0
Fast Models (Grok 4 Fast)90,000 annual questions at xAI's published Grok 4 Fast rate ($0.00065/question).$1,350$58.5
EV-gated Pro Models (Grok 4)30,000 annual questions keep frontier reasoning at the published Grok 4 rate.$450$450

At published vendor prices this thesis models $8,492 of avoided annual inference spend — $9,000 down to $509, a 94.4% reduction — before the excluded costs above.

Controls that matter here

Policy runs before routing, not after

Constrain controlled information handling

Where NIST SP 800-171 requirements apply to controlled unclassified information, access restrictions, masking, provider blocks and maximum-tier clamps would run before routing, while Enterprise Search would stay inside the approved perimeter. Receipts would show exact inference cost, configured premium baseline cost, savings and what stayed private, with access to receipts also controlled.

Enforce export access restrictions

For ITAR-controlled technical data under 22 CFR Parts 120–130, the organisation would define permitted users, locations and processing environments before enabling a workflow. Provider routing would not substitute for an export authorisation, and Open Models would be user-picked only within policy.

Require system specific authorisation

A deployment would need assessment and any required authorisation under applicable frameworks such as DoD Instruction 8510.01 and NIST SP 800-53, whether using Qua Cloud, customer VPC or an air-gapped environment. No classified authorisation is claimed, and Pro Models would remain unavailable unless both policy and the expected-value gate permit them.

  • Week one would measure local-resolution rates and source traceability using an approved unclassified document set.
  • Week one would test provider blocks, programme access boundaries and receipt handling with synthetic restricted markings.
  • Week one would compare matched-task inference costs and analyst-rated completeness without using classified or operational targeting data.
Sources

Every figure on this page, traceable

Market figures come from the publishers below. Qua savings are modelled from the vendors’ published list prices — they are not customer results.

  1. [1]Stockholm International Peace Research Institute, Trends in World Military Expenditure, 2025 (2026). Source
    World military expenditure reached $2.887 trillion in 2025, an increase of 2.9% in real terms; this does not quantify demand for AI routing.
  2. [2]NATO, Defence Investment of NATO Countries (2014–2026) (2026). Source
    NATO's 2026 figures show all 32 allies now meeting the 2% of GDP benchmark, with a 3.5% defence-investment target agreed for 2035.
  3. [3]US Government Accountability Office, Weapon Systems Annual Assessment: DOD Is Not Yet Well-Positioned to Field Systems with Speed (2024). Source
    GAO's 2024 assessment examined 95 weapon-acquisition programs representing nearly $2.4 trillion in planned investment.
  4. [4]US Department of Defense, DoD Instruction 5200.48 — Controlled Unclassified Information (CUI) (2020). Source
    DoD policy establishes requirements for identifying, marking, safeguarding and disseminating Controlled Unclassified Information; access must follow applicable authorization and handling rules.
  5. [5]US Department of State / Electronic Code of Federal Regulations, International Traffic in Arms Regulations — 22 CFR Parts 120–130 (n.d.). Source
    ITAR controls exports, reexports and transfers of covered defense articles and technical data; foreign-person access can require authorization, subject to applicable exemptions.
  6. [6]US Department of Commerce / Electronic Code of Federal Regulations, Export Administration Regulations — 15 CFR Parts 730–774 (n.d.). Source
    The EAR imposes classification-dependent export, reexport and deemed-export controls on covered technology and software, supporting restrictions on cross-border and foreign-person access.
  7. [7]US Department of Defense, DoD Instruction 8510.01 — Risk Management Framework for DoD Systems (2022). Source
    The DoD Risk Management Framework requires system-specific security assessment and authorization decisions by designated officials; general approval of a model is not a system authorization.