Ukraine · Defence Procurement

DOT-Chain Defence: A Training Course as a Signal of Procurement Institutionalisation

Ukraine’s rollout of DOT-Chain Defence training across the Armed Forces signals something larger than the launch of another digital tool. As the system moves into operational use, it is becoming part of the institutional infrastructure through which defence procurement is organised, executed and controlled.

DOT-Chain Defence: From Procurement Pilot to Legal Grey Zone

Reviewed by Oleksandr Sobovyi, Founder & CEO of CORVUS AI — editorial responsibility statement below.

On 13 August 2026, Ukraine's Ministry of Defence added an official training course on the DOT-Chain Defence weapons marketplace to the Army+ app, walking military personnel through the full order cycle — from platform access to tracking deliveries.[^1]

The training course itself is not a legal reform. What matters legally is a different signal: the state is now training end users to work with the marketplace as a permanent element of procurement infrastructure, not as a temporary pilot tool. That shift in de facto status is arriving ahead of any formal legal codification, and the gap between the two is where the next round of regulatory and contractual risk will surface.

The institutional shift is backed by scale. One day after the course launched, the Ministry reported that the Defence Forces had received over 1.2 million drones and other assets worth UAH 69.2 billion through DOT-Chain in the platform's first year of operation.[^2] A system generating that volume is no longer a pilot by any reasonable definition — it is core procurement infrastructure operating without a settled liability architecture.

Configurability as a Source of Uncertainty

In parallel, DOT-Chain now lets units select specific drone configurations — frame, flight stack, motor, propellers, ELRS receiver, camera, video transmitter, antenna, battery, and initiation board — through a built-in configurator.[^3]

For procurement practice, this is a genuine improvement: the end user receives a system tailored to a specific combat task. For legal qualification of the supply, it creates a problem that is not yet being discussed publicly: when a customer assembles a configuration from individual components through a marketplace, what exactly constitutes the delivered product — and who bears responsibility for the outcome: the integrator, the platform, or the component manufacturer.

This is not an abstract question. It directly determines how responsibility is allocated across the following areas:

  • Manufacturer responsibility — is liability anchored to the manufacturer of the base platform, or to each component manufacturer individually;

  • Acceptance testing — against what standard is a system accepted when no reference configuration exists;

  • Warranty — how is a warranty formulated for a product with no fixed factory specification;

  • Software/firmware baseline — which firmware version counts as the certified baseline when flight stack and receiver can be combined variably;

  • Cybersecurity — who is responsible for the compatibility and security of a component stack sourced from different suppliers;

  • Defect attribution — how is a defect localised in a system assembled from independently manufactured units;

  • Product configuration — is the configuration itself recorded as a distinct unit of account, and at what stage;

  • IP — how are rights allocated over integration solutions and the configuration itself;

  • Downstream operation — who is responsible for servicing and modification after delivery.

Why This Gets Harder, Not Easier

For the future production of Ukrainian systems on EU territory, none of these questions get simpler — they get harder. Regulation (EU) 2024/2847 (the Cyber Resilience Act) imposes vulnerability-handling and security-by-design obligations on manufacturers of products with digital elements across the entire product lifecycle.[^4] Directive (EU) 2024/2853, the EU's revised product liability regime, expressly addresses cases where a product is modified or assembled from components after being placed on the market, and extends liability exposure to component manufacturers and to software.[^5] A configurable marketplace procurement model transplanted into the EU jurisdiction without a pre-fixed liability architecture creates a compliance risk at the point of entry — not somewhere down the line in operation.

Recommendation

Companies working with DOT-Chain, or considering localised production in the EU, should fix the allocation of responsibility between the platform integrator and individual component manufacturers in their contract architecture now — and lock in an acceptance-testing methodology for customised configurations before it becomes the subject of a warranty dispute or a product liability claim. CORVUS AI is available to review the current contractual structure and build a compliance protocol for configurable supply chains that accounts for CRA and EU product liability requirements.

What matters. What’s next.

Disclaimer

This article has been prepared by CORVUS AI for general informational and educational purposes only. It is intended to make complex legal and regulatory developments easier to understand.

It does not constitute legal advice and does not create a professional adviser–client relationship. The information should not be relied upon as a substitute for advice based on the specific facts, circumstances and applicable law relevant to your organisation or project.

The article reflects our understanding of the law and regulatory framework as of the date of publication. Legislation, case law, regulatory guidance and administrative practice may subsequently change. While reasonable care has been taken in preparing this article, CORVUS AI does not warrant that the information is complete or remains current after the date of publication. We do not undertake to update this content.

To the fullest extent permitted by applicable law, CORVUS AI excludes liability for loss arising from reliance on this article. Nothing in this article constitutes an offer or solicitation to provide regulated legal services in any jurisdiction where doing so would be unlawful.

AI-assisted preparation: This article was prepared with the assistance of AI tools. Its legal analysis, conclusions and final text were subject to human review and editorial control and were reviewed and approved prior to publication by Oleksandr Sobovyi, Founder & CEO of CORVUS AI. CORVUS AI retains editorial responsibility for the published content.

For advice tailored to your organisation, project or specific circumstances, please contact CORVUS AI.

Notes

[^1]: Ministry of Defence of Ukraine, "Army+ adds DOT-Chain Defence weapons marketplace course," 13–14 August 2026: https://censor.net/en/news/4018208/army-adds-dot-chain-defence-weapons-marketplace-course ; Ukrainian-language original: https://www.ukrinform.ua/rubric-society/4153928-u-zastosunku-armia-zapustili-kurs-marketplejs-zbroi-dotchain-defence.html

[^2]: "DOT-Chain Defence delivers 1.2 million drones in one year," Ministry of Defence of Ukraine via Censor.NET, 14 August 2026: https://censor.net/en/news/4018417/dot-chain-defence-delivers-1-2-million-drones-in-one-year

[^3]: Ministry of Defence of Ukraine / Defence Procurement Agency, "DOT-Chain Defence launches drone constructor," 3 July 2026: https://mezha.net/eng/bukvy/bfcf6176_dot-chain_defence_launches/ ; see also the earlier configurator announcement, Defence Procurement Agency, 3 October 2025: https://dpa.mod.gov.ua/en/page/soldiers-can-now-customize-drones-for-mission-specific-needs-via-dot-chain-defence

[^4]: Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements (Cyber Resilience Act), OJ L, 2024/2847, 20.11.2024: https://eur-lex.europa.eu/eli/reg/2024/2847/oj

[^5]: Directive (EU) 2024/2853 of the European Parliament and of the Council of 23 October 2024 on liability for defective products and repealing Council Directive 85/374/EEC, OJ L, 2024/2853, 18.11.2024: https://eur-lex.europa.eu/eli/dir/2024/2853/oj

logo