Defence & Dual-Use

EUDEX 2026: When Defence Technology Becomes a Legal Question

EUDEX showed that bringing defence and dual-use technology to market is rarely just a technical challenge. Conversations around drones, GNSS, AI, autonomous systems and cross-border cooperation quickly lead to questions of regulatory compliance, liability, IP, cybersecurity, export controls and procurement. These legal issues increasingly determine whether promising technology can actually be deployed, contracted and scaled across Europe.

Complex law. Clear action.

Reviewed by Oleksandr Sobovyi, Founder & CEO of CORVUS AI — editorial responsibility statement below.

EUDEX was useful not simply because of the technologies on display.

What was more interesting was how quickly many commercial conversations turned into legal questions.

A company may have a capable antenna, UAV component, navigation solution, AI-enabled system or other advanced technology. Another company may see an opportunity to integrate it, distribute it or introduce it into a new market.

Commercially, this can look straightforward.

Legally, it rarely is.

Once defence or dual-use technology begins moving across borders — between manufacturers, integrators, distributors, government customers and operational users — several questions appear almost immediately.

And the applicable legal regime cannot be determined by looking at the technology alone.

Intended purpose, product configuration, end user, contractual role and jurisdiction may materially change the analysis.

1. What exactly is the product — legally?

This is often the first question that should be asked, but commercially it is frequently one of the last.

A GNSS antenna, communication module, navigation system or autonomous component may look like one product from an engineering perspective.

From a regulatory perspective, however, its treatment may depend on:

  • its intended purpose;

  • whether it is supplied as a standalone product or integrated into another system;

  • whether the relevant use is civil, dual-use or military;

  • the software and connectivity incorporated into it;

  • whether AI functionality is involved;

  • and the jurisdiction in which it will be placed on the market or deployed.

That classification can determine which regulatory regimes become relevant.

For civilian UAS and products intended for the civil UAS market, for example, Commission Delegated Regulation (EU) 2019/945 establishes requirements relating to the design and manufacture of certain UAS and their making available on the EU market. Military systems require a separate regulatory analysis. EU rules on unmanned aircraft systems — EUR-Lex

Radio equipment, connected products and software-enabled components may trigger other regulatory regimes.

The practical consequence is important:

market strategy should follow regulatory classification — not the other way around.

Before promising a customer that a technology can be deployed across Europe, a company should know which legal regime actually applies.

2. Where does civil technology end and defence technology begin?

This question appeared repeatedly in different forms.

Many technologies used in the defence ecosystem are inherently capable of operating across civilian and military environments.

Navigation, positioning, communications, geospatial intelligence, computer vision, AI, robotics, cybersecurity and autonomous systems are obvious examples.

But civil, dual-use and military classifications are not interchangeable concepts.

A product may have civilian applications while still incorporating controlled dual-use technology. Equally, a military end use does not by itself determine classification under every applicable regulatory regime.

The EU Dual-Use Regulation establishes a control regime covering exports, brokering, technical assistance, transit and transfers of dual-use items. The definition of dual-use items expressly includes certain software and technology, not merely physical goods. Regulation (EU) 2021/821 — EUR-Lex

This matters particularly where engineers provide technical documentation, software updates, integration assistance, training or other technical support across borders.

The correct question is therefore not simply:

“Is this a defence product?”

It is:

What exactly is being transferred, to whom, for what end use, in which configuration, and under which jurisdiction?

And, where relevant, does the item or transaction actually fall within an applicable export-control regime?

The controlled element may not always be the box being shipped.

Sometimes it is the software, technical knowledge or technology behind it.

3. Who owns the result after integration?

EUDEX also reinforced something we repeatedly see in technology partnerships: companies often discuss technical integration much earlier than they discuss intellectual property.

Imagine a European manufacturer integrating a third-party GNSS technology into a UAV or autonomous platform.

Several layers of IP can immediately appear.

Background IP
What did each party own before the cooperation started?

Integration IP
Who owns interfaces, modifications, adapters and engineering work required to make the systems work together?

Foreground IP
Who owns technology developed during the project?

Licensing and access rights
Even where ownership is clear, what rights does the other party receive? For which fields of use, territories, platforms and customers?

Software and firmware
Can the integrator modify them? Can the customer obtain access? What happens if the original supplier stops supporting the product?

Data and test results
Who can use flight data, test results, performance information and other data generated during integration?

Improvements
If operational experience results in a better version of the technology, who owns the improvement?

Without answers to these questions, a successful prototype can produce a difficult commercial dispute later.

The issue becomes even more significant where government procurement or EU-funded R&D is involved, because contractual access rights, programme-specific IP rules and government-use rights may sit on top of ordinary IP ownership.

4. What happens when the technology reaches Ukraine?

Ukraine presents a particularly important legal case.

For many European defence companies, Ukraine is simultaneously:

  • an operational environment;

  • a major defence customer;

  • a source of operational feedback and innovation;

  • a potential manufacturing and industrial partner;

  • and an increasingly important participant in the European defence-industrial ecosystem.

But transferring technology to Ukraine is not merely a sales decision.

Several separate questions may need to be assessed.

Who is the contractual customer?

Who is the ultimate end user?

Does the relevant authorisation permit re-export, re-transfer, modification or incorporation into another platform?

Can Ukrainian engineers modify the technology?

Can operational feedback be used to improve the product?

Can the resulting version subsequently be supplied to customers elsewhere?

Who owns the technical knowledge generated through that process?

And what licensing, export-control or end-use restrictions apply to the initial transfer and any subsequent transfer?

These questions become particularly important where operational experience contributes directly to product development.

The legal architecture should be designed before valuable technology, data and know-how start moving between organisations.

5. A distribution agreement may not be enough

Another issue arose from discussions around representation and market partnerships.

A technology company may say:

“We need someone who can help us enter the European market.”

The obvious commercial solution may be a distributor, representative or sales agent.

But in defence and dual-use markets, that relationship often requires considerably more structure.

Who may approach government customers?

Who controls pricing?

Can the representative make commitments on behalf of the manufacturer?

Who manages public tenders?

Who is responsible for regulatory statements made to customers?

Which party handles export-control classification, sanctions and restricted-party screening, licensing and end-use/end-user controls?

What happens if the representative identifies the opportunity but the manufacturer later contracts directly with the customer?

What territory is exclusive?

What constitutes a protected lead?

And how is liability allocated if a component fails after being integrated into another company's platform?

A two-page commission agreement may not be enough to answer these questions.

For sophisticated technology, market entry may need to develop through several stages:

market-entry mandate → technical evaluation → regulatory assessment → pilot/integration → procurement → long-term distribution or industrial cooperation.

That often reflects commercial reality better than simply appointing a “sales partner”.

6. Cybersecurity is becoming part of product market access

Another recurring theme behind many technologies at EUDEX was connectivity.

Modern defence and dual-use systems are increasingly software-defined and connected.

That means cybersecurity is no longer simply an IT department issue.

For relevant products, it increasingly affects product design, vulnerability management, documentation, incident reporting and market access.

The EU Cyber Resilience Act establishes the horizontal EU cybersecurity framework for products with digital elements.

But timing matters.

Most of the CRA applies from 11 December 2027. However, Article 14 reporting obligations already apply from 11 September 2026, while Chapter IV has applied since 11 June 2026. Cyber Resilience Act — Regulation (EU) 2024/2847

There is also a regulatory transition underway for certain radio equipment.

Cybersecurity requirements activated under the Radio Equipment Directive have applied to relevant radio equipment since 1 August 2025. Commission Delegated Regulation (EU) 2026/339 will repeal the relevant delegated act with effect from 11 December 2027, when the CRA becomes fully applicable, in order to avoid overlapping cybersecurity regimes.

For manufacturers and integrators, this raises a practical question:

who owns cybersecurity compliance when several companies build one system?

The hardware manufacturer?

The software provider?

The system integrator?

The platform manufacturer?

Or the economic operator placing the final product on the EU market?

That allocation should be understood — and, where appropriate, reflected contractually — before an incident exposes the gaps.

7. Liability follows the value chain

The same logic applies to product liability.

Modern systems rarely originate from a single supplier.

A UAV may combine:

  • third-party navigation equipment;

  • communication modules;

  • sensors;

  • embedded software;

  • AI functionality;

  • cloud services;

  • external data;

  • and integration work carried out by another company.

The revised Product Liability Directive (EU) 2024/2853 reflects this increasingly digital product environment and expressly includes software within the concept of a product.

But the timing again matters.

Member States must transpose the Directive by 9 December 2026, and, following the 2026 corrigendum, the new regime applies to products placed on the market or put into service after 8 December 2026.

So for current products and claims, the applicable liability regime still needs to be determined carefully rather than assuming that the new Directive already governs every case.

As several suppliers contribute to one system, the practical question becomes:

how is liability allocated — and how do rights of recourse operate — across the supply chain?

This makes specifications, warranties, acceptance testing, change-control procedures, cybersecurity records, technical documentation and contractual recourse commercially important.

They are not merely legal boilerplate.

Evidence becomes part of product design.

The broader lesson from EUDEX

EUDEX confirmed something that is easy to underestimate in defence innovation.

Technology does not enter a market by itself. It enters through a legal structure.

Before an antenna, UAV, AI system or autonomous platform reaches a customer, someone needs to determine:

  • what the product legally is;

  • which regulations apply;

  • whether and under what conditions it may cross borders;

  • who owns the underlying and resulting technology;

  • who may modify it;

  • who carries the compliance burden;

  • who controls the customer relationship;

  • and who bears responsibility when something goes wrong.

These questions can look secondary while companies are discussing engineering.

They are not.

They often determine whether a promising technological partnership becomes a scalable business — or a contractual and regulatory problem.

For companies operating between the EU and Ukraine, this legal architecture is becoming particularly important.

The opportunity is significant.

But companies that structure regulatory, contractual, IP and export-control issues early will be in a much stronger position to convert technological capability into actual deployment.

Complex technology requires more than technical integration. It requires legal integration as well.

Disclaimer

This article has been prepared by CORVUS AI for general informational and educational purposes only. It is intended to make complex legal and regulatory developments easier to understand.

It does not constitute legal advice and does not create a professional adviser–client relationship. The information should not be relied upon as a substitute for advice based on the specific facts, circumstances and applicable law relevant to your organisation or project.

The article reflects our understanding of the law and regulatory framework as of the date of publication. Legislation, case law, regulatory guidance and administrative practice may subsequently change. While reasonable care has been taken in preparing this article, CORVUS AI does not warrant that the information is complete or remains current after the date of publication. We do not undertake to update this content.

To the fullest extent permitted by applicable law, CORVUS AI excludes liability for loss arising from reliance on this article. Nothing in this article constitutes an offer or solicitation to provide regulated legal services in any jurisdiction where doing so would be unlawful.

AI-assisted preparation: This article was prepared with the assistance of AI tools. Its legal analysis, conclusions and final text were subject to human review and editorial control and were reviewed and approved prior to publication by Oleksandr Sobovyi, Founder & CEO of CORVUS AI. CORVUS AI retains editorial responsibility for the published content.

For advice tailored to your organisation, project or specific circumstances, please contact CORVUS AI.

CORVUS AI — Cross-Border Legal Intelligence between the EU and Ukraine.
Complex law. Clear action.

logo