1. Introduction
Europe is entering a sustained rearmament and defence-modernisation cycle. Geopolitical pressure, higher public spending, the push for strategic sovereignty and rapid advances in artificial intelligence are changing how defence capabilities are designed, procured and deployed.
The market shift, however, is not simply “more defence spending”. The more important change is architectural. Military capabilities are moving from a limited number of large, vertically integrated platforms towards a much larger and more heterogeneous estate of sensors, autonomous systems, software applications and data sources. The resulting challenge is no longer only to build better assets, but to connect them, coordinate them and turn their data into decisions at operational speed. Similarly, the orchestration of heterogeneous autonomous systems and AI penetration of mission-critical workflows have become major defence-technology frontiers.
This paper sets out Forestay’s perspective on this market development, with a primary focus on Europe and on businesses where software and AI represent a meaningful part of the product, moat, and economics, namely systems that integrate fragmented assets, orchestrate autonomous platforms, support operational decisions, maintain connectivity in contested environments and protect critical infrastructure.
As defence technologies are inherently linked to physical systems and hardware, this paper considers the broader hardware–software stack while maintaining a primary focus on business models where software and AI are central to the product, the competitive moat, and the economic model. We therefore exclude pure hardware businesses with no meaningful software layer.
2. Market Trends
Trend 1: Political Tension and European Sovereignty
The geopolitical landscape in Europe has shifted over the past few years. After a long period of underinvestment, Russia’s full-scale invasion of Ukraine triggered a large and sustained increase in defence spending. More recently, European leaders have placed greater emphasis on strategic autonomy, arguing that Europe should be able to provide for its own security [1].
A recurring theme is sovereign European capabilities: governments are steering spending toward domestically built defence and strategic infrastructure. This covers AI models, data centers, satellites and secure communications [2]. This shifts Europe from “buyer of foreign tech” to “builder at home,” creating: (1) new budgets and faster procurement for startups and scale-ups, (2) new industrial supply chains across the defence ecosystem, and (3) a clearer path for European companies to become category leaders in defence, dual-use, and critical infrastructure.
Sovereignty creates a structural form of market segmentation. In sensitive parts of the defence stack, product capability alone may not determine the winner: ownership, hosting jurisdiction, security accreditation, supply-chain control and the ability to operate independently of foreign vendors can all influence procurement. This gives credible European suppliers access to contracts that may be structurally unavailable to otherwise strong non-European competitors.
Trend 2: Capital is removing the historical financing constraint
Global military spending hit a record $2.9 trillion in 2025 (2.5% of global GDP), with the U.S. still the largest market ahead of China. Europe is smaller but growing faster [3]. Total defence spending by European NATO Allies and Canada grew by 64% between 2020 and 2025, against 4% in the U.S. and 30% in China over the same period [4][5].

That demand is also becoming more durable. At The Hague summit in June 2025, NATO Allies committed to spend 5% of GDP annually in core defence and security-related spending by 2035, split into 3.5% for core defence and up to 1.5% for defence-related infrastructure, more than doubling the 2% target set in 2014 [6]. Capital is following across asset classes. The STOXX Europe Total Market Defence, Space and Cybersecurity Innovation index was up 72% in 2025 [7], buyout, growth and credit strategies are all targeting the sector, and venture funding in European deep tech Defence, Security and Resilience (DSR) reached an all-time high of $8.7B in 2025 [8].

Dedicated defence funds are being raised across Europe, institutional LPs are more willing to allocate, and generalists are moving in: Bessemer, a ~$19B platform, has said there is "no limit" to what it will invest in European defence [9], and Project A is the most active VC in the space by number of rounds. Multiple large dedicated funds and vehicles illustrate this shift:
Table 1: Selected defence funds and vehicles in Europe
For startups and scale-ups, this shortens the path from prototype to scale, since larger public budgets expand the customer base while deeper private capital funds longer development cycles ahead of revenue. Exits are starting to follow, with Preligens acquired by Safran for €220M, Malloy Aeronautics by BAE Systems and Sky-Hero by Axon [13][8].
Trend 3: AI is changing the architecture of defence systems, not merely their functionality
AI-related companies accounted for 44% of all European Defence, Security and Resilience funding in 2025 [8], and several large AI developers are now working directly with defence customers. In July 2025, the U.S. Department of Defense awarded contracts worth up to $200M each to four frontier AI developers: Anthropic, OpenAI, Google and xAI [14]. This is a clear departure from a few years ago, when major AI labs explicitly avoided military applications.
The war in Ukraine has accelerated the development and use of autonomous systems and robots powered by AI. It has also exposed a fundamental cost asymmetry in modern warfare: mass-produced attack drones cost roughly $20,000 to $50,000, while the interceptor missiles used against them can cost millions of dollars each [15], which is driving demand for lower-cost, AI-enabled solutions across defence.
Regulation is developing in parallel. The UN Secretary-General has called for a global ban on lethal autonomous weapon systems (LAWS), more than 120 countries support negotiations for a treaty, and the European Parliament has called for rules guaranteeing meaningful human control [16][17]. No universally binding international treaty governing lethal autonomous weapons has yet been adopted, but the direction is clear, and this points demand toward decision-support, targeting and command-and-control (C2) software where a human stays in the loop over fully autonomous engagement, which carries both regulatory and reputational risk.
Four market themes stand out as especially relevant for software-focused venture and growth investors (covered in the next section):
- Autonomous Platforms & Robots: drones and ground robots that navigate, coordinate and execute missions with minimal human input
- Counter-air Systems: detecting, tracking and responding to incoming threats in real time
- Decision Intelligence, Surveillance and Reconnaissance (ISR): sensor fusion, geospatial analysis and decision support across the battlefield
- Cyber & Infrastructure Protection: AI-native tools that protect critical infrastructure and respond at machine speed, with demand for data center protection rising fastest
Space is becoming a large defence domain in its own right, with armed forces dependent on satellites for communications, navigation and intelligence, and some of Europe's largest defence tech rounds in 2025 were space companies such as ICEYE (€150M Series E) and Isar Aerospace (€150M convertible) [8]. It is out of scope in this article and deserves separate treatment.
3. Market Themes
Theme 1: Autonomous Platforms & Robots
How AI is being applied
Much of the AI runs on the device itself, whether a robot, drone, or vehicle, to solve problems such as:
- Navigating without GPS: Jamming has made satellite positioning unreliable across much of the front, so drones now find their way by matching what their camera sees against stored maps and by tracking their own motion.
- Finding and following targets: The device has to recognise a vehicle, keep track of it as it moves, and stay locked on when the radio link to the operator is cut.
The challenge with on-device AI is that it often has to run on a small, low-power computer that fits on the device, rather than sending and receiving data from an externally placed model/server. Helsing's HX-2 is a good example of this: it runs on device, navigates, and tracks under jamming. Its capabilities are improved weekly using real footage from Ukrainian missions [18]. Similar to other physical AI applications, limited access to high-quality operational training data remains a significant bottleneck for Autonomous Platforms & Robots. The player that owns the platform tends to be best positioned to collect and store the data, which builds up a valuable data moat over time.
A layer above the on-device AI is the software that makes different machines work together, often called swarm intelligence. Auterion, which raised $130M in September 2025 sells an operating system that lets drones from different manufacturers fly as a coordinated group [19]. Quantum Systems and ARX Robotics do something similar for mixed fleets of aircraft and ground vehicles, including older vehicles that armies already own. Software startups building swarm intelligence are often less tightly tangled with hardware, an area where the economics behave more like software.
In addition to on-device AI and swarm intelligence, the core brain behind these robots is often a world model, paired with vision-language models.
Why this theme does not behave like software
Almost none of the European leaders are pure software companies. Helsing builds its own airframes and has bought an aircraft manufacturer. Quantum Systems, Stark, Tekever and ARX all manufacture the machines their software runs on. Auterion is the closest to an exception, and even it ships a hardware module.
Owning the full platform, including the hardware, allows these players to gather and train on the data that makes the software work. In practice, it means that companies in this theme are usually manufacturing businesses that are trying to earn a software margin, which changes what we need to look at. Traditional defence companies run operating margins of around 11 to 13 percent [20], and Rothschild & Co describes the sector as capital- and hardware-heavy, with government customers that take a long time to decide [21]. Military customers typically involve longer procurement cycles and accreditation requirements, but also high switching costs once deployed. The questions become:
- Capacity: what does it cost to add manufacturing capacity, and how quickly can it be added?
- Working capital: how much cash sits in inventory, and how is production financed before contracts pay out?
- Unit economics: does the cost per unit fall meaningfully as volume rises?
- Revenue quality: how much is recurring software revenue, and how much is multi-year government contracts that arrive in tranches?
Theme 2: Counter-air Systems
What is driving demand
The economic imbalance in counter-air is increasingly unsustainable. Relatively inexpensive drones can force defenders to deploy scarce and significantly more expensive interceptors. The problem becomes more severe as attacks move from individual aircraft to larger, coordinated groups and combine different sizes, speeds and signatures.
The objective is therefore not simply to detect a drone, but to construct a reliable track from imperfect sensors, distinguish genuine threats from clutter, prioritise them and select an appropriate response quickly enough for the response to remain effective.
How AI is being applied
The hard part is no longer spotting a single drone. It is building one reliable picture from imperfect sensors, telling real threats from clutter, and choosing a response fast enough to matter. AI does two jobs:
- Detection and classification: combining radar, radio-frequency, camera and thermal feeds into a single track, and improving classification where any one sensor is ambiguous — a bird, a friendly aircraft or background clutter.
- Response coordination: recommending or assigning the right countermeasure — jamming, an interceptor, a directed-energy or microwave system — based on the threat's type, position, and urgency.
The measures that matter are therefore operational, not just technical: false-positive rate, decision latency, cost per engagement, magazine depth, interoperability, and how well the system holds up when communications are degraded.
Where value concentrates
The category contains four quite different businesses, and conflating them is the most common mistake:
- Sensors — hardware, increasingly software-defined, and commoditising fastest.
- Command-and-orchestration software — software margins, with switching costs that compound with every integration.
- Effectors — interceptors, microwave and directed-energy systems; a real moat, but an industrial one won on unit cost and production volume, which needs heavy capital.
- Civil airspace security — airports, ports, energy sites and borders; a more repeatable enterprise sales motion, commercial budgets and potentially stronger near-term revenue quality than military procurement.
Most funding has gone to the hardware layers, which leaves the orchestration software layer underfunded relative to how important it is. That software ties sensors and effectors from many different vendors into one picture and assigns the right response. It matters more as drones multiply, because no single vendor supplies the whole kit, and modern AI has only recently made this kind of real-time coordination workable.
Anduril’s Lattice product does exactly this orchestration job, but it is designed to run with Anduril's own sensors, drones and interceptors, and Anduril effectively gives the software away to sell that hardware. What protects the independents is sovereignty and openness. Customers increasingly don't want to be locked into one vendor's closed system, and European governments in particular are unlikely to run their national air picture on any single foreign vendor's stack. That creates room for a neutral layer.
Arondite's Cobalt is a vendor-neutral orchestration platform that connects any supplier's sensors, drones and effectors — including the hardware supplied by vertically integrated primes. Its pitch is that those integrated players only interoperate smoothly with their own kit, and struggle the moment a customer asks them to work alongside a competitor's system. Systematic and Palantir occupy adjacent ground, with Anduril and Helsing as the vertically integrated alternatives.
Theme 3: Decision Intelligence, Surveillance and Reconnaissance (ISR)
What is driving demand
Military organisations can now collect far more information than human teams can interpret. Satellite imagery, video, radar, electronic signals, intelligence reports, open-source data and battlefield updates often sit in different systems, at different classification levels and across different units.
The constraint is therefore shifting from collection to interpretation and action. The problem is not simply to create another dashboard. It is to determine what has changed, what matters, what decision needs to be made and which asset should act. This is particularly difficult in multi-domain operations, where information and capabilities must be coordinated across land, air, maritime, cyber and space activities.
How AI is being applied
AI is being used to:
- Extract information from imagery, video, reports, messages and other unstructured inputs.
- Fuse observations from several sources into a common operating picture.
- Detect relevant changes across large volumes of imagery or sensor data.
- Identify patterns that would be difficult for an individual analyst to find.
- Support mission planning and resource allocation.
- Translate an operator’s objective into a series of tasks.
- Deploy specialised models at the edge when cloud access is unavailable.
The enabling infrastructure has also improved. APIs, containerised applications, on-premise deployments and air-gapped environments make it more practical to integrate AI into sensitive workflows. Modern models can also handle the notes, chats, PDFs and slides that make up much of operational and staff work.
Foundation models alone are unlikely to be the principal source of defensibility. Models can be substituted and will continue to improve. The more durable position lies in the platform that has access to the relevant data, understands the operational workflow, deploys securely and connects recommendations to real actions.
Where value concentrates
The landscape spans broad data platforms (Palantir), established command-and-control vendors (Systematic), AI-native challengers (Arondite, Comand AI), integrated players (Helsing) and collection specialists (ICEYE). Value sits in three layers:
- Data and decision platforms. Palantir is the reference incumbent, combining deep data integration with operational applications and long government relationships. Arondite positions itself as a more autonomy-native, vendor-neutral platform spanning sensor fusion, mission orchestration, edge deployment and direct tasking of assets. Comand AI, Adarga, and Labrys Technologies enter through narrower workflows, including command and control, intelligence analysis, and secure coordination.
- AI providers. Faculty delivers operational AI across sensing, electronic warfare, command and control and back-office work. The question for this group is whether deployments become repeatable software or stay services-heavy.
- Collection and integrated platforms. ICEYE and Preligens show value can sit in collection where the sensor or dataset is genuinely scarce, since all-weather radar is far harder to replicate than ordinary optical imagery. Helsing pairs decision software with its own autonomous platforms, gaining more control over deployment data but with more hardware-heavy economics.
Theme 4: Cyber & Infrastructure Protection
What is driving demand
Critical infrastructure increasingly blends IT systems, physical-security equipment, operational technology, connected sensors, and remote communications. Energy assets, ports, airports, data centers, and transport networks now face threats that cross the line between cyber and physical. Much operational technology consists of long-lived equipment and specialised protocols and cannot be protected like a normal corporate IT estate, and the merging of IT and operational technology creates more ways for an attacker to disrupt a physical process.
The relevance is broader than military networks: energy, communications, logistics, and data centers underpin both national resilience and military readiness. Much of this demand is also backed by commercial and regulatory budgets — EU rules such as NIS2, DORA and the Cyber Resilience Act are turning security spending from optional to mandatory — regulatory budgets that can offer a more repeatable enterprise sales motion and potentially stronger near-term revenue quality than defence procurement.
How AI is being applied
AI can establish patterns of normal behaviour across large estates of devices and identify deviations that may indicate a cyberattack, equipment failure or physical intrusion. It can then correlate information from network activity, operational systems, cameras and physical sensors to give operators a more coherent view.
AI can also assist with triage. Critical-infrastructure operators may receive more alerts than their teams can investigate manually. Models can help prioritise incidents and recommend responses, although mission-critical actions still require appropriate controls and human oversight.
Resilient networking is an adjacent application. Emerging defence priorities include AI-enhanced mesh networking, dynamic spectrum management, self-healing communications and alternatives to GPS. These systems aim to maintain operations when individual communications links are jammed, degraded, or destroyed.
Where value concentrates
The market is broader and more mature than the other themes, spanning four groups:
- Established cyber and industrial vendors. Large cyber firms, industrial groups and defence primes benefit from trusted relationships and distribution. A startup has to solve an operational problem generic cyber products cannot, not just add AI to conventional monitoring.
- Operational-technology security specialists. Claroty secures cyber-physical and industrial environments; its advantage comes from specialised integrations, knowledge of operational protocols and behavioural data on how complex systems normally run. In Europe, Filigran (threat intelligence) and Sekoia.io (detection and response) are building in the same broad space.
- Defence platforms expanding into site protection. A player like Arondite could extend an orchestration platform into critical-site security, combining cameras, radar, drones, access systems and alerts into one picture. The adjacency is logical, but commercial buyers bring different compliance requirements, incumbents and procurement processes.
- Services and integration providers. Peraton, valued at over $15B, shows both the scale of the market and the risk of headcount-driven economics. The question for any new entrant is whether it captures this demand with reusable software or becomes a smaller services business built on bespoke deployments.
Two adjacent needs also sit here: post-quantum cryptography, where PQShield is building the standards-based encryption that regulation will eventually force, and resilient positioning and grid protection, where Aquark Technologies (jam-proof timing) and Optics11 (subsea-cable and grid monitoring) are early examples.
4. European VC Activity
Table 2: Selected European defence investors
5. Conclusion
The real change in defence is not the size of the budget but the shape of the systems. Capability is moving from a handful of large, self-contained platforms to a sprawl of sensors, drones, autonomous systems and data feeds, and the hard problem is no longer building any single asset, but connecting them and turning what they see into decisions fast enough to matter. That connecting layer is where software economics live, where AI is the product rather than a feature, and where European capital remains relatively thin in software-led, vendor-neutral orchestration and decision platforms.
In practice, that points to a few places:
- In counter-air and ISR, the value concentrates in vendor-neutral orchestration and decision software: the system an operator builds around and cannot easily unplug.
- In critical infrastructure, it is operational-technology security, where the problem is genuinely hard and regulation funds the buyer.
- In autonomy, it is the software layer specifically, or hardware that earns a real software margin on a genuine data advantage rather than a manufacturer with an app attached.
The strongest positions are likely to share the same protections: accreditation and clearances that take years to earn, a data advantage that compounds with every deployment, integrations that become switching costs, and, for a European company, sovereignty, which quietly decides contracts that product quality alone would not. And since government budgets move with politics, dual-use models are more durable where the commercial market is genuinely independent, rather than simply a temporary bridge to eventual defence revenue.
Vendor-neutral orchestration has often struggled to compete with vertically integrated providers, including Anduril today, that give the software away to sell hardware. What has changed is scale and politics: there are too many systems from too many vendors for any closed stack to absorb, and European buyers increasingly prioritise systems they control domestically. If that holds, the likely winners will be the companies that sit at the centre of this new architecture, fusing, deciding and coordinating, and make themselves difficult to replace.
.png)



%20Research%20page%20%201.jpg)