NOVA™ is self-assessed against NATO’s six Principles of Responsible Use of AI.
NOVA is developed and operated in line with NATO’s Principles of Responsible Use of AI. It is self-assessed against all six principles, which is the mechanism NATO currently prescribes while its Data and Artificial Intelligence Review Board finalises a formal Responsible AI certification standard.
These are the five governance papers that sit behind the self-assessment above. Each one opens here on the page. You can widen it to full screen or copy the whole text.
⚠️ ARTIFICIAL INTELLIGENCE DISCLOSURE This document was produced with AI assistance via NOVA™ (Anthropic Claude Sonnet / Pinecone RAG). All content has been reviewed and signed off by the named responsible person. Human approval constitutes acceptance of accuracy and doctrinal compliance.
NOVA™ MODEL CARD
NOVA™ — Agentic Allied Defence Training Platform
Document Ref: NOVA-MC-001 | 8 March 2026 | Will Kennedy-Long FLPI, FITOL
| Platform Name | NOVA™ — Agentic Allied Defence Training Platform |
|---|---|
| Version | v1.0 (March 2026) |
| Developed by | Will Kennedy-Long FLPI, FITOL |
| AI Model (LLM) | Claude Sonnet 4.6 — Anthropic PBC (claude-sonnet-4-6) |
| Retrieval System | Pinecone Vector Database — 4 doctrine indexes: nova-uk-doctrine, nova-us-doctrine, nova-nato-doctrine, nova-asd-doctrine |
| Embedding Model | OpenAI text-embedding-3-small (used for Pinecone ingestion) |
| Doctrine Corpus | 134 doctrine files, 207,000+ lines. UK (JSP 822, DTSM 1–5), US (TRADOC 350-70), NATO (Bi-SC 75-7), ASD/AIA (S6000T) |
| Classification | OFFICIAL only. Not suitable for OFFICIAL-SENSITIVE, SECRET or above. |
NOVA is designed and tested to operate within the following bounded context:
| ODD Dimension | Definition |
|---|---|
| Domain | Defence training design and DSAT lifecycle documentation |
| Users | Trained TDOs and training design specialists with DSAT knowledge |
| Documents | SoR, RolePS, Scoping, TGA, SoTG, FTS, TNA activities (21 activities across 4 DSAT phases) |
| Language | English only |
| Classification | OFFICIAL only |
| Frameworks | JSP 822, DTSM 1–5, TRADOC 350-70, NATO Bi-SC 75-7, ASD/AIA S6000T |
| Metric | Result | Basis |
|---|---|---|
| Doctrinal Compliance Rate | 96%+ | Testing against EW Course 2303C documents |
| DSAT Cycle Time Reduction | 4,400 hrs → ~3 hrs (99.9%) | Comparison of manual vs NOVA-assisted TNA |
| Cost Reduction (est.) | £386K → £50K (87%) | Contractor day rate estimates |
| Synonym Coverage | 1,519+ terms, 9,647 synonyms | 178 cross-doctrinal categories |
| Data Category | Handling |
|---|---|
| User-uploaded documents | Parsed client-side (PizZip/fast-xml-parser CDN) or transiently via Railway backend. Not persistently stored beyond user session. |
| AI prompts / completions | Sent to Anthropic API. Per Anthropic API Terms of Service, prompts are not used to train models. No persistent storage by Anthropic for API customers. |
| Activity data | Stored in Cloudflare D1/KV under user account. User-controlled. Exportable at any time. |
| Doctrine content | Stored in Pinecone vector DB. Doctrine files only. No user PII. |
| PII | Minimal. User email/name for account only. Not passed to AI services. |
This Model Card should be read alongside the NOVA AI Ethical Risk Assessment (NOVA-AERA-001), Bias and Harm Mitigation Analysis (NOVA-BHMA-001) and Security Risk Assessment (NOVA-SRA-001).
NOVA implements the five MOD AI Ethical Principles (ASR 2022) through: mandatory human sign-off at every lifecycle stage; doctrine-grounded generation (RAG); transparent criteria scoring with clause references; AI disclosure on all exports; and a bounded ODD preventing use outside training design.
| Document Owner | Will Kennedy-Long FLPI, FITOL |
|---|---|
| Version | v1.0 |
| Date | 8 March 2026 |
| Review Frequency | Annual minimum, or on material change to AI components |
| Next Review | March 2027 |
⚠️ ARTIFICIAL INTELLIGENCE DISCLOSURE This document was produced with AI assistance via NOVA™ (Anthropic Claude Sonnet / Pinecone RAG). All content has been reviewed and signed off by the named responsible person. Human approval constitutes acceptance of accuracy and doctrinal compliance.
AI ETHICAL RISK ASSESSMENT
NOVA™ — Agentic Allied Defence Training Platform
Prepared by: Will Kennedy-Long FLPI, FITOL | Date: 8 March 2026 | Version: v1.0
| Document Reference | NOVA-AERA-001 |
|---|---|
| JSP Reference | JSP 936 V1.1 §86 — AI Ethical Risk Assessment and Management |
| ASR Reference | Ambitious, Safe, Responsible (ASR) 2022 — Five Ethical Principles |
| Classification | OFFICIAL |
| Next Review Date | March 2027 (annual minimum) |
| Responsible Person | Will Kennedy-Long FLPI, FITOL |
This AI Ethical Risk Assessment (AERA) has been prepared in accordance with JSP 936 V1.1 (Dependable AI in Defence) §86, which mandates that an AI ethical risk assessment addressing the five MOD AI Ethical Principles must be conducted at the outset of any project and at any point where material changes to scope suggest changes to the overall risk profile.
NOVA™ is a training design automation platform that automates the UK Defence Systems Approach to Training (DSAT) lifecycle. It provides AI-assisted generation of training needs analysis, design, delivery and assurance documentation in compliance with JSP 822, DTSM 1–5, TRADOC 350-70, NATO Bi-SC 75-7 and ASD/AIA S6000T.
NOVA is intended for use by UK MOD Training Development Officers (TDOs), training design specialists, and allied defence training authorities. Classification scope is OFFICIAL only.
| Component | Provider | Function | Data Residency |
|---|---|---|---|
| Claude Sonnet (LLM) | Anthropic PBC (USA) | Document generation, extraction, compliance checking | US-based API. No persistent storage of prompts per Anthropic API ToS. |
| Pinecone Vector DB | Pinecone Inc (USA) | RAG retrieval of doctrine content (134 doctrine files) | US-based. Doctrine content only — no user PII stored. |
| Cloudflare Pages / D1 / KV | Cloudflare Inc (USA/EU) | Frontend hosting, user data storage, session management | EU-based data centres where available. User activity data stored in D1/KV. |
| Railway FastAPI Backend | Railway Corp (USA) | Analysis agent, document parsing orchestration | US-based. Processes document content transiently during extraction. |
NOVA incorporates mandatory human oversight at every stage of the DSAT lifecycle:
The following assessment addresses each of the five MOD AI Ethical Principles as defined in the Ambitious, Safe, Responsible (ASR) policy (2022) and elaborated in JSP 936 V1.1 §49.
| Stakeholder Group | Impact Assessment |
|---|---|
| TDOs / Training Designers | Positive: Reduction in administrative burden (est. 4,400 hours to ~3 hours per TNA cycle). Risk: Over-reliance on AI outputs without adequate doctrinal knowledge. Mitigation: Criteria system requires human judgement; Activity Guide provides doctrinal grounding. |
| Trainees (end beneficiaries) | Positive: More consistently DSAT-compliant training programmes. Risk: Errors in AI-generated Training Objectives could affect training quality. Mitigation: Human sign-off at TNA, Design, Delivery and Assurance stages. |
| MOD Institution | Positive: Significant cost reduction, doctrinal consistency across TLBs. Risk: Concentration of training design tooling in single supplier. Mitigation: All data exportable; no lock-in architecture. |
| General Public | No direct interaction. Indirect benefit through improved military training quality and readiness. |
| Assessment | Risk Level | Residual Risk |
|---|---|---|
| Human-Centricity | Low — human control embedded throughout | Low — mitigations in place |
Responsibility within NOVA is clearly established at multiple levels:
| Assessment | Risk Level | Residual Risk |
|---|---|---|
| Responsibility | Low — clear chain of accountability | Low |
NOVA addresses the Understanding principle through the following design features:
Gap noted: A formal NOVA User Training Package is in development (NOVA-UTP-001) to address JSP 936 §130 — training users to understand system behaviour, performance and limitations.
| Assessment | Risk Level | Residual Risk |
|---|---|---|
| Understanding | Moderate — pending user training package | Low–Moderate — UTP in development |
See also: NOVA Bias and Harm Mitigation Analysis (NOVA-BHMA-001) for full detail. Summary:
| Assessment | Risk Level | Residual Risk |
|---|---|---|
| Bias & Harm Mitigation | Low–Moderate — RAG bounds generation | Low — human review required for all outputs |
| Dimension | NOVA Assessment |
|---|---|
| Reliable | NOVA operates within a defined ODD (DSAT training documentation). Performance is bounded and testable against known doctrine. 96%+ doctrinal compliance reported in testing against verified EW course documents. |
| Robust | Fallback mechanisms prevent null outputs. All document builders are resilient to missing data and generate from available inputs. Error handling prevents cascade failures from propagating. |
| Secure | See NOVA Security Risk Assessment (NOVA-SRA-001). OFFICIAL classification only. Data flows documented. No SECRET or above data should be processed through NOVA. |
| Resilient | Service Worker implementation ensures client-side resilience. Cloudflare Pages provides 99.9%+ uptime SLA. Railway backend is independently restartable. |
| Assessment | Risk Level | Residual Risk |
|---|---|---|
| Reliability | Moderate — depends on third-party API availability | Low–Moderate — documented fallbacks in place |
Per JSP 936 V1.1 Table 1, the overall ethical risk rating for NOVA is assessed as follows:
| Dimension | Impact | Likelihood | Residual Risk Rating |
|---|---|---|---|
| Human-Centricity | Low | Low | Minor |
| Responsibility | Low | Low | Minor |
| Understanding | Moderate | Low | Moderate (UTP pending) |
| Bias & Harm Mitigation | Low | Low | Minor |
| Reliability | Moderate | Low | Moderate |
| OVERALL RATING | Moderate | Low | MODERATE — TLB-Level Oversight |
| Ref | Mitigation / Action | Status | Target Date |
|---|---|---|---|
| M-01 | AI Disclosure on all generated documents (JSP 936 §40) | COMPLETE | March 2026 |
| M-02 | Model Card published (NOVA-MC-001) | COMPLETE | March 2026 |
| M-03 | Security Risk Assessment published (NOVA-SRA-001) | COMPLETE | March 2026 |
| M-04 | Bias and Harm Mitigation Analysis published (NOVA-BHMA-001) | COMPLETE | March 2026 |
| M-05 | User Training Package (NOVA-UTP-001) | IN DEVELOPMENT | Q2 2026 |
| M-06 | Annual review of this AERA (next: March 2027) | SCHEDULED | March 2027 |
| M-07 | Monitor Anthropic API updates for model behaviour changes | ONGOING | Continuous |
| Name | Will Kennedy-Long FLPI, FITOL |
|---|---|
| Role | Founder and Developer, NOVA™ Agentic Allied Defence Training Platform |
| Date | 8 March 2026 |
| Signature | (Signed electronically — document owner acceptance constitutes sign-off) |
| Next Review | March 2027 |
⚠️ ARTIFICIAL INTELLIGENCE DISCLOSURE This document was produced with AI assistance via NOVA™ (Anthropic Claude Sonnet / Pinecone RAG). All content has been reviewed and signed off by the named responsible person. Human approval constitutes acceptance of accuracy and doctrinal compliance.
BIAS AND HARM MITIGATION ANALYSIS
NOVA™ — Agentic Allied Defence Training Platform
Document Ref: NOVA-BHMA-001 | 8 March 2026 | Will Kennedy-Long FLPI, FITOL
This document analyses potential bias and harm vectors in NOVA™ across its AI components (Claude Sonnet LLM, Pinecone RAG) and the NOVA platform design. It identifies mitigations in place and residual risks requiring ongoing monitoring.
NOVA operates in the bounded domain of defence training design. It does not make decisions about individuals, determine employment, assess performance, or recommend disciplinary action. This substantially constrains the harm surface compared to AI systems with direct human impact.
Claude Sonnet (Anthropic) is trained on large-scale internet and curated text corpora. Potential biases include:
| Bias Vector | NOVA-Specific Risk | Mitigation |
|---|---|---|
| Western / English-language bias in training data | Low — NOVA operates in English within Allied frameworks that are already English-language | ODD restricted to English. NATO/allied doctrine in English. |
| Gender bias in role descriptions | Low-Moderate — LLM may generate gender-stereotyped role descriptions or training objectives | TDO review required before sign-off. RolePS source documents define roles; AI extracts rather than invents. |
| Temporal bias (stale doctrine knowledge) | Moderate — Claude’s training cutoff may not reflect recent JSP/DTSM amendments | Pinecone RAG retrieves from verified current doctrine files. Claude’s general knowledge is secondary to RAG outputs. |
| Hallucination (confident incorrect output) | Moderate — LLM may generate plausible but incorrect doctrinal references | Every criteria check shows JSP/DTSM clause reference. Human TDO verifies. RAG constrains generation to sourced content. |
| Bias Vector | NOVA-Specific Risk | Mitigation |
|---|---|---|
| Index over-representation of one doctrinal framework | Low — four separate doctrine indexes (UK, US, NATO, ASD/AIA). Each queried by framework. | Separate Pinecone indexes per framework prevent cross-contamination. |
| Stale doctrine in index | Moderate — index may not reflect latest JSP/DTSM amendments | Doctrine files reviewed and updated by owner. Version-controlled. |
| Retrieval failure (no relevant chunks returned) | Low — LLM falls back to general knowledge, increasing hallucination risk | Fallback prompts instruct Claude to flag uncertainty rather than fabricate. |
| Harm Category | Rating | Analysis |
|---|---|---|
| Physical harm | Very Low | NOVA generates training documentation. It does not control physical systems, weapons or autonomous platforms. Training design errors could theoretically affect training quality, but not cause direct physical harm. |
| Discriminatory harm to individuals | Low | NOVA does not assess, rank or make decisions about individual service personnel. Role descriptions are based on MOD-defined RolePS documents. |
| Doctrinal non-compliance harm | Moderate | If NOVA generates non-compliant training objectives that are not caught by human review, downstream training could fail JSP 822 standards. Mitigated by criteria scoring and mandatory TDO sign-off. |
| Data security harm | Moderate | User-uploaded documents passed to Anthropic API and Railway backend. Mitigated by OFFICIAL-only classification scope and Anthropic API data handling commitments. See NOVA-SRA-001. |
| Over-reliance / automation bias | Moderate | TDOs may accept AI outputs without adequate review if the platform appears authoritative. Mitigated by criteria transparency, clause references, and pending User Training Package. |
| Monitoring Activity | Frequency | Owner |
|---|---|---|
| Review Anthropic model card updates | Quarterly | Will Kennedy-Long FLPI, FITOL |
| Review Pinecone doctrine index for stale content | On JSP/DTSM amendment | Will Kennedy-Long FLPI, FITOL |
| User feedback review for bias indicators | Monthly | Will Kennedy-Long FLPI, FITOL |
| Annual review of this BHMA document | Annual | Will Kennedy-Long FLPI, FITOL |
| Document Owner | Will Kennedy-Long FLPI, FITOL |
|---|---|
| Version | v1.0 |
| Date | 8 March 2026 |
| Next Review | March 2027 |
⚠️ ARTIFICIAL INTELLIGENCE DISCLOSURE This document was produced with AI assistance via NOVA™ (Anthropic Claude Sonnet / Pinecone RAG). All content has been reviewed and signed off by the named responsible person. Human approval constitutes acceptance of accuracy and doctrinal compliance.
STATEMENT OF AI ETHICS ASSURANCE
NOVA™ — Agentic Allied Defence Training Platform
Document Ref: NOVA-SAEA-001 | Annual Statement | 8 March 2026
I, Will Kennedy-Long FLPI, FITOL, as the developer and responsible person for NOVA™, hereby confirm the following in respect of the NOVA™ Agentic Allied Defence Training Platform for the period ending 8 March 2026:
| Assurance Statement | JSP 936 Reference | Evidence Reference | |
|---|---|---|---|
| ✓ | NOVA has been assessed against all five MOD AI Ethical Principles (Human-Centricity, Responsibility, Understanding, Bias & Harm Mitigation, Reliability) | JSP 936 §49–50 | NOVA-AERA-001 |
| ✓ | An AI Ethical Risk Assessment has been completed and the overall residual risk is rated MODERATE (TLB-Level Oversight) | JSP 936 §86–90 | NOVA-AERA-001 |
| ✓ | All AI-generated documents carry mandatory AI Disclosure statements on cover and footer per JSP 936 §40 | JSP 936 §40 | NOVA v1.0 platform |
| ✓ | A Model Card has been published documenting AI components, ODD, performance, limitations and data handling | JSP 936 Cover Note | NOVA-MC-001 |
| ✓ | A Security Risk Assessment has been completed covering all data flows, third-party services and classification constraints | JSP 936 §195–197 | NOVA-SRA-001 |
| ✓ | A Bias and Harm Mitigation Analysis has been completed and documented | JSP 936 §69–70 | NOVA-BHMA-001 |
| ✓ | Human control is embedded at every stage: no output is finalised without positive human review and "Mark Complete" action | JSP 936 §56–58 | NOVA v1.0 platform |
| ✓ | NOVA is classified OFFICIAL only. A classification warning is displayed throughout the platform and in all documentation. | JSP 936 §195 | NOVA-SRA-001 |
| ⚠️ | User Training Package (NOVA-UTP-001) is in development. Interim mitigation: Activity Guide and criteria system provide operator guidance. | JSP 936 §130 | NOVA-UTP-001 (pending) |
In support of any MOD TLB Executive Board’s Statement of AI Ethical Assurance to 2PUS, I confirm the following ongoing commitments:
This statement covers NOVA™ as a platform and tool. It does not constitute assurance for any specific MOD project or programme that uses NOVA as its tooling. Each MOD TLB remains responsible for:
| Name | Will Kennedy-Long FLPI, FITOL |
|---|---|
| Role | Founder and Responsible Person, NOVA™ Agentic Allied Defence Training Platform |
| Date | 8 March 2026 |
| Signature | (Signed electronically) |
| Valid Until | March 2027 (subject to earlier review on material change) |
⚠️ ARTIFICIAL INTELLIGENCE DISCLOSURE This document was produced with AI assistance via NOVA™ (Anthropic Claude Sonnet / Pinecone RAG). All content has been reviewed and signed off by the named responsible person. Human approval constitutes acceptance of accuracy and doctrinal compliance.
SECURITY RISK ASSESSMENT
NOVA™ — Agentic Allied Defence Training Platform
Document Ref: NOVA-SRA-001 | 8 March 2026 | Will Kennedy-Long FLPI, FITOL
NOVA™ uses a distributed architecture across the following components. All data flows are documented below for security assessment purposes.
| Component | Provider / Location | Data Processed | Data Residency |
|---|---|---|---|
| Frontend (Pages/D1/KV) | Cloudflare Inc. (US/EU) | User session, activity data, generated documents | Cloudflare EU data centres where available. D1/KV data stored per Cloudflare data localisation settings. |
| Analysis Backend | Railway Corp (US) | Document text during parsing. Transient — not persisted. | US-based Railway servers. Data transient in memory during processing only. |
| LLM API | Anthropic PBC (US) | Prompts containing document extracts and user-entered field content | US-based Anthropic infrastructure. API inputs not retained for training per Anthropic API ToS. |
| Vector Database | Pinecone Inc. (US) | Doctrine content vectors only. No user data in Pinecone. | US-based. Doctrine content only — no user PII or project data. |
| ID | Risk | Likelihood | Impact | Mitigation |
|---|---|---|---|---|
| SR-01 | User uploads OFFICIAL-SENSITIVE or SECRET material to NOVA | Low–Moderate | High | Hard classification limit stated throughout platform, in all documentation, and in onboarding. User Training Package (pending) to reinforce. Contractual obligations on MOD customers. |
| SR-02 | Anthropic API data interception in transit | Very Low | Moderate | TLS 1.3 encryption in transit. Anthropic API requires HTTPS. No plaintext transmission. |
| SR-03 | Cloudflare D1/KV data breach | Very Low | Moderate | Cloudflare SOC 2 Type II certified. Data isolated per account. Row-level security on D1. |
| SR-04 | Prompt injection attack via malicious document upload | Low | Low–Moderate | Document content is parsed and structured before LLM submission. Structured prompts reduce injection surface. Claude Sonnet has instruction hierarchy protection. |
| SR-05 | Data poisoning of Pinecone doctrine index | Very Low | Moderate | Pinecone write access controlled by API key held by developer only. Doctrine files are version-controlled. No user can modify doctrine index. |
| SR-06 | Railway backend compromise / data exfiltration | Low | Moderate | Railway processes document content transiently only — no persistent storage of user data. Railway uses isolated container environments per deployment. |
| SR-07 | Account takeover / unauthorised access | Low | Moderate | Cloudflare Access authentication. Accounts approved individually by the platform owner through the Admin Panel. Session tokens with expiry. |
| SR-08 | Third-party API service outage (Anthropic / Pinecone) | Moderate | Low | NOVA degrades gracefully — form fields remain accessible and saveable without AI features. Activity data not lost on API failure. |
| SR-09 | Model behaviour change on Anthropic API update | Moderate | Low–Moderate | Model version pinned in API calls (claude-sonnet-4-6). Anthropic notifies of deprecation. Monitored quarterly. |
| Control Area | Control | Standard / Reference |
|---|---|---|
| Data in Transit | TLS 1.3 on all connections (Cloudflare, Anthropic, Railway, Pinecone) | NCSC Cloud Security Principles |
| Data at Rest | Cloudflare D1/KV encryption at rest. | Cloudflare SOC 2 |
| Access Control | Account-based access. API keys stored as environment variables, not in code. | Secure by Design |
| Classification Enforcement | OFFICIAL-only hard limit. Warning displayed in platform and all documentation. | JSP 936 §195 |
| Third-Party Assurance | Anthropic SOC 2 / Cloudflare SOC 2 / Railway SOC 2 / Pinecone SOC 2 | Supplier security certifications |
| Incident Response | Data breach notification within 72 hours per UK GDPR Article 33. Contact: Will Kennedy-Long FLPI, FITOL | UK GDPR Art. 33 |
| Document Owner | Will Kennedy-Long FLPI, FITOL |
|---|---|
| Version | v1.0 |
| Date | 8 March 2026 |
| Next Review | March 2027 or on material change to architecture |