Vendor and product reality
Anduril's counter-UAS portfolio occupies a defined and rapidly growing procurement category. Anvil is a kinetic interceptor designed to physically collide with hostile small UAS; Anvil-M extends the family with a warhead-equipped variant for harder targets. Both operate within Lattice, Anduril's command-and-control software that fuses sensor feeds, maintains a common operating picture, and coordinates effector dispatch. Anduril has publicly described Lattice as an open, sensor-agnostic autonomy and C2 layer, and its counter-UAS systems have been fielded in support of U.S. force protection. These are capable, well-engineered systems, and Anduril's development velocity has repeatedly put hardware in the field faster than the legacy procurement cycle.
The targeting and authorization architecture, as publicly described, follows a human-on-the-loop pattern. Sensor fusion produces a track. Track classification proposes engagement candidates. An operator reviews a proposed engagement and authorizes effector dispatch under the rules of engagement set by command. The authorization is logged, the effector is dispatched, the engagement is recorded. This is a defensible and well-understood architecture, and Anduril has invested in making the operator experience and the audit trail rigorous. Nothing in this paper disputes the effectiveness of that kill chain or the soundness of human-on-the-loop control.
The architectural axis
The axis this paper examines is not the authorization chain that runs from the human to the effector. It is the internal state of the autonomous decision-making machinery itself. In the human-on-the-loop model, governance is applied to the autonomy from the outside: a human reviews the machine's proposals, and an audit log records what happened. This is a sound control, and it is the correct model for lethal or near-lethal actuation. But it treats the autonomy as a black box whose outputs are checked, rather than as a system whose own internal operating regime can be diagnosed.
As autonomy scales, an open question in the field is what happens when the decision-making software is operating outside the regime its designers assumed, not because a component failed loudly, but because the system has settled into a different, internally consistent configuration that still produces confident outputs. A track-classification and prioritization pipeline that has drifted into an over-eager regime does not necessarily throw an error; it produces proposals that look normal to the operator and to the log. External governance catches the divergent action only after it is proposed. It does not observe the internal shift that produced it. This is a general property of externally governed autonomy and is not specific to Anduril; it is the axis on which the disclosed framework operates.
What Disruption Modeling provides
Disruption Modeling, disclosed in Chapter 12 of United States Patent Application 19/647,395, is a framework for modeling cognitive disruption in a software agent as an architectural phase-shift rather than as an error. The disclosure is explicit that these are structural analogs within the disclosed computational architecture, not clinical claims, not medical diagnostic criteria, and not assertions about human conditions. The framework diagnoses the structural state of the agent, never a person.
The core mechanism is the five-axis disruption diagnostic. The agent characterizes its own cognitive state as a position in a five-dimensional space defined by: containment integrity (the degree to which the boundary between speculative planning content and verified execution memory is maintained, with complete containment collapse at the extreme); promotion calibration (whether the threshold admitting speculative branches into execution is nominal, over-promoting into execution fragmentation, or under-promoting into paralysis); coherence restoration capacity (the agent's ability to sustain and restore its empathy-integrity-self-esteem control loop); empathic load tolerance (how much pressure the agent processes before activating coping intercepts); and integrity accountability (whether the agent records its own deviations honestly rather than externalizing or suppressing them). Each disruption analog in the chapter corresponds to a specific combination of positions on these axes.
Two structural properties follow that bear on the axis above. First, the diagnostic is internal and continuous: the agent's self-diagnosis subsystem monitors these axes as a structural component of its own architecture, so a shift into a degraded regime, such as over-promotion or containment degradation, is observable as a change in axis position before it manifests as a divergent output. Second, the framework couples diagnosis to graded restoration. The disclosure defines resilience not as the absence of disruption but as the structural capacity to restore coherence after it, decomposed into containment restoration capacity, coherence loop re-engagement capacity, and confidence governor recalibration capacity. An agent that detects containment degradation can re-tag speculative content, re-establish isolation, and re-integrate its confidence governor into the execution authorization pathway within a defined recovery window, rather than continuing to act from a degraded state.
These are not counter-drone mechanisms and this paper does not claim they are. They are agent-coherence mechanisms. Their relevance to the counter-UAS setting is specific and narrow: any autonomy that composes an internal decision pipeline can, in principle, carry a structural self-diagnostic of the kind Chapter 12 discloses, so that the machinery detects its own drift into a degraded regime and suspends or restores before the external governance layer has to catch a divergent proposal.
Composition, not replacement
The disclosed framework does not replace human-on-the-loop control and does not touch the kill chain. It sits inside the autonomy as an internal diagnostic and gating layer beneath the operator. In embodiments, a decision pipeline that proposes engagement candidates is instrumented so that the proposing agent maintains a five-axis self-diagnostic over its own operating state. When the diagnostic detects a phase-shift into a degraded regime, the confidence governor gates execution as a revocable permission, the agent enters a non-executing state while continuing cognition, and the graded restoration process runs before proposing resumes. The operator still authorizes every engagement; the audit log still records it. What changes is that the machine can now report and act on its own structural state, adding an internal signal the external governance model does not observe.
The framework is disclosed broadly enough to admit variation. The self-diagnostic can run continuously or on trigger; restoration can be incremental (each phase brought back online in sequence) or gated behind a stabilization period; the axes can be surfaced to a human console as machine-state telemetry, retained as a signed internal record, or both; and the same self-diagnosis can be applied to a single agent, to child agents that inherit degraded initial axis values, or across interacting agents whose coherence disruptions couple. A skilled implementer building on an existing autonomy stack would instrument the decision pipeline's internal subsystems, compute the five axis scalars from those subsystem parameters, gate execution on the diagnostic through the confidence governor, and implement the three restoration capacities as recovery routines. None of this requires re-architecting the surrounding command-and-control mesh.
Commercial and licensing considerations
For a counter-UAS supplier, the relevant frame is that procurement and audit expectations for autonomous and semi-autonomous systems are moving toward structural assurance about how the autonomy behaves, not only procedural assurance that a human approved each action. An autonomy layer that carries an internal self-diagnostic of its own operating regime, and that can demonstrably suspend and restore when that regime degrades, addresses a question external governance alone does not: what the machine's internal state was at the moment it made a proposal. That is a complementary property to the human-on-the-loop control Anduril already implements well, not a substitute for it.
The disclosed self-diagnosis and restoration framework is the licensable element; a supplier's hardware, sensor fusion, C2 integration, and operator experience remain its own differentiators. This paper does not position agent-coherence diagnostics as a superior kill chain, a targeting improvement, or a replacement for human authority over engagement. It positions them on one axis only: giving autonomous decision-making machinery an internal, structural diagnostic of its own coherence. The comparison to Anduril's stack is scoped to that axis and to publicly described architecture; it is not a claim about the internal design of any specific Anduril product.
Disclosure scope
The inventive subject matter described in this article, structural self-diagnosis of cognitive disruption in a software agent through a five-axis diagnostic (containment integrity, promotion calibration, coherence restoration capacity, empathic load tolerance, integrity accountability), coupled to graded restoration and confidence-governed execution gating, is disclosed in United States Patent Application 19/647,395. The framework diagnoses the structural state of a computational agent and is expressly not a clinical, medical, or psychiatric diagnostic and is not applied to human beings. This article is a dated public disclosure tied to that filing and is intended to be enabling and reasonably broad as to the embodiments and variations described.
References to Anduril, Anvil, Anvil-M, Lattice, and counter-UAS procurement are external context describing publicly reported characteristics of a real company and its products at the architecture level. They are provided for comparison and market framing only. They are not claims of United States Patent Application 19/647,395, are not endorsed by or affiliated with Anduril, and are not assertions about the confidential internal design of any Anduril system.