Vendor and Product Reality: Lattice and Mission Control

Anduril's Lattice is an autonomy and command operating system for defense. It ingests sensor feeds across a heterogeneous fleet, counter-UAS radars, perimeter towers, autonomous undersea and surface vessels, loitering munitions, attritable aircraft, fuses them into a common operational picture, and exposes that picture to operators through Mission Control. Operators issue tasking through Mission Control; Lattice translates tasking into platform-specific behaviors; autonomous platforms execute within tasked scope; the loop closes through telemetry that updates the picture and informs the next tasking cycle. The product has matured from counter-UAS at fixed sites to attritable-aircraft orchestration, undersea autonomy, and integration into joint kill chains under JADC2-class data fabrics. Mission Control's design center is operational coherence under time pressure. It compresses the OODA loop. It surfaces the right platforms to the right operators with the right context. It integrates upward into ATAK for the dismounted user, sideways into partner systems for joint operations, and downward into Anduril and partner platforms for actuation. Operators report that the integrated experience is materially faster and more legible than the legacy stovepipes it replaces. Within the operating envelope of "operator tasks platforms, platforms execute, telemetry returns," the product is excellent and arguably state-of-the-art for the U.S. defense market. The architectural posture, in common with the mission-orchestration category generally, centralizes mission authority inside the application layer: the tasking flows, the state machines, the autonomy policies, and the audit logs the platform generates as a byproduct of operation. That authority is real and operationally effective. What the publicly described architecture of this category does not expose is operator intent as a portable, credentialed object that lives independently of the actuating system and can be evaluated by a party other than that system. The operator's intent enters the system as a tasking directive and is represented, thereafter, primarily through the mission record those directives leave. This is a characterization of the category's public architecture, not an assertion about Anduril's internal implementation details, which are not public.

The Architectural Gap: Intent as Log Entry, Not as Binding Substrate

The gap the mission-orchestration category does not structurally close is the binding between operator intent and admissible platform actuation. Under a tasking-and-telemetry architecture, the operator's intent, the objective, the rules of engagement, the escalation envelope, the permitted target or effect classes, and the geographic and temporal scope, is expressed through a sequence of tasking actions and is represented, structurally, by the trail those actions leave. Subsequent platform behavior is constrained by the autonomy policy and by additional operator interventions, but it is not constrained by a separately anchored, machine-evaluable declaration of what the operator authorized in the first place. Where the autonomy policy admits an action, the action proceeds; the original intent is reconstructed, after the fact, from the mission record. This is the architectural shape that the emerging international and domestic doctrine on lethal autonomous weapon systems (LAWS) and meaningful human control will not accept indefinitely. The doctrine asks a structural question: at the moment of action, was the action within the scope that an identified human operator authorized, and can that authorization be evaluated independently of the system that took the action. A log entry generated by the actuating system is a weaker answer to that question than an authorization the actuating system cannot itself have authored, because independence of the record from the system it constrains is precisely what adversarial review tests. The compliance posture this doctrine points toward favors intent that is externalized, signed, scoped, revocable, and admissible as evidence independent of the autonomy stack, rather than intent that is implicit in the stack's configuration and reconstructed from its own logs. The mission-orchestration category treats intent operationally and does so well. What it does not do, by design, is treat intent as a separable architectural object. That is the natural consequence of optimizing for the OODA loop rather than for the meaningful-human-control evidentiary loop, and it is a reasonable optimization for the mission the category was built to serve. The point is only that if LAWS doctrine matures and procurement begins to require structurally supported intent rather than logs of tasking, an intent object that already exists at the architecture level is easier to satisfy that requirement with than a mission record reconstructed after the fact.

What the Operator-Intent Primitive Provides

The operator-intent primitive externalizes intent as a first-class architectural object. Each tasking event produces an intent declaration: a structured, signed, time-scoped record carrying operator identity, the intended objective, the intended target or effect class, the intended geographic and temporal scope, the intended escalation profile, and the credential chain authorizing the operator to issue intent of that class. The declaration is anchored, cryptographically bound such that subsequent modification is detectable, and is admissible as a substrate against which platform actuations are evaluated. Platform actions, in this model, do not merely log against a mission record; they admit against an active intent declaration. An actuation is admissible when it lies within the scope of a current, valid intent declaration whose authorizing operator is credentialed for the action class. The admissibility check is structural and machine-evaluable; the evaluation can be performed independently of the actuating system; the record of admission is itself signed and anchored. Post-action review is no longer a forensic reconstruction from telemetry: it is a verification, against the intent substrate, that each action was scoped by an authorization the operator actually issued. The primitive inverts the locus of authority. Authority is no longer the property of the software stack that runs the mission; it is the property of the credentialed declaration that scopes what the stack is permitted to do. The autonomy policy continues to operate, but it operates within an envelope defined externally by intent rather than within an envelope defined by its own configuration. When a proposed actuation would exceed the active intent envelope, the admissibility evaluation does not simply reject: consistent with the graduated-response model of the disclosure, it can gate, defer pending corroboration or additional authorization, solicit further intent evidence, or escalate. The operator's authority becomes architecturally durable rather than implicit in the audit trail.

The intent object is not monolithic. The disclosure describes intent shared across multiple fidelity tiers: a full-fidelity tier in which a highly integrated unit shares structured objective and constraint state directly; a structured partial-fidelity tier in which specific structured intent signals are extracted from an integrated data source; and a behavior-inferred tier in which the mesh produces a credentialed inferred-intent observation from externally visible cues when a participant cannot declare intent directly. Each tier's observation carries the emitting authority's credential and is admitted at tier-appropriate evidential weight, with cross-tier fusion producing a composite intent estimate and an explicit uncertainty bound. Intent is revocable and corrigible: an authority can retract or correct a previously issued intent through a governance-preserving retracted-and-superseded record rather than a silent deletion, so that a rescinded authorization is both honored going forward and auditable in the past. Every emission, admission, fusion, retraction, and downstream actuation is written to a lineage record that binds each governed action to the intent object and the operator that authorized it. A skilled implementer can realize the approach over an existing tasking surface by attaching a signed intent object to each tasking event, interposing an admissibility check keyed to that object ahead of each actuation, and appending admission and lineage records; the signing, credentialing, and anchoring primitives are conventional and are not themselves claimed as novel.

Composition Pathway: Intent Substrate as Mission Control Extension

Composition with Mission Control is additive and preserves Anduril's existing operator workflow. The current tasking surface continues to be the way operators interact with the system; the change is that each tasking event also produces an intent declaration in the substrate, signed by the operator's credential and bound to the mission context. Lattice's autonomy stack continues to plan and execute; the change is that each actuation carries an admissibility check against the active intent declaration and produces a signed admission record alongside its existing telemetry. The integration is at the boundary, not at the core; the operator does not learn a new product, and the autonomy stack does not relinquish its decision authority. The first surface this opens is LAWS-doctrine compliance. As policy matures from advisory to procurement-binding, programs that have an intent substrate ready ship into the new envelope; programs that rely on log reconstruction face architectural retrofit under schedule pressure. The second surface is allied interoperability: an externalized intent substrate, anchored in a credential model that partner nations can co-validate, becomes a basis for coalition autonomy where today the lack of common intent semantics blocks shared tasking across national boundaries. The third surface is post-action review and adversarial audit, where the intent substrate provides a structurally-supported answer to the question "was the operator's authorization sufficient for the action that occurred." Each surface treats intent as something the architecture supports rather than something the audit log approximates. Mission Control would gain, through this composition, the layer above mission tasking that meaningful-human-control doctrine is moving toward and that a tasking-and-telemetry architecture does not provide on its own.

Commercial and Licensing Posture

Anduril is the natural licensee for the operator-intent primitive because Anduril already occupies the architectural seat above which the primitive composes. Mission Control is the surface where intent is generated; Lattice is the surface where intent must be admitted against; the credential model that the primitive requires is consistent with the identity and authority infrastructure that defense-grade Mission Control already maintains. Adopting the primitive as a Mission Control extension converts a forward-looking compliance burden into a procurement differentiator at exactly the moment the LAWS doctrine begins to bind. The disclosure positions the operator-intent primitive at the architectural layer where a mission-orchestration roadmap, the meaningful-human-control regulatory trajectory, and allied-interoperability requirements converge. Early adoption preserves the architectural lead a mission-orchestration leader holds today; deferred adoption raises the prospect that a competitor or a regulator defines the intent substrate from outside, after which retrofit is more costly than incorporation would have been. The comparison here is scoped to a single architectural axis, the credentialed, bounded, revocable intent envelope and the meaningful-human-control it structurally provides, and is not a judgment on Anduril's operational capability, which is substantial.

Disclosure Scope

This article is a public technical disclosure of the Operator Intent inventive step, disclosed in U.S. Provisional Application No. 64/049,409. Every statement in this article about what the invention does, its credentialed and revocable intent object, its fidelity tiers, its admissibility and graduated-response evaluation, its retraction and corrigibility mechanism, and its lineage binding, traces to that application, which controls in the event of any inconsistency with the summary here. References to Anduril, Lattice, Mission Control, ATAK, JADC2, and to lethal-autonomous-weapon-systems and meaningful-human-control doctrine are external context describing the market and regulatory environment as public fact; they are not claims of the application, and no affiliation with or endorsement by Anduril Industries is asserted or implied. Product names are the marks of their respective owners and are used here only for identification and accurate comparison. The intent envelope, fidelity tiers, and integration pathway described above are set out to enable a skilled implementer to build the disclosed approach and to enumerate its embodiments and variations; they are illustrative and non-limiting.