ObsidianOS
One operator. Many aircraft. Every engagement on the record.
ObsidianOS turns commander intent into tasking across many aircraft, runs target detection, classification and engagement prioritisation, and executes engagements inside the rules of engagement the operator has set. The human governs the envelope and holds the abort. The log holds everything else.
AI runs the chain. A human owns the envelope.
Find, classify, prioritise, engage. Onboard AI runs the chain inside rules of engagement set before the mission; the operator supervises every aircraft and can intervene, hold fire or abort at any moment. Every detection, decision and engagement is written to an append-only, hash-linked log, so after the mission the chain replays exactly and the operator, the commander and the assessor can see why each engagement happened.
What V0 demonstrates
One operator, a fleet of simulated heterogeneous UAS, observation zones to cover. Cost-based task allocation. A mid-mission link loss to one asset; re-tasking that preserves coverage or states its shortfall. Operator authority: approve, override, pause, abort, live throughout. A Safety Governor that blocks non-compliant actions. An append-only, hash-linked event log from which any mission replays deterministically. Nine beats, verified.
What V1 adds
The boundary between the command layer and the vehicle, proven with real autopilot software in the loop.
- A versioned vehicle-descriptor contract and adapter boundary.
- A MAVLink adapter driving ArduPilot SITL in the loop.
- Mixed simulated and SITL fleets.
- A range-based comms model: lossy is not absent.
- A twenty-asset performance budget.
- An operator-session mode for structured feedback.
- Data shapes aligned to STANAG 4586; alignment, never compliance.
- Two-run After-Action comparison and export signing.
What V2 builds, in simulation
Rules of engagement as versioned per-mission data, hashed into the log; a governor that refuses to loosen them mid-mission; a targeting and engagement pipeline against simulated sensors and simulated effectors; hold fire beside abort, both never disabled and both measured; and an engagement reconstruction view in After-Action Review. Tracks, classifications and outcomes are scenario data in this stage: no perception, no weapon effects, no live effector.
Planned; sequenced after the V1 gate
Design principles
Lethal by design
The command layer targets. Never disguised.
Human on the loop
Rules set by people, execution supervised, abort always honoured.
Determinism
Same log, same mission.
The event log as the spine
Append-only, hash-linked, signed at export. The system of record.
Aircraft-agnostic by descriptor
Vehicles enter by capability descriptor only.
Simulation honesty
Degraded conditions are modelled, tracks are scenario data, and the software says so.
Measured, not claimed
Independent audit of the repository, 14 September 2026; internal build measurements, not performance claims
- 4.64 ms allocation latency at 20 aircraft, against a 50 ms budget.
- 0.08 ms tick p95, against 8 ms.
- Policy violation to signed block in under 1 second, 2 of 2.
- 24 of 24 decision and action events present in replay.
- 663 events chain-verified from a five-vehicle run on real ArduPilot autopilots.
- 7 descriptors in the registry; 12 invalid cases rejected with sourced errors.
- Zero network egress from the runtime outside declared adapters.
The evidence
Six screens, and the signed log they replay from.
Mission composer
Zones, fleet and constraints, set before the run.
Command map
Fleet, zones and allocation, live.
Asset panel
Each asset's state, link and task.
Mission execution
Link loss, re-tasking, the operator's controls.
After-Action Review
The mission replayed from its log.
Engagement reconstruction
One engagement rebuilt from the log alone: the rules it ran under, the authorisation, the outcome.
Any mission replays deterministically from its signed, hash-linked log.
Standing questions
The questions we most want validators to press on.
- Comms-model fidelity: what does the link model need before the degradation beat is credible?
- Allocation: does the contract-net auction earn its keep at five assets, or does the exact solver?
- Shortfall computability: at what fleet and zone count does the shortfall stop being computable in time?
- Descriptor survival: does the capability-descriptor pattern survive a genuinely different vehicle?
- Event taxonomy: the minimum event set an assessor expects to see replayed?
- Control set: is approve, override, pause, abort, nudge the right set, or merely the easy one?
- Meaningful human control: is on-the-loop supervision with human-set rules of engagement and a real hold and abort meaningful human control, and what must the log contain to prove it after the fact?
The command layer exists as a simulation and software-in-the-loop demonstrator at TRL 3 to 4. The targeting and engagement pipeline runs against simulated sensors and simulated effectors. The aircraft is in design. A sub-scale physical demonstrator is planned for H1 2027. No live weapons have been integrated or fired.
Press on it
If one of these has an answer we will not like, tell us.