The Future of American Defense: A Sitting Army Secretary Wrote a YC Request — Here's What Building for It Actually Takes
August 1, 2026
This is the third article in a fourteen-part series reading Y Combinator's Fall 2026 Requests for Startups one at a time. This one takes the request that made the 2026 list unusual before anyone read a word of it: a Request for Startups authored by a sitting U.S. Secretary of the Army.
What the request actually says
The Fall 2026 RFS includes , authored by . Its framing is blunt. "Warfare is at an inflection point," it opens, "and the old ways of Army acquisition simply don't keep pace with modern threats. Modern combat demands commercially developed, modular open-system solutions, and that's why we ripped up the old acquisition playbook."
The ask itself is specific. "We are actively funding low-cost interceptors or any component that helps us lower the cost per kill." It continues: "We need next-gen sensors, software, payloads, and other hardware that plugs directly into our open system architecture. We need cutting-edge drones, resilient logistics, and advanced manufacturing, and we need it all to survive the most extreme climates on Earth." The geography is deliberately total — "from the Arctic to the archipelago and from space to subterranean environments" — and the closing offer is unusually direct for a government document: "Bring us your ideas, and we will give you the capital and the proving ground to scale."
Two things are worth marking. First, YC itself flags the novelty: the batch introduction notes this request comes, "for the first time, one from the sitting U.S. Secretary of the Army." Second, the language is a customer's, not a policymaker's — a cabinet-level official describing procurement reform and, in the same breath, offering founders capital and a testing range. That combination is the story.
Why this request, now
The plain reading is that the largest, most process-bound buyer of hardware in the United States is publicly telling early-stage founders it wants to buy from them — and naming the specific things it will pay for. The request's own phrase, "we ripped up the old acquisition playbook," is a tell: the bottleneck it is trying to route around is not ideas but the acquisition system itself.
The wider context is a defense-tech wave that predates this request by years. Anduril Industries, founded in 2017 by Palmer Luckey, Trae Stephens, and others, built its business selling AI-and-robotics systems — drones, sensor towers, autonomy software — to the Department of Defense as a venture-funded company rather than a legacy prime. The through-line those companies established is that commercially developed, software-defined hardware can compete for defense dollars — and that "modular open-system architecture," the exact phrase in the request, is the interface that lets a startup's box plug into a system it doesn't own. The request is, in effect, an invitation to repeat that pattern across interceptors, sensors, drones, and logistics rather than in one or two flagship programs.
The "why now" also has a cost argument buried in "lower the cost per kill." Cheap, mass-produced drones have shifted battlefield economics: when a threat costs a few thousand dollars and the thing that stops it costs a few million, defense loses the exchange even when it wins the engagement. A request for interceptors is a request to fix that math — the same "AI moving into the physical world" thesis running through the whole 2026 list, applied to the one buyer that can offer both capital and a proving ground.
What is actually hard
For most startups the customer is a market; here it is a bureaucracy with statutory rules about how it may spend. Even with an acquisition playbook that has genuinely been reformed, selling to the Army means budget cycles that run in years, program offices, testing regimes, and the gap between a pilot contract and a program of record that actually generates revenue. Vehicles like Other Transaction Authority and the Defense Innovation Unit exist to shorten that path, and the promise of "capital and the proving ground" points at them — but "we will fund you" and "you have durable revenue" are separated by a valley that has killed capable companies. The hard skill in defense is not only building the thing; it is surviving the sales cycle for the thing.
Hardware that goes near soldiers, aircraft, or munitions must be qualified, and qualification is deliberately unhurried. Environmental survivability — the demand that gear work "from the Arctic to the archipelago" — is a concrete, expensive test program, not a spec-sheet claim. "Open system architecture" eases integration but does not remove safety, reliability, and interoperability testing, and each adds months and capital to a timeline consumer software never sees.
Atoms cost money. Interceptors, drones, and sensors require prototyping, tooling, supply chains, and manufacturing lines — "advanced manufacturing" is itself one of the named asks. That collides with a certification calendar measured in years, so a defense-hardware company must raise and survive on a profile that looks nothing like a SaaS burn curve. Investors who understand this exist; the wave that produced Anduril proved the appetite is real. But a founder treating a weapons system like an app will run out of money before the first program of record.
"Lower the cost per kill" is honest language about what this hardware is for. Founders here are building instruments of lethal force for a state, and the moral weight of that — the degree of human control over a weapon, export to allies, the downstream uses of a dual-use sensor or drone — is a real decision with real stakes. The industry is not of one mind about it, and pretending the question is settled is its own kind of dishonesty.
A company that touches defense articles or defense-relevant technical data operates under regimes most startups never encounter. The International Traffic in Arms Regulations (ITAR), which implement the Arms Export Control Act and cover items on the U.S. Munitions List (22 CFR §121.1, enforced by the State Department's Directorate of Defense Trade Controls), constrain who may access technical data — including which employees and vendors. The Cybersecurity Maturity Model Certification (CMMC), the Department of Defense's framework for protecting controlled unclassified information across the defense industrial base, sets security requirements a contractor must meet to hold certain contracts. These are not paperwork afterthoughts; they shape hiring, data handling, and every tool a defense company is allowed to use.
What building it takes
Stripped down, a company answering this request is a hardware company with a government customer and a compliance perimeter: real engineering of interceptors, sensors, drones, or logistics; an environmental-qualification and test program; a manufacturing capability; a capital plan sized for a multi-year certification calendar; a procurement function that can convert a pilot into a program of record; and an ITAR/CMMC-grade security posture from the first hire. It is a defense-manufacturing company with a software layer, not a software company that happens to sell to the Army. That ordering is the whole difficulty — the same shape The Primer had, pointed at atoms and a regulated buyer instead of children and a classroom.
Where Gwen stands
Plainly:
Gwen is a business-work AI. It builds and hosts websites and web apps, generates images and video, runs email, CRM, social, and operations, and does research like this. None of that is a weapons system, an autonomy stack, or a qualified piece of defense hardware, and none of it should be mistaken for one. This request lives in a world of physical engineering, live-fire test ranges, program offices, and export law — a domain with its own experts, regulators, and hard-won failures. Gwen has no special claim there, and claiming otherwise would be exactly the hype this series exists to avoid.
The only honest overlap is a picks-and-shovels one, and it comes with a caveat the previous articles didn't need. A defense startup is still a company: it needs a website, a working web app, recruiting and marketing, a CRM to manage pilots and government relationships, content and research operations. That is Gwen's lane in general. But defense is the one case in this series where the picks-and-shovels answer is not automatically "yes." A company under ITAR and CMMC has to evaluate carefully what any external tool — including an AI that handles company data — is allowed to touch, where that data lives, and who can access it. Marketing copy and a public website may be well clear of controlled technical data; internal systems that brush up against export-controlled information may not be. So the responsible position is not "Gwen can run the business around a defense startup" full stop, but "Gwen can help with the unregulated business surface, and any use near controlled data must be assessed against that company's compliance obligations first." On this request, more than any other, the honest word is — Gwen serves the company at its edges, does not build the thing at its center, and does not pretend its data posture clears a bar it has not been measured against.