AI Governance
Your team already uses AI. Governance is what makes it defensible.
Policy, inventory, vendor review and evidence — mapped to the controls you're already assessed against. Not a template you'll file away and never open again.
The problem
AI tools reach CUI before anyone writes a policy.
Staff adopt tools because they work. By the time governance catches up, prompts containing controlled information have already left your boundary. These are the questions an assessor will ask, and most contractors cannot answer them.
- WHICH TOOLS
- Which AI services are in use across engineering, IT, contracts and proposal teams — including the ones nobody approved.
- WHAT DATA
- Whether prompts, uploads or outputs have carried CUI, export-controlled material, or contract-sensitive information.
- WHERE IT GOES
- Vendor retention, training-data use, sub-processors, and hosting location for each tool in scope.
- WHAT'S WRITTEN
- Whether your SSP acknowledges AI in the environment at all — and whether your acceptable use policy is specific enough to enforce.
The engagement
AI in CUI Environments
Two weeks. We determine which AI tools can touch CUI, and put enforceable rules around the rest.
- Inventory of AI tools already in use across the business
- Data flow analysis covering prompts, logs and retention
- Vendor and FedRAMP posture review for each tool
- Acceptable use policy written for in-scope systems
- Guidance memo for leadership sign-off
Scope
Two practices, two problems.
AI governance means something different depending on what the AI touches. If the answer is CUI, the work belongs here. If it doesn't, it belongs elsewhere.
AI inside a CUI boundary
DFARS 252.204-7012, NIST SP 800-171 and CMMC Level 2. Governance written against the control families you're already assessed on, with evidence an assessor will accept.
Discuss this engagement →Commercial and global AI governance
EU AI Act, ISO/IEC 42001 and NIST AI RMF programs for organizations outside the defense industrial base. Run by the same practitioner, on a separate site.
Visit AI GRC Advisory →Next step
Most teams find more AI in use than they expected.
A short discovery call, then a written read on where AI is touching your controlled environment today.
