AI Governance
Your team is already using AI. The question is whether CUI is going with it.
Nobody asked permission before pasting a drawing spec into a chatbot to clean up the wording. That single action can move controlled information outside your assessed boundary — and no control in your SSP describes it.
Where a prompt actually goes
Workstation
An engineer opens a browser tab and pastes a paragraph from a controlled document.
Vendor API
The text leaves your network. Transport encryption doesn't make it in-boundary.
Logs & retention
Prompts may be stored for abuse monitoring, support, or a retention window you didn't set.
Downstream use
Depending on the plan and terms, content may be reviewed by humans or used for training.
Each vendor and each plan tier behaves differently. Enterprise agreements often disable training and shorten retention; consumer accounts frequently do not. The terms are what matter, not the brand name.
Where this goes wrong
Four patterns we find in nearly every defense contractor we assess.
Tools nobody approved
Staff sign up with work email on personal plans. There's no inventory, so there's no control — and 3.4.1 asks you to have one.
External connections that aren't documented
3.1.20 requires you to control connections to external systems. An AI tool with a browser extension is exactly that.
Features enabled by default
Meeting transcription, email drafting and code assistants get switched on in suites you already pay for, without a scoping decision.
Service providers holding CUI
DFARS 252.204-7012 sets requirements for cloud services that store or process CUI. Most AI tools have not been evaluated against them.
How we approach it
Structured on the four functions of the NIST AI Risk Management Framework, mapped back to the NIST SP 800-171 controls your contracts already require.
Decide who owns the decision
An acceptable use policy that names which tools are permitted, for what data, and who approves exceptions. Written so a shop floor lead can follow it.
Find what's already in use
Inventory of AI tools across the business, including features embedded in software you already own, and where each one sits relative to your CUI boundary.
Assess each tool against the terms
Retention, training use, human review, sub-processors, and hosting location — read from the contract you're actually on, not the marketing page.
Put controls where they hold
Technical restrictions for what shouldn't be reachable, approved alternatives for what people genuinely need, and documentation an assessor can follow.
AI in CUI Environments
A two-week engagement that ends with a defensible position: what your people may use, what they may not, and documentation that survives an assessor's questions.
Common questions
Do we have to ban AI entirely?
No, and blanket bans usually fail — people route around them. The goal is approved tools for the work that needs them, with CUI kept out.
Is there a CMMC requirement for AI specifically?
Not as a named practice. AI use is governed by the existing controls: inventory, external connections, media protection, and boundary protection.
Our AI is built into Microsoft 365. Does that count?
It depends on your tenant, licensing and data residency. Embedded features are the ones most often missed, which is why the inventory comes first.
What if someone already pasted CUI into a public tool?
Treat it as a potential incident and follow your response plan. We can help you assess exposure and document what happened.
Find out where you stand first
The 25-question self-check covers the control families that AI use touches most, and takes five minutes.
This page describes our approach and is not legal advice. Requirements for cloud services holding CUI depend on your contract clauses and your contracting officer's determination.
