AI Governance

Your team already uses AI. Governance is what makes it defensible.

Policy, inventory, vendor review and evidence — mapped to the controls you're already assessed against. Not a template you'll file away and never open again.

The problem

AI tools reach CUI before anyone writes a policy.

Staff adopt tools because they work. By the time governance catches up, prompts containing controlled information have already left your boundary. These are the questions an assessor will ask, and most contractors cannot answer them.

WHICH TOOLS
Which AI services are in use across engineering, IT, contracts and proposal teams — including the ones nobody approved.
WHAT DATA
Whether prompts, uploads or outputs have carried CUI, export-controlled material, or contract-sensitive information.
WHERE IT GOES
Vendor retention, training-data use, sub-processors, and hosting location for each tool in scope.
WHAT'S WRITTEN
Whether your SSP acknowledges AI in the environment at all — and whether your acceptable use policy is specific enough to enforce.

The engagement

AI in CUI Environments

Two weeks. We determine which AI tools can touch CUI, and put enforceable rules around the rest.

$4,500 Flat fee · 2 weeks
  • Inventory of AI tools already in use across the business
  • Data flow analysis covering prompts, logs and retention
  • Vendor and FedRAMP posture review for each tool
  • Acceptable use policy written for in-scope systems
  • Guidance memo for leadership sign-off

Scope

Two practices, two problems.

AI governance means something different depending on what the AI touches. If the answer is CUI, the work belongs here. If it doesn't, it belongs elsewhere.

AI inside a CUI boundary

DFARS 252.204-7012, NIST SP 800-171 and CMMC Level 2. Governance written against the control families you're already assessed on, with evidence an assessor will accept.

Discuss this engagement →

Commercial and global AI governance

EU AI Act, ISO/IEC 42001 and NIST AI RMF programs for organizations outside the defense industrial base. Run by the same practitioner, on a separate site.

Visit AI GRC Advisory →

Next step

Most teams find more AI in use than they expected.

A short discovery call, then a written read on where AI is touching your controlled environment today.