Artificial Intelligence Is Changing How Defense Contractors Work
Artificial intelligence (AI) is rapidly becoming part of daily operations across the Defense Industrial Base (DIB), helping organizations draft documents, summarize information, support software development, conduct research, and reduce repetitive administrative work.
Can defense contractors use AI when Controlled Unclassified Information (CUI) is involved? Yes—but only when the specific AI service, deployment, and configuration are appropriate for the information being handled and satisfy all applicable contractual, cybersecurity, cloud-service, and data-handling requirements. Internal organizational approval alone is not enough.
When Controlled Unclassified Information (CUI) or covered defense information is processed, stored, or transmitted through an external AI or cloud service, organizations must understand how that service handles the data and whether the environment meets the requirements applicable to the contract and information. Using an unauthorized or improperly configured AI service can create unauthorized disclosure, contractual, cybersecurity, and compliance risk, including challenges meeting NIST SP 800-171 and CMMC requirements.
Why Defense Contractors Are Turning to AI
Artificial intelligence is quickly becoming a practical business tool for defense contractors looking to improve efficiency without increasing administrative workloads. Employees are using AI-powered solutions to draft emails, summarize lengthy documents, generate reports, organize research, assist with software development, and automate repetitive administrative tasks. These capabilities allow teams to complete routine work more efficiently and dedicate more time to activities that require human expertise and decision-making.
The increasing accessibility of AI has also accelerated adoption. Many platforms are easy to implement, require little technical expertise, and integrate with existing business applications. As organizations continue searching for ways to improve productivity while operating with limited resources, AI offers opportunities to simplify everyday workflows and support faster decision-making.
For organizations supporting Department of Defense (DoD) contracts, AI use requires additional scrutiny when sensitive information is involved. Productivity gains should not come at the expense of protecting contractual data. Before an AI service is used with business information, organizations should understand how the service collects, processes, stores, retains, and shares submitted data.
The Biggest Risk Is How AI Is Used with CUI
The greatest cybersecurity concern surrounding artificial intelligence is often not the technology itself. Instead, it is how employees choose to use it. When users copy, paste, or upload sensitive information into an AI platform without understanding how that information is handled, organizations can unintentionally expose data that must remain protected.
Controlled Unclassified Information (CUI) is government-created or government-owned information, or information created or possessed by a contractor on behalf of the government, that requires safeguarding or dissemination controls under applicable laws, regulations, or government-wide policies. CUI is not classified information, but it is still sensitive information that defense contractors must safeguard in accordance with applicable contractual and cybersecurity requirements.
Many employees naturally treat AI tools like search engines or traditional productivity software. However, AI platforms often function differently. Depending on the provider and service configuration, submitted prompts and uploaded files may be processed, retained for varying periods, or used in accordance with the vendor's terms of service.

For example, an employee may copy sections of a proposal into an AI platform to improve readability, upload technical documentation to generate a summary, or ask an AI assistant to review contract language. While these tasks may appear routine, they can expose sensitive information if the AI environment is not authorized for the specific information being handled. A platform that is approved for general business use is not automatically authorized to process, store, or transmit CUI. The specific AI service and configuration must also satisfy the applicable contractual, cybersecurity, cloud-service, and data-handling requirements.
Examples of activities that could unintentionally expose sensitive information include:
| Uploading contract documents for summarization | |
| Pasting engineering specifications into a public AI platform | |
| Asking an AI assistant to rewrite technical procedures | |
| Uploading screenshots that contain Controlled Unclassified Information | |
| Using AI to review proposal content or customer deliverables |

Entering Controlled Unclassified Information into an unauthorized AI service may result in information being stored outside the organization's approved environment or processed in ways that conflict with contractual requirements. Even if the intent is simply to improve writing or save time, submitting sensitive information to an unauthorized platform may constitute an unauthorized disclosure.
These risks are driven primarily by user decisions rather than flaws in the technology itself. Employees may not recognize that seemingly harmless requests can involve information that should never leave the organization's controlled environment.
Reducing this risk begins with education and governance. When employees understand which AI platforms are approved, what information may be entered into them, and why these requirements exist, they are better equipped to make decisions that improve productivity without compromising cybersecurity or contractual obligations.
How AI Can Affect Compliance with NIST SP 800-171 and CMMC
Using artificial intelligence does not change an organization's responsibility to safeguard sensitive information. Whether employees use traditional software, cloud-based collaboration platforms, or AI-powered services, organizations remain accountable for protecting Controlled Unclassified Information and complying with applicable contractual cybersecurity requirements.
NIST SP 800-171 establishes security requirements for protecting sensitive information in nonfederal systems and organizations. These requirements continue to apply regardless of whether employees use AI as part of their daily work. If sensitive information is submitted to an unauthorized AI platform, organizations may introduce unnecessary risk to controls involving access management, configuration management, system and information integrity, security awareness, incident response, and the overall protection of sensitive information throughout its lifecycle.
Artificial intelligence does not introduce a separate compliance framework. Instead, organizations should evaluate AI use through the same cybersecurity, risk management, and data protection processes already established for other technologies. This means assessing AI platforms before deployment, understanding vendor security practices, documenting acceptable use, and continuously monitoring how AI is used across the organization.
A comprehensive AI governance strategy should involve multiple stakeholders, including cybersecurity, information technology, compliance, legal, procurement, and executive leadership. Working together helps ensure that business objectives, contractual obligations, privacy considerations, and cybersecurity risks are evaluated before AI technologies are adopted.
On July 13, 2026, CMMC Phase II implementation was suspended, including the Phase II requirements that had been scheduled to begin later in 2026. However, the suspension did not eliminate the obligation to protect Controlled Unclassified Information (CUI) or meet applicable NIST SP 800-171 and contractual cybersecurity requirements. Phase I self-assessment requirements remain in place, and defense contractors should continue implementing and maintaining required security controls, completing applicable self-assessments and annual affirmations, documenting how CUI is protected, and monitoring official CMMC guidance as the program continues to evolve.
Rather than viewing AI as a compliance challenge, organizations should view it as another technology that requires appropriate oversight. Integrating AI into existing governance processes allows organizations to embrace innovation while continuing to meet contractual obligations and protect sensitive information.
The next step is establishing clear organizational policies that define how AI can be used safely, which platforms are approved, and what information should never be entered into an AI system.
Establishing an AI Policy for Handling CUI
Adopting artificial intelligence successfully requires more than selecting the right technology. It also requires clear governance that helps employees understand how AI should be used and how sensitive information should be protected. Without documented expectations, employees may rely on personal judgment when interacting with AI platforms, increasing the likelihood of inconsistent practices, and unnecessary cybersecurity risks.
A well-defined AI acceptable use policy provides a consistent framework for responsible AI adoption. It establishes clear expectations for employees, reduces uncertainty about appropriate use, and supports the organization's broader cybersecurity and compliance objectives.
An effective AI policy should answer key questions such as:
| Which AI platforms have been approved for business use? | |
| What types of information are prohibited from being entered into AI systems? | |
| Who is responsible for reviewing and approving new AI technologies? | |
| How are AI vendors evaluated before adoption? | |
| What should employees do if they accidentally submit sensitive information to an AI platform? |
An AI acceptable use policy should identify not only which services are approved for business use, but also what types of information each service and configuration is authorized to handle. A service approved for drafting public marketing content, for example, should not automatically be considered approved for CUI, export-controlled information, technical data, proprietary information, or customer information.
Organizations should also define exactly what information may and may not be entered into AI systems. This includes establishing restrictions on Controlled Unclassified Information, export-controlled data, proprietary business information, customer information, and other sensitive data identified by the organization. Providing practical examples can help employees recognize situations where AI should and should not be used.
Before authorizing an AI environment for CUI, organizations should evaluate the vendor, product tier, deployment model, configuration, data-processing location, retention practices, model-training practices, subprocessors, access controls, incident-response capabilities, contractual terms, and applicable cloud-service and cybersecurity requirements.
As AI technologies continue to evolve, organizations should establish a formal approval process for evaluating new tools before employees begin using them. This process should involve cybersecurity, information technology, legal, compliance, procurement, and business leadership to ensure operational, contractual, and security considerations are fully addressed.
Finally, AI governance should become part of existing cybersecurity awareness initiatives rather than operating as a separate program. Regular employee training, periodic policy reviews, and continuous communication help reinforce expectations and ensure governance evolves alongside changes in technology, business operations, and regulatory guidance.
MAD AI Governance Checklist
Artificial intelligence can deliver significant operational benefits when it is supported by thoughtful governance and consistent cybersecurity practices. Rather than allowing AI adoption to occur informally, organizations should establish practical safeguards that help employees make informed decisions while reducing compliance and security risks.
While every organization has unique operational requirements, the following best practices provide a strong foundation for responsible AI adoption.
Never Enter CUI Into an Unauthorized AI EnvironmentEmployees should never submit CUI into an AI environment unless the specific service and configuration have been evaluated and authorized for that use and satisfy the requirements applicable to the information and contract. General organizational approval of an AI tool does not automatically authorize it to handle CUI.
|
Classify Information Before Using AIEmployees should understand the sensitivity of the information they are working with before using any AI tool. Proper data classification helps determine whether AI is appropriate for the task and reduces the likelihood of accidental disclosure.
|
Evaluate AI Vendors CarefullyOrganizations should review each AI vendor's security documentation before adoption. This includes understanding how data is processed, where it is stored, whether prompts are retained, what security controls are available, and how customer information is protected. Vendor evaluations should become part of the organization's existing technology review process.
|
Train Employees on Responsible AI UseTechnology alone cannot prevent inappropriate AI use. Regular security awareness training should explain organizational AI policies, approved platforms, prohibited activities, and the potential consequences of mishandling sensitive information. Employees who understand both the benefits and risks of AI are better equipped to make informed decisions.
|
Monitor AI UsageResponsible AI governance extends beyond initial implementation. Organizations should periodically review how AI tools are being used, identify emerging risks, and verify that employees continue following established policies. Monitoring AI usage also helps identify opportunities to improve governance as business needs evolve.
|
Review AI Policies RegularlyArtificial intelligence is evolving rapidly, and organizational policies should evolve alongside it. Regular policy reviews help ensure governance reflects current technologies, vendor practices, contractual obligations, and cybersecurity expectations.
|
Use AI Without Expanding CUI Risk
Defense contractors do not have to choose between AI adoption and strong cybersecurity. They do, however, need to understand where their information is going, how the AI service processes and retains it, which requirements apply, and whether the specific environment is authorized for the intended use.
Strong AI governance connects technology approval, data classification, vendor due diligence, employee training, monitoring, incident response, and NIST SP 800-171 controls into one repeatable process. That allows organizations to benefit from AI while continuing to protect CUI and meet contractual cybersecurity obligations.
Frequently Asked Questions (FAQs)
Can I use ChatGPT or other public AI tools with Controlled Unclassified Information?
Internal organizational approval alone is not enough. Before Controlled Unclassified Information (CUI) or covered defense information is processed, stored, or transmitted through an external AI or cloud service, the organization must determine that the specific service, product tier, deployment, and configuration are appropriate for that information and satisfy all applicable contractual, cybersecurity, cloud-service, and data-handling requirements.
If those requirements have not been validated for the specific environment, do not enter CUI into the service.
Does using AI automatically violate NIST SP 800-171 or Cybersecurity Maturity Model Certification requirements?
No. AI use itself does not automatically violate NIST SP 800-171 or Cybersecurity Maturity Model Certification (CMMC) requirements. The risk depends on how the technology is used, what information it handles, where that information flows, and whether the specific environment and security controls satisfy the requirements applicable to the organization and contract.
What should an AI acceptable use policy include?
An AI policy should identify approved AI platforms, define what information may be entered into AI systems, establish vendor review requirements, outline approval processes, and reinforce employee responsibilities through security awareness training.
How can organizations determine whether an AI platform is appropriate for business use?
Evaluate the vendor's risk assessment, data handling practices, retention policies, and alignment with organizational requirements before approving the platform for business use.
What should employees do if they accidentally submit sensitive information to an AI platform?
Employees should report the incident immediately through established security reporting procedures so the organization can assess the risk, respond appropriately, and strengthen future AI governance.
Did the July 2026 CMMC Phase II suspension remove the requirement to protect CUI?
No. The suspension changed the CMMC implementation schedule, but it did not eliminate applicable contractual obligations to safeguard Controlled Unclassified Information (CUI) or meet NIST SP 800-171 requirements. Organizations should continue maintaining applicable cybersecurity controls, self-assessments, and documentation while monitoring official CMMC guidance.
Original Publish Date: September 15, 2026
Author: John Drauch | CCP, Security+ |
John Drauch is a Cybersecurity Consultant specializing in risk management and compliance for defense and research environments. He holds the CCP and Security+ certifications and works with NIST 800-53 and the DoD Risk Management Framework to support assessments, control evaluations, and ATO-related efforts. John helps organizations strengthen security posture and compliance readiness through disciplined, mission-focused security practices.
Reviewer: Jaclyn Jones | CISSP, Lead CCA, CySA+ |
Jaclyn Jones is a GRC Compliance Lead specializing in security operations and compliance, with more than 12 years of cybersecurity experience. She holds CISSP, Lead CCA, and CySA+ certifications and brings deep expertise in CMMC, NIST SP 800-171, DFARS, and CIS frameworks. Jaclyn helps organizations strengthen security controls, improve audit readiness, and build resilient compliance programs.

%20Graphics/CUI%20Checklist%20CTA%2001.png?width=500&height=261&name=CUI%20Checklist%20CTA%2001.png)