TL;DR
As AI adoption is accelerating, defense contractors must ensure CUI does not enter unauthorized AI tools. Banning AI use outright defeats the purpose of AI adoption, however, meaning organizations must find another solution. Rather, the solution is to govern AI use through the same data-first principles required for CMMC readiness: finding CUI, marking it, defining approved boundaries, controlling data movement, monitoring usage, and generating evidence. Organizations should evaluate AI tools based on data access, retention, model training, integrations, user behavior, and auditability. If you cannot prove that CUI is kept out of unauthorized AI environments, that may lead to a CMMC and contractual risk.
AI Creates a New CUI Exposure Path
AI has quickly become one of the most common CMMC-related questions from defense contractors. Organizations want the productivity gains, but they also need to prevent CUI from entering unauthorized systems, including unauthorized AI tools.
In a recent Fortra webinar, Lansing Nye-Madden noted:
That is a very, very new concept and something that gets brought up quite often now... AI tools and all of the different AI-integrated tools.
Lansing Nye-Madden, Solutions Engineer, Fortra
This increasingly common concern is not hypothetical. AI introduces new data movement paths through prompts, uploads, integrations, agents, and connected applications.
AI tools have changed how employees write, summarize, code, analyze, and search. For defense contractors, that productivity opportunity comes with a serious question: what happens if users paste CUI into an AI prompt or connect an AI agent to a repository containing CUI?
CMMC requires organizations in the defense industrial base to safeguard FCI and CUI according to applicable requirements. CUI is sensitive unclassified information that requires safeguarding or dissemination controls under law, regulation, or government-wide policy.
AI changes the risk surface because data can move through:
User prompts
File uploads
Browser extensions
AI writing assistants
Meeting transcription tools
Code assistants
AI-enabled search
Connected SaaS applications
Autonomous agents
Workflow automation
Third-party integrations
A user may not assume such actions count as "transmitting" CUI; they may think they are simply asking for a summary, drafting a proposal, or troubleshooting an engineering issue. But if the prompt or attachment contains CUI, the organization may have allowed sensitive government information into an unauthorized environment.
Why AI Governance Is a Part of CMMC Readiness
Really ensuring that your organization is using AI in a safe, secure, and governed methodology is incredibly important.
Marc Zurcher, Managing Principal, Coalfire
AI governance and CMMC readiness are connected by one common requirement: data control.
CMMC focuses on whether applicable information systems protect FCI and CUI. AI governance asks whether AI tools are approved, controlled, monitored, and aligned with business and security requirements. But these two programs should not be separate.
If an AI tool can access CUI, it likely affects the scope of your CMMC requirements. If users can paste CUI into an unapproved AI service, the organization has a data movement problem. If an AI agent indexes a CUI repository, the organization must understand where that data goes, how it is processed, whether it is retained, and who can access outputs.
At Fortra, we recommend treating AI as another data channel. In that way, the questions one would ask about any other data channel also apply to AI tools:
Can CUI enter this channel?
Is the channel approved for CUI?
Who can use it?
What data can it access?
What controls prevent misuse?
What logs prove enforcement?
What evidence supports the policy?
How To Implement AI Governance for CMMC
I boil it back down to the same spokes of the wheel: understanding where the CUI is, defining the scope, defining the controls, [and] marking data... you can put boundaries in place for that AI so that the AI doesn’t receive data that’s appropriately marked.
Lansing Nye-Madden, Solutions Engineer, Fortra
Start With CUI Discovery
If CUI is identified and marked, controls can be designed to prevent it from entering unapproved AI tools — that is the practical connection between CMMC and AI governance. But organizations cannot keep CUI out of AI tools if they do not know where CUI is.
Before writing AI rules, organizations should identify where CUI lives across endpoints, email, cloud repositories, file shares, collaboration platforms, engineering systems, and business applications.
The National Archives CUI Registry identifies categories and markings, and DoD CUI resources describe CUI as a control marking that alerts recipients that special handling may be required.
CUI discovery should include:
Marked documents
Unmarked but likely CUI
Technical drawings
Export-controlled information
Contract data
Program documents
Supplier communications
Email attachments
Cloud files
Local downloads
Archived data
Once CUI is identified, organizations can determine whether AI tools have access to those locations.
Mark CUI So Controls Can Recognize It
CUI markings help users recognize sensitive information, and metadata labels help downstream tools identify it and apply the necessary controls. In this way, AI governance becomes much stronger when CUI is marked consistently.
DoD marking guidance describes mandatory CUI markings for unclassified documents containing CUI, including the acronym “CUI” and designation indicators.
For AI governance, markings can support:
Prompt inspection
Upload blocking
Browser controls
DLP policies
Cloud access controls
Data classification rules
User coaching
Audit trails
If a document is marked as CUI visually but lacks metadata, some tools may not detect it reliably. If it contains metadata but has no visual indicator, users may not recognize the handling requirement. Use both where possible.
Evaluate AI Tools Before Approval
Not all AI tools pose the same risk. A governed enterprise AI tool with appropriate contractual, technical, and administrative controls may be very different from a public consumer AI service. But no tool should be approved for sensitive workflows until it is evaluated.
To thoroughly assess AI tools and their risk of data exposure, organizations must consider several specific questions related to how those tools handle data, what the tools have access to and integrate with, what security and compliance capabilities they possess, and what evidence they provide for compliance audits:
Data handling
What data does the AI tool process?
Is data stored?
Is data retained?
Is data used for model training?
Can the vendor access prompts or outputs?
Where is data processed geographically?
Access and integrations
What repositories can the AI tool access?
Can it connect to email, cloud storage, chat, ticketing, or code repositories?
Can users upload files?
Can agents take actions on behalf of users?
Does the tool inherit user permissions?
Security and compliance
What security certifications or authorizations does the provider have?
Can the tool support audit logging?
Can administrators restrict data sources?
Can DLP controls inspect prompts and uploads?
Can access be limited by role?
Evidence
Can the organization prove CUI was blocked?
Can it show which users accessed the tool?
Can it show what repositories were connected?
Can logs be retained for assessment support?
Can policy exceptions be reviewed?
If the answer to any of these questions is unclear, the tool should not be used with or near CUI.
Use Soft and Hard Controls
AI governance should not rely only on policy. Users need guardrails.
Soft controls help users make better decisions:
Warning banners
Just-in-time prompts
User education
Acceptable use reminders
Required business justifications
Risk-based coaching
Hard controls prevent high-risk behavior:
Blocking CUI uploads
Preventing copy/paste into unapproved AI tools
Restricting browser access
Disabling unauthorized plugins
Blocking AI access to CUI repositories
Enforcing approved enterprise AI platforms
Quarantining risky data movement
The right balance matters. If controls are too loose, CUI can leak. If controls are too restrictive, users may seek workarounds.
Build AI Governance Into the System Security Plan (SSP)
If AI tools interact with systems that process, store, or transmit CUI — or provide security protections for those systems — they may need to be considered in CMMC scoping and documentation. 32 CFR Part 170 addresses systems that process, store, or transmit FCI or CUI, provide protections for CUI systems, or are not isolated from such systems.
The SSP should reflect AI-related decisions where relevant:
Approved AI tools
Prohibited AI tools
Data types allowed or prohibited
CUI handling rules
Technical enforcement mechanisms
Monitoring and logging
User responsibilities
Exception processes
External provider responsibilities
This documentation helps show that AI is governed rather than unmanaged.
Generate Evidence That CUI Is Not Entering AI Tools
When an assessor comes in and asks, "Does this AI tool have access to CUI?" you really want to be able to prove that it doesn’t.
Lansing Nye-Madden, Solutions Engineer, Fortra
For CMMC readiness, the critical question is not “Do you have an AI policy?” Rather, it is “Can you prove the policy is enforced?”
Evidence may include:
AI tool inventory
Approved use cases
Access control records
DLP logs
Browser control events
CASB/SSE logs
Classification metadata events
Blocked upload records
Prompt inspection logs, where appropriate
User justification records
Training acknowledgments
Exception approvals
Periodic access reviews
Vendor responsibility documentation
NIST SP 800-171A provides assessment procedures for evaluating security requirements, and CMMC assessment resources help organizations understand assessment expectations. Evidence should show actual control operation, not just intention.
Fortra's Recommendations
While accurate and consistent CMMC compliance is at the top of mind for most defense contractors, that should not come at the expense of the innovation your AI tools promote. Rather, the goal should be to make AI adoption safe, governed, and defensible. Fortra recommends the following steps for proper AI governance:
Inventory AI tools already in use.
Identify where CUI lives.
Determine whether AI tools can access CUI repositories.
Classify and mark CUI.
Define approved and prohibited AI use cases.
Apply DLP and browser controls.
Restrict AI integrations by role and data type.
Log AI-related data movement.
Train users with practical examples.
Review evidence regularly.
FAQ
Expert Insights Featured in This Blog
This article includes insights from a Fortra webinar featuring Skip Chapman, Director of Government Programs at Fortra; Lansing Nye-Madden, Solutions Engineer at Fortra; and Marc Zurcher, Managing Principal at Coalfire. The discussion covered CMMC readiness, CUI discovery, scoping, audit evidence, and AI governance for organizations in the defense industrial base.