Artificial intelligence is becoming part of everyday business.
Companies are using AI to write documents, summarize information, analyze data, automate tasks, and support cybersecurity teams.
For defense contractors, however, AI creates an important question:
How can organizations use AI without putting CUI, cybersecurity, or compliance at risk?
AI can improve productivity and security, but it can also create new risks when employees use tools without understanding where information is stored, processed, or shared.
For organizations in the Defense Industrial Base, AI needs to be treated as part of the broader cybersecurity and compliance program.
What Is AI and CMMC Compliance?
AI and CMMC compliance refers to how defense contractors use artificial intelligence while continuing to protect Controlled Unclassified Information (CUI) and meet applicable cybersecurity and contractual requirements.
AI tools can create compliance risks when they process, store, transmit, or expose sensitive information without proper controls.
CMMC does not simply prohibit AI.
The concern is how AI is being used, what information it can access, and whether CUI remains properly protected.
How AI Is Changing Cybersecurity
AI can help cybersecurity teams work more efficiently.
Depending on the technology, AI may help with:
- Detecting unusual activity
- Reviewing security alerts
- Identifying phishing attempts
- Prioritizing vulnerabilities
- Analyzing large amounts of security data
- Supporting incident investigations
- Automating repetitive tasks
These tools can be valuable, but they should not replace human review or established security controls. CISA maintains a growing library of federal guidance on securing AI systems.
AI can still produce incorrect results, miss context, or make recommendations that need to be verified.
The Biggest AI Risk: Sensitive Data
One of the biggest risks comes from employees entering sensitive information into public or unapproved AI tools.
For example, an employee may copy information from a technical document into an AI platform to summarize it.
If that document contains CUI, export-controlled technical data, proprietary information, or credentials, the organization may create a serious cybersecurity or compliance issue.
Before using AI, organizations should understand:
- What data employees will enter
- Where that data is stored
- Where it is processed
- Who can access it
- How long it is retained
- Whether the provider uses submitted data to improve or train its systems
- Whether administrators can control and monitor access
A popular AI tool is not automatically appropriate for sensitive government information.
Can Defense Contractors Use AI Tools?
Yes, defense contractors can use AI tools, but the specific use should be reviewed before sensitive information is involved.
Organizations should evaluate what the AI system can access, how it handles information, and whether its use affects the company’s CMMC environment or contractual responsibilities.
The key question is not simply:
“Is AI allowed?”
The better question is:
“Is this specific AI tool approved for this specific type of information and use?”
Can CUI Be Entered Into an AI Tool?
Organizations should not enter CUI into an AI platform unless the specific environment has been reviewed and approved for that use and meets applicable cybersecurity and contractual requirements.
Defense contractors need to understand how the provider stores, processes, transmits, and protects the information.
This is especially important when AI services are operated by third-party providers.
AI and NIST SP 800-171
If an AI system interacts with CUI or systems within the CUI environment, organizations should consider how it fits into their broader NIST SP 800-171 security program.
Important areas may include:
Access Control
Who is allowed to use the AI system?
Access should be limited based on business need and user responsibility.
Identification and Authentication
Users should be properly identified and authenticated before accessing protected systems or information.
Audit and Accountability
Organizations should understand what activity can be logged, monitored, and reviewed.
Incident Response
Companies should have a process for responding if sensitive information is accidentally entered into an unauthorized AI tool. Cyber incident reporting obligations may also apply under DFARS 252.204-7012.
Security Awareness
Employees should understand what information they can and cannot enter into AI platforms.
AI and ITAR
Defense contractors may also need to consider ITAR.
The International Traffic in Arms Regulations control certain defense articles, defense services, and technical data associated with items on the United States Munitions List.
If an organization handles ITAR-controlled technical data, it should carefully evaluate whether an AI platform could create an unauthorized disclosure, transfer, or access issue.
Important questions include:
- Where is the data processed?
- Who can access it?
- Where is it stored?
- Are foreign persons or third-party providers involved?
- Does the provider’s infrastructure meet the organization’s requirements?
Strong cybersecurity alone does not automatically make an AI tool appropriate for ITAR-controlled information.
What Is Shadow AI?
Shadow AI occurs when employees use AI tools without company approval.
An employee may create a personal account to help write emails, summarize documents, analyze spreadsheets, or create code.
The employee may simply be trying to work faster.
However, company information may now be passing through a system that was never reviewed by the security team.
This is why organizations need clear AI policies, even if they have not officially adopted AI.
What Defense Contractors Should Check Before Approving an AI Tool
Before approving an AI platform, organizations should review:
- What information employees will enter
- Whether CUI, FCI, or export-controlled data could be involved
- Where data is processed and stored
- Who can access submitted information
- Whether prompts and uploads are retained
- Whether submitted information is used for model training
- How users authenticate
- What administrative and logging controls are available
- How the AI tool connects to the organization’s systems
- Which CMMC, DFARS, NIST, ITAR, or contractual requirements apply
This review should happen before the tool becomes part of normal operations. The NSA and CISA joint guidance on deploying AI systems securely offers a useful starting point for organizations evaluating externally developed AI platforms.
Create an AI Acceptable-Use Policy
A clear AI acceptable-use policy can help employees understand what is allowed.
The policy should address:
- Approved AI platforms
- Prohibited tools
- Information employees may enter
- Information that must never be entered
- CUI and export-controlled data
- Account and access requirements
- Human review of AI-generated content
- Reporting accidental disclosures
- Approval requirements for new AI applications
The goal is not necessarily to block AI.
The goal is to create clear boundaries around its use. Organizations building AI governance from scratch may find the NIST AI Risk Management Framework and its companion Playbook helpful as voluntary reference material.
AI Still Needs Human Review
AI-generated information can sound accurate even when it is wrong.
That is especially important for cybersecurity and compliance.
An AI system could provide an incorrect interpretation of a CMMC requirement, generate a weak policy, or recommend a technical setting that does not match the organization’s actual environment.
AI can support the process, but qualified personnel still need to verify important decisions and documentation.
Frequently Asked Questions About AI and CMMC
Does CMMC prohibit artificial intelligence?
No. CMMC does not simply prohibit organizations from using AI. The concern is whether CUI and systems within the CMMC environment remain properly protected.
Can AI help with CMMC compliance?
AI may help with research, analysis, cybersecurity monitoring, and administrative tasks. However, AI does not make an organization compliant. Required security controls still need to be properly implemented and assessed.
Can AI affect CMMC scope?
Potentially. If an AI system stores, processes, transmits, or has access to CUI, organizations should evaluate how that use affects their CMMC environment and assessment scope. The DoD CIO publishes official CMMC scoping and assessment guides.
Can AI create an ITAR issue?
It can. If ITAR-controlled technical data is entered into or accessed through an AI platform, organizations need to consider whether an unauthorized export, disclosure, or foreign-person access could occur.
Should employees be allowed to use public AI tools?
Organizations should establish clear policies before employees use public AI tools for business information, especially when CUI, proprietary information, credentials, or export-controlled technical data may be involved.
AI Is a Tool, Not a Compliance Strategy
AI can help organizations improve productivity and strengthen cybersecurity operations.
But AI itself does not make an organization secure or compliant.
Defense contractors still need strong security controls, employee training, documented policies, risk management, system monitoring, and ongoing oversight.
Before adopting an AI platform, organizations should understand four things:
What information is going into the system, where that information is going, who can access it, and how it affects existing compliance requirements.
mistakes and focus on what matters for contract eligibility and security.
Sources and Further Reading
Schedule a free consultation with the Brea Networks team to review your current environment, identify compliance risks, and understand what steps are required to move forward. A short conversation can help you avoid costly mistakes and focus on what matters for contract eligibility and security.