# CUI AI service-scope decision tree

Synthetic contract and data scenario. The fixture contains no CUI or export-controlled technical information. No provider approval or CMMC assessment result is represented.

A fictional contractor considers AI drafting and a security intermediary. The tree identifies the evidence required before any actual controlled-data use.

| Question | Finding | Next outcome |
| --- | --- | --- |
| Applicable contract and data category established? | No or unknown | Resolve with the contract/data owner before transmitting the proposed controlled information. |
| Information is CUI or covered defense information in scope? | Yes in the fictional scenario | Identify every storing, processing and transmitting service. |
| Information falls outside that category? | Established no for the assessed material | Review other confidentiality/export obligations; no blanket tool approval follows. |
| External provider is a cloud service handling covered information? | Yes | Obtain evidence for the applicable DFARS cloud requirements and incident obligations. |
| Level 2 ESP processes CUI or security protection data? | Yes | Apply the relevant 170.19(c) provider category and document SSP/service/CRM responsibilities. |
| A security intermediary handles only selected event data? | Data category not established | Assess whether it includes security protection data; do not assume automatic exclusion. |
| Required service evidence is missing? | Yes | Keep the proposed controlled-data path unapproved until the accountable review resolves it. |
| Unrestricted synthetic fixture only? | Yes | Use it for a scoped test without presenting the result as CUI authorisation. |

## Review steps

- Establish the contractual data scope: Record the originator, applicable clauses, information category and permitted recipients.
- Review each provider boundary: Distinguish cloud/non-cloud, CUI/security protection data and the actual service evidence.
- Keep the assessment handoff: Connect the data-flow map, system security plan and customer responsibility matrix to the accountable decision.

## Unrestricted synthetic fixture

This is a teaching note about an invented office bracket. It contains no controlled design, dimensions, materials or defence use. Rewrite a generic maintenance reminder without adding technical information.

## Fictional review record

Contract reference: CONTRACT-EX-28.
Controlled-data assumption: a separate proposed record is assumed CUI for the exercise; it is not included in this pack.
Recipients: proposed AI service and proposed security intermediary.
Provider evidence: to be obtained for the actual services before real-data use.
Control test: not run.
Authorisation to use CUI: none represented.

Record actual evidence rather than replacing missing provider requirements with a test result.

## Source and scope

Guide: https://aona.ai/resources/guides/cui-ai-assistants-cmmc/

Source check: 21 September 2026. General information, not professional approval or a completed control test.

- DFARS 252.204-7012: Safeguarding covered defense information: https://www.acquisition.gov/dfars/252.204-7012-safeguarding-covered-defense-information-and-cyber-incident-reporting.
- 32 CFR 170.19: CMMC scoping: https://www.law.cornell.edu/cfr/text/32/170.19
