# CUI AI service-scope decision tree

A fictional contractor considers AI drafting and a security intermediary. The tree identifies the evidence required before any actual controlled-data use.

Synthetic contract and data scenario. The fixture contains no CUI or export-controlled technical information. No provider approval or CMMC assessment result is represented.

Source: https://aona.ai/resources/guides/cui-ai-assistants-cmmc/
Sources checked: 2026-09-21

## The boundary includes intermediaries

### Origin

Contract and information category

### AI service

Processing, storage and provider evidence

### Security service

Content or security protection data handled

### Decision

SSP/CRM responsibilities and accountable review

| Question | Finding | Next outcome |
| --- | --- | --- |
| Applicable contract and data category established? | No or unknown | Resolve with the contract/data owner before transmitting the proposed controlled information. |
| Information is CUI or covered defense information in scope? | Yes in the fictional scenario | Identify every storing, processing and transmitting service. |
| Information falls outside that category? | Established no for the assessed material | Review other confidentiality/export obligations; no blanket tool approval follows. |
| External provider is a cloud service handling covered information? | Yes | Obtain evidence for the applicable DFARS cloud requirements and incident obligations. |
| Level 2 ESP processes CUI or security protection data? | Yes | Apply the relevant 170.19(c) provider category and document SSP/service/CRM responsibilities. |
| A security intermediary handles only selected event data? | Data category not established | Assess whether it includes security protection data; do not assume automatic exclusion. |
| Required service evidence is missing? | Yes | Keep the proposed controlled-data path unapproved until the accountable review resolves it. |
| Unrestricted synthetic fixture only? | Yes | Use it for a scoped test without presenting the result as CUI authorisation. |

## Review checklist

- [ ] Establish the contractual data scope
  Record the originator, applicable clauses, information category and permitted recipients.
- [ ] Review each provider boundary
  Distinguish cloud/non-cloud, CUI/security protection data and the actual service evidence.
- [ ] Keep the assessment handoff
  Connect the data-flow map, system security plan and customer responsibility matrix to the accountable decision.

## Included example files

- cui-ai-service-scope-review.md
- cui-ai-service-scope-review.csv
- unrestricted-cui-review-fixture.txt

## Source references

- DFARS 252.204-7012: Safeguarding covered defense information: https://www.acquisition.gov/dfars/252.204-7012-safeguarding-covered-defense-information-and-cyber-incident-reporting. (2026-09-21)
- 32 CFR 170.19: CMMC scoping: https://www.law.cornell.edu/cfr/text/32/170.19 (2026-09-21)

Use the worksheet within the relevant legal, contractual and technical scope. It is not a certification or a record of an installed-product test.
