30 Days Gen AI Risk Trial -Start Now
Skip to main content

Compliance decisions

Can CUI go into an AI assistant?

Determine the contract and data scope before sending CUI to an AI service. DFARS cloud requirements and CMMC assessment boundaries concern the actual provider, service and information handled. A commercial privacy promise, zero-retention setting or security-tool installation does not establish permission or provider suitability.

For Defence contractors, CMMC programme owners and security architects

Aona field notesC28
Review every recipient
Data + contract + service

An AI provider and a security intermediary can create different assessment obligations.

Synthetic contract and data scenario. The fixture contains no CUI or export-controlled technical information. No provider approval or CMMC assessment result is represented.

01

Start with the information and contract

Identify the originator, applicable contract and the actual information category. DFARS 252.204-7012 defines covered defense information in its contractual context and refers to relevant safeguarding requirements. Do not classify every internal engineering document as CUI, or assume a missing label proves the information is unrestricted.

Ask the programme and contract owners to establish the permitted use and recipients. This is separate from export-control analysis: a CUI safeguarding decision does not settle whether ITAR or another export regime applies to the same material.

Source context: DFARS 252.204-7012: Safeguarding covered defense information

02

Apply the external cloud-service requirement

Under the described DFARS clause, an external cloud provider used to store, process or transmit covered defense information in contract performance must meet the specified FedRAMP Moderate-equivalent security requirements and the relevant incident-reporting, preservation and related provisions.

Review evidence for the exact service and its boundary. A provider’s unrelated accreditation, a generic company statement or a claim that prompts are not retained does not establish the required arrangement. Processing or transmitting information can matter even when long-term storage is disabled.

Source context: DFARS 252.204-7012: Safeguarding covered defense information

03

Map the CMMC service boundary

For the Level 2 external-service-provider analysis in 32 CFR 170.19(c), the rule distinguishes cloud from non-cloud providers and whether they process CUI, security protection data or neither. Its table identifies different assessment treatment for those combinations.

The rule also requires relevant provider relationships and services to be documented in the system security plan and the provider’s service description/customer responsibility matrix. This guide does not establish a CMMC assessment outcome or claim every supplier needs the same certification. Use the actual contract, assessment type and data flow.

Source context: 32 CFR 170.19: CMMC scoping

04

Include security services in the data map

A guardrail or monitoring service can itself receive content or security protection data. Assess that intermediary’s role instead of assuming that security functionality places it outside the boundary. The provider that receives a raw prompt may have a different role from a service receiving only particular event metadata.

Record what leaves the device, which systems can read it and where each category is processed or stored. An installed policy tool does not make an otherwise unapproved CUI transfer acceptable. Confirm the handling and provider requirements before any controlled information enters the proposed path.

Source context: DFARS 252.204-7012: Safeguarding covered defense information · 32 CFR 170.19: CMMC scoping

05

Use explicit stop and next outcomes

The decision tree below keeps unknown contract, data and provider conditions open. A negative CUI finding can lead to a separate review of other information obligations; it is not a universal permission to use any tool. An unresolved provider requirement means the proposed controlled-data use must be resolved before proceeding.

Begin technical exploration with unrestricted synthetic material. Record the actual service evidence and accountable decision separately from a product test. No Aona CMMC certification, FedRAMP status or approval to receive CUI is asserted by this page.

Source context: DFARS 252.204-7012: Safeguarding covered defense information · 32 CFR 170.19: CMMC scoping

Put it into practice

CUI AI service-scope decision tree

A fictional contractor considers AI drafting and a security intermediary. The tree identifies the evidence required before any actual controlled-data use.

Synthetic contract and data scenario. The fixture contains no CUI or export-controlled technical information. No provider approval or CMMC assessment result is represented.

The boundary includes intermediaries
01

Origin

Contract and information category

02

AI service

Processing, storage and provider evidence

03

Security service

Content or security protection data handled

04

Decision

SSP/CRM responsibilities and accountable review

CUI AI service-scope decision tree
QuestionFindingNext outcome
Applicable contract and data category established?No or unknownResolve with the contract/data owner before transmitting the proposed controlled information.
Information is CUI or covered defense information in scope?Yes in the fictional scenarioIdentify every storing, processing and transmitting service.
Information falls outside that category?Established no for the assessed materialReview other confidentiality/export obligations; no blanket tool approval follows.
External provider is a cloud service handling covered information?YesObtain evidence for the applicable DFARS cloud requirements and incident obligations.
Level 2 ESP processes CUI or security protection data?YesApply the relevant 170.19(c) provider category and document SSP/service/CRM responsibilities.
A security intermediary handles only selected event data?Data category not establishedAssess whether it includes security protection data; do not assume automatic exclusion.
Required service evidence is missing?YesKeep the proposed controlled-data path unapproved until the accountable review resolves it.
Unrestricted synthetic fixture only?YesUse it for a scoped test without presenting the result as CUI authorisation.

Work through your review

Use the checks to organise the evidence you need. Your selections stay in this tab.

0 of 3 reviewed

Example files for this task

Keep the source material and the instructions together. You can also download the complete worksheet or matrix as CSV.

cui-ai-service-scope-review.mdInspect
# CUI AI service-scope decision tree

Synthetic contract and data scenario. The fixture contains no CUI or export-controlled technical information. No provider approval or CMMC assessment result is represented.

A fictional contractor considers AI drafting and a security intermediary. The tree identifies the evidence required before any actual controlled-data use.

| Question | Finding | Next outcome |
| --- | --- | --- |
| Applicable contract and data category established? | No or unknown | Resolve with the contract/data owner before transmitting the proposed controlled information. |
| Information is CUI or covered defense information in scope? | Yes in the fictional scenario | Identify every storing, processing and transmitting service. |
| Information falls outside that category? | Established no for the assessed material | Review other confidentiality/export obligations; no blanket tool approval follows. |
| External provider is a cloud service handling covered information? | Yes | Obtain evidence for the applicable DFARS cloud requirements and incident obligations. |
| Level 2 ESP processes CUI or security protection data? | Yes | Apply the relevant 170.19(c) provider category and document SSP/service/CRM responsibilities. |
| A security intermediary handles only selected event data? | Data category not established | Assess whether it includes security protection data; do not assume automatic exclusion. |
| Required service evidence is missing? | Yes | Keep the proposed controlled-data path unapproved until the accountable review resolves it. |
| Unrestricted synthetic fixture only? | Yes | Use it for a scoped test without presenting the result as CUI authorisation. |

## Review steps

- Establish the contractual data scope: Record the originator, applicable clauses, information category and permitted recipients.
- Review each provider boundary: Distinguish cloud/non-cloud, CUI/security protection data and the actual service evidence.
- Keep the assessment handoff: Connect the data-flow map, system security plan and customer responsibility matrix to the accountable decision.

## Unrestricted synthetic fixture

This is a teaching note about an invented office bracket. It contains no controlled design, dimensions, materials or defence use. Rewrite a generic maintenance reminder without adding technical information.

## Fictional review record

Contract reference: CONTRACT-EX-28.
Controlled-data assumption: a separate proposed record is assumed CUI for the exercise; it is not included in this pack.
Recipients: proposed AI service and proposed security intermediary.
Provider evidence: to be obtained for the actual services before real-data use.
Control test: not run.
Authorisation to use CUI: none represented.

Record actual evidence rather than replacing missing provider requirements with a test result.

## Source and scope

Guide: https://aona.ai/resources/guides/cui-ai-assistants-cmmc/

Source check: 21 September 2026. General information, not professional approval or a completed control test.

- DFARS 252.204-7012: Safeguarding covered defense information: https://www.acquisition.gov/dfars/252.204-7012-safeguarding-covered-defense-information-and-cyber-incident-reporting.
- 32 CFR 170.19: CMMC scoping: https://www.law.cornell.edu/cfr/text/32/170.19
Download cui-ai-service-scope-review.md
cui-ai-service-scope-review.csvInspect
Question,Finding,Next outcome
Applicable contract and data category established?,No or unknown,Resolve with the contract/data owner before transmitting the proposed controlled information.
Information is CUI or covered defense information in scope?,Yes in the fictional scenario,"Identify every storing, processing and transmitting service."
Information falls outside that category?,Established no for the assessed material,Review other confidentiality/export obligations; no blanket tool approval follows.
External provider is a cloud service handling covered information?,Yes,Obtain evidence for the applicable DFARS cloud requirements and incident obligations.
Level 2 ESP processes CUI or security protection data?,Yes,Apply the relevant 170.19(c) provider category and document SSP/service/CRM responsibilities.
A security intermediary handles only selected event data?,Data category not established,Assess whether it includes security protection data; do not assume automatic exclusion.
Required service evidence is missing?,Yes,Keep the proposed controlled-data path unapproved until the accountable review resolves it.
Unrestricted synthetic fixture only?,Yes,Use it for a scoped test without presenting the result as CUI authorisation.
Download cui-ai-service-scope-review.csv
unrestricted-cui-review-fixture.txtInspect
UNRESTRICTED SYNTHETIC TEACHING INPUT, NOT CUI
Rewrite a generic office-maintenance reminder. No controlled design, dimensions, materials, customer information or defence application is supplied. Do not invent technical detail.
Download unrestricted-cui-review-fixture.txt

Before you proceed

Keep these distinctions clear

No retention is not no processing
The relevant obligations can apply to processing and transmission as well as storage.
Security services are not automatically outside scope
Assess the actual information and protection data they handle.

Apply it to employee AI use

Bring your actual data path.

Aona can be evaluated with unrestricted synthetic inputs for a supported employee AI path.

No Aona CMMC certification, FedRAMP status or suitability to receive CUI is asserted. Review its own handling and contractual role before controlled-data use.

Begin with the unrestricted fixture and obtain the required service evidence separately; do not test with real CUI based on this guide.

Review your use case

FAQ

Questions for this decision

Does a zero-retention setting make an AI service suitable for CUI?
Not by itself. Review the contract, information category, provider boundary and applicable safeguarding requirements. Processing and transmission matter too.
Does every external provider need identical CMMC treatment?
No. The cited Level 2 scoping provision distinguishes cloud/non-cloud providers and CUI/security protection data. Apply the actual contract and assessment scope.
Can a DLP service be outside the review because it provides security?
Do not assume that. Determine whether it handles CUI or security protection data and document the relevant provider and customer responsibilities.
Is CUI the same as ITAR technical data?
No. They concern different legal and contractual questions. The same material may need both analyses, but one label does not settle the other.

Evidence behind the guide

Sources and scope

Prepared by Aona. Sources checked 2026-09-21. The cited material supports the specific points below; it does not certify a product or your use case.

  1. DFARS 252.204-7012: Safeguarding covered defense information

    Covered-defense-information scope, applicable NIST requirements and external cloud-service FedRAMP Moderate-equivalent and incident obligations.

    law · checked 2026-09-21
  2. 32 CFR 170.19: CMMC scoping

    Assessment boundaries and the distinct treatment of cloud/non-cloud external providers processing CUI, security protection data or neither.

    law · checked 2026-09-21
Can CUI go into an AI assistant? | Aona