Compliance decisions
Can CUI go into an AI assistant?
Determine the contract and data scope before sending CUI to an AI service. DFARS cloud requirements and CMMC assessment boundaries concern the actual provider, service and information handled. A commercial privacy promise, zero-retention setting or security-tool installation does not establish permission or provider suitability.
For Defence contractors, CMMC programme owners and security architects
An AI provider and a security intermediary can create different assessment obligations.
Synthetic contract and data scenario. The fixture contains no CUI or export-controlled technical information. No provider approval or CMMC assessment result is represented.01
Start with the information and contract
Identify the originator, applicable contract and the actual information category. DFARS 252.204-7012 defines covered defense information in its contractual context and refers to relevant safeguarding requirements. Do not classify every internal engineering document as CUI, or assume a missing label proves the information is unrestricted.
Ask the programme and contract owners to establish the permitted use and recipients. This is separate from export-control analysis: a CUI safeguarding decision does not settle whether ITAR or another export regime applies to the same material.
Source context: DFARS 252.204-7012: Safeguarding covered defense information
02
Apply the external cloud-service requirement
Under the described DFARS clause, an external cloud provider used to store, process or transmit covered defense information in contract performance must meet the specified FedRAMP Moderate-equivalent security requirements and the relevant incident-reporting, preservation and related provisions.
Review evidence for the exact service and its boundary. A provider’s unrelated accreditation, a generic company statement or a claim that prompts are not retained does not establish the required arrangement. Processing or transmitting information can matter even when long-term storage is disabled.
Source context: DFARS 252.204-7012: Safeguarding covered defense information
03
Map the CMMC service boundary
For the Level 2 external-service-provider analysis in 32 CFR 170.19(c), the rule distinguishes cloud from non-cloud providers and whether they process CUI, security protection data or neither. Its table identifies different assessment treatment for those combinations.
The rule also requires relevant provider relationships and services to be documented in the system security plan and the provider’s service description/customer responsibility matrix. This guide does not establish a CMMC assessment outcome or claim every supplier needs the same certification. Use the actual contract, assessment type and data flow.
Source context: 32 CFR 170.19: CMMC scoping
04
Include security services in the data map
A guardrail or monitoring service can itself receive content or security protection data. Assess that intermediary’s role instead of assuming that security functionality places it outside the boundary. The provider that receives a raw prompt may have a different role from a service receiving only particular event metadata.
Record what leaves the device, which systems can read it and where each category is processed or stored. An installed policy tool does not make an otherwise unapproved CUI transfer acceptable. Confirm the handling and provider requirements before any controlled information enters the proposed path.
Source context: DFARS 252.204-7012: Safeguarding covered defense information · 32 CFR 170.19: CMMC scoping
05
Use explicit stop and next outcomes
The decision tree below keeps unknown contract, data and provider conditions open. A negative CUI finding can lead to a separate review of other information obligations; it is not a universal permission to use any tool. An unresolved provider requirement means the proposed controlled-data use must be resolved before proceeding.
Begin technical exploration with unrestricted synthetic material. Record the actual service evidence and accountable decision separately from a product test. No Aona CMMC certification, FedRAMP status or approval to receive CUI is asserted by this page.
Source context: DFARS 252.204-7012: Safeguarding covered defense information · 32 CFR 170.19: CMMC scoping
Put it into practice
CUI AI service-scope decision tree
A fictional contractor considers AI drafting and a security intermediary. The tree identifies the evidence required before any actual controlled-data use.
Synthetic contract and data scenario. The fixture contains no CUI or export-controlled technical information. No provider approval or CMMC assessment result is represented.
Origin
Contract and information category
AI service
Processing, storage and provider evidence
Security service
Content or security protection data handled
Decision
SSP/CRM responsibilities and accountable review
| Question | Finding | Next outcome |
|---|---|---|
| Applicable contract and data category established? | No or unknown | Resolve with the contract/data owner before transmitting the proposed controlled information. |
| Information is CUI or covered defense information in scope? | Yes in the fictional scenario | Identify every storing, processing and transmitting service. |
| Information falls outside that category? | Established no for the assessed material | Review other confidentiality/export obligations; no blanket tool approval follows. |
| External provider is a cloud service handling covered information? | Yes | Obtain evidence for the applicable DFARS cloud requirements and incident obligations. |
| Level 2 ESP processes CUI or security protection data? | Yes | Apply the relevant 170.19(c) provider category and document SSP/service/CRM responsibilities. |
| A security intermediary handles only selected event data? | Data category not established | Assess whether it includes security protection data; do not assume automatic exclusion. |
| Required service evidence is missing? | Yes | Keep the proposed controlled-data path unapproved until the accountable review resolves it. |
| Unrestricted synthetic fixture only? | Yes | Use it for a scoped test without presenting the result as CUI authorisation. |
Work through your review
Use the checks to organise the evidence you need. Your selections stay in this tab.
0 of 3 reviewed
Example files for this task
Keep the source material and the instructions together. You can also download the complete worksheet or matrix as CSV.
cui-ai-service-scope-review.mdInspect
# CUI AI service-scope decision tree
Synthetic contract and data scenario. The fixture contains no CUI or export-controlled technical information. No provider approval or CMMC assessment result is represented.
A fictional contractor considers AI drafting and a security intermediary. The tree identifies the evidence required before any actual controlled-data use.
| Question | Finding | Next outcome |
| --- | --- | --- |
| Applicable contract and data category established? | No or unknown | Resolve with the contract/data owner before transmitting the proposed controlled information. |
| Information is CUI or covered defense information in scope? | Yes in the fictional scenario | Identify every storing, processing and transmitting service. |
| Information falls outside that category? | Established no for the assessed material | Review other confidentiality/export obligations; no blanket tool approval follows. |
| External provider is a cloud service handling covered information? | Yes | Obtain evidence for the applicable DFARS cloud requirements and incident obligations. |
| Level 2 ESP processes CUI or security protection data? | Yes | Apply the relevant 170.19(c) provider category and document SSP/service/CRM responsibilities. |
| A security intermediary handles only selected event data? | Data category not established | Assess whether it includes security protection data; do not assume automatic exclusion. |
| Required service evidence is missing? | Yes | Keep the proposed controlled-data path unapproved until the accountable review resolves it. |
| Unrestricted synthetic fixture only? | Yes | Use it for a scoped test without presenting the result as CUI authorisation. |
## Review steps
- Establish the contractual data scope: Record the originator, applicable clauses, information category and permitted recipients.
- Review each provider boundary: Distinguish cloud/non-cloud, CUI/security protection data and the actual service evidence.
- Keep the assessment handoff: Connect the data-flow map, system security plan and customer responsibility matrix to the accountable decision.
## Unrestricted synthetic fixture
This is a teaching note about an invented office bracket. It contains no controlled design, dimensions, materials or defence use. Rewrite a generic maintenance reminder without adding technical information.
## Fictional review record
Contract reference: CONTRACT-EX-28.
Controlled-data assumption: a separate proposed record is assumed CUI for the exercise; it is not included in this pack.
Recipients: proposed AI service and proposed security intermediary.
Provider evidence: to be obtained for the actual services before real-data use.
Control test: not run.
Authorisation to use CUI: none represented.
Record actual evidence rather than replacing missing provider requirements with a test result.
## Source and scope
Guide: https://aona.ai/resources/guides/cui-ai-assistants-cmmc/
Source check: 21 September 2026. General information, not professional approval or a completed control test.
- DFARS 252.204-7012: Safeguarding covered defense information: https://www.acquisition.gov/dfars/252.204-7012-safeguarding-covered-defense-information-and-cyber-incident-reporting.
- 32 CFR 170.19: CMMC scoping: https://www.law.cornell.edu/cfr/text/32/170.19
Download cui-ai-service-scope-review.mdcui-ai-service-scope-review.csvInspect
Question,Finding,Next outcome
Applicable contract and data category established?,No or unknown,Resolve with the contract/data owner before transmitting the proposed controlled information.
Information is CUI or covered defense information in scope?,Yes in the fictional scenario,"Identify every storing, processing and transmitting service."
Information falls outside that category?,Established no for the assessed material,Review other confidentiality/export obligations; no blanket tool approval follows.
External provider is a cloud service handling covered information?,Yes,Obtain evidence for the applicable DFARS cloud requirements and incident obligations.
Level 2 ESP processes CUI or security protection data?,Yes,Apply the relevant 170.19(c) provider category and document SSP/service/CRM responsibilities.
A security intermediary handles only selected event data?,Data category not established,Assess whether it includes security protection data; do not assume automatic exclusion.
Required service evidence is missing?,Yes,Keep the proposed controlled-data path unapproved until the accountable review resolves it.
Unrestricted synthetic fixture only?,Yes,Use it for a scoped test without presenting the result as CUI authorisation.
Download cui-ai-service-scope-review.csvunrestricted-cui-review-fixture.txtInspect
UNRESTRICTED SYNTHETIC TEACHING INPUT, NOT CUI
Rewrite a generic office-maintenance reminder. No controlled design, dimensions, materials, customer information or defence application is supplied. Do not invent technical detail.
Download unrestricted-cui-review-fixture.txtBefore you proceed
Keep these distinctions clear
- No retention is not no processing
- The relevant obligations can apply to processing and transmission as well as storage.
- Security services are not automatically outside scope
- Assess the actual information and protection data they handle.
Apply it to employee AI use
Bring your actual data path.
Aona can be evaluated with unrestricted synthetic inputs for a supported employee AI path.
No Aona CMMC certification, FedRAMP status or suitability to receive CUI is asserted. Review its own handling and contractual role before controlled-data use.
Begin with the unrestricted fixture and obtain the required service evidence separately; do not test with real CUI based on this guide.
Review your use caseFAQ
Questions for this decision
Does a zero-retention setting make an AI service suitable for CUI?
Does every external provider need identical CMMC treatment?
Can a DLP service be outside the review because it provides security?
Is CUI the same as ITAR technical data?
Evidence behind the guide
Sources and scope
Prepared by Aona. Sources checked 2026-09-21. The cited material supports the specific points below; it does not certify a product or your use case.
- DFARS 252.204-7012: Safeguarding covered defense information
Covered-defense-information scope, applicable NIST requirements and external cloud-service FedRAMP Moderate-equivalent and incident obligations.
law · checked 2026-09-21 - 32 CFR 170.19: CMMC scoping
Assessment boundaries and the distinct treatment of cloud/non-cloud external providers processing CUI, security protection data or neither.
law · checked 2026-09-21