Plain Answers · Defense Contracting
Can you use AI tools and stay CMMC compliant?
It depends on what the tool touches.
It depends on whether the tool ever touches Controlled Unclassified Information. No AI product is "CMMC compliant" by itself — what gets assessed is your environment, not a vendor's brochure — so the first job is scoping: deciding, on purpose, whether an AI tool sits inside or outside the environment that handles CUI. Most of the trouble comes from never making that decision, and an engineer pasting a drawing note into a chatbot to clean up the wording.
Rules that may apply to you
Depending on what you do and who you serve, you may be subject to rules such as the ones below. We link the official sources and leave the interpretation to your compliance lead, your assessor, or your contracts counsel. This is a starting point, not a complete list, and nothing on this page says what these rules require of you.
- DFARS subpart 204.75, Cybersecurity Maturity Model Certification(opens in new tab)
- DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting(opens in new tab)
- 32 CFR part 170, Cybersecurity Maturity Model Certification (CMMC) Program — 2025 CFR edition(opens in new tab)
- NIST SP 800-171 Rev. 3, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations(opens in new tab)
- NIST SP 800-171 Rev. 2(opens in new tab)
- National Archives — About Controlled Unclassified Information (CUI)(opens in new tab)
Why scope is the whole question
Contractors that handle Federal Contract Information or Controlled Unclassified Information may be subject to the DFARS cybersecurity clauses and the CMMC program rule, both linked above, along with the National Archives' description of what CUI is.
The phrase we keep in mind when reading them is "process, store, or transmit." A prompt is a transmission. A chat history is storage. A model reading a pasted spec is processing. If CUI goes into an AI tool, it's hard to see how that tool stays outside the boundary your assessor will look at — but that's their call, not ours.
If the AI is a cloud service
If an AI tool that touches CUI is a cloud service, you may be subject to additional conditions on which cloud providers you can use. The DFARS safeguarding clause and the CMMC rule both address external cloud providers, and both refer to FedRAMP. We won't summarize the conditions here. Read them with your compliance lead.
One thing we can say from the vendor side: authorizations attach to specific offerings, not to company names. A vendor's government offering and its ordinary business plan are different products with different paperwork. We won't characterize any vendor's status here, because it changes. Check the FedRAMP Marketplace for the exact offering, and get the vendor to confirm in writing which one your agreement covers.
The baseline you're being measured against
Your assessment may be measured against NIST SP 800-171. One wrinkle worth knowing: NIST's site lists more than one revision, and we've linked two of them above. Which revision governs your assessment is a question for your assessor or contracting officer. Don't take it from a blog post, including this one.
What to ask an AI vendor
- Which exact offering would we be on, and what authorization does that offering hold today?
- Will you give us a customer responsibility matrix showing which requirements you meet and which stay with us?
- Where are prompts, files, and logs stored, and who can access them? Including your support staff, and from which countries.
- Is anything we submit used to train or improve models?
- How do you support incident reporting and forensic preservation? Ask what they'd hand you, and how fast, if you had to report an incident.
- What flows down to your own subcontractors?
The option small contractors overlook: keep it out, or keep it in
There are two clean designs, and one messy one. The clean ones:
- Keep AI entirely out of scope. Staff use a commercial AI tool for proposals, marketing, and general questions, under a written rule that no CUI goes in — enforced with training and, ideally, technical controls. Cheap and sensible, if the rule holds.
- Put AI fully inside the boundary. A model on a server you own, in your enclave, with no route to the internet. There's no external cloud provider to qualify, because there isn't one.
The messy design is the default one: a consumer tool everyone uses for everything, with nothing written down. That's the one to retire.
What we check when we deploy inside a boundary
- No outbound path, provably. Firewall rules, then the unplug test. Model files and updates arrive by controlled transfer, with hashes recorded.
- The server goes in your documentation. It's an asset in your inventory and your system security plan like any other. We supply the configuration details so your documentation matches reality.
- Individual accounts tied to your directory, with multi-factor authentication where your policy calls for it.
- Prompt and response logging to your own log system. If CUI goes in, the logs contain CUI, and they're handled that way.
- Our own role, stated plainly. If we'd be managing a system inside your boundary, we may count as an external service provider in your assessment's terms. Raise that with your assessor before the install, not after. We aren't a CMMC assessor, and nothing here substitutes for one.
On hardware: a single 24GB graphics card runs a capable model for a small engineering team, and entry servers run $1,500 to $7,500. The documentation and design work around a regulated deployment is what moves a project toward the higher end of our published ranges. Southern California has a deep base of small aerospace and defense suppliers, many carrying flow-down clauses from their primes — this is who we build for. For the general version of this question, see Is ChatGPT safe for business documents?