Skip to main content

Plain Answers · Defense Contracting

Can you use AI tools and stay CMMC compliant?
It depends on what the tool touches.

It depends on whether the tool ever touches Controlled Unclassified Information. No AI product is "CMMC compliant" by itself — what gets assessed is your environment, not a vendor's brochure — so the first job is scoping: deciding, on purpose, whether an AI tool sits inside or outside the environment that handles CUI. Most of the trouble comes from never making that decision, and an engineer pasting a drawing note into a chatbot to clean up the wording.

Rules that may apply to you

Depending on what you do and who you serve, you may be subject to rules such as the ones below. We link the official sources and leave the interpretation to your compliance lead, your assessor, or your contracts counsel. This is a starting point, not a complete list, and nothing on this page says what these rules require of you.

Why scope is the whole question

Contractors that handle Federal Contract Information or Controlled Unclassified Information may be subject to the DFARS cybersecurity clauses and the CMMC program rule, both linked above, along with the National Archives' description of what CUI is.

The phrase we keep in mind when reading them is "process, store, or transmit." A prompt is a transmission. A chat history is storage. A model reading a pasted spec is processing. If CUI goes into an AI tool, it's hard to see how that tool stays outside the boundary your assessor will look at — but that's their call, not ours.

If the AI is a cloud service

If an AI tool that touches CUI is a cloud service, you may be subject to additional conditions on which cloud providers you can use. The DFARS safeguarding clause and the CMMC rule both address external cloud providers, and both refer to FedRAMP. We won't summarize the conditions here. Read them with your compliance lead.

One thing we can say from the vendor side: authorizations attach to specific offerings, not to company names. A vendor's government offering and its ordinary business plan are different products with different paperwork. We won't characterize any vendor's status here, because it changes. Check the FedRAMP Marketplace for the exact offering, and get the vendor to confirm in writing which one your agreement covers.

The baseline you're being measured against

Your assessment may be measured against NIST SP 800-171. One wrinkle worth knowing: NIST's site lists more than one revision, and we've linked two of them above. Which revision governs your assessment is a question for your assessor or contracting officer. Don't take it from a blog post, including this one.

What to ask an AI vendor

  1. Which exact offering would we be on, and what authorization does that offering hold today?
  2. Will you give us a customer responsibility matrix showing which requirements you meet and which stay with us?
  3. Where are prompts, files, and logs stored, and who can access them? Including your support staff, and from which countries.
  4. Is anything we submit used to train or improve models?
  5. How do you support incident reporting and forensic preservation? Ask what they'd hand you, and how fast, if you had to report an incident.
  6. What flows down to your own subcontractors?

The option small contractors overlook: keep it out, or keep it in

There are two clean designs, and one messy one. The clean ones:

  • Keep AI entirely out of scope. Staff use a commercial AI tool for proposals, marketing, and general questions, under a written rule that no CUI goes in — enforced with training and, ideally, technical controls. Cheap and sensible, if the rule holds.
  • Put AI fully inside the boundary. A model on a server you own, in your enclave, with no route to the internet. There's no external cloud provider to qualify, because there isn't one.

The messy design is the default one: a consumer tool everyone uses for everything, with nothing written down. That's the one to retire.

What we check when we deploy inside a boundary

  • No outbound path, provably. Firewall rules, then the unplug test. Model files and updates arrive by controlled transfer, with hashes recorded.
  • The server goes in your documentation. It's an asset in your inventory and your system security plan like any other. We supply the configuration details so your documentation matches reality.
  • Individual accounts tied to your directory, with multi-factor authentication where your policy calls for it.
  • Prompt and response logging to your own log system. If CUI goes in, the logs contain CUI, and they're handled that way.
  • Our own role, stated plainly. If we'd be managing a system inside your boundary, we may count as an external service provider in your assessment's terms. Raise that with your assessor before the install, not after. We aren't a CMMC assessor, and nothing here substitutes for one.

On hardware: a single 24GB graphics card runs a capable model for a small engineering team, and entry servers run $1,500 to $7,500. The documentation and design work around a regulated deployment is what moves a project toward the higher end of our published ranges. Southern California has a deep base of small aerospace and defense suppliers, many carrying flow-down clauses from their primes — this is who we build for. For the general version of this question, see Is ChatGPT safe for business documents?

FAQ

Quick answers.

Can defense contractors use AI tools and stay CMMC compliant?
It depends on what the tool touches. An AI tool that touches Controlled Unclassified Information may fall inside the environment your CMMC assessment covers, and a cloud AI service in that role may be subject to the cloud-provider conditions in the DFARS and CMMC rules. A tool kept entirely away from CUI is a different conversation. Scope first, with your compliance lead, before anyone pastes anything.
Is ChatGPT FedRAMP authorized?
We will not answer for any vendor, because authorizations are granted to specific offerings and they change. Check the FedRAMP Marketplace for the exact product and tier you would use, and get the vendor to state in writing which offering your contract covers. A consumer or standard business plan is not the same offering as a government one.
Does an on-premises AI server solve the CMMC problem?
It removes the external cloud provider from the picture, which is the hardest part for most small contractors. It does not remove the work: the server may well sit inside your assessment scope, in which case it needs the same access control, logging, configuration management, and documentation as every other system that handles CUI.

Next: private AI for government contractors.

How in-house AI fits a contractor's environment — proposal support, technical document search, and compliance paperwork, on infrastructure you control.

AI for Government Contractors

© 2024–2026 Integral Business Intelligence. Archivist™, Interchange™, and Sentinels™ are trademarks of Integral Business Intelligence.

Website v3.2.0 design and development by Integral Business Intelligence with assistance from AI.