← Blog

AI Governance for Defense Contractors Starts With the CUI Boundary

Parminder Singh
Parminder Singh··7 min read
Summarize with AI

AI governance for defense contractors should decide which work may use a model before FCI or CUI enters a prompt. The operating program needs a use-case register, system-boundary decision, approved endpoint, originating identity, review owner, and assessment evidence. CMMC and NIST SP 800-171 already govern the systems that process, store, or transmit covered information; AI requests have to enter that same control record.

Industry Verticalsai-governanceai-compliancenistpolicy-enforcementidentity-and-authorization
AI Governance for Defense Contractors Starts With the CUI Boundary

A program engineer selects three paragraphs from a technical drawing note and asks an LLM to rewrite them for a supplier email. The selection may include Controlled Unclassified Information. When the application submits the prompt, an HTTPS request crosses the contractor's system boundary and reaches a model endpoint under a particular account and region. AI governance for defense contractors has to decide that request before transmission. The decision needs the originating person and contract context. It also needs the information category and authorized destination, with retained evidence. I would treat any model route missing one of those fields as outside approved program work.

TL;DR

  • Register AI use cases by contract and work package. Record FCI or CUI exposure and the system boundary. Add the model route and accountable owner.
  • Keep CMMC assessment scope tied to the real applications and external services that process or store covered information, or transmit it.
  • Bind each routed HTTP model request to the originating user or agent and enforce destination and data policy before transmission.
  • Assign IAM and endpoint controls to their owners. Keep contracts with their adjacent owner. Do the same for model review and assessment evidence instead of stretching one gateway across the whole program.

CMMC attaches to covered information and contractor systems

The CMMC Program rule in 32 CFR Part 170 establishes requirements for defense contractors and subcontractors safeguarding Federal Contract Information and CUI. Its scope includes contractor systems that handle covered information. Systems that protect CUI components or lack logical or physical isolation can also enter scope. CMMC assessments verify implementation of the prescribed safeguards.

An AI feature enters that scope through its actual data path. A proposal assistant that uses public material may sit outside the CUI environment. A tool that summarizes engineering change notes may process CUI, even when the model call lasts less than a second and stores no file locally. The endpoint and calling application matter to boundary analysis. The retrieval source and identity service matter too. The evidence store belongs in that analysis as well.

The existing CMMC AI compliance guide maps access control and audit duties onto model traffic. This article focuses on approving a use case and keeping its boundary and supplier records synchronized with its reviewer and evidence records.

The register should start with the contract and work package

An AI register identifies the contract or program and the applicable work package. It also records the information expected in each request. Add the business owner and system owner. Record the calling application and retrieval sources. Record the model endpoint and hosting boundary. Add downstream actions and human review, with the evidence location. A label such as enterprise chatbot gives an assessor little to test.

Separate public-source work from covered work. Within covered work, separate FCI work from CUI work. The distinction should drive the permitted endpoint and system boundary. A public proposal outline may use one route. A maintenance summary containing controlled technical information may require an approved environment and narrower identity group. Software-development assistants need repository scope and branch permissions recorded because retrieved code can become prompt context without appearing in the user's typed sentence.

The register also needs inherited providers. A prime may approve SaaS that sends prompts to another model service. Record that provider and the data it receives. The rule covers applicable contract and subcontract awardees, so flow-down handling belongs beside the prime's route inventory.

The assessment boundary has to match production routing

A polished boundary diagram loses value when production uses an endpoint absent from the drawing. Trace the request through its application and identity handoff. Continue through the policy point and model endpoint to the response destination. Mark every place where FCI or CUI is handled.

The NIST SP 800-171 Revision 2 publication, which Part 170 incorporates for relevant CMMC levels, limits system access to authorized users and processes acting on their behalf. Its Access Control family governs CUI flow under approved authorizations. System and Communications Protection covers external and important internal boundaries. Both meet at the outbound model request.

Place direct browser chat and customer-built assistants on the diagram. Add coding tools and embedded SaaS AI. Routed API calls can carry identity-aware enforcement. Direct websites need web and endpoint controls. Vendor-managed inference needs supplier evidence and application permissions.

Per-request authorization closes the relay-identity gap

Contractor applications often call a model using one service credential. The model provider sees that credential, while the application knows the individual engineer or agent that caused the call. Governance weakens when the identity disappears between those two points. A useful control passes the originating identity and contract context to the request policy point.

The decision can evaluate the caller's role and work package. It can also evaluate the CUI category and model route, then apply that result to the requested operation. A design assistant may allow public specifications and block controlled drawing content. An agent may summarize an approved document while a supplier export requires human review. The policy version and outcome enter the evidence.

IAM remains responsible for the account and authentication. It also owns group membership and service identity. The application owns trustworthy propagation of the originating principal and program context. The gateway evaluates what the application supplies. A shared engineering-ai-prod identity erases individual attribution and should trigger remediation upstream. Identity-aware AI gateway architecture covers the context handoff at that boundary.

Evidence has to survive a CMMC assessment sample

The NIST SP 800-171 Audit and Accountability family calls for records that support monitoring and analysis. Those records also support investigation and reporting of unauthorized activity. For AI, connect use-case approval to a real request and its disposition.

Keep the approved route and system-boundary record. Add a named user's access test and the prompt classification. Record the selected destination and effective policy. Include the resulting decision outcome in the same record. For allowed requests, retain the response-handling rule and reviewer result where the use case requires review. For blocked requests, record the reason and exception owner. Protect the record through custody outside the calling application's write path.

An assessor may also need the System Security Plan description and configured policy export. The endpoint inventory and supplier evidence may also be required. Keep the change history with them. NIST SP 800-171 AI controls mapping covers requirement-family enforcement. The governance file should connect those controls to the use case and boundary. My blunt preference is a six-record sample with complete lineage over a perfect dashboard score. It exposes broken identity and stale routing within minutes.

Model and workflow changes reopen approval

Model versions and connectors change the use case. Retrieval sources and agent permissions can change it too. Governance should define which events reopen review. A new endpoint changes transmission. A CUI repository connector expands accessible information. Write permission in PLM or source control changes the possible outcome. Ticketing write permission does too. A subprocessor changes the supplier path.

The change record should identify the requester and affected contracts. Record the revised data flow and tests. Add the security owner and approving official. Test a permitted case and a blocked CUI case under a named identity, then preserve both results with the policy revision. Program and engineering reviewers own model-quality testing where output influences technical or supplier work.

Local models deserve the same governance review. They may keep processing inside the contractor boundary, which changes external-transmission risk. Access authorization and source permissions remain relevant. Response handling and audit evidence do too. The hosting team owns model infrastructure and patching. Program leadership owns acceptable use and output review.

Adjacent controls keep separate owners

An HTTP request policy point covers traffic deliberately routed through it. Endpoint teams govern personal browser sessions and extensions. They also govern removable media and local assistants. IAM manages workforce and privileged access. Configuration controls protect the surrounding CUI environment. Supplier management handles cloud agreements and subcontractor flow-down. It also owns the evidence collected from each provider.

Program managers decide which information may support the use case. Export-control and legal specialists determine restrictions beyond CMMC together with contracting specialists. Engineering reviewers validate technical output before operational use. Incident response owns suspected-disclosure investigations. CMMC assessment teams connect evidence to the SSP and assessment objectives.

Draw those obligations beside the model route. The image should show a solid line through the authenticated application and policy point to the approved HTTP endpoint. Use separate boxes for direct consumer access and embedded vendor AI. Put local inference in its own box. This visual boundary prevents a request gateway from being described as a replacement for CMMC program management or engineering judgment.

DeepInspect

DeepInspect can provide the request-policy point for customer-controlled LLM routes. It sits inline as a stateless proxy between authenticated users or agents and HTTP-based model endpoints. The application supplies the originating identity and program context. DeepInspect evaluates prompt classification and destination. It also evaluates role and versioned policy before forwarding an allowed request.

Each routed decision creates a signed, tamper-evident record outside the calling application's write path. That record can support CMMC sampling for the request boundary. DeepInspect leaves identity issuance with IAM. It leaves browser and local execution with endpoint controls. System scope stays with the contractor's CMMC team, and supplier duties stay with procurement. Technical output acceptance remains with program reviewers. Book a technical deep dive at deepinspect.ai.

Frequently asked questions

Does every AI tool used by a defense contractor enter CMMC scope?

Scope follows the contract and information described in 32 CFR Part 170. It also follows the systems and isolation described there. An AI tool that processes or stores FCI or CUI, or transmits it, can affect the applicable contractor-system boundary. A public-information use case may sit elsewhere when the systems and data are properly separated. The contractor should document the data flow and validate the boundary with its CMMC and contracting advisers instead of assigning scope solely by product name.

Which NIST SP 800-171 revision applies to a CMMC assessment?

The CMMC Program rule incorporates NIST SP 800-171 Revision 2 for the relevant requirements. NIST published Revision 3 in May 2024, but a newer publication does not silently replace material incorporated into 32 CFR Part 170. Contractors should build to the contractual and CMMC baseline that applies to the assessment and track later NIST revisions. They should obtain program-specific advice before changing the stated control set.

Can CUI be sent to a commercial model endpoint?

The answer depends on the contract and approved authorization. It also depends on the system boundary and provider arrangement, together with the configured safeguards. Governance should begin with the exact data and destination. The contractor must show how the route satisfies applicable CUI protection requirements and any additional contractual limits. A consumer account or unrecorded endpoint lacks the boundary and evidence needed for that determination. Security and contracting owners should approve the route before CUI reaches it.

What should a contractor retain for an AI use-case review?

Retain the contract and work-package context with the FCI or CUI analysis. Keep the data-flow diagram and system-boundary decision. Keep the model and provider record with the identity design. Add the policy approval and supplier evidence. Include the reviewer assignment and change triggers. Add executed access and routing tests under named identities. Where output informs technical work, preserve the source and generated material selected for use. Preserve reviewer corrections and final disposition according to the program's records policy.

Can an AI gateway replace CMMC controls or the SSP?

A gateway implements a bounded set of controls on authenticated HTTP requests to model endpoints. It can enforce information-flow and destination policy. It can also bind decisions to identity and produce audit evidence. The SSP still describes the contractor environment and control implementation. Endpoint security and IAM retain their assigned owners. Configuration management and incident response retain theirs. Supplier oversight and physical controls retain theirs. Training, engineering review, and assessment administration also retain their assigned owners.