CMMC Has No AI Clause. It Does Not Need One.


Somewhere in your company this week, an employee pasted a few paragraphs of contract material into an AI tool nobody approved, on an account nobody can see, and got back a cleaner draft in eight seconds. Nothing broke, nobody noticed, and the work shipped early. If you hold defense contracts, that invisible eight seconds is now the most important security event in your month, and no framework had to mention AI by name to make it one.
This is the fifth piece in our series on what AI actually means for regulated industries. For healthcare, financial firms, law firms, and accountants, the pattern has been the same every time: the AI arrived through employees, not through procurement, and the rules that govern it were on the books before the tools existed. Government contractors are no exception. They are the sharpest case of it.
The AI is already inside the fence
Start with what is actually happening on the machines, because every policy conversation that skips this step is fiction.
An engineer at a fifty-person subcontractor is late on a deliverable, so she pastes three paragraphs of a technical spec into the chatbot she uses at home to tighten the language. A proposal manager drops a performance work statement into an AI tool to pull out the requirements. A new hire installs a browser extension that summarizes every page he reads, and some of those pages sit in the company's contract portal. None of them thinks of any of this as a security decision.
The numbers say your company is not the exception. Verizon's 2026 data breach report found the share of employees regularly using AI tools at work tripled in a year to 45 percent, and 67 percent of the people using AI services on corporate devices were signed in with non-corporate accounts, outside any control the company has.
IBM's 2026 breach study found shadow AI involved in 43 percent of the security incidents it examined, up from 20 percent the year before. Those are cross-industry figures, not defense-specific ones. But nothing about holding a DoD contract makes your staff immune to a tool that saves them an hour, and everything about holding one raises the price of the paste.
Because in your industry, that pasted text has a legal name.
Nobody needs to write an AI rule for you. They already did.
If the text that leaves your boundary is Controlled Unclassified Information, the rulebook that covers it has been in your contracts for years, and it covers AI without ever saying the word.
DFARS 252.204-7012 requires you to safeguard covered defense information on your systems, the ones described in your System Security Plan. Your SSP draws a boundary around where CUI lives and how each system inside it is protected. A personal chatbot account is not inside that boundary. NIST SP 800-171, the standard behind your SPRS score and your CMMC level, addresses the exact move in control 3.1.20: verify and control or limit connections to and use of external systems. An AI tool nobody approved is an external system with a paste-friendly text box. The moment CUI goes into it, controlled information is sitting on infrastructure you do not manage, under an account you cannot open, close, or audit.
This is not our creative reading. In March, the Information Security Oversight Office, the federal body that oversees the whole CUI program, issued a notice addressing AI directly: for federal agencies, putting CUI into any AI system that is internet-enabled, that runs on infrastructure outside the organization's control, or that does not meet CUI protection standards is prohibited. That notice binds agencies, not contractors, but it states plainly what the protection standard means once the tool is AI, and your obligations trace back to the same CUI framework through the DFARS clause.
And watch what the government did for its own people, because it is the clearest tell of all. In December the Defense Department rolled out GenAI.mil, its own generative AI platform certified for CUI at Impact Level 5. It built a walled version at real expense for a simple reason: the consumer versions of these tools are not an approved place for controlled information, and the department knew its people would use AI somewhere.
Your employees are under the same pressure with none of the walls.
A note on CMMC timing, because the news confused it
You may have seen that the Pentagon suspended CMMC Phase 2 in July, pausing the third-party assessments that were due to start appearing in contracts this November while a reform task force rethinks the program. Some contractors read that as the pressure coming off. Read it carefully instead: the assessments paused, the obligations did not. DFARS 7012 is still in your contracts, all 110 controls of NIST 800-171 are still the standard, your SPRS score is still required, and under the program's first phase, which is still running, a named official at your company still signs an annual affirmation that you comply. The examiner stepped out of the room and your signature stayed on the table. We covered the original timeline back in June; the deadline in that piece is the thing now on hold.
The honest part
In every other industry in this series, the honest caveat was that regulators had written rules but not yet made an example of anyone over AI specifically. Government contracting is where that caveat dies. Since 2021, the Justice Department's Civil Cyber-Fraud Initiative has been settling False Claims Act cases over allegations that contractors' cybersecurity attestations did not match their reality. MORSECORP paid 4.6 million dollars to resolve allegations that included posting a self-assessment score of 104 for an environment a third-party review later scored at minus 142. Raytheon and Nightwing paid 8.4 million dollars over allegations that a system used for unclassified DoD contract work ran for years without a compliant security plan.
Georgia Tech's research arm paid 875,000 dollars over allegations that included submitting a score for a virtual campus-wide environment that did not match any real system. All three are settlements of allegations, not court findings, and notice what none of the cases involved: a breach. Nobody had to hack anyone. The alleged gap between the attestation and the reality was the whole case, and the MORSE suit was brought by a whistleblower who collected 851,000 dollars for reporting it. If CUI is sitting in personal AI accounts your company cannot even list, that same gap is open, and the False Claims Act pays the people best positioned to see it, the ones already in your office, to report it.
Visibility is the control that comes first
Here is the thread that ties all of it together. You cannot follow 3.1.20 for systems you have not identified. You cannot keep CUI inside a boundary you cannot compare against reality. You cannot write a truthful SSP, a truthful score, or a truthful affirmation about tools you have not found. Every obligation above quietly assumes one capability underneath it: knowing what AI is actually in use on your machines and which accounts it is signed into.
So the first move is not a policy memo. It is an inventory. Find every AI tool, browser extension, and AI agent running on machines that touch CUI or share a network with machines that do, and note whether each one is on a company account or a personal one, because those are different worlds legally. Then hold that list against your SSP boundary: whatever touches contract work and is not inside it either comes out of the workflow or comes into the boundary properly. Then give people one rule that removes the judgment call, the same way good phishing policy does: no contract information goes into any AI tool that is not on the approved list, and rewriting or summarizing counts as going in. And give them an approved path, because a ban with no alternative just teaches people to hide the workflow that saves them an hour.
Do that, and CMMC's eventual return to assessments becomes a calendar item instead of a crisis.
Where we fit, and where we do not
We are not a C3PAO. We do not run certification assessments, and nothing we do makes you CMMC certified. What we run is the visibility layer everything above depends on.
Our Managed AI Security service starts with a free AI Discovery: a light install, about a week of quiet observation, then a report of every AI tool, extension, and agent in use across your machines, including which are running on personal accounts, risk ranked in plain English. Nothing changes for your staff while it runs, and the report is yours whatever you do next. It is the inventory step above, done for you. From there we enforce the tool list you approve and keep watching as new AI shows up, because it shows up monthly. Alongside it we run the managed email security, endpoint detection, and security awareness training that several of the 110 controls assume somebody is operating day to day. It supports the requirements you attest to. It does not guarantee compliance, and no honest vendor would tell you otherwise.
The question worth asking this week
Not "does CMMC say anything about AI." It does not have to. Ask instead: if you had to list, right now, every AI tool your contract data has touched this month, could anyone in your company produce that list?
If you are a defense contractor or subcontractor in Washington DC, Northern Virginia, or Maryland and you want that list to exist by next month, book a free 15-minute call. The discovery that produces it is free, and the answer is yours either way.
Comments