Welcome to the CMMC Knowledgebase. Search for CMMC, resources, tools, sources, sites, and platforms using the search box below.
We add more to the database weekly, check back often.
If you cannot find an answer then contact us or click the chat button on the lower right..
-
Artificial Intelligence (AI)
-
CMMC Fundamentals
-
CMMC Levels & Requirements
-
The 14 Control Families
- Access Control (AC)
- Awareness and Training (AT)
- Audit and Accountability (AU)
- Configuration Management (CM)
- Identification and Authentication (IA)
- CMMC Incident Response (IR)
- Maintenance (MA)
- Media Protection (MP)
- Personnel Security (PS)
- Physical Protection (PE)
- Risk Assessment (RA)
- Security Assessment (CA)
- System and Communications Protection (SC)
- System and Information Integrity (SI)
-
Implementation Roadmaps
-
Industry-Specific Guides
-
CMMC Documentation & Evidence
-
SPRS & Self-Assessment
-
CMMC Costs & Budgeting
-
Technology & Tools
-
CMMC Training & Awareness
-
Policies & Procedures
- How to Submit Your SPRS Score: PIEE Step-by-Step Guide [2026 Update]
- CMMC Policies and Procedures: What Documentation You Need
- How to Write a System Security Plan: The Owner's Guide to the One Document That Gates Everything
- Creating a Plan of Action and Milestones for CMMC
- Documenting Evidence for CMMC Assessment
-
Supply Chain & Third-Party Risk
-
Incident Response & Breach Reporting
-
Common Mistakes & Failures
-
Advanced Topics & Level 2
-
Updates & Regulatory Changes
Can You Use AI and CUI?
Updated: April 2026 | Reading time: 12 min | Category: Artificial Intelligence (AI)
You’ve probably heard a lot about Artificial Intelligence (AI) lately. Your staff may already be using tools like ChatGPT to write emails, summarize documents, or look up information. Maybe you’ve even tried it yourself. AI really is impressive — and it can save your company a lot of time and money. But if you’re a defense contractor who works with the Department of Defense (DoD), there is something critically important you need to understand before anyone in your company uses an AI tool for work purposes. Get this wrong, and you could lose your contracts, face significant financial penalties, or worse.
What Is Controlled Unclassified Information (CUI)?
First, let’s make sure we’re on the same page about what Controlled Unclassified Information — or CUI — actually is. You’ve likely dealt with classified information throughout your military career. CUI is not classified, but it is sensitive. Think of it as the middle ground between a fully public document and a top-secret file.
The federal government created the CUI program to standardize how sensitive-but-unclassified information is handled across all agencies and the companies that do business with them. If your company works on Department of Defense contracts, you almost certainly have CUI in your business somewhere.
Common examples of CUI in a defense contracting business:
- Contract specifications and technical drawings for defense systems
- Personnel records and background check information
- Export-controlled technical data (regulated under ITAR — International Traffic in Arms Regulations)
- Vendor and subcontractor information tied to defense programs
- Pricing data on sensitive proposals
- System security documentation
- Procurement-sensitive information from your government customer
If any of this information lives in your email, your file server, your cloud storage, or your employees’ laptops — then your company handles CUI. And that means federal law requires you to protect it in very specific ways.
What Are AI Tools, Exactly?
Artificial Intelligence (AI) tools are software programs that can understand language, generate text, analyze documents, answer questions, and assist with a wide variety of work tasks. The most well-known ones right now are ChatGPT (made by OpenAI), Microsoft Copilot (built into Microsoft 365 apps like Word, Outlook, and Teams), Google Gemini (Google’s AI assistant), and Claude (made by Anthropic). These are extraordinary tools that can genuinely help your business. The problem isn’t the tools themselves — it’s where your data goes when you use them, and whether that environment is approved to handle CUI.
Can You Use AI Tools with CUI? The Short Answer
The bottom line — and it’s important:
You cannot input Controlled Unclassified Information (CUI) into most commercial AI tools, including the standard versions of ChatGPT, Microsoft Copilot, Google Gemini, or Claude. Doing so is a violation of your federal contract obligations and potentially federal law — regardless of how convenient it seems or how trusted the company is that made the tool.
That said, this doesn’t mean you can’t use AI at all. There are approved, secure AI environments that defense contractors can use — and we’ll walk you through those options. But the free or standard commercial versions of these tools? They are off the table for any work that touches CUI.
Why Most Popular AI Tools Are Off-Limits for CUI
Let’s walk through this in plain terms so it makes sense.
Your data leaves your control when you use commercial AI
When one of your employees types something into ChatGPT or Copilot, that information travels over the internet to a commercial server — a computer that OpenAI, Microsoft, or Google controls. That server is not a government-approved environment. Your CUI is now outside the secure boundary your contract requires you to maintain.
Think of it this way: if a sensitive contract document was accidentally sent to a company in another city with no security clearances, no approved facility, and no government oversight — that would be a serious problem. That’s essentially what happens when CUI enters a commercial AI tool.
Federal regulations require government-approved cloud environments for CUI
Federal law — specifically a regulation called 32 CFR Part 170 (part of the Cybersecurity Maturity Model Certification, or CMMC, rule) and a Department of Defense contract clause called DFARS 252.204-7012 — requires that any cloud service handling CUI must meet a federal security standard called FedRAMP Moderate authorization. FedRAMP stands for the Federal Risk and Authorization Management Program. It’s the government’s stamp of approval that a cloud service is secure enough to handle sensitive federal information.
Standard ChatGPT? Not FedRAMP authorized. Standard Copilot in a regular Microsoft 365 account? Not approved for CUI. Standard Gmail with Gemini? Not approved for CUI.
AI tools may use your data to train their systems
Many commercial AI tools, by default, use the data you submit to improve their own systems. That means the sensitive technical details your employee typed into ChatGPT could, in theory, end up shaping what that AI tells someone else in the future. This is not a scenario any defense contractor can afford.
A fresh government warning just issued in 2026:
In March 2026, the Information Security Oversight Office (ISOO) — a federal agency that oversees information security programs — issued its first-ever formal notice on this topic: ISOO Notice 2026-01. It provides official guidance on the responsible use of AI tools with CUI and classified information. The government is paying very close attention to this right now.
What Happens If You Get This Wrong?
This is where things get very serious. If an employee submits CUI to an unauthorized AI tool — even by accident, even with good intentions — your company could face:
- Termination of your existing Department of Defense contracts
- Disqualification from winning future government contracts
- Financial penalties under your DFARS contract clauses
- A mandatory breach notification report to the Department of Defense within 72 hours of discovery
- False Claims Act liability — if you certified compliance and were not actually compliant, that carries federal civil or criminal exposure
- Reputational damage with your prime contractors and government customers
The Department of Defense has made it clear that CMMC enforcement is no longer theoretical. Contracts are now being awarded with CMMC requirements attached, and auditors — called Certified Third-Party Assessment Organizations (C3PAOs) — are actively assessing contractors. They will ask about your AI tool usage. You need the right answer ready.
What You Can Safely Use AI for Right Now
Here’s the good news. You don’t have to ban AI from your company. There is plenty your team can do with AI tools today — as long as CUI never enters the equation. Think of it as two separate lanes: one for public or internal business information, and one for controlled information.
These AI uses are safe and carry zero compliance risk:
- Researching publicly available information — industry news, competitor analysis, market trends
- Drafting general business content — blog posts, social media, internal newsletters (with no CUI included)
- Employee training materials — as long as the content is sanitized and contains no CUI
- Scheduling, expense reporting, general HR workflows
- Proposal research using only public sources and non-CUI company background
- Summarizing publicly available government solicitations before your sensitive response is developed
The rule of thumb is simple: if the information you’re working with would be perfectly fine to post on your company’s public website, you can generally use a standard AI tool with it. If it wouldn’t be okay to post publicly, keep it out of any AI tool that isn’t explicitly approved for CUI.
The Right Way to Use AI with CUI
Here’s where it gets exciting — because the answer isn’t “never use AI for defense work.” The answer is “use AI in the right environment.” And that environment exists today.
Option 1: Microsoft 365 GCC High with Copilot
GCC High stands for Government Community Cloud High. It’s a special version of Microsoft 365 — the same products you may already use, like Outlook, Word, and Teams — built specifically for defense contractors handling CUI. Microsoft Copilot, their AI assistant, is available inside GCC High and operates entirely within your approved, government-compliant environment. Your data never leaves that boundary. This is the most mature compliant AI option available to defense contractors in 2026.
Option 2: Air-Gapped or On-Premises AI Solutions
For companies that handle the most sensitive types of CUI — or those who want the cleanest compliance path — there are AI solutions that run entirely on computers inside your own building, with no connection to the internet whatsoever. “Air-gapped” means there is no path for data to leave your facility. These solutions eliminate the cloud compliance concern entirely and are approved for use in Sensitive Compartmented Information Facilities (SCIFs) and other secure environments.
Option 3: FedRAMP-Authorized AI Platforms
A growing number of AI platforms built specifically for government contractors operate inside government cloud environments like Amazon Web Services (AWS) GovCloud or Azure Government. These platforms are designed from the ground up for contractors who need to use AI on sensitive work. They enforce strict data handling policies — your information is encrypted, never used for AI training, and kept within compliant boundaries.
Your five-step action plan
- Identify your CUI boundary — Map out exactly which systems, devices, and cloud tools your CUI currently touches.
- Audit your current AI tool usage — Find out what tools your employees are already using. You may have a shadow AI problem you don’t know about yet.
- Choose your compliant AI path — Based on your contract type, data sensitivity, and existing environment, select the right approved AI solution.
- Train your team — Your employees need to understand the rules clearly. One well-intentioned mistake can trigger a mandatory breach report.
- Document everything — Your CMMC assessor will expect to see evidence that your AI tool policies are written, trained, and enforced.
How a Compliance Partner Can Help
We’ll be straightforward with you: this is not a do-it-yourself project. The regulatory landscape around AI and CUI is moving fast — and the consequences of getting it wrong are severe. Most defense contractors running small-to-mid-size companies simply don’t have the in-house expertise to navigate CMMC compliance, select the right AI platform, configure a secure environment, write the policies, and train the staff — all while running a business.
A qualified CMMC compliance firm that specializes in the Defense Industrial Base (DIB) can assess where you stand today, identify any compliance gaps with your current AI tool usage, help you select and configure the right secure AI environment, and make sure you’re ready when a C3PAO assessor walks through your door. This is exactly the kind of work that separates contractors who keep winning DoD contracts from those who get left behind.
The contractors who will win in 2026 and beyond are not the ones who avoid AI — they’re the ones who adopt it responsibly, inside the right frameworks, with the right partner guiding them.
Frequently Asked Questions
My employees already use ChatGPT for work. Are we in trouble?
Potentially, yes — depending on what information they’ve been entering into it. If CUI has been submitted to an unauthorized AI tool, that may constitute a reportable cyber incident under your DFARS contract clause. The right move is to audit what has been used, stop any non-compliant usage immediately, and consult with a CMMC compliance advisor about next steps. Acting quickly and transparently is always better than hoping nothing gets noticed.
What if I only use AI for non-sensitive work tasks?
That is perfectly acceptable and encouraged. Using AI tools for publicly available research, general business writing, scheduling, and training materials that contain no CUI carries zero compliance risk. The key is maintaining a clear, enforced policy so employees know exactly where the line is — and never cross it accidentally.
Is Microsoft Copilot in my regular Microsoft 365 account safe for CUI?
No. Standard Microsoft 365 — sometimes called the commercial version — is not approved for Controlled Unclassified Information (CUI). This includes Copilot running inside it. You need the GCC High version of Microsoft 365, which is a separate environment built specifically for defense contractors. Your data in GCC High stays within a government-compliant boundary that standard Microsoft 365 cannot provide.
We’re a small company with only a few employees. Do these rules still apply to us?
Yes, absolutely. The CMMC requirements and DFARS contract obligations apply to every company in the Department of Defense supply chain — prime contractors and subcontractors alike, regardless of company size. In fact, smaller companies are often at higher risk because they have fewer resources dedicated to compliance and may not have a formal IT or security team reviewing these issues.
What is CMMC, and how does it relate to AI?
The Cybersecurity Maturity Model Certification (CMMC) is the Department of Defense’s framework for verifying that defense contractors properly protect sensitive government information. It requires contractors to implement 110 security controls based on the National Institute of Standards and Technology (NIST) Special Publication 800-171. While CMMC doesn’t mention AI by name, any AI tool your company uses to process, store, or transmit CUI automatically falls under CMMC’s requirements — and must meet the same security standards as any other system in your environment.
How much does it cost to set up a compliant AI environment?
The cost varies depending on the solution and your company’s existing IT environment. Microsoft 365 GCC High licensing is comparable in cost to standard Microsoft 365 plans. The bigger investment is typically in the proper configuration, policy development, and staff training — all of which are essential for true compliance. A CMMC compliance partner can help you scope the work and identify the most cost-effective path for your situation.
When do CMMC assessors start looking at AI tool usage specifically?
Now. CMMC Level 2 assessments are already underway, and assessors evaluate the full scope of systems that touch CUI — which includes AI tools. The FY2026 National Defense Authorization Act (NDAA) — the annual law that defines defense spending and policy — also directed the Department of Defense to develop a specific AI security framework to be incorporated into CMMC. That process is underway, with a Congressional update due by June 2026. Waiting to address this is a risk your business cannot afford.
Ready to Use AI Without the Risk? Let’s Talk.
GreypikeAI is a fully managed, FedRAMP-compliant AI environment built specifically for defense contractors. We set up and manage a secure AI workspace inside a government-approved cloud — so your team gets the productivity benefits of modern AI tools while your CUI stays completely protected and your CMMC compliance stays intact.
We are a veteran-owned firm that works exclusively with Defense Industrial Base (DIB) contractors. We understand your contracts, your culture, and what is at stake for your business.
Get a free AI compliance assessment today. We will review your current AI tool usage, identify any compliance gaps, and walk you through your options — no obligation, no jargon.
📞 (706) 254-9046 | 📧 [email protected] | Request Your Free Assessment →