Answers · CMMC & AI compliance

DFARS 7012 and AI tools: what's allowed?

Under DFARS 252.204-7012, Controlled Unclassified Information (CUI) cannot be sent to an AI tool that is not part of your authorized system — and that includes the cloud DLP tools meant to “protect” it. The only compliant way to use AI on systems that touch CUI is to scan and block prompts locally, on your own hardware, before they leave the network.

What DFARS 7012 actually requires

DFARS 252.204-7012 obligates contractors to (1) provide “adequate security” for covered defense information by implementing NIST SP 800-171, and (2) report cyber incidents — including CUI spills — within 72 hours. Any path that lets CUI reach an unauthorized system is a compliance failure.

Where AI tools break it

AI data pathDFARS 7012 statusWhy
Employee pastes CUI into ChatGPT / CopilotSpillCUI reaches OpenAI / Microsoft, outside your covered system
Cloud AI DLP (Nightfall, Strac)SpillThe tool transmits your CUI to its cloud to scan it
Microsoft PurviewPartialM365-only; no proxy for ChatGPT / Claude / Cursor traffic
Local-only AI firewall (HoundShield)CompliantCUI is scanned on your hardware and never leaves

The local-only rule

The defensible architecture is simple: the scan must happen before the data leaves, on a system you control. That means an on-prem or in-network proxy that inspects every AI prompt locally, blocks CUI, and logs the decision — with nothing transmitted to a vendor.

This is also the cheapest path to evidence: a local firewall maps directly to NIST 800-171 controls 3.1 (Access Control), 3.13 (System & Communications Protection), and 3.14 (System & Information Integrity), and can export a C3PAO-ready audit trail.

FAQ

Frequently asked questions

Use AI without leaking CUI

HoundShield scans every AI prompt locally and blocks CUI before it leaves your network. One URL change. Under 10 minutes. C3PAO-ready.