Answers · CMMC & AI compliance
What evidence does a C3PAO accept for AI usage?
For AI usage, C3PAO assessors accept the same categories of evidence they accept everywhere else: architecture, configuration, records, and policy. Concretely that means four artifacts — a data-flow diagram showing where AI-bound prompts are inspected relative to your boundary, the enforcement configuration (detection patterns and blocking policy), tamper-evident logs attributing allowed and blocked prompt events to individual users, and a written AI acceptable-use policy the technical control actually enforces. A control-mapped assessment report packages the first three into a single reviewable document.
The four artifacts, and what each must show
| Artifact | What the assessor checks | Controls it evidences |
|---|---|---|
| Data-flow diagram | AI traffic routes through an inspection point INSIDE your boundary — not a vendor cloud | 3.1.3, 3.13.1 (AC.2.003, SC.1.001) |
| Enforcement configuration | Active CUI/PII patterns and a blocking (not just alerting) policy | 3.1.3, 3.1.22 |
| Tamper-evident event log | Allowed AND blocked prompts, per-user attribution, integrity protection (e.g. hash chain) | 3.3.1, 3.3.2, 3.3.8 (AU.2.001/002/008) |
| Signed policy + training records | The written rule the control enforces, acknowledged by staff | 3.2.x, 3.6.1 |
What assessors reject
Screenshots of a vendor dashboard with no data-path diagram behind them; a written AI ban with no technical enforcement (the follow-up question is always 'and what stops it?'); logs that only show blocked events with no user attribution; and any architecture where prompt content leaves the boundary to be scanned — because then the scanning service itself becomes part of the assessment scope.
The packaged version
HoundShield's $499 CMMC AI Risk Assessment produces the packaged artifact: after 14 days running on your own infrastructure (self-hosted Docker), it generates a SHA-256-signed PDF risk-scoring every AI prompt event against NIST 800-171 Rev 2 controls — the architecture, configuration, and records evidence in one document you hand across the table. Pair it with the free control-mapped AI use policy template and the four-artifact set is complete.
Frequently asked questions
Use AI without leaking CUI
HoundShield scans every AI prompt locally and blocks CUI before it leaves your network. One URL change. Under 10 minutes. C3PAO-ready.