Answers · CMMC & AI compliance
What happens if you paste CUI into ChatGPT?
Pasting CUI into ChatGPT transmits it to OpenAI's servers — systems not authorized to hold Controlled Unclassified Information. For a defense contractor, that is a potential cyber incident under DFARS 252.204-7012, which requires rapid reporting to DoD through DIBNet within 72 hours of discovery, evidence preservation for at least 90 days, and notification up your contract chain. Deleting the chat afterward does not un-disclose the data. The right response is a scoped incident process now and a technical control that prevents the next one.
The immediate consequences, in order
- The data has left your covered system: OpenAI's infrastructure received the content, and depending on account settings it may be retained.
- The 72-hour clock may be running: if the content was CUI, DFARS 252.204-7012 directs a rapid report through DoD's DIBNet portal — which requires a medium-assurance certificate most contractors don't have on hand.
- Evidence must be preserved: 7012 requires preserving images of affected systems and monitoring data for at least 90 days from the report.
- Your prime may need to know: flowdown clauses commonly require notifying the prime contractor or contracting officer.
What deleting the conversation does and doesn't do
Submitting a deletion request and turning off chat history are sensible mitigation steps — document both. But they are mitigation, not remedy: the disclosure already happened, and your reporting obligations are triggered by the incident, not by whether the vendor still holds the data.
Preventing the next one
The corrective action assessors respect is technical: route all AI traffic through a proxy on your own infrastructure that scans prompts locally and blocks CUI patterns before transmission, writing every event to a tamper-evident log. That converts this incident's corrective action into standing evidence for flow control (3.1.3), boundary protection (3.13.1), and audit (3.3.1).
Frequently asked questions
Use AI without leaking CUI
HoundShield scans every AI prompt locally and blocks CUI before it leaves your network. One URL change. Under 10 minutes. C3PAO-ready.