Bottom line up front: if CUI reached ChatGPT, treat it as a potential cyber incident under DFARS 252.204-7012 from the moment you learn of it. That clause requires rapid reporting to DoD — within 72 hours of discovery — via DIBNet, and preservation of relevant system images and monitoring data for at least 90 days. This playbook gives you the sequence. It is an engineering playbook, not legal advice: loop in counsel and your contracts team immediately.
Hour 0–1: Contain and freeze
- Stop the bleeding. Identify the account and device involved. Suspend further AI use from that account until scoping is done.
- Capture the conversation. Screenshot and export the full chat before anything is deleted — you need the exact content for scoping. Deleting the chat does not un-disclose the data, but the record of what was sent is your scoping evidence.
- Preserve, don't clean. DFARS 7012 requires preserving images of known affected systems and relevant monitoring data for at least 90 days from report submission. Resist the instinct to wipe.
Hour 1–24: Scope the disclosure
- Was it actually CUI? Check the content against your CUI registry categories and contract markings — contract numbers, CAGE codes, technical specs, export-controlled data (ITAR/EAR), personnel information. Not every internal document is CUI; your answer determines everything downstream.
- Which contract(s)? Map the data to the covered contracts. This decides who must be notified and what your prime-flowdown obligations are.
- Account and retention settings. Document whether the ChatGPT account had history/training enabled, whether it was a consumer or enterprise account, and submit a data-deletion request to the vendor — while noting for the record that deletion requests mitigate, not cure.
Hour 24–72: Report
- DIBNet report. If CUI was involved, DFARS 252.204-7012 directs reporting through DoD's DIBNet portal (dibnet.dod.mil), which requires a DoD-approved medium-assurance certificate — obtain that certificate now, before an incident, because procurement takes days you will not have.
- Notify your prime / contracting officer per your contract's flowdown clauses. Silence discovered later is worse than the incident.
- Write the internal incident record. Timeline, content, scope, decisions, notifications — this document is what your C3PAO assessor will read when they test your incident-response practices (NIST 800-171 3.6.1 and 3.6.2).
Week 1+: Corrective action that actually closes the gap
An assessor's follow-up question is always the same: what stops the next one? A memo re-banning ChatGPT is not a control. The corrective actions that hold up:
- Technical enforcement: route all AI traffic through a local scanning proxy so CUI-bearing prompts are blocked before they leave the network. HoundShield does this on your own infrastructure (self-hosted Docker) with 16 detection engines and a SHA-256 hash-chained log.
- Evidence going forward: the same log becomes your standing proof that AI usage is monitored and controlled — turning this incident's corrective action into next assessment's strength.
- A written AI-use policy tied to the enforcement (see our CMMC AI use policy template), plus training that references this exact scenario.
What this incident should teach the SSP
Map the fix to controls so it strengthens your score instead of just closing a ticket: flow control (3.1.3), boundary monitoring (3.13.1), audit records (3.3.1), incident handling (3.6.1–3.6.2). The full mapping lives in NIST 800-171 controls that map to AI prompt monitoring.
If you want to know whether this is already happening quietly across your team, the $499 CMMC AI Risk Assessment runs 14 days in your environment and reports every AI prompt event, risk-scored against NIST 800-171 — before an assessor or an adversary finds it first.