Managing Controlled Unclassified Information Exposure Through AI
Controlled Unclassified Information (CUI) is the largest category of regulated data mid-market defense contractors handle. AI is now processing CUI inside ERP, engineering tools, procurement systems, and HR workflows. The 32 CFR 2002 CUI Program and DFARS 252.204-7012 govern protection; NIST 800-171 specifies the controls. Closing the AI-CUI exposure gap is the most consequential security work mid-market defense contractors can do this year.DFARS 252.204-7012
NIST 800-171
Where AI Touches CUI in Mid-Market Defense Contractor Environments
Mid-market defense contractors typically have CUI flowing through ERP (SAP, Oracle, Dynamics, IFS, Epicor), engineering tools (Siemens Teamcenter, PTC Windchill, CAD/CAM/CAE), procurement systems (Coupa, Ariba, Jaggaer), HR systems (Workday, ADP, Paylocity), and customer-collaboration platforms. AI is increasingly embedded into each of these systems by the vendor, sometimes without explicit notification to the customer security team.
The CUI exposure question for AI is not whether AI is touching CUI — it almost certainly is. The questions are: which AI use cases, on what data, under what controls, with what audit trail, and with what cross-reference to the NIST 800-171 controls protecting the data. The Pillar 1 discovery work surfaces the inventory; the Pillar 2 classification work produces the answers.