CUI Exposure Through AI Workflows

CUI Exposure Through AI Workflows

Managing Controlled Unclassified Information Exposure Through AI

Controlled Unclassified Information (CUI) is the largest category of regulated data mid-market defense contractors handle. AI is now processing CUI inside ERP, engineering tools, procurement systems, and HR workflows. The 32 CFR 2002 CUI Program and DFARS 252.204-7012 govern protection; NIST 800-171 specifies the controls. Closing the AI-CUI exposure gap is the most consequential security work mid-market defense contractors can do this year.
32 CFR 2002 CUI Program
DFARS 252.204-7012
NIST 800-171
AI-CUI Exposure Map

Where AI Touches CUI in Mid-Market Defense Contractor Environments

Mid-market defense contractors typically have CUI flowing through ERP (SAP, Oracle, Dynamics, IFS, Epicor), engineering tools (Siemens Teamcenter, PTC Windchill, CAD/CAM/CAE), procurement systems (Coupa, Ariba, Jaggaer), HR systems (Workday, ADP, Paylocity), and customer-collaboration platforms. AI is increasingly embedded into each of these systems by the vendor, sometimes without explicit notification to the customer security team.

The CUI exposure question for AI is not whether AI is touching CUI — it almost certainly is. The questions are: which AI use cases, on what data, under what controls, with what audit trail, and with what cross-reference to the NIST 800-171 controls protecting the data. The Pillar 1 discovery work surfaces the inventory; the Pillar 2 classification work produces the answers.

FAQ

Frequently Asked Questions — CUI AI Risk

Does the framework address the new 32 CFR 2002 CUI Program requirements?

Yes. The CUI Program established by 32 CFR 2002 governs how Executive Branch agencies designate and handle CUI; contractors handling CUI inherit obligations through DFARS 252.204-7012 and equivalent clauses. The framework’s Pillar 2 classification work cross-references AI use cases to the specific CUI category (basic CUI, specified CUI, CUI categories with additional handling requirements) and the controls each requires.

How does the framework address the DoD Cyber Crime Center reporting requirement?

Pillar 4 governance includes an incident response playbook that addresses DFARS 252.204-7012 reporting obligations including the 72-hour DC3 reporting timeline. AI-mediated CUI exposure events are documented to support the report.

What if our AI use case is processing CUI categorized as Specified CUI?

Specified CUI categories carry additional handling requirements beyond basic CUI. Pillar 2 classification identifies AI use cases touching specified CUI categories (for example, export-controlled, privacy, financial) and applies the additional safeguards each category requires. Pillar 3 observability calibrates to the specific data category.

How does the framework integrate with Project Spectrum tools?

For mid-market defense contractors using Project Spectrum and related DoD Cybersecurity-as-a-Service offerings, the framework’s deliverables are designed to complement those tools. The risk register and governance documentation produced by the framework are exportable for use in Project Spectrum’s reporting.

Does the framework address the recent NIST 800-171 Rev 3 update?

Yes. The framework cross-references AI use cases to both 800-171 Rev 2 and Rev 3 controls. As the CMMC 2.0 program transitions to Rev 3 references, the framework’s mapping is updated accordingly. Engagements scope explicitly to the Rev currently applicable to your contract obligations.

CUI Protection With AI Workflows in Scope

Apply for the free 30-day AI Risk Assessment.