DFARS 252.204-7012 and AI

DFARS 252.204-7012 and AI

DFARS cyber incident reporting applied to AI-mediated CUI exposure

DFARS 252.204-7012 requires defense contractors to safeguard covered defense information and to report cyber incidents within 72 hours of discovery. The clause predates generative AI by years but applies to AI-mediated incidents touching CUI all the same. Mid-market defense contractors need explicit AI-specific incident response posture aligned to the DFARS reporting timeline.
DFARS 252.204-7012
DC3 72-Hour Reporting
CMMC 2.0 / NIST 800-171
DFARS AI Clauses

How DFARS 252.204-7012 Applies to AI Incidents

DFARS 252.204-7012 requires implementation of NIST 800-171 controls protecting covered defense information (substantially equivalent to CUI), cyber incident reporting to the DoD Cyber Crime Center within 72 hours of discovery, preservation of media for forensic review, malicious software submission to DC3, and damage assessment information requested by DoD. The clause applies to incidents affecting covered information regardless of the attack vector.

AI-mediated incidents fall under DFARS reporting when they affect covered information. Specific scenarios that require reporting consideration: prompt-injection causing CUI disclosure to an unauthorized recipient; vendor-side AI compromise affecting CUI processed by the vendor’s AI infrastructure; AI hallucination producing decisions or output incorporating CUI shared inappropriately; adversarial manipulation of AI underwriting or quality-control systems producing CUI exposure. Each requires DC3 reporting assessment within the 72-hour window.

FAQ

Frequently Asked Questions — DFARS AI Clauses

What triggers DFARS 252.204-7012 reporting for AI incidents?

The reporting trigger is discovery of a cyber incident affecting covered defense information. Pillar 3 observability instrumentation is configured to detect AI-mediated exposure events as discovery triggers, supporting the contractor’s 72-hour reporting obligation.

How does the framework support the DC3 reporting process?

Pillar 4 governance produces an incident response playbook that integrates DC3 reporting timeline, content requirements (incident description, technical details, malicious software collection), and follow-up obligations. The playbook is designed to be operationally executable within the 72-hour window.

What about DFARS 252.204-7019 and 7020 SPRS reporting?

The 7019 and 7020 clauses require NIST 800-171 self-assessment scoring and reporting to SPRS. AI use cases touching CUI affect the 800-171 controls inventory and consequently the SPRS score. Pillar 2 risk classification work produces the updated controls implementation that affects SPRS posture.

What if a vendor-side AI incident affects our CUI?

Vendor-side AI compromises affecting CUI processed under your DFARS-flow-down obligations trigger your reporting requirements regardless of whether the incident originated inside your perimeter. Pillar 4 governance produces vendor contract language requiring vendor notification of AI-mediated incidents and your coordinated response posture for vendor-originated incidents.

How does this affect our DFARS 252.204-7021 CMMC requirements?

The 7021 clause incorporates CMMC 2.0 requirements. AI risk management feeds into the CMMC controls implementation evaluated during assessment. Pillar 4 governance documentation supports CMMC assessment preparation with AI considerations in scope.

DFARS-Compliant AI Incident Response

Apply for the free 30-day AI Risk Assessment.