DFARS cyber incident reporting applied to AI-mediated CUI exposure
DFARS 252.204-7012 requires defense contractors to safeguard covered defense information and to report cyber incidents within 72 hours of discovery. The clause predates generative AI by years but applies to AI-mediated incidents touching CUI all the same. Mid-market defense contractors need explicit AI-specific incident response posture aligned to the DFARS reporting timeline.DC3 72-Hour Reporting
CMMC 2.0 / NIST 800-171
How DFARS 252.204-7012 Applies to AI Incidents
DFARS 252.204-7012 requires implementation of NIST 800-171 controls protecting covered defense information (substantially equivalent to CUI), cyber incident reporting to the DoD Cyber Crime Center within 72 hours of discovery, preservation of media for forensic review, malicious software submission to DC3, and damage assessment information requested by DoD. The clause applies to incidents affecting covered information regardless of the attack vector.
AI-mediated incidents fall under DFARS reporting when they affect covered information. Specific scenarios that require reporting consideration: prompt-injection causing CUI disclosure to an unauthorized recipient; vendor-side AI compromise affecting CUI processed by the vendor’s AI infrastructure; AI hallucination producing decisions or output incorporating CUI shared inappropriately; adversarial manipulation of AI underwriting or quality-control systems producing CUI exposure. Each requires DC3 reporting assessment within the 72-hour window.