AI Compliance

CMMC Compliant AI Tools: Can Defense Contractors Use ChatGPT or Copilot with CUI?

No AI tool is CMMC certified on its own. Whether ChatGPT, Microsoft 365 Copilot, Azure OpenAI or a private model may touch CUI depends on where it runs, and this guide maps each option against DFARS 252.204-7012, ITAR and the CMMC status as of October 2026.

CMMC compliant AI tools are AI services that touch controlled unclassified information (CUI) only inside a boundary built to NIST SP 800-171: a cloud offering at the FedRAMP Moderate baseline or higher, as DFARS 252.204-7012 requires, or a model running inside your own CMMC-assessed enclave. Consumer ChatGPT and standard commercial AI workspaces sit outside both, so they should never receive CUI.

Where CMMC stands in October 2026

CMMC now rests on two rules. The program rule, 32 CFR Part 170, took effect on 16 December 2024 and defines the levels and assessments. The acquisition rule, DFARS Case 2019-D041 amending 48 CFR parts 204, 212, 217 and 252, took effect on 10 November 2025. That started Phase 1, in which contracts can require a Level 1 or Level 2 self-assessment as a condition of award.

Phase 2, the move to third-party Level 2 certification by a C3PAO, was scheduled for 10 November 2026. On 13 July 2026 the Department of War suspended it, along with later implementation milestones, and opened a 60-day review by a CMMC Reform Task Force. During the suspension, program offices may only specify Level 1 (Self) or Level 2 (Self), and contracting officers are removing C3PAO and Level 3 requirements from active solicitations and contracts. When this guide was published on 2 October 2026, the Department had not released the task force’s findings or a new date.

MilestoneDateStatus in October 2026
CMMC program rule, 32 CFR Part 17016 December 2024In force
DFARS acquisition rule, Phase 110 November 2025In force: Level 1 and Level 2 self-assessments
Phase 2, C3PAO Level 2 certificationPlanned for 10 November 2026Suspended on 13 July 2026
Phases 3 and 4Planned one and two years after Phase 2Suspended with the later milestones
DFARS 252.204-7012 and NIST SP 800-171 Rev 2Already in defense contractsStill enforced

What the suspension left alone matters more for AI. The Department said every contractor remains obligated to safeguard covered defense information under DFARS 252.204-7012, and that it will enforce NIST SP 800-171 Rev 2 through self-assessments and select government-led assessments. CMMC Level 2 is pinned to that revision: 32 CFR 170.14 states that its requirements are identical to SP 800-171 Rev 2, even though NIST published Revision 3 in May 2024.

Why a prompt containing CUI brings the AI tool into scope

CUI is information the government creates or possesses, or that a contractor creates or possesses for it, that a law, regulation or government-wide policy requires or permits to be handled with safeguarding or dissemination controls (32 CFR 2002.4(h)). On a defense program, drawings, specifications, test reports and contract technical information usually qualify.

Once an engineer pastes a CUI paragraph into an AI tool, the CUI exists in more places than the original file:

  • the prompt and the model’s context window;
  • the retrieval index and embeddings built from your documents;
  • conversation history, caches and generated outputs;
  • application, audit and debug logs.

Each of those components stores, processes or transmits CUI, so each belongs inside the boundary your system security plan describes. If any of them lives in a vendor’s cloud, DFARS 252.204-7012 reaches that vendor through your contract with it.

What DFARS 252.204-7012 asks of a cloud AI service

Paragraph (b)(2)(ii)(D) of the clause decides most AI tool questions. A contractor that uses an external cloud service provider to store, process or transmit covered defense information must require and ensure that the provider:

  1. meets security requirements equivalent to the FedRAMP Moderate baseline; and
  2. complies with paragraphs (c) to (g) of the clause, which cover cyber incident reporting, malicious software, media preservation and protection, access for forensic analysis, and damage assessment.

The clause defines rapid reporting as within 72 hours of discovering a cyber incident.

A DoD CIO memorandum dated 21 December 2023 spells out what “equivalent” means. The provider must show 100 percent compliance with the latest FedRAMP Moderate baseline, assessed by a FedRAMP-recognized third-party assessment organization, and give the contractor a body of evidence with every finding from that assessment closed. Offerings that are already FedRAMP Moderate authorized on the FedRAMP Marketplace qualify without further assessment. The memo also puts the burden on you: the contractor approves the cloud service, validates the evidence and remains responsible for reporting if the service is compromised.

ChatGPT, Copilot and Azure OpenAI with CUI, option by option

The table summarizes public authorization data and vendor documentation checked in October 2026. Use it to start your own review, because tenant configuration and contract terms decide the final answer.

OptionWhat vendor or FedRAMP data shows (verified October 2026)CUI under DFARS 252.204-7012ITAR technical data
ChatGPT Free, Plus or ProNot FedRAMP authorized; OpenAI may train on content unless the user opts outNoNo
ChatGPT Business, or a standard commercial ChatGPT Enterprise workspaceNot used for training by default; outside OpenAI’s FedRAMP environmentNoNo
ChatGPT Enterprise and API in OpenAI’s FedRAMP environmentFedRAMP 20x Moderate authorized, announced in April 2026 for U.S. government agenciesOnly with written confirmation of scope and the clause’s terms in your contractFedRAMP Moderate alone does not settle it
Microsoft 365 Copilot in GCCGCC is FedRAMP Moderate; Microsoft says GCC suits customers that do not handle ITAR or DFARS-regulated CUINoNo
Microsoft 365 Copilot in GCC HighCopilot is available; GCC High is FedRAMP High authorized, and prompts and responses stay in the government cloud tenantYes, inside the GCC High tenantMicrosoft positions GCC High for ITAR and EAR workloads
Azure OpenAI in Azure GovernmentIn audit scope for FedRAMP High, DoD IL2, IL4 and IL5 (with workload isolation), and IL6 in Azure Government SecretYes, as a component you build, configure and documentConfirm export-control coverage with Microsoft and your counsel
Open-weight model on servers inside your enclaveNo external authorization involved; your controls and assessment cover itYes, inside your assessed boundaryYes, if the enclave already meets your export controls

Three details are easy to miss:

  • OpenAI’s FedRAMP environment is separate. OpenAI refers to its FedRAMP environment and FedRAMP workspaces, and says it is narrowing the gap between FedRAMP and commercial product experiences. Unless OpenAI confirms otherwise in writing, treat a commercial ChatGPT Enterprise workspace as outside that boundary.
  • Training settings answer a different question. OpenAI does not train on ChatGPT Business, Enterprise or API data by default. The clause still requires the FedRAMP Moderate baseline and its incident terms on top of that.
  • Copilot follows its tenant. Microsoft states that Copilot inherits the security and compliance controls of the government cloud it runs in, and that features usually arrive later than in commercial Microsoft 365.

ITAR and EAR technical data raise the bar

Export controls add a second test that a FedRAMP authorization does not answer. Under ITAR, technical data includes the blueprints, drawings, plans, instructions and documentation needed to design, produce, operate, repair or modify a defense article (22 CFR 120.33). Releasing it to a foreign person inside the United States is a deemed export (22 CFR 120.50), and a release includes enabling a foreign person to access unencrypted technical data (22 CFR 120.56).

ITAR does carve out encrypted storage and transmission. Sending, taking or storing unclassified technical data is not an export if it is end-to-end encrypted with FIPS 140-2 compliant modules or comparably strong cryptography, and is not sent to or stored in a proscribed country (22 CFR 120.54(a)(5)). The EAR has a parallel rule for controlled technology and software (15 CFR 734.18(a)(5)), and its definition of end-to-end encryption requires that no third party is given the means of decryption.

That carve-out was written for encrypted storage and transfer. A hosted model has to decrypt a prompt to answer it, so the carve-out is hard to apply to cloud inference, and the question becomes who can reach the plaintext and where it is processed. For export-controlled programs, that usually narrows the choice to a government cloud where staff with access to customer content must pass U.S. citizenship and background checks, as Microsoft requires for GCC High, or to a model running on infrastructure you control. Confirm the design with your export compliance team.

Two ways to keep AI inside a compliant boundary

Every compliant setup puts the model, its data and its logs inside a boundary that already satisfies NIST SP 800-171. In practice there are two ways to get there.

Authorized government cloudModel inside your own enclave
ExamplesCopilot in GCC High; Azure OpenAI in Azure GovernmentOpen-weight models on GPU servers in your CMMC-assessed environment, or fully air-gapped
Who processes CUIThe cloud provider, under its authorization and your contract termsOnly systems you operate
What you documentThe provider’s authorization, your tenant configuration and the 7012 flow-down termsThe AI components as assets in your system security plan
ITAR fitDepends on the tenant and the provider’s personnel controlsFalls under the export controls you already run
Trade-offsFeatures lag commercial clouds; CUI is still processed outside your networkYou run the hardware and model updates; model choice is limited to open-weight models

Many contractors combine the two: GCC High for everyday office work, and a private model inside the enclave for engineering documents, technical data and anything the cloud tenant should not hold. The air-gapped deployment guide covers offline updates and model transfer for the second pattern.

A CMMC AI policy checklist

A CMMC AI policy turns these decisions into rules your staff can follow. Cover at least these points:

  • Approved tools by data type. Name which tools may receive public data, FCI, CUI and export-controlled technical data, and bar consumer AI from anything above public data.
  • System security plan updates. List model servers, vector stores, conversation stores and logs as assets, each with its boundary and owner.
  • Access control. Give every user a unique account through your identity provider, grant access to assistants and agents by role, and keep agent tool permissions to the minimum.
  • Audit logging. Record prompts, retrieved sources, outputs and tool calls, and protect those logs like any other CUI audit record.
  • Incident response. Treat an AI data spill as a cyber incident, meet the 72-hour reporting window in DFARS 252.204-7012, and write the provider’s notification duties into its contract.
  • Export control rules. State where ITAR and EAR technical data may be processed and who may administer those systems.
  • Change control. Approve new models and model updates as you approve other software changes, with signed packages for air-gapped sites.
  • Training and detection. Teach staff what they may paste where, and watch network and endpoint logs for unapproved AI services.
  • Review triggers. Revisit the policy when a vendor’s authorization changes or the CMMC review produces new guidance.

The AI governance policy generator drafts AI use policies, RACI tables and approval lifecycles that you can adapt to these points.

How VDF AI fits a CMMC enclave

VDF AI follows the second pattern. It is a self-hosted platform for private AI assistants and agents that installs on your own servers, on-premises or air-gapped, so models, retrieval indexes, conversation history and audit logs stay inside your CMMC-assessed enclave and under your NIST SP 800-171 controls. VDF AI holds no CMMC, FedRAMP or DoD Impact Level authorization of its own; your assessment covers it as part of your system, in the same way it covers the servers it runs on.

VDF AI Chat gives staff a private assistant with permission-aware retrieval and per-turn audit trails, and VDF AI Agents run governed workflows with tool permissions and human approvals. On-premises deployments sign users in through Microsoft Entra ID single sign-on natively, mapping Entra security groups to roles; other identity providers connect through an SSO-aware reverse proxy. Role-based access control assigns roles, permission groups and per-role tool grants. For CUI workloads, keep external model APIs switched off so every request is served by local open-weight models.

For the wider public-sector picture, see the government and defense solution, the private AI for defense guide and the government executive brief.

Sources

Frequently asked questions

Can we use ChatGPT with CUI?

Not with consumer ChatGPT or a standard commercial Business or Enterprise workspace. DFARS 252.204-7012 requires any cloud service that stores, processes or transmits covered defense information to meet the FedRAMP Moderate baseline or an equivalent, and to accept the clause's incident reporting and forensics terms. OpenAI's FedRAMP 20x Moderate authorization covers a separate FedRAMP environment of ChatGPT Enterprise and its API, built for government agencies. Put CUI only into a workspace that OpenAI confirms in writing is inside that boundary, with the flow-down terms in your contract.

Is Microsoft 365 Copilot approved for CUI?

Microsoft directs CUI, DFARS and ITAR workloads to GCC High rather than GCC, and states that Copilot is available in GCC, GCC High and DoD with prompts, responses and generated content kept in the government cloud tenant. GCC High holds a FedRAMP High authorization. That makes Copilot in a GCC High tenant the Microsoft route for CUI, with two caveats: features reach government clouds later than commercial Microsoft 365, and Copilot still has to appear in your system security plan.

Are there CMMC certified AI tools?

No. CMMC assesses a contractor's information systems, not individual products, so no vendor can sell a CMMC certified AI tool. A vendor can offer a cloud service authorized at FedRAMP Moderate or higher, which DFARS 252.204-7012 accepts for CUI, or software you install inside your own environment, where it becomes part of the scope you assess. Either way, the AI components belong in your system security plan and under your NIST SP 800-171 controls.

Does the CMMC Phase 2 suspension change the rules for AI and CUI?

No. On 13 July 2026 the Department of War suspended the November 2026 move to third-party CMMC certification and limited new requirements to Level 1 and Level 2 self-assessments during a program review. It also stated that DFARS 252.204-7012 still applies and that NIST SP 800-171 Rev 2 will be enforced through self-assessments and select government-led assessments. An AI tool that touches CUI still has to sit inside a compliant boundary.

What should a CMMC AI policy include?

At minimum: approved AI tools mapped to the data each may receive, with consumer AI barred from CUI, FCI and export-controlled data; how AI components appear in the system security plan; role-based access and logging for prompts and outputs; where ITAR and EAR technical data may be processed; incident handling that meets the 72-hour reporting window in DFARS 252.204-7012; staff training; and monitoring for unapproved AI services. Review it whenever a vendor's authorization or the CMMC timeline changes.

Can AI tools process ITAR technical data?

Only on infrastructure where no foreign person can reach the data. ITAR treats a release of technical data to a foreign person as an export even inside the United States. Encrypted storage has a carve-out, but a hosted model must work on decrypted text, so that carve-out is difficult to apply to cloud inference. Contractors with export-controlled programs usually choose a government cloud staffed by screened U.S. citizens, such as GCC High, or a model on servers they control, and confirm the design with their export compliance team.

Filed under
CMMCAI complianceregulated AIair-gapped AIon-premises AIdata sovereignty
AI Governance

Is your AI governance audit-ready?

Get a readiness review of your AI controls — policy, oversight, audit trails, and EU AI Act evidence — mapped against what production actually requires.

Keep reading