CMMC compliant AI tools are AI services that touch controlled unclassified information (CUI) only inside a boundary built to NIST SP 800-171: a cloud offering at the FedRAMP Moderate baseline or higher, as DFARS 252.204-7012 requires, or a model running inside your own CMMC-assessed enclave. Consumer ChatGPT and standard commercial AI workspaces sit outside both, so they should never receive CUI.
Where CMMC stands in October 2026
CMMC now rests on two rules. The program rule, 32 CFR Part 170, took effect on 16 December 2024 and defines the levels and assessments. The acquisition rule, DFARS Case 2019-D041 amending 48 CFR parts 204, 212, 217 and 252, took effect on 10 November 2025. That started Phase 1, in which contracts can require a Level 1 or Level 2 self-assessment as a condition of award.
Phase 2, the move to third-party Level 2 certification by a C3PAO, was scheduled for 10 November 2026. On 13 July 2026 the Department of War suspended it, along with later implementation milestones, and opened a 60-day review by a CMMC Reform Task Force. During the suspension, program offices may only specify Level 1 (Self) or Level 2 (Self), and contracting officers are removing C3PAO and Level 3 requirements from active solicitations and contracts. When this guide was published on 2 October 2026, the Department had not released the task force’s findings or a new date.
| Milestone | Date | Status in October 2026 |
|---|---|---|
| CMMC program rule, 32 CFR Part 170 | 16 December 2024 | In force |
| DFARS acquisition rule, Phase 1 | 10 November 2025 | In force: Level 1 and Level 2 self-assessments |
| Phase 2, C3PAO Level 2 certification | Planned for 10 November 2026 | Suspended on 13 July 2026 |
| Phases 3 and 4 | Planned one and two years after Phase 2 | Suspended with the later milestones |
| DFARS 252.204-7012 and NIST SP 800-171 Rev 2 | Already in defense contracts | Still enforced |
What the suspension left alone matters more for AI. The Department said every contractor remains obligated to safeguard covered defense information under DFARS 252.204-7012, and that it will enforce NIST SP 800-171 Rev 2 through self-assessments and select government-led assessments. CMMC Level 2 is pinned to that revision: 32 CFR 170.14 states that its requirements are identical to SP 800-171 Rev 2, even though NIST published Revision 3 in May 2024.
Why a prompt containing CUI brings the AI tool into scope
CUI is information the government creates or possesses, or that a contractor creates or possesses for it, that a law, regulation or government-wide policy requires or permits to be handled with safeguarding or dissemination controls (32 CFR 2002.4(h)). On a defense program, drawings, specifications, test reports and contract technical information usually qualify.
Once an engineer pastes a CUI paragraph into an AI tool, the CUI exists in more places than the original file:
- the prompt and the model’s context window;
- the retrieval index and embeddings built from your documents;
- conversation history, caches and generated outputs;
- application, audit and debug logs.
Each of those components stores, processes or transmits CUI, so each belongs inside the boundary your system security plan describes. If any of them lives in a vendor’s cloud, DFARS 252.204-7012 reaches that vendor through your contract with it.
What DFARS 252.204-7012 asks of a cloud AI service
Paragraph (b)(2)(ii)(D) of the clause decides most AI tool questions. A contractor that uses an external cloud service provider to store, process or transmit covered defense information must require and ensure that the provider:
- meets security requirements equivalent to the FedRAMP Moderate baseline; and
- complies with paragraphs (c) to (g) of the clause, which cover cyber incident reporting, malicious software, media preservation and protection, access for forensic analysis, and damage assessment.
The clause defines rapid reporting as within 72 hours of discovering a cyber incident.
A DoD CIO memorandum dated 21 December 2023 spells out what “equivalent” means. The provider must show 100 percent compliance with the latest FedRAMP Moderate baseline, assessed by a FedRAMP-recognized third-party assessment organization, and give the contractor a body of evidence with every finding from that assessment closed. Offerings that are already FedRAMP Moderate authorized on the FedRAMP Marketplace qualify without further assessment. The memo also puts the burden on you: the contractor approves the cloud service, validates the evidence and remains responsible for reporting if the service is compromised.
ChatGPT, Copilot and Azure OpenAI with CUI, option by option
The table summarizes public authorization data and vendor documentation checked in October 2026. Use it to start your own review, because tenant configuration and contract terms decide the final answer.
| Option | What vendor or FedRAMP data shows (verified October 2026) | CUI under DFARS 252.204-7012 | ITAR technical data |
|---|---|---|---|
| ChatGPT Free, Plus or Pro | Not FedRAMP authorized; OpenAI may train on content unless the user opts out | No | No |
| ChatGPT Business, or a standard commercial ChatGPT Enterprise workspace | Not used for training by default; outside OpenAI’s FedRAMP environment | No | No |
| ChatGPT Enterprise and API in OpenAI’s FedRAMP environment | FedRAMP 20x Moderate authorized, announced in April 2026 for U.S. government agencies | Only with written confirmation of scope and the clause’s terms in your contract | FedRAMP Moderate alone does not settle it |
| Microsoft 365 Copilot in GCC | GCC is FedRAMP Moderate; Microsoft says GCC suits customers that do not handle ITAR or DFARS-regulated CUI | No | No |
| Microsoft 365 Copilot in GCC High | Copilot is available; GCC High is FedRAMP High authorized, and prompts and responses stay in the government cloud tenant | Yes, inside the GCC High tenant | Microsoft positions GCC High for ITAR and EAR workloads |
| Azure OpenAI in Azure Government | In audit scope for FedRAMP High, DoD IL2, IL4 and IL5 (with workload isolation), and IL6 in Azure Government Secret | Yes, as a component you build, configure and document | Confirm export-control coverage with Microsoft and your counsel |
| Open-weight model on servers inside your enclave | No external authorization involved; your controls and assessment cover it | Yes, inside your assessed boundary | Yes, if the enclave already meets your export controls |
Three details are easy to miss:
- OpenAI’s FedRAMP environment is separate. OpenAI refers to its FedRAMP environment and FedRAMP workspaces, and says it is narrowing the gap between FedRAMP and commercial product experiences. Unless OpenAI confirms otherwise in writing, treat a commercial ChatGPT Enterprise workspace as outside that boundary.
- Training settings answer a different question. OpenAI does not train on ChatGPT Business, Enterprise or API data by default. The clause still requires the FedRAMP Moderate baseline and its incident terms on top of that.
- Copilot follows its tenant. Microsoft states that Copilot inherits the security and compliance controls of the government cloud it runs in, and that features usually arrive later than in commercial Microsoft 365.
ITAR and EAR technical data raise the bar
Export controls add a second test that a FedRAMP authorization does not answer. Under ITAR, technical data includes the blueprints, drawings, plans, instructions and documentation needed to design, produce, operate, repair or modify a defense article (22 CFR 120.33). Releasing it to a foreign person inside the United States is a deemed export (22 CFR 120.50), and a release includes enabling a foreign person to access unencrypted technical data (22 CFR 120.56).
ITAR does carve out encrypted storage and transmission. Sending, taking or storing unclassified technical data is not an export if it is end-to-end encrypted with FIPS 140-2 compliant modules or comparably strong cryptography, and is not sent to or stored in a proscribed country (22 CFR 120.54(a)(5)). The EAR has a parallel rule for controlled technology and software (15 CFR 734.18(a)(5)), and its definition of end-to-end encryption requires that no third party is given the means of decryption.
That carve-out was written for encrypted storage and transfer. A hosted model has to decrypt a prompt to answer it, so the carve-out is hard to apply to cloud inference, and the question becomes who can reach the plaintext and where it is processed. For export-controlled programs, that usually narrows the choice to a government cloud where staff with access to customer content must pass U.S. citizenship and background checks, as Microsoft requires for GCC High, or to a model running on infrastructure you control. Confirm the design with your export compliance team.
Two ways to keep AI inside a compliant boundary
Every compliant setup puts the model, its data and its logs inside a boundary that already satisfies NIST SP 800-171. In practice there are two ways to get there.
| Authorized government cloud | Model inside your own enclave | |
|---|---|---|
| Examples | Copilot in GCC High; Azure OpenAI in Azure Government | Open-weight models on GPU servers in your CMMC-assessed environment, or fully air-gapped |
| Who processes CUI | The cloud provider, under its authorization and your contract terms | Only systems you operate |
| What you document | The provider’s authorization, your tenant configuration and the 7012 flow-down terms | The AI components as assets in your system security plan |
| ITAR fit | Depends on the tenant and the provider’s personnel controls | Falls under the export controls you already run |
| Trade-offs | Features lag commercial clouds; CUI is still processed outside your network | You run the hardware and model updates; model choice is limited to open-weight models |
Many contractors combine the two: GCC High for everyday office work, and a private model inside the enclave for engineering documents, technical data and anything the cloud tenant should not hold. The air-gapped deployment guide covers offline updates and model transfer for the second pattern.
A CMMC AI policy checklist
A CMMC AI policy turns these decisions into rules your staff can follow. Cover at least these points:
- Approved tools by data type. Name which tools may receive public data, FCI, CUI and export-controlled technical data, and bar consumer AI from anything above public data.
- System security plan updates. List model servers, vector stores, conversation stores and logs as assets, each with its boundary and owner.
- Access control. Give every user a unique account through your identity provider, grant access to assistants and agents by role, and keep agent tool permissions to the minimum.
- Audit logging. Record prompts, retrieved sources, outputs and tool calls, and protect those logs like any other CUI audit record.
- Incident response. Treat an AI data spill as a cyber incident, meet the 72-hour reporting window in DFARS 252.204-7012, and write the provider’s notification duties into its contract.
- Export control rules. State where ITAR and EAR technical data may be processed and who may administer those systems.
- Change control. Approve new models and model updates as you approve other software changes, with signed packages for air-gapped sites.
- Training and detection. Teach staff what they may paste where, and watch network and endpoint logs for unapproved AI services.
- Review triggers. Revisit the policy when a vendor’s authorization changes or the CMMC review produces new guidance.
The AI governance policy generator drafts AI use policies, RACI tables and approval lifecycles that you can adapt to these points.
How VDF AI fits a CMMC enclave
VDF AI follows the second pattern. It is a self-hosted platform for private AI assistants and agents that installs on your own servers, on-premises or air-gapped, so models, retrieval indexes, conversation history and audit logs stay inside your CMMC-assessed enclave and under your NIST SP 800-171 controls. VDF AI holds no CMMC, FedRAMP or DoD Impact Level authorization of its own; your assessment covers it as part of your system, in the same way it covers the servers it runs on.
VDF AI Chat gives staff a private assistant with permission-aware retrieval and per-turn audit trails, and VDF AI Agents run governed workflows with tool permissions and human approvals. On-premises deployments sign users in through Microsoft Entra ID single sign-on natively, mapping Entra security groups to roles; other identity providers connect through an SSO-aware reverse proxy. Role-based access control assigns roles, permission groups and per-role tool grants. For CUI workloads, keep external model APIs switched off so every request is served by local open-weight models.
For the wider public-sector picture, see the government and defense solution, the private AI for defense guide and the government executive brief.
Sources
- CMMC program rule, 32 CFR Part 170, in the Federal Register
- DFARS CMMC acquisition rule, DFARS Case 2019-D041
- 32 CFR Part 170 on eCFR, including the phases in 170.3 and the model in 170.14
- Department of War release on the CMMC Phase II suspension, 13 July 2026
- Memorandum implementing the CMMC Phase 2 suspension, 13 July 2026
- DoD CIO memorandum on FedRAMP Moderate equivalency, 21 December 2023
- DFARS 252.204-7012 on eCFR
- CUI definition, 32 CFR 2002.4
- NIST SP 800-171 Revision 3 publication record
- OpenAI announcement of FedRAMP 20x Moderate authorization
- OpenAI help article on how content is used for training
- FedRAMP Marketplace data published by GSA
- Microsoft Learn on U.S. government clouds for Microsoft 365 and Copilot
- Microsoft Learn service description for GCC High and DoD
- Microsoft Learn on Azure Government compliance scope
- ITAR definitions in 22 CFR Part 120 on eCFR
- EAR 15 CFR 734.18 on eCFR