Engineers paste controlled technical data into AI coding tools. Programme managers share CUI with AI assistants. Cleared personnel use unsanctioned AI for briefing prep. Your CMMC boundary does not cover these tools. A DNS log audit finds them.
Defense contractors handle controlled unclassified information, ITAR-regulated technical data and classified programme details. Every unsanctioned AI tool creates CMMC violations, ITAR breaches and the risk of controlled data reaching adversary-accessible systems.
Engineers paste weapons system specs, avionics parameters and munitions data into AI tools. ITAR-controlled technical data reaching a commercial AI server constitutes a deemed export violation.
Programme managers share controlled unclassified information with AI assistants for briefing prep and report drafting. CUI leaves your CMMC boundary and enters systems without NIST 800-171 controls.
Systems engineers use AI to review requirements, generate test procedures and analyse architecture docs. Programme-of-record data and system vulnerabilities reach external AI platforms.
Business development teams paste RFP responses, cost proposals and technical approaches into AI for polishing. Proprietary pricing, teaming arrangements and programme strategy leak through AI sessions.
Embedded software teams paste mission-critical code into AI coding assistants. Weapon system firmware, avionics code and encryption implementations reach commercial AI servers.
Procurement staff share supplier capabilities, sole-source justifications and DFARS flow-down data with AI tools. Defence industrial base information leaks to potentially adversary-accessible AI platforms.
| Requirement | Source | Shadow AI Risk | What the Audit Produces |
|---|---|---|---|
| ITAR / EAR Controls | 22 CFR 120-130 / 15 CFR 730-774 | Technical data in AI = deemed export to server jurisdiction | AI tools mapped to hosting jurisdiction |
| CMMC Level 2+ | DFARS 252.204-7021 | CUI in AI tools outside CMMC boundary | AI services for CMMC boundary assessment |
| NIST 800-171 | DFARS 252.204-7012 | AI tools lack required security controls for CUI | AI tools flagged against 110 NIST controls |
| Insider Threat | NISPOM / 32 CFR 117 | AI tools as unmonitored data exfiltration channels | AI usage patterns for insider threat assessment |
| Supply Chain Risk | DFARS 252.204-7018 | AI vendors may use prohibited components (SCRM) | AI vendor origin and infrastructure assessment |
| Classified Spillage | DoD Manual 5200.01 | Classified data in AI constitutes spillage incident | AI tools in classified-adjacent network segments |
Sample excerpt from a shadow AI audit of a mid-tier defense contractor (2,000 employees, CMMC Level 2).
Upload your DNS or proxy logs and get a CMMC-mapped shadow AI inventory with ITAR and CUI flags.
Start Your Free Audit