Defense & Aerospace

Shadow AI in Defense: Controlled Data and National Security

Engineers paste controlled technical data into AI coding tools. Programme managers share CUI with AI assistants. Cleared personnel use unsanctioned AI for briefing prep. Your CMMC boundary does not cover these tools. A DNS log audit finds them.

Why Defense Shadow AI Is a National Security Risk

Defense contractors handle controlled unclassified information, ITAR-regulated technical data and classified programme details. Every unsanctioned AI tool creates CMMC violations, ITAR breaches and the risk of controlled data reaching adversary-accessible systems.

Controlled Technical Data

Engineers paste weapons system specs, avionics parameters and munitions data into AI tools. ITAR-controlled technical data reaching a commercial AI server constitutes a deemed export violation.

CUI and FOUO Data

Programme managers share controlled unclassified information with AI assistants for briefing prep and report drafting. CUI leaves your CMMC boundary and enters systems without NIST 800-171 controls.

Systems Engineering

Systems engineers use AI to review requirements, generate test procedures and analyse architecture docs. Programme-of-record data and system vulnerabilities reach external AI platforms.

Proposal and BD

Business development teams paste RFP responses, cost proposals and technical approaches into AI for polishing. Proprietary pricing, teaming arrangements and programme strategy leak through AI sessions.

Software and Firmware

Embedded software teams paste mission-critical code into AI coding assistants. Weapon system firmware, avionics code and encryption implementations reach commercial AI servers.

Supply Chain

Procurement staff share supplier capabilities, sole-source justifications and DFARS flow-down data with AI tools. Defence industrial base information leaks to potentially adversary-accessible AI platforms.

Regulatory and Compliance Mapping

RequirementSourceShadow AI RiskWhat the Audit Produces
ITAR / EAR Controls22 CFR 120-130 / 15 CFR 730-774Technical data in AI = deemed export to server jurisdictionAI tools mapped to hosting jurisdiction
CMMC Level 2+DFARS 252.204-7021CUI in AI tools outside CMMC boundaryAI services for CMMC boundary assessment
NIST 800-171DFARS 252.204-7012AI tools lack required security controls for CUIAI tools flagged against 110 NIST controls
Insider ThreatNISPOM / 32 CFR 117AI tools as unmonitored data exfiltration channelsAI usage patterns for insider threat assessment
Supply Chain RiskDFARS 252.204-7018AI vendors may use prohibited components (SCRM)AI vendor origin and infrastructure assessment
Classified SpillageDoD Manual 5200.01Classified data in AI constitutes spillage incidentAI tools in classified-adjacent network segments

What Your Defense Audit Report Shows

Sample excerpt from a shadow AI audit of a mid-tier defense contractor (2,000 employees, CMMC Level 2).

SHADOW AI AUDIT - DEFENSE CONTRACTOR
Scan Period14 days (DNS + proxy)
Total AI Tools Found21 unique AI services
Tools in CMMC Boundary1 of 21
Tools Training on Input9 of 21
TOP FINDINGS
ChatGPT (Free Tier)1,234 queries - engineering and BD
AI Coding Assistant567 sessions - embedded software team
AI Writing Tool389 sessions - proposal team
AI Translation134 sessions - international programmes
RISK BY DIVISION
Engineering (ITAR technical data)
Programmes / BD (CUI and proposals)
IT / Cyber (configs and tools)
Corporate / Admin

Related Resources

Defense Shadow AI FAQ

Does the audit access classified or controlled data?
No. The audit analyses DNS and proxy log files only. These contain domain names and timestamps. No classified data, CUI, technical data or programme information is accessed. The logs themselves should be reviewed for classification before export.
How does this relate to CMMC assessment?
CMMC Level 2 requires implementation of all 110 NIST 800-171 controls for systems processing CUI. AI tools used by staff working with CUI must be within your CMMC boundary and meet these controls. The audit identifies AI tools outside your boundary so you can remediate before your C3PAO assessment.
Does using AI constitute an ITAR violation?
If ITAR-controlled technical data is shared with an AI service hosted outside the US, or accessible to foreign persons, it constitutes a deemed export under 22 CFR 120.17. The audit maps every AI tool to its hosting jurisdiction, giving you the data to assess whether any ITAR technical data may have reached restricted destinations.
Can we run this on classified networks?
The audit is designed for unclassified IT networks. Classified networks (SIPRNet, JWICS) should not have internet egress to commercial AI services. If your audit finds AI tool lookups on a network segment intended to be air-gapped, that itself is a critical finding requiring immediate investigation.

Find Every AI Tool in Your Defense Organisation

Upload your DNS or proxy logs and get a CMMC-mapped shadow AI inventory with ITAR and CUI flags.

Start Your Free Audit
View pricing plans →