Why: External AI services are external systems in this requirement's sense the moment CUI could reach them, and the practice's sanction-and-boundary decisions about AI tools inform which such uses are authorized and under what conditions.
What this does not claim: Informs the approach; it does not implement the requirement's machinery. The default prohibition, defined security conditions, verification, retained agreements, and portable-storage restriction span every external system — partner networks, home computers, all unvetted SaaS — of which AI services are one slice. A strong AI-adoption stance leaves the rest of the external-system population unexamined.
- Fold sanctioned AI services into the external-system authorization list with their conditions
- Block unsanctioned AI tools from CUI repositories at the network or endpoint layer
- The sanctioned AI-service entries within the external-system register
- Blocking or DLP policy covering unsanctioned AI services
Review status: Pending NIST SME review · Reviewed by Brilliant at the Basics editorial — practitioner-authored; NIST SME review pending · updated 2026-08-06