Why: The practice's data-protection work — deciding which AI services may receive which data, and blocking CUI from leaving approved boundaries — determines where CUI is transmitted and stored, which is the scope this requirement's cryptographic mechanisms must then cover.
What this does not claim: The practice informs the requirement's scope without acting on its substance: it implements no cryptography. Whether CUI in transit to, or at rest within, an approved service is cryptographically protected is a property of that service's configuration and the organization's parameter choices, and it must be assessed on its own evidence regardless of how well AI data flows are governed.
- Maintain the approved-service list that bounds where CUI may be transmitted or stored
- Feed newly approved AI data flows into the CUI flow map that scopes cryptographic protection
- The approved AI service register with data-category decisions
- CUI flow map updates reflecting AI-related paths and stores
Mapping limitations: The relationship is scoping-only by design; it would not survive being read as implementation support and should not be presented as such.
Review status: Pending NIST SME review · Reviewed by Brilliant at the Basics editorial — practitioner-authored; NIST SME review pending · updated 2026-08-06