Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
IT-08IT SYSTEMSOFFICIAL INTENTEXPERT REVIEWED

Secure AI Adoption and Data Protection

AI is entering the workplace whether you plan for it or not. Secure adoption means deciding — before staff paste data into a chatbot — which tools are approved, what data may and may not go into them, and how AI use is governed and logged. The goal is to capture AI's value without leaking CUI or feeding sensitive data into systems you do not control.

EXPLAINER · 5 SCENES · ≈40 SEC · CAPTIONS, NO AUDIO

IT-08 in 40 seconds

The problem, the plain-words meaning, three key moves, and what “done” looks like.

Official intent

What the campaign asks for

Adopt AI capabilities securely, protecting sensitive defense information from exposure through AI tools. The official source remains authoritative.

Read the official campaign ↗

Why it matters

Public AI tools can retain, train on, or expose whatever is entered into them. A single prompt containing controlled or proprietary information can put CUI outside your boundary in seconds — an unmonitored, unauthorized data flow. Governing AI use turns an uncontrolled shadow-IT risk into a managed capability with clear rules.

Minimum / Strong / Advanced

1
Minimum

An acceptable-use policy defines approved AI tools and prohibits entering CUI or sensitive data into public/consumer AI.

2
Strong

Approved enterprise AI tools with data-protection terms are provided, use is logged, and data-loss controls flag sensitive content.

3
Advanced

AI use is governed against a recognized framework (e.g., NIST AI RMF), with data classification, monitoring, and regular review of tools and prompts.

Implementation timeline

First 24 hours
  • Publish an interim rule: no CUI or sensitive data in public AI tools
  • Identify which AI tools staff are already using
Next 30 days
  • Choose approved enterprise AI tools with acceptable data terms
  • Write and communicate an AI acceptable-use policy
Next 60 days
  • Route AI access through managed accounts and log usage
  • Extend data-loss prevention to flag sensitive content heading to AI
By day 90
  • Align governance to the NIST AI RMF
  • Train staff on what may and may not go into AI tools

Implementation steps

  1. Inventory the AI tools already in use — including browser extensions and embedded assistants.
  2. Decide which tools are approved and require enterprise terms that prohibit training on your data.
  3. Publish an AI acceptable-use policy that classifies what data may and may not be entered.
  4. Provide sanctioned tools so staff have a compliant option, and route access through managed identities.
  5. Log AI usage and extend data-loss prevention to detect CUI or sensitive data heading to AI services.

Validation

  • Confirm the approved AI tools' terms prohibit using your data for training.
  • Test that a data-loss rule flags a document marked CUI when sent to an AI tool.
  • Review usage logs for access to unapproved public AI services.

Evidence to retain

Governance

AI acceptable-use and data-classification policy

Configuration

Approved-tool list with data-protection terms; DLP rules for AI

Operations

AI usage logs and review of unapproved-tool access

Validation

DLP test result and periodic tool/terms review

Common failure modes

What looks done but is not

A policy that bans AI while everyone quietly uses it anyway, approving a tool without reading its data-retention terms, and treating AI output as automatically safe or accurate. Prohibition without a sanctioned alternative just drives the risk into the shadows.

Framework mappings

Independent mappings are aids, not authoritative equivalence or compliance determinations.

FrameworkRequirementRelationshipConfidence
NIST AI RMF (AI 100-1)GOVERN / MAPSupportingModerate
NIST SP 800-1713.1.3SupportingModerate
CIS Controls v8.13.3SupportingModerate