Official intent
Adopt AI capabilities securely, protecting sensitive defense information from exposure through AI tools. The official source remains authoritative.
Read the official campaign ↗Why it matters
Public AI tools can retain, train on, or expose whatever is entered into them. A single prompt containing controlled or proprietary information can put CUI outside your boundary in seconds — an unmonitored, unauthorized data flow. Governing AI use turns an uncontrolled shadow-IT risk into a managed capability with clear rules.
Minimum / Strong / Advanced
An acceptable-use policy defines approved AI tools and prohibits entering CUI or sensitive data into public/consumer AI.
Approved enterprise AI tools with data-protection terms are provided, use is logged, and data-loss controls flag sensitive content.
AI use is governed against a recognized framework (e.g., NIST AI RMF), with data classification, monitoring, and regular review of tools and prompts.
Implementation timeline
- Publish an interim rule: no CUI or sensitive data in public AI tools
- Identify which AI tools staff are already using
- Choose approved enterprise AI tools with acceptable data terms
- Write and communicate an AI acceptable-use policy
- Route AI access through managed accounts and log usage
- Extend data-loss prevention to flag sensitive content heading to AI
- Align governance to the NIST AI RMF
- Train staff on what may and may not go into AI tools
Implementation steps
- Inventory the AI tools already in use — including browser extensions and embedded assistants.
- Decide which tools are approved and require enterprise terms that prohibit training on your data.
- Publish an AI acceptable-use policy that classifies what data may and may not be entered.
- Provide sanctioned tools so staff have a compliant option, and route access through managed identities.
- Log AI usage and extend data-loss prevention to detect CUI or sensitive data heading to AI services.
Validation
- Confirm the approved AI tools' terms prohibit using your data for training.
- Test that a data-loss rule flags a document marked CUI when sent to an AI tool.
- Review usage logs for access to unapproved public AI services.
Evidence to retain
AI acceptable-use and data-classification policy
Approved-tool list with data-protection terms; DLP rules for AI
AI usage logs and review of unapproved-tool access
DLP test result and periodic tool/terms review
Common failure modes
A policy that bans AI while everyone quietly uses it anyway, approving a tool without reading its data-retention terms, and treating AI output as automatically safe or accurate. Prohibition without a sanctioned alternative just drives the risk into the shadows.
Framework mappings
Independent mappings are aids, not authoritative equivalence or compliance determinations.