Your team's already using AI. That isn't a guess.
Somebody pasted contract language into ChatGPT this week to get a summary out of it. Somebody else let an assistant draft a proposal section off context sitting on their desktop. And somewhere in there Controlled Unclassified Information left the building, quietly, invisibly, without a single security alert firing. (Greypike)
That's not a hypothetical whispered around compliance circles. It's the documented daily reality of the Defense Industrial Base in 2025, and the contractors it's happening to don't know they've got a problem until they're across the table from a C3PAO assessor asking them to walk through their data handling. AI tools are genuinely productive and I'm not going to pretend otherwise. But "productive" and "compliant" aren't the same word, and in defense contracting, confusing them costs contracts, certifications, clearances, and under the False Claims Act, a good deal more than that.
What ITAR and DFARS Require
Here's what ITAR and DFARS require, stated plainly. The International Traffic in Arms Regulations, enforced by the State Department's Directorate of Defense Trade Controls, govern the manufacture, sale, distribution, and export of any item on the United States Munitions List. Civil penalties run up to $1,271,078 per violation or twice the value of the transaction, whichever's greater, and criminal penalties can reach $1 million per violation with up to twenty years imprisonment. (PreVeil) Those aren't ceiling numbers somebody invented for a slide. They're per violation, and violations don't tend to arrive one at a time.
DFARS, the Defense Federal Acquisition Regulation Supplement, adds the cybersecurity layer. The CMMC 2.0 program, which became effective December 16, 2024, established three tiers of cybersecurity requirements requiring Defense Industrial Base contractors to do more than simply self-attest to compliance with long-established cybersecurity requirements. (Goodwin) Phase 1 of contractual enforcement began November 10, 2025. Phase 2, requiring third-party CMMC Level 2 certification for most contractors handling CUI, kicks in November 10, 2026. (Pivot Point Security)
That clock's running whether anybody's watching it or not, and it's the subcontractors who'll feel it first.
How It Happens, Every Single Time
The intersection of AI and these frameworks is where companies are hurting themselves right now, and it happens in the most banal way imaginable. Somebody's on a bid response and they're behind. They open ChatGPT, paste in a section of a contract document to clean up the language, hit enter. That document carries Controlled Unclassified Information. Inside five seconds it's been transmitted to a commercial cloud environment that almost certainly isn't authorized under the company's CMMC boundary. (Openapproach) Nobody meant anything by it. That's rather the point.
Compliance with ITAR in a cloud-first, AI-driven world is evolving. Shared files, cloud storage access, collaboration tools, and AI prompts can all trigger unauthorized exports of controlled technical data. (Concentric AI) Cloud AI providers with international data centers or foreign national employees may create ITAR compliance risks directly (Iternal Technologies), because ITAR doesn't only regulate what your people do with controlled data. It regulates who's allowed to touch it at all.
The platform your team's using almost certainly employs people outside the United States with access to the infrastructure that processes those prompts. That's a deemed export problem. That's an ITAR problem. Meanwhile your empowered official has spent years making jurisdiction and classification calls on individual drawings, USML category or ECCN, screening parties, filing in DECCS. Nobody asked them about the chat window. Your FSO didn't get a ticket about it and your ISSM didn't see an alert, and most small and mid-sized contractors haven't thought about it once.
The Enforcement Environment
In October 2024, DOJ and SEC announced settlements with Raytheon Company over AECA and ITAR violations, totaling more than $950 million, one of the largest joint settlements in recent years. (Venable LLP) That's Raytheon. A prime with armies of compliance officers and decades of institutional experience navigating these frameworks. Nobody's grading the smaller companies on a curve.
On May 1, 2025, Raytheon and related companies agreed to pay an additional $8.4 million to resolve False Claims Act allegations that they submitted claims falsely certifying compliance with cybersecurity requirements in contracts and subcontracts with DoD, specifically because the company failed to implement required controls on an internal development system used to perform unclassified work. (ConsensusDocs) Unclassified work. An internal dev system. That's how narrow the target gets.
Then in December 2025, the DOJ announced its first settlement targeting the defense supply chain when a precision machining subcontractor agreed to pay approximately $421,000 to resolve allegations that it failed to provide adequate cybersecurity protections for technical drawings supplied to prime contractors. The case originated as a qui tam action filed by a former quality control manager. (Holland & Knight)
That's the one I'd sit with. A machine shop. A former employee who knew exactly where things were kept. A whistleblower statute that pays out handsomely. This is the environment you're operating in, and it's got informants in it who used to work down the hall.
What an Honest Self-Assessment Looks Like
It doesn't start with AI. It starts with your data.
You've got to identify every AI tool in the environment, including the commercial assistants employees are running on work devices, and categorize them by whether they're deployed on-premise, in a private cloud, or in a commercial cloud. Then determine whether they can access, process, or store CUI. If the answer's yes, look at whether the tool's backend is authorized by the FedRAMP program to process CUI. (Washington Technology)
One instance of CUI entering a non-compliant system creates a CUI spillage requiring immediate incident response, and once CUI enters a non-compliant system you cannot undo the exposure. (VSO) There's no unsending it. Ask anybody who's run a spillage response and lost a week of a program to it.
From there your System Security Plan has to document every AI tool identified as an in-scope asset. Your acceptable use policy has to define which tools are authorized, which categories of information are forbidden from entering any AI tool at all, and what the approval process looks like for adding a new one. Then you train your people, because abstract policy without context doesn't change behavior, and the engineer pasting a drawing into a chat window at eleven at night isn't reading your SSP.
Meanwhile the NDAA directs the DoD to incorporate an AI/ML security framework into DFARS and CMMC to ensure that contractors developing, deploying, storing, or hosting AI for DoD comply. The framework will apply to "covered" AI/ML, defined as AI acquired by DoD and all associated components, including source code, model weights, and the methods, algorithms, data, and software used to develop it. (Governmentcontractslegalforum) That definition's broad, and it's broad on purpose. Build any AI capability for a DoD customer and you're already inside the perimeter, whether your compliance program reflects that or not.
The Only Architecture That Clears These Frameworks
Public AI platforms do not provide the data handling, logging, or contractual protections required under DFARS and CMMC when handling CUI or export-controlled information. (Hdtech) So the only AI architecture that clears them cleanly is one you control physically, on infrastructure you own or operate inside a properly bounded environment. That kills the cloud transmission problem, the deemed export problem, the training ingestion problem and the FedRAMP authorization chase in a single move, and it leaves you with an audit trail you can hand an assessor where every action's identified, approved and logged. That's an architecture argument, not a product one, and it's the same argument whichever framework you're bound by.
Now the honest part, because I'd rather say it than have you find it out in an assessment. Hardware is one component of a compliant program rather than compliance itself, and it won't write your SSP, work your POA&M, or defend your SPRS score for you. A contractor that signs an annual CMMC affirmation without verifying the accuracy of its compliance status, or that ignores known gaps, may be accused of acting with reckless disregard sufficient to establish False Claims Act liability. (Holland & Knight) No box on a rack saves you from that. What owning the box does is make the AI portion of that affirmation provable instead of argued.
You can't certify with a straight face while your engineers are prompting a commercial chatbot with design specifications. And you can't hide the practice from a motivated whistleblower, either.
What I Won't Recommend Until I've Watched You Work
Here's where a vendor hands you a boundary diagram out of a catalogue. I don't have one for you, and I wouldn't know what to put on it yet.
I don't know how your FSO and your ISSM divide the work, or which of the 110 NIST SP 800-171 controls your compliance analyst is still assembling evidence for out of ticketing, MDM, AD and scanner exports so the SPRS score stays defensible. I don't know which clauses your contracts administrator is flowing down to which subcontractor tier off a solicitation's clause matrix, or what your configuration and data management specialist does to keep every CDRL tracked against its DID and its DD 1423 delivery schedule. I don't know which volume your proposal manager rebuilt at two in the morning because Section L and the page limits disagreed. Those people have run that work for fifteen or twenty years, it's gold to watch, and it barely lives in the documentation. Neither of us knows it all sitting here, and that's just how programs work, with no insult intended.
So the sequence runs backwards from how this normally gets sold. I show up, sit down next to them, and shut up until I understand the work the way they run it instead of the way the procedure describes it. Discovery turns up the use cases already sitting in the building. Only then do I recommend a stack, and what I recommend is whatever the work turned out to need, inside your boundary. Then we deploy and configure it together on site, and I onboard your team on the workflows and the agentic orchestration a defense program runs on, so the thing's still working a year after I've gone.
The window before Phase 2 closes in November 2026 is narrower than most people realize. The standard is no longer good faith effort. It is provable accuracy. (Mayer Brown) If you can't walk an assessor through your AI data flows, document your controls, and demonstrate that CUI never touched an unauthorized system, you don't pass. And failing that audit doesn't just cost you a certification. It costs you the contract, and potentially a whole lot more.
If you want to know what it'd look like in your shop, start there, and I'll come to you.