Here’s the honest answer up front: there is no single, finalized “AI compliance requirement” for defense contractors yet. But there are two things that are true right now, today, regardless of that fact, and most contractors are getting at least one of them wrong.
First: the CMMC and CUI rules already in effect today already govern how your organization can use AI tools, whether or not anyone calls it an “AI compliance framework.” Second: a new statutory mandate is actively being built that will formalize AI-specific security requirements as an extension of CMMC, and the Department of Defense owes Congress a status report on it by June 16, 2026, essentially right now, as this is being written.
This is what’s settled, what’s coming, and what your organization needs to do regardless of which category each piece falls into.
What’s Already True Today, Even Without a Dedicated AI Framework
This is the part most contractors miss, because they’re waiting for a clearly labeled “AI compliance rule” to tell them what to do. That rule doesn’t exist yet. The rules that already apply to AI usage do.
Under the CMMC rules already in effect, a “CUI Asset” is anything that processes, stores, or transmits Controlled Unclassified Information. When an employee pastes a paragraph from a CUI document into a commercial AI chatbot, that service is now processing CUI, and the CMMC Level 2 scoping guide treats it as an External Service Provider within your assessment boundary, subject to the same controls as any other system that handles CUI.
That single fact has sweeping practical consequences. Under DFARS 252.204-7012, any cloud service provider that processes, stores, or transmits CUI must meet FedRAMP Moderate authorization at minimum, and tools like ChatGPT, Claude, Gemini, Grammarly, and GitHub Copilot generally don’t carry the FedRAMP authorization necessary for CUI. That means a meaningful share of the AI tools your employees are likely already using, sometimes with full organizational knowledge, sometimes not, may already put your CMMC posture at risk today, independent of any forthcoming AI-specific rule.
The most common finding related to AI tools is undocumented usage, employees using these services for CUI-related tasks without the organization’s knowledge or documentation. That gap, more than any future regulation, is the most immediate AI compliance risk facing defense contractors right now. Oneupsec
There’s a legal dimension here that deserves direct attention, not a footnote. If your organization submits a CMMC self-attestation while employees are sending CUI to non-FedRAMP-authorized AI services, you’re asserting compliance you don’t actually have, and that is False Claims Act territory. This isn’t a hypothetical future risk tied to AI-specific rules that haven’t been written yet. It’s a present-tense exposure tied to rules that have applied for years.
What’s Coming: The NDAA Section 1513 Framework
The National Defense Authorization Act for Fiscal Year 2026 directs the Department of Defense to develop and implement a framework addressing the cybersecurity and physical security of artificial intelligence and machine learning technologies acquired by the Pentagon. This is the provision most coverage of “AI and CMMC” is actually discussing, and it’s important to understand exactly what it does and doesn’t do yet.
What it requires. Section 1513 directs the DoD to incorporate this framework, once developed, into the Defense Federal Acquisition Regulation Supplement (DFARS) and the CMMC program, specifically to ensure that contractors developing, deploying, storing, or hosting AI/ML for the DoD comply with it. A companion provision, Section 1512, separately establishes a DoD cybersecurity policy for AI/ML that must address threats specific to AI, model tampering, jailbreaks, adversarial prompt injection, and create standards for testing and monitoring AI/ML systems against corruption or manipulation.
Who it will apply to. The security requirements will apply to “covered entities”, defined as entities entering into contracts or agreements with the DoD for the development, deployment, storage, or hosting of covered AI/ML, where “covered AI/ML technology” includes source code, model weights, training data, algorithms, and the software used to evaluate whether the AI is trustworthy.
How it will be built. This is the genuinely good news in an otherwise uncertain picture. The framework must be informed by established standards, including the NIST Special Publication 800 series, and must be implemented as “an extension or augmentation” of existing DoD cybersecurity frameworks, including CMMC, not as a separate, parallel compliance track. If you’re already working toward CMMC compliance, the groundwork you’re laying applies here too.
What’s still genuinely unknown. Section 1513 does not provide an implementation deadline for the framework or security requirements, it instructs the DoD to create a plan establishing implementation timelines and milestones and to provide a status update to Congress by June 16, 2026. That date is close enough to this article’s publication that the specifics may shift quickly. While specific deadlines await that DoD status update, the broader CMMC enforcement that began in November 2025 makes proactive preparation the right move regardless of how Section 1513 specifically resolves.
Where NIST AI RMF Fits In
The NIST AI Risk Management Framework is not itself a DoD mandate, and it carries no certification or enforcement mechanism on its own. But it’s positioned to become the connective tissue between today’s CMMC requirements and whatever Section 1513 eventually formalizes.
The NIST AI RMF gives DoD contractors a common language to govern AI risk while aligning with NIST SP 800-171 and CMMC Level 2, use it to set policy, scope data flows, and document controls that withstand assessor review. The AI RMF’s functions map cleanly to 800-171 control families.
That mapping matters because AI RMF is a risk management framework for AI systems, while CMMC Level 2 and the 800-171 controls remain mandatory for protecting CUI, use AI RMF to govern how you manage AI risk, and use the 800-171 controls to actually secure the systems and data. They’re complementary rather than competing: NIST AI RMF gives you the governance structure; CMMC gives you the binding requirement you have to satisfy regardless.
The practical advice that holds up regardless of how the policy layer shifts: anchor your AI compliance work on the durable artifacts, the NIST AI RMF, NIST SP 800-53, NIST SP 800-171, and the specific contract language in front of you, rather than trying to track every executive order or NDAA provision in real time. Those foundational documents change far less often than the political layer sitting on top of them.
The Practical Risk Most Contractors Have Right Now
Strip away the policy uncertainty, and there’s a concrete, actionable risk picture that applies to virtually every defense contractor today, regardless of how Section 1513 resolves.
AI is now embedded in core defense mission systems, acquisition planning, and contract administration, and the legal, compliance, and contractual risks that follow are fast-growing and consequential, capable of derailing performance, generating False Claims Act exposure, or disqualifying proposals. “AI contracting” is not a separate category of procurement, it’s a convergence of existing defense procurement rules, applied to a technology that is notoriously difficult to define, audit, and control. fedramp
A few specific technical realities compound this. Contractors building or fine-tuning models in commercial cloud environments, including AWS GovCloud or Azure Government, should understand that the cloud enclave itself may need to be scoped within their CMMC assessment boundary, not simply the endpoint systems accessing it. AI-generated outputs also present a CUI propagation problem few contractors have operationalized: where a model is trained on CUI, its outputs, summarizations, pattern extractions, derived analyses, may themselves constitute CUI requiring the same marking, handling, and protection obligations as the underlying data. The absence of policy guidance on this point does not eliminate the obligation. fedramp
There’s also a data rights dimension that’s easy to overlook entirely. The DFARS 252.227-7013 and 7014 framework was not designed for AI, the statutory categories of “computer software” and “technical data” apply with difficulty, and sometimes not at all, to model weights, embeddings, and outputs generated through techniques like reinforcement learning from human feedback. Contractors should not assume their existing data rights posture maps cleanly onto an AI development effort. fedramp
What to Do Right Now, Regardless of Where Section 1513 Lands
The contractors who handled CMMC well didn’t wait for the final rule to start building. The same logic applies here, and arguably more urgently, since the present-day False Claims Act exposure is real today.
Inventory every AI tool actually in use. Catalog all AI tools including browser extensions and personal accounts, classify CUI exposure for each, and remove non-compliant tools from sensitive workflows before your next assessment. This needs to include tools employees adopted informally, the undocumented usage problem is consistently the most common finding in this space.
Treat AI tools as scoped systems in your SSP, not invisible ones. Your C3PAO will ask about AI tools during your CMMC assessment if they appear in your SSP, interviews, or system inventory. Be prepared to identify every AI tool in use and demonstrate that CUI cannot flow to AI tools outside your assessment boundary through technical controls, with audit logs showing AI system access and usage, and a documented policy on AI tool usage.
Build an AI governance policy now, not after the framework is finalized. Documentation requirements are expanding regardless of Section 1513’s specific outcome, System Security Plans must detail AI implementations, policies need explicit AI-specific coverage, and continuous monitoring is increasingly expected to replace periodic compliance checks.
Use the NIST AI RMF’s structure to organize that policy. Since the eventual DoD framework is statutorily required to build on NIST’s 800 series and extend CMMC rather than replace it, structuring your governance now around AI RMF’s Govern/Map/Measure/Manage functions means you’re building toward where the requirement is headed, not away from it.
Review data rights language in any AI-related contract or SOW. Given how poorly existing DFARS data rights clauses map onto model weights, training data, and AI-generated outputs, this is a place where legal review now is meaningfully cheaper than a dispute later.
Track the June 2026 DoD status update and beyond, but don’t wait for it to act. The specifics of Section 1513’s framework will start coming into focus once DoD reports to Congress, but the underlying CMMC and CUI obligations that already apply to AI tool usage are not contingent on that report.
Where RSI Security Fits
RSI Security helps defense contractors assess how AI tool usage intersects with their existing CMMC and CUI obligations, build governance structures aligned to the NIST AI RMF, and prepare for the AI-specific requirements that will extend from Section 1513 as they’re finalized.
As an authorized C3PAO, we conduct CMMC Level 2 certification assessments directly, and our readiness and remediation teams help organizations close AI-related gaps in their SSP and control documentation before that assessment happens. Because Cyber AB rules require strict separation between advisory and assessment functions, those teams operate independently from our certification practice.
If your organization needs to understand its current AI-related compliance exposure under existing CMMC rules, or wants to build governance ahead of the Section 1513 framework rather than scrambling once it’s finalized, [schedule a CMMC and AI readiness consultation] or [download the Unified Federal Compliance Roadmap].
Frequently Asked Questions
Is there a specific AI compliance framework required for defense contractors right now?
Not yet, formally. The National Defense Authorization Act for Fiscal Year 2026 (Section 1513) directs the Department of Defense to develop a dedicated AI/ML security framework as an extension of CMMC, but no implementation deadline has been set, and DoD owes Congress a status update on timelines by June 16, 2026. However, existing CMMC and CUI handling rules already govern how AI tools can be used today, independent of this forthcoming framework.
Does CMMC already apply to AI tools, even without an AI-specific rule?
Yes. Under current CMMC Level 2 scoping rules, any AI tool that processes, stores, or transmits Controlled Unclassified Information is treated as an asset within the assessment boundary, subject to the same controls as any other system handling CUI. Most popular commercial AI tools do not carry the FedRAMP authorization required for CUI handling, which means unmanaged AI tool usage can already create CMMC compliance gaps today.
What is the NIST AI RMF’s role for defense contractors?
The NIST AI Risk Management Framework is a voluntary risk management structure, not a DoD mandate, but it’s expected to inform the forthcoming AI security framework required under NDAA Section 1513, since that framework is statutorily required to draw on NIST’s published standards. Contractors can use the AI RMF’s Govern, Map, Measure, and Manage functions to organize AI governance now in a way that aligns with both current CMMC requirements and the framework still being developed.
What happens if an employee uses an AI tool with CUI without authorization?
This creates immediate compliance risk under existing rules. If an organization submits a CMMC self-attestation while CUI is being processed by AI tools that don’t meet required security standards, that organization may be asserting compliance it doesn’t actually have, which can create False Claims Act exposure. The most common finding in this area is undocumented AI tool usage that the organization wasn’t tracking.
When will defense contractors know the specific AI compliance requirements they need to meet?
The Department of Defense is required to provide Congress a status update on implementation timelines and milestones for the Section 1513 AI security framework by June 16, 2026. The framework itself has no statutory implementation deadline yet, so contractors should expect the specific requirements to develop further over the coming months rather than arrive all at once.

