RatedWithAI

RatedWithAI

Accessibility scanner

AI Legal & ComplianceAugust 8, 2026

An Engineer Pasted a Drawing Into a Chatbot

Nothing was breached. Nobody was attacked. The vendor is reputable and the terms are enterprise-grade. The safeguarding clause still does not care, because it is written around where covered information went — not around whether the destination meant well.

Defense suppliers keep analysing AI adoption as a data-privacy decision. It is not. It is a contract-clause decision, and the clause was fully written before any of this tooling existed.

An external service that processes covered defense information must meet an established baseline, cooperate with incident obligations, and appear inside your assessed boundary. Those requirements are indifferent to how useful the tool is. The only real question is whether the tool you are already using clears them — and for the commercial tier of most AI products in 2026, it does not.

Five Obligations, and Where AI Hits Each

None of these obligations were drafted with language models in mind, which is exactly why they apply cleanly. Each states a requirement about information and systems, and AI tooling is simply another system once covered content reaches it.

01
Adequate security on covered systems

Implement the NIST protection requirements for controlled unclassified information on every system that stores, processes or transmits it.

An AI tool used on covered content becomes such a system. It then inherits access control, audit, media protection and configuration management requirements that a consumer subscription cannot evidence.

02
Cloud service equivalency

External cloud services handling covered defense information must meet security requirements equivalent to the FedRAMP Moderate baseline.

This is the clause that decides which AI offering you may use at all. Commercial tiers of major AI products generally do not carry it; government-community tiers exist for this reason and are a different contract, not a settings change.

03
Rapid incident reporting

Report cyber incidents affecting covered defense information within 72 hours of discovery, with media preservation and malicious software submission obligations attached.

Discovery is often a support ticket or a colleague's remark. The clock starts then, not when legal finishes deliberating whether a helpful vendor counts as an incident.

04
Flowdown to subcontractors

Include the safeguarding requirements in subcontracts where the subcontractor will handle covered defense information.

Small suppliers under deadline are where unapproved AI use concentrates, and the prime carries the consequence. Flowdown text without an affirmative attestation is a paperwork control.

05
Accurate assessment scoping

The assessment boundary must reflect where covered information actually lives and moves.

Undeclared AI tooling makes the boundary wrong. A scoping failure calls the entire assessment into question in a way that a single failed control does not.

The 72-Hour Clock Starts at Discovery

The most expensive mistake in this area is not the paste. It is the week spent deciding whether the paste counted. Reporting is triggered by an event with an actual or potentially adverse effect on covered information, and the obligation is deliberately fast — measured from discovery, which usually means the moment a colleague mentioned it, not the moment counsel reached a conclusion.

Deliberation feels prudent because the facts are unfamiliar: there is no intruder, no ransom note, no obvious harm. But the clause contemplates potential adverse effect precisely so that the contractor does not get to resolve that ambiguity in its own favour. Decide the policy now, while nothing has happened — write down that covered information reaching an unapproved external service is handled as a reportable event by default, with analysis running in parallel rather than in front.

Where the Assessor Finds It

Assessors do not ask whether you use AI. They establish the boundary from inventories, diagrams and data flows, then test against it — and undeclared tooling surfaces as a contradiction between what the documentation says and what the environment does. Every item below has been the thing that did not match.

What contradicts the boundary
  • Outbound network traffic from assessed endpoints to AI service domains that appear on no inventory.
  • Browser extensions and desktop assistants installed by individuals on machines inside the boundary.
  • AI features enabled by the vendor inside already-approved collaboration, ticketing and code platforms.
  • Code assistants indexing repositories that contain export-controlled or covered technical data.
  • Meeting transcription running on programme calls, producing a transcript store nobody classified.
  • Proposal and capture teams drafting against source documents that carry markings.

The third item deserves separate attention because nobody in your organisation causes it. Assistants and summarisation features are switched on by vendors inside platforms that already sit within an assessed boundary, routing content to processing that was never part of the authorised configuration. Treat a vendor-enabled AI feature as a configuration change subject to approval, even though the change did not originate with you — otherwise your baseline drifts on someone else's release schedule.

Flowdown Is Not a Control

Primes include the required clause in subcontracts and treat the obligation as discharged. It is not, because the risk concentrates exactly where the paperwork is weakest: a small supplier, under schedule pressure, with no security staff and a very helpful tool. The version of this that works is an affirmative attestation — a specific question about which AI services touch covered information, answered at award and refreshed annually, with a named individual behind the answer. It costs one email and converts an unknown into a documented representation you can act on.

What To Have In Place

An inventory of AI services in use, including features inside platforms you already approved. A written rule stating which tier of which service may touch covered information, with the equivalency documentation on file for anything approved. Blocking or monitoring for unapproved services on assessed endpoints, because a policy nobody can enforce is not evidence. Contract terms with any approved provider covering incident cooperation, media preservation and location of processing — not only training and retention. And a standing decision that unapproved destinations are treated as reportable, so the 72-hour clock is never spent debating.

Related Reading

Your Capability Pages Are Read During Source Selection

Compliance statements, certification badges and AI capability claims on your public site are checked by contracting officers and by competitors filing protests — and they age badly when a claim outlives the assessment behind it.

See every claim your site currently makes. Run a free scan and check each against your actual posture.

This article is general information and not legal advice. Contract clauses, assessment requirements and marking obligations vary by contract, agency and programme, and the applicable requirements are those in your award. Consult qualified government-contracts counsel and your assessment organisation before relying on any conclusion here.