AI and CMMC Compliance

AI is boosting productivity, but breaking your CMMC compliance?

If your team is using AI tools to handle project data or generate code, you might be accidentally stepping into a regulatory minefield.

In this quick 4-minute video, Kyle Lai, President and CISO at KLC Consulting, breaks down key requirements assessors look for when assessing AI environments:

  • The FedRAMP Rule: Why your AI cloud service provider must meet strict FedRAMP standards if handling CUI.
  • Tracking & Accountability: How to treat AI like an employee (with its own user ID and monitoring).
  • Control Enforcement: What alerts, safeguards, and incident response steps need to be in place if an AI tool behaves unexpectedly.
  • The “Free Version” Trap: Why using free AI tools can trigger a data leak and a mandatory incident report to the DoD.
  • The 60% Risk: How AI-generated code introduces major vulnerabilities, and whose job it is to fix them.

Don’t let a smart tool cause an expensive compliance failure.

Some key CMMC requirements:

If hosted by a Cloud Service Provider (CSP), does it have a FedRAMP Authorization to Operate (ATO) or equivalent?
 

Does the AI tool operate under a unique user or service account, and is its activity logged and monitored?
 
 

If the AI behaves unexpectedly, are standard access controls and safeguards enforced on AI identities the same way they are for human users?

What controls are in place to prevent CUI from being used in public or external model training?
 
 
 

If AI is used to generate code, is there a defined software security and vulnerability management program in place?
 
 

This video and transcript feature Kyle Lai, President and CISO at KLC Consulting, discussing CMMC compliance requirements for organizations using AI tools in CUI environments: AI and CMMC Compliance

Hi, my name is Kyle Lai, President and Chief Information Security Officer at KLC Consulting. Today we are going to talk about AI and how it impacts the CMMC compliance. As a CMMC lead assessor, these are the core requirements that we look for before we start assessing an AI tool.

Kyle Lai  0:28  

If you have an AI tool that is handling CUI, meaning stores, processes, or transmits CUI, then we will verify to see if the AI tool is provided by a cloud service provider. If it is, then we have to ensure that cloud service provider either has a FedRAMP authorization or equivalency. 

Kyle Lai  0:57  

Second one is to make sure that AI tool has an identity, and we are tracking the accountability, meaning AI needs to have a user ID or service account. Whatever AI is doing within your environment, it has to be tracked and monitored. If it’s not been tracked or monitored, you will not understand what AI tool is doing within your environment. 

Kyle Lai  1:26  

Another thing is that you have to set up the alerts right now. You know you have the monitoring and the logging. You also need to set up the alerts and be able to set up these safeguards when something happened, does it alert you or does it actually shut down the AI? So these are the things that you have to make sure that you have set up, and if it starts misbehaving, do you have an incident response plan? 

Kyle Lai  1:55  

And also data protection, make sure that all the information you provide to AI stays within your CUI environment. It doesn’t go out, it doesn’t get leaked to a public or external model for training purpose. Make sure that you have the private instance, don’t use the free version, otherwise there will be a leak, and you will have to deal with an incident response, they have to report the incidents to DoD.

Kyle Lai  2:27  

Secure code generation. A lot of software developers, they use AI to generate code. Developers, when they provide information to AI tools to generate these codes, the information provided to AI could be CUI, the control unclassified information, and that means sometimes the code it generates could be control unclassified information as well, so you need to make sure that the information, the prompts, the specifications that you provide to AI, they’re protected. If it’s in the AI short term or long term memory, you have to understand where that information is stored. If it’s long term memory, you have to understand how long it will be kept. Right, is actually meeting your retention policy as well, and also make sure the code is functional. AI may or may not think the code they generate is secure, or may not care if the code it generates is secure. So, it is the responsibility of the software developers to make sure that code generated are secure, there is an industry report mentioning AI-generated code introduced 60% more vulnerabilities, so it is important to make sure that all the codes generated by AI are scanned for vulnerabilities and vulnerabilities are resolved by the software developers. 

Kyle Lai  4:04  

If you have AI tools in your environment, and you want to learn more about how to comply with CMMC requirements, go to our website.

click here to close

Want to Know How Much a CMMC Assessment Costs?

Check out our YouTube channel and LinkedIn pages for the latest informational and educational resources for Cybersecurity Maturity Model Certification.

Lessons from Real CMMC Assessments Webinar

Scroll to Top