Representative scenario — a composite of common engagements, not a specific client.
A defense contractor faced a tension its leadership could not ignore: engineers were quietly using public AI tools to move faster, and some of that work involved CUI. Banning AI outright had not worked — it just pushed the usage out of sight.
The challenge
The risk was not AI; it was egress. Every time CUI went into a consumer chatbot, it left the boundary and landed somewhere outside the contractor’s DFARS obligations — an uncontrolled data path no one was watching. But a hard ban was costing real productivity and losing the argument.
What we did
We gave them a sanctioned path instead of a prohibition. A gateway sits in front of any AI model and runs an accept/deny step: potential CUI is detected and flagged for a human to review before a prompt ever leaves the environment. We paired it with a clear AI-use policy and training that explained the why, so people had a fast, approved way to work.
The outcome
Shadow AI use dropped because there was finally a better option that kept CUI on their own hardware. We were candid about the limits — no filter is perfect, and the human reviewer is the real control — but the combination of visibility, a sanctioned path, and a human in the loop turned an ungoverned risk into a managed one.