Representative scenario — a composite of common engagements, not a specific client.

A defense contractor faced a tension its leadership could not ignore: engineers were quietly using public AI tools to move faster, and some of that work involved CUI. Banning AI outright had not worked — it just pushed the usage out of sight.

The challenge

The risk was not AI; it was egress. Every time CUI went into a consumer chatbot, it left the boundary and landed somewhere outside the contractor’s DFARS obligations — an uncontrolled data path no one was watching. But a hard ban was costing real productivity and losing the argument.

What we did

We gave them a sanctioned path instead of a prohibition. A gateway sits in front of any AI model and runs an accept/deny step: potential CUI is detected and flagged for a human to review before a prompt ever leaves the environment. We paired it with a clear AI-use policy and training that explained the why, so people had a fast, approved way to work.

The outcome

Shadow AI use dropped because there was finally a better option that kept CUI on their own hardware. We were candid about the limits — no filter is perfect, and the human reviewer is the real control — but the combination of visibility, a sanctioned path, and a human in the loop turned an ungoverned risk into a managed one.

See how we help teams govern AI use around CUI.