Every compliance team we talk to wants two things that look like they are in tension: use modern AI to move faster, and keep Controlled Unclassified Information inside their boundary. The default answer the market offers is ‘pick one.’ It is a false choice — and understanding why is the key to using AI without creating a CUI problem.

The real risk is not AI — it is egress

When someone pastes CUI into a public chatbot, the issue is not that they used a language model. It is that CUI left the boundary and landed in a third party’s cloud, outside your control and outside your DFARS 252.204-7012 obligations. The risk is data movement, not the tool.

The architecture that resolves it

The pattern that lets you keep both is a sanitization gateway that sits in front of any AI model. Before a prompt leaves your environment, it runs an accept/deny gate: potential CUI is detected and flagged for a human to review, and nothing goes out until a person decides. Your data stays on your hardware; you decide what, if anything, ever leaves.

Be honest about the limits

Here is the part most vendors will not say: no automated filter catches everything. Anyone selling a ‘leak-proof’ or zero-miss promise is selling you a liability. The control that makes this safe is not a perfect filter — it is a human in the loop and a boundary that holds. Detection narrows what a reviewer has to look at; the reviewer makes the decision.

What to ask a vendor

  • Where does my data physically sit when the AI does its work?
  • What happens to a prompt before it leaves my boundary — is there a review step, or is it trust-and-hope?
  • Are you promising your filter is airtight, or offering to put my people in the loop? The honest answer is the second one.

Sovereignty is not a slogan — it is where your CUI sits when the work gets done. See how we help teams govern AI use around CUI.