Every compliance team we talk to wants two things that look like they are in tension: use modern AI to move faster, and keep Controlled Unclassified Information inside their boundary. The default answer the market offers is ‘pick one.’ It is a false choice — and understanding why is the key to using AI without creating a CUI problem.
The real risk is not AI — it is egress
When someone pastes CUI into a public chatbot, the issue is not that they used a language model. It is that CUI left the boundary and landed in a third party’s cloud, outside your control and outside your DFARS 252.204-7012 obligations. The risk is data movement, not the tool.
The architecture that resolves it
The pattern that lets you keep both is a sanitization gateway that sits in front of any AI model. Before a prompt leaves your environment, it runs an accept/deny gate: potential CUI is detected and flagged for a human to review, and nothing goes out until a person decides. Your data stays on your hardware; you decide what, if anything, ever leaves.
Be honest about the limits
Here is the part most vendors will not say: no automated filter catches everything. Anyone selling a ‘leak-proof’ or zero-miss promise is selling you a liability. The control that makes this safe is not a perfect filter — it is a human in the loop and a boundary that holds. Detection narrows what a reviewer has to look at; the reviewer makes the decision.
What to ask a vendor
- Where does my data physically sit when the AI does its work?
- What happens to a prompt before it leaves my boundary — is there a review step, or is it trust-and-hope?
- Are you promising your filter is airtight, or offering to put my people in the loop? The honest answer is the second one.
Sovereignty is not a slogan — it is where your CUI sits when the work gets done. See how we help teams govern AI use around CUI.