Essex Junction, VT802-335-2662dkoran@davidkoran.com
DK
David Koran& Associates

AI in Defense Manufacturing: a management framework for governed AI deployment under CMMC, DFARS, and export controls.

This white paper is a staged management plan for deploying artificial intelligence in a defense manufacturing business, written for the owners and executives of small and midsize defense manufacturers. Its premise runs through every section: the shop runs on regulated information, so every AI deployment decision is a data routing decision, and the plan deploys in stages ordered by data class, banking the low-risk wins first, reviewing the business systems second, and answering the CUI and export control questions with documented analysis rather than hope. Published August 2026. Free PDF, no registration.

Inside the Paper

The plan, staged by data class

  • The five kinds of AI, by where the data goes
  • Stage One: the low-risk wins, deployed promptly under controls
  • Stage Two: business systems, the tool review, and the FCI line
  • Stage Three: the CUI question, the SSP work, and the audit account
  • Export-controlled technical data and the questions for counsel
  • The plan run at a 50-person shop across three quarters
The Paper

Written for the executives who signed the representations.

Defense manufacturers face the same AI pressure as every other business, from employees, from vendors embedding features, and from primes, customers, and carriers asking questions in writing, with one difference that changes everything: the business runs on Federal Contract Information, Controlled Unclassified Information, and export-controlled technical data, and the company has already made promises about how that information is handled, in the SSP, in SPRS, and on every questionnaire it has answered. An unreviewed AI service touching the wrong data quietly falsifies those representations. This paper is the plan for deploying AI without that happening.

The plan opens by defining the five kinds of AI by the only distinction management has to hold, where the data goes, then deploys in three stages ordered by data class: the low-risk wins first, under organizational accounts and a working policy; the business systems second, under a tool review that respects the FCI line; and the CUI-adjacent uses last, through a documented analysis whose three legitimate outcomes include the decision not to deploy. Export-controlled technical data receives its own treatment, the audit and SSP consequences of Stage Three are priced honestly, and the whole plan closes with a 50-person precision manufacturer running it across three quarters, ending with the fall insurance renewal answered from the files. It is a companion to How to Build an AI Governance Program, arranged for the realities of a defense manufacturing business.

Contents

What the paper covers.

Ten sections, from the data classes to the worked example.

Sections 1 and 2

Why a defense shop is different, and the five kinds of AI

The four regulated information classes, the representations an unreviewed tool falsifies, a dated note on CMMC Phase 1, and the delivery-model taxonomy: public consumer services, business tiers, embedded features, government-focused environments, and locally operated models, each mapped by where the data goes.

Sections 3 and 4

The staged plan and the data map

The two axes that govern every deployment, data reach and operational consequence, the three stages in one table, the management mandate that precedes them, and the mapping pass that establishes where regulated, proprietary, personal, and privileged information actually lives.

Section 5

Stage One: the low-risk wins

What deploys promptly and why it should: governed value first, the plainest rule in the plan stated in words nobody can misread, and the training hour that reaches the employee before the consumer chatbot does.

Section 6

Stage Two: business systems and the tool review

The review for each tool and embedded feature, data handling and training terms, what certifications actually prove, the contract terms that matter, and the division that carries regulatory weight: Two-A for business information, Two-B where a tool processes, stores, or transmits FCI under FAR 52.204-21.

Sections 7 and 8

Stage Three: CUI, and the export control question

The safeguarding analysis, the cloud service provider path with the FedRAMP terminology transition explained, the non-cloud ESP path into the SSP and assessment scope, the local model option priced honestly, the audit account an AI capability must be able to give of itself, and the export analysis that belongs with counsel.

Sections 9 and 10

The floor rules, and the plan at a 50-person shop

The policy, training, output, and change controls that run at every stage, and the worked example: three quarters at a precision manufacturer, from the data map through the suspended document search feature to the insurance application answered from the files.

Every claim is hyperlinked to its canonical source: NIST SP 800-171 in both current revisions, DFARS 252.204-7012, FAR 52.204-21, the NIST AI publications, the ISO standard, the FedRAMP Consolidated Rules announcement, and the eCFR subchapters for ITAR and the EAR. The paper follows the same practitioner standard as the rest of this site's library: cited sources, free PDF, and no sales material.
The Questions It Answers

The questions defense manufacturers are asking, answered briefly.

Can AI tools touch CUI?

Only after a safeguarding and boundary analysis under NIST SP 800-171 and DFARS 252.204-7012, and most commercial cloud AI services cannot currently make the commitments that analysis requires. The realistic options are a government-focused environment evaluated as a cloud service provider, a locally operated model inside the existing boundary with the SSP work that entails, or a documented decision not to deploy, which the plan treats as a fully legitimate outcome. The paper's Stage Three section carries the full analysis.

Can our employees use public AI chatbots?

For public and approved low-sensitivity internal information, under organizational accounts and a working AI use policy, yes, and Stage One of the plan deploys exactly that promptly. CUI, FCI, and export-controlled technical data never enter a public generative AI chatbot or any tool under a personal account, whatever the deadline. The paper states this as a first-day rule, because the most common AI violation in a defense shop is an employee pasting controlled information into a consumer chatbot to save an afternoon.

Does DFARS 252.204-7012 apply to AI services?

When a service processes, stores, transmits, summarizes, indexes, or generates output from covered defense information, yes. A cloud AI service is evaluated as a cloud service provider whose specific offering must meet security requirements equivalent to the FedRAMP Moderate baseline, the language the clause still uses even as the FedRAMP program transitions to certification Classes A through D, and a non-cloud provider processing CUI is documented in the SSP and included in the assessment scope.

What does deploying AI do to our SSP?

AI in the CUI environment is a material change to the system the SSP describes: the boundary and data flow diagrams gain the inference path, the component inventory gains the model and its dependencies, the affected implementation statements are revisited, auditable events are defined for the capability, derived data such as embeddings built from CUI is handled as CUI, and the changed environment is reviewed against the current assessment and affirmation basis before the next score is relied on.

What about ITAR technical data?

Export-controlled technical data raises a separate analysis from CUI: where processing occurs, who can access decrypted content, who controls the keys, and whether the arrangement satisfies an applicable authorization, exemption, or exception. An AI service generally must decrypt content to process it, which makes the provider's architecture directly relevant, and the paper's guidance is plain: no AI tool touches export-controlled data before export counsel reviews the specific arrangement.

Do the AI features our vendors keep adding need review?

Yes, and they are the entry path employee-facing rules cannot see: features arrive through routine updates, often enabled by default, with no procurement review. The plan's standing posture is that new AI features default to disabled or restricted until reviewed, staged by the data in the host system, with named ownership of release notes and administrative consoles. The paper's worked example includes the moment this catches: a document search feature found indexing an FCI drive.

Download

Read the paper.

The white paper is available as a free PDF with no registration: AI in Defense Manufacturing: A Management Framework for Governed AI Deployment Under CMMC, DFARS, and Export Controls (August 2026). It joins How to Build an AI Governance Program in the GRC for AI white paper series, and the reference pages of the AI governance cluster carry the maintained analysis behind it, alongside the site's CMMC services and Defense Industrial Base research library. New papers are announced through the Daily Cybersecurity Brief.

Download the PDF →

Get In Touch

Discuss AI Deployment in Your Shop

Inquiries may involve any stage the paper covers: the data map, the Stage One rollout and policy, the Stage Two tool reviews and the FCI line, the Stage Three CUI and boundary analysis, or the SSP and audit work an AI deployment carries. Call, email, or send a note. I respond personally to every inquiry, usually within one business day.

Address
Essex Junction, VT
Travel
I travel to client sites nationally.

Discuss an Assessment

If the paper raises a question about what AI can deploy in your shop, what it would do to your SSP and your representations, or where to start, the first conversation carries no commitment and no pitch.

Discuss an Assessment →