A machinist in your Sarasota shop pastes a customer drawing into ChatGPT to get help writing a tolerance callout. An engineer in Boston uploads a technical data package to a free AI tool because it formats a report faster than Word. A project manager in Tampa drops a spreadsheet full of contract line items into an AI chatbot to summarize it for a Monday meeting. None of these people think they did anything wrong. None of them told IT. And every one of them just moved data outside a boundary your System Security Plan claims to control.
This is shadow AI security in practice — not a hypothetical future risk, but something happening right now inside contractor environments that are supposedly locked down for CMMC. The tools involved aren’t malware. They’re consumer-grade AI assistants that employees adopted on their own because they’re genuinely useful, and because nobody built a sanctioned alternative fast enough to compete with “just paste it into ChatGPT.”
Where Shadow AI Actually Lives Inside a Defense Contractor’s Network
Shadow AI isn’t a single application you can block with one firewall rule. It’s a category of behavior spread across browser tabs, personal phones, and third-party plugins that IT never approved and often never sees. The free version of ChatGPT is the most visible example, but the same risk shows up in AI writing assistants embedded in Chrome extensions, transcription tools bolted onto video calls, AI-powered resume screeners HR downloaded without a procurement review, and code-completion plugins engineers installed in their IDE. Each one is a potential data exit point that sits outside the boundary your compliance documentation describes.
For manufacturing and engineering shops handling CAD files, revision histories, and bill-of-materials data, the exposure is particularly acute — a drawing pasted into a public AI tool for “quick formatting help” doesn’t stay on your network, and it doesn’t stay under your access controls once it’s gone. The same pattern plays out differently in finance functions handling CUI-adjacent contract data, but the mechanism is identical: a well-intentioned shortcut moves regulated information into a system nobody vetted.
![]()
Why ChatGPT and Similar Tools Are a CUI Problem, Not Just an IT Problem
The instinct is to treat shadow AI as a policy violation — something HR handles with a stern memo. That undersells what’s actually happening. When an employee submits text to a free-tier AI tool, that content typically leaves your controlled environment and lands on infrastructure owned by a company you have no contract with, no data processing agreement with, and no audit rights over. If that text contains Controlled Unclassified Information, you’ve had a disclosure the moment it was submitted — regardless of whether anyone ever looks at it maliciously.
The CUI Registry maintained by the National Archives defines dozens of categories that show up routinely in defense contractor environments: export-controlled technical data, procurement-sensitive information, and privacy data among them. None of those categories become safe to paste into a public chatbot just because the employee’s intent was to save time. The regulatory exposure exists independent of intent, which is exactly why this can’t be filed under general IT hygiene — it belongs in the same conversation as your access controls, your compliance program, and your incident response plan.
The Data Employees Actually Paste Into These Tools
The specific categories of information that end up in AI tools tend to follow a predictable pattern, and knowing the pattern is the first step toward controlling it.
- Technical drawings and specifications — engineers seeking a faster way to summarize a spec sheet, convert units, or draft a change order narrative
- Contract and pricing data — proposal writers using AI to reword sections of a statement of work, unaware the source document contains export-controlled figures
- Source code and configuration files — developers using AI coding assistants that transmit snippets to third-party servers for “smarter” autocomplete
- Personnel and HR records — managers drafting performance reviews or termination letters using an AI tool, inadvertently including names tied to cleared personnel
- Meeting transcripts — AI notetakers bolted onto video calls that capture and store full conversations, including anything discussed about a program or a customer
None of these behaviors are exotic. They’re the same shortcuts knowledge workers take everywhere — the difference for a defense contractor is that the data involved is frequently subject to DFARS flow-down requirements, and a single careless paste can turn into a reportable incident.
How Shadow AI Undermines CMMC and NIST SP 800-171 Compliance
CMMC assessors don’t ask whether you have a policy that prohibits pasting CUI into ChatGPT. They ask how you know it isn’t happening. That distinction matters because most contractors can produce a policy document in about five minutes and produce actual evidence of enforcement in approximately never.
NIST SP 800-171 requires organizations to control the flow of CUI, restrict it to authorized systems, and monitor for unauthorized transmission — and shadow AI usage cuts directly against all three requirements simultaneously. An assessor evaluating your System and Communications Protection controls is going to ask what prevents an employee’s browser from submitting data to an unmanaged AI endpoint, and “we told them not to” is not a control. It’s a suggestion.
This is where a lot of contractors discover their System Security Plan describes a boundary that no longer matches reality. Our insight on CMMC compliance going beyond the checklist covers this exact gap: documentation that looked complete during self-assessment can fall apart the moment an assessor asks for evidence of continuous monitoring rather than a point-in-time policy statement. Shadow AI is one of the fastest ways that gap gets exposed, because the tools are free, require no procurement approval, and leave almost no trace in traditional network logs unless you’re specifically watching for them.
The Difference Between Sanctioned AI Integration and Shadow AI
None of this is an argument against AI. It’s an argument against ungoverned AI. There’s a meaningful difference between an employee using a public chatbot on their own initiative and an organization deploying AI tools through a vetted, contracted, access-controlled process — and that difference is the entire ballgame from a compliance standpoint.
Properly scoped AI integration means selecting tools with enterprise data handling agreements, ensuring inputs aren’t used for model training, restricting which data categories can touch the tool at all, and logging usage the same way you’d log access to any other system that touches CUI. Done correctly, AI can genuinely accelerate the kind of work that eats hours — drafting, summarizing, first-pass code review — without creating an unmonitored data pipeline to a vendor you’ve never assessed.
We wrote about this trade-off in more detail in our guide to AI readiness for small businesses, which walks through the assessment questions that should happen before any AI tool touches production data — questions most organizations skip because the employee who found the tool wasn’t thinking about assessment, they were thinking about their deadline.
Detecting Shadow AI Usage Before an Assessor Does
Finding out shadow AI is happening in your environment shouldn’t require an assessor to find it for you. Most organizations already have the infrastructure to detect it — they’re just not looking in the right place. A properly configured DNS filtering and web content policy will show every attempt to reach known AI domains, which is often the first surprise: the volume of traffic to consumer AI tools is usually far higher than IT assumed before they checked.
Cloud access security broker tools go a step further, distinguishing between an employee viewing an AI vendor’s marketing page and actually submitting data through the interface. Endpoint detection tools can flag clipboard activity and large paste events into browser-based applications, which is often how the largest exposures happen — not a slow trickle of small queries, but one employee pasting an entire document at once. None of this requires exotic tooling; it requires treating AI domains the same way you’d treat any other unsanctioned SaaS category and building the monitoring into your existing cybersecurity stack rather than bolting it on as an afterthought.
The CISA Cybersecurity resource library is a useful baseline here — much of the guidance on shadow IT and unsanctioned SaaS applies directly to shadow AI, because the underlying problem is the same: data leaving a boundary through a channel nobody inventoried.
![]()
Building an Acceptable Use Policy That Employees Will Actually Follow
A policy that simply says “AI tools are prohibited” tends to fail for a predictable reason — it doesn’t survive contact with an employee’s actual workflow. If ChatGPT genuinely saves someone forty minutes on a task and the policy offers no sanctioned alternative, the policy loses. Not because employees are reckless, but because the incentive structure points the wrong direction.
An acceptable use policy that holds up needs three things a one-line prohibition doesn’t provide: a clear description of what data categories can never touch an AI tool of any kind, a list of sanctioned tools employees are permitted to use for lower-sensitivity tasks, and a straightforward path for requesting a new tool be evaluated rather than employees deciding on their own. Our breakdown of what a vCIO actually does touches on this same dynamic — a lot of contractors have policy documents that were written once and never revisited as the technology landscape shifted underneath them, and AI has shifted faster than almost anything else in the last two years.
Training matters as much as the document itself. Most employees pasting CUI into ChatGPT aren’t ignoring a rule — they’ve genuinely never connected “help me summarize this document” with “I am transmitting Controlled Unclassified Information to an unaudited third party.” Closing that gap is a training problem before it’s an enforcement problem, and it needs to happen before the next assessment cycle, not after a finding.
Technical Controls That Close the Gap
Policy and training reduce risk, but they don’t eliminate it — a determined or simply hurried employee will still find a workaround unless technical controls make the unsanctioned path harder than the sanctioned one. A layered approach tends to work best rather than relying on any single control.
- DNS and web filtering tuned to categorize and block known consumer AI domains at the network and endpoint level, not just on managed laptops but on any device touching company data
- Data loss prevention rules configured to flag or block outbound transmission of content matching CUI markings, contract numbers, or export-controlled keywords
- Browser isolation or managed browser policies that prevent copy-paste into unsanctioned web applications from systems handling regulated data
- Sanctioned AI alternatives deployed through enterprise agreements with contractual data protections, so employees have a legitimate outlet for the same productivity gains
- Regular access reviews that treat AI tool usage as part of the same audit cycle as any other application inventory
This is the same layered logic that underlies a mature managed IT services program generally — no single control is sufficient on its own, and the goal is making the compliant path the path of least resistance rather than relying entirely on employee judgment under deadline pressure.
What This Looks Like Across Boston, Tampa, and Sarasota Contractors
The shape of this problem shifts slightly depending on the kind of work a contractor does, but the underlying exposure is consistent across every market we serve. In Boston, where a dense cluster of advanced manufacturing and defense supply chain firms operate close to prime contractors, the risk tends to concentrate around technical data and engineering drawings moving through subcontractor tiers where oversight gets thinner the further you get from the prime.
In Tampa and Sarasota, we see it just as often in program management and back-office functions — proposal teams and finance staff who adopt AI tools to handle the administrative load of contract compliance, not realizing the documents they’re summarizing carry the same CUI restrictions as the technical data an engineer would handle. Our Managed IT in Boston guide and our Tampa and Sarasota provider guide both touch on why local context matters when a provider is building controls around how a specific contractor’s teams actually work, rather than applying a generic template.
A co-managed IT arrangement tends to be particularly effective here, because internal IT staff usually know exactly which departments are the most likely to reach for a shortcut tool — they just don’t always have the bandwidth or the specialized compliance expertise to build the monitoring and policy structure around that knowledge. Pairing that institutional awareness with dedicated compliance resourcing closes the gap faster than either side working alone.
What an Actual Incident Response Looks Like When Shadow AI Is Involved
If you discover CUI has already been submitted to an unsanctioned AI tool, the response needs to move at the same pace as any other data exposure incident — because that’s what it is. The DFARS 252.204-7012 clause governing safeguarding covered defense information carries a 72-hour reporting requirement once a covered contractor becomes aware of a cyber incident, and a shadow AI disclosure can qualify depending on the nature of the data involved and how it was accessed or retained by the receiving platform.
The first step is determining exactly what was submitted, by whom, and to which platform — which is only possible if you’ve built the detection capability described earlier. Without that visibility, you’re relying entirely on an employee self-reporting a mistake they may not even recognize as one. The second step is documenting the vendor’s data handling terms for that specific submission, since some AI providers retain input data for model training by default while others offer contractual guarantees against it — a distinction that materially affects both your reporting obligations and your remediation options.

Conclusion
Shadow AI security isn’t a problem you solve with a single policy memo or a one-time training session — it’s an ongoing gap between how fast employees adopt useful tools and how fast your compliance program can vet them. The contractors handling this well aren’t the ones who’ve banned AI outright; they’re the ones who’ve built visibility into what’s actually leaving their network, backed it with sanctioned alternatives that meet the same productivity need, and treated the whole effort as part of their broader cybersecurity posture rather than a side project. Waiting until an assessor or a DCMA auditor asks the question is the expensive way to find out where the gaps are.
If your organization is planning its CMMC compliance journey, contact Stealth Technology Group today at (617) 903-5559 or visit the website to learn how modern cybersecurity infrastructure can accelerate your path toward certification readiness.
