Picture this: an employee pastes Controlled Unclassified Information (CUI) into ChatGPT to “clean up a report.” No new AI law was needed for that to become a compliance problem — under CMMC and DFARS, it may already be one. So when defense contractors ask “is there an AI law we need to follow?”, the honest answer is three answers: yes, no, and not yet.
That surprises a lot of contractors because the headlines make it sound as though AI regulation for the Defense Industrial Base is something that’s still years away. The reality is more nuanced. Some requirements already exist. Others have been enacted but aren’t yet enforceable. And some are still making their way through Congress. Understanding the difference matters.
Here’s how I think about it.
Tier 1 — Enforceable today
If your organization handles Controlled Unclassified Information (CUI), AI doesn’t exist outside your compliance program. It becomes part of it.Consider a simple example. An employee copies part of a CUI document into a commercial AI chatbot to rewrite a paragraph. Nothing about that action creates a brand-new AI law. Instead, your existing obligations continue to apply.DFARS 252.204-7012 already requires contractors to safeguard CUI, including when it’s processed by external cloud services , which must meet the FedRAMP Moderate baseline or equivalent where required. Many publicly available generative AI tools were never designed or authorized to process DoD CUI under those requirements.From a legal and compliance perspective, that creates a disconnect between documented security practices and what employees are actually doing.If an organization certifies compliance while those practices continue unchecked, that gap may create significant legal exposure, including potential False Claims Act risk under the Department of Justice’s Civil Cyber-Fraud Initiative.For me, this is one of the most practical AI governance issues facing the Defense Industrial Base today.The question isn’t whether you’re using AI. It’s whether AI is already interacting with your CUI.
Tier 2 — Law has been enacted, but implementation is still coming
Congress has acted. Implementation hasn’t happened yet.
Congress has already acted.Section 1513 of the FY2026 National Defense Authorization Act formally titled “Physical and Cybersecurity Procurement Requirements for Artificial Intelligence Systems”, directs the Department of Defense to develop a risk-based cybersecurity and physical security framework for AI and machine learning technologies acquired by DoD.Importantly, Congress didn’t ask DoD to create an entirely separate compliance program. It instructed DoD to build on existing standards, including the NIST SP 800 series, and integrate those requirements into familiar acquisition and cybersecurity frameworks such as DFARS and CMMC.That’s an important distinction. The statute is law. The framework is not yet operational.Section 1513 required DoD to develop implementation milestones and provide a status update to Congress by June 16, 2026. As of publication, that update has not been made public, and no implementation roadmap has been released. The next statutory milestone worth watching is August 31, 2026, when a related provision Section 1512, requires DoD to report to Congress on its review of AI and machine learning cybersecurity practices.That silence doesn’t mean nothing is happening. It means implementation is following the same deliberate pace we’ve seen with many federal cybersecurity initiatives , including CMMC itself, which began as an NDAA directive years before it became today’s assessment program.Organizations that waited for every detail of CMMC before preparing generally found themselves behind. I suspect AI governance will follow a similar path.
Tier 3 — Proposed
Finally, there are proposals that receive headlines but are not yet legal requirements.The FY2027 NDAA includes several AI-related proposals, including funding intended to help small businesses offset CMMC Level 2 assessment costs and additional AI governance initiatives.Those proposals deserve attention. They do not yet create compliance obligations.Until legislation passes both houses of Congress and is signed into law, they’re useful for planning, not for determining today’s compliance requirements.That’s a distinction I think organizations sometimes overlook. I regularly see teams preparing for proposals while missing requirements that already exist.
The Bottom Line
When clients ask me whether there is an “AI law” for defense contractors, my answer is usually: yes, but not always in the way people expect.
**Enforceable today**
*Existing CMMC requirements
* DFARS cybersecurity obligations
* Protection of CUI, including when AI is involved
**Already law, implementation still coming**
* Section 1513 of the FY2026 NDAA
* DoD’s AI security framework (status update to Congress was due June 16, 2026; not yet public)
* Future DFARS and CMMC updates
**Still proposed**
* FY2027 NDAA provisions
* Any future AI legislation that hasn’t been enacted
Those three categories aren’t interchangeable. Understanding the difference is often the difference between building a defensible compliance program and reacting to the latest AI headline.
This article was originally published in The CMMC + AI Brief, my LinkedIn newsletter on AI governance for the Defense Industrial Base. [Subscribe on LinkedIn] to get each edition first, or explore more at aigrcadvisory.com.
Need help assessing your AI security posture?
Whether you’re implementing generative AI, preparing for ISO/IEC 42001, addressing CMMC requirements, or strengthening AI governance, AI GRC Advisory helps organizations identify risks and build practical, audit-ready AI governance programs.
Book a complimentary 30-minute consultation to discuss your AI security and governance priorities.

