Is your AI tool safe for CUI?
Not “is it a good product” — which authorization boundary does your prompt land in, and does that boundary cover Controlled Unclassified Information. Below: where each assistant sends the data, what FedRAMP and DoD Impact Level authorization actually exists for that specific service, and what DFARS 252.204-7012 requires of the pattern.
As of July 27, 2026. Authorization status drifts — products get authorized, scopes get amended, terms change. Every finding here links to the primary source it came from. Open it and verify the current status with the vendor before you commit a boundary decision.
The verdicts
| Tool | Verdict | FedRAMP | DoD IL |
|---|---|---|---|
| Microsoft 365 Copilot (commercial cloud) Microsoft | Commercial environment — no CUI authorization established | Not established for this environment | Not established |
| ChatGPT (consumer, Plus, Business and standard Enterprise) OpenAI | Certification exists, but it names a different offering | Certified — but for a named separate offering | Not established |
| Gemini app and Gemini in Google Workspace (commercial) | Google caps this at DoD IL2 — below the level DoD associates with CUI | High in a Workspace FedRAMP boundary; IL2 ceiling | IL2 only (no IL4 / IL5) |
| Claude (Claude.ai, Claude for Work and the Anthropic API) Anthropic | Anthropic routes its authorized paths through AWS and Google Cloud | Not established for the direct commercial API | Not established for the direct commercial API |
| GitHub Copilot (Business and Enterprise) GitHub | Platform is certified at the Low baseline; Copilot is not named on the record | Platform certified at Class B (Low) | Not established |
| Microsoft 365 Copilot in GCC High / DoD Microsoft | Authorized environment — this is the one Microsoft points CUI holders at | Certified — Class D (High), 12/26/2024 | DoD environment assessed to SRG IL5 |
| Azure OpenAI Service in Azure Government Microsoft | In scope of the Azure Government authorizations, up to IL5 | High (Azure Government JAB P-ATO) | IL2, IL4, IL5 |
| ChatGPT Enterprise and API Platform (OpenAI FedRAMP offering) OpenAI | FedRAMP Certified at Moderate — no DoD Impact Level established | Certified — Class C (Moderate), 1/9/2026 | Not established |
| Gemini for Government | Certified at Class B (Low) — below the Moderate baseline the clause names | Certified — Class B (Low); High via Assured Workloads | IL4 via the Assured Workloads path |
| Gemini via Vertex AI under Assured Workloads | In scope at FedRAMP High and DoD IL4/IL5 — inside an Assured Workloads boundary | High (in an Assured Workloads boundary) | IL2, IL4, IL5 |
| Claude via Amazon Bedrock in AWS GovCloud (US) Amazon Web Services | FedRAMP High in AWS GovCloud; Anthropic states IL4/IL5 approval | High (AWS GovCloud US-West) | IL4 / IL5 per Anthropic |
| Self-hosted open-weight model in your own CUI enclave Your organization | No external cloud service provider — a different test applies | Not the applicable test | Not the applicable test |
| Gemini on Google Distributed Cloud (air-gapped) | DISA IL6 provisional authorization on disconnected infrastructure | Outside FedRAMP by design (not a hosted cloud service) | IL6 provisional authorization (DISA) |
Each row links to the full review: the data-location finding, the authorization record, the regulation text, and every source URL.
The rule these verdicts apply
DFARS 252.204-7012 splits the question in two, and which half you are in depends entirely on whether an external cloud service provider is in the path. That is why the same model can be fine on your own hardware and a finding in a commercial tenant.
DFARS 252.204-7012(b)(2)(i) — NIST SP 800-171 on your own systems
Any unclassified system owned or operated by or for the contractor that processes, stores or transmits covered defense information is a "covered contractor information system" and carries the full NIST SP 800-171 requirement set. An AI assistant does not sit outside this because it is new: if CUI reaches it, the system it runs on is in scope, and the revision that applies is the one in effect when the solicitation issued.
Primary source
“Except as provided in paragraph (b)(2)(ii) of this clause, the covered contractor information system shall be subject to the security requirements in National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171 ... in effect at the time the solicitation is issued or as authorized by the Contracting Officer.”
Acquisition.gov (DFARS, MAY 2024 revision) — DFARS 252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting · read 2026-07-27
DFARS 252.204-7012(b)(2)(ii)(D) — the external cloud service provider test
This is the paragraph that decides most AI questions. The moment an external cloud service provider stores, processes or transmits covered defense information, the contractor must require and ensure that provider meets security requirements equivalent to the FedRAMP Moderate baseline — and that it complies with the clause's incident reporting, malicious software, media preservation, forensic access and damage assessment paragraphs. A commercial AI endpoint is an external cloud service provider. The obligation to ensure equivalency sits on the contractor, not the vendor.
Primary source
“If the Contractor intends to use an external cloud service provider to store, process, or transmit any covered defense information in performance of this contract, the Contractor shall require and ensure that the cloud service provider meets security requirements equivalent to those established by the Government for the Federal Risk and Authorization Management Program (FedRAMP) Moderate baseline ... and that the cloud service provider complies with requirements in paragraphs (c) through (g) of this clause for cyber incident reporting, malicious software, media preservation and protection, access to additional information and equipment necessary for forensic analysis, and cyber incident damage assessment.”
Acquisition.gov (DFARS, MAY 2024 revision) — DFARS 252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting · read 2026-07-27
By deployment pattern
Commercial multi-tenant SaaS
The default consumer or enterprise tenant. An external cloud service provider is in the path, so DFARS 252.204-7012(b)(2)(ii)(D) applies and the question becomes what that provider is authorized to hold.
Commercial environment — no CUI authorization established
Certification exists, but it names a different offering
Google caps this at DoD IL2 — below the level DoD associates with CUI
Anthropic routes its authorized paths through AWS and Google Cloud
Platform is certified at the Low baseline; Copilot is not named on the record
Government cloud / sovereign variant
A separately operated environment (GCC High, Azure Government, AWS GovCloud, Assured Workloads) with its own authorization record. Same brand, different boundary — and the AI features available inside it are frequently a subset.
Authorized environment — this is the one Microsoft points CUI holders at
In scope of the Azure Government authorizations, up to IL5
FedRAMP Certified at Moderate — no DoD Impact Level established
Certified at Class B (Low) — below the Moderate baseline the clause names
In scope at FedRAMP High and DoD IL4/IL5 — inside an Assured Workloads boundary
FedRAMP High in AWS GovCloud; Anthropic states IL4/IL5 approval
In-boundary / self-hosted inference
The model runs on systems the contractor owns or operates inside its own CUI enclave. No external cloud service provider is in the path, so the FedRAMP-equivalency paragraph is not the operative test — NIST SP 800-171 applied to your own system is.
How these verdicts are made
- Every finding carries a primary source, rendered on the page— a FedRAMP Marketplace listing, the vendor’s own documentation or trust centre, a DoD authorization record, or the regulation text itself. The verbatim quote and the URL are both shown so you can re-check them.
- Where we could not source a claim, we do not make one.Those fields read “not established” and tell you to verify with the vendor. A gap is a more useful answer than a confident guess.
- The finding is about authorization boundaries, not product quality. “No authorization covering CUI” is a statement about what the authorization record says — not a claim that a product is insecure or badly built.
- Platform authorization is not service authorization. A cloud platform holding FedRAMP High does not mean every AI service running on it is inside that boundary. Each review checks whether the specific service is named in scope.
Frequently asked questions
Is it legal to use AI tools with CUI?
Yes — with the same condition that applies to any other system. DFARS 252.204-7012 asks two questions. If an external cloud service provider stores, processes or transmits covered defense information, the contractor must require and ensure that provider meets security requirements equivalent to the FedRAMP Moderate baseline and complies with the clause's incident reporting, malicious software, media preservation, forensic access and damage assessment paragraphs. If the system is one you own or operate, NIST SP 800-171 applies to it directly. An AI assistant is not a special category; it is a system, and the ordinary tests apply.
Which AI tools are approved for CUI?
The question resolves per deployment, not per brand. The same vendor can appear with an authorized government-cloud offering and an unauthorized commercial one, and this checker lists both side by side for exactly that reason. Look at the specific offering named on the authorization record, not the product name on your invoice.
My cloud provider is FedRAMP authorized. Does that cover its AI service?
Not automatically. Authorization attaches to a defined service scope, and providers publish which services are in it. Google's scope table, for instance, marks the Gemini app as Supported at DoD IL2 but carries no IL4 or IL5 entry for it, while marking Generative AI on the Gemini Enterprise Agent Platform as Supported at IL4 and IL5. Same vendor, same authorization programme, different answer.
Does a "we do not train on your data" promise satisfy DFARS 252.204-7012?
No. It is a data-use commitment, and the clause asks about an authorization boundary plus a set of contractual obligations — incident reporting, malicious software handling, media preservation, forensic access and damage assessment. Every major vendor now makes some version of the no-training commitment, which is why it does not discriminate between the compliant and non-compliant options on this page.
What about employees pasting CUI into a consumer chatbot?
That is the common real-world finding, and it is an access-control and boundary-protection problem rather than an AI problem. It lands on the NIST 800-171 controls covering control of CUI flow, connections to external systems, and use of external systems — the same controls that govern any unapproved service reachable from a workstation.
How current is this?
Every finding on this checker was read from its primary source on July 27, 2026, and each page shows the retrieval date next to the link. Authorization records change — offerings get certified, scopes get amended, classes get revised — so open the source before you commit a boundary decision. Where we could not read a source, the page says "not established" rather than guessing.
Related tools
Get a defensible CUI architecture
This AI CUI boundary check flags the gaps. The next step is a compliance architecture review where we map your data flows to FedRAMP-authorized alternatives and CMMC-aligned controls.
Schedule architecture review