Know where AI touches FCI or CUI.

A factual record for small defense contractors, not a new CMMC paperwork deadline.

Record which AI systems process, store, or transmit FCI or CUI, which environment each tool relates to, and what evidence supports your decision without uploading FCI or CUI.

FCI means federal contract information. CUI means controlled unclassified information.

Current CMMC status: On July 13, 2026, the Department of War suspended Phase II and later implementation milestones. Phase I self-assessments and existing FCI and CUI safeguarding duties remain. Checked Aug. 20, 2026. Check each solicitation and contract.

No AI addendum rule: The Level 2 Scoping Guide v2.13 has no AI, ML, or LLM requirement. The same security rules still apply when AI uses FCI or CUI. Briard's record is voluntary.

Metadata-only workflow: do not upload FCI or CUI.

Fictional data / Acme Defense Systems
Voluntary defense-contractor record

AI Use and Boundary Record

Internal record
System owner
Director of Engineering
Data handled
Processes FCI; CUI prohibited
Environment relationship
Runs in corporate tenant; no direct CUI connection
Evidence status
4 evidenced / 1 attested
Last reviewed
May 12, 2026

From AI tool to a factual boundary record.

A repeatable path from discovery to a dated, customer-owned support record.

  1. 1
    Inventory

    Identify AI systems, owners, integrations, and intended uses.

  2. 2
    Scope

    Write down if the tool processes, stores, or sends FCI or CUI. Name the work system it connects to.

  3. 3
    Evidence

    Add safe proof. Keep proven facts separate from facts your team states.

  4. 4
    Review

    Give the facts to your security lead. Briard does not score or send them to SPRS.

Records your team can review.

These voluntary records trace back to approved answers and evidence. They are not CMMC-required AI artifacts.

AI use and boundary record

A voluntary record of the tool, its data, connections, and proof.

Self-assessment support record

A dated record of scope, changes, proof, and gaps.

Gap action list

Things to fix, who owns them, and target dates.

Customer question pack

Approved answers for contract questions, with proof links.

Evidence, not certification claims.

Metadata-only handling

Do not upload FCI or CUI. Store only safe facts and proof.

Human review

Your team approves answers and artifacts before they are relied on or shared.

Tenant separation

Organization-scoped access keeps each customer and Partner client isolated.

Export integrity

Exports include a check file that can show if the record changed.

Use AI facts in the CMMC work that actually applies.

Document data handling and system relationships without inventing an AI-specific CMMC requirement.

01

Level 1 and FCI

Inventory AI systems that process, store, or transmit FCI and document the applicable environment and safeguards.

02

Level 2 and CUI

Record CUI handling decisions, system boundaries, evidence, and remediation candidates for the relevant environment.

Documentation support only

  • Does not create a required CMMC AI artifact.
  • Does not calculate your SPRS score.
  • Does not replace official clauses or qualified advice.

Need the account path in your inbox?

We will send the account and Partner booking links. Product updates remain opt-in.

No marketing nurture unless you check the box.

CMMC buyer questions

Clear boundaries before you buy or rely on an export.

Does Briard-AI certify our CMMC status?+

No. Briard-AI organizes customer-owned AI records. It does not perform a CMMC assessment, issue a CMMC status, or create an official CMMC artifact.

Does CMMC require an AI-SSP addendum?+

No. The CMMC Level 2 Scoping Guide v2.13 does not mention AI, artificial intelligence, machine learning, or LLMs. The same security rules still apply when an AI tool uses FCI or CUI. Briard's record is voluntary, not an assessor requirement.

Does the platform calculate our SPRS score?+

No. SPRS covers the applicable requirements across your assessed environment. Briard-AI helps document how individual AI systems relate to that environment.

Should we upload FCI or CUI?+

No. The workflow is designed for governance metadata, attestations, and non-regulated evidence about how controls operate.

Did the July 2026 Phase II suspension remove CMMC work?+

It suspended Phase II, the later rollout milestones, and C3PAO or DIBCAC assessment designations during the review. Phase I self-assessments, select government-led assessments, and existing FCI and CUI safeguarding duties remain. Check each solicitation and contract.

Does NDAA FY2026 section 1513 create a contractor deadline?+

No. Section 1513 directs the Department to develop an AI security framework and future acquisition requirements. It is not itself a current contractor clause, AI-SSP requirement, or compliance deadline.

Does the annual affirmation record submit to SPRS?+

No. It organizes system, boundary, change, evidence, and gap facts for the affirming official. Your authorized official remains responsible for reviewing the full requirement and completing any required SPRS action.

Can an RPO or vCISO use this with clients?+

Yes. Partner is a sales-assisted monthly subscription for isolated client organizations, a shared Partner console, and white-label exports.