AI use and boundary record
A voluntary record of the tool, its data, connections, and proof.

A factual record for small defense contractors, not a new CMMC paperwork deadline.
Record which AI systems process, store, or transmit FCI or CUI, which environment each tool relates to, and what evidence supports your decision without uploading FCI or CUI.
FCI means federal contract information. CUI means controlled unclassified information.
Current CMMC status: On July 13, 2026, the Department of War suspended Phase II and later implementation milestones. Phase I self-assessments and existing FCI and CUI safeguarding duties remain. Checked Aug. 20, 2026. Check each solicitation and contract.
No AI addendum rule: The Level 2 Scoping Guide v2.13 has no AI, ML, or LLM requirement. The same security rules still apply when AI uses FCI or CUI. Briard's record is voluntary.
Metadata-only workflow: do not upload FCI or CUI.
A repeatable path from discovery to a dated, customer-owned support record.
Identify AI systems, owners, integrations, and intended uses.
Write down if the tool processes, stores, or sends FCI or CUI. Name the work system it connects to.
Add safe proof. Keep proven facts separate from facts your team states.
Give the facts to your security lead. Briard does not score or send them to SPRS.
These voluntary records trace back to approved answers and evidence. They are not CMMC-required AI artifacts.
A voluntary record of the tool, its data, connections, and proof.
A dated record of scope, changes, proof, and gaps.
Things to fix, who owns them, and target dates.
Approved answers for contract questions, with proof links.
Do not upload FCI or CUI. Store only safe facts and proof.
Your team approves answers and artifacts before they are relied on or shared.
Organization-scoped access keeps each customer and Partner client isolated.
Exports include a check file that can show if the record changed.
Document data handling and system relationships without inventing an AI-specific CMMC requirement.
Inventory AI systems that process, store, or transmit FCI and document the applicable environment and safeguards.
Record CUI handling decisions, system boundaries, evidence, and remediation candidates for the relevant environment.
We will send the account and Partner booking links. Product updates remain opt-in.
Clear boundaries before you buy or rely on an export.
No. Briard-AI organizes customer-owned AI records. It does not perform a CMMC assessment, issue a CMMC status, or create an official CMMC artifact.
No. The CMMC Level 2 Scoping Guide v2.13 does not mention AI, artificial intelligence, machine learning, or LLMs. The same security rules still apply when an AI tool uses FCI or CUI. Briard's record is voluntary, not an assessor requirement.
No. SPRS covers the applicable requirements across your assessed environment. Briard-AI helps document how individual AI systems relate to that environment.
No. The workflow is designed for governance metadata, attestations, and non-regulated evidence about how controls operate.
It suspended Phase II, the later rollout milestones, and C3PAO or DIBCAC assessment designations during the review. Phase I self-assessments, select government-led assessments, and existing FCI and CUI safeguarding duties remain. Check each solicitation and contract.
No. Section 1513 directs the Department to develop an AI security framework and future acquisition requirements. It is not itself a current contractor clause, AI-SSP requirement, or compliance deadline.
No. It organizes system, boundary, change, evidence, and gap facts for the affirming official. Your authorized official remains responsible for reviewing the full requirement and completing any required SPRS action.
Yes. Partner is a sales-assisted monthly subscription for isolated client organizations, a shared Partner console, and white-label exports.