A ChatGPT Paste Can Trip the DFARS 72-Hour Clock. Most Defense Contractors Can't See It Happen.

Under DFARS 252.204-7012's own definitions, an employee pasting covered defense information into a public AI assistant can meet the bar for a reportable cyber incident — starting the 72-hour clock most contractors have no way to see.

By Containment.ai Research  ·  Published July 1, 2026  ·  Product status: Trust page →
One control plane, three moments of risk. The same deterministic discipline governs three boundaries: the human prompt (AI Chat Firewall, between an employee and the AI provider), the agent action (Agent Governance, between an agent and a tool or system), and the mission boundary (Mission Authorization Gateway, between an AI system and an edge, domain, or OT environment). All three run intercept, canonicalize, evaluate, enforce, audit.
FIG. A — ONE ENFORCEMENT LAYER, THREE MOMENTS OF RISKCONTAINMENT.AI

Picture the most ordinary moment in a defense contractor's day. An engineer is finishing a technical proposal, opens a browser tab, pastes a controlled spec into a public AI assistant, and asks it to tighten the language. Ten seconds, no ceremony. The document was marked. It was covered defense information. And it just left the building.

Under the Defense Federal Acquisition Regulation Supplement, that moment may be a reportable event — and the clock on it may already be running. The clause that governs it, DFARS 252.204-7012, "Safeguarding Covered Defense Information and Cyber Incident Reporting", sits in nearly every DoD contract that touches sensitive unclassified data. Most contractors read it as an infrastructure-and-incident-response obligation. Fewer have asked what it means when the "incident" is an employee pasting into a chatbot.

What the clause actually says

Start with the definitions, because the clause is unusually precise about them.

Covered defense information is unclassified controlled technical information or other CUI-registry information that is, among other triggers, "collected, developed, received, transmitted, used, or stored by or on behalf of the contractor in support of the performance of the contract." A marked spec pasted into a browser is being transmitted and used. It qualifies.

Compromise is defined as "disclosure of information to unauthorized persons, or a violation of the security policy of a system, in which unauthorized intentional or unintentional disclosure, modification, destruction, or loss of an object, or the copying of information to unauthorized media may have occurred." Read that twice. It captures unintentional disclosure. It captures the copying of information to unauthorized media. It does not require malice, a breach, or an attacker.

Cyber incident is then defined as "actions taken through the use of computer networks that result in a compromise or an actual or potentially adverse effect on an information system and/or the information residing therein."

Chain those three definitions together and a common, well-intentioned action — sending covered defense information to a consumer AI service that was never inside your authorization boundary — lands squarely inside the language.

The 72-hour clock

Here is where a definition turns into an operational problem. The clause defines "rapidly report" to mean "within 72 hours of discovery of any cyber incident," and directs contractors to "rapidly report cyber incidents to DoD at https://dibnet.dod.mil."

The clock starts at discovery. Before you report, the clause requires you to "conduct a review for evidence of compromise of covered defense information, including, but not limited to, identifying compromised computers, servers, specific data, and user accounts." You must then preserve system images and relevant monitoring data "for at least 90 days" so DoD can request them. If you are a prime, the same obligations flow down to every subcontractor that touches covered defense information.

None of that is possible if you never saw the paste. And that is the gap: most defense contractors have no telemetry at the point where an employee's browser hands data to an external model. The endpoint agent doesn't see it. The DLP rule tuned for email attachments and file uploads doesn't see a paste into a text box. The cloud access broker sees a connection to an approved SaaS domain and waves it through. The 72-hour clock can be running against you and you would have no way to know it started — or to prove afterward, one way or the other, exactly what crossed.

NIST 800-171 is the control set — and it points at the boundary

DFARS 7012 does not leave "adequate security" to interpretation. It requires contractors to implement the security requirements in NIST Special Publication 800-171, "Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations." NIST published the standard's current final revision, Rev. 3, in May 2024 — authored by Ron Ross and Victoria Pillitteri, superseding Rev. 2 from January 2021.

The control families read like a checklist written for exactly this problem: System and Communications Protection, Media Protection, Audit and Accountability, Incident Response, Access Control. Every one of them assumes you can observe and govern the channels through which CUI moves. A browser session into a large language model is now one of those channels — arguably the fastest-growing one across the defense industrial base — and for most contractors it is the single channel with no control coverage at all.

What "adequate security" looks like at the LLM boundary

The uncomfortable part is that FedRAMP-authorizing the AI platform does not close this. An authorization covers the cloud service's infrastructure. It says nothing about whether a particular prompt should have contained covered defense information, whether that data aligned with your acceptable-use policy, or whether the event was captured for the audit trail an assessor will eventually ask for. Those are your controls to run, at your boundary.

That boundary is the browser and the network path between a user and a model. The control that the "compromise" definition implies — but that almost no contractor has deployed — is one that can see a prompt before it leaves, evaluate it against policy in real time, block or redact covered defense information at the moment of the paste, and log the decision as evidence. Not a training video. Not an after-the-fact discovery six weeks later. Enforcement at the point of egress.

This is the layer Containment.AI operates. We enforce AI-use policy at the browser in real time — monitoring sessions, applying CUI-sensitive rules before data crosses into a model, and generating the audit record that turns "we think nothing left" into something you can actually show. A 72-hour clock is far easier to manage when you can see the moment it would otherwise have started — and stop it.

The regulation did not wait for AI, and it does not have to be amended to reach this behavior. The definitions already do.


Containment.AI enforces AI governance policies at the browser layer in real time — monitoring AI sessions, enforcing CUI-sensitive policy rules, and generating the audit evidence defense contractors need. See how it works →

READY TO CLOSE THE GAP?
Deterministic AI governance for regulated and mission environments.
Request a 30-minute Boundary Review → Apply to the Design Partner Program → Keep controlled data out of public AI →