Why: Third-party AI services are external systems, and the practice does to them exactly what this requirement asks: inventory what is in use, sanction specific services under known terms, and limit or block the rest.
What this does not claim: External systems reach far beyond AI — personal devices, partner networks, every unsanctioned cloud service — and the practice governs only the AI class, so the requirement's full inventory and verification work remains. Sanctioning a tool also requires verifying its handling terms (retention, training use, tenancy) against your obligations, which takes contract and configuration review the acceptable-use rule alone does not provide.
- Inventory AI tools and embedded AI features already in use, including browser extensions
- Sanction specific services under reviewed terms and block or restrict the remainder
- Provide the sanctioned alternative so unsanctioned use has somewhere legitimate to go
- The sanctioned AI service list with the terms review per service
- Blocking or discovery reports for unsanctioned AI services
Review status: Technical review complete · Reviewed by inDirectIT practitioner review — CUI security and NIST SP 800-171 engineering · updated 2026-08-06