Why: Deciding which AI services may receive, retain, or train on sensitive data — the data-protection half of this practice — determines where CUI is permitted to come to rest in the first place, which is the scoping decision at-rest protection depends on.
What this does not claim: Informs the requirement without acting on its substance: the practice encrypts no storage and configures no at-rest protection anywhere. Every location where CUI legitimately rests — file servers, endpoints, cloud tenants, backups — needs its own protection decisions and evidence, and an AI-usage policy governs only the new resting places AI adoption would otherwise create.
- Maintain an approved-tool list with data-handling and retention terms reviewed
- Block or constrain CUI flows to unapproved AI services
- Include approved AI services in the CUI-at-rest location inventory
- AI acceptable-use policy naming data classes and approved services
- Proxy or DLP rules restricting data flows to AI endpoints
Mapping limitations: The relationship depends on the organization treating AI services as CUI locations at all; where CUI is prohibited from AI tools entirely and that prohibition is enforced, the mapping reduces to policy evidence.
Review status: Pending NIST SME review · Reviewed by Brilliant at the Basics editorial — practitioner-authored; NIST SME review pending · updated 2026-08-06