Why: Secure AI adoption forces the questions this requirement institutionalizes — what data an AI tool retains, for how long, and under whose terms — so the practice's data-protection decisions inform CUI retention management for one fast-growing class of services.
What this does not claim: The practice informs the requirement without acting on its substance: information management and retention spans every repository holding CUI, driven by records schedules and legal authorities, and the practice touches only the AI-tool slice of that landscape. Retention terms negotiated for AI services are a contribution to the requirement's implementation, not an implementation of it.
- Record retention and training-use terms for each approved AI tool before any CUI-adjacent use
- Prohibit CUI in tools whose retention terms cannot be verified
- The approved AI tool register with data-retention terms per tool
- Configuration showing retention limits or training-data opt-outs applied
Review status: Pending NIST SME review · Reviewed by Brilliant at the Basics editorial — practitioner-authored; NIST SME review pending · updated 2026-08-06