A marking decides the architecture. Once a document carries a CUI banner, an export-control notice or a criminal-justice designation, the shortlist of AI tools collapses before anyone opens a pricing page: the classification has already ruled on where the material may be processed and who may reach it. Compliance leaders in defense, public safety, education and manufacturing all reach the same question early: which deployments are we even allowed to consider?
Can CUI, ITAR, FERPA or CJIS Data
Be Put Into an AI System?
What each classification restricts, why the accredited government cloud is rarely the cheap answer, and how to place a model inside a boundary you have already accredited.
Not into a general hosted AI service. CUI, ITAR and EAR, CMMC, CJIS and FERPA each restrict where regulated material may be processed and who may reach it, which makes on-device or on-premises inference the compliant pattern. Start from the control set that already governs the data and place the model inside it, rather than certifying a new external destination. Iternal built AirgapAI for that placement, and states it is deployed inside classified facilities today.
The limit: a control mapping shown in a demonstration is an illustration, not an assessment. Iternal offers a CMMC policy-writing workflow and describes the version it demonstrates as a demo that does not walk all 110 NIST controls. Treat any mapping you are shown as a worked example of the drafting rather than as evidence your scope is covered. Local execution puts the model inside a control set you have already accredited; it does not accredit the product, and the accreditation work remains yours.
Settle three things in writing before you buy. Which accreditation boundary the deployment sits inside; whether adding it widens the scope your assessor reviews; and which environment is accredited for the exact class of data you hold, confirmed by the organization operating it rather than by a published page. The questions below are phrased for a security questionnaire.
A chat application does not carry a classification; the environment it runs in does. Your obligation attaches to the data, the facility and the contract, so the useful question is which of those the deployment sits inside. For more information on the certifications and evidence a reviewer will ask for, visit the security review page.
What Each Classification Actually Restricts
Five regimes carry almost every regulated AI conversation, and they restrict different things: CUI and export control govern the content, CMMC governs the supplier, and CJIS and FERPA govern named categories of records. What each restricts, and where a model may run:
| Classification | What it restricts | Where a model may run |
|---|---|---|
| CUI | Controlled unclassified information must be stored separately, with additional protections. Buyers described whole technical-data sets marked CUI. | Inside a boundary already accredited for CUI — the device, or a server in the enclave. Buyers repeatedly told us they could not confirm a cloud-hosted model accredited for theirs. |
| ITAR / EAR | Export control limits which documents may enter an AI system at all, and who may see them once they are inside. | Disconnected operation aligns the deployment with ITAR and the related obligations a customer falls under; a private single-tenant deployment can align too. |
| CMMC | Contract eligibility for defense suppliers. Level 2 covers a wide cross-section of NIST 800-53, and every new capability is assessed against the certification already held. | Inside the assessed scope. Iternal states AirgapAI can be deployed in a secure enclave connected to a server and stay in scope for CMMC. |
| CJIS | Applies wherever a repository holds criminal-justice information, which pulls the whole workflow around it into scope. | On agency-controlled hardware, or in an accredited tenant agencies described as expensive. Iternal states AirgapAI meets the bar from a CJIS standpoint. |
| FERPA | Federal education records and the personal information inside them. Buyers named FERPA alongside HIPAA as the regime pushing them toward offline AI. | Inside institution-controlled infrastructure. Iternal designs university deployments to stay aligned with PII and FERPA requirements. |
Labeling is where the table meets reality, and the labeling is uneven. Buyers told us documents get marked CUI excessively, dragging material into scope that never needed to be there. One asked it directly: if an asset is already labeled CUI, why repeat the classification exercise every morning? Sort the labels before you scope the deployment.
The Accredited Government Cloud Is Rarely the Cheap Answer
Regulated buyers get pointed at the accredited cloud first, and they come back with the same two complaints. The first is price: a CJIS-compliant secure tenant in AWS or Azure can be pretty expensive, a secure environment still has to be proven compliant, and the government edition of a mainstream hosted assistant arrives stripped down, carrying a thousand-seat minimum that does not work for a small manufacturer.
The second complaint is the catalog. The model list inside a government region runs thinner than the commercial one, because services judged to carry more risk are kept off the government marketplace. Buyers described a proprietary model they wanted that could not run on their own infrastructure and never appeared on the government model page.
Both complaints point the same way. Iternal states the case plainly: technologies exist that are very inexpensive and work extremely well locally, and a machine already sitting inside your accredited facility needs no new tenant proven compliant. The accredited cloud stays a legitimate route, with one detail that keeps tripping evaluations — published model and accreditation pages go out of date, so two people reading two pages on the same afternoon come away with opposite answers about the same environment. Create the tenant, read the live catalog from inside it, and put the rest in writing:
-
Which tenant tier is accredited for the exact class of data we hold, and will its operator confirm that in writing?Whether the accredited-cloud route is open to you at all, without relying on a page that may have aged.
-
Which models are live in the tenant today, read from inside it rather than from a public catalog page?Whether the model your workflow depends on exists in that environment before you sign for it.
-
If we run locally instead, which parts of our assessed boundary does the deployment sit inside?Whether the deployment inherits the accreditation you hold or triggers a fresh review.
Why Controlled Material Cannot Touch a Hosted AI Tool
The most repeated finding in our regulated conversations is a wall, described almost identically across defense, legal, government contracting and manufacturing. All technical data is CUI, so internet-hosted models cannot be used. Controlled unclassified and classified information cannot be uploaded to hosted AI tools. No coding assistant can be used in a CUI environment. Secret and top-secret high-side networks run as closed loops with no route to a cloud service.
Capability is rarely what fails. One team had tried the coding assistants on the market and found them all useful; the blocker was the CUI data. Another moved into the protected environment and lost the tools the practice used day to day — the protection worked, and the productivity left with it. An air-gapped machine, as one buyer put it, lets you upload anything you want with no worry of it getting out.
The cost of getting it wrong is asymmetric. One paragraph in one document can move that document from unclassified to top secret, and buyers were candid that non-compliant devices reaching government or intelligence facilities create legal trouble. Iternal has proposed a lower-risk sequence for programs that want proof first: pilot on public solicitation data, then migrate controlled material once the deployment is accredited in place.
TAA and Cleared Environments: A Separate Test at Procurement
Classification governs the data; procurement governs the box it runs on. Passing the first test and failing the second stalls regulated deployments regularly, because the hardware requirement lives in the contract rather than in the data policy.
TAA compliance means secure supply chain — where the device was manufactured, and how its components got there. Government buyers keep getting more restrictive about where devices are made, and any machine that could end up inside a SCIF has to come from a TAA-compliant line. Iternal states the federal arms of the major hardware makers sell TAA exclusively, across laptops, servers and mini PCs, so the requirement filters an order rather than blocking it. The failure mode is mundane — a federal integrator buys laptops through a commercial sales team, and the units turn out not to qualify.
Cleared environments add the third test. Iternal states AirgapAI was built for government SCIFs, military facilities and nuclear environments, that it is deployed in SCIF facilities today, and that the stack supports NIPRNet-based and SIPRNet-based environments. Read the solicitation for the tell: language naming JWICS or SIPRNet tells you which classified network the machines will sit on, and the security protocols follow from that designation. Two questions settle the procurement side:
-
Is every device in the quote on a TAA-compliant line, confirmed by part number rather than by brand?That the hardware can enter a controlled facility without creating a procurement problem after the order is placed.
-
Which clearance level do the people who install and support this deployment need, and who on the delivery side holds it?Whether installation and support can happen inside your facility, and how much escorting you must arrange.
Where the Answer Stops Being About Classification
A regulated evaluation splits into questions with different owners. Which deployments your classifications permit is settled above; each of these has its own page:
- What Iternal holds, what is in progress and what is not — see the security review page.
- Which country or jurisdiction the material must stay inside — see the residency page.
- What happens to a prompt when a court or a records request arrives — see the records and privilege page.
- Who may reach which data sets, and how usage is logged — see the administration page.
- What keeps working once the network is gone — see the disconnected-operation page.
- Which jobs federal and defense teams put an assistant to — see the federal and defense use-case page.
- Where clinical and life-sciences teams apply the architecture — see the healthcare use-case page.
- Which options a small agency can afford — see the public-safety options page.
FAQ: Regulated Data and AI Deployment
Into a system you control, yes. Export control limits which documents may enter an AI system and who may see them once inside, which rules out a general hosted service and leaves on-device or on-premises inference. Disconnected operation aligns the deployment with ITAR and the related obligations a customer falls under. Confirm the placement against your own export-control program first.
The options that fit inside the assessed scope you already carry. Level 2 covers a wide cross-section of NIST 800-53, and every new capability is assessed against the certification already held, so the test is whether a tool sits inside your boundary or extends it. Iternal states AirgapAI can be deployed in a secure enclave connected to a server and stay in scope for CMMC.
CJIS applies wherever a repository holds criminal-justice information, and agencies described the accredited tenant that satisfies it as expensive. Iternal states AirgapAI meets the bar from a CJIS standpoint, by the same mechanism every regime here turns on: the material stays on hardware the agency controls. FERPA and HIPAA work the same way — the regime governs the environment, and the environment decides the deployment.
Accreditation attaches to a specific tenant tier and a specific service, and it moves. Buyers told us the high government tier was accredited for CUI while the standard tier stayed unclear, and others had been unable to confirm any cloud-hosted model accredited for theirs. Get it in writing from the organization operating the environment, and read the live model list from inside the tenant.
Assume yes until your assessor rules otherwise. Buyers in defense supply chains told us every new capability has to be assessed against the certification already held, which is why placing the model inside an accredited boundary costs less than certifying a new destination. The accreditation work itself remains yours.
Secure supply chain — where the device was manufactured, and how its components reached it. Iternal states many manufacturers hold the same standard, so buying compliant hardware comes down to ordering from the right line. Any machine that could end up inside a SCIF has to come from one, and confirming it by part number rather than by brand is what keeps a non-compliant unit out of a controlled facility.
Start From the Boundary You Already Accredited
The compliant path is the one that needs the fewest new approvals. Your facility, your enclave and your assessed scope already carry accreditation someone worked hard to obtain, and a model placed inside them inherits that work. Sort your labels, confirm which boundary the deployment sits inside, and run the test on one machine inside the fence.