Compliance

Where AI tools collide with the rules you operate under

A plain-language reference to the frameworks that make cloud AI a problem, and what changes when the system runs on your own hardware.

This is not legal advice. I'm an infrastructure consultant, not an attorney or a compliance auditor. Use this as a starting point for the conversation with your counsel, your compliance officer, or your assessor — not as a substitute for it.
Defense contractors

CMMC & Controlled Unclassified Information

The Cybersecurity Maturity Model Certification is the DoD's framework for making sure contractors actually protect Controlled Unclassified Information. Level 2 maps to the 110 practices in NIST SP 800-171, and it applies to a very large share of the defense supply chain — including subcontractors who don't always realize they're in scope.

The AI exposure

An engineer pastes a section of a contract deliverable into a chat tool to clean up the wording. That deliverable contains CUI. The CUI has now been transmitted to a system outside your boundary, with no assessment, no documentation, and no record you could show an assessor. The hard part is that most staff genuinely don't know which documents carry CUI markings — the exposure is usually accidental.

What on-premise changes

  • The AI system sits inside your existing assessment boundary
  • CUI never transits a network you don't control
  • Access and usage logging you can produce for an assessor
  • A documented, sanctioned tool replaces undocumented shadow usage
Aerospace & defense manufacturing

ITAR

The International Traffic in Arms Regulations control the export of defense articles and technical data. "Export" is broader than most people assume — it includes making technical data accessible to foreign persons, and it can include processing that data on infrastructure outside the United States. Penalties are civil and criminal, and they are severe. In Huntsville this is not a hypothetical concern.

The AI exposure

Technical specifications or drawings submitted to a cloud AI service may be processed on infrastructure whose location you can't verify and can't control. That's a potential export with federal consequences, and it happens in a browser tab in about four seconds.

What on-premise changes

  • Technical data never leaves the physical facility
  • No question about where processing occurred or who could access it
  • Physical and network access controls you already have jurisdiction over
Medical practices

HIPAA

Any vendor handling Protected Health Information on your behalf is a business associate and needs a Business Associate Agreement. Major AI providers offer BAAs, but generally only on higher-tier enterprise plans — not the free or consumer tiers your staff are most likely to be using. And a BAA governs the terms of handling; it doesn't remove the cloud from the path.

The AI exposure

Clinical staff paste visit notes into a chat tool to turn them into a clean SOAP note. That's PHI disclosed to a vendor with no BAA in place — a reportable event with per-violation penalties. It is one of the most common accidental disclosures happening in small practices right now.

What on-premise changes

  • No third party handles PHI, so no BAA is required for the AI itself
  • PHI stays inside systems already covered by your security assessment
  • Access controls tied to the accounts your staff already use
  • Audit logging that supports your existing documentation practices
Law firms

Attorney-Client Privilege

Privilege can be waived by disclosure to a third party. The ABA has addressed generative AI and client confidentiality directly in Formal Opinion 512, and state bars have followed with their own guidance. The professional obligation is to take reasonable precautions — and courts, not firms, decide after the fact what was reasonable.

The AI exposure

An associate uploads case files to summarize a deposition. Whether that constitutes third-party disclosure sufficient to waive privilege is an unsettled question you do not want your firm to be the test case for. Separately, it raises a bar discipline question about reasonable precautions regardless of how the waiver question resolves.

What on-premise changes

  • No third party ever receives the material — the waiver question doesn't arise
  • A defensible answer when a client, an insurer, or a court asks
  • Matter-level access controls inside the firm
  • Demonstrable reasonable precautions under your ethics obligations
Advisors, CPAs, financial firms

SEC, FINRA & Fiduciary Duty

Financial firms handle material non-public information and detailed client financial data under books-and-records requirements, data governance obligations, and fiduciary duty. Smaller RIAs and CPA practices frequently have no formal AI policy at all — not from negligence, but because the tools arrived faster than the guidance did.

The AI exposure

Client portfolio data or tax documents pasted into a cloud tool creates a data governance gap, and where MNPI is involved, a materially worse category of problem. Examiners increasingly ask what AI tools a firm uses and how their use is supervised.

What on-premise changes

  • Client data stays inside your supervised systems
  • MNPI never leaves your control environment
  • A documented, supervised AI tool to point an examiner at
  • Records retention consistent with your existing obligations

The pattern underneath all five

Every one of these frameworks turns on the same question: can you demonstrate control over where regulated information goes? Cloud AI makes that question hard to answer honestly, because the answer involves infrastructure you don't own, in locations you can't verify, under terms that can change.

On-premise deployment doesn't make compliance automatic — you still need policy, training, and documentation. What it does is remove the structural problem, so the remaining work is work you can actually finish.

Start with a conversation, not a contract

Thirty minutes, no cost, no obligation. It's entirely possible the answer is that you don't need anything from me yet — and I'll tell you that.

Book a Free 30-Minute Call