DeepSeek and the FY2026 NDAA

DeepSeek and the FY2026 NDAA

Section 1532 of the FY2026 NDAA bars DeepSeek and High Flyer AI on DoD contracts. Learn what it covers, what it does not, and the replacement path.

https://petronellatech.com/blog/deepseek-and-the-fy2026-ndaa-what-dod-contractors-need-to-know/

Chapters:
00:00 Introduction
00:14 DeepSeek and the FY2026 NDAA
08:38 What organizations should do
16:51 How to reach us

A conversation about "DeepSeek and the FY2026 NDAA: What DoD Contractors Need to Know" from the Petronella Technology Group, Inc. blog.

Subscribe to Encrypted Ambition and hear every episode: https://petronellatech.com/podcasts/

Questions about AI, cybersecurity, or compliance for your business? Call Petronella Technology Group, Inc. at 919-348-4912.


00:00:14 --> 00:00:20 Today we dive into the new DoD AI ban that forces contractors to rethink every model they use.
00:00:21 --> 00:00:33 The law, Section 1532 of the FY2026 NDAA, prohibits any contractor from using AI developed by DeepSeek or High Flyer during DoD contract performance.
00:00:33 --> 00:00:38 So if a company runs a DeepSeek model on its own servers, does the ban still apply?
00:00:38 --> 00:00:46 Yes. The statute never mentions deployment mode. Whether the model is in the cloud or on-premises, it still counts as ‘use’.
00:00:46 --> 00:00:50 That's surprising because many think self-hosting might be a loophole.
00:00:50 --> 00:00:56 The law attaches to the developer, not the hosting arrangement. It follows the model wherever it runs.
00:00:56 --> 00:01:01 So a DeepSeek API call or a GPU cluster in a private data center is covered.
00:01:01 --> 00:01:10 Correct. The text says nothing about local-model exemption. The definition of ‘covered artificial intelligence’ runs on developer lineage.
00:01:10 --> 00:01:14 What about fine-tuning a DeepSeek model? Does that change anything?
00:01:14 --> 00:01:22 Fine-tuning still ties back to the base model. The statute includes successor AI developed by DeepSeek or High Flyer.
00:01:22 --> 00:01:25 So any modification doesn't help avoid the prohibition.
00:01:25 --> 00:01:32 Exactly. The prohibition applies to any use in contract performance, regardless of how the model is accessed.
00:01:33 --> 00:01:37 What about other Chinese-origin models like Qwen or GLM? Are they covered?
00:01:38 --> 00:01:44 The statute names only DeepSeek and High Flyer. Qwen, GLM, Kimi, MiniMax are not listed.
00:01:44 --> 00:01:50 But I've heard Alibaba and Baidu were added to a DoD list. Does that change things?
00:01:50 --> 00:01:57 They joined the Section 1260H list, which could trigger a broader prohibition if the Secretary issues guidance.
00:01:57 --> 00:01:59 Has any guidance been issued yet?
00:01:59 --> 00:02:06 No public confirmation exists. The wider category remains a watch item, not a live prohibition.
00:02:06 --> 00:02:09 So for now, only DeepSeek and High Flyer are strictly prohibited.
00:02:10 --> 00:02:16 Yes, but be aware that pending legislation could add more names, and the current list is contested.
00:02:16 --> 00:02:23 Let's talk about compliance frameworks. Does CMMC or NIST 800-171 mention these AI restrictions?
00:02:23 --> 00:02:32 Neither does. CMMC maps to 110 controls of NIST 800-171, but there is no AI-origin rule.
00:02:33 --> 00:02:36 So the statutory ban is separate from CMMC compliance.
00:02:36 --> 00:02:44 Correct. The ban applies to the use of covered AI, while CMMC requires adequate security controls for every system.
00:02:44 --> 00:02:50 What about DFARS 252-7012? Does it involve AI models?
00:02:50 --> 00:03:03 DFARS 252-7012 mandates that covered contractor systems meet the same 110 controls, and cloud providers must meet FedRAMP Moderate or equivalent.
00:03:03 --> 00:03:06 So removing DeepSeek doesn't satisfy DFARS?
00:03:06 --> 00:03:15 No. DFARS concerns control implementation, not model lineage. You still need to address the statutory prohibition separately.
00:03:16 --> 00:03:20 Understood. Let's discuss the practical steps a contractor should take.
00:03:20 --> 00:03:29 First, inventory every AI model in use, both commercial and self-hosted, and trace each against the covered AI definition.
00:03:29 --> 00:03:31 How do you trace a model to the definition?
00:03:31 --> 00:03:41 Check the developer lineage. If the model originates from DeepSeek or High Flyer, or an entity with at least 20 percent stake in High Flyer, it is covered.
00:03:41 --> 00:03:45 What about models that are not named? Do they automatically comply?
00:03:45 --> 00:03:54 Not automatically. They still need to be secured under the 110 controls. You must verify they don’t send CUI to external systems.
00:03:54 --> 00:03:58 So the next step is mapping the environment to the 110 controls?
00:03:58 --> 00:04:10 Exactly. Use the seven-stage method: define the data boundary, prototype with your data, size hardware, isolate the cluster, deploy the model, layer access controls, and validate.
00:04:10 --> 00:04:12 Could you give an example of hardware sizing?
00:04:13 --> 00:04:23 A 7B parameter model runs on a single NVIDIA A100 or H100 GPU. Larger models may need two to four GPUs.
00:04:23 --> 00:04:27 What about open-weight models like Gemma 4? Are they suitable for DoD work?
00:04:28 --> 00:04:35 Gemma 4 is released under Apache 2.0, and it is not named in any U.S. restriction. It can be a compliant replacement.
00:04:36 --> 00:04:37 Does the license matter for procurement?
00:04:38 --> 00:04:45 Yes. Apache 2.0 is commercially permissive, so your procurement team can handle it without additional legal hurdles.
00:04:45 --> 00:04:47 What about compliance documentation?
00:04:47 --> 00:05:00 Petronella Technology Group provides a compliance platform called ComplianceArmor®. It automates SSP authoring, POA&M tracking, and evidence repository organization.
00:05:00 --> 00:05:03 So you can integrate the inventory and removal record into that system?
00:05:04 --> 00:05:11 Exactly. That documentation feeds into your system security plan and ensures you have evidence before any audit.
00:05:12 --> 00:05:15 What about the waiver mechanism? Can we get a waiver for using DeepSeek?
00:05:16 --> 00:05:28 Section 1532(b) offers waivers only for scientific research, national security, counterterrorism, or mission-critical functions, with risk mitigation steps.
00:05:28 --> 00:05:30 So ordinary contract analytics wouldn't qualify?
00:05:31 --> 00:05:38 Correct. The categories are narrow, and the waiver is an affirmative government decision, not an internal exception.
00:05:38 --> 00:05:41 If we can't get a waiver, what is the next best action?
00:05:41 --> 00:05:50 Remove the model from any DoD contract workflow and replace it with an unnamed, compliant model like Gemma 4 or Llama 3.1.
00:05:50 --> 00:05:54 Does that satisfy DFARS 252-7012?
00:05:55 --> 00:06:03 Yes, provided you implement the 110 controls for the new model environment. DFARS is about security, not lineage.
00:06:03 --> 00:06:08 What about the intelligence community? Does Section 6604 affect us?
00:06:08 --> 00:06:18 Section 6604 prohibits DeepSeek on intelligence community systems, and it directs the Director of National Intelligence to develop standards.
00:06:18 --> 00:06:23 So if we support an IC element, the ban applies even if the broader Section 1532 doesn't?
00:06:24 --> 00:06:30 Correct. Section 6604 is application-focused and reaches IC contractors directly.
00:06:30 --> 00:06:33 So we need to check whether we work with any IC element.
00:06:33 --> 00:06:39 Yes. If you do, you must remove DeepSeek from those workflows and replace it with a compliant model.
00:06:40 --> 00:06:42 Let's talk about the timeline. When do we need to act?
00:06:43 --> 00:06:54 Section 1532(a)(1) required the Department to remove covered AI from its systems within 30 days of enactment. The same pace applies downstream.
00:06:54 --> 00:06:57 So we have a 30-day window to audit our systems?
00:06:57 --> 00:07:04 Yes, but the audit expectation is already explicit in practitioner guidance. You should start immediately.
00:07:04 --> 00:07:08 What about the pending FY2027 bill? Should we wait for it?
00:07:08 --> 00:07:19 The bill could add names like Baidu, Zhipu AI, Moonshot AI, 01.AI, MiniMax, Alibaba, and Tencent. Until it becomes law, treat it as a watch item.
00:07:19 --> 00:07:22 So we should monitor guidance and stay ready to adjust?
00:07:22 --> 00:07:29 Exactly. Set a review cadence for any new guidance or legislation, and keep your compliance documentation up to date.
00:07:30 --> 00:07:33 What if we accidentally use a covered model in a non-DoD contract?
00:07:34 --> 00:07:41 The prohibition is limited to DoD contract performance. Non-DoD contracts are outside the statutory scope.
00:07:41 --> 00:07:45 But could that still trigger a flow-down clause or other contractual obligation?
00:07:46 --> 00:07:53 It depends on the specific DFARS clause. The statute didn't create a new clause, so you need to consult counsel.
00:07:53 --> 00:07:57 So it's safest to audit all AI use regardless of contract type.
00:07:57 --> 00:08:03 Yes, that proactive approach reduces risk and ensures compliance across all operations.
00:08:03 --> 00:08:06 How do we document the removal of a covered model?
00:08:06 --> 00:08:13 Record the model version, the date of removal, the reason, and the replacement model details in your system security plan.
00:08:14 --> 00:08:17 And we should keep evidence of the waiver if we ever apply for one?
00:08:17 --> 00:08:24 Yes, maintain signed attestations, risk mitigation plans, and any official waiver documents.
00:08:24 --> 00:08:26 What are the key takeaways for a contractor right now?
00:08:27 --> 00:08:38 Audit all AI, remove covered models from DoD workflows, replace with compliant open-weight models, map to the 110 controls, and stay alert to new guidance.
00:08:38 --> 00:08:43 What are the deeper implications if a contractor ignores Section 1532?
00:08:44 --> 00:08:49 Ignoring it could trigger enforcement actions, penalties, and loss of DoD contracts.
00:08:49 --> 00:08:52 Could those penalties be monetary or purely contractual?
00:08:53 --> 00:08:56 Both; the law can impose fines and force contract termination.
00:08:57 --> 00:08:59 Is there a risk of a broader security audit?
00:08:59 --> 00:09:03 Yes, auditors may scrutinize all AI systems tied to DoD work.
00:09:04 --> 00:09:06 How does this affect non-DoD data handling?
00:09:06 --> 00:09:11 Non-DoD data can still be processed, but the model must be compliant.
00:09:11 --> 00:09:13 What about the hardware cost for a compliant model?
00:09:14 --> 00:09:21 A 7B parameter model fits on a single NVIDIA A100, but larger ones need multiple GPUs.
00:09:21 --> 00:09:24 Do we need to size the cluster before choosing a model?
00:09:24 --> 00:09:28 Yes, a scoping prototype on your data informs hardware sizing.
00:09:29 --> 00:09:32 What if we have a mix of models, some covered, some not?
00:09:32 --> 00:09:36 Separate them by workflow; remove covered ones from DoD paths.
00:09:36 --> 00:09:39 Can we still use a covered model for training only?
00:09:39 --> 00:09:45 Section 1532(b) allows case-by-case waivers for research or training.
00:09:45 --> 00:09:47 How do we apply for such a waiver?
00:09:47 --> 00:09:52 Submit a formal request with risk mitigation steps; approval is government-issued.
00:09:53 --> 00:09:54 If we get denied, what then?
00:09:55 --> 00:09:58 You must replace the model before continuing DoD work.
00:09:58 --> 00:10:00 What are the common mistakes we should avoid?
00:10:01 --> 00:10:05 Assuming local hosting is exempt; assuming fine-tuning removes coverage.
00:10:05 --> 00:10:07 Is fine-tuning a new model under the law?
00:10:08 --> 00:10:12 No, the base model remains covered regardless of modifications.
00:10:12 --> 00:10:15 How do we document that we have removed a covered model?
00:10:15 --> 00:10:21 Log the version, removal date, reason, and replacement details in the system security plan.
00:10:22 --> 00:10:25 Do we need to update the system security plan for every change?
00:10:25 --> 00:10:29 Yes, keep the plan current to reflect the latest AI environment.
00:10:29 --> 00:10:31 What about the 30-day window for removal?
00:10:31 --> 00:10:36 The statute gave the Department 30 days; contractors should act promptly.
00:10:36 --> 00:10:39 Should we monitor for new guidance from the Secretary?
00:10:39 --> 00:10:46 Absolutely; a review cadence every 60 days keeps you aligned with Section 1532(a)(2).
00:10:46 --> 00:10:49 How does CMMC Level 2 interact with this requirement?
00:10:50 --> 00:10:57 CMMC Level 2 maps to NIST 800-171 controls but does not lift the statutory ban.
00:10:58 --> 00:11:01 So we still need to remove covered models even with a CMMC certificate?
00:11:02 --> 00:11:06 Correct; compliance frameworks and statutes operate independently.
00:11:06 --> 00:11:09 What if we use a model from an unnamed Chinese-origin company?
00:11:10 --> 00:11:16 Check the 1260H list and pending Section 1651; these may be added later.
00:11:16 --> 00:11:19 Does the 1260H list immediately impose a ban?
00:11:20 --> 00:11:27 Only if the Secretary issues guidance under Section 1532(a)(2); currently, it's a watch item.
00:11:27 --> 00:11:30 Could a vendor's 20 percent stake trigger coverage?
00:11:30 --> 00:11:35 Yes, any entity with at least 20 percent stake in High Flyer is covered.
00:11:35 --> 00:11:39 What about the 24/7 AI-plus-human hybrid threat analysis?
00:11:39 --> 00:11:44 That approach keeps AI in a controlled environment but still requires model compliance.
00:11:45 --> 00:11:48 How do we ensure the AI stays within a controlled enclave?
00:11:48 --> 00:11:53 Use a segmented VLAN or air-gap, apply encryption at rest and in transit.
00:11:53 --> 00:11:56 Do we need FIPS-validated cryptography for CUI?
00:11:57 --> 00:12:03 Yes, per NIST 800-171, FIPS validation is required for all controls.
00:12:03 --> 00:12:06 What is the cost trade-off for private deployment?
00:12:06 --> 00:12:12 At 500 tokens per day, private deployment breaks even within 6 to 12 months.
00:12:12 --> 00:12:14 What if our usage is below that threshold?
00:12:15 --> 00:12:19 Run a cost analysis before purchasing hardware; API may be cheaper.
00:12:19 --> 00:12:22 How does the hardware sizing work for a 31B model?
00:12:23 --> 00:12:30 It may need multiple GPUs; reference clusters use 128 GB unified memory per node.
00:12:30 --> 00:12:33 Do we need to sign any new DFARS clauses?
00:12:33 --> 00:12:38 No new clauses exist yet; consult your legal team to confirm flow-down.
00:12:38 --> 00:12:40 What about the 60-day guidance deadline?
00:12:40 --> 00:12:45 The Secretary must issue guidance within 60 days; monitor for that release.
00:12:45 --> 00:12:48 How do we prepare for a potential 2027 bill?
00:12:49 --> 00:12:53 Review the pending Section 1651; it could add new names to the list.
00:12:54 --> 00:12:57 What if a model is not named but originates from a covered nation?
00:12:57 --> 00:13:02 The statute does not generalize by nation; only named developers are covered.
00:13:02 --> 00:13:06 What if we inadvertently use a covered model in a non-DoD contract?
00:13:07 --> 00:13:12 It remains outside the statutory scope, but contractual flow-down may still apply.
00:13:12 --> 00:13:13 Should we still audit that usage?
00:13:14 --> 00:13:18 Yes, a proactive audit reduces risk across all operations.
00:13:18 --> 00:13:21 What are the first concrete steps a contractor should take?
00:13:21 --> 00:13:25 Start with an inventory of all AI models and their lineage.
00:13:25 --> 00:13:28 Then map each to the 110 NIST controls?
00:13:29 --> 00:13:33 Exactly; document how each model meets or fails the controls.
00:13:33 --> 00:13:35 What about the system security plan?
00:13:35 --> 00:13:39 Update it with the new AI environment, including hardware specs.
00:13:39 --> 00:13:43 Do we need to document risk mitigation for any remaining covered models?
00:13:43 --> 00:13:48 If a waiver is requested, capture all mitigation steps and risk assessments.
00:13:48 --> 00:13:51 How do we avoid common documentation mistakes?
00:13:51 --> 00:13:55 Ensure every entry references the exact model version and vendor.
00:13:55 --> 00:13:58 What if the vendor changes the model after we deploy it?
00:13:59 --> 00:14:02 Treat any new release as a new version; re-audit for coverage.
00:14:02 --> 00:14:05 What questions do clients often ask about this law?
00:14:06 --> 00:14:10 Do I need to remove the model from all systems, or just DoD workflows?
00:14:10 --> 00:14:13 Do I need to get a waiver if I only use it for training?
00:14:13 --> 00:14:16 Do I have to monitor for updates to the 1260H list?
00:14:17 --> 00:14:20 Do I need to change my cloud provider to meet the FedRAMP baseline?
00:14:20 --> 00:14:24 Do I need to re-validate encryption after a hardware upgrade?
00:14:24 --> 00:14:26 What if we have a hybrid cloud environment?
00:14:26 --> 00:14:30 Separate the DoD data path; keep the model in a compliant enclave.
00:14:31 --> 00:14:34 How do we stay ahead of the pending Section 1651?
00:14:34 --> 00:14:38 Track the legislative docket and engage with counsel for early guidance.
00:14:38 --> 00:14:41 What is the impact on our procurement process?
00:14:41 --> 00:14:45 Add a clause that requires the contractor to audit AI lineage.
00:14:45 --> 00:14:47 Should we involve our compliance team early?
00:14:48 --> 00:14:51 Yes, they can align the system security plan with the new requirements.
00:14:52 --> 00:14:55 What is the role of the C3PAO in this context?
00:14:55 --> 00:15:00 They assess the 110 controls but do not evaluate AI lineage.
00:15:00 --> 00:15:03 Will the C3PAO need to re-audit after we replace a model?
00:15:04 --> 00:15:08 They will verify the new model meets the controls and documentation.
00:15:08 --> 00:15:10 What if we use an open-weight model that is not named?
00:15:11 --> 00:15:17 It remains compliant with Section 1532, but you must still map it to NIST controls.
00:15:17 --> 00:15:20 Are there any cost-saving tips for private deployment?
00:15:20 --> 00:15:25 Use quantized models; they run on consumer GPUs and lower memory needs.
00:15:25 --> 00:15:28 What if we need to process 5 million tokens daily?
00:15:29 --> 00:15:33 Private deployment will be 60 to 80 percent cheaper than API spend.
00:15:34 --> 00:15:39 What about the 773 to 1 Level 2 certifications trend?
00:15:39 --> 00:15:44 It shows growing awareness; staying compliant positions you for more contracts.
00:15:44 --> 00:15:47 Do we need to update our POA&M for AI changes?
00:15:47 --> 00:15:51 Yes, add new action items and status updates for AI compliance.
00:15:52 --> 00:15:54 What if we accidentally re-introduce a covered model?
00:15:54 --> 00:15:59 Implement strict access controls and audit logs to detect such events.
00:15:59 --> 00:16:02 How do we handle external consultants using our models?
00:16:03 --> 00:16:07 Require them to sign attestations and confirm model compliance.
00:16:07 --> 00:16:09 What about the 24/7 hybrid approach?
00:16:10 --> 00:16:14 It keeps AI in a controlled environment but still requires model compliance.
00:16:15 --> 00:16:17 Is there a benefit to using a model like Gemma 4?
00:16:17 --> 00:16:22 It is open-weight, not covered by the statute, and under an Apache 2.0 license.
00:16:22 --> 00:16:24 Do we need to purchase a license for Gemma 4?
00:16:25 --> 00:16:29 The Apache 2.0 license is permissive; no purchase needed beyond hardware.
00:16:30 --> 00:16:32 What if we need to fine-tune Gemma 4?
00:16:32 --> 00:16:36 Fine-tuning is allowed; just document the process and data used.
00:16:36 --> 00:16:38 Do we need to report fine-tuning to the Department?
00:16:39 --> 00:16:43 No, unless the fine-tuning is part of DoD contract performance.
00:16:43 --> 00:16:46 What if our model is from a 1260H-designated company?
00:16:47 --> 00:16:51 Consult counsel before using it; it may be added to the statutory list.
Cybersecurity, ai,Compliance,business,