00:00:14 --> 00:00:20
Today we dive into the new DoD AI ban that forces contractors to rethink every model they use.
00:00:21 --> 00:00:33
The law, Section 1532 of the FY2026 NDAA, prohibits any contractor from using AI developed by DeepSeek or High Flyer during DoD contract performance.
00:00:33 --> 00:00:38
So if a company runs a DeepSeek model on its own servers, does the ban still apply?
00:00:38 --> 00:00:46
Yes. The statute never mentions deployment mode. Whether the model is in the cloud or on-premises, it still counts as ‘use’.
00:00:46 --> 00:00:50
That's surprising because many think self-hosting might be a loophole.
00:00:50 --> 00:00:56
The law attaches to the developer, not the hosting arrangement. It follows the model wherever it runs.
00:00:56 --> 00:01:01
So a DeepSeek API call or a GPU cluster in a private data center is covered.
00:01:01 --> 00:01:10
Correct. The text says nothing about local-model exemption. The definition of ‘covered artificial intelligence’ runs on developer lineage.
00:01:10 --> 00:01:14
What about fine-tuning a DeepSeek model? Does that change anything?
00:01:14 --> 00:01:22
Fine-tuning still ties back to the base model. The statute includes successor AI developed by DeepSeek or High Flyer.
00:01:22 --> 00:01:25
So any modification doesn't help avoid the prohibition.
00:01:25 --> 00:01:32
Exactly. The prohibition applies to any use in contract performance, regardless of how the model is accessed.
00:01:33 --> 00:01:37
What about other Chinese-origin models like Qwen or GLM? Are they covered?
00:01:38 --> 00:01:44
The statute names only DeepSeek and High Flyer. Qwen, GLM, Kimi, MiniMax are not listed.
00:01:44 --> 00:01:50
But I've heard Alibaba and Baidu were added to a DoD list. Does that change things?
00:01:50 --> 00:01:57
They joined the Section 1260H list, which could trigger a broader prohibition if the Secretary issues guidance.
00:01:57 --> 00:01:59
Has any guidance been issued yet?
00:01:59 --> 00:02:06
No public confirmation exists. The wider category remains a watch item, not a live prohibition.
00:02:06 --> 00:02:09
So for now, only DeepSeek and High Flyer are strictly prohibited.
00:02:10 --> 00:02:16
Yes, but be aware that pending legislation could add more names, and the current list is contested.
00:02:16 --> 00:02:23
Let's talk about compliance frameworks. Does CMMC or NIST 800-171 mention these AI restrictions?
00:02:23 --> 00:02:32
Neither does. CMMC maps to 110 controls of NIST 800-171, but there is no AI-origin rule.
00:02:33 --> 00:02:36
So the statutory ban is separate from CMMC compliance.
00:02:36 --> 00:02:44
Correct. The ban applies to the use of covered AI, while CMMC requires adequate security controls for every system.
00:02:44 --> 00:02:50
What about DFARS 252-7012? Does it involve AI models?
00:02:50 --> 00:03:03
DFARS 252-7012 mandates that covered contractor systems meet the same 110 controls, and cloud providers must meet FedRAMP Moderate or equivalent.
00:03:03 --> 00:03:06
So removing DeepSeek doesn't satisfy DFARS?
00:03:06 --> 00:03:15
No. DFARS concerns control implementation, not model lineage. You still need to address the statutory prohibition separately.
00:03:16 --> 00:03:20
Understood. Let's discuss the practical steps a contractor should take.
00:03:20 --> 00:03:29
First, inventory every AI model in use, both commercial and self-hosted, and trace each against the covered AI definition.
00:03:29 --> 00:03:31
How do you trace a model to the definition?
00:03:31 --> 00:03:41
Check the developer lineage. If the model originates from DeepSeek or High Flyer, or an entity with at least 20 percent stake in High Flyer, it is covered.
00:03:41 --> 00:03:45
What about models that are not named? Do they automatically comply?
00:03:45 --> 00:03:54
Not automatically. They still need to be secured under the 110 controls. You must verify they don’t send CUI to external systems.
00:03:54 --> 00:03:58
So the next step is mapping the environment to the 110 controls?
00:03:58 --> 00:04:10
Exactly. Use the seven-stage method: define the data boundary, prototype with your data, size hardware, isolate the cluster, deploy the model, layer access controls, and validate.
00:04:10 --> 00:04:12
Could you give an example of hardware sizing?
00:04:13 --> 00:04:23
A 7B parameter model runs on a single NVIDIA A100 or H100 GPU. Larger models may need two to four GPUs.
00:04:23 --> 00:04:27
What about open-weight models like Gemma 4? Are they suitable for DoD work?
00:04:28 --> 00:04:35
Gemma 4 is released under Apache 2.0, and it is not named in any U.S. restriction. It can be a compliant replacement.
00:04:36 --> 00:04:37
Does the license matter for procurement?
00:04:38 --> 00:04:45
Yes. Apache 2.0 is commercially permissive, so your procurement team can handle it without additional legal hurdles.
00:04:45 --> 00:04:47
What about compliance documentation?
00:04:47 --> 00:05:00
Petronella Technology Group provides a compliance platform called ComplianceArmor®. It automates SSP authoring, POA&M tracking, and evidence repository organization.
00:05:00 --> 00:05:03
So you can integrate the inventory and removal record into that system?
00:05:04 --> 00:05:11
Exactly. That documentation feeds into your system security plan and ensures you have evidence before any audit.
00:05:12 --> 00:05:15
What about the waiver mechanism? Can we get a waiver for using DeepSeek?
00:05:16 --> 00:05:28
Section 1532(b) offers waivers only for scientific research, national security, counterterrorism, or mission-critical functions, with risk mitigation steps.
00:05:28 --> 00:05:30
So ordinary contract analytics wouldn't qualify?
00:05:31 --> 00:05:38
Correct. The categories are narrow, and the waiver is an affirmative government decision, not an internal exception.
00:05:38 --> 00:05:41
If we can't get a waiver, what is the next best action?
00:05:41 --> 00:05:50
Remove the model from any DoD contract workflow and replace it with an unnamed, compliant model like Gemma 4 or Llama 3.1.
00:05:50 --> 00:05:54
Does that satisfy DFARS 252-7012?
00:05:55 --> 00:06:03
Yes, provided you implement the 110 controls for the new model environment. DFARS is about security, not lineage.
00:06:03 --> 00:06:08
What about the intelligence community? Does Section 6604 affect us?
00:06:08 --> 00:06:18
Section 6604 prohibits DeepSeek on intelligence community systems, and it directs the Director of National Intelligence to develop standards.
00:06:18 --> 00:06:23
So if we support an IC element, the ban applies even if the broader Section 1532 doesn't?
00:06:24 --> 00:06:30
Correct. Section 6604 is application-focused and reaches IC contractors directly.
00:06:30 --> 00:06:33
So we need to check whether we work with any IC element.
00:06:33 --> 00:06:39
Yes. If you do, you must remove DeepSeek from those workflows and replace it with a compliant model.
00:06:40 --> 00:06:42
Let's talk about the timeline. When do we need to act?
00:06:43 --> 00:06:54
Section 1532(a)(1) required the Department to remove covered AI from its systems within 30 days of enactment. The same pace applies downstream.
00:06:54 --> 00:06:57
So we have a 30-day window to audit our systems?
00:06:57 --> 00:07:04
Yes, but the audit expectation is already explicit in practitioner guidance. You should start immediately.
00:07:04 --> 00:07:08
What about the pending FY2027 bill? Should we wait for it?
00:07:08 --> 00:07:19
The bill could add names like Baidu, Zhipu AI, Moonshot AI, 01.AI, MiniMax, Alibaba, and Tencent. Until it becomes law, treat it as a watch item.
00:07:19 --> 00:07:22
So we should monitor guidance and stay ready to adjust?
00:07:22 --> 00:07:29
Exactly. Set a review cadence for any new guidance or legislation, and keep your compliance documentation up to date.
00:07:30 --> 00:07:33
What if we accidentally use a covered model in a non-DoD contract?
00:07:34 --> 00:07:41
The prohibition is limited to DoD contract performance. Non-DoD contracts are outside the statutory scope.
00:07:41 --> 00:07:45
But could that still trigger a flow-down clause or other contractual obligation?
00:07:46 --> 00:07:53
It depends on the specific DFARS clause. The statute didn't create a new clause, so you need to consult counsel.
00:07:53 --> 00:07:57
So it's safest to audit all AI use regardless of contract type.
00:07:57 --> 00:08:03
Yes, that proactive approach reduces risk and ensures compliance across all operations.
00:08:03 --> 00:08:06
How do we document the removal of a covered model?
00:08:06 --> 00:08:13
Record the model version, the date of removal, the reason, and the replacement model details in your system security plan.
00:08:14 --> 00:08:17
And we should keep evidence of the waiver if we ever apply for one?
00:08:17 --> 00:08:24
Yes, maintain signed attestations, risk mitigation plans, and any official waiver documents.
00:08:24 --> 00:08:26
What are the key takeaways for a contractor right now?
00:08:27 --> 00:08:38
Audit all AI, remove covered models from DoD workflows, replace with compliant open-weight models, map to the 110 controls, and stay alert to new guidance.
00:08:38 --> 00:08:43
What are the deeper implications if a contractor ignores Section 1532?
00:08:44 --> 00:08:49
Ignoring it could trigger enforcement actions, penalties, and loss of DoD contracts.
00:08:49 --> 00:08:52
Could those penalties be monetary or purely contractual?
00:08:53 --> 00:08:56
Both; the law can impose fines and force contract termination.
00:08:57 --> 00:08:59
Is there a risk of a broader security audit?
00:08:59 --> 00:09:03
Yes, auditors may scrutinize all AI systems tied to DoD work.
00:09:04 --> 00:09:06
How does this affect non-DoD data handling?
00:09:06 --> 00:09:11
Non-DoD data can still be processed, but the model must be compliant.
00:09:11 --> 00:09:13
What about the hardware cost for a compliant model?
00:09:14 --> 00:09:21
A 7B parameter model fits on a single NVIDIA A100, but larger ones need multiple GPUs.
00:09:21 --> 00:09:24
Do we need to size the cluster before choosing a model?
00:09:24 --> 00:09:28
Yes, a scoping prototype on your data informs hardware sizing.
00:09:29 --> 00:09:32
What if we have a mix of models, some covered, some not?
00:09:32 --> 00:09:36
Separate them by workflow; remove covered ones from DoD paths.
00:09:36 --> 00:09:39
Can we still use a covered model for training only?
00:09:39 --> 00:09:45
Section 1532(b) allows case-by-case waivers for research or training.
00:09:45 --> 00:09:47
How do we apply for such a waiver?
00:09:47 --> 00:09:52
Submit a formal request with risk mitigation steps; approval is government-issued.
00:09:53 --> 00:09:54
If we get denied, what then?
00:09:55 --> 00:09:58
You must replace the model before continuing DoD work.
00:09:58 --> 00:10:00
What are the common mistakes we should avoid?
00:10:01 --> 00:10:05
Assuming local hosting is exempt; assuming fine-tuning removes coverage.
00:10:05 --> 00:10:07
Is fine-tuning a new model under the law?
00:10:08 --> 00:10:12
No, the base model remains covered regardless of modifications.
00:10:12 --> 00:10:15
How do we document that we have removed a covered model?
00:10:15 --> 00:10:21
Log the version, removal date, reason, and replacement details in the system security plan.
00:10:22 --> 00:10:25
Do we need to update the system security plan for every change?
00:10:25 --> 00:10:29
Yes, keep the plan current to reflect the latest AI environment.
00:10:29 --> 00:10:31
What about the 30-day window for removal?
00:10:31 --> 00:10:36
The statute gave the Department 30 days; contractors should act promptly.
00:10:36 --> 00:10:39
Should we monitor for new guidance from the Secretary?
00:10:39 --> 00:10:46
Absolutely; a review cadence every 60 days keeps you aligned with Section 1532(a)(2).
00:10:46 --> 00:10:49
How does CMMC Level 2 interact with this requirement?
00:10:50 --> 00:10:57
CMMC Level 2 maps to NIST 800-171 controls but does not lift the statutory ban.
00:10:58 --> 00:11:01
So we still need to remove covered models even with a CMMC certificate?
00:11:02 --> 00:11:06
Correct; compliance frameworks and statutes operate independently.
00:11:06 --> 00:11:09
What if we use a model from an unnamed Chinese-origin company?
00:11:10 --> 00:11:16
Check the 1260H list and pending Section 1651; these may be added later.
00:11:16 --> 00:11:19
Does the 1260H list immediately impose a ban?
00:11:20 --> 00:11:27
Only if the Secretary issues guidance under Section 1532(a)(2); currently, it's a watch item.
00:11:27 --> 00:11:30
Could a vendor's 20 percent stake trigger coverage?
00:11:30 --> 00:11:35
Yes, any entity with at least 20 percent stake in High Flyer is covered.
00:11:35 --> 00:11:39
What about the 24/7 AI-plus-human hybrid threat analysis?
00:11:39 --> 00:11:44
That approach keeps AI in a controlled environment but still requires model compliance.
00:11:45 --> 00:11:48
How do we ensure the AI stays within a controlled enclave?
00:11:48 --> 00:11:53
Use a segmented VLAN or air-gap, apply encryption at rest and in transit.
00:11:53 --> 00:11:56
Do we need FIPS-validated cryptography for CUI?
00:11:57 --> 00:12:03
Yes, per NIST 800-171, FIPS validation is required for all controls.
00:12:03 --> 00:12:06
What is the cost trade-off for private deployment?
00:12:06 --> 00:12:12
At 500 tokens per day, private deployment breaks even within 6 to 12 months.
00:12:12 --> 00:12:14
What if our usage is below that threshold?
00:12:15 --> 00:12:19
Run a cost analysis before purchasing hardware; API may be cheaper.
00:12:19 --> 00:12:22
How does the hardware sizing work for a 31B model?
00:12:23 --> 00:12:30
It may need multiple GPUs; reference clusters use 128 GB unified memory per node.
00:12:30 --> 00:12:33
Do we need to sign any new DFARS clauses?
00:12:33 --> 00:12:38
No new clauses exist yet; consult your legal team to confirm flow-down.
00:12:38 --> 00:12:40
What about the 60-day guidance deadline?
00:12:40 --> 00:12:45
The Secretary must issue guidance within 60 days; monitor for that release.
00:12:45 --> 00:12:48
How do we prepare for a potential 2027 bill?
00:12:49 --> 00:12:53
Review the pending Section 1651; it could add new names to the list.
00:12:54 --> 00:12:57
What if a model is not named but originates from a covered nation?
00:12:57 --> 00:13:02
The statute does not generalize by nation; only named developers are covered.
00:13:02 --> 00:13:06
What if we inadvertently use a covered model in a non-DoD contract?
00:13:07 --> 00:13:12
It remains outside the statutory scope, but contractual flow-down may still apply.
00:13:12 --> 00:13:13
Should we still audit that usage?
00:13:14 --> 00:13:18
Yes, a proactive audit reduces risk across all operations.
00:13:18 --> 00:13:21
What are the first concrete steps a contractor should take?
00:13:21 --> 00:13:25
Start with an inventory of all AI models and their lineage.
00:13:25 --> 00:13:28
Then map each to the 110 NIST controls?
00:13:29 --> 00:13:33
Exactly; document how each model meets or fails the controls.
00:13:33 --> 00:13:35
What about the system security plan?
00:13:35 --> 00:13:39
Update it with the new AI environment, including hardware specs.
00:13:39 --> 00:13:43
Do we need to document risk mitigation for any remaining covered models?
00:13:43 --> 00:13:48
If a waiver is requested, capture all mitigation steps and risk assessments.
00:13:48 --> 00:13:51
How do we avoid common documentation mistakes?
00:13:51 --> 00:13:55
Ensure every entry references the exact model version and vendor.
00:13:55 --> 00:13:58
What if the vendor changes the model after we deploy it?
00:13:59 --> 00:14:02
Treat any new release as a new version; re-audit for coverage.
00:14:02 --> 00:14:05
What questions do clients often ask about this law?
00:14:06 --> 00:14:10
Do I need to remove the model from all systems, or just DoD workflows?
00:14:10 --> 00:14:13
Do I need to get a waiver if I only use it for training?
00:14:13 --> 00:14:16
Do I have to monitor for updates to the 1260H list?
00:14:17 --> 00:14:20
Do I need to change my cloud provider to meet the FedRAMP baseline?
00:14:20 --> 00:14:24
Do I need to re-validate encryption after a hardware upgrade?
00:14:24 --> 00:14:26
What if we have a hybrid cloud environment?
00:14:26 --> 00:14:30
Separate the DoD data path; keep the model in a compliant enclave.
00:14:31 --> 00:14:34
How do we stay ahead of the pending Section 1651?
00:14:34 --> 00:14:38
Track the legislative docket and engage with counsel for early guidance.
00:14:38 --> 00:14:41
What is the impact on our procurement process?
00:14:41 --> 00:14:45
Add a clause that requires the contractor to audit AI lineage.
00:14:45 --> 00:14:47
Should we involve our compliance team early?
00:14:48 --> 00:14:51
Yes, they can align the system security plan with the new requirements.
00:14:52 --> 00:14:55
What is the role of the C3PAO in this context?
00:14:55 --> 00:15:00
They assess the 110 controls but do not evaluate AI lineage.
00:15:00 --> 00:15:03
Will the C3PAO need to re-audit after we replace a model?
00:15:04 --> 00:15:08
They will verify the new model meets the controls and documentation.
00:15:08 --> 00:15:10
What if we use an open-weight model that is not named?
00:15:11 --> 00:15:17
It remains compliant with Section 1532, but you must still map it to NIST controls.
00:15:17 --> 00:15:20
Are there any cost-saving tips for private deployment?
00:15:20 --> 00:15:25
Use quantized models; they run on consumer GPUs and lower memory needs.
00:15:25 --> 00:15:28
What if we need to process 5 million tokens daily?
00:15:29 --> 00:15:33
Private deployment will be 60 to 80 percent cheaper than API spend.
00:15:34 --> 00:15:39
What about the 773 to 1 Level 2 certifications trend?
00:15:39 --> 00:15:44
It shows growing awareness; staying compliant positions you for more contracts.
00:15:44 --> 00:15:47
Do we need to update our POA&M for AI changes?
00:15:47 --> 00:15:51
Yes, add new action items and status updates for AI compliance.
00:15:52 --> 00:15:54
What if we accidentally re-introduce a covered model?
00:15:54 --> 00:15:59
Implement strict access controls and audit logs to detect such events.
00:15:59 --> 00:16:02
How do we handle external consultants using our models?
00:16:03 --> 00:16:07
Require them to sign attestations and confirm model compliance.
00:16:07 --> 00:16:09
What about the 24/7 hybrid approach?
00:16:10 --> 00:16:14
It keeps AI in a controlled environment but still requires model compliance.
00:16:15 --> 00:16:17
Is there a benefit to using a model like Gemma 4?
00:16:17 --> 00:16:22
It is open-weight, not covered by the statute, and under an Apache 2.0 license.
00:16:22 --> 00:16:24
Do we need to purchase a license for Gemma 4?
00:16:25 --> 00:16:29
The Apache 2.0 license is permissive; no purchase needed beyond hardware.
00:16:30 --> 00:16:32
What if we need to fine-tune Gemma 4?
00:16:32 --> 00:16:36
Fine-tuning is allowed; just document the process and data used.
00:16:36 --> 00:16:38
Do we need to report fine-tuning to the Department?
00:16:39 --> 00:16:43
No, unless the fine-tuning is part of DoD contract performance.
00:16:43 --> 00:16:46
What if our model is from a 1260H-designated company?
00:16:47 --> 00:16:51
Consult counsel before using it; it may be added to the statutory list.