# AI Acceptable Use Policy for CMMC Level 2

> Download a customizable AI acceptable use policy template for CUI environments, mapped to NIST 800-171 and CMMC Level 2 requirements.

canonical: https://secureframe.com/compliance-resources/ai-acceptable-use-policy

### AI Acceptable Use Policy for NIST 800-171 & CMMC Level 2

Give your team clear rules for using AI tools without exposing CUI, and establish the documented governance that NIST 800-171 and CMMC Level 2 require for external systems. Tailor the policy template to your environment and replace tool-by-tool decisions with a defensible standard.

What you'll get:

- An approved tools table that ties each AI tool to the specific data categories and conditions it's cleared for
- An evaluation process for vetting new AI tools before adopting them
- Incident reporting procedures tied to the 72-hour DoD reporting requirement under DFARS 7012
- A mapping appendix connecting every policy section to its NIST 800-171 Rev 2 requirements and CMMC Level 2 practices
