Most defense contractors tracked the FY2026 NDAA for the usual reasons — program funding, acquisition reform, pay tables. A short provision called Section 1513 got far less attention, and it's the one that will change how every company in the Defense Industrial Base uses AI.
What §1513 actually directs
Section 1513 directs the Department of Defense to develop a security framework for artificial intelligence and machine learning — and to incorporate that framework into the regulations contractors already live under: DFARS and CMMC.
Read that again. This isn't a new, separate compliance regime you can choose to opt into. It's an extension of the compliance machinery that already governs your contracts. When the framework lands, it arrives through the same flow-down clauses and certification requirements you're managing today.
Who's covered
The provision reaches entities that develop, deploy, store, or host AI/ML capabilities for DoD. That's a wide net. It isn't limited to companies selling AI products to the government — a contractor that adopts AI tooling inside an environment that touches DoD work is in scope of the direction this is heading.
If your company handles CUI and your employees use AI anywhere near it, this is about you.
Where things stand
The June 16, 2026 Congressional status-update milestone has passed, and implementation planning is live inside DoD. The framework itself isn't a published rule yet — but the direction is set, and the vehicle (DFARS/CMMC incorporation) is named in the statute.
An honest caveat, because you should be skeptical of compliance urgency-mongering: CMMC itself took years to travel from NDAA language to enforceable contract requirements. §1513 may follow a similar arc. If the framework were the only reason to act, waiting would be a defensible strategy.
It isn't the only reason. Two things are true today, regardless of §1513's timeline:
- Flow-down pressure is present-tense. Primes are already asking subcontractors about AI use in questionnaires and supplier reviews. "We'll figure it out when the rule drops" is not an answer that wins work.
- Shadow AI is a present-tense risk. Your employees are almost certainly using commercial AI tools right now — sanctioned or not. Every prompt containing CUI that leaves your boundary is a compliance exposure with or without a new framework. §1513 doesn't create that risk; it guarantees someone will eventually audit for it.
The real meaning of §1513 is this: the era of AI as an unregulated gray zone in defense contracting has an expiration date. Contractors who architect for it now get to adopt AI on their own timeline, with their own budget, choosing the approach that fits how they work. Everyone else retrofits under deadline pressure, against whatever the rule says, at whatever it costs then.
What to do now
You don't need to predict the final rule text to prepare for it. Three moves are safe under any version of the framework:
- Inventory your AI use. All of it — sanctioned tools, personal accounts, AI features embedded in software you already license. You can't secure what you haven't mapped, and an honest inventory almost always turns up shadow AI leadership didn't know about.
- Map your CUI exposure. Which AI touchpoints could plausibly see CUI? Which are safely outside the boundary? Triage use cases into boundary-safe and boundary-internal — the gains from AI don't require gambling your certification if you know which side of the line each use case sits on.
- Choose your boundary architecture. For use cases that must stay inside: GCC-High tenancy with Copilot, a private AI cluster with zero cloud egress, or a hybrid of the two. Each has different economics and different documentation burdens. Deciding deliberately now beats deciding under deadline later.
The bottom line
§1513 is an accelerant, not the fire. The fire is already burning: employees using commercial AI near CUI, primes asking questions, and competitors quietly standing up compliant AI capability. The contractors who treat AI security as an architecture decision — rather than a future compliance emergency — will spend less, choose better, and adopt faster.
If you want the map before the mandate: the Secure AI Readiness Assessment is a fixed-fee, 1–2 week engagement that delivers your AI-use inventory, CUI-exposure map, §1513 exposure summary, and a costed architecture roadmap. You keep the roadmap either way.
