How should contractors update cyber hygiene practices for AI-enhanced threats?
DFARS keeps core security and reporting duties in place, while NIST’s AI overlays are optional, customizable guidance for AI-specific risks.
AI-assisted and automatically checked against the linked primary sources.
What do the official sources establish?
DFARS 204.7302 and clause 252.204-7012 keep the core contractor cyber-hygiene duties centered on covered contractor information systems. According to DFARS, contractors and subcontractors must provide adequate security, and contractors required to implement NIST SP 800-171 must have at award at least a current Basic NIST SP 800-171 DoD Assessment. DFARS also says a reported cyber incident is not, by itself, evidence of failure, though reassessment may be needed in rare circumstances when cybersecurity risks, threats, or awareness have changed. For AI-related issues, NIST’s 2026 Cyber AI Profile workshop summary points to AI attack surfaces, governance challenges, and the need for risk-based guidance and usability resources. NIST’s COSAiS project says the AI control overlays are implementation-focused guidelines for specific AI use cases and components, and the FAQ states organizations are not required to use them. NIST also says the overlays can be customized for a system, mission space, and environment of operation.