
Managing Claude AI Desktop and Cowork on In-Scope CUI Endpoints
Organizations are questioning if AI tools like Claude Cowork can reside on CUI-in-scope endpoints via policy and training, or if they require strict technical blocks to pass a CMMC Level 2 assessment.
Addressing the proliferation of AI desktop tools like Claude AI Desktop and Cowork on CUI-in-scope endpoints has become a pressing concern for defense contractors navigating CMMC Level 2 assessments. With the upcoming rollout of CMMC 2.0 (32 CFR Part 170), organizations are grappling with how to manage these applications effectively within their environments. The core dilemma revolves around whether policy-based controls and user training are sufficient, or if strict technical blocks are mandated, particularly concerning data egress and the protection of CUI (DFARS 252.204-7012). This issue touches directly upon the Access Control (AC) and System and Communications Protection (SC) families of NIST SP 800-171, as auditors increasingly scrutinize software inventories and data flow diagrams (r/CMMC discussions). The risk of inadvertent CUI leakage via these powerful tools necessitates a robust technical strategy beyond simple 'do not use' policies.
- ›Implement technical application allowlisting to prevent unauthorized AI execution.
- ›Do not rely on 'Policy Only' controls for high-risk data egress points.
- ›Validate that Claude Cowork cannot access local CUI folders via OS permissions.
- ›Update System Security Plans to reflect the specific status of AI desktop tools.
Under CMMC Level 2, organizations must ensure that any software on an in-scope endpoint satisfies AC.L2-3.1.22, which requires identifying and authorizing all software allowed on the system. Because Claude AI Desktop and Cowork interact directly with the local environment and potentially sensitive data streams, mere policy-based restrictions are rarely sufficient to demonstrate compliance during an assessment.
Assessors look for technical implementation of at least-privilege principles (AC.L2-3.1.5) and configuration management (CM.L2-3.4.1). If an application is not explicitly required for business operations involving CUI, the default posture should be a technical block via Application Control or Move-Integrated Allowlisting. Relying solely on training increases the risk of accidental CUI ingestion into the LLM, which constitutes a data spill.
Furthermore, the system must meet SC.L2-3.13.11, which dictates how the system is protected at its boundaries. If Claude is active, it creates a persistent connection to external servers. Without technical controls like CASB, DLP, or endpoint-level execution blocks, the organization cannot effectively prove that non-cleared external services are restricted from accessing or processing CUI resident on the endpoint.