Subnet345

Industries · Military & Defense · Record Substrate

Your AI agents are acting on controlled data an assessor will ask you to account for.

Defense contractors are moving agentic systems into production against CUI. CMMC and NIST 800-171 expect an attributable record of that access. Built by a veteran-led team, the substrate produces it, inside your own boundary, designed to run air-gapped.

CMMC 2.0
Contractors handling CUI must meet Level 2 safeguards (NIST 800-171); assessments are phasing into DoD solicitations. The controls assume an attributable, reviewable record of access to CUI.
DoD IL4 / IL5
Impact Levels govern CUI and higher-sensitivity data in cloud and customer-installed DoD environments. Agents that act on that data inherit the logging and attribution burden.
NIST 800-171 / 800-53
The control baselines behind CUI protection: audit and accountability (AU) and access control (AC) families that presuppose a trail an assessor can interrogate.

§ 01 The problem

Agents are acting on CUI. The trail is not.

The moment AI agents coordinate, handing work between models, tools, and humans, the trail of what touched controlled data disappears. That is not only a technology problem. It is an accountability problem with contract consequences.

Who acted on that CUI, under whose authority, and can you show an assessor? Agent handoffs leave no reviewable record. Decision history lives inside vendor APIs, so when a model changes, the record changes with it, if it survives at all.

That is an operator problem. Subnet345 is built by a veteran-led team that runs a governed multi-agent operation every day.

§ 02 Why now

Can you account for what your agents did with CUI?

AI agents moved from controlled pilots to production faster than any previous enterprise technology. The governance acceptable in a pilot is not acceptable against controlled data. The assessment floor is rising at the same time.

2023 to 2024

Pilots. Agents in sandboxes.

Single models, isolated from controlled data. The attribution question had not arrived because agents were not yet acting on CUI.

2025 to 2026 · Now

Production. Agents touch CUI.

Multi-agent workflows act on controlled data inside contractor environments. CMMC assessments are entering contracts, and the obligation to attribute access to CUI is live, ahead of any AI-specific rule.

2026 to 2027

Enforcement. The assessor asks.

CMMC controls phase in and NIST-aligned baselines expect complete audit logging. The NDAA for FY2026 directs the Department of Defense to build an AI security framework. The obligation to prove what an agent did against controlled data arrives before the rule that names it.

The assessment question

If a DoD assessor asked you to reconstruct every action your agents took against controlled data last quarter, what would you show them?

§ 03 Use cases

Where the substrate lands first.

An attributable record is the precondition for deploying agents against controlled data at all. The contractors that build governed AI agents first carry an advantage into every assessment that follows.

Contract work on CUI

Agents that draft, review, and reconcile against controlled data, with access attributed and reviewable. Speed on the work without losing the record an assessment expects.

Restricted and disconnected environments

Coordination, policy, and the record run inside your boundary. The substrate is designed to run air-gapped: once installed, the substrate needs no route out, so it fits environments that cannot reach the open internet. An offline install path is on the roadmap.

The defense supply chain

Prime and subcontractor accountability across handoffs: which agent acted, under whose authority, against which controlled resource. The record survives the seams between systems and organizations.

§ 04 Against the frameworks

Measured against what the assessment expects.

CMMC, the NIST 800-171 and 800-53 baselines, and the DoD Impact Levels point toward a common expectation: access to controlled data must be attributed, reviewable, and kept inside a controlled boundary. This material does not constitute legal or regulatory advice, and Subnet345 holds no CMMC certification or Impact Level authorization. Assess your obligations with your assessor.

ExpectationAttributable access to controlled data
FrameworkCMMC · 800-171
WithoutNo access trail
With Subnet345Access attributed
ExpectationOperation inside a restricted boundary
FrameworkIL4 / IL5
WithoutCloud-dependent
With Subnet345In-perimeter, designed to run air-gapped
ExpectationReviewable agent action history
FrameworkNIST 800-53 AU
WithoutReconstructed later
With Subnet345Attributed, tamper-evident chain
ExpectationIndependence from a single model vendor
FrameworkSupply-chain risk
WithoutLocked to a vendor
With Subnet345Runtime and model swappable

Sources: CMMC 2.0 (DoD CIO); NIST SP 800-171 (CMMC and DFARS enforce Rev 2 today; Rev 3 is the current NIST publication) and SP 800-53 (Rev 5); DoD Impact Levels (DoD Cloud SRG). Regulatory mapping reviewed: August 2026. Informational, not legal advice.

§ 05 What we ship

The substrate, run by the team that operates one every day.

Subnet345 builds and operates the record substrate for AI agents. We do not advise on governance from the outside. We run an audited multi-agent operation ourselves, inside our own perimeter, on the same substrate we would stand up in yours.

01 / Preserve

Access to controlled data

02 / Reconstruct

Who, what, under whose authority

03 / Avoid lock-in

Keep governance portable

Result

Assessment-ready always

Built by a veteran-led team

The founding team includes U.S. Navy and U.S. Army veterans and operators who ran the infrastructure beneath national-scale security systems. We build for this environment because we came from it.

Immerse before we onboard

We stand the platform up inside your environment first, with your operators, against your telemetry, before you commit to a full rollout. We prove it before we scale it.

Transfer is the deliverable

You should be able to operate the platform without us at any point and keep running. We prove that condition before we step back, not in a proposal.

§ 06 Onboarding

How onboarding starts.

Every rollout begins with a structured conversation and ends with a transfer. No open-ended dependency, no shadow team after the sale. The engineer who stands the platform up is the one who trains your team.

01

Initial conversation · 45 minutes

Understand your current AI agent program, where CUI and controlled data are in scope, and whether this is the right fit for both organizations.

02

Governance assessment · Structured

A structured evaluation of your AI deployments against audit, incident, and CUI-attribution requirements, run inside your environment.

03

Design partner program

Early defense organizations become design partners, shaping the platform alongside the team that operates one every day.

The question we help you answer

Can you prove what your agents did with controlled data, and under whose authority?

If you cannot answer that today, and an assessor asks it tomorrow, Subnet345 is the substrate that changes that answer, inside your own boundary.