AI Policy Wiki
Dashboard

GSA — General Services Administration (AI Deployer)

high confidence · updated 2026-08-12

Federal procurement agency driving the OneGov AI-adoption blitz: $1-per-agency deals with OpenAI, Anthropic, Google + USAi.gov platform + Procurement Ecosystem Initiative.

The General Services Administration (GSA) is the principal US government vehicle for federal AI procurement. In August 2025 it ran a concentrated set of AI-procurement actions branded "OneGov," pairing $1-per-agency deals with major AI vendors with a free government evaluation platform and a request for input on a longer-term acquisition framework. GSA's role in AI acquisition is grounded in a statutory mandate under the AI in Government Act of 2020.

Mandate

Under the AI in Government Act of 2020, GSA is statutorily required to establish and carry out the AI Center of Excellence (housed in Technology Transformation Services); to convene agencies, industry, federal labs, and others to discuss AI developments; to advise the GSA Administrator, the OMB Director, and agencies on AI acquisition and use; to develop a plan to release guidance to the acquisition workforce on procuring AI systems; to support agencies in AI acquisition knowledge and resource sharing; and to advise the OSTP and OMB Directors on AI policy. The AI Center of Excellence is mandated by federal law rather than established as a discretionary initiative. This mandate is documented in GAO-25-107933 as one of the 94 government-wide AI requirements. (Source: GAO-25-107933: AI Federal Efforts Guided by Requirements and Advisory Groups)

OneGov procurement program

The OneGov actions launched in August 2025 combined a shared evaluation platform, a set of low-cost vendor agreements, and a request for input on a standing acquisition framework.

The USAi platform, launched August 14, 2025, is a free generative AI evaluation suite at USAi.gov available to all federal agencies. See GSA OneGov Program and USAi Platform (August 2025).

The OneGov vendor agreements offered software at $1 per agency per year and related savings, with OpenAI, Anthropic (Claude for Gov at FedRAMP High), Google (Gemini for Government), AWS (up to $1B in federal IT savings), and Box. The individual agreements were:

DateVendorTerms
2025-08-06OpenAIChatGPT Enterprise at $1/agency/year
2025-08-07AWSUp to $1B federal IT savings
2025-08-12AnthropicClaude for Gov (FedRAMP High) + Enterprise at $1/agency/year
2025-08-13BoxBox AI for workflow automation
2025-08-21GoogleGemini for Government OneGov
2026-07-28CORASAgentic AI platform; discounts available until September 20, 2027

The agreements provided simultaneous access to multiple vendors, described as a hedge against lock-in, and the $1 price point positioned vendors to capture government as a strategic channel rather than a revenue source, with potential conversion to paid contracts after pilots. On August 14, 2025, Public Citizen criticized the program, raising a corporate-capture risk.

The program has continued to add vendors beyond the August 2025 cohort, and beyond chat and document tooling. GSA announced a OneGov agreement with the agentic AI provider CORAS on July 28, 2026, with discounts available until September 20, 2027. Laura Stanton, Acting Commissioner of GSA's Federal Acquisition Service, said the agreement expands the AI-enabled capabilities available to agencies. Only the lede of the trade-press account was retrievable, so the agreement's pricing structure and scope are not recorded here (Source: insideaipolicy.com). See Agentic AI, Government AI Procurement.

The Procurement Ecosystem Initiative, a request for information (RFI) issued August 18, 2025, sought input on an AI-incorporated federal procurement ecosystem, addressing long-term federal AI adoption beyond one-year pilots.

GSAR AI-specific acquisition rule

GSA is preparing a draft AI-specific acquisition rule for the General Services Acquisition Regulation (GSAR), expected within "the next couple of weeks," two sources familiar told Nextgov/FCW on May 29, 2026. The rule would set a preference for firm-fixed-price contracting for AI and IT software and is framed as making GSA a "more predictable business partner" to AI developers, with a 30-day public comment window to follow publication. (Source: nextgov.com)

Where the August 2025 OneGov deals were one-off negotiated agreements, a GSAR amendment would make AI-procurement terms a standing part of the federal acquisition rulebook. The firm-fixed-price preference contrasts with the usage-metered token pricing and rapid model turnover of frontier AI software, which fit awkwardly into fixed-price contracting and set up a tension between GSA's stated predictability goal and vendors' consumption-based commercial models.

On June 17, 2026 GSA reopened the comment period on its AI-contract clause and published revised Federal Register text that dropped the earlier "any lawful purpose" language, which vendors had read as obligating them to permit government use of their models for any lawful purpose regardless of their own usage policies. The revision followed industry objections that the original phrasing conflicted with developers' acceptable-use restrictions (Source: insideaipolicy.com). As the comment deadline approached in July 2026, the Business Software Alliance requested nine changes to the proposed AI contract clause, including scoping revisions (Source: insideaipolicy.com). The rulemaking also addresses safeguarding data when large language models process government information, setting privacy and security standards for companies seeking to contract with the government; Axios characterized GSA procurement guidelines as among the building blocks of an administration "shadow AI policy" shaping the industry through procurement and export controls rather than formal rulemaking (GSAR clause 552.239-7001, Basic Safeguarding of Data Within Large Language Model Artificial Intelligence Systems (GSA, June 2026); Source: axios.com).

The June 17 text (GSAR clause 552.239-7001, Basic Safeguarding of Data Within Large Language Model Artificial Intelligence Systems (GSA, June 2026)) sets out draft clause 552.239-7001, applying "when Government data will be processed by a LLM" and excepting LLMs "embedded in a common commercial product" or where the functionality "is incidental to the primary purpose." Its structural feature is decomposing the supply chain into four roles with mandatory flowdown sub-clauses — LLM Developer (architecture, training, weights, model cards, base safety filters), System Operator (hosting, endpoints, runtime security, logging, retention, data residency), System Integrator (model selection, system prompts, RAG sources, vector stores, tools, guardrails, fine-tuning data, human-review thresholds), and Service Provider — with multiple sub-clauses required where one entity performs several roles. Government Data is defined to include prompts, outputs, and "anonymized data, derivative data, metadata, logs, synthetic data," excluding only system-level telemetry such as token counts and processing times.

The clause's most consequential provisions are paragraph (j)'s Unbiased AI principles and the evaluation rights attached to them. It requires the model to be "truthful," to "prioritize historical accuracy, scientific inquiry, and objectivity," to "acknowledge uncertainty where reliable information is incomplete or contradictory," and to be "a neutral, nonpartisan tool that does not manipulate responses in favor of ideological dogmas," with contractors barred from intentionally embedding partisan or ideological judgments "through methods such as training data selection, fine-tuning, Retrieval-Augmented Generation (RAG) references, system prompts, or other configuration methods." Enforcement runs through testing rather than reporting: the government "reserves the right to conduct automated assessments of the LLM, as deployed and configured for government users, at any time using its own benchmarks," contractors must supply tools enabling those benchmarks to run against the production system, and the benchmarks themselves remain Government Data that the government "is under no obligation to disclose" except where they ground an adverse action. Non-compliance can result in suspension of use and, after unremediated written notice, contractor liability for decommissioning costs capped at a contracting-officer-specified percentage of contract value (GSAR clause 552.239-7001, Basic Safeguarding of Data Within Large Language Model Artificial Intelligence Systems (GSA, June 2026)).

Other obligations include 72-hour incident notification with 90-day preservation of logs and forensic images, disclosure on request of "influence, direction, or control of an adversary foreign governments (see 15 CFR 791.4)" alongside NIST AI RMF-consistent system documentation — subject to a carve-out that contractors need not disclose "proprietary source code, model weights, or trade secrets" — and data-portability terms barring "proprietary formats, technical restrictions, additional costs, or additional licensing conditions" that impair migration. GSA's own questions for comment single out whether the clause "adequately address[es] risks related to foreign ownership or control of LLMs, where changes to the LLM could covertly affect Government Data, outputs, or decisions without changing the contracting entity" (GSAR clause 552.239-7001, Basic Safeguarding of Data Within Large Language Model Artificial Intelligence Systems (GSA, June 2026)).

Software and government-contractor groups told GSA on August 6, 2026 that the revised clause reflects industry input, citing a narrowed license grant and preserved contractor ownership of underlying intellectual property, and urged continued engagement as GSA finalizes the terms following the 45-day public comment period (Source: insideaipolicy.com). That response reaches the record through a paywalled lede, and the groups are not named in the retrievable text.

The draft clause is tracked as a legislative instrument at GSAR 552.239-7001 — Basic Safeguarding of Data Within LLM AI Systems (US, proposed).

Palantir called on August 11, 2026 for GSA to withdraw the draft clause entirely, arguing that "GSA -- acting alone, as it is here -- has no independent authority to promulgate a rule that would regulate government-wide acquisition of AI" and that the proposal would turn AI vendors away from GSA's contract vehicles. The agency is reviewing industry and other stakeholder input on the draft (Source: insideaipolicy.com). Only the article's lede was retrievable, so the full argument is not verified beyond that summary.

FedRAMP and vendor security

FedRAMP, the federal cloud-security authorization program GSA administers, moved toward a harder line on vendor patching after the July 2026 OpenAI–Hugging Face breach. On July 23, 2026, FedRAMP director Pete Waterman said technology companies that cannot fix dangerous, internet-exposed vulnerabilities within days should not be allowed to sell to federal agencies, citing vendor resistance surfaced by the breach, though he announced no new enforcement actions (Source: nextgov.com). Speaking on the same day at Carahsoft's FedRAMP Summit in Washington about AI developers' security practices after the breach, Waterman said: "I don't want you in the federal marketplace, and you shouldn't be selling your software to anyone" (Source: nextgov.com).

The security posture and the procurement pipeline moved in parallel. OpenAI made its GPT-5.6 family — Sol, Terra and Luna — available to federal customers on July 10, 2026, one day after the public release, through the FedRAMP-authorized ChatGPT Enterprise offering. Several 5.6 models reached all staff at the Department of Health and Human Services in late July through its OneGov purchase, with GPT-5.6 Sol available "at various reasoning levels." The models handle workflows within FedRAMP's Moderate clearance level, covering controlled unclassified information; ChatGPT Enterprise received FedRAMP Moderate authorization in April 2026, and a government-specific version of ChatGPT was first certified in January 2025 (Source: nextgov.com).

Internal AI adoption

GSA Deputy Administrator Michael Lynch said on June 12, 2026 that about 70% of GSA's workforce regularly uses AI, which he credited with unlocking "about 400,000 hours of just automation" (Source: nextgov.com). See Federal AI Adoption — Patterns and Tensions.

Relationships