Draft acquisition-regulation clause published by the General Services Administration at 91 FR 36559 on 17 June 2026 (FR Doc. 2026-12205, Notice-MVAC-2026-01), with comments due 3 August 2026. Primary text: GSAR clause 552.239-7001, Basic Safeguarding of Data Within Large Language Model Artificial Intelligence Systems (GSA, June 2026).
Status
This is a notice and request for comments on a draft clause, not a final rule. GSA states it is "publishing this notification and draft clause to gather feedback from stakeholders before taking future action (e.g., deviation and/or formal rulemaking)," and the text revises a first draft circulated through GSA Interact on 12 January 2026. Because the clause "may be used in GSA's Government-wide contracts (e.g., Federal Supply Schedule, GWACs, and OASIS+)," its practical reach extends across federal purchasing rather than GSA's own.
Scope
New GSAR 539.71 directs contracting officers to insert the clause "in solicitations and contracts, including those for commercial products and services, when Government data will be processed by a LLM," excepting LLMs "embedded in a common commercial product, such as a word processor or map navigation system" and cases where "the LLM functionality is incidental to the primary purpose."
An LLM is defined by reference to EO 14319 and extended to "the integrated technical and operational environment in which the model is configured, deployed, operated, monitored, or made available" — the clause regulates the deployed system, not the model in isolation.
Key provisions
Four roles with mandatory flowdown. The clause decomposes the supply chain into LLM Developer (architecture, training, weights, model cards, base safety filters), System Operator (hosting, endpoints, runtime security, logging, retention, data residency), System Integrator (model selection, system prompts, RAG sources, vector stores, tools, guardrails, fine-tuning data, human-review thresholds), and Service Provider, each with its own sub-clause. Where one entity performs several roles, multiple sub-clauses apply. The Integrator role is the notable addition: it reaches the configuration layer between a model vendor and a deploying agency that conventional prime-subcontractor terms leave unallocated.
Government Data. Defined to include prompts, system prompts, knowledge bases, and outputs, with outputs expressly covering "anonymized data, derivative data, metadata, logs, synthetic data," excluding only system-level telemetry such as token counts and processing times.
Unbiased AI principles. Paragraph (j)(1) requires the model to be "truthful," to "prioritize historical accuracy, scientific inquiry, and objectivity," to "acknowledge uncertainty where reliable information is incomplete or contradictory," and to be "a neutral, nonpartisan tool that does not manipulate responses in favor of ideological dogmas," barring contractors from intentionally embedding partisan judgments "through methods such as training data selection, fine-tuning, Retrieval-Augmented Generation (RAG) references, system prompts, or other configuration methods."
Government evaluation rights. Enforcement runs through testing rather than reporting. The government may "conduct automated assessments of the LLM, as deployed and configured for government users, at any time using its own benchmarks," contractors must supply tools enabling those benchmarks to run against production, and the benchmarks remain Government Data the agency "is under no obligation to disclose" except where they ground an adverse action. Remedies run from suspension of use to contractor liability for decommissioning costs after unremediated written notice.
Other obligations. 72-hour incident notification with 90-day preservation of logs and forensic images; disclosure on request of NIST AI RMF-consistent documentation and of "influence, direction, or control of an adversary foreign governments (see 15 CFR 791.4)," subject to a carve-out for source code, weights, and trade secrets; and data-portability terms barring formats or licence conditions that impair migration.
Comparison with other approaches
The clause is the clearest US instance of procurement-driven AI governance: it imposes obligations that no US statute imposes generally, through contract terms that bind only vendors selling to the federal government. Where the EU AI Act regulates by risk classification and applies to all providers, this reaches conduct through purchasing power and applies only within the contract.
Its "Unbiased AI principles" implement the policy of EO 14319 through acquisition terms, and its documentation requirements route through the NIST AI RMF rather than creating a new standard.
Key tensions
The truthfulness and non-partisanship requirements are stated as objective properties but assessed by benchmarks the government need not disclose, which gives the buyer both the standard and the measurement. The "intentionally" qualifier in the non-partisanship principle also excludes bias that arises without intent — which is the form most of the bias literature is concerned with. GSA's own questions for comment single out the residual gap it considers unresolved: whether the clause reaches "risks related to foreign ownership or control of LLMs, where changes to the LLM could covertly affect Government Data, outputs, or decisions without changing the contracting entity."
Relationships
- instance-of: Procurement-Driven AI Governance
- related: Executive Order 14319 — Preventing Woke AI in the Federal Government — the policy the unbiased-AI principles implement contractually
- related: GSA — General Services Administration (AI Deployer), NIST AI Risk Management Framework 1.0, Government AI Procurement, Federal AI Adoption — Patterns and Tensions, GSAR clause 552.239-7001, Basic Safeguarding of Data Within Large Language Model Artificial Intelligence Systems (GSA, June 2026)