AI Policy Wiki
Dashboard

GSAR clause 552.239-7001, Basic Safeguarding of Data Within Large Language Model Artificial Intelligence Systems (GSA, June 2026)

high confidence · updated 2026-07-26

GSA Federal Register notice publishing a draft acquisition-regulation clause governing LLMs that process government data, for comment by August 3, 2026. Defines four supply-chain roles — LLM Developer, System Operator, System Integrator, Service Provider — with mandatory flowdown to each; defines Government Data to include prompts, outputs, and derived data; and imposes 'Unbiased AI principles' requiring truthfulness and non-partisanship, backed by a government right to run its own benchmarks against the production system and to hold contractors liable for decommissioning costs after unremediated non-compliance.

Published June 17, 2026 at 91 FR 36559 (FR Doc. 2026-12205, Notice-MVAC-2026-01, Docket No. 2026-0331) by the General Services Administration. Comments were due August 3, 2026, with a public listening session on July 14, 2026 at George Washington Law School.

This is a notice and draft clause, not a final rule: GSA is "publishing this notification and draft clause to gather feedback from stakeholders before taking future action (e.g., deviation and/or formal rulemaking)." It revises a first draft issued through GSA Interact on January 12, 2026, and is informed by EO 14110 and OMB memorandum M-25-22.

The clause "may be used in GSA's Government-wide contracts (e.g., Federal Supply Schedule, GWACs, and OASIS+)," so its reach extends well beyond GSA's own purchasing.

Scope

New GSAR 539.71 directs contracting officers to insert the clause "in solicitations and contracts, including those for commercial products and services, when Government data will be processed by a LLM." Two exceptions narrow it: where "the LLM is embedded in a common commercial product, such as a word processor or map navigation system," and where "the LLM functionality is incidental to the primary purpose of the core requirement being procured."

An LLM is defined by reference to EO 14319 as "a generative artificial intelligence model trained on vast, diverse datasets that enable the model to generate natural-language responses to user prompts," extended to cover "the integrated technical and operational environment in which the model is configured, deployed, operated, monitored, or made available for the processing of Government Data" — so the clause regulates the deployed system, not the model alone.

The four roles and flowdown

The clause's structural innovation is decomposing the supply chain into four roles, each with its own mandatory flowdown sub-clause, and requiring that "where a single entity performs multiple roles, multiple flowdown supplemental clauses should be used."

RoleSub-clauseIllustrative responsibilities from the text
LLM Developer552.239-7001-1"model architecture, training, weights, model cards, safety documentation, base capabilities, acceptable use policies, base safety filters"
LLM System Operator552.239-7001-2"cloud infrastructure, model hosting, endpoints, API availability, runtime security, logging, retention, data residency, capacity management, rate limits"
LLM System Integrator552.239-7001-3"model selection, system prompts, prompt templates, RAG sources, vector stores, tools, plugins, agents, guardrails, filters, fine-tuning data, evaluation criteria, human-review thresholds, output constraints, workflow logic"
LLM Service Provider552.239-7001-4

GSA's stated purpose is "to ensure data safeguarding responsibilities are extended appropriately throughout the complex ecosystem of LLM development and deployment." The Integrator role in particular captures the configuration layer — prompts, retrieval sources, guardrails, human-review thresholds — that sits between a model vendor and a deploying agency and would otherwise fall between contractual obligations.

Government Data

Government Data means Data Inputs plus Data Outputs, both defined broadly.

Data Inputs covers "user prompts, queries, instructions, system prompts, source data, documents, knowledge bases, Government email addresses, user account information," excluding background IP predating the contract.

Data Outputs covers "responses, results, analyses, anonymized data, derivative data, metadata, logs, synthetic data, and any other output or action produced by the LLM, regardless of whether such output incorporates or is derived from Background Data," excluding "technical system-level data that contains no Government information or Government usage context, such as performance metrics, token counts, and processing times."

Bringing anonymized, derivative, and synthetic data expressly within Government Data forecloses the argument that de-identified or model-generated derivatives fall outside contractual protection. Background Data is separately defined to cover contractor-owned material "referenced, retrieved, augmented, or otherwise incorporated into the LLM's processing or outputs through any enrichment mechanism, including… retrieval processes, vector stores, embeddings, knowledge graphs, plugins, tool calls, agent actions."

Transparency, incidents, and portability

The clause requires the LLM to surface, at minimum, "summarized intermediate processing actions and decision points," "model routing decisions with accompanying rationale," and retrieval methods "including complete source attribution with direct links and relevant excerpts from materials used in response generation."

Incident notification runs to "as soon as possible but not longer than within 72 hours of the discovery of any incident," with daily status updates until resolution, preservation of "all relevant logs, forensic images, and incident artifacts for a minimum of 90 calendar days… to support follow-on investigation activity by law enforcement," and completion of the CISA incident reporting form. Where FedRAMP procedures conflict, FedRAMP takes priority for systems required to be FedRAMP Authorized.

Documentation obligations on request include the entity list and role mapping, decision-making logic and operational parameters, model characteristics and limitations, "system documentation consistent with NIST AI Risk Management Framework guidelines… such as system cards or equivalent documentation," privacy-control effectiveness, testing methodologies for the unbiased-AI principles, "known biases (including commercial, political, or personal considerations, advertising, endorsements, or fraudulent/corrupt interests)," and "influence, direction, or control of an adversary foreign governments (see 15 CFR 791.4)." A stated carve-out preserves trade secrets: "The contractor is not required to disclose proprietary source code, model weights, or trade secrets."

Data portability requires export of government data "in open or standard machine-readable formats, together with sufficient associated metadata and schema information," documented APIs, migration tooling, and a bar on "proprietary formats, technical restrictions, additional costs, or additional licensing conditions that materially impair the Government's ability to retrieve, use, or migrate Government Data to another service."

Unbiased AI principles

Paragraph (j)(1) requires that the LLM be "developed and monitored in accordance with" three principles:

"(i) The LLM must be truthful in responding to user prompts seeking factual information or analysis. The LLM must prioritize historical accuracy, scientific inquiry, and objectivity and must acknowledge uncertainty where reliable information is incomplete or contradictory.

(ii) The LLM must be a neutral, nonpartisan tool that does not manipulate responses in favor of ideological dogmas. The Contractor must not intentionally introduce or embed partisan or ideological judgments into the LLM's Data Outputs through methods such as training data selection, fine-tuning, Retrieval-Augmented Generation (RAG) references, system prompts, or other configuration methods."

The third requires continuous improvement processes for detecting and mitigating bias and "systems generating illegal or prohibited content," with regular evaluation "against verified factual sources."

The second principle's list of prohibited mechanisms — training data selection, fine-tuning, RAG references, system prompts, "or other configuration methods" — maps onto the four-role decomposition, reaching each layer at which ideological content could be introduced. The qualifier "intentionally" is doing significant work, since it excludes bias arising without intent.

Government evaluation rights

Paragraph (j)(2) is the enforcement mechanism, and it is unusual in placing testing capability rather than reporting obligations at the centre. The government "reserves the right to conduct automated assessments of the LLM, as deployed and configured for government users, at any time using its own benchmarks," covering "bias, truthfulness, safety, unsolicited ideological content, and other factors determined by the Government." Contractors "must provide tools and interfaces that enable the Government to run its benchmarks in an automated fashion to test the production LLM."

The asymmetry is stated explicitly: "All benchmarks, test data, and methodologies developed or used by the Government for such assessments are considered Government Data. The Government is under no obligation to disclose or provide access to the underlying data, methodologies, or systems," except where they form the basis of an adverse action.

On non-compliance, the government "retains the right to suspend use of the LLM until performance issues are satisfactorily addressed," and a contractor "is liable for reasonable decommissioning costs if the Contracting Officer terminates this contract or task/delivery order for cause for failure to remediate after receiving specific written notice of non-compliance… with the Unbiased AI Principles," capped at a percentage of contract value to be inserted by the contracting officer, with disclosure of the basis to permit remediation.

Questions posed

GSA's five questions for comment identify the provisions it considers unsettled, including whether the roles and flowdown paragraphs are clearly defined, whether commenters understand how to implement the flowdown clauses, and — the substantive one — whether "the clause adequately address[es] risks related to foreign ownership or control of LLMs, where changes to the LLM could covertly affect Government Data, outputs, or decisions without changing the contracting entity."

Relationships