The General Services Administration has published a revised proposed rule governing how contractors must safeguard government data processed by large language models, softening several contentious provisions from its earlier draft while leaving a foreign-ownership restriction in place that industry says could push mid-sized and small firms out of the AI contracting market.
Background
GSA's original draft of GSAR clause 552.239-7001 ("Basic Safeguarding of Data Within Large Language Model Artificial Intelligence Systems") drew criticism from contractors and procurement attorneys for its breadth. Per the Holland & Knight analysis, GSA first circulated the clause via GSA Interact in January 2026, followed by an informal March 2026 draft that included a "lawful use" standard and a mandatory "Made in America" requirement many in industry viewed as unworkable for a supply chain built on globally sourced components and models. George Washington University procurement law professor Jessica Tillipman told Federal News Network that earlier version used a single "blanket flow down" that pushed the same obligations onto every subcontractor regardless of role.
GSA published the revised version in the Federal Register on June 17, 2026 (91 Fed. Reg. 36559). Rather than one sweeping clause, the update splits the requirement into four role-specific flow-down clauses — 552.239-7001-1 through -4 — covering LLM developers, operators, integrators, and service providers separately, with a Contractor able to demonstrate compliance either by flowing requirements down or by obtaining attestations from each entity. GSA also dropped the "lawful use" and "Made in America" language.
The changes followed public comment on the January 2026 draft, and GSA has scheduled a public listening session for July 14, 2026, at George Washington Law School in Washington, D.C., open in person and virtually, with written comments due August 3, 2026.
Key Details
The revised clause set carries several core obligations for any contractor whose LLM system touches federal data. The government retains full ownership of all Government Data and Custom Developments processed by an LLM, and the contractor is barred from selling, licensing, or using that data beyond the contract's scope. Contractors must implement automated "eyes off" data handling — technical access controls and, where required, encryption that render government data unreadable to human personnel — so people at the contractor or any third party cannot view it in transit. Each LLM must be developed, managed, and operated by a U.S.-incorporated entity subject to U.S. law, and its operations cannot be controlled by, or subject to compelled disclosure to, a foreign government. Contractors are barred from using government data to train, fine-tune, or otherwise improve any LLM, for the government or for any other commercial or non-commercial purpose. A new "Unbiased AI Principles" requirement obligates contractors to ensure the LLM is truthful, prioritizes accuracy and objectivity, and does not embed partisan or ideological judgments into outputs through training data selection, fine-tuning, or system prompts. Contractors must notify the contracting officer within 72 hours of any known non-adherence to the clause and give at least 30 calendar days' advance notice of material changes. Because the four flow-down clauses assign obligations by role rather than uniformly, an integrator reselling or embedding a third-party model faces a narrower set of duties than the underlying LLM developer — a distinction the earlier single-clause structure did not make.
Reaction from procurement specialists has been largely favorable on the structural changes. Jose Arrieta, the former HHS chief information officer and GSA IT schedule director, called the revised rule the most consequential regulation since GSA implemented FedRAMP, telling Federal News Network that "when this is finalized, every federal AI contract eventually will reference one clause." Tillipman said GSA "got rid of the lawful use and mandatory Made in America provisions that came out in the initial rule," and that the shift to four role-specific clauses plus a new attestation provision "got much better" at easing the burden on primes.
Even with that praise, industry has flagged two provisions as unresolved. The foreign-ownership and foreign-compulsion restriction, Arrieta warned, could narrow the field of eligible LLM providers to a handful of large "hyper-scalers," squeezing out mid-sized and small firms that lack the resources to prove insulation from foreign control. Separately, the "Unbiased AI Principles" standard — which Tillipman characterized as the administration's "no woke AI stuff" — drew her description as "a very mushy term," since the clause does not spell out a testing methodology beyond giving the government the right to run its own undisclosed benchmarks against the deployed model. As of Federal News Network's July 7, 2026 report, only six official comments had been filed in the three weeks since the revised draft was published, a low volume given the rule's reach across GSA's government-wide contract vehicles, which include the Federal Supply Schedule, GWACs, and OASIS+.
What It Means for Contractors
The shift to four flow-down clauses means contractors need to identify precisely which role — developer, operator, integrator, or service provider — applies to each part of their offering, since obligations now differ by role. The new attestation provisions should ease the burden prime contractors previously faced in independently verifying subcontractor compliance, but primes will still need attestations flowing up from every tier touching government data, or must otherwise flow down the clause themselves.
Firms that cannot demonstrate U.S.-based ownership insulated from foreign-government compulsion should assume they may be excluded from GSA LLM work under the current draft, regardless of the quality of their technology — a particular concern for smaller AI vendors that rely on foreign investment, foreign parent companies, or offshore development teams. Such companies should use the comment period to make the case for alternative compliance paths, since the ownership threshold remains the more contested open question — one GSA itself asked commenters to weigh in on: whether the clause "adequately address[es] risks related to foreign ownership or control of LLMs."
Contractors building or reselling LLM-based tools into GSA contracts should also start scoping what automated "eyes off" data handling and a ban on using government data for training will mean for their existing architectures, since both are stated as firm requirements in the current draft. Given the low six-comment count reported so far, contractors that want those provisions clarified have an unusually open field to shape the record — but only if they file before the August 3, 2026 deadline or the July 14 listening session.
Sources
- Federal Register: General Services Acquisition Regulation; Acquisition of Information and Communication Technology; Notice of Listening Sessions and Request for Comments
- GSA praised for initial changes to AI draft regs, but more work needed
- GSA Proposes Sweeping AI Data Safeguarding Rules for LLM Contractors