The General Services Administration has reissued a heavily revised draft rule governing how contractors must safeguard federal data inside large language model AI systems, and the rewrite is drawing praise from acquisition lawyers and former federal technology officials who criticized the original draft. GSA will hold a public listening session on the draft on July 14, 2026, in Washington, D.C., with written comments due August 3.
Background
GSA first circulated GSAR clause 552.239-7001, "Basic Safeguarding of Data within Large Language Model AI Systems," in an earlier draft that predates the June rewrite. That version applied a single blanket clause to every contractor touching an LLM system, with one uniform set of flow-down obligations regardless of a company's role in the supply chain, and it included a "lawful use" provision alongside a mandatory Made-in-America sourcing requirement for AI systems.
The clause matters because it would govern acquisition of information and communication technology across GSA Schedule contracts and governmentwide acquisition contracts, reaching beyond agencies that explicitly buy AI products. Holland & Knight's analysis of the rule notes GSA carved out exceptions for LLMs embedded in common commercial products and for AI functionality merely incidental to a contract's primary purpose, but contractors outside those carve-outs could still be subject to the safeguarding terms. GSA acknowledged receiving substantial feedback on the original draft before issuing the June rewrite, Federal News Network reported.
GSA responded to that feedback with a substantially rewritten version published in the Federal Register on June 17, 2026. Federal News Network reported on July 7 that the reaction from outside experts has been notably more positive than the reaction to the original text, even as some structural concerns remain unresolved heading into next week's listening session.
Key Details
The June 17 draft narrows the clause's scope and, critically, replaces the single blanket requirement with four separate clauses tailored to distinct roles in the LLM supply chain: developers, operators, integrators, and service providers. That role-based structure is meant to fix the flow-down problem raised during the original comment period, since a systems integrator reselling a third-party model no longer has to certify to the same obligations as the company that actually trained it.
GSA also added a new attestation provision designed to ease the compliance burden on prime contractors managing long subcontractor chains, allowing lower-tier vendors to attest to their own compliance rather than requiring the prime to independently verify every layer of the stack. The revised clause explicitly clarifies that government data will not be used to train commercial models, closing a gap that had left ambiguity in the original draft about what happens to agency data once it passes through a contractor's LLM pipeline.
GSA also dropped two of the most contentious provisions from the original draft outright: the "lawful use" language and the mandatory Made-in-America sourcing requirement for AI systems. Former HHS Chief Information Officer Jose Arrieta told Federal News Network the rewrite is "the most consequential regulation since the agency issued the cloud security rule" to implement FedRAMP, the government's cloud-vendor vetting program. George Washington University law professor Jessica Tillipman said the flow-down mechanics "got much better because it was a blanket flow down initially," crediting GSA for tailoring the requirement by role instead.
Despite the improvements, two concerns carried over into the new draft. Foreign-ownership restrictions in the clause could disqualify or complicate compliance for vendors that rely on foreign investment or foreign-based development teams. Arrieta told Federal News Network the provision "narrows the compliant vendor pool" down to "hyper scalers only," potentially squeezing out smaller and mid-sized competitors. And language requiring "ideological neutrality" in covered AI systems remains vague — Tillipman called the term "very mushy" — with no clear definition of what neutrality means in practice or how contracting officers would evaluate compliance during a proposal or performance review.
Engagement with the docket has been thin. As of the Federal News Network report, only six comments had been filed in the first three weeks after the June 17 publication, and registration for the July 14 listening session closed July 3. The written comment period remains open through August 3, giving contractors roughly three more weeks to weigh in formally even though registration for the in-person session has already closed.
What It Means for Contractors
The role-based clause structure is the single biggest practical change for contractors to model into compliance planning. A company that only integrates a third-party LLM into a larger software product will now face different obligations than the company that trained the underlying model, which should reduce the copy-paste flow-down language that made the original draft difficult to administer across multi-tier subcontracts. Contractors should map where they sit in that four-way taxonomy — developer, operator, integrator, or service provider — before the comment period closes, since the applicable clause and attestation burden differ by category.
The new attestation provision is worth flagging to contracts and compliance teams specifically. If lower-tier subcontractors can self-attest rather than requiring the prime to conduct independent verification, that changes both the risk allocation in teaming agreements and the due-diligence documentation primes will want baked into subcontract terms going forward.
Vendors with foreign ownership stakes or offshore development teams should read the foreign-ownership restrictions closely and consider submitting comments before August 3, since that provision survived the rewrite unchanged and GSA has shown in this cycle that it will act on specific, well-documented industry feedback. The same applies to the "ideological neutrality" language: without a written comment asking GSA to define the term, contracting officers will be left interpreting it clause by clause once the rule is final, which creates exactly the kind of inconsistent enforcement contractors typically want to avoid.
Because the clause applies across GSA Schedule contracts and GWACs rather than a narrow AI-specific vehicle, any company holding a Schedule contract should treat this as relevant even if its current offerings don't market themselves as AI products, unless its LLM use falls within GSA's commercial-embedding or incidental-use carve-outs. The low six-comment count on the docket also means individual submissions carry outsized weight right now — a well-reasoned comment from a mid-sized vendor on the foreign-ownership provision is far more likely to shape the final rule in a docket this thin than it would be in a comment period drawing hundreds of submissions.
Sources
- Federal Register: General Services Acquisition Regulation; Acquisition of Information and Communication Technology; Notice of Listening Sessions and Request for Comments
- GSA praised for initial changes to AI draft regs, but more work needed (Federal News Network, July 7, 2026)
- GSA Proposes Sweeping AI Data Safeguarding Rules for LLM Contractors (Holland & Knight)