Companies that sell large language models, chatbots or agentic tools through GSA will soon have to accept a fixed set of data-handling terms: no training on government data, 72-hour violation notices and certified deletion of fine-tuned weights when the work ends. The requirements sit in clause 552.239-7001, part of GSA memo RGO-2026-01, a package of GSAR class deviations signed by Senior Procurement Executive Jeffrey A. Koses to implement Section 5 of Executive Order 14275. Nextgov/FCW reports that the LLM section takes effect Oct. 19.

The memo carries a Jan. 15, 2026 date, but Nextgov reports that GSA signed off on the LLM language in July. The clause itself is dated September 2026. GSA had earlier pushed a similar draft through public comment and, per Nextgov, ran into resistance from industry groups even after one round of modifications. The final version keeps the core data restrictions, and its self-deleting carve-outs and limited flowdown leave many contractors outside its obligations.

Which LLM Buys Trigger Clause 552.239-7001?

The prescription at GSAR 539.71 tells contracting officers to insert the clause, including in commercial product and service buys, "when procuring Large Language Model (LLM), generative assistant, chatbot, agentic system, LLM-enabled document or productivity tool, or similar system where LLM functionality is a material feature and Government Data will be submitted directly to or produced by the LLM."

Two carve-outs do much of the narrowing. Unless the contracting officer says otherwise, the clause is "self-deleting and imposes no obligation" when a contractor's LLM use stays inside its own business, back-office, operational or performance-support systems that the government neither receives nor accesses, "even if they incidentally process Government Data." It also drops out when LLM functionality is incidental or ancillary to a commercial product whose primary purpose is not AI, as long as that functionality is not required, not accessed by the government and not used to process government data.

Flowdown is limited too. Primes must pass the clause only to subcontractors performing AI Design, AI Development, AI Deployment, or Operation and Monitoring tasks as described in Appendix A of the NIST AI Risk Management Framework 1.0, and only where those subcontractors collect, process, store, train on, fine-tune on or otherwise handle government data. Paragraphs on origin, ownership and foreign control do not flow down to open-source LLM components or "Fully Open Model" providers.

The Data Rules That Survived the Draft Fight

The government owns all Government Data, meaning both inputs and outputs, along with any Custom Developments. Contractors get a limited, revocable license to use that data only to perform the work, provide support, and run de-identified security telemetry. The clause bars "Training, fine-tuning, or otherwise improving an LLM" with government data, using it to inform the contractor's "advertising, marketing, sales, monetization, strategy, operations, or other business decisions," and "Selling or licensing Government Data to any party."

Handling requirements include encrypted transmission and processing, technical access controls, and audit logging that tracks processing "without capturing or displaying actual Government Data." Government data must be logically segregated from other customers' data, though the clause says ongoing compliance with the specified FedRAMP authorization level satisfies that requirement. The clause also states that "non-persistent (zero-persistence) architectures that do not retain Government Data satisfy" the minimum handling measures.

For LLMs that run reasoning, retrieval or agentic steps, the system must expose a summary of recorded steps from input to output, including, where recorded, model routing decisions and data retrieval sources. The clause specifies that this "requires only a summary of recorded steps, not a faithful explanation of the model's internal reasoning."

One change Nextgov highlights is a removal. Quinn Anex-Ries, a senior policy analyst at the Center for Democracy and Technology, told Nextgov that "GSA’s final AI terms and conditions mark a significant improvement from prior draft versions, and establishes a stronger foundation for safeguarding government data in AI systems." He credited the rule with "almost entirely" removing language requiring adherence to "unbiased AI principles," which Nextgov describes as one of the draft's most controversial provisions because some industry groups warned there was no clear way to test for compliance.

Deadlines: 72 Hours, 120 Days and Closeout Deletion

Under paragraph (d)(2), contractors must "Notify the Contracting Officer, within 72 hours after the Contractor obtains actual knowledge of a material violation of a provision of this clause." A material violation is one that has caused, or would reasonably be expected to cause, a significant adverse effect on contract performance, government rights, security, confidentiality, legal compliance or contract administration. A separate paragraph requires notice to the contracting officer and government security contacts within 72 hours of discovering a FISMA-defined incident affecting an LLM used on the contract, followed by daily status updates until it is resolved.

Disclosure of the LLMs used to process government data is due by the date set in the contract or, if none is set, "within 120 days after commencing work." Contractors can meet that requirement with current model cards, system cards, FedRAMP packages, SOC reports or ISO certifications instead of new paperwork. A separate disclosure of any model modifications made at the request of a non-U.S. government is due within 30 days after award, unless the solicitation or contract says otherwise.

At completion, termination or expiration, contractors must "securely and permanently delete, destroy (e.g., cryptographically erase)" all government data and Custom Developments, "including fine-tuned model weights, embeddings, indexes, and caches," across every system, copy and backup, and document the deletion to the contracting officer in writing.

What It Means for Contractors

Kevin Martin, GSA program manager at Government Acquisitions Inc, wrote in a LinkedIn post quoted by Nextgov that the clause now self-deletes for back-office and incidental LLM use, but that "the workload that remains is still substantial for anyone whose product has LLM functionality in scope: a 120-day disclosure deadline, 72-hour incident reporting, deletion of embeddings and fine-tuned weights at closeout, 30 days of notice and concurrent access before a major model swap, and Government rights to benchmark the deployed model for bias and truthfulness."

Before Oct. 19, vendors on GSA vehicles should sort each offering into one of three groups: LLM as a material feature, where the clause applies; LLM as incidental functionality, where it self-deletes; and internal-only LLM use, where it also self-deletes. For the first group, the practical work is to map which subcontractors fall into the four NIST AI RMF roles and to confirm commercial license terms do not conflict, since the clause states it "takes precedence" over click-wrap, terms of service and other commercial supplier agreements. Contractors should also confirm that their retention architecture can produce documented deletion of tenant-specific weights, embeddings and caches. The memo notes that formal GSAR rulemaking, "including a full notice and comment period," will follow the deviations.

Sources