The General Services Administration published a revised draft GSAR clause on June 17, 2026 governing how federal contractors must safeguard government data processed by large language model AI systems. The clause, docketed as 2026-12205, narrows the scope of an earlier draft while retaining the most consequential requirements: government ownership of all AI-processed data and a prohibition on contractors using that data to train or improve their models.
Background
GSA’s earlier draft clause drew industry pushback for its sweeping scope and implementation ambiguity. The clause’s core premise is straightforward: when a federal contractor deploys an LLM to perform contract work, the government data that flows through that system — including employee prompts, generated responses, and any derived data — belongs to the government and must be protected accordingly. What proved contentious was how broadly the original draft defined covered systems and how contractors were expected to comply with government-data ownership requirements without fundamentally altering the commercial AI products they were licensing.
The June 2026 revision is GSA’s response to those concerns. The agency narrowed the clause’s applicability, refined contractor obligations by tier, and scheduled a public listening session before the comment deadline closes.
Key Details
The revised clause applies only when government data is processed by an LLM as part of contract performance. It explicitly excludes LLMs embedded in common commercial products and incidental LLM use — a meaningful carve-out that removes a wide range of productivity tools from coverage.
GSA defined four contractor categories with tailored obligations for each: LLM Developers, System Operators, System Integrators, and Service Providers. Each category carries distinct flowdown requirements, meaning a prime contractor that builds on top of a commercial AI platform must pass relevant obligations down to the platform vendor when government data is in scope.
The core mandates from the earlier draft survived intact. Government ownership extends to user prompts, generated responses, and derived data — so a federal employee’s question to a contractor-deployed chatbot is treated as government data from the moment it is typed. Contractors are prohibited from using that data to train, fine-tune, or otherwise improve AI models. Systems also cannot decline to perform government tasks based on contractor-imposed discretionary policies, a requirement GSA frames as a “no refusals” mandate.
The clause includes a notable carve-out that has drawn scrutiny: it states it “must not be construed to require retraining of the model or alteration of model weights.” Legal analysis published by Mondaq identifies this as a fundamental unresolved tension — the clause explicitly prohibits demanding model-level changes, yet compliance with the no-refusals obligation may, in practice, require exactly those changes. As Mondaq notes, “it’s not clear how a contractor ensures compliance with a no-refusals obligation without those technical changes.”
GSA will hold a public listening session on July 14, 2026 to allow industry input before the comment period closes. The comment period runs through August 3, 2026.
What It Means for Contractors
The narrowed applicability threshold is a genuine win for contractors using commercial AI tools in overhead or administrative functions — those uses fall outside the clause’s scope. The tiered structure also gives system integrators clearer guidance on when they must push obligations down to subcontractors and vendors.
The no-training prohibition carries operational weight. Contractors deploying commercial LLMs under enterprise licenses must verify that their vendor agreements prevent government prompt data from flowing into model improvement pipelines. Many commercial AI vendors’ standard terms permit training on user interactions unless explicitly opted out, which means contract language and vendor negotiation become compliance requirements, not just risk management preferences.
The no-refusals mandate introduces a different kind of risk. Commercial AI systems frequently include content policies that restrict outputs on specific topics. If a contractor deploys such a system and it declines a lawful government task under those policies, the contractor is in breach of the clause — not the AI vendor. Contractors will need to either negotiate vendor-level policy overrides for government deployments or select systems where task refusal is not a feature.
The supply chain complexity created by the tiered taxonomy adds another layer of exposure. Prime contractors bear compliance risk for subcontractors and platform vendors who may be operating under non-negotiable standard commercial terms. Where a prime cannot compel a platform vendor to modify its terms, the prime nonetheless remains on the hook for clause compliance — a structural problem the clause’s flowdown requirements create but do not resolve.
The unresolved model-weights tension is the clause’s sharpest compliance edge. GSA has said the clause does not require retraining, but has not explained how a contractor demonstrates that government data is not influencing model behavior without access to model internals that commercial vendors do not provide. Until GSA addresses this in final rulemaking — or listening session participants surface a workable compliance path — contractors operating at the LLM Developer tier face the most exposure.
The July 14 listening session is the primary opportunity for contractors to shape the final rule. Given the clause’s flowdown structure, both prime contractors and their AI platform vendors have standing reasons to submit comments or participate. The August 3 deadline applies to written comments submitted via the Federal Register docket.
Contractors that deploy commercial LLMs on federal contracts should use the listening session and comment period to raise three specific issues with GSA: the definition of "incidental" LLM use and where that exemption boundary sits in practice; the mechanism for demonstrating no-training compliance when vendor contracts do not provide audit rights over training pipelines; and the unresolved tension between the no-refusals mandate and the model-weights carve-out. GSA has opened a formal window to resolve these ambiguities before final rulemaking closes. Contractors that submit specific, technically grounded comments are more likely to see those questions addressed in the final clause text than those that wait for publication and then seek compliance guidance after the rule is locked.