Palantir Technologies has asked the General Services Administration to withdraw a draft rule governing how contractors must safeguard data inside large language model systems, breaking with most of the rest of the AI acquisition industry, which is asking GSA to fix the rule rather than kill it.

Background

GSA published a Federal Register notice on June 17, 2026, opening a comment period on a draft GSAR clause titled "basic safeguarding of data within Large Language Model Artificial Intelligence Systems." The clause, tied to docket Notice-MVAC-2026-01, would set requirements for how contractors handle data moving through LLM-based systems sold to federal agencies, how they monitor those systems for bias, and how intellectual property generated or processed by the models is treated under federal contracts.

The rulemaking effort comes as agencies across the government are moving quickly to acquire generative AI tools, from document summarization to decision support, often without a settled acquisition framework for the underlying technology. GSA's proposal represents one of the first attempts to write LLM-specific safeguarding language directly into acquisition regulation rather than leaving it to agency-by-agency guidance.

The comment period closed August 3, 2026. GSA received 79 stakeholder submissions, spanning trade associations, individual technology companies and law firms representing contractors, according to regulations.gov. The range of positions in those comments shows an industry that agrees GSA needs to regulate LLM safeguarding in some form, but disagrees sharply on how much authority GSA should claim to do it, and on how prescriptive the underlying compliance language should be.

Key Details

Palantir's comment, reported August 6, 2026, goes further than any other major submission: the company wants the draft clause withdrawn in its entirety, not revised. Palantir argues the rule as written would effectively bar the company from offering AI solutions on GSA contracts. It also argues GSA lacks independent statutory authority under the Federal Acquisition Streamlining Act to issue a clause of this scope, and that the rule is incompatible with legal requirements governing defense acquisitions — including limits on what clauses defense agencies can require of contractors and prohibitions on demanding proprietary IP rights as a condition of contract award. In Palantir's reading, GSA is attempting to regulate a technical domain — LLM behavior and bias — that sits outside the scope of what a civilian acquisition regulation can dictate, and in doing so risks colliding with the statutory limits that already constrain what defense agencies can demand of contractors over the same underlying technology.

That position stands apart from most of the other 78 comments GSA received. The Professional Services Council, which represents a broad swath of government services contractors, told GSA to revise the clause rather than scrap it — a stance PSC shares with several other trade groups, including the Software & Information Industry Association, the Business Software Alliance and the Information Technology Industry Council, all of which asked GSA to more clearly define the rule's scope. Their shared concern is definitional: the draft clause does not clearly define what counts as an "LLM Artificial Intelligence System," leaving contractors unsure whether the requirements would sweep in tools that use LLM components incidentally alongside systems built specifically around them. PSC went further on compliance, urging GSA to publish its benchmark methodology and evaluation criteria for the clause's "unbiased AI principles" standard and update them through notice-and-comment rulemaking, pointing to the NIST AI Risk Management Framework 1.0 and the IEEE 7003 Algorithmic Bias standard as third-party benchmarks GSA could use instead of writing bespoke bias-monitoring criteria into the regulation.

That split leaves GSA with two very different paths forward from the same comment period: withdraw the clause and start over, as Palantir wants, or narrow its scope and anchor its compliance metrics to standards the industry already uses, as PSC and the bulk of other commenters are asking for.

What It Means for Contractors

For contractors already selling or planning to sell LLM-based tools through GSA schedules, the near-term takeaway is that the rule is not close to final, and its shape could change substantially depending on which camp GSA sides with. A full withdrawal, as Palantir wants, would reset the clock and could leave a regulatory gap in the interim — agencies would keep buying LLM tools under existing IT acquisition rules with no LLM-specific safeguarding clause at all until GSA tries again. A revision along PSC's lines would likely narrow the clause's scope to more clearly-defined LLM systems and swap out subjective bias-compliance language for references to NIST AI RMF 1.0 and IEEE 7003, standards many contractors are already building compliance programs around for other federal AI requirements.

Contractors that also hold defense contracts have a specific stake in Palantir's legal argument. Palantir contends the clause's IP and data terms would run into statutory limits on what defense agencies can require of contractors, including restrictions on demanding proprietary IP rights as a condition of contract award — meaning a civilian-schedule clause could, in Palantir's telling, create obligations a company's defense-side contracts are legally barred from mirroring. Whether that risk justifies withdrawal rather than revision is one of the questions GSA must weigh in choosing between Palantir's and PSC's asks.

The bias-monitoring provisions are worth watching closely regardless of which path GSA takes. Multiple commenters, not just Palantir, flagged that "unbiased AI" as a compliance standard is difficult to audit against without an objective metric, and tying the clause to NIST AI RMF 1.0 or IEEE 7003 would give contracting officers and contractors alike a shared reference point for what compliance actually requires. Companies building or maintaining LLM-based products for GSA schedules should track whether GSA adopts those standards directly, since doing so would effectively import an existing compliance framework into the acquisition regulation rather than requiring contractors to build a new one from scratch.

GSA has not indicated a timeline for issuing a final rule or announcing which direction it will take following the comment period. With 79 submissions to review and a visible split between the industry's most prominent AI vendor and the trade group representing the broader services base, the agency's next move on Notice-MVAC-2026-01 will set an early precedent for how civilian agencies regulate LLM procurement — a question that predates this rulemaking and will outlast it regardless of how GSA resolves the current split.

Contracting officers evaluating LLM-based proposals in the meantime are left working from existing IT acquisition guidance rather than any settled GSAR clause, which is itself a source of uncertainty for vendors trying to price compliance risk into current bids. Companies that track this docket closely will have a head start whichever way GSA ultimately moves.

Sources