GSA’s Proposed AI Clause (GSAR 552.239-7001) Enters Formal Rulemaking: Re-Scoped with Four-Role Flowdown Framework and Under Heavy Industry Pushback
The General Services Administration (GSA) has officially advanced its highly anticipated AI procurement clause into formal rulemaking, releasing a heavily revised proposed rule in the Federal Register on June 17, 2026 (91 Fed. Reg. 36559). Titled "Basic Safeguarding of Data within Large Language Model Artificial Intelligence Systems (LLMs)," the new draft represents a major structural overhaul of the original March 2026 draft. The public comment period closed on August 3, 2026, drawing sharp feedback from major industry groups regarding compliance complexity and overly broad definitions.
Key Overhauls in the June 2026 Proposed Rule
1. Scope Narrowed to LLMs (With Incidental Exceptions)
The March draft applied broadly to all "Artificial Intelligence Systems." The June proposed rule narrows the scope to Large Language Models (LLMs) only. Crucially, the clause does not apply when:
- The LLM is embedded in a common commercial product (such as a word processor or map navigation system).
- The LLM functionality is "incidental" to the primary purpose of the core requirement being procured.
2. The Four-Role Flowdown Framework
To address the complexity of the AI supply chain, the GSA introduced four role-specific flowdown clauses based on the NIST AI Risk Management Framework 1.0 actor categories. Prime contractors must flow down the applicable requirements to any subcontractor or service provider performing these roles:
- GSAR 552.239-7001-1: LLM Developer Flowdown Requirements
- GSAR 552.239-7001-2: LLM System Operator Flowdown Requirements
- GSAR 552.239-7001-3: LLM System Integrator Flowdown Requirements
- GSAR 552.239-7001-4: LLM Service Provider Flowdown Requirements
3. Criteria-Based "American AI" Requirements
The March draft's blunt prohibition on non-U.S. components has been replaced by a criteria-based framework under the "Unbiased AI Principles" section. LLMs must maximize the use of systems developed, managed, and operated by U.S.-incorporated entities subject to U.S. law. No core model, data storage, or output generation components can be controlled by foreign adversaries (per 15 C.F.R. 791.4). Incidental foreign components (such as open-source libraries or globally operated infrastructure) are allowed only if they do not introduce security risks.
4. Strict Government Data Ownership and Prohibitions
The government retains full ownership of data inputs, data outputs, and custom developments. Prohibited uses of government data are expanded to include a flat ban on using government data to train or fine-tune models (including third-party models) and a strict prohibition on selling or licensing government data. A new "Background Data" definition was introduced to protect a contractor's preexisting proprietary intellectual property.
5. "Eyes Off" Technical Controls
The GSA replaced vague data handling guidelines with explicit technical controls that must be enforced at the contract level:
- Automated ingestion and processing without human content review.
- Technical access controls preventing personnel from viewing government data.
- Encrypted data transmission and processing rendering data unreadable to human operators.
- Audit logging that tracks activities without capturing or displaying actual government data.1
6. Change Notification and Liability Caps
Contractors must provide 30 days' advance written notice for planned material changes (such as replacing an LLM or changing FedRAMP status) and 7 days' notice for any material increase in output bias, decreased safety guardrails, or degraded performance. Unplanned/emergency changes require immediate notice. Decommissioning cost liability for noncompliance is now capped at a percentage of the contract value.
Industry Feedback and Pushback (August 3, 2026 Deadline)
During public listening sessions and in written comments submitted by the August 3, 2026 deadline, industry groups and contractors raised several critical concerns:
- Overly Broad Definitions: Industry representatives argued that the definition of "data outputs" is too broad and could sweep in metadata, system logs, and other non-sensitive operational information.
- Complex Flowdowns: Contractors warned that flowing down distinct clauses to third-party LLM vendors or cloud providers remains extremely difficult, as major commercial AI providers are reluctant to modify standard terms for individual federal contracts.
- Vague Testing Requirements: The requirement to report a "material decrease in safety guardrails" or "degraded performance" within 7 days was criticized as operationally impractical due to a lack of standard benchmarks for LLM behavior.
Verbatim Quotes
"Stakeholders asked for clarity, practicality and alignment with commercial norms, and this updated draft shows meaningful movement in all of those directions." — Amy Benson, Government Affairs Vice President, SAIC Nextgov/FCW
"We would argue that the definition of data, although improved, is still overly broad and must be tailored to align with commercial practices... [The definition of data outputs] is unclear and could create confusion as to when information becomes government data that requires additional safeguards." — Megan Petersen, Senior Vice President, Information Technology Industry Council Nextgov/FCW
-
An instance of AI systems cannot be procured without continuous audit rights. — It shows that federal procurement standards now mandate non-negotiable, built-in audit trails and strict technical controls for all AI platforms. ↩︎