In This Article
Key Takeaways
- On June 17, 2026, GSA published a rewritten draft of GSAR clause 552.239–7001, “Basic Safeguarding of Data Within Large Language Model Artificial Intelligence Systems,” as Notice–MVAC–2026–01. Written comments are due August 3, 2026.
- Nothing is in force. The action line reads “Proposal; request for comments,” and GSA says it is gathering feedback “before taking future action (e.g., deviation and/or formal rulemaking).”
- It would apply only when government data is processed by an LLM, with carve-outs for LLMs embedded in common commercial products and for functionality incidental to what is being bought.
- It splits the supply chain into four roles, each with its own flowdown clause, mapped to the actor categories in NIST AI RMF 1.0.
- Duties include government ownership of prompts and outputs, a ban on training on government data, a 72-hour incident clock, 30 days' notice of material changes, and a right to benchmark the production model.
Most federal AI policy in 2026 has arrived as frameworks, memoranda and bills describing what agencies should want. The document that will change what engineers actually build is smaller and duller: a contract clause. GSA published a rewritten draft of one on June 17, and comments close Monday, August 3.
What GSA published, and when
The notice is Notice–MVAC–2026–01, Docket No. 2026–0331, issued by GSA's Office of Acquisition Policy and signed by Nicholas West, Director of the Office of GSA Acquisition Policy, Integrity & Workforce. It appears at 91 FR 36559 and proposes a new 48 CFR Part 539 along with clause 552.239–7001 and four companion flowdown clauses.
GSA says the clause “may be used in GSA's Government-wide contracts (e.g., Federal Supply Schedule, GWACs, and OASIS+).” That reach is why it matters even if you have never sold to GSA: these are the vehicles other agencies buy through.
This is the second draft. The first went out through GSA Interact on January 12, 2026, attached to an advance notice for MAS Refresh 31, under the broader title “Basic Safeguarding of Artificial Intelligence Systems.” The rewrite narrows the title to data inside LLMs and, GSA writes, “reflects GSA's understanding of comments and concerns on that version.” A public listening session followed on July 14. The notice names Executive Order 14110 and OMB memorandum M–25–22, Driving Efficient Acquisition of Artificial Intelligence in Government, among its inputs.
When the clause would apply
Paragraph (a) is the whole scoping fight in three sentences. The clause “applies only when Government Data will be processed by a Large Language Model Artificial Intelligence System (LLM).” It does not apply where the LLM is “embedded in a common commercial product, such as a word processor or map navigation system,” citing Section 7223(4)(B) of Public Law 117–263, or where “the LLM functionality is incidental to the primary purpose of the core requirement being procured.”
Both exceptions do heavy lifting and neither defines its key term. A word processor with a drafting assistant is out. A case-management system that summarizes every record through a model is harder to place, and nothing tells a contracting officer where that line sits.
Paragraph (c), Order of Precedence, deserves more attention than it is getting. It folds the clause into the “schedule of supplies/services” for purposes of GSAR 552.212–4 and states that it “establishes specific requirements that take precedence over conflicting provisions in the Contractor's policies, requirements, terms, conditions, or commercial agreements.” If your model provider's standard terms allow retention or product improvement on inputs, that conflict does not resolve in the vendor's favor.
Four roles, four flowdown clauses
The rewrite's structural idea is that “contractor” is too blunt an object for an LLM stack. It defines four roles, each mapped to actor categories in NIST AI RMF 1.0, Appendix A, and gives each its own supplemental clause. Where one entity performs several roles, several flowdown clauses are used.
Roles as defined in the draft clause
| Role | Examples given in the text | Flowdown clause |
|---|---|---|
| LLM Developer | Model architecture, training, weights, model cards, safety documentation, base capabilities, acceptable use policies, base safety filters | 552.239–7001–1 |
| LLM System Operator | Cloud infrastructure, model hosting, endpoints, API availability, runtime security, logging, retention, data residency | 552.239–7001–2 |
| LLM System Integrator | Model selection, system prompts, prompt templates, RAG sources, vector stores, tools, plugins, agents, guardrails, fine-tuning data, evaluation criteria, human-review thresholds | 552.239–7001–3 |
| LLM Service Provider | The LLM-enabled application, service, workflow, API or user interface presented to end users | 552.239–7001–4 |
For a small integrator this is less abstract than it looks. Build an application on someone else's hosted model and you are both Integrator and Service Provider, owing flowdowns to a Developer and an Operator whose terms you do not control.
What a contractor would owe
Government Data means Data Inputs plus Data Outputs, and both definitions are wide. Inputs include “user prompts, queries, instructions, system prompts, source data, documents, knowledge bases, Government email addresses, user account information.” Outputs include responses, analyses, derivative data, metadata, logs and synthetic data. Only content-free telemetry is excluded.
The government retains full ownership of that data and of any Custom Developments; the contractor gets a limited, revocable licence for performance and support, and keeps the underlying model and its own Background Data. Prohibited uses are explicit: training, fine-tuning or otherwise improving an LLM, including one run by a third party; using government data to inform advertising, marketing, sales or other business decisions; selling or licensing it; retaining it past scope.
Handling rules require restricting human access, with five named mechanisms including “audit logging systems that track data processing activities without capturing or displaying actual Government Data.” Nothing leaves agreed premises or FedRAMP-authorized services without written consent, and at close-out everything is deleted and the deletion certified in writing.
Then the clocks. Every LLM used, and every entity filling a role, must be disclosed within 120 days of starting work if the contract sets no earlier date. Known non-adherence goes to the contracting officer within 72 hours. Security incidents, defined by reference to FISMA at 44 U.S.C. 3552(b)(2), carry the same 72-hour notice plus daily updates until resolved, 90-day preservation of logs, and a CISA filing.
Model versions get their own treatment: concurrent access to a successor for at least 30 days before a major version is retired, 15 for a minor one. Anyone who has watched a provider deprecate an endpoint faster will recognize the ask.
Where the model comes from
Paragraph (f)(2) tells contractors to “maximize the use of” LLMs meeting three criteria: developed and operated by an entity incorporated in the United States and subject to U.S. law; not subject to foreign-government control or compelled disclosure; and with core model, storage, processing and security components not operated by entities subject to the direction, influence or control of adversary foreign governments, as that term is used at 15 CFR 791.4.
The rewrite adds a carve-out the January draft lacked. Subparagraph (f)(2)(iii) permits “incidental foreign-developed components (e.g., open-source components, published research), ancillary Third-party services, or globally operated infrastructure dependencies” where they introduce no security risk or foreign control and where a risk-based approach applies focusing on “objective criteria such as ownership, control, hosting, and security posture.” The test is corporate and technical rather than geographic, which matters to anyone whose stack includes open-weight models or research code.
Benchmarks the government runs itself
Paragraph (j) sets out Unbiased AI principles: the model must be truthful, must “prioritize historical accuracy, scientific inquiry, and objectivity,” must acknowledge uncertainty where reliable information is incomplete, and must not have partisan or ideological judgments introduced “through methods such as training data selection, fine-tuning, Retrieval-Augmented Generation (RAG) references, system prompts, or other configuration methods.” The clause draws its definition of an LLM from Executive Order 14319, which introduced those principles for federal procurement.
The enforcement mechanism is the interesting part. The government “reserves the right to conduct automated assessments of the LLM, as deployed and configured for government users, at any time using its own benchmarks,” and the contractor “must provide tools and interfaces that enable the Government to run its benchmarks in an automated fashion to test the production LLM.” Those benchmarks are themselves Government Data, and the government need not disclose them except as the basis of an adverse action. Non-compliance can mean suspension of the model's use, plus decommissioning-cost liability capped at a percentage the contracting officer fills in. That blank is still blank.
Paired with it is a traceability requirement most agent builders will feel immediately. Where the LLM uses “reasoning, retrieval, or agentic processes,” it must summarize the intermediate steps from input to output and surface them: decision points, model routing decisions with rationale, and retrieval methods with “complete source attribution with direct links and relevant excerpts.”
What commenters said
Washington Technology reported on July 15 that the revised draft landed better than the first, and that GSA had received 16 comments. SAIC government affairs vice president Amy Benson told the publication that “stakeholders asked for clarity, practicality and alignment with commercial norms, and this updated draft shows meaningful movement in all of those directions.”
The remaining objections cluster around definitions. Information Technology Industry Council senior vice president Megan Petersen called the data definition “overly broad” and argued for excluding metadata and logs from Data Outputs. Lookout's federal engineering vice president Tim LeMaster asked GSA to say what “incidental” LLM functionality means in practice. Jessica Tillipman of George Washington University Law School proposed a three-pronged test for identifying protected data. GSA senior procurement executive Jeff Koses acknowledged the concerns.
Why it matters
The following is our analysis, not reported fact. The draft reads as a description of what a defensible LLM deployment looks like, written by a customer big enough to insist on it. Three things follow.
First, obligations attach to roles rather than products, so the mapping exercise comes before the compliance exercise. Write down which of the four roles each entity in your stack occupies, including yourself, before deciding what any of it costs.
Second, the disclosure requirement is really an inventory requirement. Naming every LLM in use and every entity behind it inside 120 days sounds mild until you try it on a system with three providers, a routing layer and a retrieval stack someone stood up last year. Teams that keep a model registry will find it trivial; teams that do not will find they cannot answer the question.
Third, evaluation stops being a good habit and becomes a contract term. A seven-day clock on bias, safety or truthfulness regressions presupposes you would detect one, and a customer able to benchmark your production system on its own schedule sets a floor under your own suite. If your testing is thin, the gap to close is between “we tried it” and “we can show the numbers” – see our guides to testing agents, hallucination rates and what to monitor in production.
A note on status
This is a draft published for comment, marked “GSAR Deviation” in its heading. Language will change and some may never take effect. The engineering it implies – a model inventory, data-handling controls, an eval suite that runs on every version change – is worth having regardless of the final text.
Know which federal AI rules are binding
Our federal coverage separates enacted requirements from drafts and proposals that have not taken effect.
Read the federal AI recapSources: Federal Register, Vol. 91, No. 116, June 17, 2026, pp. 36559–36566 (FR Doc. 2026–12205, PDF); Federal Register listing; regulations.gov; Washington Technology, July 15, 2026. All clause quotations are from the Federal Register text. Analysis by Precision AI Academy.
Common questions
Is the clause in effect? No. The action line reads “Proposal; request for comments,” and GSA says it is gathering feedback before deciding whether to proceed by deviation or by formal rulemaking.
When are comments due, and how do I file? August 3, 2026, through regulations.gov by searching for “Notice–MVAC–2026–01.” GSA asks commenters to cite page, section and paragraph, and encourages a spreadsheet format with suggested replacement language.
When would it apply? Only when government data is processed by an LLM. It would not reach an LLM embedded in a common commercial product, or LLM functionality incidental to the core requirement. Neither exception is defined further, which is the point industry has pressed.
Which contracts would carry it? GSA names the Federal Supply Schedule, GWACs and OASIS+ as examples of the Government-wide contracts where the clause may be used.