What happened
On 28 September 2026, the General Services Administration issued final clause 552.239-7001, 'Basic Safeguarding of Data within Large Language Model Artificial Intelligence Systems,' as a GSA Regulation Deviation, effective 19 October 2026. The final clause (a tightened version of the June 2026 proposal) applies where the government procures a system in which LLM functionality is a 'material feature' and Government Data is submitted directly to or produced by the LLM. It imposes data safeguarding and IP-preserving obligations, replaces the prior 'unbiased AI principles' with a reasonable-efforts accuracy/objectivity duty, restructures subcontractor flow-down around NIST AI RMF lifecycle tasks, and is self-deleting for incidental/back-office LLM use.
Why it matters
This is the first binding US federal acquisition rule specifically governing contractor handling of government data inside LLM systems. Any vendor selling LLM-based products or services through GSA vehicles (GSA schedules, MAS) must incorporate the clause and flow it down to subcontractors that process Government Data. The accuracy-objectivity obligation and material-feature threshold reshape what 'compliance' means for AI procurements and set a template that other agencies' AI contracting clauses may follow.
Action needed
Federal contractors supplying LLM-enabled systems should review GSA schedule contracts and solicitations for incorporation of 552.239-7001, map data flows to confirm whether the clause applies, ensure subcontractor flow-down, and document reasonable-efforts accuracy/objectivity practices before the 19 October 2026 effective date.