Regulatory  ·  2026-10-04

GSA issues final rule clause 552.239-7001 on safeguarding government data in LLM procurements

RegulatoryMedium impactUnited States
On 28 September 2026, the General Services Administration issued final clause 552.239-7001, 'Basic Safeguarding of Data within Large Language Model Artificial Intelligence Systems,' as a GSA Regulation Deviation, effective 19 October 2026. The final clause (a tightened version of the June 2026 proposal) applies where the government procures a system in which LLM functionality is a 'material feature' and Government Data is submitted directly to or produced by the LLM. It imposes data safeguarding and IP-preserving obligations, replaces the prior 'unbiased AI principles' with a reasonable-efforts accuracy/objectivity duty, restructures subcontractor flow-down around NIST AI RMF lifecycle tasks, and is self-deleting for incidental/back-office LLM use.
This is the first binding US federal acquisition rule specifically governing contractor handling of government data inside LLM systems. Any vendor selling LLM-based products or services through GSA vehicles (GSA schedules, MAS) must incorporate the clause and flow it down to subcontractors that process Government Data. The accuracy-objectivity obligation and material-feature threshold reshape what 'compliance' means for AI procurements and set a template that other agencies' AI contracting clauses may follow.
Federal contractors supplying LLM-enabled systems should review GSA schedule contracts and solicitations for incorporation of 552.239-7001, map data flows to confirm whether the clause applies, ensure subcontractor flow-down, and document reasonable-efforts accuracy/objectivity practices before the 19 October 2026 effective date.
GSA final clause 552.239-7001 (via Crowell & Moring client alert)Nextgov — GSA memo to set AI-specific acquisition rules
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →