GSA proposes LLM data safeguards for federal contractors
On June 17, 2026, the General Services Administration published a Federal Register proposal for a new GSAR clause, 552.239-7001, covering basic safeguarding of government data inside Large Language Model AI systems. Comments are due August 3, 2026, and GSA plans a public listening session on July 14, 2026. 1
Swipe order:
- Alert card: the event, publication date, docket signal, and comment deadline.
- Rule breakdown: the clause applies when LLMs process Government Data, with exceptions for common commercial products and incidental LLM functionality. 1
- Impact map: the draft would push requirements down the LLM supply chain to developers, system operators, system integrators, and service providers. 1
Why compliance teams should read it now:
- Government Data includes inputs and outputs such as prompts, queries, responses, analyses, logs, synthetic data, and derivative data. 1
- Contractors would be barred from using Government Data to train or improve LLMs, support advertising or sales decisions, sell or license the data, or process it through unauthorized parties. 1
- The draft requires disclosure of LLMs and entities filling covered roles, with disclosure due within 120 days after work begins if no contract date is specified. 1
- Known non-adherence and security incidents affecting government data carry a 72-hour notification requirement; planned material changes require 30 days' written notice. 1
- Status check: this is a proposed rule and request for comments, not a final binding clause yet. GSA says the draft is meant to gather feedback before future action such as a deviation or formal rulemaking. 1
References
- 1Federal Register: GSAR LLM data safeguarding proposal
federalregister.gov


Comments