GSA binds AI contractors with class deviation clause
The first binding federal AI procurement clause arrives as rescindable policy, not codified regulation, and it lets the government pull the plug on a procured LLM without explaining how factual accuracy gets measured.
TL;DR
GSA issued its AI acquisition clause as a class deviation from the GSAR, effective Oct. 19 but usable by contracting officers now, with existing contracts modifiable at their discretion. After 75-plus comments from Palantir, Microsoft and Nvidia, the clause shrank to apply only when the government is buying AI, dropped "unbiased AI principles" and the ban on "partisan or ideological judgments," and replaced them with a "reasonable efforts" factual-accuracy standard for LLMs. The government keeps broad audit and suspension rights, and decommissioning liability is capped at 25% of the affected order. Formal rulemaking has no date.

GSA has answered industry's summer of comments with a class deviation rather than a rule, and the choice of vehicle is the story. A deviation is policy until GSA rescinds it or codifies it. The clause takes effect Oct. 19, but contracting officers can invoke it today, and they can modify existing contracts at their own discretion. There's no timeline for the formal rulemaking that's supposed to follow, only a promise that it will carry a public comment period. Contractors are implementing a standard they can't yet point to in the CFR.
What narrowed
The June draft drew 75-plus comments, with Palantir, Microsoft and Nvidia pressing hardest on open-source and third-party models. The issued clause concedes a great deal. It now applies only when the government is buying AI, not when a contractor uses AI internally, unless those tools are delivered to or accessed by the government or a contracting officer flags them. The phrase "unbiased AI principles" is gone, along with the ban on embedding "partisan or ideological judgments."
In their place: the contractor must use "reasonable efforts" to design, train and configure an LLM to respond factually to prompts seeking factual information, to "prioritize accuracy, scientific inquiry, and objectivity," and to acknowledge uncertainty where reliable information is incomplete or contradictory.
What didn't
Reasonable efforts in, sweeping rights out. The government reserves the right to run automated assessments of the LLM for bias, truthfulness, safety, unsolicited ideological content and "other factors determined by the Government." And it retains the right to suspend use of the LLM at any time. The June draft had at least tethered suspension to "until performance issues are satisfactorily addressed." That language is gone. Nothing in the clause defines how a factual-accuracy standard gets tested across a fine-tuned retrieval system versus a general-purpose model.
GSA did carve out some of the open-model mess the commenters flagged. It defines three tiers: fully open models that publish architecture, weights, code and data, open-weight models that publish only weights, and open-LLM components. Prime contractors don't have to flow foreign-control requirements down to fully open models or open-source components. Open-weight models get no such exception, which means the popular middle category still pulls primes into the compliance chain.
Where the money and Monday-morning work land
Two changes matter to sub-tier contracting more than the headline edits. Flowdown now follows government data: subcontractors are covered when they handle it, not merely by role. That's close to the test Nvidia's Bruce Andrews pushed over the summer, "obligations should follow the data, not the model's authorship." Meanwhile primes must use "best efforts" to vet AI subcontractors, a shift from the June draft's "due diligence" over developers, operators, integrators and service providers, and the prime stays on the hook either way.
Decommissioning costs after a for-cause termination are capped at 25% of the affected task or delivery order. And the contractor must report, within seven calendar days, any material change that materially increases output bias, weakens safety guardrails, or degrades performance or truthfulness. "User context," defined much like a test George Washington Law's Jessica Tillipman proposed at GSA's July listening session, now scopes when usage traces count as government information.
None of this is binding law. It's a deviation that a contracting officer can drop into a solicitation this month. For compliance teams the practical read is short: scope the clause to contracts where the government is buying AI, map which subs actually touch government data, and decide now what documentation proves "reasonable efforts," because the assessment methods and the suspension triggers will be written by the government during an audit, not by the contractor at proposal time.
Published ·Deep Fathom