GSA bypasses rulemaking, binds contractors with AI memo
GSA buried a data-safeguard regime in an internal memo after industry comment stalled the formal rule, sidestepping notice-and-comment while keeping the obligations binding on contractors.
TL;DR
Page 129 of a January memo, signed by GSA Senior Procurement Executive Jeffrey Koses in July with the LLM section added, sets binding safeguards effective Oct. 19. Contractors whose products process government data in large language models can't use that data for training, advertising or resale, must encrypt transmissions and keep audit logs, and face a 120-day disclosure deadline, 72-hour incident reporting, 30-day notice before major model swaps, and deletion of embeddings and fine-tuned weights at closeout. The scope spares back-office LLM use and products where AI is "incidental." GSA tried this route by proposed GSAR rule in March, took industry fire through an August comment window, then moved the package by memo instead.

GSA couldn't get its large language model safeguards through a rulemaking, so it got them through a memo. The section, titled "Basic Safeguarding of Data within Large Language Model Artificial Intelligence Systems," sits on page 129 of a document originally signed in January; the agency added the LLM language in July, and it takes effect Oct. 19. Nothing else in the memo, per Nextgov's report, is about AI. The procedural point is the news. A proposed GSAR clause would have gone through notice-and-comment; a memo from the Senior Procurement Executive doesn't. The Federal Register notice GSA published in June framed the draft clause as a prelude to "future action (e.g., deviation and/or formal rulemaking)," and the draft itself was labeled a GSAR Deviation from the start. A class deviation carried by the contracting officer's clause insertion is faster and harder to challenge than a rule, and it's the route GSA took after a March draft drew "grave concerns" from advocacy groups and contractors who said the definitions didn't track commercial practice. Whether that's agility or avoidance depends on who's answering.
What the clause actually asks
The obligations land on primes and, by flowdown, on subcontractors who design, develop, deploy or operate the model. Government data in an LLM can't train the model, inform advertising, or be sold to a third party. Transmission must be encrypted, and the contractor has to run audit logging. Kevin Martin, GSA program manager at Government Acquisitions Inc, laid out the residual workload in a LinkedIn post: a 120-day disclosure deadline, 72-hour incident reporting, deletion of embeddings and fine-tuned weights at contract closeout, 30 days of notice plus concurrent access before a "major model swap," and government rights to benchmark the deployed model for bias and truthfulness.
That last item is worth pausing on. GSA spent much of its industry fight over an "unbiased AI principles" requirement that stakeholders said couldn't be tested. Center for Democracy and Technology senior policy analyst Quinn Anex-Ries welcomed the memo precisely because that language was removed "almost entirely." But a government right to benchmark a deployed model for bias and truthfulness reintroduces the same measurement problem through a different door.
Who doesn't have to care Monday
The memo carves out two categories, and they matter more than the obligations for most of GSA's vendor base. LLMs a contractor uses internally for business purposes are outside scope. So are products where LLM functionality is "incidental to" its primary purpose. A staffing firm on OASIS+ that runs a chatbot against its own HR policy documents is unburdened. A software vendor whose analytics product calls a model to summarize agency data is not.
That line is where compliance work will actually be argued. Contractors will want "incidental" read as anything that can be switched off; agencies will read it as "AI isn't the feature we bought." The memo defines the safeguarding regime, not that boundary.
The open end
The requirements now bind, but the reported piece doesn't describe audit mechanics or financial consequences for missing the 72-hour or 120-day clocks. A missed deadline under a GSAR clause travels toward cure notices, negative CPARS entries, and in a data-handling failure, False Claims Act exposure via the civil cyber-fraud program, which DOJ has used for exactly this kind of unmet contract security term. None of that is in the memo. It's the shape enforcement tends to take, and it's why the ambiguity isn't neutral. The compliance director has a checklist as of Oct. 19. The engineer has to build the audit pipeline that satisfies it, and someone still has to say how GSA will look inside.
Published ·Deep Fathom