From the journal

US GSA Proposes Federal Acquisition Clause for LLM Data Safeguarding, Comment Deadline August 2026

On 17 June 2026, the US General Services Administration published a proposed General Services Administration Acquisition Regulation clause requiring federal contractors to implement data safeguarding measures when large language models process government data. The proposal amends 48 CFR Parts 539 and 552, addresses data protection, intellectual property, and ethical AI development in federal procurement, and accepts public comments until 3 August 2026.

3 min read

The US General Services Administration published a proposed General Services Administration Acquisition Regulation (GSAR) clause on 17 June 2026, identified as FR Doc. 2026-12205, amending 48 CFR Parts 539 and 552. The clause is at the proposed rule stage. The public comment period closes on 3 August 2026. A public listening session is scheduled for 14 July 2026, with registration closing 3 July 2026. This is a substantially revised version of a January 12, 2026 draft.

The proposed clause amends 48 CFR Part 539 (Acquisition of Information Technology) and Part 552 (Solicitation Provisions and Contract Clauses). It applies specifically when a large language model processes Government data as part of contract performance. The clause addresses four areas: data protection standards for Government data processed by LLMs; intellectual property rights in AI-generated outputs; restrictions on using Government data to train or fine-tune AI models; and ethical AI development principles. The clause is expressly inapplicable where LLMs are embedded in standard commercial products or where LLM functionality is merely incidental to the contract deliverable. The proposed text is informed by OMB Memorandums and prior Executive Orders on federal AI governance.

Federal contractors and technology vendors who provide AI systems, AI-enabled services, or software-as-a-service incorporating LLMs that process Government data will face new contractual compliance requirements once the clause is finalised. Companies providing AI platforms, intelligent automation, AI-assisted analytics, or AI-enhanced professional services to the federal government should review their data handling architectures, subcontractor flow-down obligations, and Government data processing agreements against the proposed requirements. The "incidental use" exclusion provides a potential safe harbour for certain commercial off-the-shelf software providers, but the clause's definition of when LLM use is "incidental" is currently unsettled.

The January 2026 draft has been substantially revised, and organisations that commented on the earlier version should re-engage with the current text before the August 3 deadline. Key definitional questions remain open: what constitutes "Government data" for purposes of the clause, and when LLM processing is sufficiently incidental to fall outside the clause's scope. The proposed clause operates alongside NIST AI Risk Management Framework requirements already embedded in some federal technology contracts and will eventually interact with implementing guidance from the June 2026 Executive Order on AI cybersecurity.

Licentium advises on US federal AI procurement regulation, government contracting compliance, and AI data governance. We may be able to assist contractors in assessing exposure under the proposed clause, drafting public comment submissions, or connecting them with US federal acquisition law specialists in our partner network. Work we undertake includes federal AI procurement analysis, GSAR and FAR compliance review, AI data handling advisory, and government contracting regulatory strategy.

Source: General Services Administration, General Services Acquisition Regulation; Acquisition of Information and Communication Technology, FR Doc. 2026-12205, 17 June 2026

AI Regulatory

More from the journal

See all
Illia Prokopiev

From Cloud Concentration to AI Dependence: The UK’s Critical Third Parties Regime

The United Kingdom now directly oversees designated technology suppliers whose service failures could threaten financial stability. The question is whether the first cloud designations show a legal expansion toward AI-model providers, and what the present regime requires. This analysis assumes the quoted statement concerns the UK financial-services Critical Third Parties regime and assesses the law through 14 July 2026.

Alberta Regulated iGaming Market Launched on 13 July 2026 with 22 Operators

Alberta's regulated private iGaming market launched on 13 July 2026, making Alberta the second Canadian province to permit private online gambling operators after Ontario. The Alberta Gaming, Liquor and Cannabis Commission serves as market regulator and the Alberta iGaming Corporation oversees commercial operations and operator contracts. Twenty-two operator sites went live on day one, including FanDuel, DraftKings, BetMGM, and BetRivers. Operators must fully launch or exit the Alberta market by 13 October 2026.

European Commission Presents Cybersecurity and AI Action Plan on 7 July 2026

On 7 July 2026, the European Commission presented an Action Plan on Cybersecurity and Artificial Intelligence. The plan directs the Commission and ENISA to evaluate advanced AI models before they reach the EU market, establish a secure testing platform for critical-sector organisations, and launch an EU Grand Challenge on AI-powered cybersecurity solutions. It operates alongside the AI Act, NIS2 Directive, DORA, Cyber Resilience Act, and Cyber Solidarity Act, and introduces no new directly binding obligations.