The General Services Administration (GSA) has published a proposed rule in the Federal Register introducing GSA Regulation 552.239-7001, "Basic Safeguarding of Data Within Large Language Model Artificial Intelligence Systems". Narrowed down from earlier drafts that broadly targeted all AI, this revised rule specifically regulates Large Language Models (LLMs) processing government data.
Crucially, these safeguarding obligations apply not just to prime contractors, but through a new four-tier flowdown structure that reaches developers, operators, integrators, and service providers throughout the entire LLM supply chain.
The proposed rule introduces strict data protections, mandating that government data cannot be used to train or fine-tune models, cannot be sold or licensed, and must be handled using "eyes-off" automated technical controls that strictly prevent human content review.
However, in a concession to industry feedback, the rule shifts away from a blanket ban on non-U.S. AI. Instead, it establishes an "Unbiased AI Principles" framework, requiring LLM systems to be controlled by U.S. entities and protected from foreign compulsion, while permitting incidental foreign-developed components (like open-source tools) provided security risks are adequately mitigated.
As AI integration becomes inevitable in the GovCon space, you must proactively manage your compliance posture. I advise taking the following steps to ensure your systems are ready when these proposed measures are enacted:
Credits & Further Reading: This update is based on legal insights provided by Ryan Letson, Amy L. Fuentes, and Anne M. Delmare from Holland & Knight.