# GSA memo to set AI-specific acquisition rules

> Source: <https://www.nextgov.com/acquisition/2026/10/gsa-memo-set-ai-specific-acquisition-rules/416378/>
> Published: 2026-10-01 23:04:00+00:00

# GSA memo to set AI-specific acquisition rules

## The language includes changes some industry groups have requested through a public comment period and will go into effect Oct. 19.

The General Services Administration is adjusting its acquisition regulation to include language aimed at protecting government data that contractors process in large language models.

Buried on page 129 of an agency [memo](https://www.acquisition.gov/sites/default/files/page_file_uploads/RGO-2026-01.pdf) signed by GSA Senior Procurement Executive Jeffrey Koses is a section titled “Basic Safeguarding of Data within Large Language Model Artificial Intelligence Systems.” The section details what data protections contractors and subcontractors must include when their LLMs process government data.

For example, the rules state contractors cannot use government data to train LLMs, inform advertising or sell to a third party. Contractors must also implement data handling procedures, including encrypted data transmission and audit logging systems. The memo clarifies the language does not apply to LLMs that contractors use internally for business purposes or products where the LLM functionality is “incidental to” its primary purpose.

The memo is originally from January, but states GSA signed off on the section with the LLM acquisition language in July and that it takes effect on Oct. 19.

GSA had sought to enact a similar draft LLM acquisition rule through a public comment period but ran into [intense pushback](https://www.nextgov.com/acquisition/2026/08/palantir-calls-gsa-withdraw-draft-ai-acquisition-rule/415253/) from industry groups even after a round of modifications. Several stakeholders welcomed the memo’s take on LLM acquisition safeguards.

"GSA’s final AI terms and conditions mark a significant improvement from prior draft versions, and establishes a stronger foundation for safeguarding government data in AI systems,” Quinn Anex-Ries, a senior policy analyst at the Center for Democracy and Technology, said in a Thursday statement.

Anex-Ries praised the rule for “almost entirely” removing language requiring contractors to adhere to “unbiased AI principles.” That language was one of the most controversial provisions of GSA’s draft rule, with some industry groups warning the agency there’s no clear way to test for compliance.

“The AI clause changed in ways industry asked for. It self-deletes when LLM use stays inside the contractor's own back-office systems, or when LLM functionality is incidental to a product the Government isn't using for AI. Flowdown reaches only subcontractors who design, develop, deploy or operate the model,” Kevin Martin, GSA program manager at Government Acquisitions Inc, [wrote on LinkedIn](https://www.linkedin.com/posts/kevinmartinmba_govcon-gsar-gsa-share-7511512401356214272-J61j/?utm_source=share&utm_medium=member_desktop&rcm=ACoAAA86220BMyGTnQug97-a_z0neLVWpchqPc0).

However, “the workload that remains is still substantial for anyone whose product has LLM functionality in scope: a 120-day disclosure deadline, 72-hour incident reporting, deletion of embeddings and fine-tuned weights at closeout, 30 days of notice and concurrent access before a major model swap, and Government rights to benchmark the deployed model for bias and truthfulness,” he added.

**NEXT STORY:**
              [Google extends Gemini OneGov deal into November](https://www.nextgov.com/acquisition/2026/09/google-extends-gemini-onegov-deal-november/416320/?oref=ng-next-story)
