Back to InsightsIndustry Updates

New GSA AI Rule Can Bind Small-Business Subs

Rachel PhillipsJuly 27, 2026

If your business touches an AI tool anywhere on a federal contract, a new rule from the General Services Administration could apply to you, even if you are a subcontractor or a reseller who never signs the prime contract. That is the part small businesses are missing. On June 17, 2026, GSA published a revised proposed contract clause, GSAR 552.239-7001, "Basic Safeguarding of Data Within Large Language Model Artificial Intelligence Systems." It is not final yet. The public comment window closes August 3, 2026, which is exactly why it is worth understanding now.

The short version for a small business: if government data ever passes through an AI system on work you are part of, this clause sets strict rules for how that data is handled, and those rules follow the work down to every company in the chain.

What the clause actually does

Large language models, the technology behind tools like ChatGPT and Claude, run on data. You feed them information, they give you answers back. This clause governs what happens to the government's data on both sides of that exchange.

It defines "Government Data" broadly. That covers the "Data Inputs" (the prompts and source files fed into the tool) and the "Data Outputs" (the responses, analyses, and even the metadata the tool generates). When government data like that flows through an AI system on a federal contract, the clause kicks in.

GSA first floated this in March 2026. Industry pushed back hard, calling it vague and unworkable, so GSA rewrote it. The June version is narrower and more practical, and it is the one now open for comment. It is the latest in a growing set of federal AI rules affecting contractors.

When it applies, and when it does not

This is the first thing to get straight, because the scope is narrower than the headlines suggest.

The clause applies only when government data is actually processed by a large language model as part of the contract. It does not apply to:

  • AI baked into ordinary commercial products you happen to use, like the writing suggestions in a word processor or the routing in a map app.
  • AI that is incidental to the real purpose of what the government is buying.

So a staffing firm or a construction contractor that never runs government data through an AI tool is likely untouched. A company that builds, hosts, integrates, or resells an AI product for a federal customer is squarely in scope.

Why it can reach you even as a subcontractor

Here is the part that catches small businesses off guard. The requirements flow down the entire AI supply chain. GSA wrote four role-specific companion clauses, one for each kind of player:

  • LLM Developer, the company that builds or trains the model.
  • LLM System Operator, the company that hosts or runs it.
  • LLM System Integrator, the company that configures or adapts it for a specific job.
  • LLM Service Provider, the company that delivers the finished tool to the government user.

If your business fills any of those roles for a federal contract, the obligations can reach you even though your name is not on the prime contract. The prime has two ways to handle it: flow the clause terms down to you contractually, or collect a written attestation from you that you comply. Either way, a lean team ends up carrying real obligations. The prime also has to exercise due diligence in choosing and overseeing its AI partners, and report any known non-compliance to the contracting officer within 72 hours.

For a small business that resells or integrates someone else's AI, that means a contract you thought was simple can come with a compliance tail attached.

What a bound contractor has to do

If the clause applies to you, the requirements are specific. In plain terms:

  • Keep humans out of the data. The system has to ingest, process, and respond automatically, without your people reading the government's content. Access controls and encryption have to make that data unreadable to your staff.
  • Log activity, not content. Your audit logs can track what the system did, but they cannot capture or display the actual government data.
  • Separate the data. Government data has to be logically segregated, though GSA clarified this does not require physically dedicated servers.
  • Do not reuse the data. You cannot use government data to train or improve any model, including third-party ones. You cannot use it for your own marketing, sales, or operations. You cannot keep it past the life of the contract, and you cannot sell or license it to anyone.
  • Delete it and certify. When the contract ends, you securely delete the data and provide written certification that you did.

There are also notice requirements. Material changes to the service, adding or swapping a model, or a change in FedRAMP status generally require 30 days' advance notice. Changes that increase bias, weaken safety guardrails, or degrade performance require 7 days' notice. Emergency changes have to be reported immediately, with a remediation plan to follow.

What is more workable in the June version

The rewrite fixed several of the complaints small firms raised the first time around. The scope is narrower. Contractors keep ownership of their own background data and are not required to hand over source code, model weights, or trade secrets. The government's license to the data is limited to the purpose and scope of the contract. And the government now has to give written notice and a chance to cure before terminating for cause, with liability capped at reasonable decommissioning costs.

It is still a proposed rule. The details can change before it is final, which is the whole point of the comment window.

Where this is headed

When GSA finalizes the clause, it is expected to apply across the agency's governmentwide vehicles, including the Federal Supply Schedules, Governmentwide Acquisition Contracts, and OASIS+. If you sell through any of those, or plan to, this is a rule to watch closely.

What small businesses should do now

  1. Figure out if it even touches you. Look at your federal work and ask a simple question: does government data actually run through an AI tool anywhere in it? If the answer is no, you can breathe. If yes, keep going.
  2. Map your AI supply chain. Know which models and vendors sit behind any AI you deliver or resell, and which of the four roles you play.
  3. Decide your compliance path. If a prime asks you to accept flow-down terms or sign an attestation, understand what you are agreeing to before you sign.
  4. Check your data handling. Automated processing, encryption, activity-only logging, and a clean deletion-and-certification process are the core of what the clause expects.
  5. Consider filing a comment before August 3. Small businesses rarely comment on proposed rules, which means the firms that do get an outsized voice in how the final version lands, the same dynamic we flagged during the FAR overhaul. If this clause would be hard for a company your size to meet, that is worth putting on the record at regulations.gov.

How FEDCON helps

FEDCON helps small businesses turn confusing federal rules into a plan they can act on, from SAM.gov registration to figuring out exactly which new requirements apply to your contracts and which do not. If you are not sure whether this AI clause reaches your business, talk to a FEDCON advisor. You can also reach our Help Desk at 1-855-233-3266.

Frequently asked questions

What is GSAR 552.239-7001?

It is a proposed General Services Administration contract clause called "Basic Safeguarding of Data Within Large Language Model Artificial Intelligence Systems." It sets rules for how contractors protect government data that is processed by AI systems on federal contracts. GSA published the revised version on June 17, 2026, and is accepting public comments through August 3, 2026.

Does this rule apply to my business if I just use ChatGPT or Claude internally?

Not on its own. The clause applies when government data is processed by a large language model as part of a federal contract. It specifically excludes AI that is embedded in common commercial products or that is incidental to what the government is buying. Using a general AI tool for your own internal work is different from delivering or operating an AI system for a federal customer.

Can a subcontractor be bound by this clause?

Yes. The requirements flow down the AI supply chain through four role-specific clauses covering developers, operators, integrators, and service providers. A prime contractor can bind a sub or reseller either by flowing the terms down contractually or by collecting a written attestation of compliance.

Is the clause final?

No. It is a proposed rule. The public comment window closes August 3, 2026, and the terms can change before GSA finalizes it.

Which contracts will it apply to?

GSA is expected to apply it across its governmentwide vehicles, including the Federal Supply Schedules, Governmentwide Acquisition Contracts, and OASIS+, once it is finalized.

Sources

Ready to take the next step?

Book your free Market Assessment. A senior FEDCON advisor will review your business and show you exactly where the opportunities are.