The U.S. General Services Administration has fixed much of the overreach in its first draft of a new AI contracting clause, but the revision leaves a critical gap: "government usage context" - a phrase that determines what information about the government's work the clause protects - has no definition. That gap has direct consequences for anyone in government relying on AI tools through federal contracts.
Over the past year, the federal government has drifted into governing artificial intelligence through its contracts. Bilateral agreements lack the accountability, deliberation, and permanence that statutes provide, yet "procurement" has become the popular answer to AI governance. The GSA's proposed clause for large language model contracts is the most visible attempt to operationalize that approach.
What the revised clause does and doesn't fix
The June revision of the proposed Basic Safeguarding of Data within Large Language Model AI Systems clause is a "dramatic improvement" and corrects much of the first draft's most obvious overreach, according to analysis published by Lawfare. GSA put down the sledgehammer and built a fence, but without first locating the property line. Several of the terms that determine whether government data protections apply were undefined in the first draft and remain undefined today.
The result is a clause that restricts what vendors may retain and reuse without clarifying how far those restrictions extend. That gap has significant consequences because most federal AI procurement runs through commercial acquisition: The government buys what the market already sells, largely on the vendor's terms. Those terms typically permit the provider to retain operational information about how customers use the system and fold that insight back into the product.
The government does not have to accept those terms. But departing from commercial practice has a price. Government-unique restrictions may require separate systems, new controls, and commitments from the vendor's own suppliers. Wherever GSA draws the lines, it must draw them clearly.
The cost of an undefined boundary
An undefined boundary governing data use in an AI system cannot sit dormant until a tribunal interprets it - it is applied continuously inside contractor systems during performance. The contractor makes the first classification on what data the restriction covers, and the government's only window into it is a right to request existing documentation. Nothing requires the contractor to record that a classification was made, the rule it applied, or the records it excluded.
By the time the question is raised, the information may already have been retained, reused, or deleted. The clause covers solicitations and contracts involving government data processed by an LLM, with exceptions for LLMs embedded in common commercial products and for LLM functionality that is "incidental to the primary purpose of the core requirement being procured." But "incidental" is also undefined.
What needs to be defined
The clause defines "government data" to include logs, metadata, derivative data, and synthetic data. It applies an exclusion for technical system-level data, which vendors need to run the service. That exclusion is essential, but it applies only if the data contains neither "government information" nor "government usage context" - and the clause doesn't clarify either term.
The exclusion has two defects, according to the article. First, the examples GSA provides do not identify what is excluded, so the same category of record can fall on either side of the line. Second, the contractor makes the classification call first, inside its own systems, with no test to guide it. "You can run a truck through that gap," the article states.
Any workable definition of "government usage context" should answer three questions: Does this data exist because of government use under the contract? Does it reveal how the government works, not just how the system performed? And if a single record does not reveal that, do the records in aggregate support a material inference about the government's nonpublic activities, workloads, or priorities?
This is similar to how GSA runs its own flagship AI deployment, USAi, which distinguishes among types of system data and applies different retention and use rules in advance.
Downstream use and the attenuation problem
The clause prohibits using government data for model improvement and any purpose beyond contract performance and support. But it does not specify when applying a generalized lesson still counts as a use of government data. A vendor may learn a broader design principle from working on a government contract and later apply that principle elsewhere. Has the connection become too attenuated? The clause does not say.
The GSA does not need to predicate what engineers remember. But it does need an appropriate rule. Procurement law already handles a version of this problem: The Federal Acquisition Regulation subpart 9.5 on organizational conflicts of interest requires contracting officers to identify and evaluate potential conflicts from unequal access to information.
The clause already requires access controls and segregation of government data from other customers' data. But it does not require separation between government support work and broader product development, or explain what role such controls play in establishing compliance with the downstream-use prohibition.
Why this matters for government professionals
If you work in government and use or manage a contract involving AI, this is the clause that will likely govern the data protections, and the data withdrawals are still undefined. The revised clause is better than the first draft, but the fear remains that both you and the contractor will be operating under ambiguous rules until a dispute arises - and by then, the data in question may have already been used. For government officials responsible for AI policy, the next step is to ensure that GSA provides a functional definition of "government usage context" before this clause spreads across federal procurement vehicles. For contracting officers managing AI acquisitions, the immediate task is to understand that without this definition, it is impossible to draw the line between protecting the government's data and interfering with the vendor's operations. The GSA gets to take those balances - but it cannot strike a balance between interests it hasn't defined.
Your membership also unlocks: