2026-10-03
US GSA quietly rewrites AI buying rules to shield government data from LLM risks
The U.S. General Services Administration (GSA), which oversees most federal procurement, has issued a new memo dated October 2, 2026 that quietly but significantly tightens how agencies can buy AI services. The document adds AI‑specific language to federal acquisition rules, focusing on how contractors handle government data inside large language models (LLMs) such as those behind ChatGPT‑style services.
A new section titled “Basic Safeguarding of Data within Large Language Model Artificial Intelligence Systems” requires vendors to keep federal data segregated from other customers’ information and bars them from using that data to train or retrain their models without explicit authorization. The goal is to prevent sensitive information typed into chatbots or code assistants from leaking into broader model behavior or appearing in other users’ outputs.
Civil society experts welcomed the final terms as a substantial improvement over earlier drafts, but warned that enforcement, independent audits and penalties for misuse are still open questions. Because GSA contract language is often used as a template across agencies, these rules are likely to shape how the U.S. government adopts cloud‑based AI services over the coming years, turning abstract AI “principles” into concrete obligations for vendors.