Proposed AI Rules Could Reshape Government Contracts
The U.S. General Services Administration’s draft clause raises questions about software, data ownership, commercial agreements, and compliance for distributors working with the federal government.
By Ethan Gibble
Contributing Writer
There’s no getting away from artificial intelligence in today’s distribution operations. From productivity software and inventory management platforms to e-commerce automation, distributors are deploying AI to connect their data and expand their customer reach. Even the foodservice equipment itself is tapping into AI for features like predictive maintenance and optimized cooking times. The amount of proprietary information now flowing between AI-powered systems is endless, but like anything, that innovation and convenience comes with a downside.
For the federal government, the chief concern is the security of that data. If a malicious actor were to access an equipment distributor’s customer relationship management (CRM) system or quoting solution, for example, they could conceivably use it to distribute malware to government buyers that granted them access to sensitive information. It’s a scenario not unlike the 2020 cyberattack that breached a dozen government departments, including the U.S. Treasury and the Justice Department. Over the course of several months, the attackers modified a technology provider’s network monitoring software to install backdoors into government officials’ emails and confidential documents.
The ability for AI systems to act without human intervention only heightens those security risks. Federal policymakers are responding by regulating not only AI developers, but even businesses that use AI tools to complete government contracts. In March, the U.S. General Services Administration (GSA) published a draft contract clause aimed at safeguarding government data within large language model (LLM) AI systems. While the goal of ensuring secure and trustworthy AI for the federal government is an important one, the execution outlined in the GSA Acquisition Regulation (GSAR) clause has raised concerns that extend well beyond AI.
Compounding the issue is the GSA’s influence across all government operations. The organization administers the Multiple Award Schedule, a contracting program that federal, state, and local agencies can use to buy commercial products and services at pre-negotiated prices. Because such a wide range of government organizations purchase through the GSA rather than running their own procurements, requirements that begin as part of GSA contracts can shape how technology is deployed throughout the country.
As a result, the Software & Information Industry Association (SIIA) has warned that the clause could eventually serve as a template for broader Federal Acquisition Regulation (FAR) provisions or for policies adopted by other agencies, making the proposal equally important to companies outside the technology space. “Federal procurement terms are a leading indicator,” Bethany Abbate, director of AI policy with SIIA, explained. “What the government demands of vendors could reshape the contracts and product behavior those same vendors offer commercial customers tomorrow.”
The initial draft prompted significant concern and advocacy from groups like SIIA, leading to a heavily revised draft submission in June. Abbate was happy to see several changes, such as the removal of both the blanket prohibition on foreign components and the Office of Management and Budget directive requiring compliance for AI systems. But she also cautioned that there are still key questions that need to be answered. “We are still concerned that several of the provisions go beyond safeguarding data and seek to impose requirements on AI systems more broadly,” she said.
Could Commonly Used Software Be Covered?
By updating the name of the clause in its revised draft to “Safeguarding Data within LLM AI Systems” rather than referring to AI systems at large, GSA has narrowed the scope of its clause, though perhaps not far enough. “The general consensus was that AI needs to be more clearly defined,” Abbate said, recalling a July listening session with GSA. “There are potential downstream implications that people are still concerned about there.”
That concern is not just for companies selling standalone chatbots or AI models. An operations team may use an enterprise resource planning (ERP) system that applies AI or machine learning to help forecast product demand and recommend inventory targets. A service provider may use sensor data with AI-based predictive maintenance tools to forecast equipment failures before they occur. In either case, they may not think of themselves as using an AI system. To them, it may just be a familiar ERP platform or equipment-monitoring service. But the reality is that AI is so embedded in today’s technology solutions that the government’s proposed contract terms have the potential to cover nearly every piece of software that a foodservice equipment and supplies distributor uses.
“How regulators draw this line is going to determine how everyday software gets labeled, disclosed, and contractually treated,” Abbate said. “The vague definitions and the level of uncertainty about what counts as AI in your agreements — that would be an area to continue to pay attention to.”
Can Companies Realistically Comply?
The proposal introduces a framework based on “unbiased AI principles” that aims to ensure the neutrality of LLMs used by the government, but what does “unbiased” mean under the clause? “That is the open question,” said Abbate. “The provision itself doesn’t include enough specificity for LLM developers to even ensure compliance with this concept of unbiased AI principles. LLM development is really complicated, and each model reflects different steps to improve reliability of information that’s generated in response to user queries.”
Given that the proposed consequences for noncompliance could be as severe as decommissioning the entire system, the concern is even more heightened. SIIA has asked GSA to use objective, recognized benchmarks, including standards developed by the National Institute of Standards and Technology and international standards organizations, rather than imposing unclear government-specific requirements.
Could the Clause Trigger Changes to Intellectual Property Rights?
Data ownership is one of the key considerations for any AI integration. Some AI-driven software agreements give vendors the right to use a company’s data to train their AI models or even retain that data. If that company is using AI systems as part of a federal contract, the government’s ownership stake can further complicate matters.
The most recent proposal defines “background data” as pre-existing proprietary content, reference materials, knowledge bases, and IP owned or controlled by a contractor that may be incorporated into LLM processing. Importantly, the new language specifically states that the contractor retains ownership of that data in its original form. That protection was absent in the initial draft and is a welcome step in the right direction. But the June draft also states that “the government retains ownership of all feedback provided by the government to the contractor with respect to the LLM or custom developments, regardless of whether such feedback is generated by government personnel, the contractor, or through automated processes.”
Although the June draft clarifies that contractors retain ownership of their background data, SIIA remains concerned that the proposal gives the government broad rights in certain AI-generated outputs created during contract performance. The organization argues that those provisions could blur the traditional distinction between a contractor’s pre-existing intellectual property and work products generated from that proprietary information.
Could Government Contracts Reshape Commercial Agreements?
The proposal’s order-of-preference language could be just as consequential as the data ownership definitions. “The proposed clause introduced a departure from a lot of established procurement norms by implementing this order of precedence that would override the standard commercial licensing terms and safety policies,” Abbate said. “By incorporating this new clause into the highest precedence tier, GSA is essentially placing its AI safeguarding requirements above all other commercial terms, including a contractor’s standard commercial agreements and any negotiated terms as well.”
That could create a situation where a distributor agrees to federal AI requirements that conflict with the commercial licensing terms of the software it uses. It could also influence commercial customers outside of government contracting. “If a vendor accepts those federal terms, then the posture can eventually flow back down to how the commercial deals are structured as well,” Abbate explained. “So, it goes beyond just government here.”
Are Contractor Obligations Feasible?
The June draft requires contractors not only to follow the clause’s requirements themselves, but also to flow those requirements down to their subcontractors and suppliers and verify that they comply. As Abbate points out, that would require an incredible amount of oversight. “[SIIA] members are concerned that would be unsustainable and add another level of expense to compliance,” she said. “There’s a lot of administrative bureaucracy by demanding this type of very rigorous due diligence.”
A new provision also requires the contractor to notify the contracting officer within 72 hours of any change that causes the software to fall out of compliance with the clause. “Our members don’t see that as very efficient and cost effective in the context of federal acquisition,” Abbate said. “We have recommended that the terms of service align with standard commercial terms whenever possible here, because that’s going to be the lowest lift. That would then also mirror the real market best practices rather than creating an entirely new regulatory framework.”
What Actions Should Distributors Take?
The GSAR clause is still just a proposal. The deadline for the most recent round of public comments was Aug. 3 and more changes are likely before the clause is codified — if it is codified. With the final rule still likely a long way off, Abbate believes there is no need for distributors to make operational changes at this point. “My impression based on the July listening session is that GSA is receptive of the fact that things need to be adjusted further,” Abbate said. The key for businesses is to be on alert for updates because these AI contract rules affect more than just AI developers.
“This is a big challenge for companies across the board in terms of having to invest more in compliance over time,” Abbate continued. “It’s a concern, especially for smaller companies who are not necessarily AI companies by nature but are trying to adapt to the technology and understand how they can best comply.”
Her broader advice to distributors is to treat the GSA proposal as just one part of a fast-changing policy environment. “Look beyond just what GSA is doing and continue to pay attention to broader trends in the AI governance landscape,” she said. “View this GSA clause as one snapshot.”
That snapshot may change, but underlying questions like who owns data, which systems count as AI, what obligations can flow through a supply chain, and whether government terms override commercial protections are likely to remain important for distributors long after this clause is finalized.