Two major updates out of the General Services Administration (GSA) show how the agency is actively shaping the future of federal AI procurement and the citizen digital experience

If you are a federal contractor, tech leader, or focused on GovTech, here is what you need to know about these recent developments:

Big Revisions to AI Procurement Draft Rules

Following significant industry pushback on its initial January and March drafts, the GSA released a heavily revised second draft of its landmark AI data-safeguarding clause (GSAR 552.239-7001), specifically targeting Large Language Models (LLMs).

  • The Progress: The GSA is being praised for refining its approach. They have walked back a strict, unworkable “American AI” absolute ban on foreign components, replacing it with a more practical mandate to maximize U.S.-managed systems. They also carved out key exceptions for embedded or incidental AI (like basic word processors) and introduced clear “flowdown” rules tailored to developers, integrators, and operators.

  • The Catch: Industry experts warn “more work is needed.” Compliance friction remains a major concern, particularly for contractors on GSA Multiple Award Schedules who could face steep accountability under upcoming mandate deadlines.

Upgrading the Login.gov Experience

Login.gov, the identity-proofing platform used by over 100 million Americans to access everything from Social Security to passports, is getting a major user experience (UX) overhaul.

  • The Partnership: GSA is collaborating with the White House’s National Design Studio (led by Airbnb co-founder Joe Gebbia) to build an experimental version of the platform. The goal is to modernize and streamline the sign-up, sign-in, and identity-proofing processes.

  • The Safeguards: While the Design Studio is providing real-time expertise and fresh design concepts, GSA emphasized that its internal teams retain full ownership. Every proposed UI change must still pass rigorous, standard agency reviews for security, privacy, and accessibility before hitting the public.

The GSA is attempting a difficult balancing act, trying to move quickly to modernize public-facing digital tools while carefully navigating the complex supply chains and safety boundaries of federal AI adoption.

What are your thoughts on the updated AI procurement rules? If you are a federal contractor, do these revisions alleviate your compliance worries? Let’s discuss in the comments!

Sources:

1 Like

The GSA deserves credit for listening to industry feedback on GSAR 552.239-7001. Narrowing the focus specifically to LLMs and data safeguarding—rather than attempting a sweeping, near-impossible restriction on all “American AI” components—is a huge win for operational reality. Walking back rules that would have flagged everyday office software shows they want to cooperate with industry, not stall it.

That said, for those of us managing delivery teams on Multiple Award Schedules, the compliance anxiety isn’t entirely gone—it has just shifted. The requirement to trace and manage data across the entire LLM supply chain (developers, integrators, and service providers) is a massive administrative lift.

The Login.gov approach is a great parallel here: leveraging elite commercial design expertise (via the National Design Studio) while keeping agency-level security controls in place is exactly how GovTech should work. The challenge for GSA moving forward will be ensuring that these new LLM data-safeguarding rules don’t accidentally throttle that exact kind of innovative, agile partnership.

1 Like

The revisions ease the optics, not the execution burden. Primes still own every downstream LLM component, and small/mid-tier contractors without a compliance function will feel the flowdown first.

Pragmatic revisions by the GSA here. Moving away from the absolute ‘American AI’ ban shows they are acknowledging global supply chain realities. But for those on MAS schedules, do you feel these updates actually reduce your compliance risk, or just move the goalposts? Curious to hear from folks currently trying to map their pipelines to these new drafts.

1 Like

GSA is definitely trying to walk a tightrope here. While the shift from a rigid “American AI” ban to a more practical data-safeguarding model is a massive step forward, the supply chain tracing is going to be a heavy administrative lift for small to mid-sized GovCons.

It will be fascinating to see if the streamlined UX philosophy they are testing with Login.gov eventually makes its way into how they manage compliance friction for contractors. If the compliance tools are as cumbersome as the old regulations, innovation will still stall.