‘Hallelujah’: Stakeholders react with praise and concern to GSA AI acquisitions clause
The long-awaited General Services Administration artificial intelligence acquisitions clause is here, and stakeholders are both celebratory and cautious.
Last week, GSA issued a regulation on AI acquisitions as a deviation — meaning it can be used immediately for new contracts, before it becomes mandatory on Oct. 19 as formal rulemaking still marches onward.
Some stakeholders feel they were mostly heard in the new policy after two public comment periods, but still have some reservations.
“GSA’s final AI terms and conditions mark a significant improvement from prior draft versions, and establishes a stronger foundation for safeguarding government data in AI systems,” Quinn Anex-Ries, senior policy analyst at the Center for Democracy & Technology, said in a statement.
A GSA spokesperson said the agency has been “highly collaborative throughout this rulemaking process, and the revised clause reflects that engagement.”
“GSA is thoughtfully integrating stakeholder feedback to reduce duplicative compliance burdens, clarify definitions and contractor obligations, and improve commercial workability,” they said.
Goodbye to ‘unbiased AI principles’
There is relief from several previous commenters about the removal of the term “unbiased AI principles” from most of the clause.
“Hallelujah,” said Jessica Tillipman, associate dean for Government Procurement Law Studies at George Washington University.
There’s only so much GSA can do, given that an executive order requires agencies to buy only AI models that follow “unbiased AI principles,” but “the changes reflect how unworkable this requirement is both technically and contractually,” she said.
But is it enough? The clause still asks contractors to provide documentation and testing methods tied to “unbiased AI principles” on request, though the list of principles was cut. And beyond that, the clause still says the government “reserves the right” to evaluate LLMs for “unsolicited ideological content.”
“I think we very much do want to evaluate them for bias, so it’s hard to criticize that,” said Electronic Frontier Foundation Legal Director Corynne McSherry. “It’s just when you have that in the same sentence as unsolicited ideological content, and I don’t know what unsolicited ideological content means exactly … ideological content could mean very different things to different people.”
McSherry said that while bias is a “significant problem” in various models, “we should put in place requirements that can be understood by contractors and by the relatively educated public.”
“It’s concerning to me that what that also could be code for ‘we’ve decided that “X” content is “ideological” and therefore we won’t work with you,’” she said. “The government is moving in the right direction, but there’s still language that is somewhat alarming, and we’ll just have to see what this looks like in practice.”
The Alliance for Digital Innovation said it is still working through the “implications” of the latest version of the clause. Executive Director Ross Nodurft said in a statement that there are “many improvements,” but the group believes “there are still several areas that could hamper technology companies from participating in the public sector marketplace.”
In the latest round of comments, EFF joined in with the Electronic Privacy Information Center, Upturn and CDT on a letter flagging the “unbiased AI principles” requirements as one of their key concerns.
“The bottom line here is this really scaled-back version will have significantly fewer harmful effects,” CDT’s Anex-Ries told FedScoop.
In its place, the clause says the contractor must use “reasonable efforts” to prioritize “accuracy, scientific inquiry, and objectivity” and acknowledge uncertainty. But Anex-Ries said this could still be “broadly interpreted by an administration who wants to advance a certain political agenda with the AI vendors that they work with.”
“It does leave open a little bit of room for a federal agency or an official in an agency to attempt to force the hand of a vendor,” he said. “That being said, the final form they landed with has less opportunity for political weaponization because of how pared back it is, so it’s a better balance compared to what we started with.”
Others with more critical comments, like Palantir, which called for GSA to withdraw the rule altogether, did not respond to requests for comment. Nvidia also did not respond and representatives for Microsoft declined to comment.
Protecting government data vs. undermining AI performance
Tillipman is “obviously thrilled” to see the clause’s improved “clarity” on government data usage context — an addition that resembles her comments.
At the listening session in July, Tillipman proposed a three-pronged test to assess what should be protected government data by answering: Is it tied to government use, does it reveal how the government operates, and can that conclusion be drawn even if no single record reveals it?
Now, the “government usage context” definition asks nearly the same questions.
“As the government continues to wrestle with the tension between protecting sensitive government information and ensuring that these requirements don’t undermine the performance of the product or deter vendors from doing business with the government, I think it helps clarify the line,” she said. “There’s still a lot of work to do in this area, but it’s an improvement.”
Anytime the government can put up strong data protection guardrails is “a good thing,” McSherry said.
Anex-Ries said it was “especially promising to see some of these concrete obligations” around data protections and usage, as well as a firmer provision allowing the government to suspend use of the AI at any time, “given that these tools can often behave in unexpected ways.”
“Given some of the significant privacy harms that can be introduced by the use of an AI system, these kinds of provisions are a really important step forward,” he said.
Overall, the clause might not be perfect, but it’s important to balance the risks AI tools could introduce into a government system and the risks of potential political weaponization, Anex-Ries said.
Regulation deviation accelerating the timeline?
While in the June Federal Register notice the agency said there possibly would be a regulation deviation, last week’s issuance still caught some by surprise — though to some, a welcome one.
“I have no problem with the fact that GSA used a deviation here,” Tillipman said. “The government has gone too long without adequate AI protections. And although some in industry may disagree, I do think GSA gave industry an adequate opportunity to provide feedback, which it clearly took into account in this version.”
Anex-Ries said while AI governance is a “pressing, urgent issue,” it is also important that it is given the proper time and attention to be successful, and “it’s not clear to me what really has happened with this timeline being accelerated.”
“This is a relatively novel kind of clause to put in place, and so I would hope that sufficient groundwork has happened to make sure that the folks responsible for implementing this within federal agencies are prepared, and for vendors to understand what these new requirements are,” he said.
Now that something is on the books, it’s “wait and see,” McSherry said.
“I think they should have done this properly in the first place,” she said of GSA going the deviation route before finishing official rulemaking. “This is a place where we have to see how it plays out.”