NDIA urges multiple changes in GSA's revised AI contract clause
The National Defense Industrial Association is urging the General Services Administration to make another round of revisions to contract clause language proposed for inclusion in deals with artificial intelligence vendors, citing concerns in 17 areas including flowdown responsibilities, "government data" rights and definitions, alignment with commercial practices, incident reporting and more. “NDIA and its membership appreciate the opportunity to provide comments and firmly appreciate the government’s desire to promote a strong, dynamic, and robust defense industrial base. But, without substantial revision, the Clause will prevent the federal government from accessing the best American AI capabilities available in the commercial market. NDIA stands ready to engage in further dialogue to develop workable solutions,” according to the group’s submission to the federal procurement agency. GSA on June 17 opened a public comment period on revised language for inclusion in federal contracts with AI vendors, which closed on Aug. 3. The original version of the proposed contract terms was released in January and triggered extensive pushback from industry and other stakeholders. “GSA appreciates our vendor community partnerships. Currently, we are assessing the feedback collected regarding the draft for the proposed GSAR clause ‘Basic Safeguarding of Artificial Intelligence Systems,’” a GSA spokesperson told Inside AI Policy last week. “We will share any updates regarding this initiative at a later date.” GSA in June said the new language “reflects substantial revisions from the Jan. 12, 2026, version and reflects GSA’s understanding of comments and concerns on that version.” Revisions address scope, definitions, contractor responsibilities, “Compliance, Reporting, and Documentation,” clarification “to ensure that contractors know what, when, and how to notify GSA of changes to the LLM,” and additional context on application of “unbiased AI principles.” But NDIA states in its filing, “NDIA respectfully submits that, if not carefully scoped, new data-access and data-rights requirements could create second-order effects that reduce the very access and innovation the Government seeks, while also undermining industry’s ability to invest in and monetize value-added data capabilities.” “These effects,” the defense trade group states, “run directly counter to the Administration’s objectives to accelerate responsible AI adoption, reduce acquisition friction, expand the supplier base, and preserve U.S. technological leadership. They could also delay access to improved capabilities and critical security updates. In a field moving as quickly as AI, timely access to current technology is itself a mission and national-security concern.” Responsibilities, control The first issue flagged by NDIA is the need to “align responsibility with actual control.” “The draft places substantial responsibility on the prime contractor for implementing the Clause, exercising due diligence over the entirety of the AI tech stack, and flowing down applicable requirements,” NDIA states. “Paragraph (f), in particular, requires inventory, supplier and role mapping, documentation, incident reporting, and change-management activities that extend beyond traditional subcontractor oversight and begin to resemble a separate AI supply-chain governance function.” The group notes, “A prime may act simultaneously as developer, service provider, integrator, and user. In other cases, critical information and controls may reside with an upstream model developer, cloud provider, hosting service, platform provider, open-source project, or other commercial entity with which the prime has no contractual privity.” “Although the draft permits some reliance on flow-downs and supplier attestations,” it states, “a prime cannot compel an open-source project or major commercial provider to accept Government-specific terms, disclose proprietary testing methods, provide bespoke transparency artifacts, or offer information that is not normally available to customers.” NDIA emphasizes, “Contractors should not be held responsible for controlling information, testing, or technical decisions that reside exclusively with another party.” NDIA recommends that GSA: Assign each obligation to the entity with the relevant role, authority, and practical ability to comply. Define reasonable contractor due diligence and establish a safe harbor where a prime has made commercially reasonable efforts but cannot obtain information controlled by an upstream provider. Permit reliance on validated supplier attestations, standard model documentation, system cards, independent assessments, certifications, and other commercially available assurance materials. Provide examples showing how responsibilities apply when the prime performs multiple AI roles or relies on cloud platforms, commercial foundation models, open- source components, resellers, or other indirect providers. Clarify that a prime is not responsible for independently reproducing model-level testing or documentation that only the developer can perform or provide. Overall, NDIA argues, “A risk-based, commercially workable approach would provide the intended assurance while helping agencies innovate at the speed required to stay ahead of increasingly capable adversaries. The goal should be to avoid safeguards intended to reduce AI risk inadvertently making the Government slower to acquire, update, and secure the technology.” “These changes,” the group says, “would not weaken the Government’s assurance objectives. They would make the requirements more enforceable, improve the quality of information available to agencies, and reduce the likelihood that compliance obligations exclude capable suppliers or delay access to important technologies.”