Everyone's Fighting the GSA AI Clause. That's the Wrong Fight.
The Executive Lens
The question to sit with this week: while the industry piles on to kill the GSA AI clause, what happens if the governance requirement outlives it?
At the July 14 listening session, contractors and Palantir called GSA's revised AI rule unworkable — impractical notice windows, commercial license terms rewritten. They're not wrong. But the governance expectation is arriving from three directions at once: the GSA clause, DoD's new "CMMC for AI" framework, and OMB's vendor representations. Kill the clause and two more are still standing.
Deloitte's 2026 State of AI is the tell: nearly three-quarters of organizations plan to deploy agentic AI within two years, and only about a fifth have mature governance for it. That gap is your opening. The firm that can show an AI use register, a data-flow map, and NIST AI RMF alignment before the contract demands it will win the evaluation the others are still lobbying to avoid.
Stop lobbying the clause. Build the governance.
Legal & Regulatory Watch
GSA's revised AI clause still falls short, stakeholders say. At the July 14 listening session on GSAR clause 552.239-7001, contractors and AI vendors said the rule is still too vague and out of step with commercial contracting. The 30-day advance-notice and 7-day degradation-notice requirements were called commercially impracticable, and Palantir warned agencies may route AI buys to non-GSA vehicles if it proceeds as written. Comments to the Federal Register notice close August 3.
"CMMC for AI" is coming to DFARS. The FY2026 NDAA directs DoD to build a security framework for AI/ML it acquires and fold it into DFARS and CMMC. This advances even as the Department of War just suspended CMMC Phase II for small contractors. The cyber-general relief is real; the AI-specific bar is rising.
Senate presses DoD and 7 AI vendors to disclose contract terms. A senator wants DoD and seven companies running AI on classified networks to disclose their agreement terms. If you sub under those primes, expect data-rights and audit terms to be scrutinized and pushed down the stack.
CAISI–GSA MOU wires AI evaluation into USAi. NIST's Center for AI Standards and Innovation is backing the evaluation science behind USAi, GSA's secure gen-AI platform. If your offering isn't legible in those evaluation terms, you're harder to buy.
Readiness Framework Spotlight: NIST AI RMF
The GSA clause, CMMC-for-AI, and OMB's vendor reps all lean on the same scaffold — the NIST AI Risk Management Framework (Govern, Map, Measure, Manage). Build your internal AI governance to the RMF now and you're answering the one structure underneath all three rules. Start with Govern and Map.
Practical AI Tools & Workflows
Tool of the Week: build your AI Use Register with your authorized assistant. For CUI, use a FedRAMP High path (like Claude for Government) or Microsoft 365 Copilot only where your GCC / GCC-High tenant is authorized — confirm it. For non-CUI data, commercial Claude or ChatGPT is fine; never paste CUI into a commercial tool. This week, prompt your assistant to build a table of every AI use: use case, data type (flag CUI), model + hosting, NIST AI RMF function, human-in-the-loop control, and accountable owner. That register is your first answer to the clause, CMMC-for-AI, and any prime's flow-down. The NIST AI RMF Playbook is a free, tenant-free scaffold for the column headers.
Industry News, Filtered
CIA will take "smart risks" adopting AI. The buying pace is accelerating while governance lags — position as the integrator who brings the guardrails, not just the model.
Deloitte: the agentic-AI governance gap is wide open. Governance maturity is now a competitive differentiator on AI-enabled work, not a compliance afterthought.
GSA FAS signals commercial-first acquisition. AI purchases will increasingly flow through consolidated commercial vehicles — being on the right schedule matters as much as the tech.