← All company positions
Palantiragenda

Re: Comments to General Services Administration Proposed AI Clause

Published August 3, 2026 · Printed on page 1 below the Freshfields letterhead (Washington, DC office) and above the line "Via Federal eRulemaking Portal", and repeated above the signature block on page 18. regulations.gov records the comment as received August 3, 2026 (the comment deadline) and posted August 4, 2026. The PDF metadata gives a creation date of August 3, 2026, matching the printed date.

Not law. This is a company's own public position on AI regulation. It is not law, and it carries no legal force.

What it argues for

These are Palantir's comments on the General Services Administration's proposed contract clause on "basic safeguarding of data within Large Language Model Artificial Intelligence Systems" (GSAR 552.239-7001, published June 17, 2026 at 91 Fed. Reg. 36559, docket GSA-GSAR-2026-0331), filed on regulations.gov on August 3, 2026 by the law firm Freshfields US LLP as counsel to Palantir Technologies Inc. and Palantir USG, Inc. It asks for the clause to be dropped outright: "we recommend that GSA withdraw the Proposed AI Clause from consideration as part of any GSA rulemaking." Palantir describes itself as "an American commercial software company—not an AI model developer" whose model-agnostic AIP platform is how agencies reach commercial models through GSA contracts, and warns that the clause "will likely prevent Palantir from providing government customers with the AI-powered solutions they need through GSA contracts". The arguments are mostly legal: GSA "has no independent authority to promulgate a rule that would regulate government-wide acquisition of AI technology"; the clause's "one-sided, anti-commercial terms" breach the Federal Acquisition Streamlining Act (FASA) and FAR Part 12 by overriding commercial licences and flowing GSA terms down to commercial suppliers; it rests on the rescinded Executive Order 14110 and cuts against the current administration's deregulation and procurement orders; it clashes with defence acquisition law; and its claims of government "ownership" of custom development and of "Data Outputs" reverse the tradition that the contractor owns IP and the government takes a licence. On substance it objects that the clause assumes "commercial platform providers like Palantir can dictate every aspect of how a third-party proprietary AI technology is developed and modified", that the "unbiased AI principles" in the clause are undefined yet would put the risk of a model's perceived bias, including decommissioning costs, on Palantir, that change notices and per-model documentation are unworkable, and that barring human access to government data and keeping content out of audit logs would make data "less secure, not more". It adds that GSA did no cost-benefit analysis and considered no less burdensome alternative. Set beside Palantir's earlier filings, this applies the commercial-first procurement case of its March 2025 Action Plan memo to a concrete rule; and where its October 2025 letter to OSTP accepted that high-impact AI should carry mandated testing and monitoring, this letter opposes a specific set of LLM safeguards once they are written as contract terms binding the vendor.

Stated positions (15)

  • GSA should withdraw the clause, not amend it: "Palantir urges GSA to withdraw the Proposed Rule."
  • GSA lacks the power to set government-wide AI terms on its own: "GSA, acting alone as it is here, has no independent authority to regulate federal AI policy and acquisition terms on government-wide contract vehicles." The letter argues that the general authority in 40 U.S.C. § 121, the AI in Government Act, the Advancing American AI Act and the 2026 NDAA do not clearly give GSA that authority.
  • The central objection is commercial-item law: "The most significant flaw in the Proposed AI Clause is that it violates FASA", because the clause "would prioritize GSA’s bespoke, one-sided license terms and deliverable demands over commercial license agreements, including Palantir’s standard commercial software license agreement."
  • GSA terms should not be pushed down the supply chain: "These overbroad flow down obligations are contrary to specific restrictions in FASA and the FAR".
  • A platform provider cannot vouch for someone else's model: "Palantir cannot guarantee exactly how a third party’s proprietary AI model was trained or exactly how that model will function once deployed."
  • Advance notice of every change cannot work for software that changes daily: "Modern commercial software and AI models are updated constantly (often multiple times a day)", and "It is operationally impossible to provide any customer with advance notice of each change".
  • Security depends on seeing content, not hiding it: "No serious enterprise or LLM provider protects data by making that data invisible to its own security team", and "Content-inclusive security and audit logging is not a risk to be engineered away".
  • The unbiased-AI requirements are too vague to comply with: the clause "fails to provide fair notice of what conduct, speech, program activity, or institutional position could be considered a violation" and "arguably risks imposing political and ideological litmus tests that reach far beyond the performance of any specific federal contract."
  • Contract terms must not float with future policy: by referring to OMB M-25-21 and successor requirements, "This suggests that GSA contractors could be subject to new AI standards unilaterally imposed by some future administration’s OMB."
  • The government should not be able to suspend a model and bill the contractor for decommissioning on its own assessment that the model fails the unbiased-AI principles; the FAR's suspension and termination clauses are meant to make the contractor whole.
  • Government ownership of IP is the wrong model: "This concept of government IP ownership is contrary to longstanding federal procurement law and policy", and under the clause's definition of outputs "government personnel could direct an AI model to summarize a company’s proprietary technical data, and the government would then own the output summary".
  • The clause conflicts with this administration's own policy: "GSA describes the Proposed Rule as implementing a Biden-era Executive order that President Trump rescinded", and "if GSA’s Proposed AI Clause were essential to sound procurement, then why has the FAR Council not included the Proposed AI Clause in the ongoing Revolutionary FAR Overhaul?"
  • Defence buyers have their own rules: Congress and the DFARS "prohibit defense agencies from demanding proprietary IP rights as a condition of contract award", so the clause would push defence agencies off GSA vehicles.
  • The paperwork is unjustified: "there is no indication that GSA has conducted any cost-benefit analysis or even considered alternative approaches", and "it is not obvious what a government customer would even do with that information."
  • Keeping all human eyes off government data is unrealistic: the requirement is "a standard so unequivocal that it approaches technical impossibility".

About this document

An 18-page letter on Freshfields US LLP letterhead, filed as public comment GSA-GSAR-2026-0331-0066 on regulations.gov under Notice-MVAC-2026-01 (Docket No. 2026-0331, Sequence No. 1), with the reference line "Re: Comments to General Services Administration Proposed AI Clause". It is written by counsel "On behalf of Palantir Technologies Inc. and its wholly owned subsidiary Palantir USG, Inc." and signed "/s/" by Nathaniel E. Castellano and Ian Maurer of Freshfields US LLP as "Counsel to Palantir Technologies Inc. and Palantir USG, Inc."; the PDF metadata author is "CASTELLANO, Nathan". After an introduction summarising seven objections (A to G), Part II develops them under headings on GSA's authority, FASA and FAR Part 12, the administration's executive orders, defence acquisition, intellectual property, risk allocation and paperwork burden; Part III recommends withdrawal. It has 41 footnotes citing statutes, FAR and DFARS provisions, executive orders, case law (among them West Virginia v. EPA and Chrysler Corp. v. Brown) and two treatises on government-contract IP; several footnotes end "available at link" with the hyperlink not preserved in the text. Two small inconsistencies: Executive Order 14240 is cited at 90 Fed. Reg. 14240 in footnote 6 but at 90 Fed. Reg. 13671 in footnote 23, and one clause paragraph is referred to as "(e)(ix)".

How this sits against AI law

Each stance compared with what EU and US instruments actually require. Where no instrument addresses a theme, that gap is shown rather than hidden.

Commercial licence terms should govern government purchases of AI, without agency-specific clauses

Under FASA and FAR Part 12 agencies buying commercial AI must accept customary commercial licences with only narrowly tailored changes; a GSA clause that overrides commercial licences, adds bespoke deliverables and flows its terms down to commercial suppliers is unlawful, and "For this reason alone, GSA should not proceed with the Proposed Rule at all."

European UnionNo equivalent law

The AI Act regulates providers and deployers of AI systems and models, not the contract terms public bodies use when buying them; a public authority using a high-risk system is treated as a deployer with its own obligations.

United StatesAsks for more

OMB M-25-22 requires agencies to include AI-specific terms in contracts for AI systems and services, covering IP rights and use of government data, privacy, vendor lock-in protections, compliance with M-25-21's minimum risk-management practices for high-impact uses and ongoing testing and monitoring, and asks agencies to standardise such terms where possible. US policy therefore already expects government-specific AI terms beyond a customary commercial licence, though agency by agency rather than through one GSA clause.

Government ownership of AI outputs and custom development

The contractor should keep ownership of IP and the government take a licence, as under the Bayh-Dole tradition and long procurement practice; the clause's broad "Custom Development" definition and its claim to "Data Outputs" would hand the government privately developed technology and even proprietary information summarised in an LLM's output.

European UnionNo equivalent law

The AI Act does not allocate ownership of AI outputs or of software developed under contract; that is left to national contract, procurement and IP law.

United StatesAsks for more

M-25-22 does not claim government ownership of outputs, but it requires contract terms that "clearly delineate the respective ownership and IP rights of the government and the contractor", lists "providing agencies with rights to code and models produced in performance of a contract" among lock-in protections, and requires contracts to "permanently prohibit the use of non-public inputted agency data and outputted results to further train publicly or commercially available AI algorithms" absent agency consent: more than the narrow commercial licence Palantir defends.

Unbiased-AI requirements and vendor liability for decommissioning

The clause's "unbiased AI principles" are undefined and give no fair notice of what counts as a violation, risk imposing ideological tests beyond the contract, may import future OMB standards, and would let an agency suspend a model and charge the contractor decommissioning costs on its own judgment; the clause "goes far beyond anything required in that Executive Order."

European UnionNo equivalent law

The AI Act sets no ideological-neutrality or truth-seeking requirement for language models; its concern with bias is limited to data governance for high-risk systems and to fundamental-rights risks.

United StatesContradicts

Executive Order 14319 directs each agency head to include in every federal contract for an LLM "terms requiring that the procured LLM comply with the Unbiased AI Principles and providing that decommissioning costs shall be charged to the vendor in the event of termination by the agency for the vendor's noncompliance with the contract following a reasonable period to cure", which is the mechanism Palantir objects to. The order does ask OMB to avoid over-prescription and to let vendors comply by disclosing system prompts, specifications or evaluations, which is closer to Palantir's concern.

A platform that routes to third-party models should not answer for how those models are built and behave

Palantir is a commercial platform, not a model developer; it cannot dictate licence terms to model developers, guarantee how a third-party model was trained or will behave, or supply their documentation, so a clause that makes the platform provider responsible for every aspect of a third party's probabilistic model misallocates risk.

European UnionAligned

The AI Act places documentation and transparency obligations for general-purpose AI models on the model provider, including information and support for downstream integrators, so the party that builds the model carries the duty to document it; a downstream integrator becomes responsible as a provider mainly when it places its own high-risk system on the market.

United StatesAsks for more

M-25-22 tells agencies to "inform vendors of reasonable transparency and documentation requirements that will be placed on the vendor" and to require enough descriptive information to complete M-25-21 impact assessments; it does not distinguish a platform vendor from the model developer, so the contracting vendor carries the duty.

Documentation, change-notice and reporting duties, and the burden they create

The clause's per-model documentation lists, near-constant change notifications keyed to a vague "Material Change" test, 72-hour reporting and feedback mechanisms add paperwork with no evident use, and GSA has done no cost-benefit analysis or considered less burdensome alternatives, contrary to Executive Orders 14192 and 14275.

European UnionAsks for more

By law, providers of high-risk AI systems must keep technical documentation and records enabling conformity assessment, run post-market monitoring and report serious incidents, and general-purpose model providers must document their models; these duties are heavier than Palantir would accept as contract terms, though they fall on providers rather than on a reseller.

United StatesAsks for more

M-25-21 requires agencies to carry out impact assessments, pre-deployment testing and ongoing risk management for high-impact AI; the GSA clause, as Palantir describes it, asks vendors for the information needed to complete those assessments, and M-25-22 expressly expects agencies to obtain it from vendors. The documentation burden thus has a basis in current OMB policy, even if the clause's scope is Palantir's objection.

Security logging and human access to government data

Data should be protected by restricting access to authorised personnel on a need-to-know basis and by logging content so misuse can be detected; barring all human access to government data and excluding content from audit logs would leave security teams blind and make government data less secure.

European UnionAligned

The AI Act requires high-risk AI systems to allow automatic logging of events over their lifetime for traceability and post-market monitoring (Article 12), and requires human oversight; it does not require logs to exclude content or bar human review of data.

United StatesAligned

M-25-22 asks agencies for data-handling guidance under which agency information "must only be collected and retained by a vendor when reasonably necessary to serve the intended purposes of the contract", a minimisation and need-based standard close to Palantir's; it contains no ban on human review of government data or on content logging.

Much of what Palantir attacks in the GSA clause is not GSA's invention but current US federal policy written into contract form. OMB M-25-22 already tells agencies to put terms on IP and government data, vendor lock-in, M-25-21 risk-management compliance and ongoing testing into AI contracts, and to prohibit vendors from training commercial models on non-public agency data and outputs; Executive Order 14319 tells agencies to require that procured LLMs meet its Unbiased AI Principles and to charge decommissioning costs to a non-compliant vendor. The letter itself grants that the clause draws on that order but says it goes far beyond it, and it frames its case as GSA overreach resting on the rescinded Executive Order 14110 rather than as disagreement with the OMB memoranda. The EU has no counterpart to a procurement clause of this kind: the AI Act does not write public-sector contract terms. Its value-chain design, though, fits Palantir's main point about risk: documentation and transparency duties for general-purpose models fall on the model provider, which must support downstream integrators, rather than on a platform that routes to the model. At the same time the EU imposes by law, on high-risk providers, the kind of technical documentation, record-keeping and logging that Palantir calls anti-commercial when a buyer demands it, and its logging requirement supports Palantir's view that "Content must be logged so that misuse can be detected and investigated."

Source

https://downloads.regulations.gov/GSA-GSAR-2026-0331-0066/attachment_1.pdf
Date on the page:
August 3, 2026
Source checked:
opened and confirmed on 2026-09-30