The bill strengthens federal cybersecurity and reduces potential foreign surveillance by banning a specific app and requiring rapid agency action, but it creates short-term costs, risks of operational disruption from the tight deadline, and legal concerns about singling out a private vendor.
Federal agencies and their employees will have reduced exposure to potential foreign-sourced surveillance because the bill requires removing DeepSeek and its successors from agency IT.
Executive agencies and federal staff get clear, time-bound federal guidance (60 days) and consistent FISMA-era security standards, improving cybersecurity governance and oversight.
Law enforcement, national security personnel, and security researchers can continue authorized uses under explicit exceptions, provided they document risk mitigation, preserving necessary operations under controls.
Federal employees and tech staff may face disrupted workflows because the rapid 60-day compliance deadline could force rushed decisions or conservative blocking of the app to meet the mandate.
Agencies will need to spend staff time and potentially funds to remove the app and implement new controls, creating short-term operational and budgetary costs for federal agencies and taxpayers.
Targeting a specific private company and its successors may raise legal or trade concerns and invite challenges that allege discriminatory treatment of the vendor.
Based on analysis of 2 sections of legislative text.
Requires OMB to order removal of the DeepSeek app and successor products from federal agency IT, allowing limited documented exceptions for law enforcement, national security, and security research.
Official title: Prohibit the use of DeepSeek by the executive agencies, and for other purposes.
Introduced February 27, 2025 by Jacklyn Sheryl Rosen · Last progress February 27, 2025
Requires the OMB Director to issue standards within 60 days that force executive agencies to remove the DeepSeek application and any successor provided by High Flyer (or entities it owns) from agency information technology, while allowing limited exceptions for law enforcement, national security, and security research if agencies document risk-mitigation steps. The standards must be developed in consultation with GSA, CISA, the DNI, and the Secretary of Defense and must be consistent with existing federal information security law (chapter 35 of title 44, U.S.C.).