{"id":1652927,"date":"2026-06-08T10:30:17","date_gmt":"2026-06-08T14:30:17","guid":{"rendered":"https:\/\/observer.com\/?p=1652927"},"modified":"2026-06-08T09:55:00","modified_gmt":"2026-06-08T13:55:00","slug":"ai-procurement-governance-compliance","status":"publish","type":"post","link":"https:\/\/observer.com\/2026\/06\/ai-procurement-governance-compliance\/","title":{"rendered":"The New Front Line of A.I. Governance Is Procurement"},"content":{"rendered":"<figure id=\"attachment_1653325\" aria-describedby=\"caption-attachment-1653325\" style=\"width: 930px\" class=\"wp-caption aligncenter\"><img decoding=\"async\" class=\"wp-image-1653325 size-full-width\" src=\"https:\/\/observer.com\/wp-content\/uploads\/sites\/2\/2026\/06\/alex-shuper-gXwJ8rr0R88-unsplash.png?w=930\" alt=\"A repeating pattern of outlines of silver heads with brains and a center head with a gold brain\" width=\"930\" height=\"764\" srcset=\"https:\/\/observer.com\/wp-content\/uploads\/sites\/2\/2026\/06\/alex-shuper-gXwJ8rr0R88-unsplash.png 930w, https:\/\/observer.com\/wp-content\/uploads\/sites\/2\/2026\/06\/alex-shuper-gXwJ8rr0R88-unsplash.png?resize=300,246 300w, https:\/\/observer.com\/wp-content\/uploads\/sites\/2\/2026\/06\/alex-shuper-gXwJ8rr0R88-unsplash.png?resize=768,631 768w, https:\/\/observer.com\/wp-content\/uploads\/sites\/2\/2026\/06\/alex-shuper-gXwJ8rr0R88-unsplash.png?resize=635,522 635w, https:\/\/observer.com\/wp-content\/uploads\/sites\/2\/2026\/06\/alex-shuper-gXwJ8rr0R88-unsplash.png?resize=320,263 320w, https:\/\/observer.com\/wp-content\/uploads\/sites\/2\/2026\/06\/alex-shuper-gXwJ8rr0R88-unsplash.png?resize=50,41 50w\" sizes=\"(max-width: 768px) 135px, 200px\" \/><figcaption id=\"caption-attachment-1653325\" class=\"wp-caption-text\">Enterprise A.I. purchasing now carries far-reaching implications for data governance, liability, vendor dependency and regulatory compliance. <span class=\"media-credit\">Unsplash+<\/span><\/figcaption><\/figure>\n<p><span style=\"font-weight: 400\">In the A.I. era, traditional approaches to software procurement are no longer fit for purpose. Typically considered a commercial function\u2014secure the best software for the best price\u2014procurement teams are now making decisions about highly complex technical systems that can shape an organization\u2019s governance posture, regulatory exposure, security and operational resilience.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400\">Enterprises interact with A.I. in many forms, from standalone software to features embedded in existing platforms. Regardless of how A.I. enters the enterprise, its presence immediately raises governance questions. Who owns the data? How was the system trained? Who is liable for errors? Most procurement teams lack the technical expertise to parse this complexity and audit the systems before making purchasing decisions, creating governance risks from the outset.<\/span><\/p>\n<p><span style=\"font-weight: 400\">Exacerbating these complexities is an asymmetry of power between procurement teams and A.I. vendors. A small number of dominant A.I. providers can set the terms of use and implement top-down changes without negotiating with clients. Executives urging organizational A.I. adoption only intensify this pressure, leaving procurement officials to navigate out-of-date processes without the benefit of A.I.-specific training or guidance.<\/span><\/p>\n<p><span style=\"font-weight: 400\">Together, these factors have created a new governance frontier. Procurement has transformed from a commercial function into one of the most consequential\u2014and least mature\u2014<\/span><a target=\"_blank\" target=\"_blank\" rel=\"noopener\" href=\"https:\/\/heyzine.com\/flip-book\/7bc82d631c.html\" data-lasso-id=\"2967073\"><span style=\"font-weight: 400\">components of enterprise A.I. governance<\/span><\/a><span style=\"font-weight: 400\">.\u00a0\u00a0<\/span><\/p>\n<h3><b>The emerging risks of A.I. procurement<\/b><\/h3>\n<p><span style=\"font-weight: 400\">Unlike traditional software procurement, A.I. procurement introduces governance risks that continue to evolve after a contract is signed. A.I. supply chains span models, infrastructure providers, APIs and application layers, making it difficult to pinpoint who is liable for what if things go wrong. Even if liability is decided at the time of procurement, rolling updates and feature releases can complicate accountability structures and introduce novel risks after contracts are signed.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400\">The pace of technological and regulatory change is also shortening procurement and contract review cycles. The upside is that shorter cycles offer flexibility; the downside is that they introduce ongoing procurement and governance demands that organizations must manage continuously.<\/span><\/p>\n<p><span style=\"font-weight: 400\">These challenges are exacerbated by market concentration. OpenAI, Anthropic and Google collectively account for <\/span><a target=\"_blank\" target=\"_blank\" rel=\"noopener\" href=\"https:\/\/menlovc.com\/perspective\/2025-the-state-of-generative-ai-in-the-enterprise\/\" data-lasso-id=\"2967074\"><span style=\"font-weight: 400\">88 percent of enterprise LLM usage<\/span><\/a><span style=\"font-weight: 400\">, leaving buyers exposed to top-down changes in pricing, product features and contractual terms. On top of this, the nature of A.I. drives \u201clock-in\u201d to individual providers because models improve through interaction with user data and workflows. Switching providers can therefore become operationally disruptive, expensive and technically difficult.<\/span><\/p>\n<p><span style=\"font-weight: 400\">Data management is one of the most <\/span><a href=\"https:\/\/observer.com\/2026\/05\/ai-adoption-data-governance-enterprise-risk\/\" data-lasso-id=\"2967075\"><span style=\"font-weight: 400\">underestimated areas of risk<\/span><\/a><span style=\"font-weight: 400\"> in A.I. procurement. Core due diligence questions dealing with data collection, storage and model training are often left unanswered at the point of contract. As a result, organizations may inadvertently expose confidential information, proprietary business data or customer records to external model training processes.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400\">A.I. presents IP risks, too; models trained on data scraped from the web may generate outputs that include copyrighted or unauthorized material, exposing organizations to downstream legal and reputational risks. Other IP considerations, such as ownership of A.I. outputs and metadata, should be proactively addressed during procurement.<\/span><\/p>\n<p><span style=\"font-weight: 400\">Agentic A.I. is the next frontier of procurement risk. Capable of independently traversing multiple platforms and datasets, these systems introduce risks of a fundamentally different order of magnitude. Increasingly, vendors are <\/span><a target=\"_blank\" target=\"_blank\" rel=\"noopener\" href=\"https:\/\/www.cliffordchance.com\/insights\/resources\/blogs\/talking-tech\/en\/articles\/2026\/02\/agentic-ai-and-the-liability-gap-your-contracts-may-not-cover.html\" data-lasso-id=\"2967076\"><span style=\"font-weight: 400\">excluding key A.I.-related harms<\/span><\/a><span style=\"font-weight: 400\"> from liability clauses within agentic A.I. contracts, leaving buyers exposed. As A.I. agents grow in sophistication and popularity, all these concerns\u2014liability, accountability, dependency and data management\u2014will have to be continuously addressed and renegotiated.\u00a0<\/span><\/p>\n<h3><b>Four pillars for responsible A.I. procurement<\/b><\/h3>\n<p><span style=\"font-weight: 400\">Because purchasing A.I. introduces unique risks that are not associated with conventional software, organizations need procurement frameworks designed specifically for A.I. Based on our experience consulting enterprises on responsible A.I. adoption, we recommend building such frameworks on four pillars.<\/span><\/p>\n<p><span style=\"font-weight: 400\">First, teams should be upskilled. Procurement teams should be literate in A.I. functionalities, safety and compliance. This doesn\u2019t mean every procurement official should become a technical expert, but they do need enough understanding to evaluate governance implications.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400\">Organizations should support this through certification programs, cross-functional procurement models and closer collaboration between procurement, legal, compliance, cybersecurity and technical teams. <\/span><a href=\"https:\/\/observer.com\/2026\/03\/shadow-ai-enterprise-literacy-gap\/\" data-lasso-id=\"2967077\"><span style=\"font-weight: 400\">Broader workforce training on responsible A.I. use<\/span><\/a><span style=\"font-weight: 400\"> is also important, particularly as employees increasingly adopt A.I. tools independently.<\/span><\/p>\n<p><span style=\"font-weight: 400\">Emerging vendor engagement models, in which procurement personnel collaborate with A.I. vendors\u2019 <\/span><a target=\"_blank\" target=\"_blank\" rel=\"noopener\" href=\"https:\/\/newsroom.accenture.com\/news\/2026\/accenture-launches-microsoft-forward-deployed-engineering-practice-to-help-organizations-scale-ai-across-the-enterprise\" data-lasso-id=\"2967078\"><span style=\"font-weight: 400\">forward deployment engineers<\/span><\/a><span style=\"font-weight: 400\"> to tailor tools to operational needs, ensure a deeper understanding of technical elements. While this approach can improve outcomes, organizations also need to invest time in internal change management, governance reviews and process design.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400\">Second, tailor procurement processes to the type of A.I. system being acquired. Procurement teams face a range of A.I. products, including A.I.-powered tools, A.I.-enabled features and foundation models. Each category introduces novel governance, compliance and operational risks that require tailored procurement approaches.<\/span><\/p>\n<p><span style=\"font-weight: 400\">For A.I.-powered products, procurement teams should focus on the use case fit, data sovereignty and hosting arrangements. Consider an adverse example: when Workday released its <\/span><a target=\"_blank\" target=\"_blank\" rel=\"noopener\" href=\"https:\/\/hr.dickinson-wright.com\/2025\/06\/03\/ai-on-trial-implications-of-the-workday-lawsuit-for-automated-hiring\/\" data-lasso-id=\"2967079\"><span style=\"font-weight: 400\">A.I.-powered Applicant Tracking System<\/span><\/a><span style=\"font-weight: 400\">, it was billed as a ready-to-use tool for H.R. teams. However, the product violated the Age Discrimination in Employment Act by favoring applicants under 40. Organizations that adopted the tool without sufficient procurement scrutiny faced compliance exposure under employment law.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400\">When vendors introduce A.I. features into existing software products, procurement teams should renegotiate contracts that lack A.I.-specific clauses. This is an increasingly common situation that presents complex governance and compliance risks. For example, when <\/span><a target=\"_blank\" target=\"_blank\" rel=\"noopener\" href=\"https:\/\/www.theregister.com\/software\/2026\/03\/26\/github-we-going-to-train-on-your-data-after-all\/5229507\" data-lasso-id=\"2967080\"><span style=\"font-weight: 400\">GitHub updated its training requirements early in 2026<\/span><\/a><span style=\"font-weight: 400\">, organizations with lower-tier subscriptions found that their private data was being used to train A.I. models. Situations like this undermine organizations&#8217; privacy, data protection and security controls.<\/span><\/p>\n<p><span style=\"font-weight: 400\">When procuring a foundation model or platform, organizations should focus on technical capability and strategic implications. For example, the U.K.\u2019s NHS recently faced criticism for a procurement process that <\/span><a target=\"_blank\" target=\"_blank\" rel=\"noopener\" href=\"https:\/\/www.theguardian.com\/society\/2026\/may\/11\/palantir-access-nhs-england-patient-data\" data-lasso-id=\"2967081\"><span style=\"font-weight: 400\">allowed U.S. firm Palantir to access identifiable patient data<\/span><\/a><span style=\"font-weight: 400\"> while developing a federated data platform. The platform is intended to deploy A.I. across patient records to improve efficiency. However, the procurement approach has undermined public trust in the NHS and its services.<\/span><\/p>\n<p><span style=\"font-weight: 400\">Third, A.I. procurement should be anchored in established governance frameworks, standards and emerging regulatory requirements. Even in jurisdictions where A.I. regulation remains underdeveloped, aligning with the wider regulatory system allows organizations to demonstrate that their A.I. use is safe, responsible and trustworthy. It also creates defensible evidence that governance obligations were considered before deployment.<\/span><\/p>\n<p><span style=\"font-weight: 400\">Standards such as <\/span><a target=\"_blank\" target=\"_blank\" rel=\"noopener\" href=\"https:\/\/www.iso.org\/standard\/42001\" data-lasso-id=\"2967082\"><span style=\"font-weight: 400\">ISO 42001<\/span><\/a><span style=\"font-weight: 400\"> for A.I. management systems and <\/span><a target=\"_blank\" target=\"_blank\" rel=\"noopener\" href=\"https:\/\/www.iso.org\/standard\/77304.html\" data-lasso-id=\"2967083\"><span style=\"font-weight: 400\">ISO 23894<\/span><\/a><span style=\"font-weight: 400\"> for A.I. risk management can help organizations establish documented governance processes and create auditable evidence trails from the outset. Other mechanisms, like <\/span><a target=\"_blank\" target=\"_blank\" rel=\"noopener\" href=\"https:\/\/standards.ieee.org\/products-programs\/\" data-lasso-id=\"2967084\"><span style=\"font-weight: 400\">IEEE<\/span> <span style=\"font-weight: 400\">standards and conformity assessment<\/span><\/a><span style=\"font-weight: 400\"> and <\/span><a target=\"_blank\" target=\"_blank\" rel=\"noopener\" href=\"https:\/\/iapp.org\/resources\/article\/ai-governance-vendor-report\" data-lasso-id=\"2967085\"><span style=\"font-weight: 400\">IAPP AI Governance Vendor Reports<\/span><\/a><span style=\"font-weight: 400\">, can further support procurement due diligence.<\/span><\/p>\n<p><span style=\"font-weight: 400\">Finally, procurement should be embedded within ongoing A.I. governance processes. When an organization purchases an A.I. system, it is making governance choices about data sovereignty, liability, regulatory compliance and long-term vendor dependency. These choices require continuous review with governance stakeholders as models evolve, regulations change and vendors update products or terms of service.<\/span><\/p>\n<p><span style=\"font-weight: 400\">Organizations should therefore integrate procurement directly into broader A.I. governance structures through recurring audits, compliance reviews, performance assessments and cross-functional oversight processes. Where possible, organizations should pursue shorter contracts and procurement cycles to avoid making long-term commitments in the face of rapidly changing technology.<\/span><\/p>\n<h3><b>A.I. governance starts at procurement<\/b><\/h3>\n<p><span style=\"font-weight: 400\">For many organizations, procurement remains one of the least mature dimensions of A.I. governance. Yet procurement decisions increasingly determine how data is managed, where accountability sits, which vendors gain influence over operations and how resilient organizations remain as A.I. systems evolve.<\/span><\/p>\n<p><span style=\"font-weight: 400\">As A.I. adoption accelerates, procurement can no longer operate as a purely commercial function. Every A.I. contract now embeds decisions about governance, risk, compliance, security and strategic dependency. It has become a governance mechanism, one that will play a defining role in whether enterprise A.I. systems are deployed responsibly, compliantly and effectively.<\/span><\/p>\n<p><em><a target=\"_blank\" target=\"_blank\" rel=\"noopener\" href=\"https:\/\/www.linkedin.com\/in\/ameliajlwilliams\/\" data-lasso-id=\"2967086\"><span style=\"font-weight: 400\">Amelia Williams<\/span><\/a><span style=\"font-weight: 400\"> is a Senior Research Impact Officer at Trilateral Research with expertise in scientific communication at the intersection of emerging technologies, environmental issues, ethics, and policy. At Trilateral, she supports the development and implementation of research projects alongside policy, media and industry engagement.<\/span><\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Trilateral Research\u2019s Amelia Williams examines a growing blind spot in enterprise A.I. adoption: procurement. As organizations rush to deploy powerful A.I. systems, procurement teams often make governance, compliance and data protection decisions without adequately managing risk. <\/p>\n <a class=\"moretag\" href=\"https:\/\/observer.com\/2026\/06\/ai-procurement-governance-compliance\/\">Read More<\/a>","protected":false},"author":177935337,"featured_media":1653325,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"apple_news_api_created_at":"","apple_news_api_id":"","apple_news_api_modified_at":"","apple_news_api_revision":"","apple_news_api_share_url":"","apple_news_cover_media_provider":"image","apple_news_coverimage":0,"apple_news_coverimage_caption":"","apple_news_cover_video_id":0,"apple_news_cover_video_url":"","apple_news_cover_embedwebvideo_url":"","apple_news_is_hidden":"","apple_news_is_paid":"","apple_news_is_preview":"","apple_news_is_sponsored":"","apple_news_maturity_rating":"","apple_news_metadata":"\"\"","apple_news_pullquote":"","apple_news_pullquote_position":"","apple_news_slug":"","apple_news_sections":[],"apple_news_suppress_video_url":false,"apple_news_use_image_component":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2},"_wpas_customize_per_network":false},"post_tag":[423982473],"company":[423975525,423975358,81,423954278,423975251],"channel":[186,12374,423875666],"location":[],"nyo_column":[423982261],"person":[],"nyo_post_hidden":[],"coauthor":[424008060],"class_list":{"0":"post-1652927","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"tag-ai-experts","8":"observer_company-anthropic","9":"observer_company-github","10":"observer_company-google","11":"observer_company-openai","12":"observer_company-palantir","13":"channel-business","14":"channel-artificial-intelligence","15":"channel-technology","16":"nyo_column-expert-insights","17":"style-expert-insights"},"acf":{"homepage_position":"","homepage_title":"","homepage_excerpt":"","alternative_og_image":"","headline":{"seo_headline":""},"subheadline":{"optimized_seo_description":"","optimized_social_excerpt":""}},"apple_news_notices":[],"parsely":{"version":"1.1.0","canonical_url":"https:\/\/observer.com\/2026\/06\/ai-procurement-governance-compliance\/","smart_links":{"inbound":0,"outbound":0},"traffic_boost_suggestions_count":0,"meta":[],"rendered":"","tracker_url":"https:\/\/cdn.parsely.com\/keys\/observer.com\/p.js"},"jetpack_publicize_connections":[],"jetpack_featured_media_url":"https:\/\/observer.com\/wp-content\/uploads\/sites\/2\/2026\/06\/alex-shuper-gXwJ8rr0R88-unsplash.png?quality=80","coauthors_byline":"By Amelia Williams","display_channel":"","thumbnail":"<img width=\"300\" height=\"225\" src=\"data:image\/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==\" data-src=\"https:\/\/observer.com\/wp-content\/uploads\/sites\/2\/2026\/06\/alex-shuper-gXwJ8rr0R88-unsplash.png?w=300&amp;h=225&amp;crop=1&amp;quality=80\" class=\"lazyload attachment-grid-thumbnail size-grid-thumbnail\" alt=\"A repeating pattern of outlines of silver heads with brains and a center head with a gold brain\" decoding=\"async\" \/><noscript><img width=\"300\" height=\"225\" src=\"https:\/\/observer.com\/wp-content\/uploads\/sites\/2\/2026\/06\/alex-shuper-gXwJ8rr0R88-unsplash.png?w=300&amp;h=225&amp;crop=1&amp;quality=80\" class=\"lazyload attachment-grid-thumbnail size-grid-thumbnail\" alt=\"A repeating pattern of outlines of silver heads with brains and a center head with a gold brain\" decoding=\"async\" \/><\/noscript>","classes":["post-1652927","post","type-post","status-publish","format-standard","has-post-thumbnail","tag-ai-experts","observer_company-anthropic","observer_company-github","observer_company-google","observer_company-openai","observer_company-palantir","channel-business","channel-artificial-intelligence","channel-technology","nyo_column-expert-insights","style-expert-insights","entry-grid"],"parent_channels":"Business","thumbnail_url":"https:\/\/observer.com\/wp-content\/uploads\/sites\/2\/2026\/06\/alex-shuper-gXwJ8rr0R88-unsplash.png?w=300&#038;h=225&#038;crop=1&#038;quality=80","thumbnail_url_2x":"https:\/\/observer.com\/wp-content\/uploads\/sites\/2\/2026\/06\/alex-shuper-gXwJ8rr0R88-unsplash.png?w=600&#038;h=450","excerpt_bare":"Trilateral Research\u2019s Amelia Williams examines a growing blind spot in enterprise A.I. adoption: procurement. As organizations rush to deploy powerful A.I. systems, procurement teams often make governance, compliance and data protection decisions without adequately managing risk. ","is_sponsored":false,"formatted_date":"Jun 8","read_time":"","jetpack_sharing_enabled":true,"amp_enabled":false,"_links":{"self":[{"href":"https:\/\/observer.com\/wp-json\/wp\/v2\/posts\/1652927","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/observer.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/observer.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/observer.com\/wp-json\/wp\/v2\/users\/177935337"}],"replies":[{"embeddable":true,"href":"https:\/\/observer.com\/wp-json\/wp\/v2\/comments?post=1652927"}],"version-history":[{"count":5,"href":"https:\/\/observer.com\/wp-json\/wp\/v2\/posts\/1652927\/revisions"}],"predecessor-version":[{"id":1653326,"href":"https:\/\/observer.com\/wp-json\/wp\/v2\/posts\/1652927\/revisions\/1653326"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/observer.com\/wp-json\/wp\/v2\/media\/1653325"}],"wp:attachment":[{"href":"https:\/\/observer.com\/wp-json\/wp\/v2\/media?parent=1652927"}],"wp:term":[{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/observer.com\/wp-json\/wp\/v2\/post_tag?post=1652927"},{"taxonomy":"observer_company","embeddable":true,"href":"https:\/\/observer.com\/wp-json\/wp\/v2\/company?post=1652927"},{"taxonomy":"channel","embeddable":true,"href":"https:\/\/observer.com\/wp-json\/wp\/v2\/channel?post=1652927"},{"taxonomy":"location","embeddable":true,"href":"https:\/\/observer.com\/wp-json\/wp\/v2\/location?post=1652927"},{"taxonomy":"nyo_column","embeddable":true,"href":"https:\/\/observer.com\/wp-json\/wp\/v2\/nyo_column?post=1652927"},{"taxonomy":"nyo_person","embeddable":true,"href":"https:\/\/observer.com\/wp-json\/wp\/v2\/person?post=1652927"},{"taxonomy":"nyo_post_hidden","embeddable":true,"href":"https:\/\/observer.com\/wp-json\/wp\/v2\/nyo_post_hidden?post=1652927"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/observer.com\/wp-json\/wp\/v2\/coauthor?post=1652927"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}