News

AI and Procurement: Your Playbook for the Next 3-6 Months

Featured image for AI and Procurement: Your Playbook for the Next 3-6 Months

AI adoption inside most private-sector businesses is running well ahead of any function's ability to govern it. Many organisations report moderate to pervasive unsanctioned "shadow AI" use among staff, only a quarter have comprehensive visibility into how AI is actually being used, and a quarter have no AI policy at all - with no single function owning more than a slice of the governance gap.

Procurement is a key business safeguard and whose job is to ask "what exactly are we buying, from whom, and on what terms.

6 ways Procurement can help the business adopt AI that delivers tangible value in the next six months

1. Stand up a combined Procurement/IT/DPO/Legal/Security task force for new AI tool requests. Shadow AI isn't a future risk — it's already the default. Replace sequential governance reviews with one joined up review and sign-off gated process to optimise time to review and action business requestConsolidate demand across the business so no needs or spend is duplicated and the business demand/commercial position is maximised..

2. Build a pre-approved AI tool shortlist with the business units who'll actually use them. Involve IT, Legal and DPO for the security and integration checks, but what gets pre-approved is what the business and it’s people actually need, not what's easiest to clear.

3. Negotiate capped-spend, time-boxed pilots A 60–90 day pilot with defined use and success metrics and a clean exit clause lets the business test real value before committing to a longer contract. IT validates the pilot's technical fit and actual usage; Procurement engages business users, owns the commercial terms and the exit / extension.

4. Run a joint IT–Procurement licence rationalisation before approving any new AI spend. Most large software estates are already carrying duplicate seats, unused modules and AI features nobody's using across CRM, ERP, HR and collaboration platforms. IT can see what's actually active in the system; Procurement can see what's being paid for and when it renews. Cancel or downsize the overlap ahead of renewal, and the savings released may actually help fund new AI investment.

5. AI-powered spend analytics Use your new AI to find savings: run AI-driven spend analysis across the business P2P, ERP and contract data, working with finance to validate the numbers, to surface maverick spend, price variance and consolidation opportunities across existing suppliers.

6. Consider if usage-based / outcome-based pricing is optimal than per-seat licensing. Model out which works best for your business and chose the best software with right fit commercial model for your need and business.

10 AI Clauses for Supplier Contracts

note – private sector specific

AI is arriving inside contracts that were never written to deal with it — a CRM renewal that quietly adds a copilot feature, a managed service provider that starts using an AI agent to triage tickets, a recruitment platform that starts screening CVs algorithmically. In most of these cases, nobody sat down and negotiated new AI-specific terms. The supplier just switched a feature on, usually via a terms-of-service update that Legal and Procurement never had sight of.

For buyers, this is a tangible commercial and compliance business risk.

None of this means Procurement needs an entirely new contract framework. It means specific gaps in existing supplier contracts need closing.

1. AI Use Disclosure. Most contracts are silent on whether AI is involved in delivery at all. Build in an obligation for the supplier to disclose, at the point of contract and on an ongoing basis, where AI — including AI added via a later feature update — is used to deliver the service, generate outputs, or make or support decisions affecting your business or your customers.

2. Restrictions on Training Data Use. Can the supplier use your data — documents, prompts, customer records, usage data — to train, fine-tune, or otherwise improve its own or a third party's model? The default position to negotiate from is opt-out at minimum.

3. Purpose Limitation and Data Minimisation. A contract ideally needs the AI's operating purpose defined specifically, with an explicit obligation on the supplier to configure the system's data access accordingly.

4. Automated Decision-Making and Human Oversight. Where AI outputs feed into decisions with a legal or otherwise significant effect on individuals — screening job candidates, scoring credit or fraud risk, prioritising customer complaints — the contract should require a defined human review step before any such decision is acted on.

5. Supply Chain and Sub-Processor Transparency. A supplier's AI feature is very rarely built entirely in-house. It usually sits on top of a third-party foundation model, accessed via API, with a data flow that a standard sub-processor list was never designed to describe. The contract needs visibility into which third-party AI models the supplier relies on, and notice and consent rights before that underlying model or provider changes.

6. Model and System Change Notification. A supplier can materially change model version or architecture with no visible change to the interface, and outputs can shift as a result. Require a minimum notice period (30 days is a reasonable norm) before any material model change, with a right to test or reject the new version before it touches live use.

7. Accuracy, Hallucination Risk and Verification Responsibility. Suppliers will disclaim that AI outputs may contain errors. The contract should allocate responsibility clearly: which category of output requires human verification before reliance, and who carries the cost when an inaccurate output has already been acted on downstream before anyone caught it.

8. AI Incident and Security Notification. Build in a short, specific notification window (72 hours is a common benchmark) for any material AI malfunction or security incident.

9. Output Ownership and IP Indemnity. Get explicit assignment of AI-generated outputs to your business on creation, and pair it with an indemnity that covers third-party IP infringement claims arising from AI-generated outputs specifically.

10. Liability Caps, Audit Rights and Exit Provisions. Don't let AI-specific risk get absorbed silently into the general liability cap. Negotiate distinct treatment for AI-related liability, a right to request evidence of testing or bias assessment on demand, and exit terms covering what happens to any model fine-tuned on your data once the contract ends.

Five things procurement should do now to bring existing contracts up to date

Most of the risks listed so far are not sitting in the next RFP — it's sitting in contracts already signed. Here's where to start.

1. Run a supplier-base sweep. Cross-reference your active supplier list against every vendor that has publicly announced an AI or copilot feature in the last 12–18 months. That list — not your renewal calendar — is where undisclosed AI use is most likely already live inside a contract.

2. Triage by data sensitivity and contract value. Score each contract on the data it exposes (personal, customer, commercially sensitive) against contract value and renewal proximity, and work the top quadrant first — typically core SaaS platforms handling customer or employee data, not low-spend tail-spend tools.

3. Use a side-letter or variation. For contracts with time left to run, a short-form variation covering training data restrictions, disclosure obligations, and incident notification can be agreed far faster than a full contract rewrite — and closes the most material risk without waiting a year or more for the natural renewal point.

4. Update your DPIAs and sub-processor registers. Most data protection impact assessments and sub-processor logs were built for traditional data flows. They need a specific pass for AI: which suppliers now use AI in delivery, which third-party models sit behind them, and whether the original DPIA's risk assessment still holds once an AI feature has been switched on.

5. Build a standard AI clause playbook into contract sign-off. Rather than negotiating AI clauses from scratch every time, agree fallback and preferred wording once with legal, and make a documented pass against that playbook a mandatory gate before any new contract, renewal, or material supplier feature change is signed off.

Five key areas a PE firm should consider for its portfolio companies

A PE firm holding a portfolio has a different challenge: the same AI adoption and contract risk is playing out simultaneously across ten, twenty, or fifty management teams, each solving it alone unless the firm intervenes. That repetition is exactly where a fund can compound value.

1. Standardise AI governance and contract due diligence once, at fund level — not bespoke per portco. Build a single assessment template, contract checklist and governance policy centrally, and apply it consistently at acquisition, in the first 100 days of every new deal, and at each portfolio review, rather than leaving each management team to invent (or skip) its own version.

2. Make the AI-specific contract review a mandatory first-100-days workstream in every portfolio company. Inherited supplier contracts are exactly where undisclosed AI use, training data exposure, and missing audit rights sit — often in businesses acquired before AI was part of anyone's due diligence checklist. Applying standard process to every new acquisition, systematically, catches this before it becomes the fund's problem rather than the seller's.

3. Treat AI adoption and buying leverage as a portfolio-wide procurement lever, not a management-team-by-management-team initiative. The same logic that can apply well to tail spend applies to AI subscriptions and licensing: aggregate demand across portfolio companies, negotiate vendor terms once at scale, and share a single vetted-vendor shortlist and licence-rationalisation playbook — rather than each portco separately discovering the same shelfware problem and re-running the same negotiation.

4. Track vendor concentration as a portfolio-level risk, not just a single-company one. If several portfolio companies independently converge on the same handful of frontier AI vendors, that's a counterparty concentration risk sitting at fund level rather than company level — a single vendor's price change, outage, or policy shift can hit multiple portfolio companies' operations at once. This is only visible if someone is looking across the portfolio, not within it.

5. Build exit readiness into the AI governance programme from day one, not at the point of sale. A portfolio company that can show a clean, documented governance record and a consistent contract standard protects its valuation and moves faster through a future sale process, rather than absorbing a late-stage price chip when a buyer's diligence team finds the gaps the fund didn't.


7 Step Solutions works with all sized brands as their external procurement support - whether a managed service, rapid project solution or augmented resource into their team, we bring deep experience and outcome focused solutions across your commercial and procurement needs.

Drop Director jamesball@7stepsolutions.co.uk a message to discuss your specific needs.