Strategic Procurement, Optionality and Governance in the Age of Agentic AI
In the age of AI, competitive advantage will belong not to organisations that simply buy the best technology, but to those that can manage AI vendors strategically—balancing flexibility, value, autonomy, bargaining power and governance in a rapidly changing market.de l'article de blog :
Sanchez P.
8/21/202648 min read


Abstract
The rapid diffusion of generative and agentic artificial intelligence (AI) is fundamentally changing how organisations acquire, deploy and govern technology. Organisational adoption has reached unprecedented levels: 88 per cent of surveyed organisations reported using AI in at least one business function in 2025, while 79 per cent reported regular use of generative AI. At the same time, enterprise-wide scaling and measurable financial impact remain considerably less widespread, indicating a persistent gap between AI adoption and realised organisational value (Stanford HAI, 2026; Singla et al., 2025). This combination of rapid technological progress, uncertain value realisation and increasing dependence on external providers creates a new strategic challenge for organisations: how to manage AI vendors when the technologies, commercial models and competitive landscape are themselves changing rapidly.
Drawing on the third-quarter 2026 Gartner Business Quarterly, How to Work With AI Vendors, and recent academic, industry and institutional literature, this paper examines how organisations should redesign AI-vendor management. Gartner identifies five priorities: maintaining optionality in generative-AI vendor relationships, controlling AI expenditure, determining when to deploy AI agents, exploiting increased buyer leverage in a disrupted software market, and treating AI-vendor governance as a source of competitive advantage (Gartner, 2026). The paper develops these themes into an integrated strategic framework comprising optionality, economic discipline, appropriate autonomy, buyer leverage and continuous governance.
The analysis argues that AI challenges the assumptions underlying conventional software procurement. AI capabilities are increasingly delivered through interconnected ecosystems involving foundation-model providers, cloud infrastructure, data services, application vendors and other third parties. Vendor dependency is consequently not merely a question of supplier performance but a broader issue of technological, economic, contractual and organisational dependency. Maintaining optionality therefore becomes a strategic form of resilience, while economic discipline requires organisations to distinguish AI activity and adoption from measurable business value. Similarly, the growing availability of agentic AI requires autonomy to be treated as a deliberate economic and governance decision rather than as an inevitable consequence of technological capability.
The paper further argues that the current disruption of the software market creates a potentially temporary opportunity for buyers to negotiate greater control through interoperability, data portability, transparency, auditability, pricing protections and meaningful exit rights. However, contractual protections alone are insufficient. Effective AI-vendor management requires continuous governance spanning use-case assessment, vendor due diligence, model evaluation, contractual controls, deployment oversight, performance monitoring and exit readiness. This is particularly important as AI capabilities evolve rapidly and responsible-AI governance remains uneven. The 2026 AI Index reports both accelerating adoption and continuing gaps in transparency, governance capacity and measurement.
The paper concludes that organisations should no longer treat AI vendors as conventional software suppliers. Instead, AI-vendor management should be understood as a strategic organisational capability for managing technological dependency and preserving flexibility under uncertainty. Competitive advantage is likely to accrue not simply to organisations that adopt the most advanced AI technologies, but to those capable of evaluating, negotiating, governing, measuring and, when necessary, replacing AI capabilities faster and more effectively than their competitors.
Keywords: artificial intelligence; generative AI; agentic AI; AI vendors; technology procurement; vendor governance; strategic optionality; AI risk management; digital transformation; technology strategy
1. Introduction
Artificial intelligence (AI) has rapidly evolved from an emerging technology into a strategic organisational capability. By 2025, 88 per cent of respondents to McKinsey’s global survey reported that their organisations were regularly using AI in at least one business function, while 79 per cent reported regular use of generative AI (Singla et al., 2025). Yet adoption has not translated proportionately into enterprise-wide impact. The limited extent to which organisations have successfully scaled AI suggests a persistent gap between experimentation, adoption and the realisation of measurable business value. The AI Index Report 2026 similarly documents continued growth in organisational AI adoption while emphasising that adoption metrics should not be conflated with demonstrable economic or organisational impact (Stanford HAI, 2026).
This gap is becoming strategically consequential. Organisations are increasingly dependent on external AI vendors at the same time as the underlying technologies, commercial models and competitive landscape are evolving at exceptional speed. Unlike conventional enterprise software, AI services are not necessarily stable products with predictable release cycles. Foundation models can be replaced or materially upgraded; pricing can shift from licences towards usage-based or outcome-based models; performance can vary across use cases; and new capabilities can rapidly alter the relative attractiveness of competing providers. As a result, vendor selection is no longer a one-off procurement decision but an ongoing strategic decision about technological dependency, organisational flexibility and control.
The third-quarter 2026 Gartner Business Quarterly, How to Work With AI Vendors, brings this challenge directly into the executive domain. It identifies five priorities for organisations working with AI vendors: building optionality into generative-AI vendor relationships; controlling AI expenditure; determining when AI agents should be deployed; exploiting increased buyer leverage arising from disruption in the software market; and treating AI-vendor governance as a potential source of competitive advantage (Gartner, 2026). These priorities collectively signal a fundamental shift in the logic of technology procurement: the objective is no longer simply to identify and acquire the “best” AI product, but to design and manage a resilient portfolio of AI relationships that can adapt as technology, economics and risks evolve.
This shift raises a central strategic question:
How should organisations redesign AI-vendor management to capture the value of AI while preserving strategic flexibility, economic discipline and effective governance?
This paper argues that AI-vendor management should be elevated from a primarily transactional procurement activity to a strategic organisational capability. It conceptualises this capability around five mutually reinforcing dimensions: optionality, which reduces dependency and preserves the ability to switch; economic discipline, which links AI expenditure to measurable value; appropriate autonomy, which determines when and where agentic AI should be permitted to act; buyer leverage, which enables organisations to negotiate meaningful commercial and technological control; and continuous governance, which ensures that AI risks and vendor relationships remain manageable as both technology and regulatory expectations evolve.
2. From software procurement to AI capability management
Traditional enterprise technology procurement is largely built around a relatively stable transaction: the organisation defines its requirements, evaluates competing suppliers, selects a solution and manages the resulting relationship through contractual obligations and service-level agreements. Although conventional technology procurement has always involved uncertainty, the capability being acquired is typically sufficiently well defined to allow buyers to assess functionality, cost, performance and risk at the point of purchase.
An AI-enabled application is rarely an isolated product. Its capabilities may depend on a foundation model provided by one organisation, cloud infrastructure supplied by another, external data sources, application programming interfaces (APIs), security and safety mechanisms, and other third-party services. Changes anywhere within this technology stack can alter the performance, cost, availability or risk profile of the capability ultimately consumed by the customer. The NIST Generative AI Profile explicitly recognises this broader lifecycle, including the acquisition and use of third-party and cloud-based AI services, as an important dimension of generative-AI risk management (Autio et al., 2024).
The resulting challenge extends beyond conventional vendor risk. It is fundamentally a problem of dependency risk: the possibility that an organisation becomes structurally dependent on technologies, providers, data architectures or commercial arrangements that it cannot readily control or replace.
This distinction matters because AI dependencies are both deeper and more dynamic than many traditional software dependencies. A vendor may change the underlying model without changing the application interface; pricing may shift as inference economics evolve; model updates may alter outputs or performance; and the emergence of superior alternatives may make an existing technology strategically less attractive. Consequently, the organisation is not simply procuring a static technological asset. It is entering an evolving ecosystem of interdependent capabilities.
Janssen (2025) conceptualises generative AI as a complex adaptive socio-technical system in which people, organisational processes, data, AI technologies, policies and external actors continuously interact. This perspective has important implications for vendor management. AI governance cannot be confined to the technical system or delegated solely to the vendor. Instead, accountability and risk management must extend across the organisational and supplier ecosystem.
Emerging research on AI procurement reinforces this argument. Sanchez-Graells (2026) positions procurement as an important mechanism through which organisations can operationalise AI governance, using contractual, technical, standards-based and regulatory instruments to shape how AI is acquired and deployed. Procurement therefore becomes more than a commercial function: it becomes an important governance mechanism for managing technological dependency.
The strategic question consequently shifts from:
“Which AI product should we buy?”
to:
“How should we structure and govern our portfolio of AI dependencies so that the organisation retains sufficient control, flexibility and value as the technology evolves?”
This represents a fundamental change in the role of procurement. Rather than optimising individual purchasing decisions, organisations need to manage AI capabilities as dynamic, interconnected and potentially substitutable assets. The emphasis therefore moves from product selection towards architectural flexibility, contractual control, interoperability, portability and the ability to adapt as vendors and technologies change.
This is the conceptual foundation for the first of Gartner’s priorities: optionality. In an AI market characterised by rapid technological change and uncertain vendor trajectories, maintaining the ability to switch, combine or renegotiate AI providers becomes not merely a procurement preference, but a strategic capability.
3. Strategic optionality in AI-vendor relationships
Gartner’s first publicly identified recommendation is to build optionality into generative-AI vendor relationships (Gartner, 2026). In the context of AI, optionality refers to an organisation’s ability to switch, substitute, combine or renegotiate technology providers without incurring disproportionate cost, disruption or loss of capability. It is therefore not synonymous with maintaining multiple vendors; rather, it concerns preserving the strategic freedom to make alternative choices when circumstances change.
This distinction is increasingly important as the AI market remains highly dynamic. Foundation models that appear strategically dominant at one point may subsequently face competition from lower-cost models, open-weight alternatives or specialised systems. At the application layer, vendors may also change the foundation models underlying their products, potentially altering performance, cost, security or compliance characteristics without fundamentally changing the customer-facing interface. The result is an unusual degree of uncertainty about the durability of today's technology choices.
Excessive dependence on a single AI provider can therefore create several forms of vendor lock-in:
Technical lock-in – dependence on proprietary APIs, architectures, tools or data formats that make migration technically difficult.
Economic lock-in – exposure to switching costs, escalating usage-based charges or pricing structures that make alternatives economically unattractive.
Data lock-in – difficulty exporting prompts, embeddings, workflows, evaluation data, configurations or other organisational assets.
Capability lock-in – business processes become so closely integrated with a particular vendor or model that changing providers would materially disrupt operations.
Knowledge lock-in – employees develop expertise around one vendor’s technology, reducing the organisation’s ability to operate alternative solutions effectively.
Contractual lock-in – restrictive termination provisions, limited data-export rights, inadequate transition support or long contractual commitments constrain the buyer’s ability to exit.
These forms of dependency are particularly significant for AI because technological change can occur faster than the contractual and organisational mechanisms designed to manage it. A vendor that is strategically attractive today may become less competitive tomorrow, while the cost of migrating away from it may increase as the organisation embeds the technology more deeply into its processes.
However, the strategic response should not be to pursue a multi-vendor architecture indiscriminately. Operating multiple AI providers can generate its own costs, including duplicated infrastructure, integration complexity, inconsistent user experiences, fragmented security controls and greater governance overhead. In some circumstances, concentration with a highly capable and reliable provider may therefore be economically rational.
The strategic objective is consequently not maximum diversification, but selective optionality.
Organisations should assess AI dependencies according to factors such as business criticality, switching cost, substitutability, data portability, vendor concentration, regulatory exposure and the consequences of vendor failure or performance deterioration. Mission-critical AI capabilities should generally receive the strongest optionality safeguards, including credible alternative suppliers, documented migration procedures, portable data and appropriately structured contractual exit provisions. Conversely, for low-risk or non-critical applications, accepting greater vendor concentration may be justified where the benefits of standardisation outweigh the costs of maintaining alternatives.
This approach implies that optionality should be treated as a strategic resource whose level should be calibrated to the consequences of dependency.
Optionality should be concentrated where vendor failure, price increases, technological deterioration or strategic misalignment could materially affect organisational objectives.
Seen in this way, optionality becomes more than a procurement technique. It is a form of strategic resilience. By preserving the ability to change direction, organisations can reduce their exposure to vendor-specific shocks while retaining the freedom to benefit from advances elsewhere in the rapidly evolving AI ecosystem. This makes optionality a central component of effective AI-vendor strategy rather than simply an insurance mechanism against vendor failure.
4. Controlling AI spending: from experimentation to economic discipline
Gartner’s second priority is the need to control AI expenditure (Gartner, 2026). This recommendation reflects a fundamental challenge in the economics of enterprise AI: organisations can now deploy AI at considerable scale, but the cost structures associated with doing so are often less predictable than those of conventional enterprise software.
Traditional software-as-a-service (SaaS) procurement typically relies on relatively transparent and predictable licensing models, such as per-user or per-seat fees. Generative AI introduces a more complex economic structure. Costs may arise from token consumption, model inference, retrieval-augmented generation, storage, data processing, model routing, fine-tuning, API calls and, increasingly, autonomous agent execution. As AI becomes embedded across business processes, these variable costs can become both material and difficult to forecast.
The challenge is not simply that AI can be expensive. More fundamentally, high levels of AI adoption do not necessarily translate into equivalent levels of business value. McKinsey’s 2025 global survey found that 88 per cent of organisations reported regular AI use in at least one business function, yet only around one-third had begun scaling AI programmes across the enterprise. Moreover, just 39 per cent reported an enterprise-level EBIT impact from AI (Singla et al., 2025). This suggests a persistent gap between adoption, deployment and economic impact.
Consequently, organisations need to distinguish explicitly between AI activity and AI value.
A conventional technology-management approach may emphasise activity-based indicators such as:
the number of employees using AI;
the number of AI applications deployed;
the volume of prompts or API calls;
model utilisation;
the number of automated tasks.
Although these measures provide useful information about adoption and usage, they say relatively little about whether AI is generating economic value. A more strategically relevant measurement framework should instead focus on outcomes such as:
incremental revenue;
operating-cost reduction;
productivity gains;
shorter process cycle times;
improvements in output quality;
reductions in error rates;
improved customer outcomes;
reduced operational or compliance risk.
This distinction is critical because usage is not synonymous with value creation. An AI system can be heavily used while simultaneously generating limited or even negative economic value if its costs, implementation requirements, errors and downstream consequences exceed the benefits it produces.
The implications extend directly into vendor management. Organisations should increasingly evaluate AI suppliers not only on technical capability and unit price, but also on their contribution to measurable business outcomes. Depending on the use case, commercial arrangements may therefore incorporate usage thresholds, performance reviews, service-level commitments, price protections, benchmarking mechanisms and clearly defined termination or renegotiation rights.
This does not mean that every AI contract should become an outcome-based contract. Outcomes may be difficult to attribute where AI contributes indirectly to a broader business process, and excessive contractual complexity can itself increase transaction costs. Rather, organisations should match the commercial model to the measurability, materiality and strategic importance of the AI capability.
Economic discipline also requires organisations to consider the total cost of ownership (TCO) rather than the headline price of an AI service. TCO may include integration, data preparation, security controls, employee training, monitoring, governance, human review, model evaluation and migration costs. These indirect costs can materially alter the economics of an AI deployment.
The strategic objective, therefore, should not be to minimise AI expenditure in isolation. Excessive cost reduction may prevent organisations from investing in strategically valuable capabilities, while uncontrolled experimentation can result in fragmented technology portfolios and escalating consumption costs. The appropriate objective is to maximise risk-adjusted value: the economic benefit generated by AI relative to its direct and indirect costs, implementation risks and strategic dependencies.
The key question is not how much AI an organisation is using, but whether each significant AI investment creates sufficient measurable value to justify its economic and strategic cost.
This shift—from monitoring AI consumption to managing AI value—represents a critical step in moving enterprise AI from experimentation towards disciplined, sustainable adoption.
5. When should organisations use AI agents?
Gartner’s third priority concerns knowing when to use AI agents (Gartner, 2026). This question is becoming increasingly important as organisations move beyond generative-AI assistants towards systems capable of planning, executing multi-step tasks, interacting with external tools and systems, and operating with varying degrees of autonomy. Unlike conventional AI assistants, which primarily generate content in response to human instructions, agentic systems can initiate and coordinate actions in pursuit of defined objectives. This shift substantially increases both their potential organisational value and their risk profile.
Recent research identifies agentic AI as an important development in enterprise information systems, while highlighting significant challenges relating to trust, security, transparency, accountability and integration with existing organisational and technological infrastructures (Holldack, 2025). The scale of experimentation also suggests that this is moving rapidly from a theoretical possibility to a practical management issue. McKinsey’s 2025 global survey found that 62 per cent of respondents reported that their organisations were at least experimenting with AI agents, while 23 per cent reported scaling an agentic AI system somewhere within the enterprise (Singla et al., 2025).
However, the existence of a technical capability does not, in itself, establish a compelling business case for deploying it. The ability to automate a process should not be confused with the justification for doing so. Agentic AI introduces additional risks because autonomous systems can select actions, interact with external tools and systems, and pursue objectives with less continuous human intervention. Recent research therefore emphasises the importance of maintaining meaningful human control and designing autonomy according to the characteristics and risks of the specific use case (Holldack, Banh and Strobel, 2026; Nguyen et al., 2026; Zhu et al., 2026). Greater autonomy can generate productivity benefits, but it can also increase the likelihood of unintended actions, amplify errors and make failures more difficult to detect or reverse (Perez-Cruz and Shin, 2025; Nguyen et al., 2026). The decision to deploy an agent should therefore be based on a systematic assessment of both business value and risk, rather than on technical feasibility alone.
A particularly useful starting point is task complexity. Agents are potentially most valuable where work involves multiple sequential steps, information retrieval, reasoning, decision-making, coordination across systems or interaction with digital tools. The World Economic Forum similarly proposes evaluating agents according to factors including their function, role, predictability, autonomy, authority, use case and operating environment, highlighting the importance of understanding the context in which an agent operates rather than evaluating autonomy as an isolated technical characteristic (World Economic Forum, 2025). Research by Perez-Cruz and Shin (2025) provides a useful qualification: although AI agents can perform well on narrowly defined tasks, they can struggle with more general tasks requiring adaptation, self-assessment, error recognition and correction. This suggests that the business case for agentic AI is likely to be strongest where the workflow is sufficiently structured for the agent's capabilities to generate measurable incremental value, while remaining sufficiently complex that conventional automation or simple AI assistance would be inadequate.
The second consideration is the cost of failure. Not all decisions carry equivalent consequences, and autonomy should therefore be calibrated to the potential impact of an erroneous action. An agent that summarises internal documents or proposes meeting times operates within a fundamentally different risk environment from an agent that executes financial transactions, makes employment recommendations, processes sensitive personal information or controls safety-critical processes. The U.S. Government Accountability Office (GAO, 2025) highlights the potential for AI agents to misinterpret objectives and produce unintended consequences, particularly as agents become capable of acting autonomously across organisational systems. Gartner similarly identifies autonomy, system complexity and limited oversight as sources of new legal and compliance risks associated with AI agents (Gartner, 2025). As the potential consequences of failure increase, the justification for unrestricted autonomy correspondingly decreases.
A third consideration is reversibility. Organisations should distinguish between actions that can readily be undone and those that create persistent or irreversible consequences. This distinction is particularly important for agentic systems because autonomous actions can extend beyond generating information to modifying systems, communicating externally or initiating transactions. IBM's recent research identifies non-reversibility as one of four characteristics that can increase the risk associated with autonomous AI agents, alongside opaqueness, open-endedness and complexity (IBM, 2025). An agent drafting an email, for example, produces an output that can normally be reviewed and amended before execution. By contrast, transferring funds, deleting data, modifying a production environment or communicating a legally consequential decision may be difficult or impossible to reverse. The greater the irreversibility of an action, therefore, the stronger the case for explicit human approval, constrained permissions and additional safeguards.
The fourth consideration is human oversight. Human involvement should not be treated as a binary choice between complete human control and complete machine autonomy. Instead, oversight should be designed according to the risk, complexity and consequences of the task. Recent research on meaningful human oversight argues that simply placing a human somewhere in the process is insufficient: effective oversight requires humans to have a meaningful opportunity to understand, intervene in and, where necessary, override AI-driven actions (Zhu et al., 2026). Similarly, research on controllability in agentic AI emphasises that maintaining meaningful human control becomes increasingly challenging as systems acquire greater autonomy and pursue more complex goals with limited human intervention (Nguyen et al., 2026).
This supports a graduated approach to autonomy and oversight. At the lowest level, AI may provide recommendations while a human retains responsibility for the final decision. At the next level, an AI system may prepare an action that requires explicit human approval before execution. More mature applications may allow agents to execute routine workflows under continuous monitoring, with human intervention triggered by predefined exceptions or risk thresholds. Conditional autonomy may therefore be appropriate for low-risk operational processes where permissions are constrained, actions are auditable and rollback mechanisms are available. By contrast, high-impact or difficult-to-reverse actions should generally require stronger human involvement and more restrictive system permissions. Recent practitioner research from PwC similarly recommends task-specific permissions, auditable activity records and increasing human oversight as agent autonomy and potential consequences increase (PwC, 2026).
This suggests that autonomy should be treated as a variable to be deliberately designed rather than a capability to be maximised. The World Economic Forum explicitly distinguishes autonomy from conventional automation, arguing that autonomy involves decision-making flexibility and should be treated as a design choice determined by the agent's function, authority, risk environment and oversight requirements (World Economic Forum, 2025). The appropriate managerial question is therefore not whether an agent can perform a particular task, but whether granting it additional decision-making authority creates sufficient incremental value to justify the associated operational, financial, legal and governance risks.
This principle is particularly important because agentic AI changes the distribution of responsibility within organisations. When an AI system can independently determine a sequence of actions and execute them across organisational systems, accountability becomes more complex. Kumar, Wei and Zhang (2026) argue that agentic AI creates structural tensions around governance, labour, transparency and equity because autonomous systems increasingly interact with organisational roles, decision processes and institutional structures. The introduction of agents therefore cannot be considered solely a technology implementation decision; it is also a question of organisational design.
The implications for AI-vendor management are significant. Organisations purchasing agentic capabilities need to understand not only what the system can generate, but what it can do, what systems it can access, what permissions it possesses, how its actions are monitored, and who remains accountable for the resulting outcomes. Vendor evaluation should consequently include assessment of permissioning mechanisms, auditability, human-override capabilities, logging, incident management and the ability to constrain or terminate autonomous actions.
The strategic objective should therefore be appropriate autonomy rather than maximum autonomy. Organisations that deploy agents selectively—where task complexity, economic value, reversibility and risk justify greater independence—are more likely to capture the productivity benefits of agentic AI without unnecessarily expanding their exposure to operational and governance failures.
The key managerial question is not “Can this task be performed by an agent?” but “Does the additional autonomy create sufficient value to justify the additional risk?”
This principle connects directly to Gartner’s broader argument: effective AI-vendor management requires organisations to exercise strategic judgement not only over which technologies they acquire, but also over how much autonomy they are prepared to delegate to them.
6. Buyer leverage in a disrupted SaaS market
Gartner’s fourth priority highlights a potentially significant but time-sensitive opportunity: organisations should exploit the increased buyer leverage created by disruption in the software market (Gartner, 2026). This recommendation is particularly relevant to AI because the competitive structure of the technology market is evolving rapidly, creating conditions in which traditional assumptions about vendor power and customer dependency may no longer hold to the same extent.
Enterprise technology procurement has historically been characterised by strong vendor positions arising from differentiated products, proprietary technologies, network effects, switching costs and information asymmetries. Once a technology becomes deeply embedded within an organisation, the practical cost of changing providers can become sufficiently high that the vendor acquires considerable negotiating power. AI has the potential to disrupt this equilibrium. The rapid emergence of competing foundation models, open-weight alternatives, specialised AI providers and increasingly interoperable tools creates a more fluid competitive environment in which buyers may have greater opportunities to challenge established commercial arrangements.
This opportunity, however, should not be interpreted simply as an invitation to negotiate lower prices. The more strategically significant objective is to use the current period of technological disruption to secure greater control over the future relationship.
AI procurement agreements should therefore address issues such as interoperability, data portability, pricing protections, service-level commitments, audit rights, security requirements, notification of material model changes, transparency regarding subcontractors and other third parties, termination rights, transition assistance and appropriate benchmarking mechanisms. These provisions can reduce the organisation’s exposure to future changes in vendor strategy, pricing, technology or performance.
The importance of contractual design is reinforced by emerging legal research. Lifshitz (2026) argues that conventional procurement contracts may be insufficient to address the uncertainty associated with AI and identifies intellectual property, data governance, privacy, liability and regulatory compliance as areas requiring more specific contractual treatment. The implication is that AI contracts should not merely document the purchase of an existing capability; they should anticipate how that capability and the surrounding vendor relationship may change over time.
This is particularly important because AI systems are not necessarily static products. A vendor may introduce a new foundation model, modify model behaviour, change pricing, alter its data practices, discontinue a service or introduce new subcontractors. From the customer's perspective, such changes can materially affect the value and risk profile of the contracted service. Contractual mechanisms that provide advance notification, transparency and appropriate customer remedies can therefore convert some forms of technological uncertainty into manageable commercial risk.
For example, a customer could require advance notification of material changes to the underlying model or AI service, together with sufficient information to assess whether the change could affect performance, security, compliance or cost. Similarly, contractual data-export rights could ensure that organisational data, configurations and other relevant assets can be retrieved in a usable format if the relationship terminates. Transition assistance could further reduce the operational disruption associated with migration to an alternative provider.
The strategic significance of these provisions lies in their ability to preserve future choice. A contract that offers a low initial price but creates substantial switching barriers may ultimately be less valuable than a somewhat more expensive arrangement that provides strong portability, transparency and exit rights.
Buyer leverage should therefore be understood as the ability to negotiate control rights, not merely commercial concessions. Price reductions may generate immediate savings, but rights concerning data, interoperability, transparency, model changes and termination can protect the organisation's strategic position over a much longer period.
This is particularly important in the current AI market because bargaining conditions are unlikely to remain static. As particular vendors strengthen their market positions, consolidate ecosystems or establish deeper organisational dependencies, buyer leverage may diminish. Organisations therefore have an incentive to use periods of heightened competition to establish contractual protections before dependency becomes entrenched.
The resulting principle is clear:
The strategic value of buyer leverage lies not primarily in securing a better price today, but in securing the rights and flexibility needed to retain control tomorrow.
In this sense, AI procurement becomes an exercise in strategic risk allocation. Well-designed contracts cannot eliminate technological uncertainty, but they can determine who bears its consequences, who receives information about emerging risks, and what options remain available when circumstances change. This makes contractual design a central component of AI-vendor strategy rather than a legal formality at the end of the procurement process.
7. AI-vendor governance as competitive advantage
Gartner’s fifth priority may be the most strategically consequential: AI-vendor governance should be treated as a source of competitive advantage rather than merely a compliance obligation (Gartner, 2026). This represents an important shift in perspective. Governance is often characterised as a constraint on innovation—a set of approval processes, controls and documentation requirements that organisations must satisfy before new technologies can be deployed. In the context of AI, however, the absence of effective governance can create greater constraints by increasing uncertainty, slowing decision-making and exposing organisations to risks that are difficult to identify or manage after deployment.
Effective governance can instead accelerate responsible innovation. By establishing clear criteria for evaluating AI use cases, vendors and risks, organisations can reduce the need to make every AI decision from first principles. Employees and business units can experiment within defined boundaries, while higher-risk applications are subject to proportionately stronger scrutiny. Governance therefore becomes an organisational infrastructure that enables faster decision-making while maintaining appropriate control.
This is particularly important because AI systems and their associated risks are not static. Janssen (2025) conceptualises generative AI as a complex adaptive socio-technical system and argues that responsible AI governance must extend across the organisation and evolve alongside the technologies being governed. A governance framework that is appropriate when an AI system is initially procured may become inadequate as the underlying model changes, new capabilities are introduced, the system gains access to additional organisational data or its role within business processes expands.
The NIST AI Risk Management Framework (AI RMF) provides a useful foundation for this lifecycle-oriented approach. Rather than treating AI risk as a one-time assessment, the framework structures risk management around the continuous functions of governing, mapping, measuring and managing AI risks. Its Generative AI Profile further identifies risks and corresponding considerations specific to generative-AI systems (NIST, 2024). This supports the proposition that AI-vendor governance should begin before procurement and continue throughout the entire lifecycle of the relationship.
A robust governance model should therefore begin with use-case assessment. Before selecting a vendor, the organisation should establish the business problem the AI capability is intended to address, the expected benefits and the potential consequences of failure. The use case should then be classified according to factors such as data sensitivity, operational criticality, regulatory exposure, degree of automation and potential impact on individuals or stakeholders. This ensures that governance requirements are proportionate to the actual risk.
The next stage is vendor due diligence. Organisations should evaluate not only technical performance but also the vendor’s security architecture, financial stability, data practices, governance arrangements, subcontractor dependencies and ability to meet relevant regulatory and organisational requirements (NIST, 2024; OECD, 2025). The NIST AI RMF and its Generative AI Profile emphasise the importance of identifying and managing risks across the AI lifecycle, including risks associated with third-party and cloud-based AI services (NIST, 2024). Similarly, OECD work on AI procurement highlights the importance of embedding governance considerations into procurement processes rather than treating responsible AI as a separate activity after vendor selection (OECD, 2025). Vendor selection should consequently consider the provider’s capacity to manage AI-related risk over time, rather than focusing exclusively on current product functionality (Janssen, 2025; NIST, 2024).
This should be followed by model and system assessment. Buyers need to understand the performance characteristics and limitations of the relevant AI capability, including how it is evaluated, how errors are identified, how model updates are managed and whether changes to the underlying technology can materially affect the organisation (NIST, 2024; Holldack, Banh and Strobel, 2026). This is particularly important because AI systems are not static technologies: changes to models, system configurations or underlying providers can alter system behaviour and risk profiles. For generative and agentic systems, assessment should therefore also consider issues such as hallucination, security, prompt injection, inappropriate outputs, autonomy and access to organisational systems (NIST, 2024; Nguyen et al., 2026; Holldack, Banh and Strobel, 2026). The need for such assessment is reinforced by evidence that AI systems continue to exhibit significant variation in performance, reliability and responsible-AI characteristics (Stanford HAI, 2026).
These requirements should then be translated into contractual controls. Procurement and legal arrangements should establish appropriate provisions governing data ownership and use, confidentiality, security, liability, auditability, material system changes, incident notification, regulatory cooperation and termination (Sanchez-Graells, 2026; Lifshitz, 2026). The contractual framework should also reflect the organisation’s requirements for interoperability, data portability and exit, particularly where the AI capability is strategically or operationally critical. Such provisions are important because contractual mechanisms can translate otherwise abstract governance principles into enforceable obligations between buyers and vendors (Sanchez-Graells, 2026). They can also help preserve strategic optionality by reducing the costs and risks associated with changing suppliers (Gartner, 2026).
Once the system is deployed, governance must continue through operational controls. These may include access management, human oversight, activity logging, performance monitoring, incident-response procedures and restrictions on how AI systems can interact with other organisational systems (NIST, 2024; Janssen, 2025). For agentic AI in particular, permissions should be carefully aligned with the risk associated with the actions an agent is authorised to perform. Research on agentic information systems and AI controllability suggests that increasing system autonomy creates corresponding challenges concerning human control, accountability and the delegation of decision-making authority (Holldack, Banh and Strobel, 2026; Nguyen et al., 2026). Effective governance should therefore ensure that the autonomy granted to an AI system remains proportionate to the consequences of its actions.
The organisation should then establish continuous monitoring. This is essential because the risk profile of an AI vendor can change after procurement as models, pricing, data practices, security arrangements and service capabilities evolve (NIST, 2024; Janssen, 2025). Organisations should therefore monitor model performance, pricing, vendor financial and strategic developments, security incidents, changes in data practices, regulatory developments and material changes to the underlying AI service. Continuous monitoring should also evaluate whether the AI capability continues to generate sufficient business value to justify its cost and risk, thereby connecting governance with the economic discipline discussed earlier in this paper (Gartner, 2026; Singla et al., 2025).
Finally, effective governance requires exit readiness. An organisation should understand how it would discontinue, replace or migrate an AI capability if the vendor became commercially unattractive, technologically obsolete, non-compliant or strategically misaligned. Exit planning is therefore closely connected to the principle of optionality identified by Gartner (2026). Data portability, interoperability, documented dependencies and transition assistance can reduce switching costs and prevent an AI capability from becoming an uncontrolled source of vendor lock-in. Exit readiness should consequently not be interpreted as an indication that the organisation expects the relationship to fail; rather, it is a mechanism for preserving strategic flexibility and reducing dependency (Gartner, 2026; Sanchez-Graells, 2026).
Emerging research on AI procurement supports this lifecycle perspective. Johnson et al. (2026), examining AI procurement in US state governments, finds that the effectiveness of AI policy depends in part on translating high-level principles into concrete procurement specifications, evaluation criteria, contractual provisions and monitoring mechanisms. This demonstrates the importance of connecting governance principles with the practical mechanisms through which organisations select and manage technology suppliers. The finding is consistent with the broader lifecycle orientation of the NIST AI RMF, which treats AI risk management as an ongoing organisational process rather than a one-time assessment (NIST, 2024).
Taken together, these elements suggest that AI-vendor governance should be understood as a continuous management capability rather than a one-time compliance exercise. Governance begins with use-case and vendor assessment, continues through model evaluation and contracting, and extends into deployment, monitoring and eventual exit (NIST, 2024; OECD, 2025). The strongest organisations will not necessarily be those with the most restrictive governance frameworks, but those capable of applying the right level of governance at the right point in the AI lifecycle (Janssen, 2025; NIST, 2024).
This creates a potentially important source of competitive advantage. Organisations with mature governance capabilities may be better positioned to evaluate AI vendors consistently, identify unacceptable risks earlier, negotiate more effectively, deploy approved technologies with greater confidence and respond more rapidly when technologies or market conditions change (Gartner, 2026; OECD, 2025). Conversely, organisations with weak governance may either expose themselves to unnecessary risk or respond to uncertainty through broad restrictions that slow innovation. The strategic value of governance therefore lies not in maximising control, but in creating sufficient clarity and organisational capability to enable faster, safer and more informed AI adoption.
The strategic proposition is therefore:
Good AI governance should not determine whether an organisation can innovate; it should determine how quickly and safely it can innovate.
AI-vendor governance consequently becomes an enabling capability—one that connects procurement, risk management, technology strategy, economic evaluation and innovation. When designed effectively, it can allow organisations to capture the benefits of rapidly evolving AI technologies while maintaining sufficient control over the dependencies and risks that accompany them (Gartner, 2026; NIST, 2024; Janssen, 2025).
8. The role of standards and regulation
AI-vendor management cannot be separated from the regulatory and standards environment in which AI systems are developed, procured and deployed. As organisations become increasingly dependent on external AI providers, regulatory requirements, technical standards and contractual arrangements are becoming interconnected components of responsible AI management (NIST, 2024; OECD, 2025; Janssen, 2025). Compliance should therefore not be treated as a separate legal exercise conducted after a technology has been selected; rather, relevant requirements should be incorporated into procurement, vendor assessment and ongoing governance from the outset (Sanchez-Graells, 2026; OECD, 2025).
The European Union's AI regulatory framework is particularly significant for organisations operating within or serving the European market. The EU AI Act adopts a risk-based regulatory approach and establishes different requirements depending on the characteristics and intended use of AI systems (European Union, 2024). For organisations procuring or deploying AI, this creates an important distinction between the responsibilities of different actors within the AI value chain. Responsibility cannot simply be transferred to an external vendor through procurement. Organisations must understand their own role and obligations and ensure that contractual and operational arrangements provide the information, controls and cooperation necessary to meet applicable requirements (European Union, 2024; Sanchez-Graells, 2026).
This is particularly important because AI procurement increasingly involves complex relationships between providers, deployers, infrastructure providers, application vendors and other third parties. The organisation purchasing an AI capability may therefore have limited visibility into the underlying technology while nevertheless remaining responsible for how the system is used within its own operational environment. NIST's Generative AI Profile similarly recognises that risks can arise across the lifecycle and supply chain of acquired and cloud-based AI systems (NIST, 2024). Consequently, vendor governance must address not only the functionality of the immediate supplier but also relevant dependencies within the wider AI ecosystem.
Regulation, however, should not be regarded as a complete governance solution. Legislation establishes minimum requirements and accountability structures, but it cannot anticipate every technological, organisational or commercial risk associated with rapidly evolving AI systems. AI governance therefore requires the interaction of regulation, technical standards, contractual controls and organisational governance (NIST, 2024; Janssen, 2025). Sanchez-Graells (2026) similarly argues that procurement and contracting can serve as important mechanisms for operationalising responsible AI requirements, particularly where regulation alone does not determine the detailed allocation of responsibilities between parties.
Technical standards can provide an important bridge between high-level regulatory principles and operational practice. The NIST AI Risk Management Framework (AI RMF) provides a structured approach and common vocabulary for identifying, assessing, managing and monitoring AI risks throughout the system lifecycle (NIST, 2023). Its Generative AI Profile extends this approach to risks associated specifically with generative-AI systems and includes considerations relevant to acquired and cloud-based AI services (NIST, 2024). Such frameworks can help organisations translate broad principles such as transparency, accountability, security and risk management into practical vendor-assessment, deployment and monitoring activities.
The OECD similarly highlights public procurement as a mechanism for operationalising AI governance. Its work on AI in public procurement identifies areas including data governance, standardisation, procurement practices and organisational capabilities as important conditions for responsible AI adoption (OECD, 2025). The broader implication extends beyond government procurement: the procurement process can function as a practical governance mechanism through which organisations convert high-level AI principles into specific requirements, evaluation criteria and contractual obligations (OECD, 2025; Sanchez-Graells, 2026).
This has an important implication for AI-vendor management: compliance requirements should be translated into procurement specifications and contractual obligations wherever possible. Rather than treating a vendor's statement that its product is “compliant” as sufficient assurance, buyers should seek evidence that enables them to assess whether the technology, controls and organisational practices actually meet the requirements relevant to the use case (NIST, 2024; OECD, 2025). This approach is consistent with the broader shift from principle-based AI governance towards mechanisms capable of demonstrating how principles are implemented in practice.
For example, buyers should establish what data the system processes, whether the vendor uses customer data for model training, where data is stored and processed, and which employees, subcontractors or other third parties can access it. They should also understand how relevant models are evaluated, what performance and safety testing is undertaken, how incidents are detected and reported, and how material changes to models or services are communicated to customers (NIST, 2024; Janssen, 2025). These questions are particularly important where AI services depend on multiple external providers because the organisation's risk exposure may extend beyond its immediate contractual counterparty.
The same principle should apply to auditability and exit. Organisations should determine what evidence a vendor can provide to demonstrate compliance and risk management, whether appropriate audit and information rights exist, and what happens to organisational data and other relevant assets when the contractual relationship ends (Sanchez-Graells, 2026; Lifshitz, 2026). These considerations become particularly important where an AI capability is integrated into critical business processes or involves sensitive organisational information. Exit arrangements also support Gartner's (2026) emphasis on optionality because they reduce the risk that regulatory, technological or commercial changes leave an organisation unable to change suppliers.
This approach moves AI governance from a declaration-based model to an evidence-based model. The distinction is significant. A declaration-based approach asks whether a vendor claims to satisfy a particular requirement. An evidence-based approach asks how that requirement is demonstrated, what controls support it, what evidence can be independently assessed, who is accountable for the outcome, and what remedies are available if the vendor fails to meet its obligations (NIST, 2024; OECD, 2025). Such an approach is particularly appropriate for AI because claims about performance, safety and governance can become outdated as models and services change.
The distinction also strengthens the buyer's negotiating position. Requirements concerning data governance, security, transparency, auditability, incident management and model changes can be incorporated into procurement criteria and contractual provisions rather than remaining abstract governance principles (Sanchez-Graells, 2026; Lifshitz, 2026). This creates a direct connection between regulatory expectations, vendor selection and ongoing supplier management. It also reinforces Gartner's (2026) argument that the disruption of the AI market can provide buyers with an opportunity to negotiate greater control over their technology dependencies.
Ultimately, standards and regulation should be viewed as foundations for organisational control rather than substitutes for it. Regulation establishes the external boundary of acceptable behaviour; standards provide frameworks and methods for implementing risk management; contracts translate expectations into enforceable obligations between buyers and vendors; and organisational governance integrates these elements into day-to-day decision-making (European Union, 2024; NIST, 2024; OECD, 2025; Janssen, 2025).
The strategic objective is therefore not simply to purchase an AI system that is declared “compliant”, but to establish sufficient evidence, transparency and contractual control to demonstrate that the AI capability remains appropriate throughout its lifecycle. This is particularly important because compliance and risk are not static properties: changes in models, vendors, regulations, data practices and organisational use can alter the risk profile of an AI system after procurement (NIST, 2024).
Effective AI compliance therefore begins not with asking whether a vendor is compliant, but with asking what evidence demonstrates compliance, who is accountable for it, what contractual rights support it, and how compliance will be maintained as the technology and regulatory environment evolve.
9. An integrated framework for AI-vendor management
The preceding analysis suggests that Gartner’s five themes can be integrated into a coherent strategic framework for managing AI vendors. Taken together, optionality, economics, autonomy, buyer leverage and governance represent five interdependent dimensions through which organisations can manage the opportunities and risks associated with AI procurement (Gartner, 2026). The framework extends Gartner’s practitioner perspective by connecting it with research on AI governance, procurement, agentic systems, technological dependency and responsible AI (NIST, 2024; OECD, 2025; Janssen, 2025; Holldack, Banh and Strobel, 2026).
The first dimension is optionality. The central strategic question is whether the organisation can change or substitute suppliers if circumstances require it. Optionality is supported by interoperability, data portability, alternative suppliers and credible exit arrangements, all of which can reduce the strategic consequences of vendor dependency (Gartner, 2026; Sanchez-Graells, 2026). This is particularly relevant in AI because the underlying technology and vendor landscape can change rapidly, potentially altering the relative attractiveness of providers over comparatively short periods. Optionality should therefore be understood not as a requirement to maintain multiple vendors in every circumstance, but as a strategic capability that preserves the organisation’s ability to respond to changes in vendor performance, pricing, technology or market structure. Where dependency risk is high, the value of maintaining credible alternatives may outweigh the additional costs of doing so (Gartner, 2026).
The second dimension is economics. Organisations must determine whether their AI investments are generating sufficient value to justify their direct and indirect costs. This requires moving beyond measures of adoption and usage towards total cost of ownership, return on investment, productivity, business outcomes and risk-adjusted value (Gartner, 2026; Singla et al., 2025). The distinction between adoption and realised value is particularly important given the continuing gap between widespread organisational experimentation with AI and the proportion of organisations reporting substantial enterprise-level financial impact (Singla et al., 2025; Stanford HAI, 2026). Economic discipline therefore ensures that AI becomes an investment portfolio to be actively managed rather than a collection of technology experiments whose costs accumulate without clear accountability for results.
The third dimension is autonomy. The relevant question is not simply whether an AI system can act independently, but whether it should be permitted to do so. Research on agentic information systems suggests that greater AI agency changes the traditional relationship between humans and information systems by introducing new forms of delegation and decision-making authority (Holldack, Banh and Strobel, 2026). The appropriate level of autonomy consequently depends on factors including task complexity, potential harm, reversibility, business value and the availability of meaningful human oversight (Nguyen et al., 2026; Zhu et al., 2026). A risk-based approach allows organisations to capture the potential benefits of agentic AI while avoiding unnecessary delegation of consequential decisions or actions. Autonomy should therefore be treated as a design variable that is calibrated to the context rather than as a capability that organisations should maximise.
The fourth dimension is buyer leverage. Organisations should ask what degree of technological and commercial control they can secure in their relationships with AI vendors. Gartner (2026) identifies the disruption of the AI market as creating an unusual opportunity for buyers to strengthen their negotiating position. Interoperability requirements, data-export rights, price protections, audit provisions, model-change notifications, termination rights and transition assistance can all strengthen the buyer’s strategic position (Gartner, 2026; Sanchez-Graells, 2026; Lifshitz, 2026). The objective is therefore not simply to negotiate a lower purchase price, but to secure the control rights necessary to preserve future choice and strategic flexibility. This distinction is important because contractual value may arise not from immediate cost savings but from reducing future switching costs, dependency and exposure to unexpected changes in the technology or commercial relationship.
The fifth dimension is governance. Organisations must be able to identify, assess and manage risks as AI technologies, vendors and regulatory expectations change. This requires continuous monitoring, clear accountability, appropriate controls and lifecycle-based risk management (NIST, 2024; Janssen, 2025). The NIST AI RMF, for example, frames AI risk management as an ongoing organisational process rather than a one-time assessment, while the Generative AI Profile extends this approach to risks associated with generative-AI systems and services (NIST, 2024). Governance therefore provides the organisational infrastructure through which the other four dimensions can be implemented, monitored and adjusted over time.
These five dimensions should not be managed as independent objectives. They are mutually reinforcing and, in some cases, involve unavoidable trade-offs. Maintaining alternative vendors can strengthen optionality but also increase technology, integration and governance costs. Similarly, deploying agentic AI may generate productivity gains while simultaneously increasing the need for oversight, monitoring and risk controls (Holldack, Banh and Strobel, 2026; Nguyen et al., 2026). Strong contractual protections may improve buyer leverage but potentially increase procurement complexity or affect the commercial attractiveness of a vendor relationship (Sanchez-Graells, 2026; Lifshitz, 2026). These relationships demonstrate why AI-vendor management cannot be reduced to a single optimisation objective.
The framework should therefore be understood as a dynamic system rather than a checklist. Decisions within one dimension inevitably affect the others. A decision to consolidate AI suppliers, for example, may reduce procurement and integration costs while simultaneously weakening optionality and increasing dependency risk (Gartner, 2026). A decision to increase agent autonomy may improve productivity but require stronger governance, monitoring and human-oversight mechanisms (Nguyen et al., 2026; Zhu et al., 2026). A decision to negotiate extensive audit and exit rights may strengthen strategic control but increase contractual complexity or influence the commercial terms offered by a vendor (Sanchez-Graells, 2026).
This interconnectedness suggests that the objective of AI-vendor management should not be to maximise any single dimension. Maximum optionality could be prohibitively expensive; minimum cost could create unacceptable dependency; maximum autonomy could increase operational risk; and excessive governance could constrain experimentation and innovation. Research on AI governance similarly emphasises the importance of proportionate, context-sensitive approaches rather than uniform controls applied independently of the characteristics and consequences of individual AI systems (NIST, 2024; OECD, 2025; Janssen, 2025).
Instead, organisations should seek an appropriate balance between flexibility, value, autonomy, bargaining power and control according to their specific strategic circumstances. The appropriate balance will differ according to factors such as the criticality of the AI application, the sensitivity of the data involved, the consequences of failure, the maturity of the technology, the availability of substitutes and the organisation's tolerance for dependency. In this sense, AI-vendor management resembles a portfolio and risk-management problem rather than a conventional procurement decision.
The resulting framework can therefore be understood as a model of optimal strategic flexibility under uncertainty. It recognises that organisations cannot eliminate technological uncertainty in a rapidly evolving AI market. They can, however, design their vendor relationships so that they retain sufficient economic, technical, contractual and organisational flexibility to respond when circumstances change. This interpretation is consistent with Gartner’s emphasis on optionality and buyer leverage, while extending these ideas through the lifecycle and risk-management perspectives developed in the AI governance literature (Gartner, 2026; NIST, 2024).
The strategic objective is not to eliminate dependency, minimise expenditure or maximise control in isolation, but to create sufficient flexibility and governance to capture AI’s value while remaining resilient to technological and commercial change.
This integrated perspective also reinforces the central argument of this paper: AI-vendor management should be treated as a strategic organisational capability rather than a narrow procurement activity. The organisations most likely to derive sustained value from AI will not necessarily be those that select the most advanced individual technology. Rather, competitive advantage is likely to accrue to organisations capable of continuously evaluating, governing, negotiating, integrating and, when necessary, replacing AI capabilities as the technological and competitive environment evolves (Gartner, 2026; NIST, 2024; OECD, 2025).
10. Implications for managers
The preceding analysis has several practical implications for managers responsible for technology strategy, procurement, risk, digital transformation and organisational performance. The central message is that AI-vendor management requires a shift from transactional supplier management towards continuous strategic management of AI dependencies (Gartner, 2026; NIST, 2024). This reflects the increasingly dynamic and interconnected nature of AI ecosystems, in which organisations may depend simultaneously on application vendors, foundation-model providers, cloud infrastructure, data services and other third parties (Janssen, 2025; NIST, 2024).
First, organisations should establish and maintain a comprehensive AI-vendor inventory. Many organisations have established processes for identifying their formal software suppliers but may have considerably less visibility into which of those suppliers embed AI capabilities within their products. This creates a governance challenge because AI functionality can be introduced through existing software relationships without a separate procurement decision. NIST's Generative AI Profile emphasises the importance of understanding the risks associated with acquired and third-party AI services throughout the system lifecycle (NIST, 2024). The problem is particularly acute in the context of Shadow AI, where employees adopt AI tools outside formal organisational processes. Silic (2025) identifies associated risks including privacy concerns, hallucinations, bias and governance drift. An effective inventory should therefore identify not only dedicated AI vendors but also conventional software providers, cloud platforms and other third parties whose products incorporate AI capabilities.
Second, responsibility for AI-vendor decisions should be cross-functional rather than concentrated within procurement. AI procurement involves interconnected questions of architecture, information security, data governance, legal liability, regulatory compliance, financial value and business performance (NIST, 2024; OECD, 2025). Procurement professionals may lead the commercial relationship, but effective decision-making requires collaboration between procurement, IT, information security, legal, risk management and relevant business functions. This is consistent with Janssen's (2025) conceptualisation of AI governance as an organisation-wide socio-technical activity rather than a narrowly technical responsibility. It is also consistent with OECD (2025), which identifies organisational capabilities and procurement practices as important components of responsible AI adoption. A cross-functional model is particularly important for high-impact or business-critical AI applications, where no single organisational function is likely to possess all the expertise necessary to evaluate the technology, its dependencies and its consequences.
Third, organisations should adopt a risk- and criticality-based approach to vendor management. Not all AI vendors present the same level of strategic exposure and therefore should not be subject to identical governance requirements. The risk-based logic of the EU AI Act provides an important regulatory illustration of why obligations should reflect the characteristics and potential consequences of AI applications (European Union, 2024). NIST (2024) similarly emphasises the importance of context-specific risk identification and management rather than treating all AI systems as equivalent. A vendor providing a low-risk productivity or writing assistant therefore presents a fundamentally different risk profile from a provider whose AI system influences customer decisions, processes sensitive data or controls important operational workflows. Vendor criticality should consequently be assessed according to factors such as business impact, data sensitivity, degree of autonomy, regulatory exposure, substitutability and potential consequences of failure (NIST, 2024; Nguyen et al., 2026). Higher-criticality vendors should receive proportionately stronger due diligence, contractual protections, monitoring and contingency planning.
Fourth, AI contracts should be designed for change rather than technological stability. Conventional software agreements may implicitly assume that the product being purchased remains broadly consistent throughout the contractual period. AI makes this assumption increasingly problematic because models, pricing structures, data practices, capabilities and underlying providers may change over time (Gartner, 2026; NIST, 2024). Contracts should therefore anticipate material technological and commercial change. Appropriate provisions may include advance notification of significant model changes, data-governance requirements, incident-reporting obligations, audit rights, pricing protections, service-level commitments and clear termination and transition arrangements (Sanchez-Graells, 2026; Lifshitz, 2026). Such provisions help prevent technological change from automatically translating into unmanaged contractual or operational risk and reinforce Gartner's (2026) emphasis on optionality and buyer leverage.
Fifth, organisations should evaluate AI expenditure against measurable business outcomes. The widespread availability of generative AI has lowered the barriers to experimentation, but adoption alone does not demonstrate organisational value. McKinsey's 2025 research illustrates this distinction: although 88 per cent of respondents reported AI use in at least one business function, only around one-third reported that their organisations had begun scaling AI programmes across the enterprise, while 39 per cent reported an enterprise-level EBIT impact (Singla et al., 2025). The Stanford AI Index Report 2026 similarly distinguishes accelerating AI adoption from the more difficult question of measuring realised organisational impact (Stanford HAI, 2026). Managers should therefore establish explicit criteria for scaling, maintaining or terminating AI initiatives. These criteria should consider not only direct financial returns but also productivity, quality, customer outcomes, cycle times, risk reduction and other strategically relevant measures (Gartner, 2026). This creates a disciplined mechanism for moving from experimentation towards sustainable enterprise adoption.
Finally, organisations should position governance as an enabler of innovation rather than a constraint upon it. Governance that is excessively restrictive may slow experimentation or encourage employees to circumvent formal processes, while the absence of governance can expose organisations to unnecessary operational, legal and reputational risks (Janssen, 2025; NIST, 2024). A well-designed governance framework instead establishes clear boundaries within which experimentation can occur. Lower-risk use cases can move through proportionate and streamlined approval processes, while higher-risk applications receive deeper assessment and oversight. This principle of proportionate governance is consistent with the risk-management orientation of NIST (2024) and the broader emphasis on context-sensitive AI governance in the OECD's work on responsible AI adoption (OECD, 2025). Such an approach allows organisations to increase the speed of responsible AI adoption without abandoning appropriate controls.
Taken together, these implications point towards a broader change in managerial responsibility. Leaders should not view AI-vendor management as a narrow procurement or technology issue. It is increasingly a question of organisational resilience, strategic flexibility and value creation (Gartner, 2026). Managers must understand where AI dependencies exist, determine which dependencies matter most, establish appropriate commercial and governance protections, and continuously reassess whether those arrangements remain strategically appropriate (NIST, 2024; Janssen, 2025).
The managerial challenge is therefore not simply to decide which AI technologies to adopt, but to build an organisational capability that can continuously determine which AI capabilities to adopt, under what conditions, from which vendors, at what level of autonomy, at what cost and with what mechanisms for control and exit. This formulation brings together the five dimensions developed in this paper: optionality determines the ability to change, economics determines whether adoption creates sufficient value, autonomy determines how much decision-making authority should be delegated, buyer leverage determines the degree of control that can be secured contractually, and governance determines how these choices are monitored and adjusted over time (Gartner, 2026; NIST, 2024).
Organisations that develop this capability should be better positioned to respond to rapid technological change while avoiding the two extremes of uncontrolled adoption and excessive caution. In this sense, AI-vendor management becomes a strategic organisational capability: it enables organisations not merely to adopt AI, but to adopt, govern, evaluate, renegotiate and replace AI capabilities deliberately as technology, markets and organisational needs evolve.
11. Discussion
The central finding emerging from the Gartner practitioner perspective and the academic and institutional literature is that AI is changing the nature of the buyer–vendor relationship itself. The implications extend beyond the procurement of a new category of technology. AI alters how organisations experience technological dependency, assess economic value, allocate decision-making authority, negotiate with suppliers and manage risk over time. The resulting challenge is therefore not simply how organisations should buy AI, but how they should manage an evolving portfolio of AI dependencies while preserving strategic flexibility.
This argument is particularly significant given the speed at which AI capabilities are developing. The 2026 AI Index reports that organisational AI adoption reached 88 per cent in 2025, while generative AI adoption reached 79 per cent. At the same time, AI capabilities continue to advance rapidly and the competitive gap between leading models has narrowed, increasing competitive pressure around factors such as cost, reliability and domain-specific performance rather than capability alone. This combination of rapid adoption and rapid technological change creates an unusual procurement environment. Organisations are making increasingly consequential technology decisions while the underlying basis for comparing vendors can change within relatively short periods.
Traditional IT procurement is largely based on a relatively stable exchange: an organisation identifies a requirement, evaluates alternative products, selects a supplier and manages the resulting relationship through contractual and operational mechanisms. AI increasingly disrupts this model. A business application may depend on a foundation model from one provider, cloud infrastructure from another, external data services, specialised AI components and additional third-party systems. The buyer therefore enters an ongoing socio-technical relationship with an interconnected technology ecosystem, rather than simply purchasing a discrete product.
Four characteristics distinguish this relationship.
First, it is dynamic. Models, capabilities, pricing structures, APIs and vendor strategies can change rapidly. The 2026 AI Index indicates that leading AI model performance is increasingly competitive, with several providers clustered near the top of performance rankings. This creates opportunities for buyers but also makes long-term technology decisions more difficult.
Second, the relationship is uncertain. AI systems do not always produce deterministic outputs, and their performance can vary according to context, data and task. This is not merely an academic concern. Stanford's 2026 AI Index reports substantial variation in hallucination rates among leading models and identifies continuing weaknesses in responsible-AI performance and transparency. Consequently, vendor evaluation cannot be based solely on advertised functionality or benchmark performance at the point of procurement.
Third, the relationship is interdependent. AI systems increasingly rely on other systems, data sources, infrastructure providers and organisational processes. A change made by one supplier can therefore affect the performance, cost or risk profile of capabilities that appear to belong to another vendor. This makes dependency management more important than conventional supplier-performance management.
Fourth, the relationship is increasingly strategic. AI capabilities are moving into core business processes rather than remaining peripheral productivity tools. McKinsey's 2025 research found that 62 per cent of respondents were already experimenting with AI agents, although most organisations remained in relatively early stages of enterprise-wide scaling and only 39 per cent reported enterprise-level EBIT impact from AI. The strategic question is consequently no longer whether AI will be used, but which AI capabilities should become embedded in organisational processes and under what conditions.
These characteristics provide the rationale for Gartner's first priority: optionality. The analysis suggests that optionality should be understood as a strategic response to technological uncertainty rather than simply a procurement preference. An organisation that can change providers, migrate data or adopt alternative models is better positioned to respond to changes in vendor performance, pricing, technological capability or market structure. Optionality therefore represents a form of organisational resilience.
However, the analysis also reveals an important tension. Maintaining multiple suppliers or alternative architectures can increase costs and complexity. Consequently, optionality should not be maximised indiscriminately. The appropriate level should depend on the strategic importance of the AI capability, the cost of switching, the availability of substitutes and the consequences of vendor failure or deterioration. This leads to a more nuanced proposition: organisations should concentrate optionality where dependency risk is strategically material.
Gartner's second priority, economic discipline, follows directly from this argument. The rapid diffusion of AI creates a risk that organisations will equate adoption with value. Yet the available evidence suggests that the two are not equivalent. McKinsey reports widespread AI use but much more limited enterprise-level financial impact, while the AI Index notes that reported adoption should be interpreted as directional rather than as a comprehensive measure of business performance.
The implication is that AI investment should increasingly be governed as a portfolio of economic decisions. Organisations need to distinguish between experimentation, adoption and value realisation. Measures such as the number of employees using AI or the number of deployed applications may demonstrate activity, but they do not establish whether an initiative is economically successful. More meaningful measures include productivity, revenue, cost reduction, quality, cycle time, customer outcomes and risk-adjusted returns.
This distinction has implications for vendor contracts as well. If organisations are unable to demonstrate the value generated by an AI capability, they will struggle to determine whether rising consumption costs remain justified. Economic discipline therefore requires a closer relationship between AI usage, business outcomes and vendor commercial models.
The third priority, appropriate autonomy, introduces another important dimension. The rapid development of agentic AI means that AI systems can increasingly move beyond producing recommendations or content to executing multi-step activities. McKinsey's finding that 62 per cent of surveyed organisations are experimenting with agents demonstrates the speed at which this capability is entering organisational environments. Yet the same research shows that scaling remains limited.
This suggests that organisations are entering an important decision phase: not whether agentic AI exists, but where autonomy creates sufficient value to justify its risks. Autonomy should therefore be treated as a variable to be deliberately designed. Low-risk, reversible tasks may justify relatively high levels of autonomy, while consequential or irreversible decisions require stronger human oversight. The appropriate degree of autonomy should be determined by task complexity, failure costs, reversibility and accountability.
This perspective challenges a technologically deterministic approach in which greater AI capability automatically leads to greater delegation. The strategic objective should instead be appropriate autonomy. The question is not whether an agent can perform a task, but whether its independent execution creates sufficient incremental value to justify the additional operational and governance risk.
The fourth priority, buyer leverage, introduces a different but complementary argument. AI-market disruption may temporarily improve the negotiating position of technology buyers. The competitive convergence among leading models documented by Stanford suggests that organisations may increasingly evaluate providers on cost, reliability, specialised performance and commercial terms rather than simply asking which vendor possesses the most capable model.
This creates an opportunity to negotiate more than price. Buyers can seek interoperability, data portability, transparency, model-change notification, auditability, security requirements and meaningful exit rights. These provisions have strategic value because they preserve future choice. A low-cost contract that creates substantial dependency may ultimately be less valuable than a contract with slightly higher direct costs but stronger rights to migrate, audit and renegotiate.
The concept of buyer leverage, however, should be treated as time-sensitive. As AI markets consolidate and organisations become increasingly dependent on specific providers, bargaining power may shift towards vendors. The implication is that organisations should use periods of competition to secure contractual protections before technological dependency becomes entrenched.
The fifth priority—AI-vendor governance as competitive advantage—provides the mechanism that connects the other four dimensions.
The evidence increasingly suggests that AI governance remains a significant organisational challenge. Stanford's 2026 AI Index reports that AI-specific governance roles increased in 2025 and that the share of businesses without responsible-AI policies fell from 24 per cent to 11 per cent. However, organisations continue to identify knowledge gaps, budget constraints and regulatory uncertainty as major obstacles to implementation. The report also highlights declining transparency among major AI companies.
These findings reinforce the argument that governance cannot be reduced to compliance. Organisations need mechanisms that allow them to make rapid but informed decisions about AI vendors and use cases. A mature governance framework can establish clear risk categories, standardised due diligence requirements, approved contractual provisions and proportionate approval processes. This reduces the need to reinvent the governance process for every AI initiative.
The strategic significance is that good governance can increase organisational speed rather than reduce it. Where governance is absent, decision-makers may respond to uncertainty by delaying adoption or imposing broad restrictions. Where governance is excessively bureaucratic, innovation can become unnecessarily slow. A proportionate governance model creates predefined boundaries within which experimentation can proceed more rapidly.
The five Gartner themes should therefore be understood as interdependent capabilities rather than separate recommendations. Optionality protects flexibility; economic discipline protects value; appropriate autonomy balances productivity and risk; buyer leverage protects contractual and strategic control; and governance provides the mechanisms through which all four can be coordinated.
The relationships between these dimensions also reveal important trade-offs. Maintaining alternative vendors may increase optionality but raise costs. Increasing agent autonomy may improve productivity but require stronger governance. More extensive contractual protections may improve buyer control but increase transaction costs or make a vendor relationship less commercially attractive. Conversely, excessive supplier consolidation may lower costs while increasing dependency.
The objective should therefore not be to maximise any single dimension. Rather, organisations should seek an optimal configuration of flexibility, value, autonomy and control under conditions of uncertainty.
This leads to a broader theoretical proposition. AI-vendor management is evolving from a transactional procurement function into a form of strategic capability management. The relevant organisational capability is not simply the ability to select an appropriate vendor at a particular point in time. It is the ability to continuously evaluate AI technologies, assess dependencies, measure value, negotiate with suppliers, govern risk and change direction when circumstances warrant.
This perspective also reframes the meaning of competitive advantage in AI. Technological leadership may be temporary because model capabilities and vendor positions can change rapidly. By contrast, the organisational capability to manage AI effectively may prove more durable. Organisations that can identify valuable use cases, select appropriate vendors, retain optionality, negotiate meaningful control, deploy appropriate levels of autonomy and govern AI throughout its lifecycle may be better positioned to capture sustained value from technological change.
The paper therefore arrives at a central proposition:
In an increasingly competitive and rapidly changing AI market, competitive advantage may depend less on access to a particular AI technology than on an organisation's ability to manage its portfolio of AI dependencies more effectively than its competitors.
This proposition also provides an important qualification to the enthusiasm surrounding AI adoption. The strategic challenge is not simply to move quickly. Nor is it to minimise risk by moving slowly. The challenge is to develop the organisational capabilities that allow the firm to move quickly where the opportunity is attractive, cautiously where the consequences of failure are high, and flexibly enough to change course when technology or market conditions shift.
In this sense, the five Gartner priorities form a coherent strategic logic. Optionality provides resilience; economic discipline provides value orientation; appropriate autonomy provides controlled delegation; buyer leverage provides strategic control; and continuous governance provides organisational adaptability. Together, they provide a foundation for managing AI not as a collection of isolated technology purchases, but as an evolving strategic capability embedded within a wider technological and commercial ecosystem.
12. Conclusion
Artificial intelligence is changing not only the technologies organisations procure, but also the nature of the relationships through which those technologies are acquired, deployed and governed. The evidence examined in this paper suggests that conventional approaches to software procurement are increasingly insufficient for an environment in which AI models evolve rapidly, costs can vary with usage, autonomous systems can execute organisational tasks, and multiple vendors may contribute to a single AI capability.
Drawing on Gartner’s five priorities for working with AI vendors—optionality, expenditure control, appropriate use of AI agents, buyer leverage and vendor governance—this paper has argued that organisations should move from transactional software procurement towards strategic AI capability management (Gartner, 2026). The distinction is important. The objective is no longer simply to select the technically strongest or lowest-cost vendor at a particular point in time. Instead, organisations must establish relationships that allow them to capture value while retaining sufficient flexibility to respond to technological, economic and regulatory change.
Five principles emerge from the analysis.
First, optionality is a strategic asset. Organisations should avoid unnecessary dependency on individual AI providers and preserve the ability to substitute vendors, migrate data and adopt alternative technologies where the consequences of dependency are significant. Optionality should not be pursued indiscriminately, however, because maintaining alternatives also creates cost and complexity. It should be concentrated around strategically important AI capabilities.
Second, AI expenditure must be connected to business value. High adoption and extensive usage do not necessarily demonstrate successful AI transformation. Organisations should distinguish experimentation and activity from measurable outcomes and assess AI investments according to their contribution to productivity, revenue, cost reduction, quality, customer outcomes and risk-adjusted value. This requires a shift from managing AI consumption to managing AI economics.
Third, autonomy should be deliberately designed rather than maximised. Agentic AI creates opportunities for substantial productivity improvements, but increased autonomy also increases the potential consequences of system failure. Organisations should therefore determine the appropriate level of autonomy according to task complexity, risk, reversibility and the availability of human oversight. The question is not whether AI can act independently, but whether it should.
Fourth, buyer leverage should be used to secure strategic control. The disruption of the AI market creates opportunities for organisations to negotiate interoperability, data portability, transparency, audit rights, price protections, change notification and meaningful exit arrangements. The value of these provisions extends beyond immediate commercial savings: they preserve the organisation's ability to respond when vendors, technologies or market conditions change.
Fifth, governance should be treated as an organisational capability rather than merely a compliance function. Effective governance can provide the structure required to evaluate vendors, classify risks, approve use cases, monitor performance and manage change. When governance is proportionate and embedded into procurement and operational processes, it can reduce uncertainty and enable organisations to adopt AI more quickly and confidently rather than simply restricting innovation.
Taken together, these principles suggest that the strategic challenge of AI-vendor management is fundamentally one of managing dependency under uncertainty. Organisations cannot eliminate technological change, guarantee that a particular vendor will remain dominant, or predict precisely how AI capabilities will evolve. They can, however, determine how exposed they are to these uncertainties and how effectively they can respond when circumstances change.
This leads to the paper's central conclusion:
Sustainable advantage in enterprise AI is unlikely to depend solely on selecting the most capable technology. It will increasingly depend on an organisation's ability to manage AI vendors, dependencies and capabilities in a way that preserves value, flexibility and control over time.
The most strategically resilient organisations will therefore be those that combine optionality, economic discipline, appropriate autonomy, buyer leverage and continuous governance. These capabilities enable organisations to experiment without becoming unnecessarily dependent, scale without losing economic discipline, delegate without abandoning accountability, and innovate without sacrificing strategic control.
AI-vendor management should consequently be elevated from a narrow procurement responsibility to a strategic organisational capability involving procurement, technology, business leadership, legal, security, risk and governance functions. As AI becomes increasingly embedded in core organisational processes, the ability to manage these relationships effectively may become as important as the technologies themselves.
Ultimately, the question for organisations is not simply which AI vendor should we choose? It is:
How should we structure our AI ecosystem so that we can capture today's opportunities while retaining the flexibility to respond to tomorrow's technologies, risks and markets?
That shift in perspective—from vendor selection to strategic capability management—is the central implication of this paper.
References
Autio, C., Schwartz, R., Dunietz, J., Jain, S., Stanley, M., Tabassi, E., Hall, P. and Roberts, K. (2024) Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile. NIST AI 600-1. Gaithersburg, MD: National Institute of Standards and Technology.
Gartner (2026) Gartner Business Quarterly: Q3 2026 – How to Work With AI Vendors. Gartner Business Quarterly.
Gartner (2025) ‘What GC Need to Know About AI Agent Risks’
Janssen, M. (2025) 'Responsible governance of generative AI: conceptualizing GenAI as complex adaptive systems', Policy and Society, 44(1), pp. 38–51. doi:10.1093/polsoc/puae040.
Johnson, N. et al. (2026) 'Innovators and Transformers: From policy to public value: how procurement governs AI adoption in US State government', International Journal of Physical Distribution & Logistics Management, 56(6), pp. 640–660. doi:10.1108/IJPDLM-02-2025-0084.https://link.springer.com/article/10.1007/s12525-025-00861-0
Holldack, F., Banh, L. and Strobel, G. (2026) ‘Agentic information systems’, Electronic Markets, 36, Article 5. doi:10.1007/s12525-025-00861-0
IBM (2025) Scaling Responsible Agentic AI.
Kumar, N., Wei, X. and Zhang, H. (2026) 'Agentic artificial intelligence as a new frontier in information systems: Promise, peril, and research opportunities', Information & Management, 63(3), 104317. doi:10.1016/j.im.2026.104317.
Lifshitz, L.R. (2026) Procurement in the age of AI: the legal architecture of AI procurement. Oxford University Press.
McKinsey & Company (2025) Seizing the agentic AI advantage. McKinsey & Company, 13 June.
NIST (2024) Artificial Intelligence Risk Management Framework. National Institute of Standards and Technology.
Nguyen, M.H., Nguyen, D.H., O’Sullivan, B. et al. (2026) ‘On Controllability in Agentic AI: A Survey’, Minds and Machines, 36, Article 29.
OECD (2025) Governing with Artificial Intelligence: AI in Public Procurement. Paris: OECD.
Perez-Cruz, F. and Shin, H.S. (2025) ‘Putting AI agents through their paces on general tasks’, BIS Working Papers, No. 1245.
PwC (2026) AI agents as workforce counterparts—what governance should look like.
Sanchez-Graells, A. (2026) 'Competition implications of artificial intelligence in public procurement’, in Quinot, G. (ed.) A Research Agenda for Public Procurement Law, Policy and Regulation. Cheltenham: Edward Elgar.
Silic, M. (2025) 'From Shadow IT to Shadow AI–Threats, Risks and Opportunities for Organizations', Strategic Change. doi:10.1002/jsc.2682.
Singla, A., Sukharevsky, A., Hall, B., Yee, L. and Chui, M. (2025) The State of AI in 2025: Agents, Innovation, and Transformation. McKinsey & Company, 5 November.
Stanford Institute for Human-Centered Artificial Intelligence (2026) The AI Index Report 2026. Stanford University.
World Economic Forum (2025) AI Agents in Action: Foundations for Evaluation and Governance.
Zhu, L., Lu, Q., Ding, M., Lee, S.U. et al. (2026) ‘Designing meaningful human oversight in AI’, AI and Ethics, 6, Article 286.
Contact
Reach out via email for inquiries.
Subscribe to newsletter
info@grcadvisory.ch
© 2025. All rights reserved.