The interesting question about AI in procurement is not what it can do. It is what it must never do, because an agent that fabricates a number you repeat to a vendor, or leaks the one you meant to keep, is worse than no agent at all. These are the lines we will not let it cross.
Most writing about AI in procurement is a list of new capabilities. This is the opposite. The capabilities are the easy part, and by themselves they are dangerous, because a procurement agent operates on the two things a company can least afford to get wrong: the numbers it takes into a negotiation, and the information it must not let out of one. An agent that invents a benchmark is not a productivity gain, it is a liability you will repeat to a vendor. An agent that leaks your walk away price has not saved you time, it has cost you the deal.
So the design that matters most is not what the AI is allowed to do. It is what it is not. These are the lines the platform draws on purpose, and the reason each one exists.
The first and firmest rule is that no number reaches you without a citation. Every figure an agent produces is tagged back to the document or the benchmark cohort it came from, and answers pass a groundedness check before they are ever shown. When the underlying data is thin, the honest output is that the data is thin, not a confident number improvised to fill the silence.
This is not a nicety, it is the whole point of a procurement analyst. A benchmark you cannot trace is not a benchmark, it is a rumour with a decimal point, and a rumour you carry into a negotiation and cannot defend is worse than saying nothing. By refusing to state a figure it cannot ground, the agent stays the kind of colleague you can actually quote, because everything it tells you comes with its receipt.
The second rule governs action. The agents prepare, they do not commit. The ghost writer drafts the reply to the vendor, the copilot whispers the fact during the call, the dossier assembles the package, and in every case a person makes the move that binds the company. There is no path where an agent emails a vendor, accepts a term, or sends a number on its own. Draft is a machine verb. Send is a human one.
And before anything drafted goes out, it is scanned for what it should not reveal. Outbound text destined for a vendor runs through a confidentiality check that looks for your own sensitive figures, your mandate, your walk away, your internal targets, and warns you if a draft is about to expose them. It never blocks you, because sometimes you mean to share a number, but it never lets you leak one by accident either. The judgment stays yours, with a second pair of eyes that never gets tired.
The third rule is about defense. Modern AI can be manipulated by the very documents it reads, a vendor proposal or an inbound email carrying hidden instructions meant to steer the model. So every piece of vendor authored text, proposals, emails, invoices, is wrapped and explicitly marked as untrusted before it reaches the model, and the system is instructed to treat it as data to analyze, never as commands to follow. An instruction buried in a vendor's PDF telling the analyst to ignore its rules is treated as exactly what it is: part of the vendor's document, not a directive.
This defense is enforced in the code, not just intended. The build itself fails if a new feature feeds document text to the model without the untrusted wrapper, so the protection cannot quietly erode as the platform grows. Custom instructions are screened before they are saved. The principle is simple: the buyer's agent takes its orders from the buyer, and from no one whose text happens to pass through it.
No set of rules makes an AI system perfectly safe, and we do not claim it. Groundedness checks can miss, scans are not omniscient, and defenses against a manipulated document are an arms race, not a solved problem. Every agent action, human and machine alike, lands in the same audit trail precisely because trust is verified, not assumed, and because you should be able to see exactly what was done on your behalf.
What we can say plainly is where the lines are drawn and why. The machines take the reading, the watching, the reconciling, and the first draft. People keep the figures they will defend, the messages they will send, and the signature that binds the company. An AI you can hand a renewal to is not the one that can do the most. It is the one whose limits you can name.
Fredrik has spent more than twenty years in enterprise software, with time at Oracle, IBM, SAP, and Salesforce before moving to the buy side. He structured and priced the kind of large agreements most buyers only see once or twice in a career, which taught him where the leverage sits and how far a vendor will actually move. He started VendorBenchmark to hand that knowledge to every sourcing team.
What shipped on the platform, and the pricing and licensing moves worth knowing before your next renewal. One email a week, to your work address. Unsubscribe any time.