Evidence note: This perspective is an SOS governance framework, not legal advice or a claim about one supplier. Procurement requirements should be adapted to the organisation, use case, jurisdiction and risk level.

The most expensive AI procurement mistake often happens before a contract is signed: the buyer evaluates the demonstration, but not the operating system around it.

A polished output is not due diligence

A convincing demo can show that a tool produces a useful result. It cannot, by itself, show where data travels, who can inspect it, how decisions are challenged or what happens when the supplier changes its model. That is why responsible AI governance and assurance must begin during procurement, not after deployment.

Six questions every AI buyer should evidence

1. What data enters the system?

Map personal, confidential and commercially sensitive information before approving access. Record the permitted purpose, retention position and whether customer data can be used to train another system.

2. Which decisions can the system influence?

Separate assistance from authority. In high-consequence workflows such as recruitment compliance verification, define which decision stays with an accountable person and what evidence they receive.

3. How is performance tested?

Ask for evaluation evidence relevant to your users and conditions. Generic benchmark scores are not a substitute for acceptance testing, error analysis and a documented route for reporting failure.

4. What can the tool reach?

Review integrations, permissions, credentials and outbound connections. Apply the same discipline described in our perspective on agentic AI security and connected systems.

5. Who owns the operating decision?

Name the person who approves the use case, the person who monitors it and the person who can stop it. The SOS Standard for accountable AI systems makes that ownership visible.

6. Can you leave safely?

Contract for export, deletion, transition support and evidence retention. Exit planning protects continuity and prevents a useful pilot from becoming an uncontrolled dependency.

Buy the control environment, not only the capability

A strong AI supplier should make scrutiny easier. The commercial advantage is not an assurance slogan; it is the ability to show how the system behaves, who remains accountable and what happens when conditions change.

Want to turn this perspective into a practical operating decision?

Talk to us about AI governance