Source-to-pay & procurement technology

What can AI realistically do in a procurement function?

Short answer

AI is reliable in procurement for language and data work that a knowledgeable person can check: classifying spend, resolving supplier records to parent level, extracting terms and dates from contracts, drafting first versions, and answering routine questions about policy and process. Start with spend classification, because it is verifiable and most other things depend on it. Judgement, evaluation and award decisions stay with people and have to be evidenced as such. Before any of it, settle which tools may see commercially sensitive material and what an agent is permitted to do without a person in the loop.

Updated 4 September 2026 / 8 min read
On this page06
  1. Where it works
  2. Where it does not help
  3. The question that has replaced the evaluation question
  4. What a usable position has to say
  5. What the rules currently say
  6. Related questions

Where it works

The work that currently pays for itself in a commercial function shares three characteristics: the input is language or messy data, the volume is high enough that people avoid the work, and a person who knows the subject can check the output.

  1. Spend classification and supplier resolutionMapping transaction lines to categories and grouping supplier records to parent level. This is now a bought capability with quoted accuracy rather than a frontier, and it remains the right place to start because it is verifiable and because the pipeline, the category work and the reporting all sit on top of it.
  2. Contract data extractionPulling parties, values, terms, notice periods, renewal mechanics and liability caps out of a folder of agreements into a register. The checking is much faster than the reading. The question that follows is the one to decide in advance: when the extracted value and the signed document disagree, which one the register treats as authoritative and who adjudicates.
  3. Drafting and comparisonFirst drafts of specifications and clarification responses, and comparison of a supplier's returned terms against a standard position. The draft is a starting point and the commercial content still comes from a person.
  4. Reducing long material to what bears on a decisionSummarising supplier responses or a long report down to the points that matter for the decision in front of you. Useful for preparation, and not a substitute for reading the source where the decision has to be defended.
  5. Answering the routine internal questionsThresholds, routes, how to raise something. Low risk, high volume, and it returns capacity to people who were being interrupted all day.

Where it does not help

  • Deciding what to buy. Requirement, risk appetite and what the organisation can live with are not language tasks.
  • Negotiating. Preparation can be supported; the negotiation depends on relationship, timing and what each side will concede.
  • Forecasting prices from your own transaction history. Where price forecasting works it rests on external index and market data, and the prior question is whether your contracts contain indexation clauses that make a forecast actionable at all.
  • Creating discipline that does not exist. A function without a contract register does not need contract intelligence; it needs a register, and the tool will help build one rather than stand in for it.
  • Anything where nobody can tell whether the answer is right. Fluent and wrong is the characteristic failure, and an extracted renewal date that is wrong is worse than no renewal date.

The constraint is almost never the model. It is the state of the data and whether anyone is actually checking the output.

The question that has replaced the evaluation question

For two years the governance conversation in procurement was whether a model should score a bid. It should not, and that is now the easy part. The live question is what an agent is permitted to do on its own.

Procurement suites increasingly offer actions rather than answers: raising a requisition, approving below a threshold, chasing a supplier, applying a redline from a clause playbook, clearing an invoice exception, sending a clarification. Each of those is an act that commits or exposes the organisation, and each needs the same treatment as a delegated authority, because that is what it is.

  • What may an agent do with no person in the loop, and up to what value.
  • What must it propose rather than execute.
  • What does the log capture: the action, the inputs it saw, the rule it applied, and who it was acting for.
  • Who is accountable when it is wrong, and what the reversal looks like.
  • How does any of this appear in the scheme of delegation, which currently names people.

An organisation that has not answered those will answer them by default, in a configuration screen, when the vendor turns the feature on.

What a usable position has to say

Most AI policies in commercial functions are a page of principles, which nobody can follow because a principle does not tell you whether you may paste a supplier's pricing into a tool. A position a procurement director can actually issue states eight things.

  1. The approved tools, by nameAnd what tier of information each may take: public, internal, commercially sensitive, personal data. A named list, kept current, not a category of tool.
  2. What the contract behind each tool actually saysWhether inputs may be used for training, what the retention period is, who the sub-processors are and where the data sits. Most people assume the enterprise agreement covers this. It is worth checking rather than assuming.
  3. The prohibited uses, with no discretionSupplier pricing or bid content into a tool that is not approved. Generating an evaluation score or the reasoning behind one. Personal data without the assessment your information governance requires.
  4. Where a person has to decide, and what the record containsWho decided, what they saw, what they wrote, and where it is kept so that it survives a challenge months later.
  5. The confidentiality position, both waysA supplier's pricing is usually covered by an obligation you signed. Putting it into a third-party tool may be a disclosure. That is a contract question, not an IT question.
  6. Agent permissionsThe five questions in the section above, answered in writing. This is the part most positions are missing entirely, and it is the part that will matter first.
  7. What happens when something goes in that should not haveWho is told, within what time, and what the containment step is. Written before it happens, because it will.
  8. An owner and a review dateBoth the tools and the expectations are moving, and a position with no owner ages into a document people quote at each other.

What the rules currently say

For central government departments and their arm's length bodies there is already a central position on AI in procurement, and it is narrower than most people expect. It recommends asking suppliers to disclose their use of AI in preparing a tender, treats those questions as for information only and not scored, and is explicit that authorities must not discriminate against suppliers on the basis of the answers. It also asks authorities to put proportionate controls in place so that suppliers do not use confidential authority information as training data, and suggests additional due diligence, such as clarification questions or presentations, where AI has been used in a response.

Two things follow that are worth being precise about. Disclosure is not a scoring criterion, so a bid that used AI cannot be marked down for it. And that guidance addresses supplier use rather than the authority's own use in evaluation, so an organisation using AI in its own assessment process is operating on its own judgement rather than on a published rule.

The constraint on that judgement is the one that has always applied: an award decision has to be capable of being explained and defended afterwards, on the criteria published, by the people who made it. Anything that cannot be reconstructed at that level of detail is a problem regardless of how it was produced.

Organisations with European operations, or handling personal data in a decision process, have further regimes to consider. That is a question for legal and information governance rather than for a procurement article, and it should be asked before deployment rather than after.

Related answers

All answers

Next step

Working through this for real.

If this is a live decision rather than background reading, describing the situation in a couple of sentences is usually enough for a useful reply.