top of page
Search

Controlled autonomy in procurement: AI that may act, you who remain accountable

23 hours ago
6 min read

AI in procurement has moved to a new phase. It is no longer limited to chatbots that summarise contracts, answer policy questions or help prepare sourcing documents. A new generation of AI agents can plan activities, use multiple systems, make recommendations and, within agreed boundaries, execute procurement actions. The market is not yet ready for fully autonomous procurement. What you see now is controlled autonomy: agents increasingly run multi-step processes, while people remain responsible for material commercial, legal, financial and ethical decisions. For SME entrepreneurs, CFOs and procurement teams, that is the distinction that matters. Not “AI takes over procurement”, but “AI may do more, you remain accountable”. If you do not hardwire that distinction into mandate, limits, clear definitions, clear workflows and an audit trail, you buy speed and risk in one package.


What makes an AI agent different in procurement


Classic procurement automation follows predetermined rules. Generative AI can interpret information and produce text, but usually waits for your instruction. An AI agent goes further. You give it an objective, for example finding savings opportunities, onboarding a supplier or preparing a sourcing event. The agent then determines the steps, retrieves information, works in approved systems, analyses and proposes or executes actions. Think of an agent that:

  • interprets a purchase request

  • checks it against procurement policy

  • selects approved suppliers

  • collects quotations

  • compares commercial and non-commercial criteria

  • prepares an award recommendation

  • routes that recommendation through the approval process


and after approval creates a requisition in the procurement system. The difference with an assistant is fundamental. The agent does not only generate an answer. It coordinates a workflow and can complete part of it.


What is already happening in the market


Agentic AI in procurement is past the concept stage. Major end-to-end procurement and spend platforms are introducing specialised agents for supplier management, sourcing, risk monitoring, contract analysis and purchasing support.


Early applications are already running in controlled production environments. Maturity varies widely. Many organisations are still experimenting. A smaller group is integrating agents into live processes. The most mature applications are repetitive, data-intensive and clearly bounded:

  • spend classification and opportunity identification

  • intake and routing of requests

  • supplier onboarding and documentation checks

  • contract data extraction and obligation monitoring

  • preparation of sourcing events

  • supplier risk monitoring

  • quotation comparison

  • purchase-to-pay administration


routine exception handling. Sensitive steps remain limited: autonomous supplier selection, negotiation, contractual commitment or strategic category decisions. There, AI mainly supports professional judgement. The direction is clear nonetheless. Procurement technology is shifting from systems that record transactions to systems that can initiate and coordinate actions.


From copilot to agent: more value, more risk


A copilot drafts a request for proposal, summarises a supplier contract or flags unusual spend. You decide the next step. An agent can go further. Within its permissions it may create a sourcing event, request information, monitor responses, evaluate bids and route a recommendation through approval. That frees capacity for procurement teams. Less time gathering information, preparing documents, chasing approvals and resolving routine exceptions. More attention for category strategy, negotiation, innovation, supplier relationships and risk management. But acting is different from advising. A chatbot with a wrong answer creates confusion. An agent with transaction rights can approve the wrong supplier, disclose confidential information, bypass an approval process or create an unauthorised commitment. As autonomy increases, governance requirements must grow with it. That is not a brake on innovation. It is the condition for innovation to land responsibly.


Where the business case really sits


The value goes beyond administrative efficiency. Agents can run repetitive coordination and analysis continuously. Sourcing cycles become shorter, onboarding faster, capacity is released for higher-impact work. Compliance can improve because the agent checks activity against policy, contracts, thresholds and preferred-supplier rules before completion. Fragmented data across


contracts, orders, invoices and supplier records becomes more usable in operational decision-making. Savings opportunities, contract leakage and duplicate suppliers surface earlier. Risk signals can escalate sooner. And employees may engage procurement through a conversational channel instead of forms and screens. The greatest gain often sits in the combination across the end-to-end process. That is exactly where you need stronger integration, ownership and control.


Six conditions without which you should not let an agent act


1. An explicit mandate


Every procurement agent needs a clear mandate: which objective, which limits, clear definitions, which systems and data, which actions, when to escalate, and who remains accountable. “Optimise sourcing” is not a mandate. A workable mandate authorises the agent to prepare a request for quotation and evaluate responses against fixed criteria, while requiring approval before an award decision goes outside the organisation.


2. Process first, technology second


An agent on an inefficient or fragmented process mainly automates complexity. First determine which steps are truly necessary, where professional judgement belongs, which exceptions arise, which approvals add value and which controls must remain. That requires clear definitions and a clear workflow. This is an operating-model question, not a pure IT implementation.


3. Reliable procurement data


Incomplete, outdated or inconsistent data leads to unreliable recommendations and actions. Supplier master data, contracts, spend classification, specifications, orders, invoices, performance, risk assessments, category strategies, authorities and policies must be in order. Agentic AI does not remove the need for data governance. It makes it more urgent.


4. Secure integration with least privilege


Value emerges when the agent can work with ERP, contract management and risk systems. Access must not create a bypass of approval limits, segregation of duties, budget controls, preferred-supplier policy, contractual authorities or data restrictions. Default: only the permissions required for the assigned task.


5. Risk-based human oversight


Not every action requires the same degree of human involvement. Low risk: the agent may execute and record. Moderate risk: act within limits, with monitoring or sample review. High risk: the agent recommends, a human approves. Critical: the agent analyses, but does not execute the decision. Supplier exclusions, final awards, contractual commitments, material pricing decisions and conflicts of interest belong with meaningful human review.


6. Audit trail and explainability


Procurement decisions must be reconstructable for management, auditors, regulators and suppliers. Record: the instruction, information used, criteria applied, systems accessed, alternatives considered, the recommendation, the approval or override, and the action taken. Without that path you buy a black box into your control framework.


What this means legally and for governance


Agentic AI touches mandate, liability, privacy, cybersecurity, supplier fairness, contractual commitment and demonstrable control. European regulation, including the AI Act and GDPR, makes that demonstrability not a luxury. If an agent communicates with suppliers, processes data or initiates transactions, you want to be able to explain in advance who is responsible for what. The core question for boards and CFOs is simple. Can you explain what the agent may do, which decisions stay with people, which limits and definitions apply, which workflows apply, which data and systems are accessible, how supplier fairness and confidentiality are protected, whether material actions are reconstructable, who is accountable when things go wrong, and how you measure value, errors and human overrides? Without clear answers, AI does not only accelerate the process. It also increases legal, financial and operational vulnerability.


How DH Legal supports organisations


DH Legal helps organisations make agentic AI in procurement legally sound and practically workable. We combine legal analysis with knowledge of governance, risk management, internal control, financial processes and assurance. That can include:

  • assessing proposed use cases

  • formulating agent mandates and delegated authorities

  • identifying legal, regulatory and contractual risks

  • designing human oversight and escalation

  • aligning permissions with procurement policy and approval matrices

  • governance frameworks and liability

  • reviewing supplier contracts and technology-provider agreements

  • requirements for documentation, definitions, workflows and audit trail

  • assessing data protection, cybersecurity and confidentiality


policies and control frameworks for implementation and assurance. The objective is not to block innovation. It is to introduce agentic AI in a way that is efficient, transparent and demonstrably controlled.


From experiment to controlled implementation


A sensible path is stepwise. First assist: analyse, draft documents, support users. Then recommend: propose decisions with evidence. Then act after approval. Then independently handle defined low-risk activities within limits. Only then coordinate


across an end-to-end process, while management retains grip on objectives, material decisions and exceptions. Each step needs appropriate governance, data quality, access control, monitoring and ownership. Start by setting definitions and locking workflows before autonomy increases.


Start with an Agentic AI Procurement Review


Considering an AI procurement agent, building a pilot or reviewing an existing implementation? DH Legal can run a focused review of your use case, identify the principal legal and control risks, and provide practical recommendations for responsible adoption based on definitions, workflows, risks and policy. The review can cover suitability of the use case, mandate and autonomy, human oversight, data and system access, alignment with procurement policy, legal and contractual requirements, control design, auditability and implementation priorities. Agentic AI can accelerate procurement, improve compliance and free capacity for more strategic work. The value depends on one demonstrable point: every agent operates reliably, transparently and within clearly defined boundaries. AI may do more. You remain accountable. DH Legal helps you turn that accountability into clear governance, legal safeguards and effective internal controls. Questions about mandate, limits or audit trail? Contact DH Legal.

 
 
 

Comments


bottom of page