Skip to content

AI agents in procurement: where controls belong

Procurement agents can research suppliers, compare offers, prepare orders, and monitor routine work. The moment they can request a purchase, the business needs a separate authority layer.
By Arnav Kakar 12 minute read

The operating principle

Use AI agents to reduce procurement work, not to invent their own purchasing authority. The agent can discover, analyze, recommend, and submit. A deterministic control layer should decide whether the request fits the company's budget, supplier, category, geography, timing, and approval rules.

What procurement means

Procurement is how a business obtains the goods and services it needs. It includes identifying a need, finding suppliers, comparing terms, selecting a vendor, obtaining approval, creating an order, receiving what was purchased, and maintaining the supplier relationship.

Buying office chairs is procurement. So is renewing Notion, sourcing a new cloud vendor, arranging business travel, or ordering components from a manufacturer. The process can be simple for a small company and highly controlled for a large one, but the financial question is the same: who is allowed to commit the business, for what, and within which limits?

Where AI agents can help

IBM's overview of AI agents in procurement describes use cases across supplier, contract, order, pricing, and market analysis workflows. Those use cases cover different levels of consequence, so they should not all receive the same autonomy.

ActivityUseful agent roleAuthority needed
Supplier researchCollect candidates and compare published factsRead-only access to approved sources
Quote comparisonNormalize prices, terms, and delivery windowsNo purchasing authority
Renewal monitoringFind upcoming renewals and prepare a recommendationRead access to contracts and usage data
Purchase requestSubmit merchant, amount, category, and justificationScoped request credential and mandate
Autonomous routine orderRequest an in-policy repeat purchaseDeterministic approval within narrow limits
Supplier or policy changePrepare a proposal for a personHuman approval; agent cannot self-approve

One controlled procurement-agent journey

A startup creates an agent named Procurement Desk to manage routine software and office-equipment requests. Its monthly budget is $2,000, its autonomous transaction limit is $250, and it may use only US merchants in approved categories. New merchants require review; cryptocurrency and gambling are blocked.

  1. 01Need appearsA team requests a Notion renewal and the agent gathers the plan, merchant, amount, and category.
  2. 02Agent submitsProcurement Desk sends a structured $96 software request using its own scoped key.
  3. 03Policy checksThe server verifies the agent, active mandate, remaining budget, amount limit, category, merchant, country, and expiration.
  4. 04Risk checksThe engine evaluates novelty, amount anomaly, velocity, category mismatch, and geography.
  5. 05Decision returnsA known Notion renewal can be APPROVED. A first-time Notion purchase can be APPROVAL_REQUIRED. A blocked category is DECLINED.
  6. 06Evidence remainsThe business can inspect the original intent, agent, request, rule results, risk factors, decision, and human resolution.

The minimum procurement mandate

  • Purpose: the business job the agent is allowed to perform.
  • Budget: aggregate exposure for a month or another defined period.
  • Transaction limit: the largest request eligible for autonomous approval.
  • Categories: what kinds of goods and services fit the job.
  • Suppliers: approved, blocked, and first-time merchant treatment.
  • Geography: allowed countries and international-review rules.
  • Time: activation, expiration, and renewal cadence.
  • Escalation: which conditions require a named human role.

These controls should be structured data, not a paragraph that an agent reinterprets for each purchase. Natural language can help draft the policy, but the user must review the fields and activate a version that deterministic code can evaluate.

New suppliers deserve special treatment

A new supplier introduces uncertainty that a familiar recurring merchant does not. The business may need to verify legal identity, tax information, security posture, sanctions exposure, contract terms, data handling, delivery capability, or bank details. An agent's ability to find a compelling offer is not evidence that those checks passed.

A practical default is to route first-time merchants to human approval and display why the supplier is new. Later repeat purchases can qualify for narrower autonomy if the supplier remains approved, the category matches, and the amount fits the mandate.

Prompt injection is a procurement risk

Procurement agents read content controlled by other parties: supplier websites, quotes, PDFs, emails, catalogs, contracts, and tool output. Any of that content can contain instructions designed to redirect the agent, expose data, change a destination, or trigger an unauthorized tool call.

Filtering suspicious phrases is useful but insufficient. The authorization service should accept a narrow transaction schema, derive organization and agent identity from authenticated credentials, reject extra fields, and keep policy mutation behind separate user permissions. Untrusted text should never be able to change budgets, merchant rules, approvers, or payment destinations.

For a deeper threat model, read prompt injection and AI-agent payments.

Risk scores should escalate, not grant authority

An agent's request may be in an allowed category and still look unusual. It could be much larger than the agent's prior purchases, arrive after several rapid requests, come from an unexpected country, or involve a new supplier.

Those signals can require review or strengthen a decline. They should not override a hard policy failure. A low anomaly score cannot make a blocked supplier eligible or restore a revoked agent. Keep policy reasons and risk factors distinct so procurement and security teams can understand what happened.

How to introduce procurement agents safely

  1. Begin with research and request preparation, where the agent cannot commit funds.
  2. Choose one narrow category with predictable merchants and transaction amounts.
  3. Set a small budget and require approval for every new merchant.
  4. Test approved, review, and declined scenarios before granting autonomy.
  5. Monitor decisions, false positives, policy changes, and credential usage.
  6. Expand scope only after evidence shows the controls work as intended.

IBM similarly recommends gradual introduction, clear standards, accurate data, and human preparation. The important point is that the pilot should test the control system as carefully as it tests the agent.

What Mandate adds to a procurement stack

A procurement platform, ERP, supplier portal, or commerce protocol can provide data and execution surfaces. Mandate is designed as the decision gateway between an agent's proposed purchase and those downstream systems: authenticate the agent, load its authority, evaluate policy and risk, involve a person when required, and return explainable evidence.

Start by defining spending limits for the procurement agent. Then review the full agentic-payment architecture and the structure of an AI-agent payment mandate.