AI vendor selection is not software procurement

TL;DR AI
2 min readKey summary
AI procurement needs its own review because model access, training use, and sub-processing create risks that ordinary SaaS checklists do not cover.
The article says prompts and customer data may be used for training, embedded in model weights, or routed through undisclosed sub-processors.
It argues ISO 42001 is a more relevant governance standard for AI vendors than SOC 2 or ISO 27001 alone.
Examples like AWS Bedrock, Anthropic Claude, Azure OpenAI, and Salesforce show that similar products can have very different data-access and compliance terms.
Procurement teams should do AI-specific due diligence to avoid contractual, regulatory, operational, and lock-in risk.
