DECISION BRIEF 17 | AI STRATEGY AND CAPITAL ALLOCATION | 10 SEPTEMBER 2026

AI Procurement: Make Exit Costs Visible Before You Buy

AI procurement should not end with selecting the most impressive model or the lowest introductory price. The CEO should approve a material AI commitment only after the company can prove the business outcome, control its data, see consequential changes, intervene when performance fails, and move critical work elsewhere.

An AI supplier can change models, routing, prices, policies, subprocessors, and product boundaries while the workflow remains embedded in your operation. The contract therefore has to protect both value creation and the company’s capacity to change course.

Decision Brief 17 | Evidence reviewed 10 September 2026 | Scope: Indonesia and Southeast Asia, informed by public procurement evidence from the United States, United Kingdom, and ASEAN guidance

Key evidence signals

The evidence does not prove that every AI contract creates lock in. It shows why conventional software procurement leaves important AI risks outside the buying decision.

Signal Leadership implication Scope and limitation
13 acquisitions The US Government Accountability Office found recurring trade offs involving requirements, data rights, testing, performance, cost, and vendor oversight. GAO reviewed 13 acquisitions at four US federal agencies through fiscal year 2025. Public sector findings are design evidence, not a prevalence estimate for private companies in Southeast Asia.
Four agencies The selected agencies were not systematically collecting lessons learned, including useful terms on data rights and testing. GAO published the finding on 13 April 2026. All four agencies agreed with the recommendations, but implementation outcomes were not yet available.
Five control areas A proposed GSA clause covers data and IP, documentation, privacy, portability, change notification, performance, and remediation across multiple provider roles. Federal Register notice dated 17 June 2026. It applies to a defined US government context and is not binding on Indonesian private companies.
Relative index 43 AI procurement led three comparison terms worldwide over 90 days. Google Trends average through 10 September 2026. The index is relative, not search volume, and the query has mixed intent.

Direct answer

Buy the outcome, but contract for change. A CEO should treat replaceability as part of the initial investment case, not as a legal clean up exercise after adoption.

This does not mean forcing every supplier into a short contract or running several models at all times. It means knowing which parts of the workflow must remain portable, what evidence the supplier must provide, and what it would cost to keep operating if the relationship changes.

The decision question

Can the company approve this supplier without making a critical workflow dependent on claims it cannot independently verify? If the answer is no, the procurement is not ready for a long term commitment.

The useful question is not, “Which model is best?” Model quality matters, but it can change. The more durable question is whether the company can govern the whole service across data, prompts, retrieval, integrations, human review, pricing, incidents, and exit.

The conventional assumption being challenged

Traditional software procurement assumes that the product is reasonably stable, the scope is visible, and switching is mainly a migration project. AI weakens all three assumptions.

A demonstration may use curated data and limited scenarios. Production use adds confidential information, exception cases, evolving user behavior, and integrations with systems of record. A supplier may also route work through models or subprocessors that were not visible in the original demonstration.

The legacy buying pattern is to negotiate price, security, service levels, and renewal terms after a preferred vendor emerges. For AI, those discussions must include evaluation, model change, data use, human intervention, and migration evidence before the preference becomes difficult to reverse.

What AI changes

AI turns a software contract into an ongoing allocation of agency, information, and operational dependency. The system can influence decisions even when it does not hold formal decision rights.

Five changes matter to the CEO:

  1. Performance is probabilistic. The same workflow can produce different quality across cases, languages, data conditions, and model versions.
  2. The service can change underneath the workflow. Model routing, safety policies, context limits, prices, and supporting components may change without a conventional product release.
  3. Data moves through a chain. Prompts, source documents, outputs, logs, feedback, embeddings, and tool calls may involve several parties.
  4. Switching cost is architectural. Migration can require rebuilding evaluations, prompts, retrieval, workflow logic, permissions, and user behavior, not merely exporting records.
  5. Accountability remains human. A supplier can operate the technology, but the company remains responsible for where AI is used, what evidence is accepted, and which consequences are tolerable.

Point of view

The strongest AI contract is not the one with the most clauses. It is the one that makes business performance, control, and exit testable before dependence becomes material.

Legal language cannot repair a workflow that has no accepted outcome, no baseline, and no owner. Nor can a strong technical architecture compensate for a commercial agreement that hides price changes or blocks access to operational data.

The procurement decision must connect four systems at once: value creation, operating model, technical architecture, and contractual rights. Fragmenting them into separate approvals produces a supplier decision without a coherent company position.

Thought process

Start with the business outcome, then map every dependency required to produce it. Only after that should the team negotiate the commercial commitment.

Use this sequence:

  1. Define the decision or workflow outcome the business will accept.
  2. Establish current cost, quality, cycle time, and risk without the new service.
  3. Map the model, data, retrieval, tools, integrations, and human review needed.
  4. Identify which components can be substituted and which create hard dependency.
  5. Turn each critical dependency into evidence, a contract term, an operating control, or a stop condition.
  6. Rehearse failure and migration before expanding the commitment.

The goal is not zero dependency. Every strategic supplier creates some dependency. The goal is a dependency that leadership has priced, bounded, and chosen deliberately.

Five tests before signing

A material AI contract should pass five tests. A polished demonstration is not evidence that the production relationship can pass them.

1. Outcome test

The contract should name the business result and how performance will be evaluated after deployment.

Define accepted outcomes, rejected outputs, comparison baselines, evaluation data, review frequency, and remediation. Avoid paying for activity when the investment case depends on a verified result.

Questions to settle:

  1. What result is the company buying?
  2. Who accepts or rejects it?
  3. Which quality and risk thresholds apply?
  4. What happens when performance degrades?

2. Data and IP test

The company should know what enters the system, what is created, who can use it, and what can be retrieved on exit.

The map should cover prompts, source documents, outputs, feedback, logs, embeddings, fine tuning assets, and derived data. It should also distinguish company data from supplier background technology and third party components.

3. Change visibility test

Material changes should trigger notice, revalidation, or approval according to their consequence.

Not every model update needs CEO attention. Changes to data use, model family, system behavior, subprocessors, jurisdiction, pricing logic, or high impact controls may require a new review.

4. Oversight and intervention test

The operating team must be able to see failures, stop unsafe actions, preserve evidence, and restore service.

Logs, incident notification, human intervention, access controls, evaluation results, and remediation responsibilities should be usable in the real workflow. Documentation that cannot support an operational decision is not sufficient oversight.

5. Exit and continuity test

The company should prove that it can export the necessary data and keep the critical process running under a credible alternative.

Specify format, metadata, timing, support, deletion, transition assistance, and the treatment of prompts, evaluations, and workflow logic. An exit clause without a migration rehearsal is an untested promise.

Options and trade offs

There is no universally correct sourcing model. The CEO should choose the dependency profile that fits the value, speed, capability, and risk of the workflow.

Option Best fit Main advantage Main trade off
Extend an incumbent platform A narrow, lower risk workflow already sits inside a governed system of record. Faster adoption and simpler integration. Less visibility into model routing and fewer substitution choices.
Buy a specialist managed service The supplier brings distinctive workflow expertise and measurable performance. Faster access to domain capability. Higher dependency on vendor data models and operating knowledge.
Use a modular or multi model design The workflow is material and benefits from substitutable components. More leverage and resilience. More integration, evaluation, and operating complexity.
Build selected components The data, workflow logic, or control layer is strategically differentiating. Greater control over critical assets. Higher talent, maintenance, security, and capital burden.

Decision rights

The CEO should decide the acceptable dependency, not negotiate every clause. Execution belongs to accountable specialists with clear escalation rules.

The CEO should:

  1. Decide the business outcome, maximum acceptable dependency, protected assets, and conditions for scaling or stopping.
  2. Delegate commercial terms to procurement and legal, architecture to the CTO or CIO, security controls to the CISO, and workflow acceptance to the business owner.
  3. Instrument quality, total cost, model or supplier changes, incidents, human overrides, and migration readiness.
  4. Escalate material changes in data use, control, jurisdiction, performance, pricing, or supplier concentration.
  5. Stop any irreversible commitment when the company cannot establish data rights, evaluation evidence, operational intervention, or a credible continuity plan.

A 60 day evidence test

Before a multi year commitment, run one production shaped test that includes both normal performance and a controlled exit rehearsal. Keep the scope narrow enough to reverse.

Days 1 to 10: Define the outcome

  1. Select one material but bounded workflow.
  2. Record the current cost, quality, time, and failure profile.
  3. Define accepted outcomes and the human owner.
  4. Map protected data and required controls.

Days 11 to 25: Demand supplier evidence

  1. Run the supplier on representative cases, including exceptions.
  2. Inspect data handling, model routing, logs, and subprocessor roles.
  3. Record full workflow costs, not only licence or token prices.
  4. Agree which changes require notice or revalidation.

Days 26 to 40: Rehearse intervention and exit

  1. Trigger a safe failure scenario and verify intervention.
  2. Export data, outputs, logs, evaluations, and relevant metadata.
  3. Reconstruct the minimum viable workflow with an alternative provider or manual fallback.
  4. Measure time, cost, missing assets, and loss of quality.

Days 41 to 60: Decide

  1. Compare the accepted outcome economics with the baseline.
  2. Price the residual dependency and migration burden.
  3. Close gaps through design, contract terms, or operating controls.
  4. Approve, limit, renegotiate, or stop the commitment.

Testable hypotheses

The test should disprove weak assumptions before the contract hardens them. Use hypotheses that can fail.

  1. The service improves cost, quality, or cycle time on accepted outcomes without adding unacceptable risk.
  2. The company can detect a material change in performance or supplier configuration.
  3. Required data and operating evidence can be exported in usable formats with adequate metadata.
  4. A named owner can intervene, continue the process manually, or route it to an alternative.
  5. The measured cost of switching remains within the dependency approved by the CEO.

The decision threshold

Approve a material commitment only when all five areas have adequate evidence. A weakness in one area may justify a limited pilot, but not an irreversible scale decision.

Approve when:

  1. The business outcome and acceptance method are explicit.
  2. Data and IP rights match the operating reality.
  3. Material changes are visible and actionable.
  4. Oversight and intervention work under test.
  5. Exit and continuity are credible, costed, and rehearsed.

Renegotiate when the business case is sound but the contract or architecture does not preserve the required control. Stop when the supplier cannot provide evidence for a critical dependency or when the company cannot name an accountable business owner.

Implications for decision makers

AI procurement is an operating model decision disguised as a buying process. Senior leaders should judge it by the quality of the dependency the company is choosing.

For the board, ask whether management can explain concentration, data rights, material changes, and continuity for critical AI workflows. For the CEO, connect supplier approval to a named business outcome and dependency limit. For the CFO, price the full workflow and the switching burden. For technology and security leaders, make model routing, data flows, intervention, and migration observable. For procurement and legal, convert those operating requirements into enforceable terms.

The irreducible leadership responsibility is to choose which dependence the company will accept in exchange for speed and capability. No model evaluation or legal review can make that judgment on the CEO’s behalf.

Frequently asked questions

What is AI procurement?

AI procurement is the process of defining, evaluating, contracting,
and governing an external AI capability. It includes the model, data,
integrations, operating controls, performance evidence, commercial
terms, and exit plan.

How is buying AI different from buying ordinary software?

AI performance can vary by case and change with models, data,
routing, and policies. The buyer therefore needs continuing evaluation,
change visibility, and intervention rights in addition to conventional
price, security, and service terms.

Should every AI contract require multiple vendors?

No. Multi vendor operation can add cost and complexity. The
requirement is credible continuity and a deliberately chosen dependency,
which may be satisfied by portability, a manual fallback, modular
architecture, or a second provider for critical workflows.

What should a CEO personally decide?

The CEO should decide the business outcome, acceptable dependency,
protected assets, and conditions for scaling or stopping. Specialists
should negotiate and operate the detailed controls.

When should the company walk away from an AI vendor?

Walk away when a critical dependency cannot be tested, data rights
are incompatible with the workflow, material changes cannot be seen,
intervention is ineffective, or continuity costs exceed the approved
business case.

Evidence ledger

Source Date Claim supported Limitation
US Government Accountability Office, AI Acquisitions 13 April 2026 AI buying involves trade offs in requirements, data rights, testing, performance, cost, and oversight. The review covered 13 acquisitions and found four selected agencies were not systematically collecting lessons learned. US federal public sector evidence through fiscal year 2025.
US Federal Register, proposed GSA LLM safeguarding clause 17 June 2026 Useful contract areas include data and IP, documentation, privacy, portability, change notice, performance, remediation, and responsibility across supplier roles. Proposed US government clause with a defined scope. Not binding on private companies in Southeast Asia.
GSA, Buy AI Updated 1 September 2026 AI procurement is moving into formal contracting channels and government wide buying vehicles. Describes United States federal procurement options.
UK Government AI Playbook 10 February 2025 Start requirements with the problem, data strategy, supplier approach, integration, and vendor lock in considerations. Government guidance, not a private sector contract standard.
Expanded ASEAN Guide on AI Governance and Ethics January 2025 Regional guidance connects accountability, data, trusted deployment, incident reporting, testing, assurance, and security. Voluntary policy guidance. It does not replace national law or private legal advice.
Google Trends Accessed 10 September 2026 AI procurement led the three comparison terms worldwide and recorded the strongest signal in Indonesia on the latest complete day, 9 September. Relative index, mixed query intent, not absolute volume or demand forecast.

Source notes

Evidence was reviewed on 10 September 2026. Public procurement sources are used as design evidence because they make requirements visible. They are not presented as rules that automatically apply to Indonesian or Southeast Asian private companies. Local counsel and control owners should map any contract to the company’s jurisdiction, industry, data, and risk profile.

Language version

Baca dalam Bahasa Indonesia: Pengadaan AI

Continue Reading

  1. AI Cost Management: Measure Cost per Business Outcome
  2. AI Data Center Strategy: Build, Rent, or Partner?
  3. AI Agent Security: Three Controls Before Granting Autonomy
  4. AI Policy: What CEOs Should Permit, Monitor, Prohibit

About the author

Antovany Reza writes CEO Decision Lab, an independent decision platform for AI fluent CEOs and senior leaders. The work connects emerging technology with business value, operating model design, governance, trust, and accountable execution.

Invitation to discuss

If your company is evaluating a material AI supplier, the useful conversation begins before the preferred vendor is locked in. Antovany works with leadership teams to clarify the decision, evidence, trade offs, decision rights, and smallest credible test. Discuss an executive decision.

Share


Discover more from Antovany Reza

Subscribe to get the latest posts sent to your email.

Discover more from Antovany Reza | The CEO Decision Lab

Subscribe now to keep reading and get access to the full archive.

Continue reading