Agentic AI is reshaping procurement as software negotiates, optimizes suppliers and gains economic authority, creating new governance risks.
What follows is a hypothetical, and nothing in the public record shows that it has happened. A manufacturer gives a software agent authority over a portfolio of several hundred suppliers. The agent scores each one continuously on delivery, defects, price, financial health, geopolitical exposure and compliance. One component supplier slips, slightly at first and then steadily. The agent prices the alternatives, finds that moving the volume improves its objective by more than the cost of switching, and issues a termination notice with a replacement purchase order. No executive decided anything; a policy executed itself. The supplier, which had been expanding capacity at the buyer’s request, learns of its fate from an automated message. The question that follows is less technical than constitutional: can a company delegate economic agency without delegating the responsibility that travels with it?
The evidence available in early October 2026 suggests that the scenario runs ahead of practice, though in a recognizable direction. The best-documented autonomous negotiation is narrow. Walmart, with more than 100,000 suppliers, used a negotiation agent from Pactum on “tail-end” suppliers whose terms would otherwise have gone unnegotiated, and after expanding beyond a Canadian pilot reported agreement with 68 percent of the suppliers approached and average savings of about 3 percent, starting with goods not for resale. Pactum’s September 2026 release notes now claim that its agents “close more agreements without a buyer in the loop,” with contracts executed through electronic signature. Larger platforms are more cautious. SAP’s sourcing assistant generates counteroffers from policy and bid data but is described as recommending awards, with general availability of its agentic version listed as the third quarter of 2026. Coupa says that in its autonomous sourcing flows humans stay in the loop for oversight and approval. No vendor material reviewed for this analysis describes autonomous supplier termination. Gartner, meanwhile, warns of “agent washing”, estimates that only about 130 of thousands of agentic vendors are real, and predicts that more than 40 percent of agentic projects will be canceled by the end of 2027.
The thesis that procurement is becoming an autonomous decision system therefore holds in a narrower form than the headline implies. Autonomy is arriving in increments, at the tactical edge where each decision is small and the volume is large, and the governance problem lives in the aggregate: thousands of low-stakes delegations that together amount to a decision-making institution. The firing is a feasible extrapolation, not a documented practice. The increments are already real.
That is why the line between recommendation and decision is better understood as a configuration screen than as a philosophical boundary. A setting that tells a negotiation agent how aggressively to push, a threshold below which no human sees the result, an escalation rule that defines “exception”: each is a grant of authority written as a parameter. Pactum itself offers an “aggressiveness control” for exactly this purpose. Where a manager approves 500 agent decisions in a morning with a click each, the approval is a formality unless the manager has the information, time and power to refuse. Singapore’s Infocomm Media Development Authority makes the test measurable in its framework for agentic artificial intelligence (AI): a low human override rate may signal rubber-stamping, and very short review times may signal automation bias or fatigue. The European Union’s Artificial Intelligence Act is more exact about what oversight requires, obliging providers of high-risk systems to let overseers understand the system, stay alert to automation bias, override it and stop it. The reasons for that wording are old: research on automation complacency has long documented how people over-rely on automated output. The premise that this statute governs procurement agents does not hold, however. Its list of high-risk uses covers areas such as employment and credit scoring of individuals, not corporate purchasing, and the high-risk obligations were in any case postponed to December 2027. Article 14 is a benchmark that a prudent buyer may borrow, not a rule that binds it.
Machine-to-machine bargaining is the least evidenced part of the picture. The plumbing is arriving: the Agent2Agent (A2A) protocol reached version 1.0 with more than 150 supporting organizations, and the Model Context Protocol (MCP) for connecting models to tools now sits in a neutral foundation. Those standards define how agents talk, not what they agree. No primary source reviewed shows independent buyer and supplier agents negotiating production contracts at scale; in the Walmart pilot the counterparty used a text interface. Laboratory work is more sobering. In a simulation of language-model agents negotiating consumer-product prices as buyers and sellers, stronger models systematically won better deals: weaker sellers earned about 9.5 percent less than in an even match, weaker buyers paid about 2 percent more, and some agents breached their own budget or cost-floor constraints. Negotiating capability thus becomes an asset that suppliers without comparable agents may lack. Separately, language-model pricing agents in a simulated duopoly reached prices above the competitive level without any instruction to collude, a result that held with a newer model in 2026. That setting concerns sellers, and whether buyer agents behave analogously is an inference, not a finding.
Once procurement is expressed as objectives, constraints and changing inputs, it invites autonomous optimization. In its simplest form the supplier-selection problem allocates demand across suppliers with landed unit cost :
where is capacity, a minimum allocation if supplier is used at all, records whether it is used, and caps the share of demand tolerated from any region or group . Quality, reliability, lead time and compliance enter as further constraints. Real systems replace cost with a weighted objective,
in which is procurement cost, logistics and lead-time cost, disruption risk, quality-related cost and geopolitical or geographic concentration risk. The coefficients are management’s strategic priorities written as numbers. Whoever sets them, together with the caps , has written the strategy the agent will pursue without fatigue or doubt. With and near zero and no cap , the mathematically correct answer is typically to concentrate volume with the cheapest capable supplier.
An illustrative calculation, with assumed inputs and not data, shows how a flawless optimizer can still be wrong. Suppose two suppliers each fail independently with probability a year, a full stoppage costs 40 percent of annual spend, losing half the supply costs 10 percent, and the second supplier charges a 3 percent premium on its half of the volume. Single sourcing carries an expected loss of percent of spend. A 50/50 split carries;
plus a 1.5 percent premium, or 2.55 percent in all. An agent minimizing expected cost keeps the single source, even though the probability of a full stoppage is 5 percent against 0.25 percent for the split, a twentyfold difference. A constraint capping that probability at 1 percent reverses the choice. Nothing in the agent’s reasoning was mistaken; the objective simply omitted what management cared about. The more serious danger of delegation may be a perfectly rational decision against the wrong objective, repeated across a portfolio until local optimization has produced global fragility.
History supplies the pattern. In February 1997 a fire at Aisin Seiki, the sole source of a brake valve used in every Toyota vehicle, threatened to halt the group when only two or three days of stock were on hand. Aisin was among Toyota’s most trusted suppliers, so a scorecard would plausibly have rated it highly; the exposure was concentration, not performance. Assembly resumed after two days largely because suppliers organized themselves to produce the part, a capacity that no delivery or defect metric records. The McKinsey Global Institute found that month-long disruptions strike industries every 3.7 years on average and that single sourcing can magnify the damage when it is not calibrated to risk. Context cuts the other way as well. A supplier’s late deliveries may be the echo of the buyer’s own erratic orders, the bullwhip effect in which demand signals distort as they travel upstream, and an agent that acts in seconds on a deteriorating score may have no way of knowing it. Human cycles of days and weeks are slow, but the delay is often where context arrives.
The legal position is clearer on some points than the debate suggests. Whether software can form a contract is largely settled: the Uniform Electronic Transactions Act (UETA) of 1999, as enacted in Texas, allows a contract to form through the interaction of electronic agents even if no individual reviewed their actions, and the federal Electronic Signatures in Global and National Commerce Act bars denying a contract’s validity solely because electronic agents acted, “so long as the action of any such electronic agent is legally attributable to the person to be bound.” The United Nations Convention on the Use of Electronic Communications in International Contracts says much the same in its article 12. The open question is attribution and authority. Under apparent authority doctrine, a principal is generally bound by an agent’s acts within the authority a third party reasonably perceives, even where undisclosed limits were imposed; applying that to software is an analogy that courts have not tested for procurement. A British Columbia tribunal did reject an airline’s suggestion that its chatbot was “a separate legal entity that is responsible for its own actions” in Moffatt v. Air Canada, though a small-claims decision about a misstatement is no precedent for contract formation. For the counterparty, therefore, the safer working assumption is that the company decided. Recourse against the vendor or integrator is a matter of contract, because the European Union’s revised Product Liability Directive compensates death, personal injury, property not used exclusively for professional purposes and non-professional data, not a company’s procurement losses, and the European Commission withdrew its AI liability proposal in October 2025. The Law Commission of England and Wales has flagged possible “liability gaps” while noting that they are not guaranteed to arise. Three levels of autonomy are also not equivalent: AI-generated text, AI-assisted decisions and AI-executed contractual action raise different questions. A termination notice that ignores a cure period can be a breach by the buyer, whoever or whatever pressed the button.
Security changes character in the same move. Business email compromise cost victims $3.05 billion in reported losses across 24,768 complaints in 2025, according to the Federal Bureau of Investigation (FBI)’s Internet Crime Complaint Center (IC3), and the scheme works by persuading a person to authorize a payment. An agent that executes removes that human gate and replaces it with inputs to be corrupted. The Open Worldwide Application Security Project’s top ten for agentic applications lists goal hijacking, identity and privilege abuse, memory poisoning, cascading failures and polished explanations that mislead human approvers. The National Institute of Standards and Technology (NIST) found in a benchmark exercise that new attacks raised agent-hijacking success from 11 percent to 81 percent, though not in a procurement setting. The target shifts from stealing information to seizing economic agency: an attacker who cannot read a database but can alter a supplier ranking, a risk threshold or a payment term achieves much the same end.
Suppliers will adapt to the score. Once ranking criteria are machine-readable and consequential, suppliers have reason to optimize the metric rather than the performance it was meant to measure, the dynamic summarized as Goodhart’s law. Data readiness is uneven. In the European Union in 2025, 41 percent of small enterprises used enterprise resource planning software against 89 percent of large ones, in a survey that omits firms with fewer than 10 employees. A plausible inference is that sparse data reads as uncertainty, which an objective prices as risk, so smaller suppliers lose business to firms that are merely better documented. No study reviewed measures whether supplier scoring actually produces that effect, so it remains a hypothesis worth testing before it becomes a procurement outcome.
Concentration is the paradox on which the rest depends. Companies deploy agents to improve resilience, but agents trained on similar data and optimizing similar variables may converge on the same few suppliers, so decentralized decisions produce a centralized exposure. This is inference, not documented fact. The nearest evidence comes from competition policy, which concerns sellers. The UK Competition and Markets Authority catalogs hub-and-spoke and autonomous coordination scenarios, says the current reality of agentic AI “may be modest,” and notes research suggesting that more diverse agents reduce collusion risk, which makes diversity a design variable. The U.S. Department of Justice’s proposed settlement with RealPage concerned software alleged to have relied on rivals’ nonpublic data to set rents. Whether shared benchmark pools among buyers raise parallel questions is unresolved.
Governance therefore has to be designed before autonomy scales, and several of the needed controls already exist in financial practice. Authority is a delegation-of-authority matrix extended to software, with spend limits by category and supplier tier, in the spirit of Singapore’s advice to grant least-privilege access and approval thresholds for purchases. Constraints belong outside the model, as hard limits on supplier share, regional share and payment terms, because the same framework prefers deterministic limits to instructions written into prompts. Explainability means a decision log recording inputs, weights and alternatives considered, enough for a reviewer to reconstruct why a supplier lost volume. Escalation should capture terminations, new-vendor onboarding, payment-term changes and statistical outliers, with override rates and review times monitored to confirm that escalation is real. Reversibility is the control most often forgotten: cooling-off periods before a termination takes effect, a stop mechanism, and the recognition that a contract signed electronically cannot be recalled, so the gate must sit before signature. Shadow-mode operation, where the agent decides but nothing executes, and red-teaming against the attack classes above test the whole structure. Accountability stays with the corporation, and voluntary structures such as the NIST AI Risk Management Framework and ISO/IEC 42001, which sets requirements for an AI management system, offer ways to assign it to named owners. In practice the most important owner is whoever holds the objective function.
The sharper question is not whether AI will replace procurement jobs. It is how much economic authority a corporation should delegate to software before the software becomes part of the corporation’s decision-making institution. The defining issue is not whether machines can make procurement decisions, which within narrow bounds they increasingly can, but which decisions corporations let them make, under what constraints, and who remains accountable when the software gets it wrong.
Apple News, Google News, Feedly, Flipboard, and WhatsApp Channel



