Show pageOld revisionsBack to top This page is read only. You can view the source, but not change it. Ask your administrator if you think this is wrong. ====== AI Procurement ====== **Knowledge Bundle:** Public-Sector AI Readiness **Concept ID:** government:ai_procurement **Concept Type:** Procurement Guidance **Status:** Draft **Audience:** Procurement staff, IT teams, legal counsel, department leaders, vendors **Steward:** OKF Expert **AI Use:** Human-reviewed **Last Reviewed:** June 2026 ===== Purpose ===== AI procurement is the process of evaluating, purchasing, contracting for, and managing artificial intelligence tools or services in a way that protects the agency, the public, and the integrity of government operations. AI tools should not be purchased solely because they are popular or impressive. They should be evaluated based on the problem they solve, the risks they introduce, the data they require, and the agency’s ability to govern their use. ===== Procurement Questions ===== * What specific business problem will the AI solution address? * Is AI necessary, or would a simpler tool solve the problem? * What data will the vendor collect, process, store, or retain? * Will the vendor use agency data to train its models? * Where will data be stored? * What cybersecurity standards apply? * What privacy protections are required? * Can the agency audit or review the vendor’s performance? * Can the agency export its data if the contract ends? * What happens if the vendor changes pricing, features, models, or terms of service? * What human review and accountability requirements apply? ===== Recommended Procurement Requirements ===== * Clear scope of work * Data ownership provisions * Data retention and deletion requirements * Confidentiality and privacy protections * Cybersecurity requirements * Incident notification requirements * Limits on vendor model training using agency data * Accessibility requirements * Audit and reporting rights * Performance measures * Exit and transition provisions * Requirement for human oversight where appropriate ===== Vendor Evaluation Categories ===== ^ Category ^ Questions to Ask ^ | Security | How does the vendor protect data, manage access, and respond to incidents? | | Privacy | What data is collected, retained, shared, or used for model training? | | Transparency | Can the vendor explain how the system works and what its limitations are? | | Reliability | What happens when the system produces inaccurate, incomplete, or harmful output? | | Accessibility | Does the tool support accessible public services and staff use? | | Interoperability | Can the agency export data and integrate with existing systems? | | Governance | Does the vendor support audit logs, administrative controls, and human oversight? | ===== Procurement Record ===== For each AI purchase, the agency should maintain a record including: * Proposed use case * Responsible department * Vendor name * Data involved * Risk level * Required approvals * Contract protections * Review date * Renewal or termination conditions ===== Related Concepts ===== * [[government:ai_governance|AI Governance]] * [[government:ai_risk_assessment|AI Risk Assessment]] * [[government:approved_ai_use_cases|Approved AI Use Cases]] * [[government:vendor_requirements|Vendor Requirements]] * [[government:ai_readiness|Return to Public-Sector AI Readiness]] government/ai_procurement.txt Last modified: 2026/06/22 00:22by leonidas Log In