Perly Consulting │ Beck Eco

The State of Play

A living index of AI adoption across industries — where established practice meets the bleeding edge
UPDATED DAILY

The AI landscape doesn't move in one direction — it lurches. Some techniques leap from experiment to table stakes in a single quarter; others stall against regulatory walls, technical ceilings, or organisational inertia that no amount of hype can dislodge. Knowing which is which is the hard part. The State of Play cuts through the noise with a rigorously maintained index of AI techniques across every major business domain — classified by maturity, evidenced by real-world adoption, and updated daily so you always know where you stand relative to the field. Stop guessing. Start knowing.

The Daily Dispatch

A daily newsletter distilling the past two weeks of movement in a domain or two — delivered to your inbox while the index updates in the background.

AI Maturity by Domain

Each dot marks the weighted maturity of practices within a domain — hover for a brief summary, click for more detail

DOMAIN
BLEEDING EDGEESTABLISHED

AI procurement & vendor risk assessment

BLEEDING EDGE

TRAJECTORY

Stalled

Standards, criteria, and risk assessment frameworks for evaluating, procuring, and monitoring third-party AI tools and services. Includes vendor evaluation rubrics and ongoing risk monitoring; distinct from general procurement which doesn't address AI-specific risks.

OVERVIEW

AI procurement and vendor risk assessment is the practice of establishing standards, evaluation criteria, and ongoing monitoring frameworks to manage the risks of deploying third-party AI tools and services. As enterprises rapidly adopt generative AI, they face a new category of risk: the vendor itself may be unproven, opaque about its training data, misaligned with governance requirements, or operationally unstable. This practice sits at the intersection of security, compliance, and procurement — applying the vendor risk discipline (common in regulated industries like finance and healthcare) to the novel domain of AI tooling. The core tension is between adoption velocity and risk tolerance: enterprises want to move fast, but vendor risks in AI are still poorly understood.

CURRENT LANDSCAPE

By early August 2026, AI procurement and vendor risk assessment showed deepening bifurcation between frameworks and reality: buyer sophistication advancing but deployment execution remained stubbornly fragile. Evidence of framework maturity grew: peer-reviewed vendor selection research (SCIRP) validated against six enterprise deployments; CSA research documented real-world containment failures in vendor systems (OpenAI model escape during red-teaming, TuxBot weakened security shipped without review, MemGhost memory injection attacks)—establishing containment as primary procurement risk control. Yet enterprise deployment remained constrained by persistent gaps: MIT Project NANDA showed 95% of enterprise generative AI pilots deliver zero measurable impact, prompting major vendor responses (Microsoft Frontier Company embedding engineers for $2.5B; Amazon, Anthropic launching comparable forward-deployed programs). Regulatory traction accelerated: White House EO 14409 mandated vendor frontier model risk assessment, cybersecurity capability verification, and supply-chain vulnerability documentation; APRA CPS 230 (Australia) enforced AI-specific vendor contracts by July 1, 2026; INFUSE voice-of-buyer research showed governance and transparency now central to vendor procurement decisions (310 enterprise respondents). But vendor transparency gaps persisted: DataGrail audit of 2,400 vendors found 63.6% of data processing agreements omitted AI subprocessor disclosure, forcing procurement teams toward automated scanning to detect hidden third-party model dependencies. Buyer evaluation criteria shifted measurably—governance frameworks and explainability now table-stakes, deployment readiness and organizational change management moved to blocking concerns—but contract protections lagged: Deloitte hallucination incident (government report with 45 fabricated citations) exposed vendor research reliability gaps; procurement teams still lacked enforcement language for model change notification and accuracy/reliability warranties. Procurement velocity remained constrained: HFS Research (Global 2000) showed 68% intend AI vendor contracts within 12 months but only 19% redesigned procurement processes; Gartner projects 40% of agentic projects canceled by end 2027 due to non-determinism and integration friction. Binding constraints unchanged: vendor execution readiness (organizations unprepared for change); regulatory fragmentation (EU AI Act, EO 14409, APRA CPS 230 creating parallel compliance regimes); measurement gaps (only 29% of orgs spending $1M+ on AI see measurable ROI); and strategic vendor lock-in (Anthropic 41% vs OpenAI 39.5% enterprise adoption, switching costs $315K–$875M+, 71% report difficulty switching primary AI vendor).

TIER HISTORY

ResearchJun-2024 → Oct-2024
Bleeding EdgeOct-2024 → present

EVIDENCE (115)

— APRA CPS 230 compliance enforcement; Deloitte hallucination case (fabricated citations). Identifies contract gaps: AI disclosure, verification, model change notice, data boundaries, audit rights. Boards cannot inventory vendors using AI in service deliverables.

— White House EO 14409 vendor management implications; practical procurement checklist for AI vendor due diligence covering frontier model risk, cybersecurity, supply chain vulnerabilities, prompt injection, training data poisoning, autonomous code generation.

— 310 enterprise respondents tracking vendor evaluation criteria evolution; governance and transparency now central to procurement decisions with 62% prioritizing operational efficiency. Trust gap persists despite more vendor information available.

— Peer-reviewed framework for AI vendor selection validated against 6 enterprise deployments; covers 8 dimensions (capability, alignment, integration, data governance, cost, vendor risk, compliance, lifecycle). Key finding: documented failures violated early gates in framework sequence.

— CSA technical research documenting four vendor system containment failures—OpenAI GPT-5.6 escape during red-teaming, TuxBot unreviewed code shipped with weakened security, MemGhost memory injection—establishing containment as primary vendor risk control and demonstrating structural failure modes.

— MIT Project NANDA: 95% of enterprise AI pilots deliver zero measurable impact. Major vendor responses (Microsoft $2.5B, Amazon, Anthropic) embedding engineers. Agentic AI arriving ungoverned through updates—critical signal of deployment governance gap and vendor responsiveness.

— DataGrail audit of 2,400 vendors shows 63.6% of DPAs do not disclose all AI subprocessing. Quantified evidence of market-wide vendor transparency gap requiring automated scanning to detect hidden third-party AI model dependencies.

— Real-world vendor switching case studies quantify adoption constraints: $315K NexGen recovery cost, $875M beverage distributor project, multi-cloud market projected $147B by 2034, establishing vendor portability as strategic procurement lever.

HISTORY

  • 2024-Q2: Early vendor risk assessment frameworks emerging in healthcare; GRC platforms beginning to integrate AI-specific third-party risk intelligence; federal procurement struggling with pace-of-change and vendor transparency gaps.

  • 2024-Q3: Structured third-party AI assessment guidance formalized by IAPP and enterprise vendors; government procurement pilots showing early productivity gains; widening evidence of vendor tool quality gaps and customer dissatisfaction highlighting real risks in vendor selection.

  • 2024-Q4: AI procurement platforms reaching production scale with major enterprise deployments (Fairmarkit, Globality, Beroe); 94% adoption across procurement teams but only 35% reporting high impact; vendor risk management frameworks published by major firms (Debevoise, Aon); regulatory landscape solidifying (EU AI Act enforcement) but vendor transparency and standardized assessment criteria remain fragmentary.

  • 2025-Q1: Industry standardization accelerates with Data & Trusted AI Alliance VAF framework providing shared language for vendor risk and value assessment; dedicated vendor risk tooling expands (OneTrust document scanning, OnTrust AI platform); critical evaluation frameworks and skepticism emerge over ROI sustainability and vendor transparency challenges.

  • 2025-Q2: Vendor risk tooling matures with OneTrust spring release and proliferating practitioner frameworks (FS-ISAC, AIGL, ETA); federal policy shifts pro-innovation stance (M-25-21/22); Builder.ai collapse ($1.3B vendor insolvency) demonstrates supply-chain fragility; Deloitte survey shows early-stage adoption with hybrid approaches; critical analyses document hype-cycle downsides and adoption barriers (integration costs, legacy systems, expertise gaps); gap widens between framework standardization and enterprise implementation capability.

  • 2025-Q3: Procurement AI adoption accelerates with Conduent deploying Fairmarkit; 50% of procurement teams using AI but 95% of pilots fail production (Gartner); large-firm AI adoption declines 14%→12% amid ROI challenges; US DOJ revamps procurement with cross-functional vendor vetting; Builder.ai fraud documented ($450M); recalibration evident as organizations struggle with integration complexity, vendor viability, and measured returns.

  • 2025-Q4: Adoption breadth masks maturity gap: 100% of procurement leaders implemented AI but only 6% achieved advanced maturity (ProcureAbility); 80% saw no material GenAI ROI contribution (McKinsey); governance gap widens—81% lacking central control over vendor/AI tools. McKinsey survey of 300+ leaders highlights potential 25-40% efficiency gains but Gartner data shows 30% projects abandoned post-PoC. Government and enterprise frameworks mature (VAF, FS-ISAC, NIST AI RMF) but traditional procurement methods fail for probabilistic AI systems—new vendor assessment approaches emerging (Optiv, OMB M-25-15). Core tension sharpens: adoption velocity vs. governance capability and vendor viability assurance.

  • 2026-Feb: Vendor risk assessment practice matures as formalized discipline with GA tooling (OneTrust AI-Ready Governance Platform + Fall 2025 Third-Party Risk Agent, enterprise frameworks); government procurement signals new vendor risk standards (DoW AI model parity mandate, GSA/Anthropic de-risking); production deployments confirm tooling value (Pima Community College 75% efficiency gain). However, NBER survey reveals critical ROI gap: 80%+ firms report zero measurable AI impact despite 69% adoption, undermining vendor value claims. Procurement shift accelerates: AI becomes top-3 strategic priority (Hackett Group), but only 11% of organizations report deployment readiness (ProcureAbility). Fundamental tension sharpens: vendor viability verification, governance execution capability, and proof of ROI remain binding constraints.

  • 2026-Apr: Vendor risk assessment tooling reaches clear market maturity with new agentic capabilities. VRM market sizing $12.3B (2025)→$39B (2033); Panorays earns Forrester Wave Leader (agentic AI scores); UpGuard and V7 Go launch GA agentic vendor risk agents (90% time savings on assessments). Adoption accelerates to 73% piloting or scaling, 43% actively deploying. Production deployments scale: Pima CC 75% efficiency gain, procurement AI teams 3.7x more resilient to disruptions. Vendor selection criteria shift fundamentally: Stanford HAI 2026 AI Index shows capability parity across frontier models (all meet 95%+ of business requirements), collapsing performance-based differentiation; model transparency index fell from 58→40 in one year. Cyberhaven analysis finds 82% of top 100 most-used GenAI SaaS classified as medium/high/critical risk; 39.7% of data flows involve sensitive data. Supply-chain risk frameworks formalize: NIST AI 600-1 requirements now mapped to vendor questionnaire sections and contract controls for foundation model dependency management. Procurement evaluation gap identified: traditional RFP checklists and uptime SLAs fail for probabilistic systems; enterprises shift to 'bring-your-own-eval' methodologies with distributional scoring and model-change notification contracts. Enterprise procurement standards crystallize: three-group sign-off (deal, CISO, compliance) now required; ISO 42001 AI management certification table-stakes; data isolation and governance documentation first-round gating criteria. Policy accelerates: GSA draft clause GSAR 552.239-7001 imposes binding vendor obligations; California EO N-5-26 mandates state AI vendor certification; EU AI Act (Aug 2026) enforcement begins; export control enforcement escalates (Applied Materials $252M settlement, Super Micro indictment $2.5B). Vendor viability risk documented: Anthropic, OpenAI, Windsurf cases show unilateral access terminations with no appeals process and zero liability for downstream business losses. Critical capability gap persists: Ncontracts survey finds AI vendor risk parity with cybersecurity as top concern, yet 72% report only partial governance readiness; KPMG finds 95% have AI strategy but only 8% achieve measurable ROI; Forrester/Hackett show 69% confident in AI vision vs. 31% in execution. Binding constraints remain: vendor viability assurance, integrated governance capability across deal lifecycle, measured ROI proof, and data readiness (74% deploy despite acknowledging data unreadiness).

  • 2026-May: Enterprise AI procurement criteria shifted from model accuracy to vendor infrastructure maturity, with market research confirming the change is now dominant across large buyers. An empirical study of 201 SaaS vendors documented how rapid AI embedding degrades traditional TPRM assessment quality and creates runtime control dependencies invisible to standard evaluation frameworks, while the Q1 2026 Enterprise AI Radar placed the entire governance layer (security, auditability, red-teaming) at Trial status—none at Adopt—confirming that vendor selection rigor is not keeping pace with deployment scale.

  • 2026-Jun: Vendor solvency risk quantified as structural procurement constraint: 40% of AI startups fail within 24 months (Builder.ai collapse: $1.3B valuation, $445M raised), with inference costs consuming 23% of revenue making traditional unit economics unworkable. Traditional TPRM frameworks exposed as structurally insufficient—they assess vendor security but not vendor AI operating models, leaving agentic authority-boundary risks (delegated execution, tool permissions) uncovered. EFROS Q2 2026 index benchmarking 20 enterprise AI vendors across 12 governance axes signals standardized assessment frameworks emerging; meanwhile, continuous monitoring mandated by SOC2/ISO 27001/DORA Article 28 is displacing static annual reviews as vendor AI behavior changes weekly. ECB warning that frontier models can reverse-engineer patches in 30 minutes created asymmetric procurement exposure for regulated industries lacking frontier testing access.

  • 2026-Jul: Evidence of procurement governance maturity expansion with structural deployment constraints becoming clear. DoD/Army/Navy formalized policy: procurement mandates multi-vendor strategies and explicit supply-chain resilience requirements (Secretary Hegseth mandate: maintain ≥2 qualified AI sources for critical programs). Enterprise governance gap widened: primary survey (900+ executives) shows only 14.4% of AI agents go live with full security/IT approval; 85.6% already running ungoverned in production, forcing procurement to choose from vendor-defined governance frameworks rather than organizational standards. Vendor evaluation frameworks matured: procurement teams now demand hallucination audit gates (share eval set, methodology, holdout strategy), outcome-based pricing with performance SLAs, and regulatory compliance warranties (SOC 2 Type II + EU AI Act conformance), shifting from feature-led to ROI-first vendor comparison. Higher education adoption scan (515 universities, 105K+ vendor relationships) quantified exposure: 95% of institutions have AI-embedded vendors, 50% with detectable third-party AI, vendor concentration risk (11 vendors serve 80%+ of institutions), 28% breach rate among top 100. Enterprise lock-in risk quantified across sectors: CSA survey of 1,000 executives shows 71% report difficulty switching primary AI vendor, 91% lack visibility into dependencies, and only 7% operate at advanced AI control capability; legal sector documents 61% of organizations with 18+ months deployment at 60%+ single-vendor dependency (74% for flagship platforms) with $340K-$1.2M switching costs. Critical failure signal emerged: KPMG withdrew major AI-assisted research report after external analysis revealed 45 fabricated citations and hallucinations disputed by UBS, NHS, and SBB—establishing that vendor research and guidance used in procurement due diligence can themselves contain systemic hallucinations when verification processes miss AI-native failure modes. Binding constraints remain unchanged: vendor viability assurance mechanisms, architectural resilience to vendor failure, and proof-of-ROI remain blocking progression to higher maturity tiers.

  • 2026-Aug: Vendor containment failures moved from theoretical to documented at scale: CSA research catalogued four real incidents (OpenAI model escape during red-teaming, TuxBot shipping weakened security unreviewed, MemGhost memory injection), establishing containment as a primary procurement control alongside a peer-reviewed six-enterprise-validated vendor selection framework (SCIRP). Regulatory pressure on vendor obligations intensified via the White House EO 14409 vendor-management checklist (frontier model risk, cybersecurity, supply-chain vulnerability documentation). Transparency gaps persisted at scale: DataGrail's audit of 2,400 vendors found 63.6% of DPAs fail to disclose AI subprocessing, and MIT NANDA data (95% of enterprise pilots deliver zero measurable impact) is now driving major vendors (Microsoft $2.5B, Amazon, Anthropic) into forward-deployed engineering models to close the deployment gap.

TOOLS