September 4, 2026 · 7 min read
AI Procurement Automation: Sourcing Suppliers Without a Buyer
By Sahan, co-founder, systems and delivery
AI procurement automation, for a company with no procurement department, means an agent that does the search-and-paperwork half of sourcing: it builds a longlist of candidate suppliers, pulls what can be verified about each one, sends the same structured request for quotation to all of them, and returns the replies normalised into one table you can compare. It does not choose the supplier and it does not place the order. We run one across our own group, where sourcing sits with people whose main job is something else.
Where the hours go when nobody’s job title is “buyer”
Sourcing a new input contains four distinct jobs, and only one of them is judgement. Finding candidates is search. Checking they exist and are allowed to trade with you is lookup. Getting comparable prices out of them is correspondence. Deciding is the judgement, and it takes ten minutes once the other three are done properly.
In a company without a buyer, the first three land on whoever is free. They get done between other work, over three weeks, and the shortlist that comes out is two names, because the third supplier never replied and nobody chased.
The people who do this for a living are clear about what the capability is worth. In Deloitte’s 2025 Global Chief Procurement Officer Survey, published 19 August 2025 from responses by more than 250 CPOs across 40 countries, 74% named keeping active alternate sources as the most effective way to mitigate supply risk, ahead of multi-tier visibility at 64%. That is self-reported by executives, not measured, but it is a straight description of the thing an owner-operator does not have: a live second supplier, already checked, already quoted.
The same survey ranked where those teams point generative AI. Writing RFIs, RFPs and RFQs came in at 42.33% of respondents, sourcing optimisation suggestions at 27.51% and supplier risk identification at 22.75%. Find, request, vet. Large procurement teams are automating the same three jobs a company without a procurement team never gets to.
The longlist is the cheap part, so go wide
The agent starts from a written specification, not a product name. Grade, quantity, packaging, destination, the certifications your buyer will demand, and the date it has to land. From that it searches trade registries, certification body directories, marketplace listings and industry association member lists, then deduplicates: the same factory usually appears three times, under a trading name, a group name and a sales agent.
Every candidate becomes a record carrying the source it came from and the date it was read. That second field matters more than it looks. A supplier directory entry from 2019 is a lead, not a fact.
Going wide is only sensible when widening is free. A person stops at eight candidates because the ninth costs another forty minutes. The agent stops when the search stops returning new names.
Vetting: what a machine checks, and what it cannot
The agent checks things that have an authoritative source and a stable format: company registration and status, certificate numbers verified against the certifying body’s own directory rather than the supplier’s PDF, denied-party and sanctions list matches, published financial filings where the jurisdiction has them, and the age and ownership of the domain the quotes will arrive from.
Two dated examples of why this is not a one-off task. The revised EU Deforestation Regulation applies to large and medium operators from 30 December 2026 and to small operators, meaning under 50 employees and under €10 million of turnover on the products concerned, from 30 June 2027, per the European Parliament’s press release of 17 December 2025. Due diligence statements did not go away in the revision, they moved to whoever places the product on the EU market first.
The second example is why screening is not name-matching. The US Bureau of Industry and Security published a rule on 30 September 2025 extending Entity List restrictions to any foreign company owned 50% or more, directly or indirectly, by listed entities. Six weeks later, on 12 November 2025, BIS suspended that rule for a year, through 9 November 2026. Same supplier, same list, three different answers inside one quarter depending on the date you asked.
So the agent’s vetting output is not a score. It is a file: what was checked, what the source said on what date, what came back missing, and what it could not check at all. A confidence percentage on a supplier nobody has met is a made-up number wearing a lab coat.
The RFQ works only if everyone answers the same question
Most quote comparisons fail before the quotes arrive, because each supplier was asked a slightly different question. One got a phone call, one got a forwarded email thread, one got the spec attached as a photo.
The agent sends one structured request to every candidate, with the same fields and the same deadline: specification, quantity, packaging, incoterm, required documents, requested payment terms, and the date a reply is needed. Then it chases the non-repliers on a schedule, which is the job people quietly skip.
| Step | The agent does this alone | A person does this |
|---|---|---|
| Build the longlist | Searches, deduplicates, records source and date | Nothing, unless the spec was wrong |
| Registration and sanctions checks | Runs them, files the evidence with dates | Reads the exceptions and the gaps |
| Certificate claims | Checks the number against the issuing body | Judges whether the scope covers your product |
| Send the RFQ | Sends one identical request, chases non-repliers | Approves the supplier list before it goes out |
| Normalise the replies | Restates every quote on one basis, flags blanks | Reads the comparison |
| Choose and commit | Never | Selects, negotiates, signs, sends the order |
Quotes are not comparable until someone normalises them
This is the part that decides whether the exercise was worth running. Four quotes for the same material arrive with four unit bases, two incoterms, three currencies, minimum order quantities that differ by a factor of five, lead times counted from different starting events, and payment terms running from full advance to sixty days.
The cheapest number on the page is frequently the most expensive order. A price 6% lower ex-works, on a minimum order twice your requirement, at 100% advance, is not a saving.
The agent restates every quote on one basis: landed cost per unit at your destination, at your actual order quantity, with payment terms priced as what the cash timing costs you, and lead time measured from the order date. Where a supplier left a field blank, the line says blank. It does not fill the gap with an assumption, because a filled gap is invisible on a table and an empty one is not. Our freight desk runs the same normalisation on shipping rates, described in freight quote automation.
What it hands over, and what it will never touch
The deliverable is a shortlist with the working shown: normalised quotes, the vetting file behind each supplier, what is missing from each one, and the questions worth asking before anyone commits.
Then it stops. It does not send the purchase order, it does not negotiate, and it does not sign. Committing company money to a counterparty is the decision the business exists to make.
There is a second reason for that boundary. Business email compromise produced 24,768 complaints and $3.05 billion in reported losses in the United States during 2025, the second largest loss category in the FBI Internet Crime Complaint Center’s annual report, out of $20.877 billion reported across all categories. BEC is exactly the mechanism by which a fake or hijacked supplier gets paid.
An agent that could both find a supplier and pay one would be the most attractive target in your business. Ours writes the file. A person sends the money, and the posting side of that is covered in automate purchase order to accounting.
Where this goes wrong
Three failure modes, all upstream of the software.
No written specification. If the requirement lives in one person’s head, the agent sends a vague RFQ to forty suppliers and produces forty non-comparable answers faster than a person could produce four. Garbage at scale is worse than garbage.
No decision rule. If nobody can say what would make supplier A better than supplier B, the shortlist sits unread and the order goes to the incumbent anyway. Write the rule down first, even if it is only “cheapest landed cost that holds the certification and can ship by the 20th”.
Sourcing was never the bottleneck. Plenty of businesses source twice a year and pay late every week. The second problem is worth more.
What it costs to find out
An AI Operations Audit is $1,900 fixed, delivered in writing by day 10: a map of your operations, a ranked build list scored by effort and return, and a 90-day roadmap. If sourcing is not in your top three, the list says so, and if we find nothing worth building you get the fee back.
What gets built afterwards is one tomte, our word for one production agent with one defined job, running under the same rules as the rest of our agent fleet: registered before it runs, fenced to the systems it may touch, and logging every action. As of July 2026 that fleet stood at 41 registered agents with 9 live in production, and 5,450 runs across the 13 days measured, with zero failures.
Send us the last three things you sourced and how long each took from request to order. You get a written scope, a fixed price, and a plain statement of what the agent will and will not do on its own, inside one business day. No meeting. Start async.