Skip to main content

Third Party Risk Management

When AI Agents, Not Analysts, Select the Vendor

For the better part of a decade, artificial intelligence in procurement and supply chain functions meant dashboards - better visibility, faster analytics, more accurate forecasting. The decision itself still sat with a human being. That is changing, and the change is arriving faster in oil and gas than in almost any other sector, for a specific structural reason: the industry's supply chains are unusually complex, multi-jurisdictional, and time-critical, which makes them precisely the environment where autonomous decision-making delivers the most obvious value.

Industry analysis published in 2026 describes a maturity curve now underway in procurement functions: basic AI agents triggered by human input are giving way to automated agents monitoring RFQs, contracts and spend data continuously in the background, with semi-autonomous agents - pursuing defined goals independently, within human-set thresholds - expected to become mainstream between 2026 and 2028.

Realistic industry projections suggest AI agents could handle 60 to 70 percent of routine, end-to-end transactional procurement activity within this window, covering tail spend, standardised sourcing events, continuous supplier performance monitoring and early risk flagging. Academic research specific to upstream oil and gas is now documenting this shift directly in supply chain decision-making, examining how autonomous AI agents are beginning to interpret sourcing intent, evaluate vendor risk criteria and trigger procurement workflows without step-by-step human direction. The shift under discussion at industry forums is being framed candidly: the move is not from "using AI" to a slightly smarter version of the same workflow - it is from AI as a tool to AI as an agent, and from human operators directing systems to human supervisors overseeing them.

This has a direct and underappreciated implication for third-party risk management. Vendor selection, supplier scoring and contract monitoring have traditionally been process steps with a visible, auditable human decision point - someone chose this vendor, for these reasons, on this date. As agents absorb these functions, that decision point becomes distributed across a chain of automated reasoning that is far less visible unless it is deliberately engineered to be so. The procurement industry's own analysis is explicit on what this demands: full explainability, with every AI action and reasoning chain logged and auditable; defined escalation rules setting clear limits on autonomous decision-making; and human-in-the-loop checkpoints for anything crossing a financial or strategic threshold.

For a sector already navigating heightened scrutiny of supplier concentration, sanctions exposure and OT-adjacent vendor access, the emergence of agentic procurement introduces a new governance question that most existing TPRM frameworks were not built to answer: who is accountable when an autonomous agent, rather than a named procurement officer, selects or de-selects a critical vendor. Regulators internationally are beginning to take note - the NIST AI Agent Standards Initiative is actively developing compliance frameworks specifically addressing autonomous agent accountability, an early signal that this will not remain an internal governance matter for long.

The organisations that will manage this transition well are unlikely to be the ones that resist agentic procurement, given the scale of efficiency gain on offer. They are more likely to be the ones that treat agent governance as a formal extension of third-party risk management from the outset - building the audit trail, the escalation logic and the accountability structure into the agent's design, rather than retrofitting it once an agent has already made a decision that needs explaining to a regulator, an insurer or a board.