What changed

Two current AI business signals point in the same procurement direction. Deloitte’s State of AI in the Enterprise findings report that worker access to AI rose 50% in 2025. At the same time, only 25% of organizations have moved 40% or more of pilots into production, and just one in five has a mature governance model for autonomous AI agents.

Separately, CB Insights’ State of AI Q1’26 report highlights record AI funding, elevated M&A, and consolidation among model developers and big tech.

The practical issue is not whether every pilot will scale or whether any specific provider will consolidate. It is that access, agent capability and market structure can move faster than contract templates written for limited trials.

The hinge for counsel

AI procurement language should be reviewed for resilience. A pilot agreement may be tolerable when a small team tests a tool in a limited setting. It becomes weaker when the same tool enters production, becomes a workflow dependency, or adds functions that can act without human approval.

Before approving new or renewed AI contracts, separate three questions:

  • Use: Is the deployment a pilot, a production workflow, or a broad worker-access tool?
  • Dependency: Is the vendor, model, or platform becoming important enough that exit assistance and substitution rights matter?
  • Agency: Can the system take steps without human approval, and if so, which steps are contractually controlled?

Contract review gates

1. Data-use and training limits

The agreement should state whether customer data and outputs may be used for vendor training or other vendor purposes. It should also address customer-data segregation, confidentiality and trade-secret handling.

If the vendor relies on subcontractors, model providers or other service components, review whether subcontractor and model-change notice provisions align with the sensitivity of the deployment. The point is to avoid a data-use promise that looks clear at signing but becomes uncertain after a model, vendor, or service-chain change.

2. Output ownership and risk allocation

Do not leave output risk to generic software clauses. Review output ownership, permitted use, infringement allocation and indemnity scope.

If the vendor makes benchmark, accuracy or capability claims, decide which claims are contractual commitments, which are only descriptive, and what records support reliance on them. This is especially important where product teams are using vendor claims to justify a move from pilot to production.

3. Autonomous-agent controls

Deloitte’s finding on low maturity for autonomous-agent governance should push teams away from vague approvals of “AI agent” functionality.

For each agent use, define whether the system can act without human approval, what approvals are required, what audit or reporting the customer receives, and how incidents are noticed. If the contract does not describe the agent’s authority, the operating team may be left to infer the control boundary after deployment.

4. Vendor change and exit

CB Insights’ market-structure signal supports a practical exit review. Contracts should not assume that the same vendor, model or ownership structure will remain static.

Check termination assistance, export assistance, model or vendor substitution rights, and notice for subcontractor or model changes. The goal is not to predict which provider changes. It is to preserve operating choices if the market changes around the deployment.

5. Pilot-to-production documentation

Because Deloitte reports uneven pilot-to-production conversion, approvals should make the transition explicit. Require a documented decision when a pilot becomes production or when worker access expands materially.

At that gate, update the approved use, accountable owner, data-use assumptions, output review expectations, audit or reporting terms, and any unresolved contract exceptions. This turns scaling into a controlled decision rather than an accumulation of informal access.

Questions for the next procurement review

Use the next AI procurement meeting to answer a short set of operational questions:

  • Which AI uses are still pilots, and which are already production dependencies?
  • Which vendors or models would be difficult to replace quickly?
  • Which functions can act without human approval?
  • What limits apply to vendor use of customer data and outputs?
  • What notice is required for subcontractor or model changes?
  • What assistance is available on termination or export?
  • Who bears output infringement, accuracy, or capability-claim risk?
  • What audit, reporting, and incident-notice rights will the business actually use?

Limits of the signal

The Deloitte material is survey-based, and the CB Insights material is a quarterly market report. They are market and adoption signals, not legal rules and not findings that any specific vendor contract is deficient. Their value is as a trigger for contract review before access, autonomy and vendor dependence outgrow the original procurement file.