A vendor’s tool update is a code push straight into the hands of a firm’s agents, with no release anyone reviews, so vendor oversight and supply-chain security stopped being separate disciplines. Buy where the market has a leader, and treat every vendor as part of the attack surface, because for agents they are.
Why this matters
The category map splits cleanly into three states, and knowing which state a firm is shopping in saves more money than any comparison sheet. Mature: enterprise assistants and low-code platforms, where every serious vendor clears the certification bar and the real decision is where the firm’s data already lives. Buyable with care: gateways, guardrails, observability. Leaderless: agent runtime security, identity for agents, AI governance platforms; the absence of an anchor there is a finding to act on, not a gap for a vendor to fill.
What makes this dimension different from ordinary third-party risk is the update path. Approving a tool at install time approves the version inspected that day; the description the model reads as instructions can be rewritten afterwards, by the vendor, without a deployment on the buyer’s side. The mechanism and the named precedents are in tool and supply-chain compromise; the control that answers it is failing closed when approved metadata changes, not a better questionnaire, and it is set out in supply-chain vetting.
Three arrival channels that watching procurement will not show:
- Through the staffing and services channel. Vendors now sell “digital labour” alongside people: one Adecco-and-Salesforce-backed company exists specifically to plan and oversee a mixed human-and-agent workforce. Agents can enter through an MSA, not an IT purchase.
- Through existing suppliers’ own tooling. The agency’s staff adopted coding agents; what the firm is buying changed without the contract changing. Add it to the diligence questions.
- As a managed service. Roughly one in six respondents in one survey want agents run for them by a partner. A managed agent operated by a third party still acts inside the client’s systems, which means recordkeeping, oversight and offboarding obligations follow it home.
Diligence questions that are specific to agents, on top of the standard bar (SOC 2 Type II, ISO 27001, deployment mode, SSO and SCIM, RBAC, environment separation, exportable audit logs, zero retention, no-training terms, audit rights, exit path):
- Who captures the learning? If a vendor-hosted agent improves on a client’s interactions, the contract should say who owns that improvement and what happens to it at termination. This is a published prescription with no known counterparty who has agreed to it: reasoning, not practice.
- Where does the model run, and can our data be extracted from it? Data residency, training use, retention, and model inversion are the four questions financial clients actually raise, and the last is the one nobody else covers.
- What changes without telling us? Tool descriptions, connector scopes, model versions underneath the API.
Two numbers worth keeping in proportion. 77% of companies now factor an AI solution’s country of origin into vendor selection and 58% build primarily with local vendors (n=3,235, fielded Aug–Sep 2025). For a US or EU fund this surfaces as data-residency and hosting clauses rather than vendor nationality screening. And cross-organization agent interaction remains rare: even among extensive adopters, about 27% say they let outside agents interact with their own without a human involved, against 17% at pilot stage. The defensible reading is that three-quarters still do not, which makes this a frontier exposure, not a present one.
Finally, the thing vendors cannot sell. Vendor support reliably gets a platform implemented and reliably fails to get it adopted; the named causes are usability and internal communication. External specialists drafting the guardrails is a real pattern with real precedent (two of six cases in one study used one, including a certification program that gated platform access), but the playbook arrives without the enablement, which stays in people.
Where you stand
| Level | Looks like | Cheapest next move |
|---|---|---|
| Crawl | Builders connect whatever tools they find. Nobody knows which third-party servers agents talk to. | Enumerate the tools and connectors your agents actually use, then compare against what procurement believes you bought. |
| Walk | Vendors pass standard third-party review at purchase. Tool updates are invisible after that. | Pin versions and require change notification for anything an agent reads as instructions. |
| Run | Agent-specific diligence terms in contracts; approved tool catalogue with provenance; re-vetting on change rather than on renewal. | Test the exit path for one vendor: can you export the traces and the configuration today? |
| Fly | Fail-closed enforcement on metadata change, vendor telemetry reconciled against the registry, and viability tracked as an M&A-aware watchlist. | Re-check the M&A state of your stack quarterly; half this map has already been acquired. |
Concerns this dimension covers
- Tool and supply-chain compromise — the highest-severity client-side threat, with named precedents.
- Privilege and identity abuse — what a third-party tool inherits when it runs on the firm’s credentials.
- Recordkeeping and compliance gaps — the obligations that follow a managed agent into someone else’s infrastructure.
- Grounded in: Model Context Protocol, the standard whose trust model is the weak point.
Controls that answer them
- Supply-chain vetting — pinning, provenance, and failing closed on change.
- Identity and access for agents — scoping what a vendor’s tool can reach when it acts for the firm.
- Egress control — the boundary that survives a vendor trusted incorrectly.
Who sells it — the category map
- Mature buy: enterprise AI assistant platforms, low-code agent platforms.
- Buy with care: AI gateways, guardrail products, observability and eval platforms.
- Leaderless: agent runtime security, identity platforms for agents, AI governance platforms.
- Adjacent incumbents extending into agents: DSPM and data classification, comms archiving and surveillance.
- Vertical: domain-specific finance AI platforms.
Sequencing and where this is checked
- Build vs buy — the decision framework and the contract terms.
- Day 3 sequencing — which purchases are Day 1 and which can wait.
- Registry review cadence — vendor tools re-vetted on the same cycle as the agents using them.
- Offboarding agents and owners — including the vendor a firm leaves.
Open questions
- Which leaderless categories consolidate and which get absorbed into platforms? The M&A record so far favours absorption, which argues against long contracts with point tools.
- Nobody has published what an agent-aware vendor questionnaire should contain. The three questions above are ours, and the IP-capture clause has no known precedent in a signed contract.