The data: what they're already asking before signing
- 66% of B2B buyers already required SOC 2 certification before signing with a SaaS vendor, even before AI entered the equation.
- Since summer 2026, buyers vet AI services on three axes: AI Act conformity for the service's risk category, a demonstrable AI governance system (such as ISO/IEC 42001), and contractually fixed audit rights, data provenance, and incident response.
- Procurement checklists now routinely demand: kill switches, verifiable audit trails, clear human oversight boundaries, model change control, outcome-based SLAs, and ISO/IEC 42001 or SOC 2 attestations as a gating condition.
- And yet, 80% of organizations have no governance for their autonomous agents — most procurement policies are still written assuming a human buyer, not an agent acting without judgment of its own.
It's the direct continuation of what we already saw with the compliance evidence banks and large clients are asking for and with the 97% of companies deploying agents with no governance strategy. The difference is it's no longer just your bank — it's any large client buying anything that involves AI.
Why it changed: from best practice to contract clause
The shift comes from two forces arriving at once. First, full AI Act applicability to high-risk systems since August 2026 forces documentation of conformity assessments and risk management — documentation that didn't exist before, and which, now that it does, can be requested. Second, procurement teams have stopped treating AI agents as ordinary SaaS: if an agent can act without direct oversight, the buyer wants to know what happens when it fails, not just when it works.
The result is that a lack of internal governance is no longer just a security risk living inside your company — it's something your client can discover mid-negotiation, right when you have the least room to fix it.
What a 2026 RFP will ask if AI is involved in what you sell
- Model documentation: versions used, training data provenance, and a 24-month change history.
- Traceability and explainability: a log of every relevant output, detailed enough to reconstruct why the system decided what it decided.
- Human oversight by design, not improvised: clear points where a person approves or can stop the action, with a real kill switch if something goes off the rails.
- Model drift SLAs with measurable thresholds and defined remedies if performance degrades over time.
- Data deletion obligations that extend to backups and archives too, not just the active database.
- Certifications like ISO/IEC 42001 or SOC 2, increasingly used as a gating condition or a scoring criterion against competitors who lack them.
Most vendors won't be able to answer this yet. The 80% governance gap isn't an abstract statistic — it's literally the RFP section where your competitors will leave a blank. That's an advantage for whoever shows up prepared, not just another hurdle to clear.
Checklist: what to prepare before they ask
- Inventory the AI that touches the client. Which agents or models are involved in the service you deliver, even if they aren't "the product" — support, reporting, analysis of their data.
- Document the data journey. What comes in, where it comes from, where it's stored, and how it's deleted — including backups.
- Log the decisions that matter. Detailed enough that if a client asks "why did this happen," you have an answer instead of a reconstruction after the fact.
- Define human oversight points in writing: what the system can act on alone, and what needs a person's approval.
- Assess whether a formal certification (ISO/IEC 42001, SOC 2) makes sense given who you sell to — sooner rather than later if your clients are banks, insurers, or large accounts; otherwise, detailed documentation of your own is usually enough for now.
Conclusion
AI governance stopped being just a defensive exercise and became part of the sales pitch: whoever can clearly answer what their AI does, with what data, and under what oversight, closes deals that stall in procurement for vendors without that documentation.
At Dataverse Solutions we help build that governance documentation not as paperwork, but as another piece of your commercial argument to your own clients.
Frequently asked questions
Do I need ISO/IEC 42001 certification to sell to large enterprises?
Not yet mandatory in most sectors, but more and more RFPs include it as a scored criterion or a tiebreaker between similar vendors. Until it's a hard requirement in your sector, detailed documentation of your own — an AI inventory, data provenance, logs, and human oversight points — covers most real-world requests.
Does this apply if I only use AI internally, not in the product I sell?
Yes, if that AI is involved in how you deliver the service to the client — customer support, analysis of their data, report generation — even if it isn't the product itself. B2B buyers increasingly ask how their data is processed across the whole chain, not just in the final software they sign for.