How AI Agents Will Negotiate Your Vendor Contracts

How AI Agents Will Negotiate Your Vendor Contracts

🎙 Cloud Security Podcast 👥 39K 📅 May 27, 2026 ⏱ 37 min 👁 8K 📄 expert opinion 🧭 2026-08-16
Available in: English (current) Français

Keywords

AI agentsvendor riskTPRMshadow AIDORA

Summary

In this episode of the Cloud Security Podcast, host Ashish Rajan interviews Igor Andriushchenko, CISO at Lovable, and Jasper Mills, CEO of Ethira, about the transformation of third-party risk management (TPRM) through AI. They discuss the historical pain points of TPRM, which involved manual, paper-based processes and 200-page checklists. The conversation covers the impact of regulations like DORA, the use of AI to automate vendor assessments and questionnaires, and the build vs. buy debate for AI security tooling. They highlight the risks of shadow AI, where non-technical teams deploy unauthorized AI tools, and propose treating AI agents as a contracted workforce with lifecycles and governance. The episode concludes with predictions about agent-to-agent negotiations by 2027, where humans are removed from the loop, and the need for contractual accountability through AI guardrails. The discussion emphasizes the need for up-to-date inventories and continuous monitoring of AI agents and their data access.

149 words

Critical Evaluation

Value of the Information & Strength of the Argument

The episode provides valuable insights into the practical application of AI in TPRM, drawing from the speakers’ direct experiences. Igor and Jasper offer concrete examples of how AI can automate tedious tasks like vendor assessments and questionnaires, and they discuss the challenges of shadow AI and the need for governance. Their argumentation is coherent and grounded in real-world scenarios, though some claims about future trends are speculative. The discussion on build vs. buy is particularly useful, highlighting the hidden costs of maintaining in-house tools. The speakers also address the importance of balancing autonomy and human oversight, which is a nuanced perspective. However, the lack of quantitative data or case studies weakens the overall argumentation.

Scientific Rigor, Source Quality, Title Accuracy

The episode maintains a high level of scientific rigor in the sense that the speakers are experienced professionals who provide practical insights. However, they do not cite specific studies or external sources, relying instead on anecdotal evidence. The title accurately reflects the content, focusing on AI agents in vendor contract negotiations. The discussion is well-structured, with clear chapters, and the speakers stay on topic. The lack of citations is a minor weakness, but the practical expertise compensates. The title is slightly broader than the content, as the episode covers more than just negotiations, but it is still appropriate.

227 words

Title / Content Match

The title accurately reflects the core theme of the episode, which focuses on the future role of AI agents in vendor contract negotiations, though the discussion covers broader aspects of TPRM.

Quality & Reliability

7/10

The episode features two experienced security professionals (CISO and CEO) discussing practical applications of AI in third-party risk management. They provide concrete examples and acknowledge limitations, but the discussion is largely anecdotal and lacks rigorous data or peer-reviewed sources. The claims about future trends (e.g., agent-to-agent negotiations) are speculative.

Chapters

Cited Sources

Concurring Sources

Dissenting Sources

  • Critique of AI in Risk Management — Some experts argue that AI cannot fully replace human judgment in risk assessment, which contrasts with the episode's optimistic view.

Contribution & Novelties

The episode offers a fresh perspective on TPRM by integrating AI agents into the process, moving beyond traditional manual methods. It introduces the concept of treating AI agents as a contracted workforce, which is a novel approach. The discussion on shadow AI and the need for governance of AI agents is timely and relevant. The prediction of agent-to-agent negotiations by 2027 is forward-looking and sparks thought about future security challenges.

Pour aller plus loin :

124 words

Radar Profile

The radar profile shows balanced scores across all dimensions, with slightly lower scores for technical depth and reliability. This indicates a well-rounded discussion that is accessible but not overly technical, and relies on expert opinion rather than empirical evidence.

Reliability 6/10

💬 Sur les 8 commentaires analysés, les téléspectateurs ont salué la pertinence du sujet et la qualité des intervenants, certains exprimant un intérêt pour les applications pratiques des agents IA dans la gestion des risques fournisseurs.