How AI Features Arrive Without a Procurement Event
The assumption in most state AI frameworks is that an agency decides to procure AI. An RFP goes out. A contract comes back. Before signing, someone reviews the risk tier, runs an assessment, checks data processing terms, and ensures the system meets the state's AI accountability standards.
That model fits deliberate AI acquisitions. It does not describe how a substantial share of enterprise AI is actually reaching state agencies.
Platform vendors routinely add AI capabilities to existing products:
- Microsoft 365 Copilot is available to state agencies as a paid add-on to existing M365 enterprise agreements — a separate licensing SKU rather than a new standalone contract. Many agencies processed this as a license extension or renewal amendment. The result is a tool that indexes emails, documents, and Teams conversations and generates responses across those datasets, acquired through a procurement action that often bypassed AI-specific risk review because it was categorized as a license add-on rather than a new AI system acquisition subject to governance requirements.
- Salesforce Einstein AI features ship with standard Salesforce SKUs and are activated at the administrator level. State agencies running Salesforce for case management, constituent relations, or grants administration receive AI capabilities that can generate draft responses, classify cases, and summarize records when an admin enables them.
- ServiceNow Now Assist delivers generative AI features — ticket summarization, automated resolution suggestions, employee-facing chatbots — to state ServiceNow instances. Under the legacy licensing model most state agencies were on before April 2026, Now Assist required a separate paid tier with significant price uplift above base editions. ServiceNow's April 2026 restructuring made Now Assist standard across its new licensing tiers, meaning agencies renewing contracts in 2026 may encounter it as an included feature — acquired through a renewal rather than a new AI procurement decision.
- Oracle and SAP have embedded generative AI across HR, finance, and procurement modules in their cloud ERP products. State agencies running these platforms on cloud subscriptions encounter new AI functionality in standard version updates.
In each case, the delivery mechanism is a license entitlement, a feature flag, or a version update — not a new contract. The existing agreement governs the relationship. No state solicitation document anticipates what was not yet a product when the contract was signed.
Why Existing AI Governance Frameworks Don't Cover This
Most state AI policies — whether an executive order, an administrative code, or an agency AI-use policy — identify the procurement process as the point where AI review happens. California's Executive Order N-5-26 directs the Department of General Services and the California Department of Technology to develop certifications for future AI acquisitions. Colorado's AI policy guidance directs agencies to complete risk assessments before procuring AI systems. These frameworks are representative: across the states that have issued AI guidance or executive orders, procurement is the standard trigger point for review.
These frameworks are structurally oriented toward new acquisitions. That is appropriate as far as it goes. But it creates a specific governance gap: when an AI capability arrives through an existing contract, no new procurement occurs, no RFP triggers a vendor evaluation, and no risk assessment requirement activates. The AI feature is now in production.
Agencies that turn it on — or whose users discover it and begin using it — are outside the governance boundary the policy intended to cover. State agency employees are already using Copilot for document drafting, Now Assist for IT ticket management, and Einstein for case triage in agencies that have never conducted a formal AI assessment of those tools.
The Risk Surface of Embedded Enterprise AI
The risk profile of an embedded enterprise AI feature differs from a standalone AI product in ways that matter for state agencies.
Data breadth. Enterprise AI tools are designed for maximal context. Copilot's value proposition is precisely that it can reach across email, SharePoint, Teams, and connected applications to synthesize answers. That breadth of access — which makes it useful — means the data exposure surface is much larger than a narrowly scoped AI application would be.
Foundation model dependency. Enterprise platforms typically embed AI through partnerships with foundation model providers: Microsoft with OpenAI, Salesforce and ServiceNow with their own model agreements. The state's contract governs the enterprise vendor. It does not directly govern what data the foundation model provider receives, retains, or uses. Data processing addenda exist — but they require careful reading, and their terms vary significantly between vendors and product versions.
Model versioning without notification. Foundation models are updated continuously. A state agency that assessed a Copilot deployment in January may be running a different model by September. Unlike traditional software, where version changes are documented in release notes and subject to regression testing, model updates can change output behavior in ways that are not obvious without deliberate evaluation. Most existing state contracts do not require vendors to notify agencies of model changes or provide re-assessment rights.
Administrative activation without oversight. Many enterprise AI features are activated by agency IT administrators, not by a procurement or governance process. In large state agencies, individual departments or bureaus may enable features without the CIO's office or the CISO's awareness. By the time anyone asks whether an assessment was done, the feature has been running for months.
A Mid-Contract Review Protocol
The absence of a new procurement trigger does not mean risk assessment is optional. It means the state has to build the mechanism the procurement workflow would otherwise provide.
A practical mid-contract AI review has five components:
1. Inventory. Identify every enterprise platform under active contract that includes AI features. Ask vendors directly what AI capabilities are included in current licensing. Do not assume the original contract language covers this — AI features were not there when most agreements were signed. Each major platform needs a current answer.
2. Activation audit. For each platform with available AI features, determine which capabilities are currently active in production environments, which are available but inactive, and which require explicit opt-in. This is an IT asset management task at the tenant or instance level, not the organizational level.
3. Risk-tier classification. Apply the existing state risk framework retroactively to each active AI capability. What data does it access? What actions can it take? Who uses it? A Copilot feature used by an analyst with access to personnel records is a higher-priority review than a Now Assist feature for summarizing IT tickets. Triage by risk, not by procurement history.
4. Data processing addenda review. Vendors who launched AI features typically offered data processing amendments or new terms when the capability went live. Identify whether the state accepted those terms, and what they commit to regarding data residency, retention, and the vendor-to-foundation-model data flow. Gaps between what the state needs and what the addendum provides are negotiation items.
5. Activation gates for sensitive-data systems. Establish a policy that AI features in systems handling sensitive data — Medicaid, SNAP, child welfare, criminal justice, personnel, tax — require explicit CIO and CISO sign-off before activation, regardless of whether a new contract is involved. An administrator enabling Copilot on a SharePoint instance containing eligibility case files is a governance event, not an IT configuration task.
The Amendment Opportunity
Contract renewals and upcoming amendments are the practical moment to close this gap formally. Solicitations and renewals should now include:
- AI feature inventory requirements: the vendor discloses AI capabilities included in the licensed product at contract execution and with each renewal
- Change notification: the vendor notifies the agency before activating new AI features or changing the underlying foundation model
- Assessment rights: the state may defer activation pending completion of its AI risk review
- Foundation model transparency: the vendor identifies the foundation model provider and provides data processing terms that govern that relationship
- Audit access: the state retains rights to review AI-generated outputs, access logs, and request evidence of safety evaluations
These are not exotic terms. They are the AI-specific versions of change notification, audit rights, and data handling requirements that state agencies already negotiate for sensitive-data systems. The challenge is that most existing contracts predate the AI version of those terms. Renewals are the lever — but only if the agency arrives with a prepared position rather than discovering the gap after activation.
Sources and further reading
- California Executive Order N-5-26 (March 30, 2026) — procurement-centered AI governance framework; describes the baseline that mid-contract delivery bypasses.
- OMB Memorandum M-24-10, Advancing Governance, Innovation, and Risk Management for Agency Use of Artificial Intelligence (March 2024) — federal AI governance framework directing agency inventories and risk management requirements; state analogs track this structure.
- NASCIO, "Your AI Blueprint: 12 Key Considerations as States Develop Their Artificial Intelligence Roadmaps" (December 2023) — state-specific guidance on AI risk tiering, governance design, and procurement practices.
- Colorado OIT AI Guidance — a state example of the procurement-trigger risk assessment model; illustrates the structural gap this article addresses.
Spartan X's AI advisory work with state technology leaders includes governance reviews for existing deployed environments — not just procurement planning. Understanding what AI capabilities are already running in an agency's enterprise platforms, and building the operational controls to govern them, is frequently the starting point that precedes any new acquisition strategy.



