← Back to Overview
PUBLICATION TIMESTAMP
--

When Your CPO Is Also Your CISO: The Shadow AI Crisis Forcing Procurement’s Hand

When Your CPO Is Also Your CISO: The Shadow AI Crisis Forcing Procurement’s Hand

There’s a joke bouncing around r/procurement that’s only half a punchline. It goes: “My company’s AI strategy right now is just 47 people pasting contracts into the free ChatGPT tab and hoping Legal doesn’t find out.” The thread got 340 upvotes and a cascade of confessions—one sourcer admitted to running a multimillion-dollar RFQ through a consumer AI tool just to see if the bot could flag supplier weirdness faster than their own team. It did. It also left proprietary technical specs sitting on a server somewhere outside the org’s control. That quiet normalisation of shadow AI inside the enterprise is more than a governance headache. It’s a window into why Zip’s second annual State of AI in Spend report, released in mid-2026, lands like a bucket of cold water. The headline is a clean 6x: organizations deploying AI across most or all procurement processes are six times more likely to report clear ROI than those still piloting or dabbling. But peel the layers and the report reveals something less comfortable. Only 17% of large enterprises have unlocked anything resembling measurable returns, and the divide between the haves—Zip calls them Builders—and the have-nots is widening not because of budget, but because of nerve.

The Two Tribes, and the Missing Middle

Zip’s global survey of 1,050 procurement, finance, IT, and operations leaders at mostly 1,000-plus-employee companies draws a line right through the market. Builders aren’t the ones with the fattest AI line items. 55% of them already run AI across most or all procurement processes—against 4% of everyone else. Their confidence in scaling AI over the next two to three years sits at 71%, compared with a jittery 11% for Bystanders. ROI clarity follows the same split: 39% versus 6.5%. But the shape of the data contains an inconvenient twist, a sort of scale paradox. In the jumbo segment—organisations with 50,000 employees and up—AI deployment breadth is actually higher (33% run it widely). Yet clear ROI crashes to just 11%. That’s not a fluke. Forrester analyst Michael Denari, now Zip’s GM of AI, calls procurement “the highest-ROI opportunity most organizations have consistently underestimated,” but those enormous enterprises prove that throwing AI at a messy, legacy-bound process without rewiring how work gets done just creates expensive noise. One Hacker News commenter, reacting to Zip’s Superagents launch, paraphrased the problem bluntly: “You can’t agentic-AI your way out of a process that was designed by a committee in 2008 to frustrate every stakeholder equally.” That captures something the survey data only implies. Deployment depth demands more than model access—it insists on rethinking intake, approval routing, and the very definition of a procurement function that’s been treated, in many firms, as a cost-centre backwater.

The Shadow AI Audit Trail

The 6x ROI stat is compelling, but it’s the shadow AI finding that ought to keep CFOs up at night. According to Zip’s report, 57% of respondents have used AI tools their employer hasn’t sanctioned. IT, the group ostensibly in charge of stopping this, leads the pack at 64%. Throw in the “considered it” crowd and you’re at 68% of people actively flirting with unapproved AI at work. This stops being abstract when you look at what’s actually being uploaded. IBM’s 2025 Cost of a Data Breach report found that organizations with high levels of shadow AI face an average breach cost of $4.63 million, a $670,000 premium over those with minimal shadow usage. Then there’s the human toll. Just last May, Community Bank in Pennsylvania discovered an employee had fed customer nonpublic personal information—names, Social Security numbers, birth dates—into an external AI app. It barely made headlines, but it’s the kind of quiet disaster that repeats across industries. Samsung’s 2023 ChatGPT incident, where engineers pasted internal source code into the chatbot, is now three years in the rearview, and yet the behavior hasn’t slowed. It’s accelerated. One risk manager I spoke with, who asked to remain nameless because her company hasn’t formalised its AI policy yet, described the situation as “an entire parallel procurement process happening inside consumer AI tools, and we have absolutely zero visibility into what’s leaking.” She paused. “Honestly, I’m not sure I want to know.”

Agentic Procurement’s Real ROI, With a Side of Salt

Zip didn’t just survey people. It commissioned Forrester to run a Total Economic Impact study on its own platform, and the numbers were unsurprisingly rosy: 386% ROI, payback in under six months, an average 3.3% savings on all spend routed through the system, and a 70% drop in time spent on request processing. OpenAI saved 1,400 hours annually from a single intake validation agent; Snowflake claims $305 million in savings through the platform; Canva slashed cycle times by 70%. Is the Forrester study worth taking at face value? It’s a vendor-funded exercise based on a composite organisation stitched together from four global enterprises with revenues between $10 billion and $45 billion. The methodology is sound in the abstract, but it’s still a snapshot of ideal conditions. A composite isn’t your company. It assumes the data foundations are already poured, the change management muscle exists, and the organisation isn’t deeply siloed. The real-world gap between TEI promises and a messy ERP integration tends to be where procurement VPs develop a thousand-yard stare. Still, the directional signal is getting hard to ignore. Bain & Company clocks organizations using AI well in procurement as raising annual ROI up to five times and squeezing extra savings of 3% to 7%. IDC’s benchmarks suggest a $1 billion enterprise can generate $48 to $90 million in annual value from next-gen procurement automation inside 18 months. The Zycus deployment data is even more provocative: over 1,000 regular users and 4,500 suppliers running through a single conversational intake portal, no pilots, straight to production. Their Merlin Agentic Sourcing engine is now live with at least one enterprise running end-to-end autonomous sourcing workflows, pausing only at human decision gates. CEWA, a multi-vertical conglomerate, went live with the complete Zycus agentic S2P suite earlier this year. But here’s the thing: for every CEWA, there are dozens of companies that bought the license and never finished the rollout.

The Organisational Engineering Problem

BCG put it in plain language over the summer: scaling agentic AI in procurement is an organizational challenge. Not a technology challenge. Their survey of more than 200 CIOs, procurement leaders, and specialised IT buyers surfaced four recurring killers: heterogeneous inputs and dirty data, the slog of integrating AI with legacy systems, the impossibility of transforming while keeping the lights on, and governance constraints that strangle autonomy. A senior procurement architect on Reddit described her 18-month AI rollout attempt as “death by a thousand data dictionaries.” Another user, who claimed to be a consultant for a Big 4 firm, wrote: “Every single client I’ve worked with thinks they’ll get AI-driven savings by bolting a fancy layer onto SAP. The ones who actually see returns are the ones willing to admit their category taxonomies were a crime scene and start over.” That’s not a technology problem. It’s an embarrassing, unglamorous, spreadsheet-level reckoning that most executive sponsors don’t want to fund. Zip’s own data reinforces this. The massive 50,000-employee orgs deploy AI widely and still can’t get ROI because deployment width is not the same as depth. Depth is about re-engineering the intake process, retraining approval flows, and making the hard call to collapse roles that AI renders unnecessary. And here’s where it gets uncomfortable for the workforce: 33% of survey respondents expect the team managing third-party spend to shrink within five years, while only 26% expect growth. Nearly half of organisations have already cut or consolidated roles because AI can do the work (29%), with another 19% planning to. Yet 89% still say AI is a net productivity gain even after accounting for time spent fixing its errors. That dissonance—cutting humans while also needing them to babysit the AI—feels like an unspoken tension that will define the next phase of adoption.

[SPONSORED]

AI INFRASTRUCTURE AUDIT

Is your tech stack bleeding resources? Let our engineers evaluate your architecture.

Who’s Actually Leading, and Who’s Just Talking

If you squint at the procurement AI vendor landscape in mid-2026, you can see three lanes emerging. Zip is betting the farm on agentic procurement orchestration—an army of AI agents handling intake, contracts, AP, and supplier research, all governed inside a platform that now supports the Model Context Protocol (MCP), the Anthropic-created, Linux Foundation-hosted open standard. Downloads of the MCP SDK hit 97 million monthly by March 2026, and Zip’s move to release a procurement-native MCP is an attempt to make its platform the silent plumbing between a company’s AI assistant and its spend data. It’s a hedge against the shadow AI problem: if you can’t stop people from using their preferred AI tools, at least connect those tools to governed procurement data. Ivalua continues to dominate deep sourcing and contract management, with a Forrester TEI claiming 393% ROI and customers like Honeywell who lean heavily on the savings and ROI tracker. Coupa, meanwhile, has the broadest installed base but is taking flak on community forums and peer review sites. A user on Gartner Peer Insights called it “terribly designed and difficult to use,” while a Redditor in r/procurement labelled Coupa’s AI as “glorified chatbots that can’t handle a real RFQ.” Vibe check: the buzzwords are wearing thin. Newer entrants like Levelpath, which raised $55 million in a June 2025 Series B, are coming at the problem from an AI-native angle, building for interaction-first procurement rather than trying to retrofit intelligence onto legacy architectures. Their customer list includes Ace Hardware, Amgen, and Coupang. They’re not yet at the scale of a Zip or Ivalua, but they represent a directional bet that the UI layer matters as much as the AI underneath.

What the Open Source and Builder Communities Are Doing

Something genuinely interesting is happening outside the vendor sphere. On GitHub, projects like ULTRATHINK are demonstrating that automated pricing intelligence doesn’t require a seven-figure SaaS contract. A Reddit user built BidBuddy, a 16-section system prompt that turns any LLM into a procurement copilot handling supplier research, RFP analysis, and negotiation strategy. It’s not enterprise-grade. It doesn’t have audit trails or governance controls. But it works, and it’s free. The instructions ask about business needs, constraints, timelines, and existing suppliers—essentially replicating, in a prompt, a chunk of what a platform like Zip charges for. Does this threaten the commercial vendors? Not in the short term. Enterprises need compliance features, SOC 2 reports, role-based access, and someone to sue when things go sideways. But open source and community-built tools are constantly raising the floor. They also serve as a pressure valve for frustrated practitioners who are tired of waiting for internal IT to approve a procurement AI tool while their colleagues quietly solve the problem themselves. A r/PromptEngineering thread from late 2025 captured the mood: “I don’t need another demo. I need something that won’t hallucinate a supplier’s payment terms and cost me a quarter of my annual savings target.” A user replied: “That’s the neat part. Even the paid tools do that. The difference is you have a support ticket to show your boss.”

The 40% Cancellation Rate Hovering Over Everything

For all the momentum, there’s a number lurking in Gartner’s 2026 data that should cool the hype. More than 40% of agentic AI projects are expected to be cancelled by the end of 2027, victim to spiralling costs, unclear business value, and insufficient risk controls. This isn’t a procurement-specific stat; it’s an enterprise-wide prediction from analysts watching the same adoption curve that sees only 17% of organizations having actually deployed AI agents, while over 60% expect to within two years. The parallel in procurement is stark. EFESO’s 2026 CPO Annual Pulse found that a mere 5% of procurement organizations have truly scaled GenAI across operations, despite 83% of respondents in large enterprises reporting regular use of GenAI at work. That gap—between individual experimentation and organisational integration—is where the 6x ROI multiplier gets lost. A user on r/supplychain described it as “the AI equivalent of everyone having a gym membership and nobody actually going.” Suplari’s 2026 Procurement Benchmarks put the industry average for AI readiness at 2.1 out of 5, below the 2.5 threshold considered the minimum for effective AI deployment at scale. Zycus’ report in May found only 9% of teams have crossed into autonomous AI operations, even though 82% of senior leaders say they want AI to negotiate on their behalf. Wanting is not doing.

Where the Savings Actually Come From (And Where They Don’t)

The 3.3% average savings on all spend ZIP’s Forrester study claims is an eye-catching number, but it’s worth understanding what’s driving it. Spend optimization in AI procurement rarely comes from a single dramatic renegotiation of a massive contract. It’s the accumulation of smaller wins: tail spend consolidation, faster cycle times that reduce maverick buying, better compliance that prevents leakage, supplier risk flags caught before they become supply chain emergencies. Forrester’s composite model showed a 70% reduction in request processing time and a 4-5x reduction in engineering overhead compared to legacy solutions. Those are real money, but they’re also efficiency gains that require volume and consistent platform usage to materialise. A CFO who expects the 386% ROI to show up in Q1 after sign-off is likely to be disappointed. As the VP of Strategic Sourcing at a large retail enterprise told Forrester, “We have far and away exceeded our savings expectations. From an ROI perspective, the business has enjoyed a 10X return.” Note the tense: enjoyed. Past. This is cumulative ROI measured over time, not a magic trick. Dollar Tree identified more than $100 million in savings, Northwestern Mutual saw significant gains through AI agents, and Discover eliminated 3,000 manual approvals annually. These aren’t vanity metrics. They’re also not universal. Success correlates tightly with the willingness to redesign processes, not just automate the existing ones. That’s the thread that connects every successful case study, regardless of vendor.

The Talent Equation Nobody Wants to Discuss Publicly

LinkedIn posts about AI in procurement tend toward the uplifting: “augment, don’t replace,” “upskill your team,” “human-in-the-loop.” The data tells a more complicated story. Zip’s report notes that 33% of organisations expect the team managing third-party spend to shrink, and the skill erosion they’re observing is concentrated below the executive level. This aligns with Swiss labour market research showing a 16% drop in entry-level procurement roles since the rise of AI, while senior positions increased 26%. Scale AI and the Center for AI Safety ran a bracing experiment: in real paid freelance work, the best available AI agents completed only 2.5% of projects to client-acceptable standards. That suggests the human isn’t disappearing anytime soon, but the nature of the work is changing fast. Entry-level tasks—validating intake forms, chasing down missing fields, routing approvals manually—are the first to be absorbed by AI. The roles that remain require judgment, supplier relationship management, and the ability to make sense of AI outputs that are often subtly wrong. A procurement director at a Fortune 500 manufacturer told me off the record: “I’ve got people who’ve spent ten years getting really good at tasks an AI agent now does in twelve seconds. Their next skill set can’t be ‘even better at that task.’ It has to be something else entirely, and nobody’s figured out a clean way to retrain at scale.”

[SPONSORED]

COMFYUI WORKFLOW OPTIMIZATION

Reduce render times by 40% with our automated edge-silicon pipelines. Download Whitepaper.

What Happens Next (Without Saying ‘Game-Changer’)

Zip has processed over $500 billion in spend and claims to have saved customers over $10 billion through its AI suite. It’s a Gartner Magic Quadrant Visionary (youngest ever in that quadrant), an IDC MarketScape Leader for AI-enabled spend orchestration, and backed by $371 million at a $2.2 billion valuation. More than 50 AI agents are live across hundreds of enterprise customers. These are substantial, credible signals. But the broader market is still mostly stuck. Only 5% have truly scaled GenAI in procurement, per EFESO. Only 9% have reached autonomous AI operations, per Zycus. The 6x ROI is real for those who’ve committed deeply, but the majority of enterprises are still standing on the sidelines, running pilots that were never designed to graduate. The “Bystander” label in Zip’s report might feel unkind, but it’s accurate. One thing has become clear: the companies that treat AI procurement as a software install aren’t the ones getting the 6x. It’s the ones treating it as a redesign of how money flows through the organisation—from the moment someone types “we need a supplier” to the moment the invoice is coded and the relationship is managed—who see the multiplier. The Builders aren’t buying a tool. They’re rewiring a function. The shadow AI problem, if anything, adds urgency. Employees aren’t waiting for the official rollout. They’re solving their procurement problems right now with tools the company can’t see, govern, or secure. The Builders might get the 6x. But the Bystanders are already bleeding data, and most of them don’t know it yet.

Editorial Disclosure: This commercial analysis is compiled from global informational platforms and developer community discussions. Due to rapid technical cycles, readers are advised to independently verify volatile metrics. FUTUREMARSNEWS maintains structural objectivity and independent neutrality. more
This publication is intended solely for commercial, educational, and informational purposes. Articles may include news reporting, editorial opinions, technical analysis, software tutorials, deployment guidance, benchmark testing, hardware evaluations, workflow optimization strategies, pricing references, market intelligence, developer resources, and enterprise technology commentary. Product specifications, APIs, licensing models, cloud pricing, benchmark results, software capabilities, commercial terms, and hardware availability are subject to change without notice. Any performance figures or comparisons are based on publicly available information, vendor documentation, independent testing, or specific test environments and should not be interpreted as universally representative. Readers are encouraged to verify all technical and commercial information directly with official vendors before making engineering, purchasing, investment, or operational decisions. Unless explicitly labeled as sponsored content, advertising, affiliate content, or paid partnerships, editorial decisions remain independent. FUTUREMARSNEWS does not warrant the completeness, accuracy, or future availability of third-party products, services, software, or information referenced within this publication.