
Humanitarian procurement is good at buying things that stay bought. A water tank is the same water tank the day after you sign for it. An algorithmic system is not, and that one difference breaks the current purchasing process.
The reflexive answer to AI risk in aid work has been to write more guidance. We have ethical AI frameworks, codes of conduct, assurance toolkits, and decision trees. Maybe too many responsible AI guidelines to follow as it is.
This is the wrong approach, according to a new Access Now report by Giulio Coppi, Reinventing Humanitarian Aid Procurement for the Age of AI. It argues that aid organizations lose control of algorithmic systems at procurement, and procurement is the one function almost nobody is reforming.
What you bought is not what you are running
Procurement assumes a static asset. You write a specification, run a competitive bid, evaluate the product against the spec, sign, and operate what you evaluated. That logic holds for generators and tarpaulins.
It fails for cloud-hosted software, because the vendor can change the product after the contract is signed, through updates you did not request and may not notice.
The report maps this directly. The most common way algorithmic features enter a humanitarian organization’s systems is not a purchase at all. It is a supplier-driven update or add-on to a product the organization already owns, sliding new functionality into the stack behind a terms-of-service notice and a download prompt.
The human rights impact assessment you ran at procurement, if you ran one, describes a product that no longer exists. Every meaningful update can quietly outdate it.
Sign Up Now for more humanitarian technology insights
Most algorithmic systems never reach procurement
If the asset mutates after purchase, the harder problem is that most of it was never procured at all.
The 2025 Humanitarian Leadership Academy found that, 93% of humanitarian workers had used or tried AI tools while only 8% of their organizations reported wide integration, and 69% reached for commercial platforms like ChatGPT and Claude rather than anything purpose-built.
None of that moved through a tender.
It moved through staff opening personal accounts on free tiers, because that is what a local organization can reach without a framework agreement it has no leverage to negotiate.
The report is blunt about what this means.
Local actors enter the algorithmic arena with little capacity to decipher or negotiate contractual terms, and almost none reach the paid tiers that carry the stronger privacy and security guarantees, so free-versus-paid access has itself become a new digital divide.
The data on the most vulnerable people in a crisis is flowing through the cheapest, least protected version of a tool no procurement officer ever saw. There is nothing to fix at the buying gate, because nobody walked through it.
If you bought it, you licensed a snapshot
If an organization procured an AI solution via a license agreement with one of the major providers, did what they bought match what you are using now?
A vendor can change in ways that have nothing to do with software. Companies pivot, merge, get acquired, take defense money, and abandon missions, in every sector. That is a real procurement risk and an old one, and it is not what makes algorithmic systems different.
Treating “the vendor changed” as the headline misses the failure that is specific to generative AI.
The specific failure is model drift – the product itself drifts while the contract, the interface, and the invoice all look identical. You evaluate a model’s behavior at a moment in time.
By the time a procurement cycle finishes, weeks or months later, what you signed for is a snapshot that was already stale, because the model you tested has been fine-tuned, re-routed, version-bumped, or retired in the interim, on a schedule you do not control and are mostly not told about.
This is measurable, not hypothetical.
Stanford and Berkeley researchers tested the March 2023 and June 2023 versions of GPT-3.5 and GPT-4 on identical tasks and found the same service behaved substantially differently across just three months.
On one math task, GPT-4’s accuracy fell from 84% to 51% over that window. Their conclusion was that when and how these models change is opaque to the people using them, and that the only adequate response is continuous monitoring.
Now put that inside a humanitarian deployment.
The IRC built aprendIA, the education chatbot it is taking to teachers in northeast Nigeria, Colombia, and Bangladesh, on OpenAI’s models. The model answering a teacher’s question this quarter is not guaranteed to behave like the model that was evaluated when the partnership was signed, and the IRC does not set the update schedule.
Multiply that across every organization that wired a commercial model into a frontline workflow, which the survey above says is most of them.
How can we write a competitive bid, evaluate against a fixed specification, and sign a fixed-term contract for a product that can change quarterly, monthly, weekly, even daily?
You cannot, with a process built for water tanks. The specification describes a moment. The product is a moving target, and the gap between the two widens every time the vendor ships.
Checklists make procurement heavier
The instinct to make procurement “strategic” turns easily into making it longer. The report’s own interviewees say so.
None of the organizations it consulted had set up a dedicated procurement protocol for algorithmic systems, and many considered building one a pointless exercise, because the dynamic nature of these tools outpaces any vetting process an under-resourced nonprofit can maintain.
Adding more forms, the report concludes, would be performative and ultimately ineffective. A procurement officer handed a stack of new AI assessment templates is right to ask what risk they prevent.
So the case for strategic procurement only holds if “strategic” means something other than “more paperwork.”
What strategic procurement demands
Strategic means continuous. The transactional model fails because it treats procurement as a moment, and the model-drift problem is the proof: a moment is exactly the wrong unit for a product that moves weekly.
The first fix is to treat every material change to an algorithmic product as a trigger that can reopen the assessment, and to monitor vendors and their models across the life of the contract rather than vetting them once at the start.
The report borrows the right idea from cybersecurity: zero trust. Stop treating “trusted provider” as a fixed category, assume any system inside your environment can be altered without notice, and build the monitoring to catch it when it is.
There is a more direct answer to drift than watching for it: take the upgrade path out of the vendor’s hands. An open-weight model you host yourself does not change unless you change it.
At Intelehealth, we chose self-hosted open models for exactly that reason, because we did not want a vendor silently updating a model and shifting our clinical decision-support outputs without our testing or consent.
In a tool that walks a community health worker through a patient encounter, a model that changes its answers from one week to the next puts patient safety at risk. Owning the weights is the route the Access Now report itself recommends, privileging small language models and locally owned, self-hosted open-source systems over dependence on a handful of cloud providers.
It is not free. You take on the hosting, the maintenance, and the in-house skill to run it, which is a real cost that many organizations cannot carry. But it converts drift from something done to you into something you schedule, after you have validated what changed.
Monitoring drift and owning the model both demand the same thing structurally: not a procurement task, but procurement, IT, legal, cybersecurity, and protection working as one standing function instead of a committee that reconvenes per purchase.
On a base of more than €20 billion a year in humanitarian procurement, the sector has the scale to staff this. The open question is whether donors will pay for it as core capacity rather than overhead to be squeezed.
The strategic procurement function needs to be:
- Locally owned, prioritizing self-hosted open-source models over default Big Tech dependence.
- Integrated, merging procurement with cybersecurity, legal, and protection into one team that holds authority over the whole digital stack rather than signing off at the end of it.
- Open by default, requiring open procurement and minimal non-disclosure agreements instead of treating procurement reform as administrative cost.
- Demanding of vendors, forcing tech companies to disclose planned changes to the models behind their products, version those models so a buyer can pin and test what they run, and warn clients before behavior shifts underneath them.
Is procurement reform really the answer?
An organization that just lost half its budget will not staff a standing tech-governance function. It will open a free ChatGPT account and get back to work. Demanding otherwise without funding the capacity is how “strategic procurement” becomes one more bar the well-resourced clear and everyone else fails.
Also, if the people who buy the software are now a minority voice in deciding what it does, the honest move is not to give procurement a better checklist. It is to admit procurement was never the control point we pretended it was, and decide what should be.

