Transcript 0:00 You've seen this demo. The agent picks up an intake request, it drafts the RFQ, ranks the responses, writes the award memo all automatically. 0:10 Heads nod, somebody says, "This is the future," somebody else asks about implementation timelines. 0:18 Now, I've sat through dozens of these demos in the past couple years, and I've almost never heard anybody ask the one question that to me matters most: 0:28 Which large language model are you calling in the back end to make this work? 0:32 [on-hold music] Welcome to ProcureTech Unpacked. I'm Joel Conin de Merce. 0:49 This is the show for procurement professionals who wanna understand the technology shaping our function. So here's the thing about that question. 0:56 Almost every vendor selling you procurement AI agents is calling Claude, ChatGPT, Gemini, or Copilot in the background. They are not building their own LLM models. 1:07 They're getting them by the API call and then wa-wrapping workflow data and user experience around the response. That's not a criticism. It's the rational choice. 1:18 Nobody in ProcureTech should be burning capital trying to train and build an LLM model, at least not at this day and age. But it does mean something specific for you as a buyer. 1:29 A core dependency of the software you're about to sign for is a downstream supplier that you never evaluated, never contracted with, and cannot see. In direct procurement, we map and tier supplier risk all the time. 1:42 This is the same exercise one layer down, but in the software stack. All right, so here's my thesis. Everything after this is the case for it. 1:51 In the next few months, savvy organizations will stop accepting whatever model their software vendor ships out of the box and will start requiring support for models that they've already vetted and approved themselves internally. 2:04 Bring your own LLM. I've been talking about this on the show for a while now, and this is the time where I detail the why behind it. 2:12 So procurement should be right there with IT at the forefront of this conversation, and there's four forces that, in my opinion, are pushing us there. Number one, cost. 2:22 A few weeks ago on the show, I covered how the era of cheap, predictable frontier large language models is slowly ending. Subsidized adoption, then load-bearing dependency, then usage-based billing. 2:35 It's the same playbook that cloud ran a decade ago. And if you're low on the maturity curve and not using LLMs much today, this is sort of background noise for you. 2:45 But if you're already running agents across thousands of workflows every month, the token bill is gonna stop being background noise very quickly. 2:54 Right now, the true cost is buried inside your vendor subscription price, but I don't think it's gonna stay buried for long if you're using lots of tokens and that usage is growing. Number two, performance. 3:08 Do you need the most expensive leading large language models to classify spend data? Probably not. Model selection is a price-performance decision, and it's task specific. 3:20 So extracting fields from a PO confirmation, for example, is not the same job as drafting negotiation strategy against a sole source supplier. 3:29 Different tasks should be routed to different models at different price points depending on complexity. And right now, your vendor is making those routing decisions for you, and they might not be the right ones. 3:43 Number three, data security. Where an LLM model provider sits determines which privacy and data residency laws will apply to whatever data your people feed into it. 3:53 We saw this play out in real time with the Fable release in the US, and your people are feeding it plenty of data. 4:01 LayerX's October twenty twenty-five report, uh, around the enterprise AI and SaaS data security found that among employees using GenAI tools or large language models, seventy-seven percent paste company data directly into them, and eighty-two percent of those pastes come from unmanaged personal accounts that are outside your firewall. 4:22 Now, that was in October of last year, so hopefully it's improved, but you get my point. 4:27 And then to add, Cyberhaven's twenty twenty-six AI Adoption and Risk Report puts roughly forty percent of all these AI interactions as involving sensitive data. 4:39 I've seen other figures around thirty, thirty-five percent, but still, you know, one in three prompts or discussions with large language models have sensitive data in them. 4:51 That's a shadow AI problem, and most chief information security officers are already on it. However, the version that nobody's de-dealt with yet is much quieter. 5:01 It's the sanctioned procurement platform or the sanctioned platform in any other function for that matter. 5:07 The one that you bought, the one that you passed through security review that is releasing new functionality that's agentic and silently routing your supplier pricing, your contract terms, your payment data to a model in a jurisdiction that nobody on your team has checked. 5:23 So nobody pasted anything, but the integration is doing it on its own. Number four, control. This is build versus buy, but applied to LLM models. 5:34 On one end, you've got a closed API where everything behind it is a black box, and most of these US frontier models are exactly that. 5:42 On the other, you've got open source models that you could download, uh, change the code, run on your own infrastructure. You can even run them offline if you want. And you've got stuff everywhere in between. 5:54 And so more control means more fit for exactly the problem you're trying to solve, but it also means more maintenance, version testing, depreciate-- uh, depreciation cycles, uh, security patching, et cetera. 6:08 Regulated industries, defense, and anyone with data sovereignty requirements that are really, really stringent will want that trade, but smaller businesses probably won't or probably co- can't even support that trade. 6:21 Now, those are my four elements, and I think that's what's pushing us towards bring your own LLM. I don't think it's speculative because in enterprise software generally, it's already shipped. 6:33 If we look at Salesforce Agentforce, UiPath, GitLab Duo, all of them now let you bring your own model, and all of them frame it the same way, control the cost, control compliance, control sovereignty. 6:46 Every one of those vendors originally shipped a managed model and told customers, "Ah, don't worry about it," and every one of them now offers you a way out. And procure tech isn't at zero either. 6:57 There are platforms in our space that will let you bring your own models today if you ask and if you've done the homework on what you want to run and why. I know that for a fact, but it's nowhere close to generalized. 7:10 For every one vendor who will have this conversation, there's several who have made the decision for you and have just never brought it up in the demo or the discovery calls. 7:19 So the question isn't whether this is coming, it's whether the vendor that's sitting in front of you is ahead of it or behind it. And if we follow this logic to the end, uh, it lands in one place. 7:32 Large language models are becoming a utility-like spend category, not a feature, not a line item buried inside a SaaS subscription, but a metered input consumed continuously, priced by volume with switching costs and supply risks baked in. 7:49 Your team has run this playbook before if you've got IT category managers for cloud or in your telecommunications and mobile phone, uh, domains or even energy. 8:00 So mature organizations are gonna do what mature organizations do. 8:04 They're gonna build a vetting process, approve a shortlist instead of a single source since nobody's landing on one model provider for everything as the concentration risk is too obvious, especially if you're going full agentic and the price performance spread across tasks is really too wide. 8:21 You're gonna wanna start monitoring continuously for price changes, for performance drift, and you're gonna wanna split ownership clea-cleanly. 8:29 IT is gonna ow-own a lot of these operational considerations, but you as procurement are gonna wanna own the commercial ones. 8:36 And so once you have your vetted list of model, the thesis I opened with stops being a prediction. It's just the next line in your software sourcing requirements. 8:47 So what do you actually do with this information Monday morning? Put questions in your next software RFP to at least start gathering information around how your software providers are dealing with LLMs. 9:00 Here's three that I'd start with. Number one, which LLM providers and specific models that you use as your platform call? Name them. 9:08 Number two is our data, our prompts, our documents, our outputs, are they sent to the models in the back end? Is there anonymization of data? And number three, if we bring our model, how does your pricing change? 9:19 That third one is one that most vendors have not thought through or haven't been asked much. Ask it anyway. 9:25 If the answer is that, uh, that pricing doesn't change, then you should start asking why you're paying twice for the same type of functionality, right? If you're already paying the LLM portion of it on your end. 9:37 Here's why I'm telling you this now. Right now, none of this is expensive. 9:41 Token costs are buried, the vendors are still in land grab mode, and adding a bring your own LLM clause to a contract you're already negotiating costs you a conversation. 9:51 In two years, when your agentic platform is load-bearing, you're using it a lot more, the invoice has arrived for tokens, that same clause costs you leverage that you no longer have. 10:03 If your organization is racing towards becoming an agentic one, it's procurement's job to flag the supplier risks sitting underneath it. 10:11 And if IT hasn't looped you into this conversation yet, don't wait for the invitation. Start it yourself. Thanks so much for tuning in. We'll see you next time. 10:19 [upbeat music] That's a wrap on this episode of ProcureTech Unpacked. If this one resonated, subscribe wherever you get your podcast and sign up for the ProcureTech newsletter for weekly insights between episodes. 10:31 If something we covered sparked a question or an idea, we'd love to hear from you. All the links for the reports we discussed are in the show notes. We'll see you next time. [upbeat music] Resonate.