Core claim: Vendor assessments have started asking a question most suppliers cannot answer — how much of your codebase is AI-written, and how is it reviewed? — and the way you answer it is quietly becoming a procurement signal: an estimate says “we don’t track this,” while evidence says “we run a controlled process,” long before anyone reads the details.
The questionnaire grew a new section
Anyone who sells software to enterprises knows the ritual: the security questionnaire, the sub-processor list, the business-continuity attachment. That stack has started growing a new section. Buyers ask what share of the delivery is machine-generated, which AI tools the team uses, whether AI-written changes get human review, and how all of that is documented. Procurement teams copy questions from each other — it is how the ritual has always evolved — which means a question that appeared in a few assessments this year will be standard boilerplate next year.
The trigger is not curiosity. Buyers carry their own obligations — supply-chain security expectations, the EU’s product liability and cyber-resilience regimes described in our earlier articles, insurers asking about AI exposure — and every one of those flows downhill into the vendor questionnaire. Your customer’s compliance burden becomes your sales burden. That is the same mechanism that made SOC 2 reports and sub-processor lists table stakes.
Estimates read as “we don’t know”
Most teams today answer the AI question with a number someone made up in good faith: “roughly 30%.” It is an honest guess — and an experienced assessor recognizes it as exactly that, because the team cannot say where the number comes from. The follow-up questions land immediately: measured how? Over which period? Reviewed by whom? An estimate followed by silence tells the assessor the real answer: this team does not track authorship in their own codebase.
Contrast the team that answers from a record: this share of changes in the last twelve months was machine-authored, here is the review coverage on those changes, here is how a third party can verify the record without trusting us. The number itself matters less than its provenance. A supplier who can show how they know passes a different kind of judgment than a supplier with a rounder, prettier, unsourced figure — the same way audited accounts read differently from a spreadsheet, whatever the totals say.
The assessment is an opportunity wearing a checklist
Here is the asymmetry worth acting on: right now, almost nobody can answer the question well. That is precisely what makes it a differentiator. The vendor who responds to the AI section with a verifiable evidence trail — recorded while the work happened, checkable offline, independent of the vendor’s own word — does not just clear the bar; they reset it for whoever is compared against them next. And because provenance evidence can only be recorded going forward, the gap between “started recording last year” and “will start when a customer insists” widens every week.
The question is already in the questionnaires. The teams that treat it as a filing chore will keep shipping estimates. The teams that treat it as a trust surface get something rare in enterprise sales: an answer the buyer can check for themselves.
When the assessment asks who wrote your code, “about 30%” is an answer. A record the buyer can verify is an advantage.
This follows article 1, “Who wrote your code? The provenance gap in AI-built software” — the provenance gap it describes is now arriving in procurement, one questionnaire at a time.
Sources
- Article 1’s regulatory sources carry the underlying obligations that drive buyer questionnaires: Product Liability Directive (EU) 2024/2853 — https://eur-lex.europa.eu/eli/dir/2024/2853/oj (CELEX 32024L2853); Cyber Resilience Act (EU) 2024/2847 — https://eur-lex.europa.eu/eli/reg/2024/2847/oj (CELEX 32024R2847).
- This article’s claims about assessment practice are observational (how procurement questionnaires evolve), not legal claims.