AI Governance Is Arriving Through Procurement
Table of Contents
If you’re a manufacturer, supplier, or operations leader asking which AI law applies to you, you may be watching the wrong door. The first real deadline often arrives through a customer contract, a renewal packet, or a supplier questionnaire with a due date, not through a statute that names your company directly.
A clear example is Fannie Mae Lender Letter LL-2026-04, published April 8, 2026 with an effective date of 120 days out: August 6, 2026. It requires seller/servicers to govern vendor and subcontractor AI use to a standard no less protective than their own. That matters well beyond mortgage, showing how AI governance moves through procurement and into companies that were never named in the original rule.
This post explains why that pattern matters, what a supplier AI questionnaire is really asking for, and what to put in place before someone asks.
Why does this question keep showing up in supplier packets?
Picture a supplier quality manager opening a routine annual vendor packet from an OEM customer: same portal, same timeline, same expectation that the forms will be easy to finish because they were easy last year.
Then a new section appears, with eleven questions about artificial intelligence: which AI systems touch the parts you supply, what data those systems process, who validated them, and what happens when a software vendor changes the model behind a tool you’ve been using for two years.
Nobody on the distribution list knows who owns the answer. The company doesn’t even think of itself as “using AI” in any formal way.
That’s why the usual question, “Which law applies to me?”, isn’t enough on its own. For many mid-market manufacturers, the honest answer is still “none of them, not directly.” The obligation can still arrive anyway, through procurement rather than legislation.
What changed on August 6, 2026?
The easiest current example is Fannie Mae’s new AI governance requirement.
In plain language, Lender Letter LL-2026-04 tells Fannie Mae seller/servicers, the companies it buys mortgages from and the companies that service them, to maintain documented governance around AI and machine learning use. That includes policies, oversight, risk management, and the ability to explain what systems are being used and for what purpose.
The sentence that matters most for everyone else is this one:
Seller/servicers must manage the risks and governance of vendor and subcontractor AI use to a standard no less protective than their own.
Fannie Mae doesn’t need direct authority over every vendor in the chain: only authority over the company that buys from them.
How do AI governance obligations flow down to companies no law names?
This is where the issue becomes practical.
Fannie Mae can’t send a letter to a small supplier in another industry and demand an AI inventory. What it can do is require its seller/servicers to manage third-party AI risk. Those seller/servicers then reach vendors the only way they know how: through contract terms, onboarding packets, renewal language, questionnaires, and procurement conditions.
In other words, the entity holding the obligation and the entity doing the work are often different entities.
That’s why these deadlines can feel so confusing when they first appear. The supplier answering the questions may never have tracked the original rule, read the underlying letter, or considered itself part of an AI governance conversation at all.
🛡️ Responsible AI Note: ISO/IEC 42001 calls this out directly in Annex A.10.2 and A.10.3. If you can’t clearly explain who owns outcomes across your AI value chain, your company, your vendor, or your vendor’s vendor, that accountability gap becomes a real business risk quickly.
Why is this bigger than mortgage?
I’d be less confident about this if mortgage were the only place it were happening.
Government contracting is already moving in the same direction. This June 2026 GSA clause analysis describes proposed safeguards for large language model use that would flow through the supply chain to developers, integrators, and service providers who may never sign the prime contract themselves.
If you’re in defense or aerospace, you’ve already lived through the finished version of this. CMMC and DFARS requirements didn’t matter to lower-tier suppliers because Congress singled them out by name. They mattered because primes pushed common security expectations down the chain. A supplier who wanted to keep the work had to answer the questionnaire. This CMMC flow-down explainer captures that pattern well.
The same mechanism shows up here as a procurement story and a supplier-readiness story, well beyond mortgage.
What does softer federal guidance actually mean?
I want to be careful here, because there’s a version of this argument that overstates itself, and it’s not the one I want to make.
On April 17, 2026, shortly after the Fannie Mae letter, the federal banking agencies issued revised model risk management guidance in OCC Bulletin 2026-13. The tone was more proportional than punitive. The guidance is non-enforceable on its own, and it explicitly excludes generative and agentic AI from scope.
However, the federal guidance got looser and narrower in the same month the contracts got tighter and broader. I read that less as a contradiction than as the actual finding. Right now, the counterparty is where the pressure comes from, and a counterparty doesn’t need enforcement authority to create it, only the power to delay, deny, or condition the work.
🛡️ Responsible AI Note: When guidance leaves room for judgment, human oversight matters more, not less. Teams need a plain-language explanation of who reviews important AI-assisted outputs, what gets checked, and when someone can stop or override the process.
What is a supplier AI questionnaire really asking for?
Most supplier AI questionnaires look longer than they are. Underneath the wording, they usually ask for four things you can’t assemble honestly at the last minute.
- An AI inventory. A current list of systems, features, and vendor tools using AI in ways that affect work, decisions, or customer outcomes. This includes embedded features you didn’t intentionally buy as “AI.”
- A supplier standard. A written expectation of what you require from vendors and subcontractors, specific enough to act on rather than a general AI policy statement.
- Validation records. Evidence that a person checked higher-risk uses of AI and documented what they reviewed, what they found, and what action followed.
- A change-notification path. A way to learn when a vendor changes a model, adds a new AI feature, or materially changes how an existing system behaves.
These are the quiet pieces of operational discipline that make a company look prepared instead of surprised.
🛡️ Responsible AI Note: Inventories are boring until someone asks for one. They’re also hard to recreate after the fact. If a system influenced an outcome six months ago, memory and guesswork aren’t a substitute for documentation. That’s why inventory and recordkeeping sit so close to the center of responsible, human-first AI governance.
How should you prepare before the questionnaire arrives?
If this topic feels abstract, the next steps don’t have to be.
- Start with visibility. List the AI systems your team uses today, including features inside existing software.
- Decide where accountability sits. Name who owns inventory, vendor review, validation, and escalation.
- Write the minimum standard. Document what you need from vendors before AI use touches customer work, quality, safety, or sensitive data.
- Plan for review. Make sure a person can inspect important outputs, challenge bad results, and stop a workflow when needed.
That turns responsible AI into everyday operations instead of an abstract policy conversation: a clear workflow for the people who actually have to answer the questions.
If a questionnaire is already on your desk, the work is still worth doing, just more stressful under deadline. If you have a quiet month, use it: that’s often the cheapest time to build an honest inventory and a workable supplier standard.
For companies that want help structuring that work, Violet Beacon’s services focus on practical, human-first AI adoption and governance.
What should you take away from this?
What I’d say to a manufacturer reading this: don’t wait to find out whether an AI law names you. It probably won’t, and that won’t protect you.
Watch your customers instead: the industries they answer to, and the questionnaires they’re likely to inherit. If your business depends on regulated buyers, government buyers, primes, or large OEMs, there’s a good chance AI governance reaches you first through them.
The companies that handle that shift best will be the ones that can answer simple questions clearly: where AI is used, who owns it, how it’s reviewed, and what happens when a vendor changes the system.
That’s the work. It’s not glamorous, and it’s also much easier to do before the deadline arrives.
How AI Was Used in This Post
AI helped research this piece, pulling the primary regulatory documents and checking dates against the source rules instead of secondhand coverage. Kate Waldhauser drafted, edited, and composed the final piece. The header image is AI-generated.
Key references
Frequently Asked Questions
Not directly. Lender Letter LL-2026-04 binds Fannie Mae seller/servicers. It matters outside mortgage because it requires those seller/servicers to govern their vendors' and subcontractors' AI use to a standard no less protective than their own, which pushes the requirement into companies Fannie Mae has no direct authority over. The same structure appears in other sectors.
Flow-down is when an obligation placed on one company gets passed to its suppliers through contract terms rather than through law. The supplier isn't named in the underlying rule and may not be regulated at all, but has to comply to keep the business. Defense contractors know this pattern from cybersecurity requirements like DFARS and CMMC, and it's now happening with AI.
Four things, in rough order of difficulty: an inventory of every AI system in use including vendor-embedded features, a written standard you hold your own suppliers to, validation records for any AI that affects product or decisions, and a defined path for finding out when a vendor changes a model. None can be assembled quickly, which is the reason to start before the request arrives.
Annex A.10 is the relevant family. A.10.2 covers allocating responsibilities across the AI value chain, and A.10.3 covers suppliers specifically. In the NIST AI RMF, the closest equivalents are GOVERN 6.1 and 6.2.
Want your AI governance program ready before a customer asks?
Get Violet Beacon's Responsible AI Guidelines: practical standards for inventory, oversight, and vendor risk.
Get the Guidelines