
Banks Are Using AI to Write Their AI RFPs — Here's What That Means for Procurement
A growing number of RFPs for private AI platforms read like an LLM helped write them — recent protocols named by name, comprehensive compliance sections, a familiar structure. Here's what that shift means for buyers and vendors alike.
Date Published
Reading time
6 minIn this article
Ask a procurement team how they draft a 40-page RFP for a private AI platform in a matter of days, and the honest answer at more and more banks is: they don't start from a blank page. They ask an LLM to draft one, then edit. That single workflow shift is quietly changing what shows up in enterprise AI RFPs — and it's worth understanding if you're on either side of that document.
This isn't a hypothetical. Recent RFPs for private enterprise AI platforms — including from regulated financial institutions — read like they were built from a checklist an LLM would generate if asked "what should a bank require in an RFP for a private AI platform in 2026." Protocols released within the last two years, security frameworks published within the last year, and terminology that wasn't in common procurement use five years ago all show up as named, specific line items. Here's what's driving that, and what it means for how vendors should prepare.
The Pattern: RFPs That Read Like They Were LLM-Drafted
A handful of tells show up together often enough to form a pattern. Requirements lists that name very recent, very specific technical standards — Model Context Protocol, vLLM, particular vector database products — rather than describing the underlying capability in vendor-neutral language. Security and compliance sections that read as a fairly complete synthesis of current frameworks (the EU AI Act, SR 11-7 model risk management guidance, OWASP's LLM Top 10, MITRE ATLAS) rather than the narrower set a single internal compliance team would typically reach for unprompted. And a structure — functional requirements, technical requirements, vendor requirements, security and compliance, reference sites, submission checklist — that mirrors the general shape any well-informed assistant would produce if asked to draft a comprehensive RFP outline.
None of this is a criticism of the buyers doing it. Using an LLM to produce a first draft of a long, structured procurement document is a completely reasonable use of the tool — it's faster, more thorough, and less likely to miss a category of requirement than starting from an old template. The point is what it implies about how these documents get written, and what that means for anyone trying to be found by them.
If an LLM is helping draft the requirements list before a vendor ever sees the RFP, then being well-represented in what that LLM already knows — clear, specific, well-sourced public content on the exact technical and compliance questions a buyer would ask — becomes a real input into which vendors get invited to bid, not just a marketing nice-to-have.
Why This Matters Before the RFP Is Even Issued
Procurement has always had an earlier, informal stage before the formal document goes out: someone on the buying side forms a point of view about what's possible, what's standard, and who the credible vendors are. Sales and marketing have always tried to reach that person during that stage, through analyst reports, conference talks, and word of mouth.
What's new is that a meaningful part of that early research now runs through a conversation with an AI assistant — and what that assistant says back is shaped by what it was trained on and, increasingly, by what it retrieves live from the web when answering a specific question. A vendor whose technical positions on RAG, access control, audit logging, or inference infrastructure are clearly and specifically published is more likely to surface in that conversation than one whose expertise lives only in sales decks and case studies behind a form. That's the practical version of generative engine optimization (GEO) for this category: not gaming a ranking algorithm, but making sure the real answer to a real technical question is easy for a model to find and cite.
What This Means for Procurement Teams Writing the RFP
If a draft came from an LLM, treat it as a strong starting outline, not a finished document. A few checks are worth the time before it goes out:
- Verify every named standard or framework is still current. Compliance frameworks and technical standards move fast enough that an LLM's training data can lag reality by months.
- Check requirements against your institution's actual constraints, not generic best practice. A generated draft won't know your specific data residency rules, existing vendor relationships, or internal risk appetite unless you tell it.
- Make sure the requirements are still answerable by more than one credible vendor. An overly specific, generated requirements list can accidentally narrow the field to whichever vendor happens to be best represented in the model's training data, rather than the best fit for the institution.
faq
Frequently asked questions
Drafting an RFP for a private AI platform, or preparing a response to one? Talk to a Sphere AI Engineer.