---
title: "Rewiring Procurement for AI Advantage"
author: "Richard St-Pierre"
date: 2026-01-30
category: Policy
tags: ["procurement-reform", "ai-policy", "digital-government", "interoperability", "vendor-lock-in", "canada", "open-standards", "modular-contracting"]
summary: "Canada can make AI a durable engine of national productivity — but only if the federal procurement model shifts from project-by-project buying to platform-level orchestration. This paper argues the government must act as ecosystem orchestrator, setting open standards and buying outcomes in modular competitions, and lays out ten concrete procurement shifts and a 24-month action plan to fix the pipes through which AI must flow."
url: https://richardstpierre.com/articles/rewiring-procurement-for-ai-advantage
---

# Rewiring Procurement for AI Advantage

> **Key finding:** Two-thirds of Canada's ~7,500 federal applications are reported in poor health. AI must work *during* modernization, not after it — which means success hinges on adapters, open APIs, and contract models that pay for integration, not greenfield demos.

## Executive summary

Canada stands at a hinge point. AI can be a durable engine of national productivity, service quality, and security — **but only if the federal procurement model shifts from project-by-project buying to platform-level orchestration**. Today's rules and rituals give an *illusion of control* while entrenching vendor lock-in, fragmenting data, and slowing adoption. The result is negative compounding — literally an "Innovation Tax" on Canada: each year of slow adoption widens capability gaps, raises migration costs, and deepens technical debt across thousands of legacy systems.

**Thesis.** The federal government must act as *ecosystem orchestrator*, not product builder. It should set the rails — standards, governance, interfaces, incentives — and let a broad supplier base compete to deliver modular capabilities that plug into a common AI platform layer. This requires explicit procurement reform: outcome-based, modular competitions; mandatory portability and open interface clauses; a national AI interoperability scheme; and investment vehicles that reward integration with legacy systems, not greenfield demos.

**Why now.** The policy stack is ready (TBS Policy on Service and Digital; Algorithmic Impact Assessment; GC API Standards), and there is hard evidence of the problem's scale (two-thirds of ~7,500 federal applications in poor health). AI can deliver measurable improvements in service productivity and integrity, but only if we fix the pipes — procurement and interoperability — through which AI must flow.

**Bottom line.** Move in the next 24 months from one-off RFPs toward an AI ecosystem platform anchored in open standards, modular contracting, and portable architectures. The prize is a compounding productivity effect across the state and the economy; the risk of inaction is a compounding deficit of capability and cost.

## 1) The opportunity: AI as an engine of public-sector productivity and trust

AI's promise for the state is pragmatic: fewer backlogs, faster eligibility decisions, higher fraud detection, better service routing, and safer operations. Other governments estimate multi-point savings in public outlays through digitization and AI — savings primarily from administrative simplification, workflow automation, and compliance analytics — while cautioning that benefits require disciplined execution and governance.

Canada already has assets to build on:

- **A policy baseline for responsible use** — the Directive on Automated Decision-Making (ADM) and its Algorithmic Impact Assessment (AIA) tool institutionalize risk-tiering, transparency, and explainability. These instruments can be extended to generative and assistive AI and linked to procurement.

- **Digital standards favoring openness** — the Government of Canada Digital Standards explicitly call for the use of open standards and solutions, supported by API standards that encourage abstraction and interoperability.

- **Security guardrails** — work on Zero Trust architecture and GC Cloud Guardrails provides a path to deploy AI securely in multi-cloud environments.

These foundations can support a national AI ecosystem that compounds capability across departments and, via procurement, catalyzes private-sector adoption.

## 2) The constraint: our procurement model creates an illusion of control

**The current process favours big, monolithic awards that hard-wire vendor choices into architecture.** Detailed RFPs specify solution designs far upstream, foreclosing competition on how best to meet outcomes and making change costly later. International watchdogs and national audit bodies point to vendor lock-in — particularly in cloud and software licensing — as a persistent risk that reduces negotiating leverage and inflates lifecycle costs.

**Illusion of control.** Traditional compliance checks (pages of requirements, heavy artifacts) look like control, but they *shift* control to incumbents by freezing designs and making exit expensive. The EU's guidance on interoperability and open standards is blunt: when public buyers don't enforce open interfaces, lock-in grows and innovation stalls.

**Result:** fragmented pilots that don't scale, limited reuse across departments, and long migration tails.

## 3) Why AI makes lock-in even costlier

AI systems are *composite*: data pipelines, feature stores, model hubs, prompt and retrieval services, evaluation harnesses, MLOps/LLMOps, policy enforcement, and observability. No single vendor can or will own this full stack sustainably — **the value emerges from orchestration and interchangeability**. Standards such as NIST's AI Risk Management Framework and ISO/IEC 42001 emphasize governance across the system lifecycle, not allegiance to a particular tool. Procurement must therefore focus on properties (portability, transparency, auditability) rather than brands.

## 4) Canada cannot outspend the United States — and should not try

The U.S. is deploying *hundreds of billions* across CHIPS and climate-tech industrial policy, including roughly **US$52.7B** for semiconductors alone under the CHIPS Act, plus large, flexible tax credits under the Inflation Reduction Act. Canada's fiscal instruments are material but smaller — e.g., the **$15B Canada Growth Fund** (not in the right area of focus) — and cannot replicate U.S. scale. **Our advantage must be strategic: change the game with ecosystem rules, not subsidy volume.**

## 5) The operational reality: AI must integrate with thousands of legacy systems

The Auditor General reports that **~7,500 federal applications** exist across departments and agencies, with **two-thirds reported in poor health**, including many mission-critical systems. This is the environment AI must inhabit; it cannot wait for full modernization. **Therefore, success hinges on adapters, open APIs, and contract models that pay for integration, not just demos.**

## 6) Government's role: orchestrator, not solution provider

**Definition.** Orchestration means establishing shared rails — **reference architectures, common data models, open APIs, trust and risk frameworks, evaluation and monitoring infrastructure — and then running modular procurements for capabilities that plug into those rails.** This mirrors "government as a platform" thinking and global digital public infrastructure (DPI) practice (e.g., GovStack), which emphasize reusable building blocks and whole-of-government interoperability.

**What this unlocks.** With stable interfaces, departments can swap components (e.g., RAG providers, model gateways, red-team tools) without rewriting everything. Competition moves from *who wins the mega-contract* to *who delivers the best module against a common test suite*.

## 7) Procurement reform — ten concrete shifts

### 1) Mandate open interfaces and portability

Insert standard "no lock-in" clauses in all AI-related procurements:

- Data and metadata portability (including embeddings, vector indexes, and evaluation traces).
- Model portability commitments where feasible (e.g., ONNX/MLflow export or weight escrow for fine-tunes; documented prompts/templates for generative systems).
- API conformance to GC Standards on APIs; publication of interface specs and change logs.

### 2) Buy outcomes in small modules (modular contracting)

Use *short, iterative* task orders to deliver narrowly scoped capabilities with objective acceptance tests (latency, accuracy, bias metrics, interoperability). Draw on modular contracting approaches formalized in FAR 39.103 and the TechFAR playbook, adapted to Canada's context.

### 3) Create pre-qualified capability pools

Establish supply arrangements for specific AI building blocks (e.g., retrieval layer, red-teaming, evaluation, data quality tooling, model governance) with rolling on-ramps and periodic bake-offs against common test suites aligned to NIST AI RMF and ISO/IEC 42001 practices.

### 4) Separate "platform" from "apps"

Procure the **GC AI Platform Layer** (identity, policy enforcement, model registry, observability, evaluation harness, prompt hub) as a government-operated foundation with open interfaces. Then procure applications as plug-ins. This is consistent with digital public infrastructure practice (GovStack) and reduces duplication.

### 5) Tie funding to integration, not pilots

Weight evaluation criteria toward demonstrated integration into *at least two* existing systems (adapters, ETL, APIs) and contribution to shared assets (reusable connectors, playbooks), with higher scores for re-use across departments. **Pay for the hard thing.**

### 6) Require evidence and transparency

All AI procurements above a risk threshold must include an ADM-compliant AIA, public model cards/decision documentation, and ongoing publication of evaluation metrics. Align with TBS ADM Directive and AIA disclosure practices.

### 7) Embed security by design (Zero Trust + Guardrails)

Ensure every component — open source or proprietary — meets GC Cloud Guardrails within 30 days of account provisioning and follows the GC's Zero Trust trajectory. Build portability *and* security into the base contract.

### 8) Use challenge and innovation procurement as *feeders* — not substitutes — for production

Innovative Solutions Canada and challenge-based pilots remain vital for de-risking novel approaches, but winning pilots should graduate only when they meet platform interface and security requirements.

### 9) Institute spend controls for platform consistency

Borrow the UK model: require central approval for digital/AI spend that duplicates platform capabilities, and publish an annual "risk and importance" portfolio to steer reuse. This is about functional assurance, not micromanagement.

### 10) Publish the rules of the game

Codify the "AI Orchestration Playbook": reference architectures, interface specs, evaluation protocols, audit requirements, and reusable artifacts. Keep it evergreen and open.

## 8) Architecture: the GC AI ecosystem platform

**Layer 0 — Secure infrastructure.** Multi-cloud landing zones hardened by GC Cloud Guardrails; network segmentation; key management; logging; identity federation with role-based access and attribute-based controls.

**Layer 1 — Data exchange and contracts.** Common data models for high-value domains; streaming and batch gateways; data contracts and lineage (OpenLineage-style), with privacy/classification labels enforced at the interface. (Align with Digital Standards' emphasis on open standards and API abstractions.)

**Layer 2 — Model and retrieval services.**

- **Model Gateway:** policy-enforced access to multiple model providers (foundation, domain-specific, department fine-tunes), with adapter interfaces to swap vendors.
- **RAG & Knowledge Layer:** vector stores, document loaders, and evaluation suites, standardized across departments.
- **Evaluation and Monitoring:** bias, robustness, safety, performance; red-teaming workflows; logging for explainability and audits — mapped to NIST AI RMF.

**Layer 3 — Application plug-ins.** Task-specific agents (eligibility triage, correspondence drafting, case summarization, regulatory search, OSINT for enforcement) that consume Layer-2 services through stable APIs and publish their telemetry for oversight.

**Layer 4 — Governance and assurance.** Central policy services (policy-as-code engines), AIA repository, audit APIs, and capabilities for incident reporting and rollback. **Design for explainability at the platform level, not app-by-app.**

## 9) Why this must be procurement-led

**Technology leadership is necessary but insufficient.** Without procurement reform:

- Vendors optimize proposals for compliance theatre, not integration.
- Departments recreate duplicative stacks because RFPs reward "complete solutions."
- Exit costs mount; switching becomes politically and financially prohibitive.

OECD's procurement principles underscore that procurement used strategically enables productivity, inclusion, and trust; that is the lever we control now.

## 10) Addressing common objections

**"RFPs protect us from risk."** They protect against *some* risks while amplifying others (lock-in, technology obsolescence). Modular competitions with strict acceptance tests and portability clauses reduce total risk by making change *cheaper*. U.S. modular contracting policy exists for precisely this reason.

**"Open standards reduce performance."** Open interfaces do not preclude high performance; they create contestability. The EU's interoperability guidance links open standards to better long-term value and lower lock-in.

**"We can copy U.S. playbooks."** We should adopt techniques (modular contracts, tech playbooks), but attempting to match U.S. subsidy scales is a losing strategy for Canada. Our competitive edge comes from *rules that grow ecosystems*, not from trying to outspend Washington.

**"We need to modernize first."** **AI must work *during* modernization.** With two-thirds of applications in poor health, we cannot wait for a perfect greenfield. The platform approach funds adapters and APIfication first, reducing migration risk.

## 11) A 24-month action plan

### First 100 days

1. **Issue an orchestration mandate.** The CIO of Canada and PSPC jointly announce that AI will be procured against a **GC AI Orchestration Reference Architecture**, with mandated interface and portability clauses for all AI-related buys over a set threshold. (Anchor in the Policy on Service and Digital.)

2. **Publish the baseline specs and tests.** Release v1.0 of: API profiles (OpenAPI+security profiles), data contract templates, evaluation protocols, logging/schema requirements, and Zero Trust alignment checklist. (Map to GC API Standards, AIA requirements, Cloud Guardrails.)

3. **Set spend controls for duplication.** Introduce central spend assurance for any AI build that replicates platform services without justification, adapted from the UK model.

### Months 4–12

4. **Stand up the platform spine.** Launch the **Model Gateway**, **Evaluation Service**, and **Observability/Logging Bus** on GC cloud landing zones, with two model providers and at least three department use-cases integrated.

5. **Create capability pools and run bake-offs.** Pre-qualify suppliers for key building blocks (retrieval, eval, red-team, governance tools). Run quarterly competitive bake-offs with objective metrics; publish results for transparency.

6. **Reshape challenge procurement.** Align Innovative Solutions Canada challenges with platform interfaces and require a portability demonstration for graduation to production.

7. **Legacy integration fund.** Allocate a dedicated "Adapter Fund" to build and open-source connectors for the top 100 legacy systems; require departments to contribute back adapters built under their projects.

### Months 13–24

8. **Scale across 20 priority services.** Target the top high-volume, high-value transactions (benefits, permits, compliance) for AI augmentation via the platform.

9. **Institutionalize assurance.** Make AIA outputs and model evaluation metrics automatically published to an open catalogue, with red-team reports summarized for public trust.

10. **Codify the procurement playbook.** Update the Directive on the Management of Procurement to include AI-specific clauses on portability, interface conformance, evaluation transparency, and modular competitions; align departmental procurement templates accordingly.

## 12) Funding and incentives aligned to Canada's context

**We won't win on subsidy magnitude.** We will win by **market-shaping**: set rules that make integration and reuse profitable for vendors. Use targeted instruments (e.g., the Canada Growth Fund and program-level envelopes) to **reward conformance to platform interfaces and cross-department reuse**, not just first deployments. This complements industrial policy without trying to replicate U.S. scale.

## 13) Governance: simple, transparent, and enforceable

- **Stewardship board.** A small, empowered board chaired by the CIO of Canada, with PSPC, Shared Services, two provincial CIOs, and three independent experts (security, AI ethics, procurement).
- **Public scorecards.** Quarterly publication of: platform uptime; conformity assessments; reuse counts; vendor concentration ratios; and the percentage of spend via modular competitions.
- **Exit reviews.** Any sole-source or large single-vendor award must include a published exit/portability plan, with testable criteria.

## 14) Risk management and assurance by design

**Policy risk.** TBS's ADM Directive and AIA already provide a risk-tiered instrument — embed it in solicitations and acceptance criteria. **Security risk.** Anchor deployments in the GC Guardrails and Zero Trust roadmap. **Operational risk.** Modular contracts with strict acceptance tests limit blast radius. **Ethical risk.** Align with NIST AI RMF and ISO/IEC 42001 (AIMS) to embed governance practices; require suppliers to map their controls to these frameworks.

## 15) Metrics that matter

- **Reuse**: number of departments using each platform service or adapter.
- **Portability**: time and cost to swap a component (e.g., RAG provider) with no service regression.
- **Integration velocity**: days from award to first "hello world" call against platform APIs; days to production.
- **Service impact**: cycle-time reduction, backlog burn-down, fraud detection uplift, and error/correction rates by service.
- **Risk posture**: % of AI solutions with published AIA and evaluation metrics; % meeting Guardrails within 30 days; incident MTTR.

## 16) The counterfactual cost of inaction

If we continue with RFP-as-usual:

- **Lock-in deepens.** Cloud and software licensing terms create technical and economic exit barriers; negotiating leverage falls.
- **Technical debt compounds.** With thousands of aging applications, every bespoke integration adds brittleness and drags on future modernization.
- **Public trust erodes.** Without transparent evaluation and explainability, AI deployments risk headlines rather than benefits — despite our having policy tools to mitigate these risks.

## 17) A Canadian strategy that plays to our strengths

We cannot — and should not — try to mirror U.S. spending. Instead, **we can lead on how a democratic government orchestrates an AI ecosystem**:

- Open, modular, and contestable by design.
- Security-first but not vendor-exclusive.
- Practical about legacy reality: fund adapters and contracts that reward integration.
- Transparent assurance, using instruments we already have.
- **Procurement as the principal lever**, used strategically in line with OECD principles for public value.

**The action is in the rules.** Change the rules, and suppliers will bring their best modules, not their biggest lock-in.

## Closing: a deliberate bet on rules, not vendors

Canada's advantage won't be measured in the size of a single grant or the brand of a single platform. It will be measured in the **contestability** of our ecosystem, the **portability** of our components, and the **repeatability** of our integrations across thousands of systems. That is a procurement choice.

Shift procurement from specifying *things* to specifying *properties* — interoperable, portable, observable — and then **orchestrate** the market to deliver them. If we do, AI's compounding benefits will accrue to Canada: faster, fairer services; a more secure and modern state; and an economy that grows because its digital infrastructure is open by design.

> *Sources: Government of Canada policy and guidance (Policy on Service and Digital; Directive on Automated Decision-Making and the AIA tool; Digital Standards; Standards on APIs; GC Cloud Guardrails and Zero Trust guidance; Directive on the Management of Procurement; Agile procurement and Innovative Solutions Canada). Audit and legacy systems: OAG Report 7 (2023) on modernizing IT systems (~7,500 applications, two-thirds in poor health); TBS Report on the State of Aging IT. Lock-in, interoperability and procurement principles: GAO on restrictive licensing; European Commission interoperability guidance; OECD Recommendation on Public Procurement. Modular contracting: FAR 39.103, TechFAR Handbook, U.S. Digital Services Playbook; UK spend controls and G-Cloud model. AI governance: NIST AI RMF 1.0; ISO/IEC 42001:2023. Digital public infrastructure: GovStack; G20 Leaders' Declaration. Canadian AI ecosystem context: CIFAR Pan-Canadian AI Strategy; SCALE AI; CVCA. U.S. scale comparison (for context, not imitation): CHIPS & Science Act (US$52.7B for semiconductors); Inflation Reduction Act.*
