Buying AI after the demo: a 2023–2026 retrospective
A convincing demonstration leaves several buying questions unanswered: which information the system can use, what it is allowed to do, how its output will be accepted and who takes responsibility when it fails. Looking back at public guidance from 2023 to 2 October 2026 helps explain why those questions belong in the project brief.
What to take away
- External milestone dates are separate from this article’s preparation and publication.
- Risk frameworks, Australian guidance and engineering recommendations have different scopes.
- Use the history to ask for concrete evidence, permission boundaries and operating ownership.
Purpose and scope
This retrospective was prepared on 3 October 2026. It covers selected external milestones, not DataXLR8's publication or delivery history. The dates below describe source events. They do not imply that this article, its recommendations or company experience existed at those dates.
Our reading of the sequence is practical: buyers have increasingly explicit material to draw on when specifying evidence, authority and operational responsibilities. These publications do not establish how quickly businesses adopted those practices, or prove that every AI product follows them.
2023 supplied a general risk-management reference
On 26 January 2023, the US National Institute of Standards and Technology published version 1.0 of its AI Risk Management Framework. It is voluntary guidance intended to work across use cases. Its publication supplies a dated reference point for discussing AI risks; it is not Australian law or a certification of any product.
For a buyer reviewing a proposal now, the useful question is how the supplier has translated general risk considerations into the proposed job. What outcome matters? Who can be affected by an error? What evidence will support the release decision? A framework citation in a slide deck does not answer those questions on its own.
That distinction also helps keep a historical article honest. The existence of a framework establishes that the guidance was published. It does not demonstrate that a particular business used it, that a supplier was compliant with it, or that a system's risks were resolved.
- 26 January 2023
NIST publishes AI RMF 1.0, a voluntary US framework.
- 21 October 2024
OAIC publishes commercial-AI privacy guidance.
- 25 November 2024
Anthropic announces the Model Context Protocol.
- 11 September 2025
Anthropic publishes tool-evaluation guidance.
- 21 October 2025
Australia’s Guidance for AI Adoption introduces six essential practices.
2024 added more specific privacy and architecture questions
NIST dates the release of its generative-AI profile to 26 July 2024. This is a more specific milestone within its risk-management work. Here it serves as historical context; this article does not claim to assess a system against every item in that profile.
In Australia, OAIC published guidance on commercially available AI products on 21 October 2024, with the current page recording an update on 17 January 2025. It explains privacy considerations around AI inputs and outputs, including the possibility that incorrect generated information about an identifiable person is still personal information. The publication did not create all underlying privacy duties on that date.
The buying implication is to examine the whole information flow. A description of where the main database is hosted is only part of that discussion. Ask about prompts, outputs, logs, support access and retained copies. Determine the applicable obligations for the actual organisation and use, rather than treating a general checklist as a legal conclusion.
On 25 November 2024, Anthropic announced the Model Context Protocol as an open standard for connecting AI assistants to data and business systems. The announcement supplied a common protocol vocabulary. Our practical inference is that connection and permission still need separate decisions: a connector's existence does not authorise an assistant to read every record or perform every available action.
Anthropic's 19 December 2024 article on effective agents distinguished predefined workflows from agents that dynamically direct their process and tool use. The live article now acknowledges later tooling changes. Its displayed publication date supports this milestone, while its present SDK and product references should not be treated as a frozen record of the 2024 ecosystem.
For today's proposal comparison, ask the supplier to explain why the job needs dynamic decisions. A fixed workflow can be a sensible choice when the route is known. The word “agent” does not settle that design question.
By 2 October 2026, the useful output is a better brief
This review's 2026 endpoint is the source-check date, not a claim that a new law or product suddenly resolved AI purchasing. The milestones provide different kinds of evidence: a US voluntary framework, Australian regulator and adoption guidance, vendor engineering recommendations and security guidance. Treating them as interchangeable would obscure their purpose.
| Evidence strand | Question to put in the brief | Deliverable to request |
|---|---|---|
| General risk management | Which outcomes and errors matter in this job? | Defined scope, affected parties and release criteria |
| Information handling | What information is used and where does each copy go? | Reviewed data-flow and access record |
| Architecture | Why does this task need an agent or custom build? | Comparison with existing tools and a fixed workflow |
| Permissions | Which actions are permitted, and who approves them? | Explicit read/write boundaries and enforced approval checks |
| Evaluation | What happens in ordinary and difficult cases? | Versioned cases, observed outcomes and unresolved failures |
| Operation | Who monitors, corrects and stops the system? | Named owner, support scope and recovery procedure |
Use the distinctions to complete this commissioning worksheet. The proposed questions below are our synthesis, rather than a copied regulator checklist.
These questions connect a historical reading exercise to a decision you can make now. If the next project concerns internal documents, use the source and answerability worksheet in Can your company knowledge answer the question? If it concerns taking action, start with Before an AI workflow acts, decide how it can fail.
Bring the resulting brief to a consultancy discussion with the unanswered questions still visible. They are useful inputs to scope, price and acceptance. A supplier's response to those gaps will tell you more about the proposed engagement than a retrospective timeline alone.
Before you proceed
- Identify the job, affected parties and consequences of error.
- Ask how each cited framework applies to the actual use.
- Map information access and retained copies.
- Compare a fixed workflow with a proposed agent.
- Specify allowed actions and approval checks.
- Request expected and observed evaluation outcomes.
- Name the operating owner and recovery procedure.
Sources and further reading
Official sources support the requirements described here. Our suggested workflows and illustrative examples are practical guidance, not an assurance of compliance or a claim about client results.
- Artificial Intelligence Risk Management Framework 1.0NIST
Opened and checked 2 October 2026. Source scope and limitations are recorded in the editorial source inventory.
- AI Risk Management Framework and generative-AI profileNIST
Opened and checked 2 October 2026. Source scope and limitations are recorded in the editorial source inventory.
- Guidance on privacy and the use of commercially available AI productsOAIC
Opened and checked 2 October 2026. Source scope and limitations are recorded in the editorial source inventory.
- Introducing the Model Context ProtocolAnthropic
Opened and checked 2 October 2026. Source scope and limitations are recorded in the editorial source inventory.
- Building effective agentsAnthropic
Opened and checked 2 October 2026. Source scope and limitations are recorded in the editorial source inventory.
- Writing effective tools for agentsAnthropic
Opened and checked 2 October 2026. Source scope and limitations are recorded in the editorial source inventory.
- LLM06:2025 Excessive AgencyOWASP
Opened and checked 2 October 2026. Source scope and limitations are recorded in the editorial source inventory.
- Australia’s AI Ethics Principles and adoption-guidance historyDepartment of Industry, Science and Resources
Opened and checked 2 October 2026. Source scope and limitations are recorded in the editorial source inventory.
- Guidance for AI Adoption: implementation guidanceNational AI Centre
Opened and checked 2 October 2026. Source scope and limitations are recorded in the editorial source inventory.