After AI Enters the Workflow · Season Three: “When AI Starts Acting for the Organisation” · Article Six
Negotiation is not the repeated averaging of two numbers. A supplier lowers price by five per cent in exchange for a longer commitment. The customer accepts the term but asks for a stronger service level. The parties then trade payment timing, liability, exit rights and operational obligations. Every concession exchanges one form of value for another form of risk.
AI is well suited to handling complexity. It can compare clauses, calculate total cost, retrieve precedent, prepare counter-proposals and sustain multiple rounds of exchange in seconds. Once it sends “we can accept” directly to the other party, however, it has moved from analysis into authority.
The most important design object for a negotiating AI is not its prompt. It is an authority envelope: the dimensions in which it may move, the distance it may move, the combinations that force a stop and the person who may expand the boundary.
Separate negotiation into four acts
A negotiation appears to be one continuous conversation but contains different powers:
- Understand: extract price, term, obligation and condition from the other party.
- Recommend: compare options internally and prepare a counter-proposal.
- Communicate: transmit an already approved position accurately.
- Commit: accept, refuse or change conditions within delegated authority.
An organisation can permit the first three while retaining the fourth, or delegate only a small part of commitment. A system might respond automatically within a published discount range while escalating any liability term, intellectual-property variation or duration beyond one year.
Risk begins when an interface collapses the four acts into one command: “Let AI handle the negotiation.” If the business user cannot see whether the system is organising, recommending or committing, accountability is already unclear.
An authority envelope is not one monetary limit
“Do not concede more than ten per cent” is insufficient. AI may stay inside the price limit while accepting a longer lock-in, poorer payment terms or greater liability that makes the transaction worse overall.
A complete envelope covers several dimensions:
| Dimension | Example boundary | Mandatory escalation |
|---|---|---|
| Price | Discount within approved percentage | Total value beyond delegated amount |
| Time | Contract no longer than twelve months | Auto-renewal or long price lock |
| Payment | Standard timing range | Prepayment, refund or credit arrangement |
| Liability | No change to standard allocation | Indemnity, cap or exclusion changes |
| Data | Approved purposes and locations only | New sharing, training or cross-border arrangement |
| Intellectual property | Standard licence | Ownership transfer, exclusivity or sublicensing |
| Service | Variation within approved level | Security, availability or remedy commitments |
The envelope must also recognise combinations. Each condition can remain within its individual limit while the combined outcome is unacceptable. A low price, long term and high service obligation together may create a risk hidden by single-variable controls.
The organisation needs prohibited combinations, an aggregate risk measure and stopping rules, not only a minimum and maximum for every field.
The other party’s language can alter AI behaviour, making negotiation a security problem
Contract text is ordinary negotiation content. For an AI that interprets instructions, it may also become an input attack. An attachment, webpage or message can contain text telling the system to ignore constraints or reveal an internal budget. If external material is not isolated from internal instructions, negotiation content can attempt to rewrite agent behaviour.
The OWASP Top 10 for Large Language Model Applications includes prompt injection, sensitive information disclosure, excessive agency and insecure output handling among major risk areas. OWASP, “Top 10 for Large Language Model Applications” In negotiation these are not abstract vulnerabilities. They can cause disclosure of a reserve price, acceptance of an unapproved term or execution through an external tool.
Every counterparty input should be treated as untrusted content. System rules, internal strategy and external text need separation. Sensitive limits should not enter model context without necessity. Sending, signing and payment tools require independent permission checks. The transaction layer must validate even when the model says a proposal complies.
AI should not receive every card the business holds
Human negotiators distinguish what may be spoken from what is only for internal judgement. Placing full budgets, competing bids, legal advice and strategic priorities into an AI context makes prompt injection, logging exposure or mistaken quotation more consequential.
Data minimisation applies to negotiation. A system may need an authorised range rather than the complete reserve price; an approved clause library rather than every historical contract; a signal that risk is acceptable rather than privileged legal advice in full.
This is not a decision to keep AI uninformed. It pairs knowledge with action. A system preparing internal comparison may receive broader analytical information. A system communicating directly with an outsider should operate on a narrower, processed context.
The UK National Cyber Security Centre’s secure AI deployment guidance emphasises access control, infrastructure protection, logging, monitoring and incident management. NCSC, “Secure deployment” A negotiation agent needs these controls at each tool and data boundary rather than inheriting every permission of the employee account it uses.
The counterparty must know when a real commitment has formed
If AI moves among “that sounds possible”, “we are willing to consider” and “agreed”, the parties may form different views of transaction status. Machine-speed exchange worsens the ambiguity because dozens of rounds can occur before a person looks.
A negotiation protocol should distinguish inquiry, non-binding proposal, condition pending internal approval, formal offer, acceptance and withdrawal. Important status should not exist only in natural language. It also needs a structured marker, version and time.
Australia’s Electronic Transactions Act 1999 provides a framework for attribution, dispatch and receipt of electronic communications. Federal Register of Legislation, Electronic Transactions Act 1999 UNCITRAL’s Model Law on Automated Contracting directly addresses automated systems in contract formation. UNCITRAL, Model Law on Automated Contracting Legal effect still turns on applicable law and facts, but the system-design lesson is clear: faster automation requires clearer transaction state.
Escalation cannot wait until AI “feels uncertain”
Model uncertainty is not the only trigger. AI can be confident and wrong, or perfectly clear about a term that remains outside authority. Rules, consequence and novelty should trigger escalation:
- a value or combination outside the envelope;
- a new clause, non-standard definition or conflicting information;
- regulatory, privacy, security, intellectual-property or liability change;
- a request to reveal internal information or alter the interaction protocol;
- negotiation beyond a round, time or cumulative-concession limit; and
- a counterparty stating reliance on an unconfirmed expression.
On escalation, the person needs a difference summary: what changed from the standard position, what AI has already said, which conditions remain unconfirmed and the total economic and risk effect. Giving a manager a long transcript does not create meaningful review.
The manager’s response should become an explicit new boundary rather than a casual “fine this time” inside chat. Otherwise the system cannot distinguish an exceptional approval from permanent policy.
Every concession needs a source and a cost
A negotiation record should preserve more than the final contract. The organisation needs to reconstruct why AI proposed each material concession: which authority supported it, what it received in exchange, what alternatives existed and who approved a boundary change.
A round can be recorded as:
Counterparty request: move payment from 30 to 60 days
AI assessment: outside standard, within finance approval range
Exchange: reduce price discount by 2%
Status: awaiting finance owner
Authority source: procurement matrix v3.2
This structure is more useful than preserving purported model “thought”. The institution does not need unverifiable internal reasoning. It needs inspectable input, rule, change, approval and result.
Records also allow later comparison: whether AI repeatedly concedes on one dimension, discloses more to a category of counterparty, gains speed at the cost of worse terms, or is frequently overturned by people.
Pause, withdrawal and takeover must be designed in advance
A negotiation agent needs more than a start button. A supplier failure, anomalous concession, information disclosure or legal issue should allow the business to stop all outward messages, preserve state and withdraw proposals not yet finally confirmed.
The takeover owner needs the latest valid conditions rather than hundreds of messages. The system should provide the last version confirmed by both parties, open items and the agent’s current authority, clearly distinguishing drafts.
If an incorrect commitment has already been sent, correction must be handled by an authorised role. The same agent should not freely generate a “withdrawal”, because withdrawal can itself be a legal and commercial representation.
Conclusion: AI may exchange conditions inside the boundary, not change the boundary itself
Negotiation creates value through understanding what can be exchanged, who may exchange it and what must remain. AI can expand the organisation’s capacity to compare options and process complex terms, but historical patterns and counterparty pressure do not create authority.
The final principle is:
A negotiating AI may propose, communicate and accept conditions within an explicit multidimensional authority envelope. It may not expand that envelope, reveal reserve information or turn one exception into policy. Any change to liability, long-term obligation, data rights or material value requires confirmation by a person with corresponding authority.
With a sound boundary, AI need not stop after every sentence. It can act quickly in a low-risk space and stop accurately where institutional judgement begins. Maturity is not measured by how many rounds an agent can negotiate. It is measured by whether it recognises the step that no longer belongs to it.
Primary sources and further reading
- OWASP: Top 10 for Large Language Model Applications
- UK National Cyber Security Centre: Secure deployment
- Federal Register of Legislation: Electronic Transactions Act 1999
- UNCITRAL: Model Law on Automated Contracting
Continue reading: Explore the After AI Enters the Workflow series.
Discover more from Geoffrey Chen
Subscribe to get the latest posts sent to your email.