Skip to main content

    Diversity is downstream of vendor selection

    A field note from three closed-door Labs in Oslo, Stockholm, and Cambridge. The diversity report is the document of record. Procurement was the policy.

    Javad Mushtaq · Founder and Executive Director · 5 February 2026

    Reading time 5 min · Published by ImpactLab

    Editor's note

    • Clarification · 13 August 2026The five contract conditions set out here and the five clauses in Issue 07 are the same instrument, developed across both essays. They are maintained as one document. The five clauses

    There is a recurring pattern in Nordic boardrooms in 2026. A senior leadership team commissions a diversity audit of the AI systems it is about to deploy. The audit comes back with thoughtful recommendations on bias testing, representation in training data, and stakeholder consultation. The team adopts the recommendations. The vendor is already chosen, the contract is already signed, and the system is already configured to a workflow that — six months earlier, in a procurement decision treated as routine — quietly determined every one of the questions the audit was sent to answer.

    The diversity report is the document of record. The procurement decision was the policy.

    This essay is a field note from three closed-door Labs in Oslo, Stockholm, and Cambridge over the past quarter, where this pattern came up so consistently that it is no longer reasonable to call it a coincidence. Inclusion is not an outcome of AI deployment. As of mid-2026, it is — almost entirely — a property of vendor selection.

    The point at which the choices are real

    Three structural features make procurement the operative layer for inclusion under the EU AI Act regime.

    First, AI Act compliance is enforced on deployers as well as providers. Article 4 has applied since 2 February 2025 and applies to deployers and to the persons acting on their behalf, calibrated to the persons on whom the AI is used [1]. The deployer therefore needs to know, in detail, what it is buying — including the inclusion characteristics of the system — before it buys.

    Second, Norway's draft AI Act, expected to take effect in summer 2026 with Nkom as the proposed coordinating supervisory authority, will require organisations to map AI usage including indirect use via third-party systems, to determine their role for each AI system (provider or deployer), and to assess risks based on use and purpose [2]. None of those determinations are possible without contractual artefacts created during procurement.

    Third, the cost of getting inclusion wrong is asymmetrically high for public bodies and for any private institution operating under public scrutiny. Reputational risk, audit risk, parliamentary risk, and citizen-trust risk all converge on the moment an institution has to explain why it bought a system that produced a discriminatory or opaque outcome. By the time the diversity report is being written, the procurement officer is no longer in the room.

    What the three Labs surfaced

    Across the three Labs — a municipal pilot in Oslo, a financial-services group in Stockholm, and a research-clinical partnership in Cambridge — the same five conditions kept reappearing on the procurement side of the wall.

    The model card was not part of the tender. The vendor offered a marketing deck and a security questionnaire. There was no model card, no training-data summary, no evaluation summary, no known-limitations statement attached to the contract. The diversity work that started afterwards had no documentary foundation to build on.

    The human-oversight specification was generic. "A human in the loop" appeared as a single line in the contract. The actual specification — who exactly performs oversight, what they are trained on, what they can override, what they cannot override, how the oversight log is preserved — was left to be defined later, by whoever happened to be in the operating role.

    Article 4 literacy was assumed, not specified. The vendor was not asked to identify which staff and persons acting on its behalf would interact with the system, or to certify that their literacy had been calibrated to context. The deployer was therefore unable to demonstrate calibration on its own side either [1].

    The exit and portability clause was missing. At termination, the deployer would have received its own data back, but not the decisions made on its behalf, not the evaluation history, and not the documentation needed to defend prior decisions in a regulator-led review. The diversity audit, in other words, would have evaporated with the contract.

    The allied-assurance overlay was invisible. The hyperscale layer behind the vendor carried commitments — on cybersecurity, export controls, technology transfer, data protection, responsible AI, and KYC — to a third government under instruments such as the Microsoft–G42 Intergovernmental Assurance Agreement [3]. None of those commitments were referenced in the procurement file. They are mostly in the deployer's interest. They should still be on the file.

    In all three Labs, the diversity audit subsequently flagged exactly the issues that were locked in by these omissions, and could no longer be unlocked without renegotiating the contract.

    Five clauses that move inclusion upstream

    A defensible Nordic public-interest AI procurement in 2026 carries five clauses. None is exotic. None requires special drafting authority beyond what every Nordic municipality, hospital trust, and public agency already has.

    One. A vendor representation that the system is or is not a high-risk AI system under Annex III of the EU AI Act, with the reasoning, and an obligation to update the classification if it changes.

    Two. A model and data documentation appendix — at minimum a model card, training-data summary, evaluation summary, and known-limitations statement — refreshed at agreed intervals, in a form that survives staff turnover on both sides.

    Three. A human-oversight specification consistent with Article 14 of the AI Act: who exactly performs oversight, what they are trained on, what they can override, what they cannot override, and how the oversight log is preserved.

    Four. An AI literacy obligation flowed down from Article 4: the vendor identifies the staff and persons acting on its behalf who interact with the system, and certifies, with documentation, that their literacy has been calibrated to context [1].

    Five. An exit and portability clause: at termination, the deployer receives the inputs it provided, a portable record of decisions made on its behalf, and the documentation needed to defend prior decisions in a regulator-led review.

    Inclusion lives or dies in those five clauses. The diversity report can either describe what they delivered or apologise for what they failed to require.

    The implication for Nordic institutions

    The implication is straightforward and uncomfortable. If a Nordic institution wants its inclusion commitments to be more than ornamental, the work has to move upstream from the audit function to the procurement function. The board does not need a new diversity policy. It needs to read the next AI tender before it goes out.

    That is less marketable than a values statement. It is, as of mid-2026, the only version that holds.

    Bear case · Open · Resolves Q2 2028

    If a European public buyer adopts inclusion conditions in an AI tender and the resulting deployment shows no measurable difference in who the system works for, then procurement is not the lever this argues it is.

    All tracked bear cases

    Footnotes

    1. [1] European Commission, Directorate-General for Communications Networks, Content and Technology, "AI literacy — questions & answers", 2025. https://digital-strategy.ec.europa.eu/en/faqs/ai-literacy-questions-answers
    2. [2] Schjødt, Line Krydsby, "Norway's new AI Act — what it will mean for your business", 15 January 2026. https://svw.no/en/norways-new-ai-act-what-it-will-mean-for-your-business/ Primary source: Digitaliserings- og forvaltningsdepartementet, "Høring — utkast til ny lov om kunstig intelligens", consultation closed 30 September 2025. https://www.regjeringen.no/no/dokumenter/3112327/id3112327/
    3. [3] Microsoft, Brad Smith, "Microsoft's $15.2 billion USD investment in the UAE", 3 November 2025. https://blogs.microsoft.com/on-the-issues/2025/11/03/microsofts-15-2-billion-usd-investment-in-the-uae/

    Cite this issue as: ImpactLab, The Dispatch, Issue 03, 5 February 2026.

    Author

    Javad Mushtaq

    Founder and Executive Director, ImpactLab. The byline is set inside the publication; ImpactLab is the publisher of record.