The short answer
If the pressure is a security questionnaire, do 27001. If the pressure is an AI questionnaire, do the AI governance work first and add 27001 later only if the client base demands it.
What this means for you
The two share control areas — access, supplier management, incident handling, competence — so the second one is materially cheaper than the first.
If you do both
Run one integrated management system with one document set and one internal audit cycle, rather than two parallel programmes.
Delaying the decision does not remove the question — it only leaves you answering the next questionnaire with a promise instead of a certificate. Decide by what the next tender or questionnaire will actually ask for.
Start with the standard the market is already asking for.