The Build-vs-Buy Decision Framework
Route any AI request through five honest options, why the line now leans toward build, the five-year promise that comes with it, and how the smallest builds win the adoption that unlocks the big ones.
The one rule, and how it moved
Buy the system of record. Build the system of intelligence. The system of record is the infrastructure everyone in your industry shares and no one wins on, so buy it. The system of intelligence is the layer that turns your data and your particular way of working into advantage, so build that.
But know that the line has moved, hard, toward build. AI has made building faster and cheaper than it has ever been, so the honest default now leans toward build more than the old procurement wisdom allowed. When you catch yourself reaching for a vendor out of habit, stop and ask whether a small, sharp build would be faster than the buying cycle.
The five routes
Every AI request comes down to one of five moves. Most of the discipline is routing each request to the right one, on purpose.
- Self-serve. Give people secure access to general-purpose tools, with education and accountability. This is where the AI Product Partner earns their keep: train for self-service, because most of the work lives here Operator heuristic (call it roughly 70%; the point is the majority, not the decimal), and a surprising amount of value arrives with no project at all.
- Buy. License a mature capability the market already builds well, the commodity infrastructure everyone shares. This is a system of record.
- Build. Create the capability only you can, on your data and your workflows. This is a system of intelligence, and in this era you will build more of it than you used to.
- Redesign. Change the workflow or decision structure itself. Automate a broken process and all you get is the same breakage, faster.
- Do nothing. Decline the weak requests. Not every problem needs AI, and saying no protects your attention and your credibility.
Route the request
Ask these in order, and stop at the first yes.
- Can people already do this with tools you have? Self-serve. Train them and set guardrails, not a project. Most requests end here.
- Is the honest fix a different workflow, not a tool? Redesign first. Do not automate the old shape.
- Is there a strong, ready vendor for a capability everyone shares? Buy it. It is a system of record.
- Is it yours to build, and can you own it for five years? Build only if both are yes. See the five-year test below.
- Is the value thin or the problem not real? Do nothing, for now.
Build what you can’t or won’t buy
You build for two reasons, and the bar for both has dropped.
- You can’t buy it. The capability is genuinely unavailable, or your proprietary data and your particular workflow are the whole point and no vendor has them. This is the system of intelligence.
- You won’t buy it. It is bespoke and tailored enough that a vendor implementation would take more work, cost, and compromise than building it yourself. With AI in hand, a focused build is often faster than the procurement it replaces.
The old caution was drift toward build, rebuilding commodity you should have licensed. That is still true for the system of record, so do not write your own cloud or your own lab notebook. Past that line, build more freely than you used to.
Build is a five-year promise
Here is the caveat the build-more era needs, because it is where the enthusiasm gets people hurt. Building a demo and owning a production system are not the same act, and AI has collapsed the first while barely touching the second. A weekend prototype that dazzles the room still has to become something your company can run for years. Time to demo is now trivial. Time to validated production is not, and the total cost of ownership lives almost entirely on the far side of the demo.
So before you build anything, answer one question honestly, and treat a no as disqualifying:
Are we willing and able to own, operate, secure, validate, support, and eventually retire this capability for the next five years?
That is not one question but a checklist wearing a single sentence. Each verb is a standing cost:
- Own and operate. Someone is accountable for it running, not just for shipping it.
- Secure. Access control, data handling, and a real security review, revisited as the threats change.
- Validate. In regulated work, computerized-system validation and change control on every meaningful update, on the risk-based terms your quality function sets (see the FDA’s Computer Software Assurance guidance, and check with your own quality and regulatory function).
- Support. Monitoring for model and data drift, a path for when it breaks, and documentation that lets someone other than the author keep it alive.
- Retire. A plan for the day it is replaced, including the data and the dependencies it leaves behind.
If no one will own that list, you have not decided to build. You have decided to accumulate a liability that looks like an asset. A fast prototype is evidence that building is now cheap. It is not evidence that your company should own the production system. When you cannot own the operation, buy the capability and spend your scarce engineering on the part you can.
Solve small, and they will bring you big
Here is the part most frameworks miss. The temptation is to reserve “build” for the big strategic bets, to only swing for the fences. In an AI-native company that is exactly backwards, because adoption and change are the whole game.
Solve one person’s real problem, however small, and they come back with bigger ideas than they had before. A small build that makes a scientist’s Tuesday better is not a distraction from the strategic work. It is how you earn the trust and the momentum to do the strategic work at all. Solve for the individual, and you unlock the institutional.
Revisit the line
The line is not fixed. What is a differentiating build this year can become a commodity you should buy in two, once the vendors catch up, and what was too expensive to build last year is a weekend now. Put a date on the calendar to re-route your biggest builds and your oldest buys alike.
Run your three loudest AI requests through this once, out loud, with the people who own them. Then run your three smallest, the ones you have been ignoring. The small ones are where adoption is won.