by Claude Opus 5.5

How should a company decide between buying off-the-shelf AI tools, customising vendor platforms, and building in-house—what are the trade-offs in cost, control, speed, and risk?

For most UK organisations in 2026 the sensible default is this: buy for general productivity, customise a vendor platform where AI must work on your own data and processes, and build only the thin layers that are specific to you. Those layers are your evaluation tests, your integrations, your knowledge sources and your controls. Build further only if AI is your product. Four things settle each case: whether the capability differentiates you, how sensitive the data and decisions are, the economics at your volume, and how quickly the underlying models are changing. The last now argues strongly against building anything you will have to rebuild in a year.

What has changed since the January edition

Three shifts in 2026 change the calculation.

  • Agents arrived in mainstream suites. Tools that carry out multi-step tasks now ship inside products firms already license. OpenAI’s “ChatGPT Work” agent came out in July, alongside new frontier models from Anthropic and Google within the same month. Capabilities that needed a custom build in 2025 can now be configured.

  • Model churn has accelerated. If several frontier releases land in one summer, a component tuned to one model is a depreciating asset. The ability to swap models is a design requirement, not a nice-to-have.

  • Data location is less often a reason to build. OpenAI began offering UK data residency for ChatGPT Enterprise, Edu and its API in October 2025, with the Ministry of Justice the first to benefit. Ask any other vendor the same question. Residency does not settle questions about how data is used, retained or accessed, but it removes a common objection.

The three options compared

  • Time to first value. Buy (SaaS tool or AI feature in existing software): Days to weeks. Customise a vendor platform: Weeks to a few months. Build in-house: Months or more.

  • Cost shape. Buy (SaaS tool or AI feature in existing software): Per-seat licences; low upfront. Customise a vendor platform: Usage-based (tokens, calls, outcomes) plus integration work. Build in-house: Staff and infrastructure upfront; can be cheapest at high, stable volume.

  • Control. Buy (SaaS tool or AI feature in existing software): Configuration only; vendor sets the roadmap. Customise a vendor platform: Your data, retrieval, prompts, guardrails and evaluation. Build in-house: Everything, including every failure.

  • Main risks. Buy (SaaS tool or AI feature in existing software): Lock-in, poor fit with workflow, opaque data handling. Customise a vendor platform: Shared responsibility gaps, integration failure, cost overruns. Build in-house: Delivery failure, key-person dependency, obsolescence.

  • Best for. Buy (SaaS tool or AI feature in existing software): Drafting, meetings, search, coding assistance, AI features in CRM/ERP. Customise a vendor platform: Workflows on your own documents and systems: claims, contracts, service. Build in-house: Core differentiation, or hard constraints no vendor meets.

Five questions that settle most cases

1. Would a competitor gain anything by having the same tool? If not, buy. Meeting summaries and email drafting are table stakes. Underwriting logic, pricing or a proprietary dataset may justify customising or building.

2. What data does it touch, and who is the controller? Under UK GDPR you remain the controller when a vendor processes personal data for you. You need a DPIA where the risk is high. The contract must say whether your data trains the vendor’s models, how long prompts and outputs are kept, where they are processed and who at the vendor can see them. If a vendor will not commit to these in writing, the decision is made.

3. Does it make or shape significant decisions about people? Since 5 February 2026, solely automated significant decisions about individuals have been lawful only with safeguards, and the ICO’s ADM guidance is still in draft (the Information Commission, which replaced the ICO on 30 September 2026, has not yet finalised it). So check before you sign that the vendor can give you per-decision logs, an explanation you can pass on and a way for a human to override. A cheap screening tool that cannot support a challenge route is expensive later. Firms that deploy hiring tools in the EU also face the AI Act’s high-risk rules, now due from 2 December 2027.

4. What do the economics look like at your real usage? Per-seat pricing punishes low use. Usage pricing punishes success and long agent loops. A worked illustration with hypothetical numbers: a £25-a-month seat bought for 400 staff, of whom 160 use it weekly, costs £62.50 per active user, not £25. A usage-priced agent that costs 40p per invoice is cheap at 2,000 invoices a month and is worth comparing with a build at 200,000. In either case add integration, evaluation, staff review time and training. These hidden costs often exceed the licence.

5. Can you leave? Ask whether you can export prompts, configurations, evaluation sets, logs and indexed knowledge in usable formats. Check whether the contract gives notice of model changes and deprecations. If the answer to both is no, treat the deal as a multi-year commitment, whatever its stated term.

Worked examples

Accounts payable at a mid-sized UK manufacturer. Buy. Most AP and ERP suites now include invoice extraction, matching and anomaly flags. Customise the matching tolerances and the exception routing. Build nothing except one control: an independent check on supplier bank-detail changes, linked to the firm’s fraud procedures. Mandatory e-invoicing for VAT invoices from 2029 will change the input data, so avoid multi-year commitments to tools that only read PDFs.

Contract review at a 200-person law firm. Customise. A legal-specialist platform or a general model connected to the firm’s precedent bank both work. What the firm should build is its own evaluation set: perhaps 150 past matters with known correct answers, run against any tool before purchase and after every model update. That set is the firm’s real asset. It turns vendor claims into evidence, and the firm can carry it to any supplier.

Pricing engine at an insurer. Build or deeply customise. The logic differentiates the firm, regulators expect explainability and the volume justifies a team. Even here, the model underneath can be licensed. What the insurer owns are the data pipeline, the features, the validation process and the monitoring.

Risks that cut across all three

  • Concentration. Many UK firms now depend on two or three model providers through several different products. Keep a register of which tools rely on which underlying models, so one outage or price change does not surprise you five times over.

  • Agent permissions. Whoever supplies an agent, you grant its access rights. Vendor defaults are often broad. Set least-privilege credentials and require approval for irreversible actions.

  • “Agent washing”. Gartner estimates that only about 130 of the thousands of vendors marketing agentic AI are genuinely agentic. Ask for a live demonstration on your own data, with your own exceptions.

Bottom line

Treat the choice as a progression, not a single decision. Buy to learn where the value is. Customise where the work runs on your own data. Build only the evaluation, integration and control layers that make you independent of any one vendor. Those layers are the in-house capability most worth having, and the one most firms neglect.

Sources

From AI and Jobs: UK, October 2026