Build vs Buy vs Partner
The useful question is not whether to build or buy AI, but which capabilities the enterprise must own, which it can source and which it should share. Two tests decide most cases: would we still have an advantage if competitors had this capability tomorrow, and how badly would a vendor's change hurt us? The answer differs by layer, and it changes over time, so every choice needs an exit.
After this chapter you can
- Reframe "build or buy?" as "what must we own, source or share?"
- Explain when build, buy and partner each fit, and the trap each one hides.
- Apply the differentiation test and the control test to one capability.
- Make the sourcing choice layer by layer, and recognize when building on a bought system changes legal duties.
- Plan for change and exit, so today's choice can be revisited.
In March 2023, Bloomberg published a paper describing BloombergGPT, a 50-billion-parameter language model built for finance. It had been trained on 363 billion tokens drawn from Bloomberg’s own financial data sources, plus 345 billion tokens of general text1. Few companies anywhere had the data, the engineers or the budget to attempt it. On paper, it was the strongest possible case for building.
Within months, a team of researchers tested general-purpose models that anyone could rent against it. On most financial text tasks, the general models did better. On conversational questions about financial reports, GPT-4 answered 76 percent correctly without examples; BloombergGPT managed 43 percent. Only on picking out names of people, places and organizations did the purpose-built model keep a lead2.
The comparison is not a verdict on Bloomberg. It is a lesson about where advantage sits. Bloomberg’s position never rested on owning a language model. It rests on data, a terminal and the daily workflows of the people who use them, none of which a competitor can rent. The model was the one layer that the market was improving fastest, and so the one most likely to be matched by something anyone could buy.
The question beneath the question
Most sourcing debates start with a binary: can we build it, or should we buy it? That framing produces slogans. “AI is strategic, so we build.” “A vendor already sells it, so we buy.” Both slogans skip the question that matters to an executive: which capabilities must we own, which can we source, and where should we share the work with a partner?
The market has already moved toward buying. In Menlo Ventures’ survey of about 500 US enterprise decision-makers, 76 percent of AI use cases were purchased rather than built in late 2025, up from 53 percent a year earlier3. The survey comes from an investor and is a signal rather than a census, but the direction is clear. The same survey reports that ready-made tools are reaching production more quickly, which is a buyer’s view of speed, not a measured return.
When buying is the default, the strategic work is to name the exceptions. The idea is older than AI. James Brian Quinn and Frederick Hilmer argued in 1994 that a firm should concentrate its own resources on the few competencies where it can be preeminent and create unique value for customers, and outsource activities for which it has neither a critical strategic need nor special capability4. C. K. Prahalad and Gary Hamel had already warned of the other edge: outsourcing can be a shortcut to a competitive product, but the skills behind the next product cannot be “rented in”5. A sourcing decision for AI is both at once. It decides what you get, and what your organization will still know how to do in five years.
Three options, three traps
Each option has a situation it fits and a trap that sounds like strategy.
Build means developing significant capability inside the organization: a proprietary product, a knowledge layer made from your own documents and history, a specialized way of testing AI quality. It fits when the capability differentiates you, when you need tight control over its behavior, data or roadmap, and when it depends on data and expertise only you have. The trap is applying “strategic” to every layer. Teams then rebuild what the market already sells, deliver slowly and carry maintenance they cannot staff. Strategic does not mean proprietary.
Buy means acquiring a capability the market already offers: a general-purpose assistant, a document-reading service, a managed model. It fits when the capability is mature, many vendors offer something similar, and speed matters. The trap is believing that buying needs no strategy. A purchased capability still needs decisions on data, security, integration and governance, because it becomes part of your enterprise, and so do its failures. When an airline argued that its website chatbot was responsible for its own misleading answer, a Canadian tribunal rejected the idea and held the airline liable6.
Partner means combining what you know with what a specialist knows, to create something neither could easily make alone. It fits when you know the problem deeply and the specialist has skills that would take years to grow. The trap is vague ownership: who owns the improvements, who may reuse them, whether the partner can sell the same thing to your rivals, and how you leave.
The differentiation test
The first test does most of the work, and it is easy to read backwards. Ask: if our competitors had exactly this capability tomorrow, would we still have an advantage?
If the answer is yes, the capability is not where your advantage comes from. You would win anyway, because your edge lies somewhere else: in your customers, your brand, your network, your data. Buying is probably sensible, and the money and talent you save can go to what does set you apart. If the answer is no, and handing the capability to rivals would erase your lead, then this capability is your edge. Consider owning it.
The logic follows the resource-based view of strategy. Jay Barney argued that lasting advantage comes from resources that are valuable, rare and hard to imitate7. A capability any rival can buy from the same vendor next quarter is valuable, perhaps, but it is not rare. Michael Porter made the same point through activities: advantage comes from the particular things a firm does and how it links them, not from inputs everyone can acquire8.
A “no” answer is only half a decision. The second question is whether you can build the capability and run it for years, with the engineering, data, security and product skills that takes. Plenty of technically attractive builds fail because the organization cannot sustain them. If you can, build. If you cannot, partner, and keep the data and the workflow on your side. AI and Competitive Advantage and Proprietary Data, AI Moats and Differentiation, later in this module, look more closely at what makes an edge last.
Decide layer by layer
The second idea is that the choice is rarely made once for a whole system. Any AI capability is a stack of layers, and the answer can differ at each one.
At the top sits the workflow: how the work runs, who checks what and who decides. That is usually where advantage lives, so organizations tend to own it. Below it sits the knowledge layer, your documents, product information and policies, prepared so an AI system can find and use them. It is often built, because it is made from what only you know. Then comes the model, the general-purpose engine, which most enterprises buy. Beneath that sit your data and the infrastructure: own the first, usually buy the second.
Marco Iansiti and Karim Lakhani describe AI-first firms as running an “AI factory” of data pipelines, algorithms and experimentation built into the operating core9. The factory is what such firms own. Many of the parts that go into it are bought. The model layer is the clearest case for buying, because it is where rivals catch up quickest. In 2026 the most capable open-weight models trailed the leading closed models by an average of about four months10. A layer that the whole market catches up on within a season is a poor place to stake your edge, which is what the BloombergGPT comparison showed. How a shared platform should be organized across these layers is the subject of AI Platform Strategy.
The control test
The second test asks: how badly would it hurt if a vendor changed its price, its availability, its behavior or its roadmap? This is not hypothetical. When researchers tracked one hosted model under the same name, its accuracy at identifying prime numbers fell from 84 percent in March 2023 to 51 percent in June11. Retirement is scheduled, too. Under one major cloud provider’s standard policy, a generally available model version is retired 18 months after launch, and retired models return errors to every request12.
Dependency builds up quietly, through custom integrations, data held in a vendor’s format and skills tied to one product. When the harm would be serious, there are three protections. Keep a thin layer of your own between the vendor and your applications, so the model can be swapped without rebuilding the workflow. Keep a second supplier possible, even if you do not use one yet. And write protections into the contract. Each adds complexity, so the question is always whether the flexibility is worth its cost for this capability. For many low-stakes tools it is not.
Control also has a legal side. Building on top of a bought system can change who carries the duties for it.
The answer changes, so plan the exit
No sourcing choice is permanent. A company might buy in its first year to learn quickly on a mature product, partner in its second as its own data and skills grow, and build in its third once the capability has proved to be a real differentiator. The reverse happens just as often, when something built in-house becomes a commodity that the market does better and cheaper.
That is why every major dependency needs an answer to one question: what happens if we need to leave? Can we take our data with us in a usable form? How long would migration take? Who else could supply the capability? The contract should match the strategic intent, covering who owns the data and the improvements, whether the vendor may train on your data, who owns the intellectual property, and how termination and portability work. Revisit the choice at strategy reviews, when the technology shifts, when a vendor changes terms and when a capability becomes more important.
Cost matters too, and the first invoice is never the cost. Building carries talent, operations and upgrades; buying carries usage fees, integration and switching costs; partnering carries coordination. The arithmetic belongs to Build vs Buy Economics and Investment Decisions in Module 08. Here the question is strategic: what to own.
Story: Thomson Reuters builds, partners and buys
Thomson Reuters sells legal, tax and news information to professionals, through services such as Westlaw and Practical Law. When generative AI arrived it had to decide what to own, and in 2023 it told shareholders its answer: a “build, partner, buy” strategy, backed by more than 100 million dollars a year of additional AI investment14.
Each word went to a different layer. Build went where the company said it had “the content, the technology and the domain expertise to excel”: generative AI added to Westlaw Precision and to Practical Law, whose answers are validated against content written by more than 650 legal experts1415. Partner went to distribution: a contract-drafting tool built with Microsoft for Microsoft 365 Copilot in Word, where lawyers already write. Buy went to speed. In June 2023 the company agreed to buy Casetext, a 104-person start-up, for 650 million dollars in cash, and completed the deal in August. Casetext’s assistant, CoCounsel, launched earlier that year, ran on a model the start-up rented: GPT-416. Thomson Reuters said the purchase was “enabling us to move faster” and that the assistant would become the interface for all its generative AI products14.
The model layer was the one it did not try to own at first. By November 2024 CoCounsel was “multi-model”, testing and combining models from OpenAI, Anthropic and Google to find which best served specific uses17. That is the control test at work: no single supplier’s change could break the product. The company also named its edge in its own words: “our proprietary content databases and our extensive teams of experts”14. A rival could rent the same models next quarter. It could not rent Westlaw.
Then the answer moved. In August 2026 Thomson Reuters announced Thomson, a model of its own. It spent about 40 million dollars over two years on talent and compute (the final training run cost about 450,000 dollars) and trained it from an open-source foundation and on decades of its Westlaw, Practical Law, Checkpoint and Reuters content18. CoCounsel stays “multi-model by design”, using the new model “where it delivers the clearest advantage and other leading models elsewhere”19. It went first into one high-volume document-review feature18.
The build came three years after the purchase, on the one layer where the company’s data is unique, and next to rented models rather than instead of them. This is a record of stated choices, not proof of results: the company’s filings do not show which layer earned what. The tests did not give one answer for the whole stack. They gave a different answer at each layer, and a different answer as time passed.
A picture helps to hold the idea. A good wine estate buys its bottles, corks and presses, because every estate uses the same ones. It owns its vineyard and its blend, which no rival can copy. It may hire a consulting winemaker, a partner who brings skill while the estate keeps the land and the label. Nobody pays for a great vintage because of the glass. The picture breaks down in one place: a glass supplier cannot change the taste of your wine overnight. An AI vendor can, which is why the control test exists.
What this means for leaders
Treat sourcing as a capability decision, not a vendor selection, and expect buying to be the right answer most of the time. The leader’s job is to name the few exceptions, the capabilities that are your edge, and to protect them. Ask for every proposal to be split into layers before anyone says build or buy. Read the differentiation test slowly, because the direction of the answer matters. Run the control test on everything you buy, and insist that every major dependency comes with a written exit. Then put a review date on the decision, because the right answer will move.
Check yourself
- If competitors could get exactly this capability tomorrow and we would still have an advantage, the capability is our edge.
- Strategic AI means building our own model.
- Buying an AI capability transfers accountability for it to the vendor.
- A hosted model’s behavior can change even when its name does not.
- Open-source AI is free.
- The right sourcing choice for a capability can change over time.
Reflection: where your edge sits
What comes next
Deciding what to build, buy or share raises a further question: who inside the enterprise should own the capabilities you keep? Should a central team run them, should business units build their own, or is a hybrid best? The next chapter, Centralized vs Federated AI, takes up that choice.
Laws referenced
Not legal advice. Laws change; verify before relying on this, and consult counsel for decisions.
EU AI Act · EU
Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744
Risk-based rules. Prohibited practices include social scoring, untargeted scraping of facial images, and emotion recognition in workplaces and schools (with narrow exceptions). High-risk systems (Annex III: biometrics, safety components of critical infrastructure such as energy, water and traffic, employment and worker management, credit, education, essential services, law enforcement, migration, justice) need risk management, data governance, documentation, logging, human oversight, human oversight that keeps people able to understand the system, notice automation bias (over-reliance on its output), override it or stop it (Art. 14(4)), appropriate accuracy, robustness and cybersecurity (Art. 15), automatic logging of events (Art. 12), a provider quality-management system (Art. 17) and conformity assessment. An Annex III system is not high-risk if it poses no significant risk of harm, for example a narrow procedural or preparatory task that does not replace human assessment; systems that profile people are always high-risk, and a provider relying on this exception must document it and register (Art. 6(3)). Deployers of high-risk AI must use it as instructed, assign competent human oversight, monitor its operation, keep logs for at least six months and report serious incidents (Art. 26); employers must inform workers' representatives (Art. 26(7)). Public bodies, private providers of public services, and deployers of credit-scoring or life and health insurance pricing systems must carry out a fundamental-rights impact assessment before first use (Art. 27). Providers must run post-market monitoring (Art. 72). A deployer that puts its name on a high-risk system, substantially modifies it, or changes its purpose so that it becomes high-risk takes on the provider's obligations (Art. 25(1)). A substantial modification (Art. 3(23)) of a high-risk system needs a new conformity assessment, unless the change was pre-determined and documented at the first assessment, as with planned continuous learning (Art. 43(4)). Providers of general-purpose AI models (from 2 Aug 2025) must keep technical documentation, have a policy to comply with EU copyright law including text-and-data-mining opt-outs, and publish a sufficiently detailed summary of training content (Art. 53). Research, testing and development before a system is placed on the market or put into service is outside the Act, except testing in real-world conditions (Art. 2(8)). Since the 2026 Omnibus, the Art. 4 AI-literacy duty is an obligation of effort (take measures to support literacy), not of result. Fines reach EUR 35 million or 7% of global turnover for prohibited practices.
- 2024-08-01 — Entered into force
- 2025-02-02 — Prohibited practices (Art. 5) and the AI-literacy duty (Art. 4) apply
- 2026-07-27 — Omnibus softens Art. 4: providers and deployers must take measures to support AI literacy; no specific level must be guaranteed
- 2025-08-02 — General-purpose AI model obligations apply; governance and penalties regime in place
- 2026-08-02 — Transparency duties (Art. 50) apply: disclose AI interaction, label synthetic and deepfake content (marking for generative systems already on the market: 2 Dec 2026)
- 2027-12-02 — High-risk obligations for Annex III systems (e.g. hiring, credit, education, essential services) - moved from 2 Aug 2026 by the 2026 Omnibus
- 2028-08-02 — High-risk obligations for AI in products regulated under Annex I
Last verified 2026-10-06 · official text
References
- Shijie Wu, Ozan Irsoy, Steven Lu, Vadim Dabravolski, Mark Dredze, Sebastian Gehrmann, Prabhanjan Kambadur, David Rosenberg and Gideon Mann. BloombergGPT: A Large Language Model for Finance. arXiv 2303.17564 (v1 30 March 2023; v3 21 December 2023). 2023.
- Xianzhi Li, Samuel Chan, Xiaodan Zhu, Yulong Pei, Zhiqiang Ma, Xiaomo Liu and Sameena Shah. Are ChatGPT and GPT-4 General-Purpose Solvers for Financial Text Analytics? A Study on Several Typical Tasks. Proceedings of EMNLP 2023: Industry Track, pp. 408-422. 2023.
- Menlo Ventures. 2025: The State of Generative AI in the Enterprise. Menlo Ventures (9 December 2025). 2025.
- James Brian Quinn and Frederick G. Hilmer. Strategic Outsourcing. Sloan Management Review 35(4), Summer 1994, pp. 43-55. 1994.
- C. K. Prahalad and Gary Hamel. The Core Competence of the Corporation. Harvard Business Review 68(3), May-June 1990, pp. 79-91. 1990.
- Civil Resolution Tribunal (British Columbia). Moffatt v. Air Canada, 2024 BCCRT 149. CanLII. 2024.
- Jay B. Barney. Firm Resources and Sustained Competitive Advantage. Journal of Management, vol. 17, no. 1, pp. 99-120. 1991.
- Michael E. Porter. Competitive Advantage: Creating and Sustaining Superior Performance. Free Press. 1985.
- Marco Iansiti and Karim R. Lakhani. Competing in the Age of AI: Strategy and Leadership When Algorithms and Networks Run the World. Harvard Business Review Press. 2020.
- Epoch AI. Open models lag state-of-the-art closed models by 4 months. Epoch AI (Data Insights). 2026.
- Lingjiao Chen, Matei Zaharia and James Zou. How Is ChatGPT's Behavior Changing Over Time?. Harvard Data Science Review 6(2). 2024.
- Microsoft. Foundry Models lifecycle and support policy. Microsoft Learn. 2026.
- European Parliament and Council of the European Union. Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act). Official Journal of the European Union. 2024.
- Thomson Reuters. Management Proxy Circular and Notice of Annual Meeting of Shareholders, June 5, 2024. U.S. Securities and Exchange Commission (EDGAR, Form 6-K exhibit 99.1). 2024.
- Thomson Reuters. Thomson Reuters unveils generative AI strategy designed to transform the future of professionals. Thomson Reuters press release, November 2023. 2023.
- Thomson Reuters. Thomson Reuters Corporation signs definitive agreement to acquire Casetext. Thomson Reuters news release, 26 June 2023 (filed with the SEC on Form 6-K). 2023.
- Thomson Reuters. Thomson Reuters CoCounsel tests custom LLM from OpenAI, broadening its multi-model product strategy. Thomson Reuters press release, 25 November 2024. 2024.
- SiliconANGLE. Thomson Reuters launches proprietary AI model for legal work. SiliconANGLE, 24 August 2026. 2026.
- Thomson Reuters. Thomson Reuters leverages its world-class data assets to launch its own frontier model. Thomson Reuters press release via PR Newswire, 24 August 2026. 2026.
Further reading
- James Brian Quinn and Frederick G. Hilmer. Strategic Outsourcing. Sloan Management Review 35(4), Summer 1994, pp. 43-55. 1994.
- C. K. Prahalad and Gary Hamel. The Core Competence of the Corporation. Harvard Business Review 68(3), May-June 1990, pp. 79-91. 1990.
- Marco Iansiti and Karim R. Lakhani. Competing in the Age of AI: Strategy and Leadership When Algorithms and Networks Run the World. Harvard Business Review Press. 2020.
Sources last verified 2026-10-10.