Almost a third of organisations have now decided against buying at least one software product because they could build it themselves instead. That is 32 percent, from the McKinsey State of AI survey fielded in May and June 2026 across 1,719 respondents in 97 countries.
The more interesting number sits underneath it. Among the companies McKinsey classes as high performers, the six percent who attribute at least five percent of their EBIT to AI, nearly half skip the purchase and build. Among everyone else it is 31 percent.
So the build-or-buy line is moving, and it moves fastest in the companies where AI already shows up in the profit line. Which makes it worth being precise about what is actually on the table, because “AI software” is not one thing. It is four, and the difference between them is not how advanced they are. It is whose data it is, whose logic it is, and what you are left with when the supplier changes the terms.
AI software, defined without the marketing
AI software is software where part of the decisions are made by a model trained on data, rather than by a rule a person wrote out explicitly.
That sounds academic and has one very practical consequence. A classic program answers the same question the same way every time, because someone wrote that down in code. A program with a model inside may answer differently. Not because it is broken, but because that is how it works.
All the engineering around such a system comes down to one question: what is the model allowed to decide, and what has to stay on the side of a rule and a human. We will come back to that question a few times, because it is what separates a system you can run a company on from a demo that looks good in a slide deck.
Before we go further: the letters "AI" on a box are not a technical property. Since 2023 they have appeared on products that do exactly what they did before. The only way to check is to ask which specific decision in this program is made by a model, and what happens when the model gets it wrong.
Four kinds of AI software, and what actually separates them
This is not a ladder from worse to better. These are four different answers to four different situations.
| Kind | Example | Whose data | Whose logic | Where it fails |
|---|---|---|---|---|
| 1. Off-the-shelf tool | ChatGPT, Copilot | the vendor’s | the vendor’s | when it needs to know your process |
| 2. AI feature in a system you own | a module in your ERP, CRM, TMS | the vendor’s | the vendor’s | when they did not anticipate your case |
| 3. Automation or agent platform | low-code tools, agent platforms | yours, but hosted by them | yours, but inside their limits | when the platform changes the rules or disappears |
| 4. Bespoke system with AI inside | built around your process | yours | yours | when the process is standard |
1. An off-the-shelf tool on a subscription. You buy access and use it. Upside: it works immediately, the risk is close to zero. Downside: the tool knows nothing about your company, and everything you paste into it leaves the building.
It is worth doing the arithmetic, because a subscription looks cheap only while you count it per person. Microsoft 365 Copilot lists at 30 USD per user per month as an add-on, and requires a qualifying base plan underneath. At twenty people that is 7,200 USD a year for the add-on alone, before you count the licences it sits on. Resellers with an annual commitment quote lower, around 18 EUR net, but that is a conditional price rather than the list one.
2. An AI feature bolted onto a system you already own. Your ERP, CRM or TMS vendor switches on a module: suggestions, classification, generated descriptions. Upside: the data stays where it was and there is no new implementation. Downside: it works exactly within the limits of the vendor’s imagination. A case outside their roadmap does not get handled.
3. An automation or agent platform. You assemble the flow from ready blocks and plug a model into it. Upside: fast, and without a developer. Downside: you live on someone else’s platform. Billing is usually per operation or per completed task, so the cost grows with scale, which is precisely when the thing starts working. And when the platform changes its pricing or shuts down, the flow goes with it.
4. A bespoke system with AI inside. The code is yours, the data is yours, the logic is yours. Upside: the system describes your process rather than the market average. Downside: it is a project, not a purchase, so you need to know what is being built.
The conclusion: most companies need kind 1 and kind 2 and should stop there. You move to kind 4 when the process you want to support is your competitive advantage, because then you do not want it squeezed into someone else's form. That is also the pattern in the McKinsey data: the companies building instead of buying are not the average ones. If you are at that point, we have written separately about how to choose a supplier for such a system.
What is inside: five technologies you will meet
The same names keep coming back in proposals and articles. Below each one is described by the job it does in a company, not by a textbook definition.
Machine learning. Predicting a number from historical data. When a machine will fail, how long a route will really take, which customer will stop ordering. The entry condition is hard: you have to have that historical data, in a form something can read, not scattered across emails and notes.
Neural networks and deep learning. The same job, on data that does not fit in a table: images, audio, free text. It needs more data and more compute. In practice a small or mid-sized company uses models someone else has already trained rather than training its own.
Natural language processing and chatbots. Reading and writing text. Classifying incoming mail, pulling an amount and a due date off an invoice, drafting an answer to a routine enquiry. This is currently the most common and the cheapest use of AI in a company, because everyone has more text than they can read.
Computer vision. Quality control on a production line, reading plates and trailer numbers, checking whether someone is wearing a helmet. It works well where a camera can be placed in repeatable conditions.
Process automation. The connective tissue for everything else: moving data, triggering the next step, sending a notification. And here a warning, because this is the most common misuse in the market: automation on its own is not artificial intelligence. A flow that copies form data into a spreadsheet is automation, whatever the salesperson calls it.
You do not need to know which of these technologies you need. That is the supplier's job. What you do need is the ability to tell when the supplier does not know either, and the simplest test is this: "which decision in this system is made by the model, and which by a rule?" Anyone who works on such systems answers without pausing.
Where it works today, and where it does not yet
Four areas where we see the shortest path from implementation to effect:
- Manufacturing. Predictive maintenance and quality control. The sensor and camera data is already there, and usually nobody reads it.
- Transport and logistics. Planning, transport document flow, driver settlements. The largest gap between potential and adoption of any sector we work in.
- Document flow and company finance. Reading invoices, matching them to orders, closing the month. The easiest first step, because the effect shows up in hours of work.
- Sales and customer service. Classifying enquiries, drafting answers, keeping customer data in order.
What is not on that list. Medical diagnostics and regulated financial services are a different league of requirements: approvals, validation, liability for error. Specialised teams do that work and it is not our field. A supplier who lists AI for diagnostics, credit scoring and route planning in one breath is worth asking about implementations in each of those areas separately.
Your data, GDPR and the EU AI Act
Ask the same three questions about each of the four kinds. The answers differ, and they are usually what settles the choice.
- Where does my data physically land? Inside the EU, outside it, with whom, for how long.
- Is it used to train someone else’s model? In consumer plans usually yes, in business plans usually not, but that has to be read rather than assumed.
- What happens when I terminate the contract? Whether you take the data with you and in what format. With kind 3 this question is critical, because the flow stays on the platform.
The EU AI Act causes more worry than it should. The calendar in short: since February 2025 prohibited practices and an AI literacy obligation for staff have been in force. Since August 2026 the transparency obligations apply: you must disclose that someone is talking to an AI system, and label generated content. Obligations for high-risk systems arrive on 2 December 2027, a date moved back from August 2026 under the Digital Omnibus package. Penalties reach 35 million euro or 7 percent of worldwide turnover.
Your typical case looks like this: a bespoke transport system, an invoice workflow, a production panel. Those are not high-risk systems. High risk starts where AI assesses people: recruitment, scoring, access to benefits.
None of the above is legal advice. It reflects the state on 3 September 2026, and at this pace of change it is worth checking the date before relying on it.
How to choose the kind for your company: three questions
This is not about choosing a supplier. It is the decision that comes before: which category to consider at all.
Question 1: does the process you want to support look the same at your company as at your competitors? If yes, buy off the shelf. Nobody will pay you a premium for a proprietary way of issuing invoices. If no, and that difference is the reason customers choose you, a bespoke system stops being an indulgence.
Question 2: what does that process cost you today in people’s hours? If you cannot answer, that is your first task, not an AI implementation. Without that number no quote can be assessed, because there is nothing to compare the price against.
Question 3: what happens if the supplier raises the price by 40 percent or shuts the product down? With kind 1 you shrug and find another. With kind 3 you lose a flow that was doing real work. With kind 4 nothing happens, because the code is yours.
Orders of magnitude, so there is something to hold the answers against:
| Situation | The kind that fits | Order of magnitude | What to expect |
|---|---|---|---|
| I want the team to write and search faster | 1. off-the-shelf tool | ~30 USD/user/month plus base licence | effect within a week, zero fit to your process |
| I have an ERP or CRM and want suggestions in it | 2. vendor feature | an uplift on the subscription | fast effect, rigid limits |
| I want to connect several tools into one flow | 3. platform | billed per operation | fast start, cost grows with scale |
| My process is my advantage, first system | 4. bespoke | 8,000–45,000 USD for an MVP on the market | a project, not a purchase |
| I need an operating system for the company | 4. bespoke | 150,000–500,000 USD mid-market, up to 2M enterprise | plus 20–30% a year for maintenance |
Two notes on that table, because the numbers come from different places.
The market ranges are published by vendors, not measured by an independent study, so read them as an order of magnitude rather than a price list. What is consistent across them is the shape: an MVP in the tens of thousands, an operating system for a mid-market company in the hundreds of thousands, and maintenance at 20 to 30 percent of the project value per year.
Our own figures sit below that range, and we state the scope in which they hold: a first working system between 1,500 and 7,500 USD, and an operating system for a mid-sized company between 15,000 and 75,000 USD. That applies to new systems built from scratch, which is the only scope where the speed-up behind those numbers is documented. We have written up the method, together with the studies that contradict it, in a separate article on AI-assisted engineering.
When you reach the point of “right, so who do I hire to build this”, the decision framework with ten questions for a supplier is on a separate page.
What a system that really has AI inside looks like
Below are systems we built for ourselves and work on every day. These are not client implementations.
A weekly report on the company’s condition. The model reads the state of every system and on Monday morning sends the owner a report with recommendations. The key design decision: a deterministic algorithm computes the priority, and the model only puts the result into language. The same situation always produces the same priority, because the model does not decide what is urgent.
A mailbox that classifies post and drafts replies in the owner’s voice. It also extracts facts from correspondence and suggests them to the customer database. The first learning cycle collected ten corrections out of 838 messages.
A validator for incoming content. It rejected an attempt to inject an instruction into the body of an email, aimed at getting the system to write an entry into the database. It happened in production.
A customer database that separates fact, calculation, missing data and conflicting data. It never presents a guess as a certainty.
Three rules come out of those four examples, and they are worth asking any supplier about:
- Nothing reaches a person without approval. Our lead nurturing system deliberately has no automatic schedule, because a schedule on the sending step would be sending without consent.
- Incoming content is untrusted. An email, a form and a comment are data, not instructions for the system.
- The machine proposes, a person decides, and that decision stays in the history along with the reason.
That is the answer to the most common worry about AI in a company: that something will act without anyone knowing. The three rules above are how you rule that out.
Frequently asked questions
Does AI software need its own server? In the vast majority of cases, no. Models are provided as a service and your system simply connects to them. Your own infrastructure comes into play when the data cannot leave the company, and then it is a deliberate, expensive decision rather than a default.
Will my data be used to train someone else’s model? It depends on the plan, not on the vendor. In consumer plans usually yes; in business plans and through programming interfaces usually not. It is a clause in the contract that has to be read before anyone pastes a proposal or customer data into it.
How long until the first working result? With an off-the-shelf tool, days. With a feature from your system vendor, weeks, provided they have it. With a bespoke system built using AI-assisted methods, the first working piece should appear in weeks, not months. If you hear “first demo in six months”, ask why.
Do I need an IT department? For kinds 1 and 2, no. For kinds 3 and 4 you need one person on your side who understands the process and has the authority to decide, not a team of developers. The absence of that person is the most common reason an implementation stalls.
How is AI different from ordinary automation? Automation performs steps someone described in advance. AI makes a decision nobody described explicitly, based on what it learned from data. Most of what is sold as AI today is in fact automation, and very often that is entirely sufficient. The difference starts to matter when the price reflects one and you receive the other.
Where to start
Three sentences to close.
First: before you start choosing a tool, establish which of the four kinds you are looking for, because the proposals you receive will cover all of them at once. Second: count what the process you want to improve costs you today, because without that number no quote has a reference point. Third: note where the McKinsey data points. The companies skipping the purchase and building instead are not the average ones; they are the ones already showing AI in their EBIT.
Where the numbers come from: build-versus-buy data and the high-performer split come from McKinsey, "The State of AI: Global Survey 2026", fielded 4 May to 8 June 2026 across 1,719 respondents in 97 countries. The Copilot figure is Microsoft's published list rate for the add-on; the reseller price quoted beside it is conditional. The market cost ranges are aggregated from figures published by development vendors in 2026 and are indicative rather than measured. The AI Act calendar follows Regulation (EU) 2024/1689 together with the Digital Omnibus package of June 2026. Our own figures are our own, converted from the currency we work in, and hold for new systems built from scratch.
Find out which kind of AI your company needs
A free digital audit takes one to two days and ends with a diagnosis, not a quote. You will hear when a subscription is enough, and when it is worth building your own.
Book a free audit →