Start with two questions
Danielle Benecke, who founded and leads Baker McKenzie’s Applied AI practice, uses two scales to decide what her firm owns and what it rents:
“One way that we think about it is there’s a scale from generalizable to custom, there’s a scale from extremely strategic to not so strategic.”
Plot the capability on both, then apply her rule:
| Not strategic | Strategic | |
|---|---|---|
| Generalizable | Rent. “For the stuff that is super generalized, not particularly strategic or important to your organization, totally fine to rely on a harness that lives outside of your environment.” | Rent, but avoid lock-in. Watch the dependency of running on someone else’s platform. |
| Custom | Buy, or build only if it is cheap to maintain. | Own it. “For the very strategic stuff that ultimately turns on your expert steering or internal playbooks and internal know-how, you need to be very careful about where that harness lives.” |
The test is whether the work turns on your expert steering, your internal playbooks, and your know-how. When it does, owning that layer is the point. When it does not, renting is fine.
You are already running several of these
Danielle’s description of the layers a large organization ends up with, all at once:
- Direct model access through cloud AI environments.
- Productivity-layer harnesses, with Anthropic’s Cowork and the equivalent capability in Microsoft environments as examples.
- Domain-specific vendor tooling, where most large firms hold several tools with different harnesses.
- Your own bespoke harnesses. At Baker McKenzie every service line and every system they design for a client carries its own. Her note on how simple this can start: “The most simple harness is probably a folder of markdown files.”
Her caution on the portfolio: be agile and “not bet the farm on any one thing.”
The framework
| Criterion | Build when… | Buy when… |
|---|---|---|
| Speed to value | You have an internal team that can ship within weeks, AND no vendor currently nails the problem | A vendor already solves it well and you can integrate in days |
| Control & policy | You’re in a regulated industry where policies, patches, and compliance posture must be yours (Vinh’s framing at RBC) | The use case is horizontal and the vendor’s controls already match your bar |
| Differentiation | The capability IS your differentiation, or the way you operationalize it is | The capability is generic and customers won’t care who built it |
| Data moat | You have proprietary data competitors can’t replicate | The vendor’s moat is data aggregated across many customers, something you can’t realistically reproduce alone (Carol on Sumble) |
| Team capability | You have AI builders embedded in the function that owns the problem | You have functional experts but not engineering bandwidth |
| Total cost of ownership | The build will produce reusable infrastructure (a platform, not a feature) | The buy avoids long-term maintenance you don’t want to own |
| Risk tolerance | Mistakes are tolerable, learning is part of the goal | You need production-grade reliability from day one |
Examples from the show
Build calls that worked:
- RBC’s Lumina data platform and Agentic Control Plane (Ep 2). Vinh’s argument: in a regulated industry, building gives you “control of your destiny, your policies, your patches, your compliance posture.” Open source has matured, AI coding tools give 10-100x engineering leverage, and cloud democratizes services that used to require a large vendor. Building costs more and gives control.
- Logitech’s composable commerce architecture (Ep 3). Deepa’s reframing: composable architecture wasn’t an AI play. But it’s the reason agentic commerce is available to her team today. The platform decisions made to “modernize” the stack now look like AI-readiness decisions.
Baker McKenzie runs both at once (Ep 5). The firm reaches frontier models directly, buys best-in-class vendor tooling including Legora, and builds its own harnesses per service line. Danielle starts from what clients need rather than from the technology: “Our clients need strategic clarity, decision velocity, and risk mitigation.” That need decides which capability gets plugged in where. She also flags what most buyers underweight: “Many players in the industry still think of this as primarily a technology shift. Technology is obviously a big part of it, but the commercial model transformation part is” the larger change.
Buy calls that worked:
- Cohesity using Sumble for top-of-funnel ABM (Ep 6, on the recording schedule). Carol’s framing: “Same old decision tree of build vs. buy. What do you want to continue to maintain? In this case, a company like Sumble, let somebody else collect all the buying signals. We don’t need to.”
- Logitech using Typesense for the agentic commerce search layer (Ep 3). Jason’s pitch to a customer who could conceivably build it: “Sure, you could build this with LLMs, but it would take you a long, long time.” The proprietary knowledge graph is the moat.
Warning signs you picked the wrong side
- You’re building but every sprint feels like you’re rebuilding something a vendor already does. The build was about pride, not strategy.
- You’re buying but the vendor’s roadmap is taking them away from your use case. The moat you bought into is eroding.
- You’re building but the team isn’t shipping. The build was a real strategic call, but you don’t have the engineering bandwidth to back it.
- You’re buying but the data your vendor’s AI is being trained on is your data. The integration is more strategic than you priced it.
- You’re renting a harness that steers work turning on your own playbooks and know-how. By Danielle’s test, that one belongs inside your environment.
Where this came from
Every quote above is from an episode of Enterprise Aligned AI. The build-vs-buy discussion with Baker McKenzie and Legora is in Who Owns the Legal AI Harness?. Vinh Tran’s case for building inside a regulated bank is in Royal Bank of Canada’s $1B AI Transformation.
Real conversations with enterprise leaders implementing AI. New episodes by email: enterprisealignedai.com/subscribe