Where deep-tech AI startups should own the stack, where they should rent it, and where ownership has quietly stopped being an option.
Two years ago the build-versus-buy debate for AI was a debate about capability: could you get a good enough model without training one? That question is closed for all but a handful of frontier labs. The 2026 debate is about commitment — which parts of the stack a company can realistically own, maintain, document, and evolve over a multi-year horizon.
Three forces did the work. First, price. Stanford's AI Index reported that querying a model at GPT-3.5-equivalent accuracy fell from about $20 per million tokens in November 2022 to roughly $0.07 by October 2024 — a ~280× reduction. Later 2026 write-ups extend the trend to ~1,000× over three years, though the multiplier depends on which benchmark and which two dates you pick.
Second, the open-weight floor. The open-vs-closed performance gap narrowed from 8% to 1.7% on some benchmarks within a single year. For a startup, the open floor is optionality. It is what makes "swap the model underneath" a real plan rather than a slide.
Third, the failure record. MIT's Project NANDA found that about 95% of enterprise generative-AI pilots produced no measurable P&L impact. We cite it because it is the most-referenced datum in every 2026 build-buy-partner discussion. The failures were concentrated in integration and organisational learning, not model quality or regulation.
The vocabulary is loose in practice, so fix it. Build means permanent internal ownership of a capability and its lifecycle. Buy means acquiring the capability as a product, licence, or company. Partner is a collaborative engineering relationship in which external expertise contributes to architecture while the client retains ownership of the outcome.
| Dimension | Build | Buy | Partner |
|---|---|---|---|
| Time to first production value | Quarters to years; one estimate puts 18–24 months and $1.5–2M+ per year | Days to weeks for a hosted product; months if it is an acquisition | Weeks; a fixed-scope, time-boxed proof of concept (e.g. four weeks) |
| What you actually own | Code, weights, data pipeline, and the whole lifecycle | A contract and a roadmap dependency you do not control | The outcome and the IP — if the engagement is written that way |
| Recurring obligation | Model drift, retraining cycles, eval maintenance, compliance documentation | Price and terms risk; vendor regret is among the most expensive problems | Knowledge-transfer discipline; a partner who builds for you leaves a dependency |
| Principal failure mode | Sunk cost in a commodity layer; first-time builders reported to fail over 60% | Undifferentiated product — if any competitor can buy the same tool, it is overhead | Open-ended retainers, black-box delivery, no structured handover |
| Best fit | The one or two capabilities that are your defensible advantage | Commodity capability, mature market, low switching cost | Differentiated but not permanent: low internal capability + high complexity |
A single company-level answer is the wrong resolution. The decision is per layer, and for science-based ventures the layer that carries the defensibility is rarely the model — it is the instrument, the assay, the simulation, the physical process, or the proprietary measurement loop that produces data nobody else has.
| Layer | Default posture | Reasoning |
|---|---|---|
| Compute & serving | Buy / rent | Utilisation break-even rarely favours owned GPUs pre-scale. Inference routing and caching matter more than ownership. |
| Foundation models | Buy, with a portability plan | Price falls ~10× a year at fixed quality; the open-weight floor is close. Build only if the model is the science. |
| Domain data & labelling loop | Build | The only asset that compounds and cannot be bought by a competitor at the same price. |
| Evaluation & safety harness | Build | Your eval set encodes domain knowledge that makes improvement possible — and it is what regulators will ask about. |
| Orchestration & agent logic | Build (thin) | Owning orchestration lets you swap the model when a supplier changes terms or availability. |
| Hard integrations (EHR, ERP, lab) | Partner | High complexity, low strategic content, brutal calendar risk. A scoped engagement compresses timeline. |
| Compliance & audit evidence | Partner, own the artefacts | Buy expertise; keep documentation and model cards in-house. They are due-diligence assets at the next round. |
| Go-to-market motion | Partner | Distribution via incumbents whose customers you serve is the pattern attributed to fastest-growing companies. |
Margin. The marginal cost of serving an AI query is not near zero. Cost of goods scales with usage, which is why practitioner analyses place AI gross margins around 50–60%, compared to 75–85% for traditional SaaS. For a build decision this matters twice: you carry both the inference bill and the amortised cost of the team maintaining what you built.
Deflation cuts both ways. If inference cost per million tokens halves, a product priced unchanged moves to higher margin. But the same deflation erodes any moat built on model access, and there is a credible argument that current token prices reflect a subsidy-driven buyer's market.
The deep-tech time tax. BCG found that deep tech investments take 25–40% more time between funding stages, carry greater failure risk at each stage, and that among funds above $1B in assets 42% of investments are multi-round.
A build decision in deep tech spends the scarcest resource — the 25–40% longer interval to the next milestone — on a layer that may deflate by an order of magnitude before it ships. Every quarter of build time on a commodity layer is a quarter not spent producing the proprietary data that makes the next round raisable.
For a startup, the most consequential form of "buy" in this market is one where the startup is the asset. The structure — variously called the reverse acqui-hire or quasi-merger — pairs a non-exclusive technology licence with the hiring of founders and core researchers, leaving the legal entity intact. The mechanical driver is that traditional acquisitions above roughly $120M trigger mandatory Hart-Scott-Rodino pre-merger notification; a licence-and-hire package generates no such filing and can close in weeks.
| Deal | Reported structure | Outcome for the shell |
|---|---|---|
Microsoft / Inflection Mar 2024 | ~$650M total; ~$620M for model licence + ~$30M non-suit; ~70-person team hired including CEO | No HSR filing. Last valued near $4B; investors took modest return or were repaid $1.3B |
Amazon / Adept Jun 2024 | ~$25M licensing fee; roughly two-thirds of team hired; no equity purchased | Drew regulatory questions; FTC opened probe following Microsoft–Inflection inquiry |
Google / Character.AI Aug 2024 | $2.5–2.7B for non-exclusive model licence; founders returned to Google | Proceeds used to buy out investors; staff received cash and equity — most employee-favourable case |
Meta / Scale AI 2025 | Large minority stake plus hiring CEO to lead internal lab; voting rights transferred back | Customer flight — Google terminated. A live warning about neutrality-dependent business models |
Three practical consequences for founders and their boards. One: team composition and research output carry exit value independent of revenue. Two: standard single-trigger acceleration does not fire on a licence-and-hire; acceleration clauses should be redrafted to cover talent-and-licence transactions. Three: for anyone whose business depends on being seen as neutral infrastructure, a strategic investor's stake can be a customer-retention risk.
Partnering is the option most often omitted from the analysis and the one that most often fits: a differentiated capability that needs architectural expertise, delivery speed, or an investment level an internal team cannot sustain. The failure modes are contractual, not technical. The clean form is a scoped engagement rather than an open-ended retainer.
The distinction worth writing into the statement of work is simple: a partner building with you leaves the organisation stronger after the engagement; a partner building for you leaves a system and a dependency.
If you build a general-purpose model, you take on provider obligations. If you buy one, you inherit a supplier's compliance posture and your own deployer duties. For EU-facing companies the calendar is concrete. GPAI model obligations have applied since 2 August 2025. The Digital Omnibus on AI defers high-risk duties but does not dismantle them.
| Date | What applies | Who it binds |
|---|---|---|
| 2 Aug 2025 · in force | GPAI model obligations (Art. 51–56); AI Office operational | Anyone who builds a general-purpose model |
| 2 Aug 2026 · live | Article 50 transparency (disclose AI interaction, AI-generated content); watermarking grace period to 2 Dec 2026 | Almost every AI product touching EU users |
| 2 Dec 2026 | Watermarking grace period ends; Art. 5 prohibition on non-consensual intimate imagery and CSAM | Generative image, video, and audio providers |
| 2 Dec 2027 | High-risk obligations for Annex III systems — recruitment, credit, education, law enforcement | Applied-AI startups in those verticals |
| 2 Aug 2028 | High-risk obligations for AI embedded in Annex I regulated products — medical, machinery, vehicles | Most hardware-bearing deep tech |
Penalty tiers: €35M or 7% of turnover for prohibited practices, €15M or 3% for high-risk and transparency breaches, €7.5M or 1.5% for supplying misleading information.
Score each candidate capability — not the company — against six tests. Rate where low internal capability with high complexity and high criticality points to partnering.
Ask any AI company for its model-routing and caching strategy with the same rigour as customer acquisition cost — in 2026 it is the larger swing factor. And ask what happens to the product if its primary model supplier changes price, terms, or availability next quarter.
Whether you're evaluating build-versus-buy decisions, designing a deep-tech stack, or planning an investor roadshow, we can help map this framework to your context.
How AI and software engineering cut avoidable cost and shorten lead times for Irish and EU metal fabricators — with a reference architecture and pilot plan.
How AI governance and AI security differ, what each one guards against, and how to combine them into a single layered defence for enterprise AI systems.
A plain-English GDPR handbook for SMEs — and how the EU AI Act, Data Act and a wave of new regulation now sit on top of it.