AI Governance · 2026-03-05

Build vs Buy in the Age of LLMs

sovereigntyprocurementLLMspublic sectorinfrastructure strategy
Key Insight

The build-vs-buy question is really a sovereignty dial: governments should optimize for control of data, risk, and upgrade paths, not a romantic preference for in-house models.

Review

Governments are increasingly confronting a deceptively simple strategic question: should they buy AI capability from vendors or build their own? The paper “Build vs Buy in the Age of LLMs” addresses this issue and avoids the usual binary framing. Instead, it presents a spectrum of options ranging from simple API access to fully sovereign national models, evaluated through lenses such as sovereignty, security, cost, talent availability, and national strategy.

That framing is the paper’s central contribution. In reality, most public sector deployments will fall somewhere between the extremes. Licensed model instances, retrieval‑augmented systems that keep national data local, and adaptations of open models are likely to dominate. Treating AI capability as strategic infrastructure rather than just another software procurement decision is exactly the perspective governments need.

The paper also highlights operational concerns that practitioners recognize immediately but policy debates often overlook: data residency, supplier concentration, crisis resilience, and public trust. These are not theoretical risks. They determine whether systems survive regulatory change, geopolitical tension, and the scrutiny that accompanies high‑profile public sector deployments.

However, the work reads more like a strategic briefing than a practical decision framework. While it identifies the right dimensions of the problem, it stops short of translating them into something a procurement team could operationalize. There is no scoring model, no structured method to weigh sovereignty against cost, and no comprehensive total‑cost‑of‑ownership analysis covering deployment, compliance, security testing, and long‑term operations.

The same limitation appears in the governance and security discussion. Risks are acknowledged, but the paper offers little in the way of concrete operational controls or procurement safeguards. Anyone familiar with large government technology programs knows that these implementation details often determine success or failure.

Overall, the paper succeeds in reframing the debate. The next step is turning that framing into a repeatable playbook. Governments do not simply need a conversation about build versus buy. They need a structured method to decide when each option actually makes sense.

Key Insight

The build-vs-buy question is really a sovereignty dial: governments should optimize for control of data, risk, and upgrade paths, not a romantic preference for in-house models.

Continue exploring

Related reviews

More in AI Governance
AI Governance · 2026-05-09

Governing Artificial Intelligence in India: Data Sourcing, Synthetic Content, and Technological Sovereignty

Kautilya School of Public Policy Working Paper #3

The paper connects data sourcing, synthetic content, and technological sovereignty as one governance loop rather than three separate policy problems. Its central gap is that it proposes institutional remedies without fully specifying the enforcement architecture, evidence duties, revocation mechanics, and redress pathways needed to make those remedies operational.

AI Governance · 2026-03-14

Advancing Indigenous Foundation Models

White paper

The paper’s decisive analytical move is treating indigenous foundation models as public-interest infrastructure, but it stops short of specifying the assurance, procurement, and lifecycle governance machinery needed to make that ambition operational.

Read review · uploaded white paper: Advancing Indigenous Foundation Models