
The Build-vs-Buy Line Just Moved — And Almost Nobody's Pricing the Run Cost

Somewhere in a procurement meeting this year, someone pulled up Cursor or Codex, pointed at a SaaS quote, and asked: "why are we paying for this when an agent could just build it?" According to McKinsey, that conversation is no longer rare. It's happening at roughly a third of companies.
The number that's turning heads
McKinsey's The State of AI in 2026: On the Road to ROI, published in August and based on 1,719 responses across 97 countries collected between May and June, found that 32% of organizations have decided against buying an off-the-shelf software product because they could build the functionality themselves with AI-powered coding agents. That's not a fringe behavior anymore — it's a mainstream procurement decision.
The number isn't evenly spread. Among the small slice of "high performers" — companies that attribute at least 5% of EBIT to AI — nearly half are skipping software purchases in favor of building. Large enterprises (>$1B revenue) are scaling agents in production functions at 40%, up from 27% a year earlier. By industry, tech leads at 41%, with healthcare payers/providers (39%) and professional services and energy (38%) close behind.
Why this is happening right now
This shift tracks almost exactly with how fast the underlying agents have gotten better at real engineering work, not just autocomplete. OpenAI's GPT-6 Astra, released this month, is explicitly positioned around coding, computer use, and multi-step professional tasks — the model reports 57.9% on Terminal-Bench 4.0 and 74.1% on DeepSWE v1.1, and OpenAI cites 1.9x faster task completion versus GPT-5.6 Sol on the Mind2Web benchmark. In Codex specifically, Astra can keep notes across context windows and search earlier sessions for requirements or test results it saw days ago — the kind of persistent working memory that used to be the hard part of letting an agent run unsupervised on a real codebase.
Put simply: the gap between "agent that writes a plausible function" and "agent that can be handed a vague internal tool request and come back with something that runs" has narrowed a lot in the last twelve months. That's exactly the gap that used to justify buying instead of building.
The part the survey doesn't price in
Here's the catch: McKinsey's 32% measures a purchase decision at a single point in time — the moment someone decided not to sign a SaaS contract. It says nothing about what happens eighteen months later, when that internally-built tool needs a security patch, a SOC 2 audit, an upgrade to a new auth provider, or a rewrite because the one engineer who understood the agent's output left the company.
That's not a hypothetical risk category. It's the entire reason software vendors exist: someone has to own the thing for its whole life, not just the first commit. An agent can generate a working internal dashboard in an afternoon. It's much less reliable at:
Reasoning about the security implications of a change six months after the original context is gone
Making the kind of architecture call that trades short-term speed for long-term maintainability
Knowing when NOT to ship — when a feature request is actually a symptom of a bad data model upstream
Carrying institutional judgment about compliance, contracts, and what "done" means for this specific business
This is exactly the blind spot September's coding-agent security roundups have been flagging — default CI/CD configurations in agent-generated pipelines reaching remote code execution, and OWASP adding a dedicated risk list for autonomous coding "skills." Speed of generation and soundness of what gets generated are two different curves, and only one of them is improving as fast as the demos suggest.
Building software with an agent is cheap. Owning software — patching it, securing it, and being able to explain why it works — is exactly as expensive as it always was.
What this actually means if you're the one deciding
The honest read of the McKinsey data isn't "stop buying software" or "agents can't be trusted." It's that the build-vs-buy calculus has genuinely shifted for a specific category: internal tools, workflow glue, and narrow line-of-business apps that used to cost $30–150k/year in SaaS fees for something 80% of teams only used 20% of. For that category, an agent plus a competent engineer reviewing its output is now a legitimate default, not a risky experiment.
It hasn't shifted nearly as much for anything customer-facing, security-sensitive, or load-bearing for revenue — the stuff where the cost of being wrong isn't "rewrite it next quarter" but "breach disclosure" or "the product that makes the company money goes down." That's still where deep engineering judgment — knowing which 20% of an agent's output to keep, which to rewrite, and which requirement it quietly missed — is worth more than ever, precisely because everyone else is shipping agent output faster and less carefully.
The teams getting real leverage out of this moment aren't the ones asking "buy or build?" as a binary. They're the ones asking a sharper question: for this specific piece of software, is the multi-year cost of ownership lower with an agent-assisted internal build, supervised by someone who can catch what the agent can't reason about — or with a vendor whose whole job is to own that risk for you? Increasingly, for internal tools, the answer is build. For anything that touches customers or money, the answer is still: build it carefully, with a human who understands the whole system, or don't build it in-house at all.
Sources
McKinsey — The state of AI in 2026: On the road to ROI (PDF)
Digital Applied — A Third of Companies Skipped Buying Software and Built It
THE D*AI*LY BRIEF — A Third Skipped a SaaS Buy. Now Price the Run Cost.
The New Stack — OpenAI launches GPT-6 Astra and says welcome to the "AGI era"
Adversa AI — Top AI coding agent security resources, September 2026


The 60/20 Gap: What Anthropic's 2026 Coding Report Says About AI Delegation
