Regulated industries know this pattern well: A new capability emerges. Teams spin up point solutions, each one solving a discrete problem. Before long, the organization is managing fifteen tools that were never designed to work together and spending more engineering time on integration than on meaningful outcomes. That is what happened with DevOps toolchains. And it is exactly what is starting to happen with agentic AI.
The slow cost of DIY platforms
When AI coding tools started delivering real productivity gains, the instinct for many organizations was to go deeper. A code assistant here. An internal AI gateway there. A few open-source models, some custom orchestration, and suddenly the team is calling it a platform.
Also read: From Firefighting to Foresight: What Agentic AI Needs to Actually Work in Enterprise IT
There’s a reason this happens. Technology teams are wired to build, and that instinct isn’t wrong. Building is how engineers learn, how teams develop expertise, and how genuinely novel problems get solved. The same DIY energy that shaped the early DevOps era produced some remarkable tools and practices. But divergent experimentation rarely serves the broader organization. Organizations don’t want some people to be AI-enabled. They want everyone to be AI-enabled, consistently, in a way that’s governable and scalable. That tension drives every build vs. buy conversation right now.
Before going further, consider what you’re actually deciding.
Build means assembling agentic frameworks, orchestration layers, custom governance, and the underlying infrastructure needed to run it all, including the compute, storage, databases, and networking. The organization becomes the platform vendor.
Buy means adopting a platform that already unifies models, tools, orchestration, and governance across the SDLC. The organization becomes the platform consumer.
That distinction matters enormously in a regulated environment.
The real complexity is in the orchestration layer
What makes agentic AI different from earlier generations of tooling isn’t the model, but the orchestration sitting in front of it. The most important piece of any modern AI system is increasingly the agentic framework: the logic that decides which tools to invoke, in what sequence, with what guardrails, and with what accountability trail.
This is where the current wave of fragmentation is taking hold. Teams are installing their own agentic frameworks and coding tools, each making rational choices in isolation. But those choices accumulate over time. Every independently adopted framework creates a new integration surface, a new governance gap, and a new silo that the broader organization has to either absorb or work around.
Building an internal agentic AI platform in banking or insurance demands a multi-year orchestration engineering commitment with a regulatory surface area that most organizations underestimate:
Start with agentic framework management. Selection, integration, drift monitoring across agent behaviors, and deprecation are ongoing obligations with no off switch. This is followed by security hardening. Agents touching code and infrastructure must meet obligations well beyond a standard SaaS integration, including prompt injection defenses, sandboxing, SIEM and DLP integration, and red-team testing.
Under frameworks like DORA and the EU AI Act, an internal AI system functions as a regulated system, meaning the organization defines the risk classification, maintains the documentation, and produces audit evidence for the life of the system. Every agent embedded in the SDLC also creates a mini-product that teams must maintain across tool versions, framework changes, and org restructures.
Beyond those obligations sits the cost that rarely makes it into initial analyses. Every engineer building the platform is unavailable to modernize a legacy pipeline, remediate security debt, or accelerate a critical delivery program.
Learning from the DevOps era
The DevOps era offers a useful reference point. Teams didn’t set out to build fragmented toolchains; they made rational, incremental decisions. A better CI tool here. A preferred SCM there. A security scanner bolted on. A separate secrets manager. A different deployment orchestrator. Each decision made sense in isolation, but collectively, they created sprawl. Integration burdens, inconsistent governance, duplicated efforts, and no single view of what was happening across the SDLC.
The industry spent the better part of a decade consolidating around platforms precisely because that sprawl was expensive and hard to audit. Agentic AI is following the same arc. Organizations that make a platform decision early, rather than a series of point decisions, will compress years of catch-up into months.
Three questions to guide your decision
Rather than a generic build vs. buy debate, anchor on three questions.
Is the requirement truly unique? Build is defensible when the organization has workflows that no vendor supports, deployment patterns no platform can meet, and a genuine appetite to fund platform engineering as an enduring capability. Modern platforms, however, increasingly meet regulated organizations where they are, supporting cloud-hosted, self-managed, and dedicated single-tenant deployments, to narrow the gap between platform convenience and enterprise control requirements. For goals like faster code review, pipeline migration, security triage, or test automation, platforms are already delivering results for peer organizations.
How much regulatory surface area can the organization realistically own? Building makes the organization the system owner under ICT risk frameworks, the AI provider under emerging AI regulations, and the entity accountable for model behavior, documentation, and monitoring. Buying doesn’t eliminate regulatory responsibility, but it offloads platform-level obligations to a vendor whose business depends on getting them right, freeing compliance cycles for how AI is used rather than how it is built.
What is the time horizon? If the board expects demonstrable AI value across multiple teams within 12–24 months, a multi-year internal build is misaligned with those expectations from day one.
The numbers reflect this gap. For a regulated organization of roughly 200 developers, an internal build on a cloud AI foundation typically runs approximately $1.4M in year one, covering engineering labor, infrastructure, integration, security, and compliance, with 6–12 months before anything is production-ready and 2–3 dedicated FTEs required to keep it stable. Time to first real use case: 12–18 months, conservatively.
A purpose-built agentic AI platform runs approximately $410K–$460K for the same population, with initial deployment in days and early productivity gains of 15–25% (based on previous implementations) once agents are embedded in everyday workflows. Time to first use case: weeks, not years. That gap represents the difference between delivering AI ROI this fiscal year and explaining to the board why the organization is still building infrastructure.
What an integrated platform actually provides
The right platform solves four distinct problems that DIY approaches consistently struggle to address.
Model and tool agnosticism. The agentic AI landscape is evolving too quickly to bet on a single model or framework. A platform that supports any backend model and integrates cleanly with existing coding tools gives organizations freedom of choice without sacrificing coherence. The platform becomes the governance layer, not a bottleneck to adoption.
Trusted, deterministic guardrails around non-deterministic agents. Agentic systems are inherently probabilistic. Organizations can embed them within deterministic workflows that enforce code review, security scanning, and compliance checks before AI-generated output reaches production. The agents accelerate, while the platform ensures accountability.
Customization within governance. Most users can access agents through a shared catalog, getting immediate value within a governed environment. Power users can tailor agents to their specific context by adjusting system prompts and parameters, without writing a line of code. Teams with genuinely differentiated use cases can develop custom agent flows and publish them to the catalog, turning internal work into organizational capability.
AI enablement across the full organization. Developer productivity is the entry point, but it’s rarely the ceiling. The platform can serve project managers, infrastructure engineers, testers, security professionals, and compliance teams, each with agents tuned to their workflows, all operating within the same governance layer.
Where customization belongs in the architecture
Customization is a legitimate requirement in regulated industries. The goal is to identify where it’s most necessary, not to take it off the table. Intelligent orchestration produces coherence and flexibility, not uniformity. Everyone operates within the same governance layer, with flexibility that scales to need.
The DevOps consolidation applies directly. The real cost was tool decisions that accumulated faster than organizations could govern them, not the tools themselves. Agentic AI deserves the same discipline.
The article has been written by Bryan Ross, Field CTO, GitLab















