
Build, Buy, or Steward
Build versus buy misses the question that usually causes trouble later: who keeps the system secure, current, documented, and portable?
Buy when an enterprise product does the job and its rules fit the data. Build only when a distinct requirement justifies the cost and the office can maintain the result. Use a stewarded model when the family needs a tailored, portable system but does not want to staff a full AI team.
Choose who owns the work after launch.
The model demo is the easy part. Data ownership, integrations, permissions, review, maintenance, staffing, and exit last much longer.
Buying makes sense when the work is common and bounded. A custom build fits unusual data, workflow, or location requirements, provided someone can maintain it. Stewardship sits between them: the family owns a tailored system and an outside team helps keep it running.
Three paths, three different burdens.
| Decision factor | Buy | Build | Steward |
|---|---|---|---|
| Time to initial use | Usually shortest. | Usually longest. | Between the two; begin with a bounded deployment. |
| Customization | Within the product’s controls and integrations. | Highest potential flexibility. | Tailored architecture with a controlled scope. |
| Internal burden | Administration, policy, vendor oversight, and user support. | Architecture, engineering, security, evaluations, support, and continuity. | Shared duties documented between office and steward. |
| Vendor dependence | Concentrated in the product. | Can shift to key developers, cloud services, and model providers. | Reduced through portability requirements and documented handoff. |
| Best fit | Common, low-to-moderate risk workflows. | Distinctive needs plus durable internal capability. | Sensitive or integrated workflows where family control matters but a full internal AI team is not practical. |
Buy unless a real requirement forces custom work.
Custom work should solve a specific problem. Prestige, a general concern about privacy, or the desire to “own a model” does not justify the extra upkeep.
Buying is usually sufficient when:
- The work uses non-sensitive or well-classified information.
- The required retention, identity, and admin controls exist in the product.
- No privileged connection to core systems is needed.
- Outputs are reviewed before they influence a material decision.
- The office accepts the provider’s roadmap and exit terms.
Custom or stewarded architecture earns consideration when:
- Information must remain inside a defined technical or jurisdictional boundary.
- Permissions must reflect trusts, entities, generations, advisers, and temporary duties.
- The system needs governed access across several family-controlled sources.
- Agents will interact with consequential workflows.
- Model, provider, and integration portability are explicit requirements.
Custom does not automatically mean independent.
Ask who owns the data map, code or settings, credentials, infrastructure accounts, tests, backups, and handoff notes. A custom interface can still leave the family tied to one developer.
Plan for year two before launch day.
- Maintain the data-flow and dependency map.
- Review access, vendors, models, and integrations when they change.
- Run a fixed evaluation set before production updates.
- Monitor incidents, vulnerabilities, and consequential agent actions.
- Test backup, export, rollback, and provider exit.
- Document decisions for the family, advisers, and successors.
PwC describes family-office adoption in stages, from early enablement through broader use. That progression requires someone to take on more operating work as the system grows. Citi also treats build, buy, and outsourcing as practical choices rather than assuming one default.
Use the ChatGPT Enterprise comparison to judge a specific buy option. Use the private AI architecture guide to define the controls a tailored environment would need.
Questions to settle before choosing an operating model.
Should a family office build its own AI model?
Usually not as a first step. Most offices gain more from governing data, retrieval, permissions, integrations, and model choice than from training a proprietary base model.
What does AI stewardship mean?
It means someone remains responsible for the system after launch: updates, security, tests, documentation, backups, and the ability to change providers.
Is buying enterprise AI less secure than building?
Not necessarily. A well-governed enterprise product can be safer than a poorly maintained custom system. Compare the required controls, data flows, operating capability, and consequences.
What internal staff does a custom system require?
Name owners for the business work, technology, security, legal or privacy review, and output review. Outside specialists can do much of the work, but the office still needs a person accountable for each part.
How should a family office test vendor independence?
Run a documented export, identify replacement dependencies, confirm credential and account ownership, restore from backup, and estimate how the priority workflow would continue without the provider.
Where these claims come from.
- Citi, “AI in the Family Office,” May 11, 2026
- PwC, “How AI is reshaping the modern family office,” June 8, 2026
- NIST, AI Risk Management Framework
Published 2026-07-12. Product terms and legal duties change. Check them against the family office’s current facts before acting.
Compare the other decisions
Still choosing between software and custom work?
We will separate the requirements that matter from the complexity you can avoid.
Request a private briefing