Services · 15 ways across one gap

All services

Work · proof, not promises

All case studies

Insights · street talk, written down

Magazine

Company · AI in production since 2011

About Voidgap

Build · AI Strategy · AI Implementation · AI Governance

Buy the seat,
or build
the stack?

Bought

An enterprise assistant: ChatGPT Enterprise, Microsoft 365 Copilot, Claude for Work and the like. A product per seat, run by the vendor.

Built

Your own assistant: a model through an API or open weights, your retrieval, your interface, in your cloud or data centre.

01 · Side by side

A product,
or a system.

The category first, then the three products we are asked about most, in their vendors’ own words. No prices: they change too often, and your volume decides.

Bought vs. Built
DimensionBoughtBuilt
What you getA finished product: chat, files, connectors, admin console, updatesExactly what you build: interface, workflows, tools, nothing more
Data handlingThe vendor’s terms. All three named here state they don’t train on business data by default. Retention per plan and admin settings.Your choice of model provider and region, or open weights on your own hardware. Retention is whatever you implement.
Where it runsVendor regions. Europe is offered for some plans and some data; check which data stays where.Where you deploy it: your cloud region, your data centre, on-premises
IntegrationThe vendor’s connectors for common tools; your own systems through custom connectors where supportedAny system you can reach, with your permissions and your business rules
ControlThe admin settings the vendor offers. Model, system prompt and release cycle are the vendor’s.Everything: model choice, prompts, guardrails, versions, rollbacks
Cost modelPer seat and month. Predictable, and paid whether a seat is used or not.Build cost upfront, then usage: tokens or hardware, plus operation and maintenance
Time to valueDays to weeks: procurement, SSO, trainingWeeks to months for the first production version
Lock-inChats, custom assistants and connectors live in the vendor’s formatYour code, your data. The model provider can be swapped if you designed for it.
ComplianceThe vendor supplies the DPA, certificates and documentation. You still decide what goes in and train your people.You own the chain: contract with the model provider, security, logging, documentation, transparency
Who operates itThe vendor. Your IT manages seats and settings.You, or someone you pay: monitoring, evals, updates, on-call

The bought side, checked · vendor pages, September 2026

Not a ranking, and not complete. Plans, regions and terms change; the linked page is the truth, this is a snapshot.

ChatGPT EnterpriseOpenAI
  • No training on business data by default
  • SAML SSO, SCIM, role-based access, Enterprise Key Management
  • Data residency in Europe (EEA and Switzerland) for new Enterprise and Edu workspaces, with inference residency
  • SOC 2 Type 2; ISO/IEC 27001, 27017, 27018, 27701

openai.com/enterprise-privacy ↗openai.com/business-data ↗

Microsoft 365 CopilotMicrosoft
  • Prompts, responses and data accessed through Microsoft Graph not used to train foundation models
  • Shows only data the user already has at least view permission for
  • EU traffic stays in the EU Data Boundary. Models provided by Anthropic as a subprocessor are currently excluded from it
  • Web search queries go to Bing, governed by a privacy setting

learn.microsoft.com · Copilot privacy ↗

Claude for WorkAnthropic
  • Inputs and outputs of commercial products not used for training by default; feedback you submit may be
  • Enterprise plan: SCIM, audit logs, custom data retention, compliance API, customer-managed encryption keys
  • Processing location can be chosen, Europe included; stored data is kept in the US

privacy.claude.com · training ↗privacy.claude.com · servers ↗

02 · When to pick which

Pick by who
uses it.

The product decision follows from the user and the workflow, not from a feature list.

Buy when

  1. 01
    Everyone needs help with writing, summarising and research, starting next month

    General productivity is what these products are built for.

  2. 02
    Your work already lives in one suite, like Microsoft 365

    The integration exists. Building it again rarely pays.

  3. 03
    Nobody on your side can run an AI system

    Someone has to operate what you build. With a product, that is the vendor.

  4. 04
    You want to learn what people actually use AI for

    A few months of seats is cheap research before you build anything.

Build when

  1. 01
    The assistant has to act in your ERP, CRM or ticket system, with your rules

    Deep integration and fine-grained permissions are the reason to build.

  2. 02
    No data may leave your infrastructure, not even for a second

    Only a build lets you control every hop.

  3. 03
    Customers, not employees, will use it

    Enterprise seats are for your staff. A customer-facing assistant is a product you build, and label as an AI (Art. 50 AI Act).

  4. 04
    Many users, each with one narrow task

    Usage-based can beat a seat for everyone. Do the maths with real volumes.

And Often both: seats for general work, and a build for the one workflow that matters.

03 · Decide

Five questions,
one lean.

The lean moves while you answer. The recommendation appears when all five are in.

01Who will use it?

02Where does it need to work?

03What do your data rules say?

Ask your data protection and security people, not the vendor’s slides.

04Who runs it after launch?

05Should it differ from what everyone else has?

04 · Together

Most teams end up
with both.

Bought and built are not rivals for long. Five things that make the mix work.

  1. Seats for everyone, a build for the coreBoughtGeneral writing, research, summariesBuiltThe workflow with your systems and your rulescommon
  2. Bring your systems to the bought assistantBoughtSeveral products accept custom connectors, some through MCPBuiltYou build and secure the connector, with least privilege and an audit trailcommon
  3. One governance for bothBoughtApproved-tools list, AI policy, what may go inBuiltThe same policy, plus owners, logs and release rulesalways
  4. One eval set for bothBoughtTest it with your real questions before the rolloutBuiltRun the same set in CI on every changealways
  5. An exit planBoughtKnow how to export chats and custom assistants, and in which formatBuiltKeep the model behind an interface, so you can switch providerplan it

Always: needed in every setup. Common: what we see in production. Plan it: cheap on day one, expensive on day 500.

05 · Questions

Asked by
procurement.

Is ChatGPT Enterprise, or Copilot, GDPR-compliant?

A product can’t be compliant on its own; your use of it can be. Vendors offer a data processing agreement. You still need a legal basis, an entry in your record of processing, and possibly a DPIA for what you put in.

Do these vendors train on our data?

OpenAI, Microsoft and Anthropic each state that business data isn’t used to train their models by default (checked September 2026, links below). Read the exceptions: feedback you submit, for example, may be used.

Is building our own cheaper?

Sometimes per use, rarely in total at the start: building, hosting, evals and operation add up. Compare with your real number of users and real usage, not with a demo.

Can we switch later?

From bought to built, yes: the usage from the seats tells you what to build. From one model to another, yes, if the model sits behind an interface you control.

What does the EU AI Act ask of each?

Using a bought assistant makes you a deployer: AI literacy measures for your staff (Art. 4). Building one and offering it under your name makes you a provider; if people talk to it, it must say it is an AI (Art. 50).

What about shadow AI?

If you don’t offer a sanctioned assistant, people use private accounts with company data. A bought assistant with a clear policy is often the fastest fix.

Bought, built or both

Start with
the workflow.

Not with the product. Tell us the one workflow that matters; the rest of the decision follows from it.