
Pieter Bruegel the Elder, *The Tower of Babel*, 1563. Oil on panel. Kunsthistorisches Museum, Vienna. A visual reminder that complex systems depend on shared understanding of the work and responsibility each participant carries. Image: Google Art Project, via Wikimedia Commons; public domain.
Suppose an organization purchases an AI assistant to help employees understand company policies. The AI supplier provides the application, and the context (e.g., policies) already exists in customer policy repositories in various locations. The service architecture sounds straightforward until someone asks whether the assistant can distinguish between documents available to all employees and those restricted to managers.
Other questions like this arise as the implementation moves forward. Who makes sure AI stops using an expired policy? What happens when someone connects AI to the human resources system so employees can act on its answers? How does the assistant differentiate a “thou shalt” statement in a FAQ, preserved email, or review note from an actual, approved policy? The purchase of the AI assistant now involves decisions or engineering related to identity, information quality, judgment, data labeling, and authority to change business records.
These questions give CISOs a useful entry into the AI sourcing conversation. Instead of a buy-versus-build binary analysis, stakeholders need to understand which responsibilities the enterprise will retain and whether it has the capabilities to manage them, across a spectrum of ownership options.
The groundwork for addressing nuanced purchasing decisions has been laid over the last 30 years. The adoption of cloud computing moved organizations from the in-house-versus-outsourcing decision to recognizing that there are several ways to divide the work of operating an information system. Purchasing an application and developing software on rented infrastructure, or renting parts of the infrastructure while owning the configuration that governs it, required different engineering, communication, and governance capabilities to some degree of the purchaser’s choosing. AI services present purchasers with this type of complex decision.
Organization 1: Returning to the policy assistant, the enterprise could purchase a finished application connected to an approved document collection. The supplier would operate much of the technology. Internal teams would still need to establish who can use it, what information it can retrieve, and whether its answers are acceptable.
Organization 2: Another organization might build an internal application while purchasing access to a model through an API. Its application would retrieve relevant policy passages and send them to the external model. The enterprise would control more of the information flow while assuming responsibility for application security, integrations, and testing. Both organizations have purchased AI services, but they have retained different amounts of work.
Organization 3: The enterprise could also host an externally developed model within its controlled infrastructure. Requirements concerning data movement or update timing might justify that choice. Someone would then need to manage capacity, protect model artifacts, maintain supporting software, and investigate failures. The promised control depends on the organization’s ability to operate the deployment.
Customization introduces further choices. Retrieving approved policies supplies information without necessarily changing the model itself. Instructions and tools shape how the system responds and what it can do. Fine-tuning changes the model’s learned parameters. An organization can combine these approaches with either an external model service or an internally hosted model.
Buying, hosting, adapting, and building can therefore coexist within one system. Describing the purchase alone tells the CISO relatively little about where information travels or who can authorize an action.
A useful way to make this concrete is to trace one employee request through the proposed architecture. Follow it from sign-in through document retrieval, model processing, and any resulting action. At each boundary, ask:
- What information passes through, and whose permissions govern access?
- Who operates this component, and who can change it?
- What evidence would help us investigate an incorrect answer or unauthorized action?
A data flow diagram can expose responsibilities that a product description leaves unclear. Those findings should inform supplier agreements, staffing, and acceptance criteria before the service becomes embedded in daily operations.
The CISO’s contribution is to help colleagues connect the desired governance capability with the work required to sustain it. The sourcing decision becomes more defensible when stakeholders can explain what they are relying on, who is accountable for it, and how they will recognize when it needs attention.
Further Reading for Decision Context:
- Arnold, U. (2000). New dimensions of outsourcing: A combination of transaction cost economics and the core competencies concept. European Journal of Purchasing & Supply Management, 6(1), 23–29. https://doi.org/10.1016/S0969-7012(99)00028-3
- Jurison, J. (2024). The Role of Risk and Return in Information Technology Outsourcing Decisions. Journal of Information Technology, 10(4), 239–247. https://doi.org/10.1177/026839629501000404
- MIT Sloan (2025, September 17). Buy, boost, or build? Choose your path to generative AI | MIT Sloan. https://mitsloan.mit.edu/ideas-made-to-matter/buy-boost-or-build-choose-your-path-to-generative-ai
- NIST: Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile — NIST AI 600-1.
- GV-6.1-004: contracts and service agreements addressing ownership, quality, security, and provenance.
- GV-6.1-009: acquisition assessments spanning embedded AI, APIs, libraries, and fine-tuned models, with ongoing monitoring.
- GV-6.2-003: ownership and rehearsal of incident response for third-party AI.
Further Reading for Instrumentation:
- Agent Skills. (n.d.). Agent skills overview. Retrieved October 2, 2026, from https://agentskills.io/home
- Anthropic. (n.d.). Claude for the financial industry: A practical deployment guide. https://www-cdn.anthropic.com/files/4zrzovbb/website/34783bca828d7fa331f515ced26f1c9232151b2c.pdf
- Fandi, A., Finney, A., Rust, A., Nwatu, C., Ugurlu, E., Pagano, J., Cooke, T., Gurnaney, V., & Devadiga, Y. (2026, September 30). Manifesto. GRC Engineering. https://grc.engineering/
- Hugging Face. (n.d.). Parameter-efficient fine-tuning. Retrieved October 2, 2026, from https://huggingface.co/docs/transformers/peft
- Yang, D. (2025). Lecture 11: Efficient adaptation [Lecture slides]. Stanford University. https://web.stanford.edu/class/cs224n/slides_w25/cs224n-2025-lecture11-adapatation.pdf
