Skip to main content
Vantaige

Buy, Don’t Build - Until Receipts Are Mandatory (2026): Menlo’s 76% Purchased Flip and EU AI Act Article 50

A
Aymen B
18 min read
Buy, Don’t Build  -  Until Receipts Are Mandatory (2026): Menlo’s 76% Purchased Flip and EU AI Act Article 50

# Buy, Don’t Build - Until Receipts Are Mandatory (2026): Menlo’s 76% Purchased Flip and EU AI Act Article 50

You are not choosing “innovation culture” versus “boring SaaS.” You are choosing who owns the receipts when a regulator, a customer, or your own counsel asks how synthetic content was labeled, who was told they were talking to a bot, and which system produced the deepfake that hit a public channel.

As of 2 September 2026, two clocks have already collided. Menlo Ventures’ late-2025 enterprise survey showed buyers flipping hard to purchased GenAI. The EU AI Act’s Article 50 transparency obligations became enforceable on 2 August 2026, with a marking/detection grace for older systems through 2 December 2026. Build-it-yourself stacks that cannot produce machine-readable provenance are no longer a clever shortcut. They are a compliance liability with a price tag measured in fines, not vanity ARR.

This is operator math for mid-market buyers deploying copilots, agents, and content pipelines into (or exporting into) the EU. It is not legal advice. Concrete numbers get quoted; adjectives do not. Stats below map to /workspace/vantaige-ai-market-research-2026.md (compiled 2026-09-02) unless labeled as method/illustration.

Table of contents

  1. 1. TL;DR

  2. 2. The buy flip in one table (Menlo)

  3. 3. Why “build” lost the enterprise vote

  4. 4. PLG, shadow AI, and the 27% problem

  5. 5. What Article 50 actually requires (buyer cut)

  6. 6. Dates, grace, fines, and extra-territorial reach

  7. 7. KPMG budgets: use the number, don’t abuse it

  8. 8. Mid-market compliance + procurement checklist

  9. 9. Buy / build / hybrid decision matrix

  10. 10. Watch out / when NOT to buy (or build)

  11. 11. 90-day operator plan

  12. 12. FAQ

  13. 13. References

  14. 14. Related from Vantaige

TL;DR {#tldr}

  • Menlo (Dec 2025 survey, 495 U.S. enterprise AI decision-makers): GenAI solutions flipped to 76% purchased (from 53% purchased / 47% built in 2024). AI deals convert to production at 47% vs 25% for traditional SaaS. PLG is 27% of AI app spend (vs ~7% traditional software); with shadow AI, Menlo flags maybe ~40%.

  • EU AI Act Article 50: transparency obligations apply from 2 August 2026. Systems placed on the market before that date get until 2 December 2026 for Art 50(2) marking/detection only. Max fines: up to €15M or 3% worldwide turnover (SME proportionality). Non-EU providers can be in scope if output is used in the EU.

  • Buyer duties that matter: disclose AI interaction when not obvious; machine-readable marking/detectability of synthetic media/text (providers); deepfake disclosure and public-interest AI text labeling (deployers); inform people exposed to emotion recognition / biometric categorisation.

  • KPMG Global AI Pulse: planned AI investment weighted averages US$186M (Q1 2026) and US$188M (Q2 2026). That figure is large-enterprise-weighted (~¾ of respondents from orgs >$1B revenue). Do not treat it as a mid-market average.

  • Practical rule for mid-market: default to buy for copilots, content pipelines, and customer-facing agents until your vendor (or your build) can show Art 50-ready disclosures, marking, and audit trails. Build only where the workflow is proprietary *and* you can staff the receipt stack.

  • MIT/MLQ (2025) rhyme: externally sourced tools succeed more often (reported ~67% success vs much lower for internal builds) - consistent with Menlo’s buy flip, not a license to skip governance.

The buy flip in one table (Menlo) {#buy-flip}

Source: Menlo Ventures - *2025: The State of Generative AI in the Enterprise* (Dec 9, 2025); survey Nov 7-25, 2025, n=495 U.S. enterprise AI decision-makers; bottoms-up market model. Scope excludes chips, hyperscaler inference/serving, and AI bolted into non-AI software. PDF: https://menlovc.com/wp-content/uploads/2025/12/menlo_ventures_enterprise_ai_report-2025-123125.pdf

Metric2025 (Menlo)Prior / contrastWhy it matters for buyers
Purchased vs built76% purchased53% / 47% purchased/built in 2024Default posture flipped in one year
AI deal → production47%Traditional SaaS 25%Purchased GenAI is converting faster than classic SaaS
PLG share of AI app spend27%Traditional software ~7%; with shadow AI maybe ~40%Procurement must see what employees already bought
Startup share at app layer63% revenue shareWas 36%Incumbent suite alone is not the whole shortlist
“True” agents (plan→act→observe→adapt)16% enterprise / 27% startup deploymentsMost “agents” are still copilots/workflowsDo not buy agent theater
Enterprise GenAI spend (market)$37B (2025)$11.5B restated 2024; $1.7B 2023Spend boom ≠ your unit budget

Watch out: Menlo’s $37B is a U.S. enterprise GenAI market bottoms-up number, not your company’s AI budget and not Gartner’s full-stack AI procurement spend. Never blend Menlo with Gartner/IDC/Stanford into one “AI market” claim.

Why “build” lost the enterprise vote {#why-buy}

In 2024, build felt rational: APIs were new, vendors were thin, and every platform team wanted a “strategic LLM layer.” By late 2025, three pressures flipped the vote.

1. Time-to-production math. Menlo’s 47% AI deal conversion to production versus 25% for traditional SaaS is the cleanest operator signal in the report. Purchased products arrive with connectors, eval harnesses, admin, and (increasingly) compliance paperwork. Internal builds burn calendar on glue code, prompt sprawl, and “we’ll add logging later.”

2. External tools win more often on impact. MIT Media Lab Project NANDA / MLQ’s *GenAI Divide* report (2025) frames the infamous 95% carefully: organizations getting zero measurable P&L return from GenAI pilots - not “AI doesn’t work.” Inside that story sits a build/buy split: externally sourced tools succeed more often (reported ~67% success vs much lower for internal builds). Read the primary PDF for exact wording before you paste it into a board deck: https://mlq.ai/media/quarterly_decks/v0.1_State_of_AI_in_Business_2025_Report.pdf

3. Regulation raised the cost of undocumented generation. Article 50 does not ban GenAI. It forces transparency receipts. Homegrown content pipelines that spit unmarked synthetic audio/image/video/text into EU-facing surfaces now carry fine risk. Buying a provider that already ships machine-readable marking and deployer disclosure templates is often cheaper than staffing a watermarking program yourself.

None of this means “never build.” It means build is a product decision with a compliance backlog, not a weekend hackathon.

PLG, shadow AI, and the 27% problem {#plg-shadow}

Menlo’s GTM cut is the procurement story boards miss.

  • PLG is 27% of AI app spend versus roughly 7% for traditional software.

  • With shadow AI, Menlo suggests the effective share may approach ~40%.

  • Menlo footnotes (via NBER WP 34255, Sep 2025) that roughly 27% of ChatGPT Plus usage is work-related - personal seats doing company work.

Translate that into a mid-market week:

  1. 1. Marketing buys Midjourney/Runway seats on a card.

  2. 2. Sales pastes customer emails into a consumer chatbot.

  3. 3. Support trials a PLG agent that “just works.”

  4. 4. Legal discovers none of it has Art 50-ready labeling or a DPA.

You did not “fail to innovate.” You failed to inventory. The buy flip at 76% purchased is partly the market catching up to what employees already purchased - and pulling it into contracts that can survive an audit.

Shadow AI is also why “we’ll build an internal GPT” often fails: the competing alternative is a polished PLG product with weekly model upgrades. Your build has to beat that *and* carry transparency obligations. Most mid-market platform teams cannot do both in one quarter.

What Article 50 actually requires (buyer cut) {#art50}

Primary: European Commission FAQ - Transparency obligations under Article 50 AI Act: https://digital-strategy.ec.europa.eu/en/faqs/transparency-obligations-under-article-50-ai-act

Guidelines library: https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems

Buyer-relevant obligations from the research dump (confirm against the FAQ/guidelines before you sign anything):

ActorObligation (plain language)Typical mid-market surface
Providers of systems interacting with peopleInform users they are interacting with AI (unless obvious)Support chatbots, voice agents, website assistants
Providers of generative systemsMachine-readable marking / detectability of synthetic audio, image, video, text (Art 50(2))Marketing content studios, product image gens, synthetic voice
DeployersDisclose deepfakes; label AI text on public-interest matters without human editorial controlSocial posts, newsroom-like blogs, political/IR content
Deployers / providers (emotion / biometric categorisation)Inform exposed personsHR screening tools, in-store analytics (high scrutiny - often avoid)

Extra-territorial note: Non-EU providers can be in scope if output is used in the EU. If your U.S. SaaS generates customer-facing copy for EU users, “we’re not headquartered in Brussels” is not a strategy.

This article is not a substitute for counsel. Art 50 sits inside a larger AI Act risk-classification regime. Your checklist below is for transparency + procurement hygiene, not full high-risk system conformity assessment.

Dates, grace, fines, and extra-territorial reach {#dates-fines}

ClockDateWhat it unlocks / closes
Art 50 applies2 August 2026Transparency obligations enforceable
Marking/detection graceUntil 2 December 2026Only for systems placed on market before 2 Aug 2026, and only for Art 50(2) marking/detection
Max fine bandUp to €15M or 3% worldwide turnoverSME proportionality applies - still existential for many mid-market firms
Today (this article)2 September 2026You are inside the enforceable window; grace for pre-Aug systems’ marking runs ~3 more months

Operator reading:

  • If you bought or built after 2 Aug 2026, do not lean on the grace narrative for Art 50(2).

  • If you have a pre-Aug generative system still unmarked, the grace is a finish-the-marking window, not a vacation from other Art 50 duties (interaction disclosure, deepfake rules, etc.).

  • Fine math at 3% turnover means a €40M-revenue company is staring at a theoretical €1.2M band before SME adjustments - enough to fund years of proper vendor diligence.

KPMG budgets: use the number, don’t abuse it {#kpmg}

Boards love a round budget number. Use this one carefully.

SourceFigurePopulation / caveat
KPMG Global AI Pulse Q1 2026 (press, Mar 31, 2026)Weighted avg planned AI investment next 12 months US$186M; 74% say AI remains top priority even in recession; ASPAC $245M / Americas $178M / EMEA $157MSenior leaders; ~¾ from orgs >$1B revenue; 20 countries - https://kpmg.com/xx/en/media/press-releases/2026/03/kpmg-global-ai-pulse-survey.html
KPMG Global AI Pulse Q2 2026Planned spend US$188M (steady); 76% say AI delivering meaningful value (+12 pts)https://assets.kpmg.com/content/dam/kpmgsites/xx/pdf/2026/06/global-ai-pulse-q2.pdf
Secondary TechTimes cutQuotes $186M with only 8% reporting tangible ROI in one Pulse framingPrefer KPMG primary PDFs/press

Hard rule (from the research file’s own non-claims): $186-188M is large-enterprise-weighted planned budget, not a mid-market average. If your CFO pastes “industry average $186M” into a Series C operating plan, you have created a fiction.

What mid-market operators should take instead:

  1. 1. Direction: planned spend stayed steady Q1→Q2 at the large-enterprise weighted mean ($186M → $188M).

  2. 2. Governance share: as value claims rise (76% “meaningful value” in Q2), expect compliance, audit, and procurement line items to grow inside the same envelope - not vanish.

  3. 3. Your method: build a bottoms-up sheet (seats × tools + API + implementation + compliance labor). Compare to peers in your revenue band, not to KPMG’s mega-cap mean.

McKinsey’s mid-2026 *State of AI* rhyme (n=1,719; 97 countries): 89% of orgs use AI in ≥1 function, but only 37% report any positive EBIT contribution and ~6% are “high performers.” Spending like a giant without workflow redesign is how you join the flat EBIT cohort.

Mid-market compliance + procurement checklist {#checklist}

Use this as a living RFP annex for copilots, agents, and content pipelines that touch the EU. Score each vendor 0 / 1 / 2 (missing / partial / evidenced). Kill anything that stays at 0 on rows marked blocker.

A. Inventory & scope (you, week 0)

#CheckBlocker?Pass evidence
A1List every GenAI surface: copilots, agents, image/video/voice, customer chat, internal RAGYesSpreadsheet with owner + data classes
A2Flag EU users / EU-deployed output / EU customers in scopeYesGeo + product map
A3Separate provider vs deployer roles per systemYesOne-pager counsel-reviewed
A4Shadow AI discovery (expense, SSO, browser, NDA interviews)NoPLG seat list; Menlo’s 27%/shadow framing as motivation

B. Article 50 transparency (vendor + you)

#CheckBlocker?Pass evidence
B1User-facing AI disclosure when interaction is not obviousYesScreenshot + config default ON for EU
B2Art 50(2) machine-readable marking / detectability for synthetic media/text the vendor generatesYes (if generative)Spec + sample files; grace plan if pre-Aug system
B3Deployer tooling for deepfake disclosure / public-interest AI text labelingYes (if you publish)Playbook + product hooks
B4Emotion recognition / biometric categorisation - inform or preferably do not buyYes if usedWritten “not in scope” or notice UX
B5Provenance retained for audit (who prompted, which model, when, outputs)Yes for customer-facingRetention policy + export

C. Contract & security

#CheckBlocker?Pass evidence
C1DPA / SCCs as needed; training-on-customer-data stance in writingYesSigned DPA
C2Subprocessors list + change noticeNoCurrent list dated
C3Indemnity language for IP / synthetic content claims (negotiate; don’t invent coverage)NoRedlines
C4EU data residency options labeled as optional vs required for your riskNoArchitecture note
C5Admin kill-switch / EU geo policyYes for chat agentsDemo

D. Evaluation math (anti-hype)

#CheckBlocker?Pass evidence
D1Workflow redesign owner named (McKinsey high performers ~75% redesigned vs ~25% others)NoRACI
D2Success metric ≠ “employees like the chatbot” (aim at cycle time, error rate, or $)YesBaseline + 90-day target
D3Agent washing test: does it plan→act→observe→adapt? (Menlo: only 16% enterprise true agents)NoDemo script
D4Build alternative TCO includes marking, disclosure UX, evals, on-call - not just GPUYes if build proposedSide-by-side sheet

Buy / build / hybrid decision matrix {#matrix}

SituationDefaultWhyReceipts you must still own
Horizontal copilots (writing, meeting notes, Office)BuyMenlo horizontal copilots alone were $7.2B of a $8.4B horizontal slice - category is productizedDisclosure UX; logging; data classes
Departmental coding assistantsBuy (seat or API)Coding was $4.0B / 55% of departmental AI in Menlo 2025; velocity claims are self-reported 15%+ - still buy before buildRepo permissions; secret scanning; evals
Customer-facing support / voice agents in EUBuy with Art 50 disclosure baked inInteraction disclosure is load-bearing; PLG shadow tools fail auditsTranscript retention; human handoff
Marketing synthetic image/video/audio for EUBuy marking-capable stack or pauseArt 50(2) marking/detectabilityAsset pipeline that preserves marks
Proprietary underwriting / pricing model with thin vendor fitHybridCore logic may justify build; wrap with purchased LLM gateway + compliance layerFull Art 50 stack on the wrapper
“Strategic internal LLM platform” with no unique workflowDon’tMIT/MLQ + Menlo both punish vanity buildsN/A - kill the program

Hybrid pattern that works: purchased foundation (model API or enterprise assistant) + thin proprietary orchestration + shared transparency service (watermarking, disclosure banners, audit export). Do not rebuild Claude/ChatGPT; rebuild the receipt rail.

Watch out / when NOT to buy (or build) {#when-not}

Watch out

  1. 1. Grace confusion - The 2 Dec 2026 date is not a blanket delay of Article 50. It is a limited Art 50(2) marking/detection grace for systems placed on the market before 2 Aug 2026.

  2. 2. $186M misuse - Quoting KPMG’s large-enterprise-weighted mean as “what companies like us spend” will get you laughed out of a diligence call - or worse, funded into waste.

  3. 3. Agent washing - Gartner (Jun 2025) predicted >40% of agentic AI projects canceled by end of 2027, citing costs, unclear value, and weak risk controls. Menlo’s 16% true-agent rate says most of what you are sold is not that architecture.

  4. 4. PLG without SSO - A 27% PLG spend share (and higher with shadow AI) means finance will discover tools before security does.

  5. 5. Provider vs deployer mix-ups - Buying an API does not erase deployer duties when *you* publish deepfakes or public-interest AI text.

  6. 6. EBIT theater - McKinsey’s 37% any-positive-EBIT and ~6% high-performer cuts are the antidote to vendor ROI slides.

When NOT to buy

  • The vendor cannot show Art 50 disclosure/marking evidence and your use is EU-facing generative or interactive.

  • You only need a personal assistant for 10 people - force-fitting an “enterprise AI platform” RFP is how mid-market teams burn a year.

  • The pitch is “fully autonomous agent” but the demo is a chatbot with tools and no observe/adapt loop.

When NOT to build

  • You cannot staff watermarking, disclosure UX, evals, and on-call for 12 months.

  • Your “moat” is a system prompt and a vector DB - that is not a moat under Art 50.

  • Leadership wants a platform “because strategy” with no workflow owner (see McKinsey redesign gap).

When NOT to wait

  • You are shipping EU-facing synthetic media now (Sep 2026) without a marking plan and hoping December is a vibe. It is not.

90-day operator plan {#plan}

Days 1-15 - Inventory. Complete checklist sections A-B on paper. Freeze new PLG cards without security review. Name a single Art 50 owner (often Legal + Eng shared RACI).

Days 16-45 - Shortlist. Run three vendors max through blocker rows. Require sample marked outputs and disclosure screenshots. Kill builds that lack a receipts budget.

Days 46-75 - Pilot with receipts on. Production-like EU flag, logging export, disclosure defaults ON. Measure the D2 success metric, not NPS cosplay.

Days 76-90 - Contract + kill list. Sign the winner; sunset shadow tools that duplicate it; document grace status for any pre-Aug generative system still being marked. Put the 2 Dec 2026 date on the engineering calendar with an owner.

Illustration only (not a research statistic): a 400-person B2B SaaS with EU customers might spend more calendar time on A1 inventory + B2 marking proof than on model bake-offs - and that is the correct order in mid-2026.

FAQ {#faq}

Does Article 50 ban generative AI in the EU?

No. It imposes transparency duties (disclosure, marking/detectability, deepfake and public-interest labeling, notices for certain biometric/emotion systems). Risk-tier rules elsewhere in the AI Act are separate. Read the Commission FAQ before you freeze product plans.

We are a U.S. company. Do we care?

If your output is used in the EU, extra-territorial reach can pull you in. “No Brussels entity” is not a complete defense. Map product surfaces that EU users see.

Is the grace period until 2 December 2026 a free pass?

No. It applies to Art 50(2) marking/detection for systems placed on the market before 2 August 2026. Other transparency duties and post-Aug systems do not get that story.

Should every mid-market company spend ~$186M on AI?

No. KPMG’s $186-188M planned average is large-enterprise-weighted. Build your own bottoms-up budget. Treating $186M as a mid-market norm is explicitly flagged as a non-claim in the research file behind this article.

Why did purchased GenAI jump to 76%?

Menlo’s survey shows the flip from a near even 53/47 buy/build split in 2024 to 76% purchased in 2025, alongside higher production conversion (47% vs 25% SaaS) and heavy PLG. Regulation raising the cost of undocumented generation reinforces the same direction - even though Menlo’s survey window precedes the Aug 2026 enforceability date.

Can we keep building internal tools?

Yes, when the workflow is proprietary and you fund the receipt stack (marking, disclosure, audit). Default to buy for commodity copilots and content pipelines. MIT/MLQ’s reported higher success for externally sourced tools is a prior, not destiny - but it matches Menlo’s buy flip.

What is “shadow AI” in one sentence?

Employees using personal or unmanaged AI tools for work - Menlo ties PLG/shadow dynamics to roughly 27% of AI app spend (and possibly ~40% with shadow), plus a NBER-cited signal that ~27% of ChatGPT Plus usage is work-related.

Are most enterprise “agents” real agents?

Per Menlo, only 16% of enterprise deployments meet a plan→act→observe→adapt bar (27% at startups). Budget accordingly.

References {#references}

Accessed September 2026. Stats aligned to Vantaige research dump compiled 2026-09-02.

  1. 1. Menlo Ventures - *2025: The State of Generative AI in the Enterprise* (Dec 9, 2025): https://menlovc.com/perspective/2025-the-state-of-generative-ai-in-the-enterprise/

  2. 2. Menlo PDF: https://menlovc.com/wp-content/uploads/2025/12/menlo_ventures_enterprise_ai_report-2025-123125.pdf

  3. 3. European Commission - Transparency obligations under Article 50 AI Act (FAQ): https://digital-strategy.ec.europa.eu/en/faqs/transparency-obligations-under-article-50-ai-act

  4. 4. European Commission - Guidelines on transparency obligations for providers and deployers: https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems

  5. 5. KPMG - Global AI Pulse Survey Q1 2026 press (Mar 31, 2026): https://kpmg.com/xx/en/media/press-releases/2026/03/kpmg-global-ai-pulse-survey.html

  6. 6. KPMG - Global AI Pulse Q2 2026 PDF: https://assets.kpmg.com/content/dam/kpmgsites/xx/pdf/2026/06/global-ai-pulse-q2.pdf

  7. 7. MIT Media Lab Project NANDA / MLQ - *The GenAI Divide: State of AI in Business 2025*: https://mlq.ai/media/quarterly_decks/v0.1_State_of_AI_in_Business_2025_Report.pdf

  8. 8. Gartner - Over 40% of agentic AI projects will be canceled by end of 2027 (Jun 25, 2025): https://www.gartner.com/en/newsroom/press-releases/2025-06-25-gartner-predicts-over-40-percent-of-agentic-ai-projects-will-be-canceled-by-end-of-2027

  9. 9. Reuters coverage of Gartner agentic cancel prediction: https://www.reuters.com/business/over-40-agentic-ai-projects-will-be-scrapped-by-2027-gartner-says-2025-06-25/

  10. 10. McKinsey / QuantumBlack *State of AI 2026* figures as summarized in Vantaige research (adoption 89%, EBIT 37%, high performers ~6%; survey May 4-Jun 8, 2026, n=1,719) - prefer McKinsey primary when publishing externally.

  11. 11. Vantaige internal compilation - AI Market Research Dump September 2026 (vantaige-ai-market-research-2026.md), Appendix rows M12, M25, M33-M37, M40, M51-M52, M54.

  • The Three AI Markets Problem (2026) - why you must not blend Gartner / IDC / Stanford / Menlo into one “AI market” number

  • The Agentic ROI Gap (2026) - Gartner’s >40% cancel prediction vs spend, with a cancel-risk scorecard

  • Coding Ate Enterprise AI (2026) - Menlo’s $4B coding slice and seat vs API math

  • GEO After the Rankings Divorce (2026) - citation-grade publishing when AI Overviews stop mirroring classic top-10 SEO

  • Glean vs Hebbia vs Perplexity Enterprise (2026) - buy the workflow, not the category mashup

---

One short email a week: the buy/build calls that aged well, the compliance dates that actually bite, and the budget myths (looking at you, $186M “average”) we refuse to launder. Subscribe at vantaige.io.

*Written as Aymen B for Vantaige.io - 2 September 2026. Operator guide for mid-market AI procurement and transparency hygiene - not legal advice, not investment advice. Re-check primary Commission, Menlo, and KPMG links before you sign or file.*

Get the best new AI tools and guides, weekly

One short email a week. The tools worth trying, the guides worth reading, nothing else.

No spam. Unsubscribe anytime.

A

Aymen B

Contributing writer at Vantaige, covering the AI tools ecosystem.