Buy, Don’t Build - Until Receipts Are Mandatory (2026): Menlo’s 76% Purchased Flip and EU AI Act Article 50

# Buy, Don’t Build - Until Receipts Are Mandatory (2026): Menlo’s 76% Purchased Flip and EU AI Act Article 50
You are not choosing “innovation culture” versus “boring SaaS.” You are choosing who owns the receipts when a regulator, a customer, or your own counsel asks how synthetic content was labeled, who was told they were talking to a bot, and which system produced the deepfake that hit a public channel.
As of 2 September 2026, two clocks have already collided. Menlo Ventures’ late-2025 enterprise survey showed buyers flipping hard to purchased GenAI. The EU AI Act’s Article 50 transparency obligations became enforceable on 2 August 2026, with a marking/detection grace for older systems through 2 December 2026. Build-it-yourself stacks that cannot produce machine-readable provenance are no longer a clever shortcut. They are a compliance liability with a price tag measured in fines, not vanity ARR.
This is operator math for mid-market buyers deploying copilots, agents, and content pipelines into (or exporting into) the EU. It is not legal advice. Concrete numbers get quoted; adjectives do not. Stats below map to /workspace/vantaige-ai-market-research-2026.md (compiled 2026-09-02) unless labeled as method/illustration.
Table of contents
1. TL;DR
12. FAQ
13. References
TL;DR {#tldr}
Menlo (Dec 2025 survey, 495 U.S. enterprise AI decision-makers): GenAI solutions flipped to 76% purchased (from 53% purchased / 47% built in 2024). AI deals convert to production at 47% vs 25% for traditional SaaS. PLG is 27% of AI app spend (vs ~7% traditional software); with shadow AI, Menlo flags maybe ~40%.
EU AI Act Article 50: transparency obligations apply from 2 August 2026. Systems placed on the market before that date get until 2 December 2026 for Art 50(2) marking/detection only. Max fines: up to €15M or 3% worldwide turnover (SME proportionality). Non-EU providers can be in scope if output is used in the EU.
Buyer duties that matter: disclose AI interaction when not obvious; machine-readable marking/detectability of synthetic media/text (providers); deepfake disclosure and public-interest AI text labeling (deployers); inform people exposed to emotion recognition / biometric categorisation.
KPMG Global AI Pulse: planned AI investment weighted averages US$186M (Q1 2026) and US$188M (Q2 2026). That figure is large-enterprise-weighted (~¾ of respondents from orgs >$1B revenue). Do not treat it as a mid-market average.
Practical rule for mid-market: default to buy for copilots, content pipelines, and customer-facing agents until your vendor (or your build) can show Art 50-ready disclosures, marking, and audit trails. Build only where the workflow is proprietary *and* you can staff the receipt stack.
MIT/MLQ (2025) rhyme: externally sourced tools succeed more often (reported ~67% success vs much lower for internal builds) - consistent with Menlo’s buy flip, not a license to skip governance.
The buy flip in one table (Menlo) {#buy-flip}
Source: Menlo Ventures - *2025: The State of Generative AI in the Enterprise* (Dec 9, 2025); survey Nov 7-25, 2025, n=495 U.S. enterprise AI decision-makers; bottoms-up market model. Scope excludes chips, hyperscaler inference/serving, and AI bolted into non-AI software. PDF: https://menlovc.com/wp-content/uploads/2025/12/menlo_ventures_enterprise_ai_report-2025-123125.pdf
| Metric | 2025 (Menlo) | Prior / contrast | Why it matters for buyers |
|---|---|---|---|
| Purchased vs built | 76% purchased | 53% / 47% purchased/built in 2024 | Default posture flipped in one year |
| AI deal → production | 47% | Traditional SaaS 25% | Purchased GenAI is converting faster than classic SaaS |
| PLG share of AI app spend | 27% | Traditional software ~7%; with shadow AI maybe ~40% | Procurement must see what employees already bought |
| Startup share at app layer | 63% revenue share | Was 36% | Incumbent suite alone is not the whole shortlist |
| “True” agents (plan→act→observe→adapt) | 16% enterprise / 27% startup deployments | Most “agents” are still copilots/workflows | Do not buy agent theater |
| Enterprise GenAI spend (market) | $37B (2025) | $11.5B restated 2024; $1.7B 2023 | Spend boom ≠ your unit budget |
Watch out: Menlo’s $37B is a U.S. enterprise GenAI market bottoms-up number, not your company’s AI budget and not Gartner’s full-stack AI procurement spend. Never blend Menlo with Gartner/IDC/Stanford into one “AI market” claim.
Why “build” lost the enterprise vote {#why-buy}
In 2024, build felt rational: APIs were new, vendors were thin, and every platform team wanted a “strategic LLM layer.” By late 2025, three pressures flipped the vote.
1. Time-to-production math. Menlo’s 47% AI deal conversion to production versus 25% for traditional SaaS is the cleanest operator signal in the report. Purchased products arrive with connectors, eval harnesses, admin, and (increasingly) compliance paperwork. Internal builds burn calendar on glue code, prompt sprawl, and “we’ll add logging later.”
2. External tools win more often on impact. MIT Media Lab Project NANDA / MLQ’s *GenAI Divide* report (2025) frames the infamous 95% carefully: organizations getting zero measurable P&L return from GenAI pilots - not “AI doesn’t work.” Inside that story sits a build/buy split: externally sourced tools succeed more often (reported ~67% success vs much lower for internal builds). Read the primary PDF for exact wording before you paste it into a board deck: https://mlq.ai/media/quarterly_decks/v0.1_State_of_AI_in_Business_2025_Report.pdf
3. Regulation raised the cost of undocumented generation. Article 50 does not ban GenAI. It forces transparency receipts. Homegrown content pipelines that spit unmarked synthetic audio/image/video/text into EU-facing surfaces now carry fine risk. Buying a provider that already ships machine-readable marking and deployer disclosure templates is often cheaper than staffing a watermarking program yourself.
None of this means “never build.” It means build is a product decision with a compliance backlog, not a weekend hackathon.
PLG, shadow AI, and the 27% problem {#plg-shadow}
Menlo’s GTM cut is the procurement story boards miss.
PLG is 27% of AI app spend versus roughly 7% for traditional software.
With shadow AI, Menlo suggests the effective share may approach ~40%.
Menlo footnotes (via NBER WP 34255, Sep 2025) that roughly 27% of ChatGPT Plus usage is work-related - personal seats doing company work.
Translate that into a mid-market week:
1. Marketing buys Midjourney/Runway seats on a card.
2. Sales pastes customer emails into a consumer chatbot.
3. Support trials a PLG agent that “just works.”
4. Legal discovers none of it has Art 50-ready labeling or a DPA.
You did not “fail to innovate.” You failed to inventory. The buy flip at 76% purchased is partly the market catching up to what employees already purchased - and pulling it into contracts that can survive an audit.
Shadow AI is also why “we’ll build an internal GPT” often fails: the competing alternative is a polished PLG product with weekly model upgrades. Your build has to beat that *and* carry transparency obligations. Most mid-market platform teams cannot do both in one quarter.
What Article 50 actually requires (buyer cut) {#art50}
Primary: European Commission FAQ - Transparency obligations under Article 50 AI Act: https://digital-strategy.ec.europa.eu/en/faqs/transparency-obligations-under-article-50-ai-act
Guidelines library: https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems
Buyer-relevant obligations from the research dump (confirm against the FAQ/guidelines before you sign anything):
| Actor | Obligation (plain language) | Typical mid-market surface |
|---|---|---|
| Providers of systems interacting with people | Inform users they are interacting with AI (unless obvious) | Support chatbots, voice agents, website assistants |
| Providers of generative systems | Machine-readable marking / detectability of synthetic audio, image, video, text (Art 50(2)) | Marketing content studios, product image gens, synthetic voice |
| Deployers | Disclose deepfakes; label AI text on public-interest matters without human editorial control | Social posts, newsroom-like blogs, political/IR content |
| Deployers / providers (emotion / biometric categorisation) | Inform exposed persons | HR screening tools, in-store analytics (high scrutiny - often avoid) |
Extra-territorial note: Non-EU providers can be in scope if output is used in the EU. If your U.S. SaaS generates customer-facing copy for EU users, “we’re not headquartered in Brussels” is not a strategy.
This article is not a substitute for counsel. Art 50 sits inside a larger AI Act risk-classification regime. Your checklist below is for transparency + procurement hygiene, not full high-risk system conformity assessment.
Dates, grace, fines, and extra-territorial reach {#dates-fines}
| Clock | Date | What it unlocks / closes |
|---|---|---|
| Art 50 applies | 2 August 2026 | Transparency obligations enforceable |
| Marking/detection grace | Until 2 December 2026 | Only for systems placed on market before 2 Aug 2026, and only for Art 50(2) marking/detection |
| Max fine band | Up to €15M or 3% worldwide turnover | SME proportionality applies - still existential for many mid-market firms |
| Today (this article) | 2 September 2026 | You are inside the enforceable window; grace for pre-Aug systems’ marking runs ~3 more months |
Operator reading:
If you bought or built after 2 Aug 2026, do not lean on the grace narrative for Art 50(2).
If you have a pre-Aug generative system still unmarked, the grace is a finish-the-marking window, not a vacation from other Art 50 duties (interaction disclosure, deepfake rules, etc.).
Fine math at 3% turnover means a €40M-revenue company is staring at a theoretical €1.2M band before SME adjustments - enough to fund years of proper vendor diligence.
KPMG budgets: use the number, don’t abuse it {#kpmg}
Boards love a round budget number. Use this one carefully.
| Source | Figure | Population / caveat |
|---|---|---|
| KPMG Global AI Pulse Q1 2026 (press, Mar 31, 2026) | Weighted avg planned AI investment next 12 months US$186M; 74% say AI remains top priority even in recession; ASPAC $245M / Americas $178M / EMEA $157M | Senior leaders; ~¾ from orgs >$1B revenue; 20 countries - https://kpmg.com/xx/en/media/press-releases/2026/03/kpmg-global-ai-pulse-survey.html |
| KPMG Global AI Pulse Q2 2026 | Planned spend US$188M (steady); 76% say AI delivering meaningful value (+12 pts) | https://assets.kpmg.com/content/dam/kpmgsites/xx/pdf/2026/06/global-ai-pulse-q2.pdf |
| Secondary TechTimes cut | Quotes $186M with only 8% reporting tangible ROI in one Pulse framing | Prefer KPMG primary PDFs/press |
Hard rule (from the research file’s own non-claims): $186-188M is large-enterprise-weighted planned budget, not a mid-market average. If your CFO pastes “industry average $186M” into a Series C operating plan, you have created a fiction.
What mid-market operators should take instead:
1. Direction: planned spend stayed steady Q1→Q2 at the large-enterprise weighted mean ($186M → $188M).
2. Governance share: as value claims rise (76% “meaningful value” in Q2), expect compliance, audit, and procurement line items to grow inside the same envelope - not vanish.
3. Your method: build a bottoms-up sheet (seats × tools + API + implementation + compliance labor). Compare to peers in your revenue band, not to KPMG’s mega-cap mean.
McKinsey’s mid-2026 *State of AI* rhyme (n=1,719; 97 countries): 89% of orgs use AI in ≥1 function, but only 37% report any positive EBIT contribution and ~6% are “high performers.” Spending like a giant without workflow redesign is how you join the flat EBIT cohort.
Mid-market compliance + procurement checklist {#checklist}
Use this as a living RFP annex for copilots, agents, and content pipelines that touch the EU. Score each vendor 0 / 1 / 2 (missing / partial / evidenced). Kill anything that stays at 0 on rows marked blocker.
A. Inventory & scope (you, week 0)
| # | Check | Blocker? | Pass evidence |
|---|---|---|---|
| A1 | List every GenAI surface: copilots, agents, image/video/voice, customer chat, internal RAG | Yes | Spreadsheet with owner + data classes |
| A2 | Flag EU users / EU-deployed output / EU customers in scope | Yes | Geo + product map |
| A3 | Separate provider vs deployer roles per system | Yes | One-pager counsel-reviewed |
| A4 | Shadow AI discovery (expense, SSO, browser, NDA interviews) | No | PLG seat list; Menlo’s 27%/shadow framing as motivation |
B. Article 50 transparency (vendor + you)
| # | Check | Blocker? | Pass evidence |
|---|---|---|---|
| B1 | User-facing AI disclosure when interaction is not obvious | Yes | Screenshot + config default ON for EU |
| B2 | Art 50(2) machine-readable marking / detectability for synthetic media/text the vendor generates | Yes (if generative) | Spec + sample files; grace plan if pre-Aug system |
| B3 | Deployer tooling for deepfake disclosure / public-interest AI text labeling | Yes (if you publish) | Playbook + product hooks |
| B4 | Emotion recognition / biometric categorisation - inform or preferably do not buy | Yes if used | Written “not in scope” or notice UX |
| B5 | Provenance retained for audit (who prompted, which model, when, outputs) | Yes for customer-facing | Retention policy + export |
C. Contract & security
| # | Check | Blocker? | Pass evidence |
|---|---|---|---|
| C1 | DPA / SCCs as needed; training-on-customer-data stance in writing | Yes | Signed DPA |
| C2 | Subprocessors list + change notice | No | Current list dated |
| C3 | Indemnity language for IP / synthetic content claims (negotiate; don’t invent coverage) | No | Redlines |
| C4 | EU data residency options labeled as optional vs required for your risk | No | Architecture note |
| C5 | Admin kill-switch / EU geo policy | Yes for chat agents | Demo |
D. Evaluation math (anti-hype)
| # | Check | Blocker? | Pass evidence |
|---|---|---|---|
| D1 | Workflow redesign owner named (McKinsey high performers ~75% redesigned vs ~25% others) | No | RACI |
| D2 | Success metric ≠ “employees like the chatbot” (aim at cycle time, error rate, or $) | Yes | Baseline + 90-day target |
| D3 | Agent washing test: does it plan→act→observe→adapt? (Menlo: only 16% enterprise true agents) | No | Demo script |
| D4 | Build alternative TCO includes marking, disclosure UX, evals, on-call - not just GPU | Yes if build proposed | Side-by-side sheet |
Buy / build / hybrid decision matrix {#matrix}
| Situation | Default | Why | Receipts you must still own |
|---|---|---|---|
| Horizontal copilots (writing, meeting notes, Office) | Buy | Menlo horizontal copilots alone were $7.2B of a $8.4B horizontal slice - category is productized | Disclosure UX; logging; data classes |
| Departmental coding assistants | Buy (seat or API) | Coding was $4.0B / 55% of departmental AI in Menlo 2025; velocity claims are self-reported 15%+ - still buy before build | Repo permissions; secret scanning; evals |
| Customer-facing support / voice agents in EU | Buy with Art 50 disclosure baked in | Interaction disclosure is load-bearing; PLG shadow tools fail audits | Transcript retention; human handoff |
| Marketing synthetic image/video/audio for EU | Buy marking-capable stack or pause | Art 50(2) marking/detectability | Asset pipeline that preserves marks |
| Proprietary underwriting / pricing model with thin vendor fit | Hybrid | Core logic may justify build; wrap with purchased LLM gateway + compliance layer | Full Art 50 stack on the wrapper |
| “Strategic internal LLM platform” with no unique workflow | Don’t | MIT/MLQ + Menlo both punish vanity builds | N/A - kill the program |
Hybrid pattern that works: purchased foundation (model API or enterprise assistant) + thin proprietary orchestration + shared transparency service (watermarking, disclosure banners, audit export). Do not rebuild Claude/ChatGPT; rebuild the receipt rail.
Watch out / when NOT to buy (or build) {#when-not}
Watch out
1. Grace confusion - The 2 Dec 2026 date is not a blanket delay of Article 50. It is a limited Art 50(2) marking/detection grace for systems placed on the market before 2 Aug 2026.
2. $186M misuse - Quoting KPMG’s large-enterprise-weighted mean as “what companies like us spend” will get you laughed out of a diligence call - or worse, funded into waste.
3. Agent washing - Gartner (Jun 2025) predicted >40% of agentic AI projects canceled by end of 2027, citing costs, unclear value, and weak risk controls. Menlo’s 16% true-agent rate says most of what you are sold is not that architecture.
4. PLG without SSO - A 27% PLG spend share (and higher with shadow AI) means finance will discover tools before security does.
5. Provider vs deployer mix-ups - Buying an API does not erase deployer duties when *you* publish deepfakes or public-interest AI text.
6. EBIT theater - McKinsey’s 37% any-positive-EBIT and ~6% high-performer cuts are the antidote to vendor ROI slides.
When NOT to buy
The vendor cannot show Art 50 disclosure/marking evidence and your use is EU-facing generative or interactive.
You only need a personal assistant for 10 people - force-fitting an “enterprise AI platform” RFP is how mid-market teams burn a year.
The pitch is “fully autonomous agent” but the demo is a chatbot with tools and no observe/adapt loop.
When NOT to build
You cannot staff watermarking, disclosure UX, evals, and on-call for 12 months.
Your “moat” is a system prompt and a vector DB - that is not a moat under Art 50.
Leadership wants a platform “because strategy” with no workflow owner (see McKinsey redesign gap).
When NOT to wait
You are shipping EU-facing synthetic media now (Sep 2026) without a marking plan and hoping December is a vibe. It is not.
90-day operator plan {#plan}
Days 1-15 - Inventory. Complete checklist sections A-B on paper. Freeze new PLG cards without security review. Name a single Art 50 owner (often Legal + Eng shared RACI).
Days 16-45 - Shortlist. Run three vendors max through blocker rows. Require sample marked outputs and disclosure screenshots. Kill builds that lack a receipts budget.
Days 46-75 - Pilot with receipts on. Production-like EU flag, logging export, disclosure defaults ON. Measure the D2 success metric, not NPS cosplay.
Days 76-90 - Contract + kill list. Sign the winner; sunset shadow tools that duplicate it; document grace status for any pre-Aug generative system still being marked. Put the 2 Dec 2026 date on the engineering calendar with an owner.
Illustration only (not a research statistic): a 400-person B2B SaaS with EU customers might spend more calendar time on A1 inventory + B2 marking proof than on model bake-offs - and that is the correct order in mid-2026.
FAQ {#faq}
Does Article 50 ban generative AI in the EU?
No. It imposes transparency duties (disclosure, marking/detectability, deepfake and public-interest labeling, notices for certain biometric/emotion systems). Risk-tier rules elsewhere in the AI Act are separate. Read the Commission FAQ before you freeze product plans.
We are a U.S. company. Do we care?
If your output is used in the EU, extra-territorial reach can pull you in. “No Brussels entity” is not a complete defense. Map product surfaces that EU users see.
Is the grace period until 2 December 2026 a free pass?
No. It applies to Art 50(2) marking/detection for systems placed on the market before 2 August 2026. Other transparency duties and post-Aug systems do not get that story.
Should every mid-market company spend ~$186M on AI?
No. KPMG’s $186-188M planned average is large-enterprise-weighted. Build your own bottoms-up budget. Treating $186M as a mid-market norm is explicitly flagged as a non-claim in the research file behind this article.
Why did purchased GenAI jump to 76%?
Menlo’s survey shows the flip from a near even 53/47 buy/build split in 2024 to 76% purchased in 2025, alongside higher production conversion (47% vs 25% SaaS) and heavy PLG. Regulation raising the cost of undocumented generation reinforces the same direction - even though Menlo’s survey window precedes the Aug 2026 enforceability date.
Can we keep building internal tools?
Yes, when the workflow is proprietary and you fund the receipt stack (marking, disclosure, audit). Default to buy for commodity copilots and content pipelines. MIT/MLQ’s reported higher success for externally sourced tools is a prior, not destiny - but it matches Menlo’s buy flip.
What is “shadow AI” in one sentence?
Employees using personal or unmanaged AI tools for work - Menlo ties PLG/shadow dynamics to roughly 27% of AI app spend (and possibly ~40% with shadow), plus a NBER-cited signal that ~27% of ChatGPT Plus usage is work-related.
Are most enterprise “agents” real agents?
Per Menlo, only 16% of enterprise deployments meet a plan→act→observe→adapt bar (27% at startups). Budget accordingly.
References {#references}
Accessed September 2026. Stats aligned to Vantaige research dump compiled 2026-09-02.
1. Menlo Ventures - *2025: The State of Generative AI in the Enterprise* (Dec 9, 2025): https://menlovc.com/perspective/2025-the-state-of-generative-ai-in-the-enterprise/
2. Menlo PDF: https://menlovc.com/wp-content/uploads/2025/12/menlo_ventures_enterprise_ai_report-2025-123125.pdf
3. European Commission - Transparency obligations under Article 50 AI Act (FAQ): https://digital-strategy.ec.europa.eu/en/faqs/transparency-obligations-under-article-50-ai-act
4. European Commission - Guidelines on transparency obligations for providers and deployers: https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems
5. KPMG - Global AI Pulse Survey Q1 2026 press (Mar 31, 2026): https://kpmg.com/xx/en/media/press-releases/2026/03/kpmg-global-ai-pulse-survey.html
6. KPMG - Global AI Pulse Q2 2026 PDF: https://assets.kpmg.com/content/dam/kpmgsites/xx/pdf/2026/06/global-ai-pulse-q2.pdf
7. MIT Media Lab Project NANDA / MLQ - *The GenAI Divide: State of AI in Business 2025*: https://mlq.ai/media/quarterly_decks/v0.1_State_of_AI_in_Business_2025_Report.pdf
8. Gartner - Over 40% of agentic AI projects will be canceled by end of 2027 (Jun 25, 2025): https://www.gartner.com/en/newsroom/press-releases/2025-06-25-gartner-predicts-over-40-percent-of-agentic-ai-projects-will-be-canceled-by-end-of-2027
9. Reuters coverage of Gartner agentic cancel prediction: https://www.reuters.com/business/over-40-agentic-ai-projects-will-be-scrapped-by-2027-gartner-says-2025-06-25/
10. McKinsey / QuantumBlack *State of AI 2026* figures as summarized in Vantaige research (adoption 89%, EBIT 37%, high performers ~6%; survey May 4-Jun 8, 2026, n=1,719) - prefer McKinsey primary when publishing externally.
11. Vantaige internal compilation - AI Market Research Dump September 2026 (
vantaige-ai-market-research-2026.md), Appendix rows M12, M25, M33-M37, M40, M51-M52, M54.
Related from Vantaige {#related}
The Three AI Markets Problem (2026) - why you must not blend Gartner / IDC / Stanford / Menlo into one “AI market” number
The Agentic ROI Gap (2026) - Gartner’s >40% cancel prediction vs spend, with a cancel-risk scorecard
Coding Ate Enterprise AI (2026) - Menlo’s $4B coding slice and seat vs API math
GEO After the Rankings Divorce (2026) - citation-grade publishing when AI Overviews stop mirroring classic top-10 SEO
Glean vs Hebbia vs Perplexity Enterprise (2026) - buy the workflow, not the category mashup
---
One short email a week: the buy/build calls that aged well, the compliance dates that actually bite, and the budget myths (looking at you, $186M “average”) we refuse to launder. Subscribe at vantaige.io.
*Written as Aymen B for Vantaige.io - 2 September 2026. Operator guide for mid-market AI procurement and transparency hygiene - not legal advice, not investment advice. Re-check primary Commission, Menlo, and KPMG links before you sign or file.*
Get the best new AI tools and guides, weekly
One short email a week. The tools worth trying, the guides worth reading, nothing else.
No spam. Unsubscribe anytime.
Aymen B
Contributing writer at Vantaige, covering the AI tools ecosystem.
Similar articles

GEO After the Rankings Divorce (2026): Why Only 37.9% of AI Overview Cites Are Top-10 Pages

Coding Ate Enterprise AI (2026): The $4B Use Case, Anthropic’s Share, and Seat vs API Math
