← Insights

Enterprise AI agents: build, buy, or open source

A decision guide for the 2026 buy — and the lock-in nobody prices in.

Playbook · 24 July 2026 · Bernhard Huber

Enterprise AI agents are the line item almost every large organisation added to its 2026 budget, and the market is already signalling that a large share of that spend will not survive to production. Gartner predicts that over 40% of agentic AI projects will be cancelled by the end of 2027, citing escalating cost, unclear business value and inadequate risk controls, based on a poll of 3,412 webinar attendees. Layered on top of that is what Gartner itself calls “agent washing”: of the thousands of vendors now marketing an agentic product, the firm assesses only around 130 as having substantial, genuine agentic capability. Forrester's independent view lands in roughly the same place from a different angle, predicting that three in four firms building aspirational, fully independent agentic architectures on their own will fail.

None of that means the technology doesn't work — Sierra has ridden real revenue — $100M ARR in under two years — to a ~$15.8B valuation. It means the category is noisy enough that choosing a vendor by demo is a bad method. The question worth a strategy afternoon isn't which logo to buy. It's build vs buy vs self-host, and — whichever you choose — how much lock-in you are contractually and technically signing up for on day one. That is the frame this playbook uses.

The market splits into three buyer archetypes

Every enterprise agent offering today falls into one of three buying patterns, each trading speed against control differently.

Pure-play specialists

Pure-play specialists sell one deep agent product with no incumbent software to defend. Sierra, founded in 2023 by ex-Salesforce co-CEO Bret Taylor and ex-Google's Clay Bavor, prices on outcomes, and rode that model to $150M ARR on the way to a $950M Series E at a ~$15.8B valuation in May 2026. Wonderful.ai targets a gap the US-built platforms leave open — non-English and culturally specific markets — and raised a $150M Series B at a $2B valuation. Neither carries a legacy install base — the edge and the risk at once.

Data-gravity suites

Data-gravity suites bundle agents into software you already run. Google Gemini Enterprise (renamed from Agentspace, October 2025) layers agents onto Workspace and Google Cloud at $21–$60+/user/month plus token billing, and Google reports 8M+ paid seats across ~2,800 companies. Microsoft Copilot Studio bills in Copilot Credits inside the M365 stack, and Microsoft reports 230,000+ organisations, including ~90% of the Fortune 500. Salesforce Agentforce runs three pricing models at once — $2/conversation, Flex Credits, or a $125/user/month seat — and Salesforce reports $1.2B in ARR, up 205% year-on-year. None locks you to its own model — all three let you bring Anthropic, Meta or other models in — but all three tie the agent to the platform around it: Data Cloud, Workspace, or Azure/Entra ID.

Open source and self-host

Open source and self-host trades vendor risk for engineering ownership. Botpress ships its core under a clean MIT licence, self-hostable via Docker — but its “model-agnostic” marketing needs a caveat: bring-your-own-LLM is gated behind Botpress's paid Enterprise plan, and the open-source README itself still markets the product as “powered by OpenAI”. Dify is the most turnkey of the group, but its Apache-2.0 base carries a resale carve-out — no multi-tenant SaaS or unbranded resale without Dify's written permission. Rasa still carries an “open-source conversational AI” reputation its 2026 flagship no longer earns: the free tier caps at 1,000 conversations/month, and the product enterprises actually want, Rasa Pro, requires a commercial licence. Underneath it all sits LangGraph — not a product, but the open substrate teams reach for when they'd rather build the agent layer themselves, cited in production at Uber, LinkedIn and Klarna.

Seven platforms, side by side

The prose above carries the numbers and the hedges; this table is the terse reference to come back to when you're scoping a shortlist. The dots read the three lock-in-sensitive columns from the buyer's side:

Favours the buyer Mixed / conditional Favours the vendor — higher lock-in
Enterprise AI agent platforms: pricing, model freedom, standards and where the lock-in actually sits
Platform What it is Pricing model BYO-LLM? Open standards Where the lock-in sits Best-fit buyer
Sierra Outcome-based CX agent platform on proprietary AgentOS Outcome-based (paid per resolved outcome), blended with consumption Multi-model “constellation” internally; no customer-facing model swap disclosed No public MCP/A2A commitments found Closed AgentOS; workflow changes typically routed through Sierra's own consultants Enterprises wanting a turnkey, outcome-priced CX agent at Fortune-50 scale
Wonderful.ai Localised voice/chat/email CX agents for non-English and underserved markets Not public; high-touch enterprise sales Vendor describes the architecture as model-agnostic, routed per use case Not publicly documented High-touch, deeply integrated deployment; no independent portability data exists Multinationals needing culturally and linguistically localised agents
Google Gemini Enterprise Enterprise search + agent platform (formerly Agentspace) with an open Vertex AI Agent Builder/ADK dev layer $21–$60+/user/month across four editions, plus token/compute billing Yes — Vertex Model Garden hosts Claude, Llama and Mistral alongside Gemini ADK is open-source and model-agnostic Google Cloud/BigQuery/Workspace data gravity, not the model Google Workspace/Cloud-native enterprises
Microsoft Copilot Studio Low-code agent builder inside M365; pro-dev layer is Azure AI Foundry Agent Service Copilot Credits (25,000-credit pack, $200/tenant/month annual) plus M365 Copilot seat inclusion Yes — Foundry model catalogue spans OpenAI, Llama, Mistral, DeepSeek, Grok, Phi MCP generally available; A2A in public preview Azure/Entra ID/Graph/Dataverse/Fabric integration Microsoft 365/Azure-native enterprises
Salesforce Agentforce Autonomous “digital labor” agents for service, sales, marketing and commerce Three coexisting models: $2/conversation, Flex Credits ($500/100,000), or $125/user/month seat Yes via the Models API (Bedrock, Azure OpenAI, OpenAI, Vertex); orchestration stays on Salesforce's proprietary Atlas Reasoning Engine MCP built in via Salesforce-hosted servers; A2A planned via MuleSoft Agent Broker Data Cloud as a de facto prerequisite at scale; one researcher puts a full platform exit at an 18–36 month CRM migration Established Salesforce CRM/Data Cloud shops
Botpress Open-source (MIT) conversational agent builder — Studio, Cloud, Hub Free self-hosted core; paid Cloud and Enterprise tiers Gated behind the paid Enterprise plan; OSS/Cloud tiers ship “powered by OpenAI” MIT-licensed core; no proprietary code lock None on the licence itself if self-hosted — cost shifts to your own uptime, scaling and patching with no vendor SLA Teams that want full self-hosted ownership and are prepared to run their own ops
Build-your-own (LangGraph) MIT-licensed orchestration framework, not a packaged product Free framework; paid observability via LangSmith/LangGraph Platform Fully model-agnostic by design Fully open; no proprietary transport or billing layer None at the framework layer — but you own the entire product and operations layer yourself Engineering-heavy organisations building a bespoke agent product from primitives

Buy, build, or open source: the decision logic

Buy wins when speed to value outweighs control. A CX specialist such as Sierra or a CRM-native suite such as Agentforce gets a working agent live in weeks rather than quarters, and both are built for organisations comfortable trading some data gravity for outcome-based or seat-based pricing at Fortune-50 scale — the buyer profile the platform table above sketches out. “Appetite for outcome pricing” is doing real work in that sentence: it means the buyer is willing to let the vendor meter and bill per resolved case or per seat, in exchange for not having to own the model-selection, prompt-evaluation and failure-handling engineering underneath. Buy also wins when the organisation genuinely lacks the engineering bench to run an agent stack in production: on-call, evals, prompt regressions and all.

Build or open source wins on close to the opposite conditions: data sovereignty — keeping conversation logs, embeddings and customer data inside your own infrastructure rather than a vendor's cloud — a non-English or heavily regulated market the large US-built platforms serve thinly — the wedge Wonderful.ai has built a $2B valuation on — or a cost-control mandate that can't tolerate open-ended, metered billing once volume scales. Self-hosting Botpress's MIT-licensed core, for instance, avoids the resale and multi-tenancy restrictions bundled into Dify's Apache-2.0-plus-carve-out licence, at the cost of running Studio, the runtime and every integration yourself.

Neither path is free of risk, and the honest accounting matters more than either side's marketing. On the build side, Forrester predicts that three in four firms building aspirational, fully independent agentic architectures on their own will fail — DIY is not a hedge against vendor risk, it's a bet that your organisation is the exception, and the Gartner cancellation and “agent-washing” findings cited above are the same warning from a different angle. On the open-source side, self-hosting doesn't remove risk so much as relocate it: you are converting vendor risk into engineering-team ownership of uptime, scaling, model cost and patching, with no vendor SLA to fall back on when something breaks at scale.

The one-line heuristic: buy when you need working outcomes fast and can live inside someone else's data gravity; build or open-source when data sovereignty, market fit or cost control matter more than speed — and budget the engineering headcount that choice actually requires.

Where the lock-in actually lives

Model lock-in is the least of it. Google, Microsoft and Salesforce all now let customers bring a third-party model to their agent platform — Vertex Model Garden hosts Claude, Llama and Mistral; Azure AI Foundry's catalogue spans OpenAI, Llama, Mistral, DeepSeek, Grok and Phi; Agentforce's Models API supports Bedrock, Azure OpenAI, OpenAI and Vertex. The moat has moved one layer down, to wherever the enterprise's data already lives: BigQuery and Workspace for Google, Dataverse/Fabric/Graph and Entra ID for Microsoft, Data Cloud and the CRM object model for Salesforce. Azure binds tightly to Entra ID and Microsoft Graph for identity and access, and Vertex defaults its search/grounding layer to its own stack — fine-tuned weights and embedding indexes typically don't move across Bedrock, Azure AI Foundry and Vertex, on one independent analyst's assessment, even when the underlying model does.

How an enterprise AI agent integrates with systems of record A central AI agent, wired via MCP, A2A, connectors and APIs, links to six enterprise systems: CRM and customer records (Salesforce, Dynamics); data warehouse and lakes (BigQuery, Snowflake); knowledge base and docs (Workspace, SharePoint); ticketing and ITSM (Zendesk, ServiceNow); identity and access (Entra ID, Okta); and channels and telephony (web, email, voice). CRM & customer records e.g. Salesforce, Dynamics Data warehouse & lakes e.g. BigQuery, Snowflake Knowledge base & docs e.g. Workspace, SharePoint Ticketing & ITSM e.g. Zendesk, ServiceNow Identity & access e.g. Entra ID, Okta Channels & telephony e.g. web, email, voice Enterprise AI agent orchestration + reasoning voice · chat · email · web wired via MCP · A2A · connectors · APIs
How an enterprise AI agent wires into an organisation's systems of record. The agent is only as useful as these integrations make it — and that wiring is exactly where data gravity, and lock-in, accumulate.

Open standards close a real slice of this gap, but a narrower one than the marketing implies. MCP was donated to the Agentic AI Foundation, formed under the Linux Foundation, in December 2025, and A2A went directly to the Linux Foundation in June 2025, with AWS, Microsoft, Salesforce, SAP and ServiceNow among its backers. What that buys is portable tool-calling and agent-to-agent messaging. It does not make the orchestration logic sitting on top of it — Atlas Reasoning Engine, Foundry's agent graphs, ADK-built flows — portable, and it does nothing for fine-tuned weights or pricing structure. Copilot Studio workflows, Agentforce configurations and ServiceNow AI configs remain vendor-specific and non-portable by design, in one specialist researcher's assessment.

That same researcher, VaasBlock, puts a number on it — a single-source estimate, not a market consensus, but the right order of magnitude to plan against. An enterprise walking away from Agentforce is implicitly signing up for an 18–36 month CRM migration, and unwinding a ServiceNow deployment means rebuilding “tens of thousands of engineering hours” of configuration that AI capability has been layered directly into.

The five-lever exit-cost framework

Score any platform on five levers before you sign, not after you're stuck with it:

  • Data portability — can logs, embeddings and fine-tunes be exported in an open format, on demand?
  • Orchestration portability — is the workflow layer built on MCP/A2A and open frameworks, or locked to the platform's proprietary reasoning engine?
  • Model substitutability — can the underlying model be swapped, contractually and technically, without a re-platforming project?
  • Rebuild cost — the engineering hours to reconstruct the capability elsewhere; the ServiceNow and Agentforce anchors above are the right order of magnitude to model against.
  • Pricing exposure — how much of the contract is fixed versus outcome- or usage-based, and how exposed that leaves you to surprise charges — 78% of IT leaders report unexpected consumption or AI-pricing charges within a year, per Zylo's 2026 SaaS Management Index.

Put a rough number on it: exit cost ≈ (rebuild hours × loaded engineering rate) + re-migration data cost + pricing-volatility premium − negotiated switching credits. Treat that as directional, not an audited model — but running it once, before signing, turns lock-in from a surprise into a line item you priced in advance.

That last term is the one most buyers skip. Vendors compete for displacement business, and exit offsets — migration credits, a capped rebuild-hours guarantee, a data-export SLA — are negotiable if you raise them at the same table as the pricing discussion, before you sign. Raising them eighteen months into a deployment, once you actually need to leave, is negotiating from a hostage's position.

Score a platform on these five levers below.

Score your lock-in before you sign

Rate a platform on five levers. It runs entirely in your browser — nothing is sent or stored.

0 of 6 set

Indicative only — a fast self-rating to structure a procurement conversation, not advice.

How we'd advise

Don't buy the demo. Buy the exit. Every platform in this piece can put a working agent in front of you inside a week — that was never the hard part, and the vendors know it. The hard part is the eighteen-month CRM migration or the “tens of thousands of engineering hours” of configuration rebuild waiting on the other side of a “no” decision three years from now. That number is knowable in advance if you price it before you sign, not after you're stuck inside it. Run the five-lever scorer above against your actual shortlist before the RFP goes out — not after a vendor's SE has already shaped the requirements around what they sell.

The build/buy/open-source call is not, underneath it, a feature comparison. It's a data-gravity question — whose infrastructure ends up holding your conversation logs, embeddings and fine-tunes. It's a regulatory question — whether your market and your data-residency obligations tolerate a US-hosted suite, or push you toward self-hosting regardless of feature parity. And it's a team-capability question — whether you have, or are willing to build, the on-call and evals discipline that self-hosting or a bespoke build actually demands, day two onward. Answer those three honestly and the vendor shortlist mostly picks itself.

Bernhard Huber, 24 July 2026.

This sits alongside the delivery work itself: Digital & AI Strategy for the platform decision, Executive Advisor & Operating Cadence for the governance cadence around it, and Interim Management if you need someone to own the migration for a quarter.

Sources consulted

This playbook draws on primary company disclosures, independent reporting and analyst research, not secondary aggregation; vendor-reported figures (funding, ARR, seat counts) are distinguished in the prose above from independently reported ones. Snapshot date: 24 July 2026. Vendor pricing, funding and adoption figures move quickly — treat a later edition, if one exists, as the version of record.

Primary sources

Sierra: TechCrunch, Series E coverage · TechCrunch, $100M ARR milestone · Sierra, outcome-based pricing

Wonderful.ai: TechCrunch, Series B coverage · Index Ventures, seed-round coverage

Google Gemini Enterprise: Devoteam, the Agentspace rename · Coworker.ai, pricing breakdown · Getpanto.ai, adoption statistics

Microsoft Copilot Studio / Azure AI Foundry: Microsoft, Build 2025 announcements · Stackmatix, adoption statistics · Azure AI Foundry, model catalogue

Salesforce Agentforce: Salesforce, pricing announcement · SaaStr, three coexisting pricing models · Salesforce Ben, $1.2B ARR

Open source: Botpress, MIT licence · Botpress, README · Gumloop, Botpress alternatives · Dify, licence · Dify, open-source policy · Rasa, pricing · LangChain, built with LangGraph

Standards: Model Context Protocol, joining the Agentic AI Foundation · Linux Foundation, A2A project launch

Analysts and independent research: Gartner, project-cancellation forecast · Forrester, agentic AI predictions · VaasBlock, vendor lock-in research · Zylo, 2026 SaaS Management Index · BitsLovers, Bedrock vs Azure AI Foundry vs Vertex

How to cite this article

APA-style:

Huber, B. (2026). Enterprise AI agents: build, buy, or open source. Consulting Huber. https://consulting-huber.com/ai-agent-platform-playbook.html

BibTeX:

@article{huber2026aiagents, author = {Huber, Bernhard}, title = {Enterprise AI Agents: Build, Buy, or Open Source}, journal = {Consulting Huber}, year = {2026}, url = {https://consulting-huber.com/ai-agent-platform-playbook.html} }

Snapshot date: 24 July 2026. This is a practitioner playbook synthesising public reporting and vendor documentation, not procurement or legal advice; verify vendor-specific pricing and licence terms against current, primary vendor sources before relying on them.

Related: The AI Measurement Crisis: what enterprise AI actually costs · The delivery layer underneath AI · The EU AI Act: an operator's compliance playbook