Rent AI from a vendor, or run your own?
Self-hosted systems create compounding data assets while managed APIs reset, bounding product quality to a competitor's ceiling and risking strategic vulnerability.
The question
Every AI feature can be built two ways. The simple path: call a managed AI API (ChatGPT, Claude, Gemini) — fast to ship and nothing to operate, but your data and your customers' data flow to the vendor and you're tied to their stack. The hard path: run open models on your own infrastructure — you keep the data and the control, but you own the security, reliability, and operations. For which workloads do you accept the managed API and hand over the data, and for which do you self-host to keep control?
Counsel's position
Self-host open models for core IP and sensitive data, using managed APIs only for non-differentiating, non-sensitive, or rapidly evolving features.
Verdict
The verdict: Self-host open models for core IP and sensitive data, using managed APIs only for non-differentiating, non-sensitive, or rapidly evolving features.
How the criteria decide
3 of 3 criteria resolved on cited evidence.
| Criterion | Favours | Evidence |
|---|---|---|
| Data ownership and exposure risk | Self-host open models | Self-hosted systems create compounding data assets while managed APIs reset claude gives results. openclaw builds a system that stores process and data. Microsoft is investing US$2.5bn to embed 6,000 enterprise AI experts Their data, intellectual property and competitive advantage will not be used to train models in ways that commoditise what differentiates them in their industry. |
| Vendor lock-in and switching cost | Self-host open models | Renting a foundation model bounds product quality to a competitor's ceiling When the core intelligence of your product is a model someone else owns, the quality of your product is bounded by the quality of that model, and you do not control that boundary. Generic fine-tuning APIs plateau when targeting highly specialized proprietary data This approach works well for proof-of-concept deployments and many production use cases. But Salamanca argues that it fundamentally plateaus when organizations try to solve their hardest problems. |
| Reliability, security and ops burden of self-hosting | Use managed AI API | Open-weight model API pricing is $1 to $2 per million tokens Most production workloads don’t need the smartest model. They need a good-enough model that’s fast, cheap, customizable, and runs on infrastructure the company controls. |
Self-hosted systems create compounding data assets while managed APIs reset
Given your choice between managed APIs and self-hosting, owning the infrastructure allows you to retain execution history and memory as proprietary assets.
Open-weight model API pricing is $1 to $2 per million tokens
When deciding which workloads to self-host, open-weight models offer a massive cost advantage for production tasks that do not require frontier-level reasoning.
Renting a foundation model bounds product quality to a competitor's ceiling
When you rely on a managed API, the core intelligence of your product is controlled by a vendor who can easily replicate your features.
Generic fine-tuning APIs plateau when targeting highly specialized proprietary data
For workloads involving deeply guarded intellectual property or unique domain languages, self-hosting and advanced training are required to surpass off-the-shelf model capabilities.
Microsoft is investing US$2.5bn to embed 6,000 enterprise AI experts
While evaluating managed vs. self-hosted paths, note that major vendors are now offering embedded engineering to ensure your proprietary data isn't used to train public models.
Read another verdict
- Which process should we point AI at first?
- Put one person in charge of AI — or is a Head of AI premature for us?
- Buy a tool for this process, or build around our own knowledge?
- Centralize AI strategy under CEO or distribute ownership?
- Adopt new AI ROI tools or refine existing methods?
- Invest in pre-build costing or post-deployment ROI tracking?
- Our documents are a mess. Clean them up before AI, or after?
- How do we measure the return on an AI workflow — and what baseline is honest?