McKinsey's 32 percent is real and it measures a decision, not a cancellation. Across twelve software vendors' June to September 2026 disclosures, no filing or transcript attributes a single churned or downsold customer to an internally built replacement, and forward commitments are growing at every one of them. This report separates what buyers said from what sellers filed, then prices the build that would replace a licence: about $1.26 million over three years against $540,000 of subscription.
McKinsey's State of AI 2026, published on 25 August 2026, reported that 32 percent of respondents said their organization decided against buying one or more software products or features because the functionality could be built internally with agentic coding tools. Within days the finding was in trade press, analyst notes and vendor battlecards. By the time it reaches a board deck it has usually lost the words that carry all the meaning: one or more, products or features, decided against buying. What is left reads as a third of enterprises cancelling software, and nothing in the survey supports that.
Nobody was asked whether the replacement shipped, whether it passed an audit, or whether a contract was terminated. A deferred evaluation and a killed renewal score identically. A respondent who cancelled a seven-figure ERP renewal and a respondent who declined a $400 a month scheduling tool are indistinguishable inside the 32 percent. The sample is a standing executive panel of more than 33,000 opted-in members, 1,719 responses fielded 4 May to 8 June 2026, weighted by each respondent's nation's share of global GDP. That weighting corrects for geography. It does not correct for software spend, for seniority, or for whether the person answering has any visibility into a renewal calendar.
So the report goes to the other side of the trade and reads what sellers filed. Twelve vendors across enterprise applications, analytics and developer tooling, every figure taken from a press release, an 8-K or an earnings call in the June to September 2026 reporting run. Then it prices the build that would replace one of them, line by line, over three years. The question is not whether buyers are saying this. They are. The question is whether it has cost anyone a renewal yet, and what it costs the organization that goes through with it.
Every claim below carries an evidence label in the report itself: fact, vendor claim, third-party estimate, assessment, hypothesis or scenario. Vendor figures come from press releases, 8-K filings and earnings coverage in the June to September 2026 run, and where a metric is a vendor's own non-standard definition, the report says so rather than smoothing it over.
McKinsey asked whether an organization had decided against buying one or more software products or features because the functionality could be built internally. Nobody was asked whether the replacement shipped, whether it passed an audit, or whether a contract was terminated. A shelved evaluation, a declined module, an unfunded proof of concept and a killed renewal all score the same, and they have wildly different revenue consequences for a vendor.
1,719 responses across 97 nations, fielded 4 May to 8 June 2026, drawn from a Global Survey Panel of more than 33,000 opted-in participants. That is a response rate near five percent with self-selection into each wave. The GDP weighting fixes geography. It does nothing about the two skews that matter here: people enthusiastic enough about AI to answer an AI survey, and the absence of any weighting by software spend.
Across Salesforce, SAP, ServiceNow, Workday, Snowflake, Datadog, Atlassian, GitLab, HubSpot, Asana, DocuSign and C3.ai, not one filing or transcript in the June to September 2026 run attributes churn, downsell or slowed renewal to customers building replacements with agentic coding tools. ServiceNow's renewal rate held at 98 percent. Atlassian's cloud revenue grew 31 percent on seat expansion, which is the opposite signal.
Atlassian's remaining performance obligations rose 44 percent, Snowflake's 30 percent, SAP's current cloud backlog 26 percent, ServiceNow's current remaining performance obligation 21 percent, Salesforce's 14 percent. Workday is slowest at 8 percent on total subscription backlog and gave a bookings-mix reason. Contracted future revenue is where declined renewals appear first, months ahead of reported revenue, and it is going the other way.
Gartner's July 2026 forecast has worldwide IT spending up 14.2 percent in 2026 to $6.37 trillion, with software growing 15.1 percent. If a third of enterprises were withdrawing purchases at any material dollar value, the software segment is the first place it would appear. It has not appeared.
HubSpot's net revenue retention sits at 102 percent, down a point year over year, and Asana's at 97 percent. Both are soft, both companies attribute it to budget scrutiny and seat optimization, and both metrics have been drifting since before agentic coding tools were purchasable. Asana has now improved for five consecutive quarters, which is close to fatal for the displacement reading of that number.
Modelling a 300-seat application at $180,000 a year, and pricing engineering, agentic tooling, security review, compliance evidence, hosting and one staff departure at published unit costs, the build lands near 2.3 times the buy over three years. The build only pays where the annual licence exceeds roughly $420,000, and that threshold sits above the entire departmental software portfolio of most mid-market organizations.
First-version development is the smallest recurring cost in any three-year model. The maintenance literature has put post-release work at 60 to 80 percent of lifecycle cost for four decades, and GitClear's 2026 analysis of 623 million code changes finds refactoring line moves down 70 percent and duplicated code blocks up 81 percent as AI authorship rises. Cheaper first versions and more expensive second years is a worse trade than it looks.
IBM's 2026 study of 602 breached organizations found shadow AI involved in 43 percent of incidents, up from about 20 percent a year earlier, with those incidents averaging $5.39 million against a $4.99 million global average. Sixty-eight percent of breached organizations had no policy governing AI use at all. Run the inventory of what your teams have already built before you run the build-versus-buy analysis.
Technology reported 41 percent and healthcare payers and providers 39 percent, against insurance at 19 percent and the public and social sector at 17 percent. The spread tracks regulatory dependency and certification burden almost exactly. That ordering is more useful than the headline, and it is the best available evidence for which categories are actually protected.
The scenario is a departmental application replacing a purchased product at $180,000 a year, which is $600 per seat per year and typical of mid-market CRM, IT service management or analytics. Three years of licence at flat pricing is $540,000. Every line below is built from published unit costs at United States onshore engineering rates, and the model is shown line by line in the report so the assumptions can be moved without rebuilding it. An offshore team roughly halves the largest bar and moves the break-even with it.
1.5 full-time equivalent years in year one and one thereafter, at $250,000 fully loaded. That sits inside the published range: the Bureau of Labor Statistics puts median software developer pay near $133,000 with senior roles at $150,000 to $185,000, and current benchmarks put the fully loaded cost of a senior US engineer at $250,000 to $265,000 once benefits, payroll tax, equipment, recruiting and overhead are counted.
$875,000 over three years
Assumes the application falls in scope for a SOC 2 Type II. A first-year programme including readiness, testing, tooling and internal time runs $30,000 to $150,000, with the audit fee alone $30,000 to $75,000 at mid-market scope and renewals at 75 to 90 percent of it. The $45,000 used here is the low end and assumes an existing compliance programme the application joins rather than one it creates.
$115,000 over three years
A flat $30,000 a year for the environment the application runs in. Small next to engineering, and unlike a licence it does not stop when the application stops being useful. It is one of the lines that continues at full rate in years two and three, which is where the build's cost profile diverges most sharply from the purchase.
$90,000 over three years
Tech sector tenure runs roughly two to three years against a 4.1 year national average. LinkedIn's 2025 data puts the direct cost of replacing a software engineer near $43,700 in recruiter fees, signing bonuses and onboarding, and Gallup's replacement range is 50 to 200 percent of salary for senior technical roles. Deliberately conservative, and it excludes the cost that actually bites: losing the only person who understood why the agent wrote it that way.
$90,000 over three years
$20,000 in year one and $15,000 in each of years two and three. A SOC 2 penetration test for a standard software-as-a-service scope runs $8,000 to $25,000, and an internally built application carries the full testing burden because there is no vendor attestation to inherit. A custom app in scope for SOC 2, HIPAA or PCI gets a heavier treatment than a purchased one, not a lighter one.
$50,000 over three years
Three engineers at $350 a month all in. Published 2026 benchmarks put GitHub Copilot Enterprise at $39 per user per month and Cursor Business at $32, but seat price is not the cost. Once agentic use begins, total monthly spend per developer at thousand-seat scale lands between $200 and $500, and Claude Code deployments average $150 to $250. Most likely to be understated in a business case, and the smallest line either way.
$37,800 over three years
The annualised run cost of about $419,000 is the number worth carrying out of the report. A purchased product has to cost more than roughly $420,000 a year before an onshore in-house replacement is cheaper on cash alone, before any adjustment for risk. Note also where agents actually help. They compress the engineering line in year one, which is $375,000 of a $1.26 million total, or 30 percent. Halving first-version development time saves about 15 percent of the three-year cost and changes no decision. Everything agents currently do well sits in the smallest part of the model, and everything they do badly sits in the largest. The model excludes the opportunity cost of the engineering capacity consumed, which is its largest omission.
Exposure here means the probability that a competent internal team with agentic tooling can produce something a business unit will accept in place of the purchased product, within a budget cycle. It is not a judgment about product quality. Data gravity is the weakest defence, because it is a cost of moving rather than a prohibition, and it erodes as extraction gets cheaper. Certification is stronger, because it turns a build decision into a multi-year programme with an external gatekeeper. Regulatory dependency is strongest, because it is a permanent obligation to track somebody else's rule changes, and no volume of generated code discharges it.
No external data dependency, no certification, no audit inheritance. Already the target of low-code, and the population most likely to have been bought on a corporate card rather than through procurement.
Nothing protects it
The data is already inside the organization. The purchased product supplies presentation, and presentation is the thing agents produce most convincingly on a first pass.
Nothing protects it
Short-lived, low blast radius, and the work agents are demonstrably best at. This is where displacement is real and where the dollars are smallest, which is the shape of the whole problem in one row.
Nothing protects it
Buildable in outline. The value sits in deliverability reputation, the connector estate and data accumulated over years, none of which an agent writes. Atlassian's 31 percent cloud growth on seat expansion says the incumbents are still winning project and task tracking in practice.
Data gravity, and it erodes
For analytics platforms, ingest economics and retention scale defeat the build: the cost that matters is storage and query, not the application, which is why these vendors price on consumption. For financial systems it is audit dependency, and a system with no vendor attestation puts the entire evidence burden on the organization.
Certification and unit economics
Jurisdictional rate maintenance is a permanent subscription to somebody else's regulatory research; the software is not the product, the tax tables are. Add GxP validation, change control that makes agent-speed iteration a liability, and a failure mode that is a regulatory event rather than an outage.
Regulatory dependency holds
Switching cost is doing less work here than vendors would like. An organization with agentic tooling can regenerate a great deal of custom integration code cheaply, which is exactly the moat integration-heavy vendors have relied on. What it cannot regenerate is an attestation, a certification, or a jurisdictional rate table maintained by someone contractually liable for it. Vendors whose defence is complexity should expect that defence to weaken. Vendors whose defence is liability should not.
METR's randomized controlled trial of 16 experienced open-source developers across 246 real tasks found them 19 percent slower with early-2025 AI tools, while forecasting a 24 percent speedup beforehand and estimating a 20 percent speedup afterwards. A February 2026 follow-up on later tools showed some evidence of speedup, but METR reported selection effects that made the central estimate unreliable. That 39-point gap between measured and perceived productivity is the most important number in the report for anyone approving a build, because every business case for an internal replacement is written by the people who felt 20 percent faster, and the reviewers share the perception.
The run cost is the other half. GitClear's 2026 analysis of 623 million code changes from 2023 to 2026 found refactoring line moves down 70 percent against 2022 levels, cross-file function calls down 35 percent and long-term legacy maintenance work down 74 percent, while within-commit copy and paste rose 41 percent, duplicated code blocks rose 81 percent, error-masking constructs rose 47 percent and two-week churn rose 15 percent. Read that as a maintenance cost forecast rather than a code quality complaint. Duplication and swallowed exceptions are precisely the properties that make a change in year two expensive. An organization that builds in 2026 at agent speed is buying a year-two profile nobody has priced, because no codebase built this way is three years old yet.
DORA's framing is the right lens for the decision: AI amplifies whatever engineering discipline already exists. An organization with automated testing, disciplined version control and continuous integration converts agent output into shipped software. An organization without them converts it into rework. Most organizations considering replacing a purchased product with an internal build are doing so because they do not have a large disciplined engineering function, which is the condition under which the amplifier works against them.
The call is that agentic coding is changing what enterprises build, not yet what they renew. The displacement that is real sits at the edges: the departmental tool, the reporting layer, the second seat tier nobody uses. The absence of vendor corroboration is not proof of absence, and the report says so plainly. Displacement concentrated in vendors too small to be covered, in purchases never made rather than contracts cancelled, or in the long tail of departmental subscriptions below any disclosure threshold would be invisible to this method by construction. That is why the recommendation is gross retention rather than net. A vendor with 120 percent net retention and deteriorating gross retention is losing customers and hiding it inside expansion, and that is the only pattern consistent with quiet build displacement.
For CIOs, carry the $420,000 threshold into the renewal conversation, and run the inventory of what your teams have already built before you run the build-versus-buy analysis. For vendor CFOs, nothing in the disclosure record justifies modelling build-driven attrition as a distinct line yet, but separating gross from net in your own internal reporting is worth doing now, and the exposed revenue is the low-utilization seat a customer can eliminate without replacing anything at all. For procurement, ask a build proposal for the four numbers it will not contain: the fully loaded run cost in years two and three, the compliance scope and who signs the evidence, the named maintenance owner, and the decommissioning cost. Those four together are 70 percent of the three-year total.
Keep the two theses apart. Build displacement and AI-native substitution have opposite implications for total category spend: the first shrinks it, the second reallocates it. The Intuit downgrades from JPMorgan and Bank of America are substitution, customers switching to cheaper AI-native competitors rather than writing their own tax software. The UBS downgrade of SAP is closer to attach-rate risk, a warning that slow agent delivery pushes customers to build agents on top of SAP data instead of buying SAP's. Neither is evidence for the build thesis, and both have been cited as though they were. Klarna, the canonical case, turned out to be a vendor consolidation rather than an AI replacement, and its chief executive said in March 2025 that he doubted others would follow.
The report closes with four scenarios to 2028 and their earliest visible signs: edge erosion with the core intact at 50 percent, the run cost landing and displacement partially reversing at 25, displacement becoming visible in disclosure at 15, and substitution rather than construction at 10. The probabilities are the least reliable content in it. The tripwires are the useful part, and every one is observable from public disclosure: a vendor separating gross from net retention, a build-displacement risk factor appearing in two or more annual filings, ServiceNow's renewal rate dropping below 97 percent, Atlassian cloud seat expansion decelerating below 15 percent, or the first earnings call where a vendor names a churn cohort lost to customer-built replacements. That last one would overturn the call.
This isn't a vendor summary. Every sentence is labeled by what stands behind it: verified fact, vendor claim, third-party estimate, my assessment, hypothesis, or scenario. Sources are numbered and clickable. Forward-looking sections use scenarios with observable tripwires, not forecasts. It's the same method behind every market assessment I write.
Twenty-six pages, built from public sources with no client brief and no interviews. Read it in the browser or take the PDF.
Each report here answers a real question, directed and researched against public sources and evaluated against a stated assumption, then delivered as Word and PDF. If you're weighing a platform, sizing a category, or defending a number to a board, tell me the decision behind it and I'll tell you honestly whether a report is the right tool.
Commission an assessment