Build-vs-Buy at the Acquisition Inflection
On March 17, 2026, OpenAI announced its acquisition of Promptfoo, the open-source eval framework that had become the default tool for agent evaluation across roughly 40% of mid-market agent programs. The acquisition price was undisclosed but estimated at $190M-$240M against ARR somewhere between $14M and $22M โ a multiple driven by strategic absorption, developer mindshare, and the eval-set asset, not by standalone revenue. The reaction inside the average agent-platform-strategist's calendar took approximately forty-eight hours: by Thursday afternoon, every strategist who had built their agent program on Promptfoo had two emergency meetings on the books and one Slack thread with the CFO. Should the company acquire a different eval vendor while the others are still available? Partner with OpenAI's now-owned offering and live inside that roadmap? Rebuild against an alternative (Braintrust, Langfuse, Inspect, Helicone) before the consolidation continues? Or build an internal eval framework, accepting the cost, to insulate against the next acquisition? This lesson is the strategist's decision framework for build-vs-buy at the acquisition inflection โ the moment when a category that was a healthy multi-vendor ecosystem becomes a one-vendor or two-vendor market because the frontier labs and hyperscalers are absorbing the layer. Four questions: roadmap alignment, customer overlap, license-continuity risk, build-cost-if-they-disappear. A decision tree the strategist defends in the CFO meeting. And the named cases from the first half of 2026 that show what each branch looks like in practice.
The Acquisition Inflection as a Strategic Event
The acquisition of a category-defining vendor is not just a news item the strategist reads on TechCrunch. It is a forcing function that resets the cost-of-doing-nothing on every platform decision the strategist has made over the prior eighteen months. Before the acquisition, the vendor was a healthy multi-bidder choice; the strategist could swap it out cheaply if it underperformed. After the acquisition, the vendor is either a deep strategic partner (with all the lock-in and roadmap dependencies that implies) or a stranded dependency (with all the migration cost that implies). The strategist who treats the acquisition as news and goes back to existing roadmap is the strategist whose architecture is colonized within four quarters.
The three patterns of the inflection
Inflection pattern one: frontier-lab absorption of an open-source or tooling vendor. OpenAI/Promptfoo (March 2026) is the canonical example. The pattern: a fast-growing open-source or developer-tools vendor gets absorbed by one of the labs whose models the vendor's product was used to evaluate, monitor, or develop against. The strategic logic for the lab is to lock in developer mindshare; the consequence for customers is that the vendor's roadmap converges on the acquiring lab's product strategy, and competing labs' integrations may be deprioritized or deprecated.
Inflection pattern two: hyperscaler absorption of a data, integration, or workflow vendor. Salesforce/Informatica (closed March 14, 2026, for $8B) is the canonical example. The pattern: a large incumbent platform absorbs a complementary capability vendor to fill a gap in its own agent offering. The strategic logic is to make the platform's agents more capable end-to-end; the consequence for customers of the absorbed vendor is product roadmap alignment with the acquiring platform, often at the cost of cross-platform neutrality.
Inflection pattern three: vertical-incumbent absorption of a vertical agent vendor. The Q1-Q2 2026 rollups (Thomson Reuters/LexisNexis/Clio in legal-tech, athenahealth/Waystar in RCM-healthcare, Guidewire and carrier subsidiaries in insurance-claims) follow this pattern. The pattern: an incumbent in a regulated vertical, having under-built agents itself, acquires the vendor that shipped first. The strategic logic for the incumbent is to buy years of head-start; the consequence for customers is that the vendor's roadmap aligns with the acquirer's broader product, often at the cost of cross-incumbent compatibility.
Each pattern requires a different strategist response. The decision framework below is general but the weights on the four questions vary by pattern.
The cost of doing nothing
The default response to an acquisition is to wait and see โ to keep using the vendor under its new ownership and watch how the integration unfolds. The cost of this default is rarely zero. The new owner reshapes the roadmap, often within ninety days; integration with the acquirer's products is prioritized over integration with competitors; pricing strategy resets at the next renewal; support quality often dips during integration; the smaller vendor's most senior people often leave between six and eighteen months post-close. The strategist who does nothing is choosing, by default, to accept all of these as the company's destiny.
The strategist who acts has three branches: acquire (a competing vendor in the same category while options remain), partner deeply (commit to the acquired vendor's roadmap and negotiate the integration on favorable terms now), or rebuild (against an open alternative or internal stack to remove the dependency). Each branch has costs and risks; the framework helps the strategist pick the right one for the company's specific posture.
Acquisitions are not news. They are forcing functions that reset the cost of every platform decision the strategist made. The default of doing nothing accepts the new owner's roadmap, pricing, support, and team-departure timeline as the company's destiny. Strategists who treat the inflection as a decision moment retain the freedom; strategists who treat it as news lose it.
The Four Questions That Drive the Decision
The strategist runs four questions when an acquisition inflection lands. Each has a quantitative answer the strategist commits to in writing. The four answers together determine the decision branch.
Question one: roadmap alignment
Does the vendor's roadmap under new ownership align with the company's roadmap for the next eighteen to thirty-six months? The strategist answers by asking what the acquirer's strategic priorities are and how those reshape the vendor's product direction. If the acquirer is OpenAI and the vendor is Promptfoo, the strategist predicts: tighter integration with OpenAI's developer tools, first-class support for GPT-5.x and successors, second-class or eventually-deprecated support for non-OpenAI providers, increased focus on enterprise developer use cases that align with OpenAI's go-to-market.
The strategist scores the question on a five-point scale: 1 (roadmap actively conflicts with our needs), 2 (roadmap partially conflicts), 3 (roadmap is neutral or unknown), 4 (roadmap partially aligns), 5 (roadmap actively aligns). Companies that built on Promptfoo as a multi-provider eval tool because they run agents on Anthropic, Google, and OpenAI typically score this 2-3 because the acquirer's incentives push toward OpenAI optimization. Companies that already had OpenAI as their dominant model provider typically score this 4-5 because the alignment is favorable.
Question two: customer overlap
How much of the company's existing agent infrastructure depends on the vendor? Specifically: what fraction of production agents use the vendor; what fraction of evals, traces, prompts, or workflows are stored in the vendor's systems; what would the migration off the vendor cost in engineering time; how many customer-facing contracts have terms that reference the vendor by name.
The strategist scores: 1 (vendor is critical and embedded across most agents), 2 (vendor is widely used but with internal abstractions that limit lock-in), 3 (vendor is used by some teams), 4 (vendor is used by few teams), 5 (vendor is not used or is easily replaced). Companies with most evals in Promptfoo scored 1-2; companies that used Promptfoo as one of several tools scored 3-4; companies that had standardized on Braintrust scored 5 on this question.
Question three: license-continuity risk
What is the risk that the license, pricing, or contract terms change unfavorably under new ownership? The strategist asks: is the vendor open-source under a permissive license (MIT, Apache, BSD) that the new owner cannot easily revoke; or under a license the new owner can change (MongoDB-style relicensing to SSPL has precedent); or is it commercial software whose pricing the new owner can reset at the next renewal; are there contractual price-protection terms that survive change of control; are there source-code escrow provisions that would let the company continue on the existing version indefinitely.
The strategist scores: 1 (high risk of license change or unfavorable repricing), 2 (moderate risk with limited mitigation), 3 (some risk with reasonable mitigation), 4 (low risk with strong contractual protection), 5 (essentially no risk; license cannot be changed unfavorably). Promptfoo's MIT-licensed open-source core scored 4-5 on this dimension; commercial features and hosted offerings scored 2-3.
Question four: build-cost-if-they-disappear
How much would it cost to rebuild the vendor's capability internally if it became unusable tomorrow? The strategist sizes: engineering headcount required, calendar months, third-party costs (alternative tools, services, contractors), and operational disruption during the migration. This is not the cost to migrate to a competing vendor (that is question two extended); this is the cost to build the capability from scratch on top of the open-source ecosystem or open standards.
The strategist scores: 1 (rebuilding would take more than 18 months and over $5M in engineering), 2 (12-18 months and $3M-$5M), 3 (6-12 months and $1.5M-$3M), 4 (3-6 months and $500K-$1.5M), 5 (less than 3 months and under $500K). The strategist who has scored this exercise carefully has already determined whether the company would, in extremis, survive the vendor disappearing. For most companies' eval framework needs, the rebuild score is 3-4 (Promptfoo's surface is bounded and the open-source ecosystem has alternatives); for deep integration vendors like Informatica, the score is 1-2 (rebuilding decades of integration assets is genuinely infeasible).
The decision tree from the four scores
The strategist sums the four scores and reads off the recommended branch. The thresholds are calibrated against six months of strategist case experience with the 2026 acquisitions and represent the median experience; specific company contexts shift the thresholds.
Score 16-20 (high alignment, low risk). Partner deeply. The acquisition is favorable to the company; the strategist negotiates an enterprise agreement that locks in pricing, roadmap input, and feature commitments under the new ownership. The strategist accepts the lock-in because the roadmap is aligned and the cost of switching is low. The action is to formalize the relationship at the new owner's preferred enterprise tier within ninety days.
Score 12-15 (mixed picture). Hedge. The strategist commits to the acquired vendor for the immediate roadmap but begins parallel evaluation of one or two alternatives. Internal abstractions are built or reinforced so that the company can switch within nine months if the roadmap drifts. The action is a six-month re-evaluation checkpoint with explicit go/no-go criteria.
Score 8-11 (mostly unfavorable). Migrate. The strategist commits to migrating off the vendor within twelve to eighteen months. The migration target is named (a competitor, an open-source alternative, or an internal build); the engineering plan is sized; the customer-facing impact is mapped. The action is a written migration plan with quarterly milestones, reviewed by the platform team and the CFO.
Score 4-7 (highly unfavorable). Acquire or build. The strategist either acquires a competing vendor in the same category (if one exists and is acquirable; M&A is rarely a fast option), or builds the capability internally. The decision between acquire and build depends on the size of the company, the speed required, and the existence of an acquirable target. The action is a corp-dev brief or an engineering RFP within sixty days.
The Promptfoo/OpenAI Deal Walked Through the Framework
The OpenAI/Promptfoo deal is the canonical March 2026 example. The strategist runs the framework for three different companies โ each with a different posture โ and shows how the same deal produces different decisions.
Company A: a fintech that runs agents on GPT-5.2 only
Company A built its agent platform on OpenAI from the start. All twelve production agents use GPT-5.2 or successor models. The eval framework is Promptfoo (the company adopted it in 2024). The company has approximately 800 eval cases across the agents and uses Promptfoo's CI integration to gate every prompt change.
Roadmap alignment: 5. The acquisition is unambiguously favorable; OpenAI optimization is the company's optimization. Customer overlap: 1. Promptfoo is critical and deeply embedded. License-continuity risk: 4. The open-source MIT license is durable; commercial features may reprice but the core is safe. Build-cost-if-they-disappear: 3. Rebuilding the eval framework would take 6-9 months and approximately $2M in engineering. Total: 13. Decision: Hedge. The strategist commits to Promptfoo for the next 12-18 months, formalizes an enterprise agreement on OpenAI's terms, and builds internal abstractions over the Promptfoo API so that migration to a successor (if needed) is within nine months. Six-month re-evaluation checkpoint at September 2026.
Company B: a healthcare RCM company that runs agents on Anthropic and Google
Company B chose Anthropic Claude 4.5 and Google Gemini 3 Ultra as its primary models for regulatory and uptime diversity reasons. The eval framework is Promptfoo, adopted because of its multi-provider support. The company has approximately 1,400 eval cases across nine production agents, with extensive provider-specific test cases.
Roadmap alignment: 2. The acquisition is mildly unfavorable; OpenAI is unlikely to invest in deep Anthropic and Google integration in Promptfoo going forward. Customer overlap: 1. Promptfoo is critical. License-continuity risk: 4. Open-source core is safe. Build-cost-if-they-disappear: 3. Same as Company A. Total: 10. Decision: Migrate. The strategist commits to migrating off Promptfoo within 12-15 months. Target: Braintrust (which maintains strong multi-provider neutrality) or an internal build on top of open-source primitives. Engineering plan sized at 4-6 engineers for two quarters. Customer-facing impact: none, because the eval framework is internal infrastructure.
Company C: an early-stage startup with 3 agents and 200 eval cases
Company C is small. The eval surface is bounded. The strategist runs the framework but the answers tilt toward simplicity.
Roadmap alignment: 3 (the company is multi-provider but flexible; OpenAI alignment is acceptable). Customer overlap: 2 (Promptfoo is used but the surface is small). License-continuity risk: 5 (open-source core is safe and the company would happily stay on the current version indefinitely). Build-cost-if-they-disappear: 5 (200 eval cases on 3 agents can be re-implemented in 4-6 weeks on top of the open-source Promptfoo fork or a simple in-house framework). Total: 15. Decision: Hedge (with low effort). The strategist continues to use Promptfoo, monitors the roadmap for six months, and has a low-cost migration path if needed. The action is to add a "evaluate Braintrust" item to the next quarterly architecture review and otherwise focus engineering attention elsewhere.
The lesson from three companies
The same acquisition produces three different decisions because the four scores produce three different totals. The framework is not opinionated about which decision is right; it is opinionated that the strategist must run the four questions, score them honestly, and act on the score. Strategists who run the framework for the same deal produce defensible decisions; strategists who skip the framework produce decisions they cannot defend in a CFO meeting six months later.
The CFO Meeting the Strategist Walks Into
The strategist who runs the four-question framework arrives at the CFO meeting with a one-page artifact and a defensible recommendation. The strategist who skips the framework arrives with a Slack thread and a vibe. The CFO meeting is where build-vs-buy decisions live or die; this section is the format the strategist uses.
The one-page artifact
The artifact has six elements. (1) The acquisition event in one sentence with date and price. (2) The company's exposure summary: how many agents use the vendor, how many eval cases or workflows are stored there, what the annual contract value is. (3) The four scores with brief justifications. (4) The recommended branch (Partner, Hedge, Migrate, or Acquire/Build) with one-sentence rationale. (5) The proposed action with a budget figure and a timeline. (6) The risk if the recommendation is rejected, with a quantified consequence. Six elements, one page, no font smaller than eleven point. The CFO reads it in three minutes.
The three questions the CFO will ask
The strategist prepares for three CFO questions. First: "what is the budget impact of doing what you recommend?" The strategist has the number ready โ engineering hours, contractor spend, vendor cost delta, opportunity cost on other initiatives. Second: "what is the budget impact of doing nothing?" The strategist has this number too โ the unmitigated post-acquisition cost over twelve to twenty-four months, including the silent regression from roadmap divergence and the eventual forced migration when the vendor's new owner deprecates the company's primary use case. Third: "what is the risk of being wrong?" The strategist names the two ways the recommendation could be wrong (overestimating roadmap divergence; underestimating switching cost) and shows the option-preservation in the recommendation (internal abstractions, parallel evaluation, six-month checkpoint) that mitigates being wrong.
The escalation path if the CFO declines
The strategist plans for the CFO declining the recommendation. If declined, the strategist documents the recommendation in writing, dates it, and stores it in the platform team's decision log. If the recommendation turns out to have been correct (the post-acquisition divergence happens as predicted), the dated decision log is the artifact that prevents blame from landing on the strategist and that gives the strategist standing to escalate again at the next inflection. Strategists who skip the documentation are strategists who absorb the blame for decisions they didn't make.
When Acquiring a Competitor Is the Right Branch
The Acquire branch of the decision tree is the option strategists most often misread. It is rare but not impossible. The branch is correct when (a) the company is large enough to actually execute an acquisition; (b) a credible competing vendor exists and is acquirable; (c) the strategic value of owning the alternative is significant; and (d) the company has the corp-dev capacity to integrate another vendor while also responding to the original acquisition. Most companies fail one or more of these tests, but those that pass do so decisively.
The 2026 examples that came close
Several large companies considered acquiring competing eval vendors in the weeks after OpenAI/Promptfoo. Anthropic was rumored to be in discussions with Inspect (the open-source UK-government-originated eval framework) but the talks did not progress to a public announcement by May 2026. A large hyperscaler reportedly looked at Braintrust but the price expectations did not align. The fact that these talks happened illustrates that the Acquire branch is real; the fact that they didn't close illustrates that it is rare.
The corp-dev brief the strategist writes
When the strategist recommends Acquire, the deliverable is a one-page corp-dev brief. The brief has: target company name and brief description, strategic logic (why this is the right answer to the inflection), preliminary diligence on the four DD pack categories most relevant to this specific target, estimated valuation range with supporting comparables, recommended deal structure (acquisition / acqui-hire / strategic investment with right of first refusal), and a recommended next step (preliminary outreach by corp-dev lead). The brief is the input to the corp-dev process, not the conclusion; the strategist has done the strategic-fit thinking but the deal-making is the corp-dev team's domain.
The internal-build alternative
If acquisition is infeasible, the build branch is the alternative. The strategist sizes the engineering investment, identifies the team, sets a realistic timeline (eval framework: 6-12 months for a robust version; integration platform: 12-24 months; full agent platform: 24-36 months), and presents the build-vs-acquire trade-off explicitly. The build branch is what companies above approximately 10,000 employees with sophisticated platform teams default to; the acquire branch is what companies between 1,000 and 10,000 employees with active corp-dev consider; the partner-or-migrate branches are what companies below 1,000 employees realistically have.
The Anti-Patterns Strategists Avoid
Five anti-patterns recur when strategists respond to acquisition inflections. Each has a named symptom and a named fix.
The frozen-deer response
Symptom: the strategist reads the news, calls a meeting, and the meeting concludes with "let's see how this plays out." No decision is made; the four-question framework is not run; the calendar moves on. Three months later the vendor announces a roadmap change that strands the company. Fix: the strategist commits to running the framework within two weeks of any qualifying acquisition, with a decision in four weeks.
The roadmap-faith fallacy
Symptom: the strategist accepts the acquiring company's public statements about roadmap continuity at face value ("we are committed to multi-provider support") and scores roadmap alignment higher than the strategist's own analysis would suggest. Twelve months later the multi-provider support is feature-frozen and the new owner's provider has all the new features. Fix: score roadmap alignment based on incentives, not statements. The new owner's incentives are revealed by what they pay for; statements are marketing.
The single-question dominance
Symptom: the strategist over-weights one of the four questions (usually customer overlap because it is the easiest to measure) and under-weights others. The result is a recommendation that ignores the deepest risk. Fix: weight all four questions equally unless there is a specific reason to reweight, and document the reweighting in the artifact.
The "build" overconfidence
Symptom: engineering leadership confidently scopes a 6-month build for what is actually a 24-month capability. The strategist accepts the estimate, builds the recommendation around it, and twelve months later the build is 30% complete and the original vendor's situation has gotten worse. Fix: triple any internal build estimate from engineering leadership, and benchmark the estimate against external evidence (how long did the original vendor take to build what they built?).
The serial-inflection ignorance
Symptom: the strategist responds to one acquisition (OpenAI/Promptfoo) without planning for the next two (Anthropic/[eval vendor], hyperscaler/[observability vendor]). The result is a stack that is well-positioned for the first inflection and poorly positioned for the next. Fix: every framework run produces a "what would we do if X happened" contingency for the most likely next inflection, and the platform architecture is shaped to keep that contingency cheap.
Key Takeaways
- Acquisitions of category-defining vendors are forcing functions, not news. The default of doing nothing accepts the new owner's roadmap, pricing, and team-departure timeline as the company's destiny.
- The strategist runs four questions on every qualifying acquisition: roadmap alignment, customer overlap, license-continuity risk, and build-cost-if-they-disappear. Each is scored 1-5.
- The four scores sum to a recommendation: 16-20 Partner, 12-15 Hedge, 8-11 Migrate, 4-7 Acquire or Build. Specific company context shifts the thresholds but the framework is robust.
- OpenAI/Promptfoo (March 2026) is the canonical example. The same deal produces different decisions for a GPT-5-only fintech (Hedge), a multi-provider healthcare RCM company (Migrate), and an early-stage startup (Hedge with low effort).
- The CFO meeting requires a one-page artifact: event, exposure, four scores, recommended branch, proposed action, risk if rejected. The strategist prepares for three CFO questions: budget impact of acting, budget impact of inaction, risk of being wrong.
- The Acquire branch is rare but real. It requires sufficient company size, a credible acquirable target, significant strategic value, and corp-dev bandwidth. Most companies default to Partner, Hedge, or Migrate.
- The Build branch is real for companies above approximately 10,000 employees with sophisticated platform teams. Realistic timelines: 6-12 months for eval frameworks, 12-24 months for integration platforms, 24-36 months for full agent platforms. Triple every engineering estimate.
- Five anti-patterns: frozen-deer response, roadmap-faith fallacy, single-question dominance, "build" overconfidence, serial-inflection ignorance. Each has a named fix.
- The strategist documents every recommendation in writing in the platform team's decision log. If the CFO declines, the dated artifact is what gives the strategist standing at the next inflection.
- Every inflection response includes a contingency for the next likely inflection. The strategist who responds well to one acquisition and poorly to the next has done half the job.
Skill.re