Home Services About Blog Contact 📞 1-800-890-6133

Custom AI Is a Permissions Project

By Brian Shad  ·  Pro Link Systems  ·  October 07, 2026

Every few weeks an executive asks some version of the same question: should we build our own AI, or buy what Microsoft is already selling us? It was a sharp question in 2023. In 2026 it has quietly stopped being the right one — not because the answer changed, but because the thing being bought changed underneath it.

The shift, offered as analysis rather than fact: the model is no longer the product. It is the most interchangeable component in the stack. What you are actually purchasing — and what you will pay for, argue about, and maintain — is everything attached to it.

Nobody in the 20-to-500 seat range is training a model

"Custom AI" has always been a misleading label for mid-market work. No business of this size with a real P&L is pretraining a frontier model, and that was true three years ago. It is more true now, with capable models available on tap from Microsoft, Google, OpenAI, and Anthropic.

So when a proposal lands on your desk describing a custom AI solution, read it for where the hours go. They do not go into intelligence. The hours go into four places: connecting the system to your data, defining what a correct answer looks like, testing whether it keeps producing one, and keeping the arrangement working when the underlying model is updated on the vendor's schedule rather than yours.

That last item carries more weight than it usually gets. A vendor can improve a model and change the behavior your workflow depends on in the same release. Build a process on one model's particular habits and you have taken on a maintenance obligation that looks less like buying software and more like running software. That is a staffing question before it is a technology question.

Custom in 2026 means your documents under your permissions

Strip away the vocabulary and most custom AI work in the mid-market is the same project. Take a capable general model. Point it at your own content — contracts, tickets, proposals, SharePoint, the shared drive nobody has pruned since the last office move. Make it answer questions about that content.

The system therefore inherits your permissions model. Whatever a user can already open, the assistant can read on their behalf and summarize in seconds. This is the design working correctly. It is also the part that surprises executives.

Most organizations have an access control problem they have never had to confront, because finding the wrong file used to require knowing it existed. Picture a compensation spreadsheet sitting in a Teams site that someone opened to everyone in the organization during a project nobody remembers. Nothing was breached. The exposure was real and invisible at once, protected entirely by obscurity. Natural-language retrieval removes the obscurity. Ask a direct question and the assistant will surface what your permissions allow it to surface.

Which is why the first real deliverable of a serious AI deployment is usually not a model. It is a permissions audit, a sharing-link cleanup, and a sensitivity labeling scheme across Microsoft 365. Unglamorous work, invoiced as infrastructure, and in our judgment the highest-leverage move available before anything gets deployed. Identity is the perimeter now, and an assistant with search is the most efficient test of that perimeter ever installed inside a business.

Off-the-shelf does not remove governance, it scatters it

The buy side carries a cost that rarely appears in the comparison. Assistants are arriving inside software you already own: the CRM has one, and so does the accounting platform, the e-signature tool, the project tracker, the phone system, the HR portal. Each arrived by update rather than by decision, each processes your data somewhere, and each came with terms a procurement review from two years ago had no reason to anticipate.

You did not choose an AI strategy. You accumulated several, one release note at a time.

The governance question is not whether AI is in the business. It is whether you can say where your data goes when an employee presses the summarize button in a tool you had forgotten you were paying for. Third-party risk used to mean vendors who could take you offline. It now also means vendors who have quietly become processors of your most sensitive internal text. Reviewing that surface is ordinary cybersecurity work, and it belongs on a schedule rather than in a memory.

Shadow AI is the same problem with a worse ending. When sanctioned tools are slow or restricted, people paste into whatever is open in another tab. The remedy is rarely a stricter policy. It is a sanctioned tool good enough that the unsanctioned one stops being tempting, paired with enough visibility to know the difference.

Four questions that settle build versus buy

Set aside the vendor framing. These are the questions worth asking in a leadership meeting, and the honest answers usually point in one direction quickly:

None of the four is about the model. That is the point.

Rent the intelligence, own the plumbing

Here is the reframing worth taking into your next leadership meeting. Buy the model, because you cannot win that race and have no need to enter it. Own your data, your permissions, your identity controls, and your record of where information flows. Treat the integration layer, not the model, as the thing that is genuinely yours — and govern both deliberately rather than by exception.

For most Los Angeles businesses the honest next step is less exciting than an AI strategy and considerably more valuable. Find out who can see what. Clean it up. Instrument it. Then deploy an assistant into an environment where any answer it produces is one you would have been comfortable with a person finding manually.

There is a sequencing argument underneath all of this, and it is analysis rather than a promise: organizations that do the access work before deployment are not discovering their permissions problems in production, in front of staff, with a model doing the discovering.

Pro Link Systems has supported Los Angeles businesses from Woodland Hills since 1999, long enough to recognize a familiar pattern. New technology rarely creates problems. It reveals the ones already in place, faster than the old tools ever could. Our in-house, US-based IT support team fields the questions that follow.

If you would rather handle the permissions and data-governance groundwork before an AI deployment than after one, that work sits inside our managed IT services.

Ready to talk to a real IT engineer?

Pro Link Systems has been protecting and managing IT for Los Angeles businesses since 1999. Book a free 15-minute discovery call — no pressure, no obligation, no scripts.