One-third of companies skipped a software purchase this year because an AI coding agent could build the equivalent in-house. That is the headline from McKinsey’s State of AI 2026 survey — and it is the most consequential finding for developers this week. Not because the 32% figure is impressive, but because of what the report buries: a 44% AI code security failure rate, a 40% agentic project cancellation forecast, and a run-cost trap most teams will not see coming until year two.
What McKinsey Actually Measured
The survey covered 1,719 organizations across 97 countries and asked whether they had decided against purchasing at least one software product because agentic coding tools could build it internally. Thirty-two percent said yes. In the technology sector, the rate hit 41%. Among organizations McKinsey classifies as “high performers” — the 6% that attribute at least 5% of EBIT to AI — the figure approaches 50%.
That is a forgone purchase, not a cancelled contract. It is a narrower signal than the headline implies, but it is real: AI coding agents are entering budget conversations they did not belong in two years ago.
The Execution Gap Nobody Talks About
Here is the part that should give developers pause. Eighty percent of organizations report individual productivity gains from AI. Only 37% report any measurable EBIT impact — and that number has not moved year-over-year. McKinsey’s own framing: “Organizations’ conviction in AI is growing faster than the immediate financial returns they can attribute to it.”
The project-level data is worse. Gartner projects that more than 40% of agentic AI projects will be cancelled by end of 2027 due to escalating costs, unclear business value, and inadequate risk controls. Deloitte’s 2026 enterprise survey found only 11% of organizations have production-ready agentic systems. The build trend is accelerating faster than the ability to execute it.
The Run-Cost Trap
This is the most important thing the McKinsey headline does not tell you. Cancelling a SaaS renewal to build in-house does not eliminate maintenance costs — it converts a vendor line item into a payroll line item where nobody will audit it against the original savings justification.
Peer-reviewed software economics research puts ongoing maintenance at roughly 90% of a product’s lifetime cost, with annual upkeep running 15–25% of the original build cost. One in five organizations already report that AI operating costs — primarily token bills — are constraining their use of the technology. Among the heaviest builders, that constraint hits three times more frequently than it does for their peers.
The math works until it does not. A prototype built in a week can cost more per month to run and maintain than the SaaS contract it replaced, once you account for model API costs, security remediation, and the engineering hours that do not show up in the original build estimate.
The Security Floor
Veracode’s 2026 GenAI Code Security Report tested more than 100 AI models across standardized code-generation tasks. The average security pass rate: 56%. That means 44% of AI code-generation tasks introduced a security vulnerability in testing. The rate has barely moved from 55% the previous year. Java sits at 30%. Code that compiles and runs is not code that is safe to ship.
Vendor SaaS products absorb established security programs, compliance certifications, and liability. Internal builds carry the full burden. If your organization is building with agents and does not have mandatory static analysis and human security review as a gate — not a suggestion — your run cost includes the security incident you have not had yet.
When to Build, When to Buy
The McKinsey data is not an argument to stop building. It is an argument to build deliberately. High performers — the ones actually translating AI to profit — redesign workflows before tooling decisions, not after. They require named ownership for years 2–5, not just for the launch sprint. They model token costs at steady state, not at proof-of-concept load.
Before cancelling any software renewal, require answers to five questions:
- Is this a proprietary differentiator or a commodity function?
- What is the token bill at steady state, not build cost?
- Who owns maintenance in 18 months — name, team, budget line?
- What replaces the vendor’s security infrastructure?
- Does IT governance cover this build with audit trails and agent decision boundaries?
The sectors with the lowest build rates — insurance at 19%, public sector at 17% — are not falling behind. They are making rational decisions about compliance costs. FedRAMP authorization at Low impact level runs $250,000 to $500,000 to obtain. Vendors absorb that cost. Internal teams cannot escape it.
The Bottom Line
Aggregate software spending hit $1.468 trillion in 2026 — up 15.5% year-over-year — so this is not a market collapse. It is a reallocation. The developers who benefit from this shift are the ones who can make the build-vs-buy case with run-cost math, not just proof-of-concept demos.
Thirty-two percent of companies skipped a software purchase this year. A meaningful number of them will regret it by 2027. The question for every developer in that conversation is whether you are the one who flagged the maintenance economics before the decision was made — or the one who is still explaining them after the project gets cancelled.













