Let’s give credit where it’s due. The Department of Defense has finally begun doing what tech leaders inside and outside of government have been pushing for years: buying technology that works instead of wasting time and money building less effective solutions from scratch.
For too long, government teams have defaulted to building software in-house. The logic has always been the same: if we build it ourselves, we’ll have more control, more security, more alignment with mission needs. In reality, what agencies often end up with is a tool that lags years behind commercial capabilities, costs ten times more to sustain, slows operations, and never truly scales.
By leveraging commercial off-the-shelf (COTS) solutions that already meet the highest standards for security, compliance, and mission readiness. Defense leaders are proving that they’re serious about speed, performance, and impact. We’ve seen this in action with the rollout of secure generative AI platforms now being made available across Combatant Commands, the Joint Staff, and the Office of the Secretary of Defense—not as pilots, but as operational infrastructure. That kind of scaled enterprise-grade adoption is exactly what it looks like when COTS is treated as a strategic asset, not an afterthought.
For decades, agencies have treated innovation as something that had to be built from scratch to be taken seriously. But the landscape has changed: the private sector has moved faster, spent more, and hired thousands of the best engineers to solve the exact problems the government now faces. There is no shame in leveraging that. In fact, it’s the only responsible path forward.
The best COTS solutions outperform custom builds because they’re continuously tested, professionally maintained, and built with robust security from the start. When agencies select commercial platforms that meet the highest government standards like FedRAMP High, IL5, IL6, and Top-Secret authorizations, they’re not taking a risk; they’re making the smart choice. These capabilities aren’t theoretical. They exist now and they’re exactly what mission-ready AI requires. Yet, some agencies still choose to reinvent the wheel.
Why does this keep happening? Most often, it’s ego. The “not invented here” mindset is still alive and well—the belief that if a tool wasn’t built internally, it can’t possibly meet the mission. Add to that a laundry list of requirements that are rarely revalidated or challenged, and it’s no surprise agencies struggle to find a good fit. In many cases, the problem isn’t the technology. It’s that no one stops to ask if the requirements themselves still make sense. The result? Agencies spend taxpayer dollars reinventing tools that already exist, while the mission waits.
Let’s be honest: most in-house AI tools aren’t built to last. They get just enough support to launch a “pilot,” just enough funding to say progress has been made, and then they stall. There’s no path to scale, no long-term roadmap, no support team keeping the lights on.
Commercial solutions, on the other hand, are sustained by revenue, not one-time budgets. They raise capital, drive innovation through market demand, and continuously improve by aggregating feedback and features across hundreds of customers. That scale lowers costs, adds value, and ensures the product evolves with its users.
There’s also a policy problem, or more accurately, a policy avoidance problem. The rules already exist. FAR Part 12 requires agencies to prioritize commercial solutions. Executive orders reinforce that mandate. This isn’t a gray area. And yet, agencies still ignore the law and build from scratch, often under the cover of experimentation. Let’s stop pretending these are pilots. If you’ve rolled it out, funded it, and expect people to use it, it’s not a pilot. It’s production. And it needs to follow the same rules as everything else.
To their credit, DoD leaders are waking up to this. They’ve seen the downside of shadow IT and the upside of real, secure AI infrastructure. They understand that the mission doesn’t slow down to wait for a software sprint. They’re choosing tools that deliver impact now, not someday.
That’s the model we must replicate across the federal government. Commercial vendors have already made the investment. They’ve already solved the hard problems. They’ve already earned the certifications. Why spend taxpayer dollars duplicating what’s already working?
We also can’t keep saying we’re worried about the shrinking Defense Industrial Base while actively undermining it. When agencies choose to build instead of buying, they send a message to startups and innovators that the investment in FedRAMP, ATO, and years of compliance work isn’t worth it. If the government competes with its own vendors, it will slow innovation and drive the most capable players out of space entirely.
When the mission is on the line, agencies need technology that works. The Department of Defense has shown what forward motion looks like. The rest of the government should follow their lead.
The author, Nicolas Chaillan, is Founder & CEO of Ask Sage.
