Compute & Cost
When Not to Buy AI: A Cost Argument
· 11 minute read
An agent is a recurring cost with a threat surface. If the work is a lookup, a stamp or a queue, buy the lookup. Do not buy a model so the minutes can say AI-enabled.
A directorate in a western state put eight lakh rupees a month on a hosted model so a helpdesk could 'answer scheme questions'. The questions were twenty-two. The answers already lived on a static page that STQC had certified the year before. After eleven weeks the CIO asked for the deflection number. The vendor sent a token graph. The call centre still took the same calls. The tokens were being spent on officers pasting the same FAQ into a box because the box felt modern.
That is not an argument against intelligence. It is an argument against buying a furnace to warm a cup of tea. Government work has many cups of tea. Some of them are genuinely hard: multilingual case reconstruction, messy annexures, officers drowning in unstructured mail. Many of them are a register, a stamp, a search box, or a clerk who already knows the circular.
This is a cost opinion for CIOs and finance controllers who are being asked to 'do AI' before anyone has written the unit of work. It is written on 17 August 2026 for Indian departments, PSUs and campuses. It is not legal advice and it is not a GFR interpretation. Prcept AI builds on-prem and air-gapped agents at prcept.com. We still tell buyers not to buy us when the file is a lookup.
The India AI Governance Guidelines that MeitY released on 5 November 2025 talk about innovation over restraint as a sutra. They do not instruct you to rent a model for every queue. A guideline is not a purchase order. A purchase order still has to survive GFR propriety and a later audit paragraph about avoidable expenditure.
The unit of work is the budget
Start with the unit, not the model. A unit is a closed piece of work a stranger can count: a grievance classified, a circular found, a draft noting prepared, a certificate checked against a rule, a ticket closed without a second human. If you cannot name the unit, you cannot name a cost. You can only name a feeling.
Then price the current unit. Include the officer's loaded cost, the queue delay, the error that creates a rework, and the complaint that creates a VIP reference. Do not romanticise the as-is. Clerks are expensive when they are scarce. Clerks are cheap when the work is already a stamp.
Then price the proposed unit. Include licence or token, retrieval estate, evaluation, human review, logging that meets the CERT-In 180-day floor in Indian jurisdiction, a security review, and the meeting time you will spend explaining the agent to audit. If the proposed unit is not cheaper, faster, or less error-prone on a number you can defend, you are buying a press note.
| The job as sold | What it actually is | Cheaper object |
|---|---|---|
| AI-powered scheme explainer | Twenty static FAQs | A certified page plus a search box |
| Intelligent file movement | A status field nobody updates | A mandatory status in the existing MIS |
| Generative noting assistant | Copy-forward of last year's note | A template with three blanks |
| Citizen voice bot | IVR with a language problem | A short form and a callback slot |
Recurring cost is the real one
Capital is visible. Recurring is where files die. A hosted model is a meter. An on-prem model is power, cards, a person who can restart a node, and a patch clock. Both are fine when the unit pays for them. Both are waste when the unit is a lookup.
Add the hidden recurring lines that vendor decks treat as someone else's problem: prompt and policy versioning, eval on a hold-out set after every change, red-team hours before a public URL, PII redaction in logs, and the officer who must still sign. Human-in-the-loop is not free. It is a second pass with a nicer font.
Denial of wallet is the ugly twin of recurring cost. A citizen-facing box on a metered API can be flooded. A helpful officer can paste a hundred-page PDF into a hosted context window because nobody set a cap. Those are not model failures. They are budget failures with a security accent. Price the cap before you price the model.
When the model is the wrong shape
Do not buy generation when you need retrieval. If the officer's question is 'where is the 2024 circular', a full-text index with access control is the product. A generator that paraphrases the circular will eventually paraphrase it wrong, and you will pay for the paraphrase and the correction.
Do not buy an agent when you need a workflow. If the work is 'if income certificate older than the cut-off, reject', a rule in the existing MIS is the product. An agent that 'reasons' about staleness will invent a vibe. Rules are boring. Boring is how public money is supposed to move.
Do not buy a multimodal spectacle when the paper is already a PDF with a barcode. Optical character recognition plus a validator is older than the current fashion and often more honest. Fashion is not a GFR category.
- Lookup, not synthesis: buy search.
- Branching rule, not judgement: buy a form.
- Queue, not conversation: buy a slot.
- Translation of a fixed glossary: buy a glossary engine, not an open chat.
- High-stakes write to a register: do not buy an agent until the threat model is written.
When the cost case is real
There are rooms where an agent earns its keep. A state scholarship cell drowning in unstructured annexures, where officers already spend twelve minutes finding the right circular for each file, can win if retrieval is logged and the officer still signs. A campus helpdesk that answers the same eight hundred variants of 'when is the exam form' in three languages can win if the corpus is owned and the model cannot invent a date.
The test is still the unit. Measure twelve minutes becoming four, with a hold-out of real files, not a vendor demo. Measure rework down, not tokens up. If you cannot run that measurement on your own documents, you are not ready to buy. You are ready to run a two-week time-and-motion study, which is cheaper than a year of GPU rent.
Prcept's own bias is on-prem and air-gapped agents that do not train on your cases. That bias does not make a bad unit good. If your unit is a stamp, we will say so in the first meeting. A vendor who never says no is pricing your vanity.
The minutes problem
The worst cost cases start in a review meeting. Someone says the ministry has asked for AI. Someone else writes AI-enabled into the minutes. Procurement then has to find a thing that can be called AI. That is how eight lakh a month lands on twenty-two FAQs.
Write a different minute. 'We will not buy a model until the unit of work, the as-is cost, and the proposed cost are on one page.' That sentence is cheaper than any platform. It also survives a CAG question about why public money rented a chatbot to recite a page you already hosted.
Innovation over restraint is a design culture. It is not a waiver of propriety. If the cheaper object exists, the AI purchase needs a reason that is not embarrassment.
Objections you will hear — and what to do with them
These are the lines that stall the file. Answer them in the room, then put the answer in the note. A spoken answer without paper will be forgotten by the next officer.
If we do not buy AI we will look backward.
Looking backward is cheaper than looking foolish in an audit para. Publish the unit page. If a later year the unit changes, buy then. Fashion is not a performance indicator.
The model is cheap per token.
Per-token is not the cost. Review, eval, logging, security, and the officer's second pass are the cost. A cheap token that creates a wrong speaking order is the most expensive token you will buy.
We can start small and expand.
Starting small is correct when the small thing has a unit. Starting small on a vague assistant is how meters run while nobody owns a number. Write the stop rule on day one: if deflection is below X after six weeks, we cancel.
Leadership has already announced it.
Then buy the smallest honest object that makes the announcement true: a retrieval box over public circulars, no personal data, a hard spend cap. Do not launder a bad unit through an announcement.
A two-week 'do not buy' test
Run this before a demo. Demos create commitment. Commitment creates invoices.
- Day 1–2: write the unit in one sentence. If two officers write different sentences, you do not have a unit.
- Day 3–5: time twenty real cases as-is. Use a watch, not a workshop.
- Day 6–7: price the cheaper object — search, form, template, extra clerk, callback slot.
- Day 8–10: if you still want an agent, write the proposed unit cost including review, logs, eval and a spend cap.
- Day 11–12: write the stop rule and the threat-model one-pager. No write tools unless the threat model exists.
- Day 13–14: take both pages to finance. If they cannot mark a number, do not buy.
How this shows up in the file
Subject: Decision not to procure a generative assistant for [workflow] — cost note.
The unit of work is [one sentence]. Twenty timed cases show an as-is cost of [₹ / minutes]. The cheaper object is [search / form / template / staff]. A generative or agentic purchase would add licence or tokens, evaluation, CERT-In-aligned logging, and a human review pass. No measurable unit improvement has been shown. We will not issue an RFP for this workflow. If a later measurement changes the unit, this note will be revised.
This note is an internal aid. It is not legal or procurement advice. It is the page that should have existed before the minutes said AI-enabled.
This article is informational field guidance for Indian public institutions, not legal, procurement, security-accreditation or engineering advice. Confirm against the current Gazette, GFR, GeM term, CVC instruction, CERT-In direction, DPDP text, departmental manual and your counsel before you file it.
Questions this usually raises
- Is this an argument that government should never buy AI?
- No. It is an argument that you should buy a unit of work, not a fashion. Ugly retrieval over messy files can win. A chatbot that recites a page you already host usually loses.
- Does GFR forbid experimental AI spend?
- GFR requires propriety and financial prudence. It does not name models. A small, time-boxed experiment with a stop rule is easier to defend than an open-ended assistant with no unit. Ask finance and counsel; this is not a ruling.
- What if the cheaper object is politically unacceptable?
- Then buy the smallest honest AI object that still has a unit and a cap, and write that politics — not the unit — drove the extra spend. Honesty in the file is cheaper than a later fiction.
- Are on-prem agents cheaper than hosted APIs?
- Sometimes, at volume, if you already have the rack and the people. Sometimes not. That is a TCO question, which is the next article. Cheap tokens with egress and a meter can become the expensive option overnight.
- Who should own the 'do not buy' decision?
- The programme owner writes the unit. Finance marks the number. The CISO marks undeclared tools. The CIO signs the note. A vendor should not own the no.
- How does Prcept handle a 'do not buy' conversation?
- We would rather lose a bad unit than inherit a file that cannot be defended. If the work is a lookup, we will say so. If the work is messy retrieval with a tiny write surface, we will talk about an on-prem agent that you can turn off.
Sources
- Department of Expenditure — General Financial Rules, 2017
- Department of Expenditure — Delegation of Financial Powers Rules, 2024
- Digital Personal Data Protection Act, 2023 (India Code)
- India AI Governance Guidelines (PIB document, November 2025)
- CERT-In Directions under Section 70B, 28 April 2022 (PDF)
- Prcept AI — on-prem / air-gapped agents