Today, nearly every major bank in Latin America has some generative AI initiative underway. The question is no longer whether to use it, but how: with a proprietary model or with a third-party provider’s?
The uncomfortable question
Three years ago, the debate was whether generative AI was even relevant to banking. That discussion is closed: according to a global NVIDIA survey (2024), 78% of financial institutions worldwide have active projects. The conversation has shifted to more uncomfortable ground: which model do we work with, and who controls it?
Deciding between building a proprietary model or contracting an external one — like GPT, Claude, or Gemini — is a strategic decision, not a technical one. It means taking a position on data control, competitive advantage, long-term costs, and regulatory scrutiny. And in banking, where customer data is both the most valuable and the most sensitive asset, the answer carries more weight than in any other industry.
What it costs to build
Training a model from scratch is out of reach for almost any bank. The compute power alone to train GPT-4 cost between 50 and 100 million dollars, according to Epoch AI estimates. Add to that the specialist team, the data infrastructure, and ongoing maintenance.
But “building” comes in degrees. Most institutions that claim to have a “proprietary model” are actually adapting an open model — like Llama or Mistral — with their own data. That’s a reasonable option for specific cases: regulatory compliance, contract analysis, or customer service in regulated language. That kind of adaptation can start at around 50,000 dollars, far less than training from scratch. The trap is the cost of keeping it running: according to Andreessen Horowitz (2024), 80% of a model’s total operating cost comes after launch.
What it costs to buy
External models are quick to deploy, accessible, and improve on their own: the provider updates them and the bank gets the improvement for free. Rollout is measured in weeks, not months.
The problem isn’t the price, which keeps falling, but where the data goes. When a bank queries an external model, it sends information about its customers, processes, and products to a third party’s infrastructure. For many regulators in the region, that’s a problem: Brazil’s Central Bank, Mexico’s CNBV, and Colombia’s SFC are already working on rules governing the use of AI providers, and the handling of sensitive data is the point of greatest tension.
The other risk is provider dependency. If the provider changes its pricing, retires a version, or suffers an outage, a bank that built its customer service on that model has no immediate backup plan. A McKinsey study (2024) found that 60% of companies that adopted external models reported concerns about their long-term operational continuity.
The approach that’s winning: hybrid
The most sophisticated institutions don’t choose between building and buying: they combine both. General tasks — summaries, drafting, analysis of public documents — run on external models, with no sensitive data involved. Customer data processing — transactions, credit evaluation, fraud detection — runs on proprietary or adapted models, within the perimeter the regulator requires. And the real differentiation lies in the layer that decides which model handles which task.
BBVA, for example, has agreements with OpenAI while also developing internal models for regulated use cases. JPMorgan combines proprietary and external models depending on data sensitivity across more than 300 use cases. In Latin America, banks like Itaú and Bancolombia are moving down the same path, though at a smaller scale.
The question that matters
The decision isn’t answered in the abstract, but case by case, with three questions: how sensitive is the data involved? How much real competitive advantage does a proprietary model actually generate? Is there a team in place to sustain it over time?
For most banks in the region, the honest answer is: buy for general uses, adapt a proprietary model for regulated and sensitive cases, and build from scratch only if the data and the business case justify it. The danger isn’t getting it wrong at the start — that can be corrected. The danger is locking into an architecture that can’t evolve.
In AI, the model in use today probably won’t be the one in use in 18 months. The advantage doesn’t come from the model itself: it comes from the ability to adopt, integrate, and improve faster than everyone else.

