How to Choose Between Fixed-Scope, Managed Appliance, and Co-Build Contracts for a Private LLM

Compare fixed-scope builds, managed appliance subscriptions, and co-build engagements for a private LLM, with price ranges, risk allocation, and exit terms.

Nate Nead9 min read
A brass balance scale weighing a server appliance against a stack of bound contracts on a boardroom table.

Most CISOs walk into a private LLM procurement assuming the contract shape is a formality: pick a vendor, sign an SOW, wire the money. The pricing question feels bigger than the commercial-model question. It is not. The structure you sign under decides who eats the cost of a bad assumption, who owns the weights when the relationship ends, and whether your compliance team can actually attest to what the model does in production.

Three structures dominate the market right now for private LLM work: a fixed-scope build, a managed appliance subscription, and a staff-augmented co-build. Each is defensible. Each fits a specific procurement posture. Getting the match wrong is the most expensive line item most buyers never see.

Why the Contract Shape Matters More Than the Sticker Price

The base rates for private LLM work are converging. Entry-level deployments of 7B to 13B models on a single high-memory GPU run roughly $600 to $3,000 per month, while 30B to 70B setups on 4–8 GPUs land between $15,000 and $40,000 per month. Those are hosting numbers. They do not include the build. Regulated-industry customization typically adds $200,000 to $600,000 to baseline build costs, and a fine-tuning engagement often absorbs four to six engineers for three to five months at $500,000 to $900,000 in talent alone.

Where projects actually fail is not the hardware line. It is the assumption line. MIT's Project NANDA report on the state of AI in business found that despite $30 to $40 billion in enterprise generative AI spending, roughly 95% of organizations were seeing no measurable business return, with only about 5% of integrated pilots extracting significant value. RAND's review of more than 2,400 enterprise AI initiatives puts the failure rate near 80%, about twice the failure rate of typical IT projects. The contract is where you decide who absorbs that risk.

The Cost Envelope for a Private LLM Engagement
$3,000
Entry-tier hosting (7B-13B)
Upper bound, per month
$40,000
Mid-tier hosting (30B-70B)
Upper bound, per month
$600,000
Regulated build add-on
Upper bound, one-time
$900,000
Fine-tuning engagement
Upper bound, talent only
Four figures a private LLM buyer will see, at the top of each published range. Source: Aimprosoft & TechAhead, 2025-26

Fixed-Scope Build: When the Requirement Is Actually Fixed

A fixed-scope build is a turnkey engagement. The vendor commits to a defined deliverable, a defined date, and a defined price. You get a running model, an evaluation harness, an audit trail, and a handover. For a well-bounded use case — a claims-triage assistant on a known corpus, a contract-clause extractor, a specific RAG pipeline over a stable data source — this is the cleanest instrument on the table.

The pricing math is straightforward but rarely cheap. Expect the vendor to load a contingency reserve into the number: fixed-price software contracts typically include buffers of 15% to 30% or more for unknowns, which the client pays regardless of whether the risks materialize. That premium is the price of a predictable line item on next year's budget.

The failure mode is scope drift. A 2017 study in the International Journal of Project Management linked fixed-price contracts to a higher risk of project failure than time-and-materials arrangements. LLM work is unusually vulnerable to this because the evaluation criteria change as stakeholders see early outputs. A hallucination that looked acceptable in the SOW becomes a P0 in demo week. Every change becomes a change order, and change orders carry their own margin.

Sign a fixed-scope build when your data is stable, your evaluation criteria are written down and approved, and your legal team needs a single deliverable to attest to. Insist on: named acceptance tests, weight and artifact ownership on delivery, source access to fine-tuning datasets, and a defined post-acceptance support window. If you cannot describe the pass/fail state of the model in a paragraph, you are not ready for this structure. Reading why most open source AI pilots fail before scoping is worth the hour.

Managed Appliance Subscription: Buy the Outcome, Rent the Perimeter

A managed appliance subscription reframes the deal. Instead of buying a project, you buy a running system: hardware (or a VPC image), a chosen model, the update cadence, monitoring, and an SLA. The vendor operates it inside your network perimeter. You consume it. Commercially, it looks like a managed service agreement layered onto a piece of physical or virtual infrastructure — closer to a LLM appliance lease than a build contract.

This is the structure that has been maturing fastest. Hardware like the NVIDIA DGX Spark, with 128 GB of unified memory and a petaflop of throughput, can fine-tune open-source models up to roughly 70B parameters locally, which makes a self-contained appliance genuinely viable in a compliance closet rather than a datacenter. The commercial model follows: a monthly fee that bundles the box, the weights, the observability stack, and remote operations, typically with a one-to-three-year term.

A rack-mounted server appliance in a glass-walled compliance closet with a single cable running out.

Risk allocation flips versus fixed-scope. The vendor carries model performance, uptime, and drift management. You carry data governance, prompt design, and use-case fit. That is usually the right split for teams that do not want to run a full MLOps function but do need weights and logs to stay on their side of the firewall. The tradeoff is optionality: you are on the vendor's release schedule and their model catalog. If they discontinue support for the base model you fine-tuned on, you renegotiate.

Exit terms are where these contracts live or die. Demand three things in writing: an egress clause that gives you weights, adapters, and vector indexes in a portable format at termination; a data-destruction attestation with a defined SLA; and a right to run the appliance in read-only mode for a wind-down period. Without those, the "managed" part becomes lock-in. The general shape of a defensible managed services agreement is well-documented in the managed services agreement guide that most enterprise procurement teams already work from.

Where Each Contract Structure Lives
Where Each Contract Structure LivesFixed-scope build: 25; Managed appliance: 55; Co-build engagement: 85; Public API subscription: 15Scope flexibility →Buyer governance load →12341Fixed-scope build2Managed appliance3Co-build engagement4Public API subscription
Illustrative positioning: how much scope change each structure absorbs, versus how much day-to-day management the buyer takes on. Illustrative: a visual comparison, not measured data.

Co-Build Engagement: Staff Augmentation With Shared IP

The co-build is the model most first-time buyers underestimate. The vendor provides senior engineers — model, MLOps, security, evaluation — who work under your technical leadership alongside your team. Billing is time-and-materials or a monthly retainer. Deliverables are agreed sprint by sprint, not up front. Intellectual property terms explicitly contemplate joint work.

This structure is right when the requirement is genuinely emergent. If you are building an private AI agents platform that will touch a dozen internal systems, or standing up an AI center of excellence, you cannot write a fixed SOW for it. The scope changes every sprint because the organization is still learning what the model should do. A co-build absorbs that reality instead of fighting it.

The commercial risk is different, not lower. You are paying for hours, so governance is your job. Weekly demos, a defined burn rate, and a hard ceiling per phase are the difference between a co-build and an open-ended consulting drip. Retainer-based dedicated teams commonly run several thousand dollars per engineer per month at the low end and into five figures for senior specialists, so a four-person squad is a real line item. The upside is that scope changes cost hours, not change orders, and the team accumulates institutional context that a turnkey vendor never will.

The clause that matters most is IP allocation. Joint development creates joint-invention risk, and the standard Hogan Lovells guidance on IP ownership in collaborative agreements is a good starting point for legal review. For LLM work specifically, the terms need to name: who owns the fine-tuned weights, who owns the training corpus derivatives, who owns the evaluation harness, and who can reuse pipeline code. Silence on any of these gets ugly at renewal.

Matching the Contract to Your Procurement Posture

The choice is less about the technology and more about what your organization can absorb.

  • Fixed-scope build. Right when scope is stable, evaluation criteria are written, and finance wants one number. Wrong when the use case is exploratory, because every discovery becomes a change order.
  • Managed appliance. Right when the compliance function needs the perimeter but the internal team does not want to run MLOps. Wrong when you need bespoke fine-tuning on a non-standard base model or when your data governance forbids any vendor operator access, even remote.
  • Co-build engagement. Right when the roadmap is emergent, when you already have engineering leadership, and when institutional context matters more than a deliverable. Wrong when your team lacks the bandwidth to govern a shared squad, which turns time-and-materials into a slow leak.

Most mature buyers end up in a hybrid. A common sequence: a short co-build to characterize the problem, a fixed-scope build to ship the first production workload, then a managed appliance to run it. That progression matches how most enterprises are still stuck at pilot stage rather than scaled deployment, and it lets the contract structure change as the organization's certainty about the use case improves.

A Common Multi-Phase Path
A Common Multi-Phase PathCo-build discovery sprint: 1 mo; Fixed-scope build of first workload: 4 mo; Production cutover: 9 mo; Managed appliance subscription begins: 10 mo; Annual renewal & scope review: 22 mo1 moCo-build discoverysprint4 moFixed-scope buildof first workload9 moProduction cutover10 moManaged appliancesubscriptionbegins22 moAnnual renewal &scope review
Illustrative: many enterprises change contract shape as their certainty about the use case improves. Illustrative: a visual comparison, not measured data.

What to Put in the Contract Regardless of Shape

Three provisions belong in every private LLM contract, no matter which structure you sign under. They are the difference between a system you operate and a system that operates you.

First, weight and artifact ownership. Name the deliverable set explicitly: base model, adapters, quantized variants, RAG indexes, evaluation datasets. State that ownership transfers on payment, and specify the export format. Public API vendors do not offer this. Private deployments should.

Second, audit and observability access. Your control plane must log every inference, every retrieval, and every fine-tuning run in a format your SOC 2 or HIPAA auditors can read without vendor mediation. This is a hard requirement for SOC2, HIPAA, and GDPR compliance, not a nice-to-have.

Third, a clean exit. Data destruction with attestation, weight portability, a defined transition-services period, and no residual license claims on your fine-tuning corpus. If the vendor will not sign this, choose another vendor.

The Decision Under the Decision

The contract shape is a bet on how much you already know about the workload. A fixed-scope build says the requirement is knowable today. A managed appliance says the operation is the hard part. A co-build says the answer will emerge from the work. All three are honest positions. The mistake is signing one shape while believing the other — buying a fixed-scope build for an exploratory problem, or a co-build for a well-specified one.

Read your own certainty first, then price the contract that fits it. The private LLM market has enough vendors, enough hardware, and enough open-weight models that you no longer have to accept a structure that fights your procurement posture. The leverage is in matching them.

Enterprise AI: Adoption vs Returns
Enterprise AI: Adoption vs ReturnsPilots seeing significant value: 5; Pilots with no measurable return: 9595%Pilots seeing significant value5 · 5.0%Pilots with no measurable return95 · 95%
MIT's GenAI Divide report: the share of integrated enterprise AI pilots extracting significant value. Source: MIT Project NANDA, 2025
// written by
Nate Nead

Nate Nead is the founder and CEO of Marketer, a distinguished digital marketing agency with a focus on enterprise digital consulting and strategy. For over 15 years, Nate and his team have helped service the digital marketing teams of some of the web's most well-recognized brands. As an industry veteran in all things digital, Nate has founded and grown more than a dozen local and national brands through his expertise in digital marketing. Nate and his team have worked with some of the most well-recognized brands on the Fortune 1000, scaling digital initiatives.

Bringing AI in-house, the right way.

Talk through your private or on-prem LLM deployment with an expert who has shipped them in regulated environments.

// the briefing

Private AI, in your inbox.

Occasional, high-signal notes on enterprise LLM deployment, security, and model strategy. No spam.