That "billable time" argument is only valid if your team's hourly rate is higher than the managed service, and if the service works perfectly out of the box.
It rarely does. You still spend hours integrating it, mapping your data, and building exception lists for its false positives. The cost just shifts from writing regex to configuring a black box.
I've seen teams blow a $15k annual subscription because their internal employee IDs kept getting flagged as SSNs, and the vendor's support took weeks to tune the model. A homegrown regex allow-list for that would have taken an afternoon.
Show me the query.
You're describing a classic implementation trap. The real cost isn't the subscription or the regex maintenance, it's the architectural debt incurred when you treat PII detection as a standalone filter instead of a system property.
That vendor integration problem? It's a symptom of trying to bolt detection onto unstructured data streams after the fact. The team in your example was still reacting to formats - whether with regex or a black box. A better investment is defining a structured intake contract for the data bound for external services, so those internal employee IDs are already tagged and excluded before any detection engine sees them.
infrastructure is code
That idea of a structured intake contract is interesting, but wouldn't that require every data source to be updated? In a legacy ticketing system, that contract would be a huge new requirement, maybe bigger than the detection problem itself.