← Articles
Nº 001May 14, 2026

Defensibility in the AI era

Why the moat is a sequence, not a list.

AI keeps pushing the cost of building toward zero. The startup world has mostly agreed on what that means: build on what doesn't clone. The agreement is sound. But that answer names only a handful of durable advantages when there are many more, and the sequence you build them in is part of what makes them hold.


When the cost of building something falls toward zero, the interesting question stops being can this be built? and becomes can this be defended? In the AI era, a defensible business is one built on an asset that does not clone when execution becomes nearly free. The startup consensus names four such assets: networks, proprietary data, communities, and infrastructure. Each is a candidate moat, a competitive advantage that survives contact with a serious, well-funded rival. The consensus is directionally right, but it is also quietly misleading. The consensus list of four moats is incomplete, there are at least six more that belong on it, and the ones that hold are built in a sequence, not picked from a menu.

AI has collapsed the cost of execution. Code, content, design, and analysis that once required a funded team now take one person an afternoon. The implication everyone has correctly drawn: an undifferentiated product is now a liability, because the moment it works, it gets cloned. In early 2026 the market began pricing this in. Investors and analysts started calling it the "SaaSpocalypse," a roughly $2 trillion fall in the market value of business-software companies, driven by the fear that AI would make much of their software easy to replace.

So far, so agreed. The disagreement that matters is not whether you need a moat. It is the shape of the answer: is defensibility a checklist of four things to acquire, or an order of operations? Here is what eighteen months of evidence, some of it brutal, actually shows.

The four pillars don't hold evenly

Examine the consensus four one at a time and they turn out to behave nothing alike.

Networks are the strongest pillar, with one important caveat

NFX, an early-stage venture firm known for its research on network effects, studied 336 companies that reached a billion dollars in value and found that network effects accounted for roughly 70% of all technology value creation, a figure Morgan Stanley independently confirmed. Morningstar upgraded Airbnb to a "wide" moat rating in 2025, citing exactly this advantage. Veeva Systems, the pharma-specific CRM vendor, kept 9 of the top 20 pharma companies on its Vault CRM despite Salesforce's direct attack, because industry-specific network effects and shared data standards outweighed Salesforce's distribution. But the consensus blurs a distinction that decides everything. There are behavioral network effects, built on habit and familiarity, and structural ones, built on liquidity, data density, and trust that is genuinely embedded in the product. Marketplaces are the canonical case of the structural kind: liquidity itself becomes the moat, because each side attracts the other in a self-reinforcing loop that a new entrant cannot start cold. AI erodes the behavioral kind and cannot touch the structural one. Autonomous purchasing agents (which ARK Invest, an investment research firm, estimates could eventually steer $9 trillion in spending) sweep listings and ignore brand loyalty entirely, so habit-based lock-in evaporates. But an AI agent cannot manufacture a host's 500 real five-star reviews. Morningstar's review of 132 companies landed exactly here: simple customer familiarity will face pressure, while genuine network effects are expected to increase in value. The pillar is real. Half of what gets called by its name is not.

Data holds, but only one kind of data

This is where the consensus is loosest, and most dangerous. Martin Casado, a partner at the venture firm a16z, dismantled the generic "data moat" argument. Most so-called data network effects are just data scale effects with steep diminishing returns, and data goes stale. Synthetic data has accelerated the collapse. Google's research achieved cost reductions of 500 to 1,000 times over human labeling, with models trained on synthetic data outperforming those trained on real data. The precedent is SDL and Lionbridge, two companies that built fortunes on proprietary language datasets and were gutted once Google Translate became good enough using public data. Chegg is the sharpest recent case. Its database of 79 million solved homework problems, once a real asset that students paid to access, became close to worthless when ChatGPT could solve any problem instantly and for free. Chegg's stock fell 99% and the company cut 45% of its staff. That was a static data moat: a library. Static data moats are dead. Dynamic data moats, where data is continuously generated by operations, embedded in workflows, and impossible to copy without doing the actual work, are alive and strong. Bloomberg's $15 billion in annual revenue runs on exactly this kind of data: real-time financial feeds, traders' workflows wrapped around them, and an AI layer (BloombergGPT, trained on 363 billion financial tokens) that makes the data more valuable the more it is used. Palantir's ontology, covering 3,400 patents and generating 128% net revenue retention, is the same shape. Flatiron Health's oncology data, pulled from 265 cancer clinics, was worth $1.9 billion to Roche because it was regulatory-grade evidence that synthetic data cannot generate. The single word "data" in the consensus list is doing far too much work. Static data is a liability. Dynamic data is a flywheel. They are not the same moat.

Community is the weakest pillar, and it is usually mislabeled

Most "community moats" are really audience moats wearing a costume, and audiences disperse. Stack Overflow, the question-and-answer site for programmers, saw its monthly questions fall from a peak of about 200,000 to 6,866 in early 2026, roughly the volume it had at launch in 2008. The community was hollowed out by the AI coding tools it had helped train. Clubhouse reached a $4 billion valuation backed by Andreessen Horowitz, then collapsed within months once Twitter, Discord, and Spotify copied the core mechanic and the creators it depended on moved on. Even Twitter itself, the most entrenched community moat in media history, lost 60% of its advertiser revenue and saw mass user migration to Bluesky, Threads, and Mastodon once trust broke. The distinction that matters: a genuine community is self-sustaining, like Figma's plugin ecosystem or Notion's 80-plus user-run groups. An audience depends on continuous investment, and the moment you stop feeding it, or break its trust, it disperses faster than any other moat type. The consensus treats community as a single durable asset. Mostly, it is not.

Infrastructure is the deepest moat in technology, and the one you most likely cannot build

This is the pillar the consensus names and then skips past. When infrastructure is real, nothing is more durable. NVIDIA's CUDA software ecosystem, built over twenty years and now used by more than 4 million developers, has resisted AMD and Intel despite their billions in resources. Apple spent more than $20 billion growing its silicon team and now owns its full stack from Neural Engine to Core ML to operating system. Tesla designs custom AI chips and trains its self-driving model on telemetry from millions of vehicles in the field. But the word "infrastructure" hides a brutal accessibility problem. It is not one moat, it is several, and most of them require billions in capital and a decade of time. For the solo founder or small team the consensus is supposedly advising, listing infrastructure as one of four equal options is almost a mistake of category. It belongs on the map. It does not belong on your map unless you arrived with billions and a decade to spend.

So the consensus list, examined honestly, is uneven. One pillar is half real. One means two opposite things. One is usually mislabeled. One is out of reach for most readers. The list is still useful, but it is not something you can simply pick up and execute. And it is missing things.

The moats the consensus forgot

Several of the moats below are well documented in the broader business strategy literature. But many are missing from current AI-startup commentary, where the conversational consensus generally focuses on the same four pillars. Test that consensus against what is actually defending companies right now, and at least six more moats appear. Several are more durable than data or community, and several are genuinely within reach of a small team.

Regulatory and compliance barriers are the single most durable moat AI cannot compress

The venture firm Mighty Capital analyzed 578 well-funded AI companies and ranked regulatory moats above data, networks, and everything else. The mechanism is simply time. Certifications like HIPAA, SOC 2, FedRAMP, FDA validation, and banking licenses take two to five years to earn, and no model speeds up a government approval process. The EU AI Act, enforceable from 2026, carries fines of up to €35 million or 7% of global revenue for non-compliance. Stripe is the canonical accumulation play: state money-transmitter licenses across jurisdictions, a Georgia merchant acquirer charter giving direct card-network access in April 2025, a conditional OCC national trust bank charter for its Bridge subsidiary in February 2026, each layer earned over years. Epic Systems, the dominant US medical-records company, is not unreplaceable because its software is good. It is unreplaceable because the compliance work is the product.

Workflow embedding creates switching costs that survive AI disruption

When your product becomes the system of record, the central place other tools connect to, every new integration raises the cost of removing it. Salesforce has more than 3,000 integrations in its marketplace, so unplugging it means renegotiating all of them at once. The AI-era version is sharper still. Bessemer Venture Partners (BVP) frames the evolution as "systems of action replacing systems of record": AI-native products do not just store data, they act on it, and the accumulated actions, decisions, and working context create deeper embedding than storage ever could. A spreadsheet of transactions is portable. A working, machine-readable model of a customer's risk profile, consent boundaries, exception patterns, and accumulated working context is not. Vertical AI companies like Filevine (legal) and Basis (accounting) reach implementations that take 6 to 12 months to land and would cost a full year of productivity to undo. Unlike infrastructure, a focused team can reach this kind of depth in 18 to 24 months.

Process power is the gap between a demo and production

Research from Harvard and Stanford finds that 90 to 95% of corporate AI projects never reach durable production value. A demo hits 95% task completion; the same system in real conditions averages 50 to 55%. That gap is the moat. A rival can build a toy compliance demo in days, but Greenlite, a YC-backed compliance startup, took years of accumulated edge cases to get its production system to work, because the last 10% of reliability costs 10 to 100 times the effort of the first 90%. Harvey, a legal AI company, went from a $3 billion to an $8 billion valuation in a single year on exactly this kind of operational depth.

The AI-native version of process power is agentic orchestration reliability. If each step in a ten-step agent workflow runs at 95% accuracy, the compounded end-to-end success rate is roughly 60%. Building agent systems that survive real workloads requires what the consulting firm Bain identifies as three layers: orchestration to manage the workflow, observability to trace and monitor every step, and governed data access so the agent acts inside its permissions. Teams that reach 80 to 90% autonomous completion get there through prompt engineering, retrieval grounded in their own knowledge bases, tightly bounded scope, and many iterative tuning loops, not by swapping in better models. Emerging standards like the Model Context Protocol may eventually compress some of this complexity, but for now the depth required is genuine and accumulates the same way the rest of process power does.

Counterpositioning exploits the incumbent's paralysis

A newcomer adopts a business model the incumbent cannot copy without damaging its existing business. The clearest AI example is pricing. Traditional software charges per user seat, but AI reduces the number of seats a company needs, and the 2026 SaaSpocalypse showed CIOs cutting seats fast as AI agents absorbed user workflows. An AI-native company that charges per result offers economics the seat-based incumbent cannot match without cannibalizing its own revenue. Meta's Llama strategy is the textbook case at a different level: open-sourcing frontier-class models commoditizes competitors' proprietary model revenue, and Meta can afford to do it because models are not how Meta makes money. By late 2025 Llama had passed a billion downloads. This is the most accessible moat on the list, because it costs insight rather than capital. It is also the most temporary, lasting only until the incumbent decides to absorb the loss and copy the model.

Brand functions as a trust proxy when AI output is hard to inspect

When two AI products perform comparably on the same benchmark, the buyer cannot directly verify which one fabricates less, fails less gracefully, or handles edge cases better. They use brand as the shortcut. In early 2026 ChatGPT held 64.5% of tracked AI chatbot usage against Gemini's 21.5%, despite Google reaching comparable performance on most public benchmarks. ChatGPT became the generic name for its category, the way a few brands quietly do once they win category-defining mindshare. The AI search startup Perplexity grew past $75 million in annual revenue largely on a brand built around "no ads, no hidden agenda, transparent sourcing," compounding trust iteratively as the AI search category itself stayed messy. Brand effects are strongest in regulated, high-stakes fields like healthcare, finance, and legal, where verification is hardest and the cost of being wrong is real.

This pillar carries a Nokia and Netscape warning. First-mover brand advantages in consumer technology have a history of collapsing quickly once a clearly superior product arrives in a category where switching costs are low. ChatGPT's dominant share is the current state, not a guarantee. Anthropic's Claude has been closing in, with Anthropic raising at valuations above OpenAI's and posting unusually strong enterprise adoption. That is exactly the kind of competitive pressure that turns first-mover brand into a defending position rather than a dominant one.

Speed earns time, then runs out

The cleanest demonstration in the AI era is Cursor, an AI coding tool that went from zero to $2 billion in annual revenue in three years against GitHub Copilot, which carried VS Code's distribution, GitHub's 100-million-developer user base, and a deep OpenAI partnership. Cursor's lead came almost entirely from velocity: roughly 60 to 100 internal releases a day, around five pull requests per engineer per day. NFX has named the underlying shape, borrowing from medieval military architecture. A motte-and-bailey was the dominant form of Norman castle: a raised earthwork crowned by a fortified keep, the motte, was the inner stronghold where defenders held out; surrounding it at ground level was a lower walled enclosure, the bailey, where daily life and the outer defenses sat. In a siege, the bailey fell first. The motte was where defenders actually held out.

Speed is the bailey. A serious competitor can match a release cadence next quarter by hiring engineers and copying a continuous-integration setup; what they cannot match next quarter is the years of accumulated reliability, edge-case knowledge, and customer trust that constitute the motte. The venture firm Oxx VC put the underlying mechanic plainly: speed is an arbitrage between what is technically possible at the vanguard and what the typical customer believes is possible, and the gap atrophies. As foundation models improve and the market matures, pure velocity earns less and less.

The right way to think about speed in the AI era is therefore not as a defense but as a clock. Every fast release ships into real users; every real-user encounter surfaces edge cases that do not appear in any demo; the accumulation of those edge cases, over years, is what becomes process power. Speed earns the time required to build the motte. It is not the motte itself.

That brings the working list to ten moats once the consensus four are counted alongside the six additions. Which is the deeper problem with treating any of them as a checklist.

The real shift: a sequence, not a list

Here is the move that actually matters. It is not on the consensus list because it is not an item on a list. It is a reordering.

Moats in the AI era are not all-or-nothing, and they are not parallel options you choose between. They are layered and sequential. You do not pick one. You build them in an order, and each one earns the right to the next.

First, the landscape. This is what you are choosing between:

Moat typeDurabilityBuildable by a small team?
Structural network effectsVery highEventually, not first
Regulatory / complianceVery highVery hard
InfrastructureVery highExtremely difficult, billions and a decade+
Workflow embedding / switching costsHighYes, in 18–24 months
Process power (incl. agentic orchestration)HighHard but possible
Dynamic proprietary data (flywheel)HighYes, as a byproduct
CounterpositioningModerate–highYes, it costs insight
Brand as trust signalModerateYes, but emergent
Community (genuine, not audience)ModeratePartly
Iteration velocity (speed)TransitionalYes, but a head start, not a moat

Now the order. The evidence from NFX, the growth-equity firm Insight Partners, the investor Elad Gil, and Y Combinator converges on the same path. Most software, as Gil puts it, "starts off default non-defensible and builds a moat over time." Here is what that looks like, stage by stage.

Phase 1, months 0 to 6: speed and counterpositioning. Ship fast in a narrow market, with a business model incumbents cannot copy. This buys time. It is not a moat. Cursor's trajectory, already covered, is the cleanest example: zero to $2 billion in annual revenue in three years against GitHub Copilot, on velocity alone. Speed in this phase is the bailey. It earns the right to embed.

Phase 2, months 6 to 18: workflow embedding. Become the system of record for your market. Every customer implementation should deepen how your product connects to their existing tools, and accumulate the working context that makes leaving expensive.

Phase 3, months 18 to 36: the data flywheel and process power. If the embedding worked, you are now generating proprietary, operational data that nobody else has: the live kind, not the library kind. The demo-to-production gap is now working for you instead of against you.

Phase 4, months 36 and beyond: network effects and community. With enough users and enough data density, you can finally build for network effects. Genuine community follows a product people depend on. It cannot be willed into existence first.

Regulatory work sits outside this sequence. It is a parallel track. If you are in a regulated field, start the two-to-five-year clock on day one.

Brand sits outside the sequence in a different way. It is emergent, not scheduled. It accrues across phases two through four as a byproduct of shipping a product that works reliably. You cannot will it on day one; it shows up later if the work was real.

Notice what this does to the consensus list. Networks, the strongest pillar, comes last, because you cannot build one until you have density. Data comes third, because the data worth having is generated by the workflow embedding you did in phase two. Community arrives with networks in phase four, because it follows a product, not the other way around. Infrastructure does not appear at all, having already been labelled out of reach for challengers. The consensus was not wrong about the destinations. It was wrong to present them as a menu when they are a path.

Defensibility is built, not designed

This is also why "build the moat first" is bad advice. You cannot. The moat is not a feature you ship in version one. It is a property that emerges from doing the work, in the right order, better and faster than everyone else. The whole picture compresses into one line: models commoditize, workflows differentiate, data flywheels compound, networks defend. The companies best positioned in 2026 are not the ones with a single dominant moat. They are the ones stacking reinforcing layers in the right sequence.

The strongest evidence here is for network effects as the top digital moat, for static data being dead, and for the demo-to-production gap as genuine defensibility. All three are well documented across independent sources. Hold two things more loosely: whether AI purchasing agents will actually erode marketplace networks at scale (the logic is clean, but real-world evidence is still thin), and how long counterpositioning moats last (this depends entirely on when incumbents decide to copy the model). The map is good. Some of the borders are still being drawn.

Anything worth building must be defensible: the consensus got that right. The correction is the part that follows from it. Defensibility is built, not designed. It is not an architecture you draw up front. It is what remains after you have done the work, in sequence, in a world where AI has pushed the cost of the work itself toward zero.