What AI Broke
Lab — early draft from Era Haus

The moat moved upstream

Jun 26, 2026What AI Broke

The scarcest assets in AI are the people who build the models and the physical plant that runs them. The model itself is the easy part to copy. Three moves this week made that concrete: two of Google's most decorated researchers walked to rivals and took billions in market value with them, Anthropic told Washington that a Chinese competitor had copied its model's behaviour at industrial scale, and a rocket company tightened its grip as a compute landlord to its own AI rivals.

Talent is the frontier's scarce input

The defensible read was that a lab with the most compute, the deepest data, and a research bench deep enough to win a Nobel held a self-reinforcing lead, and that its best people stayed because no rival could match the resources around them. Google's London-based research lab, the group behind the protein-folding breakthrough that won a 2024 Nobel and behind the Gemini models, was the case study. Talent was a human-resources question. You assumed the people who built the frontier would stay to keep building it.

That broke in a single week. Noam Shazeer, who co-wrote the 2017 paper that defines today's models, left for OpenAI. John Jumper, the chemistry Nobel laureate who led the protein-folding work, left for Anthropic. Two more senior researchers followed, per reporting from Fortune and Bloomberg around June 23. Alphabet had its worst trading day in over a year, falling as much as 7% on June 22, with the slide tied to the departures alongside worries about AI spending. One researcher reportedly had compute pulled from his project shortly before he resigned. The chief executive insisted the lab is still a net winner of talent.

The exposed party is any operator whose AI plan assumes a given lab will hold its frontier position, and any organisation that treats its own AI talent as locked in by salary and equipment. A lead built by a few hundred people can leave through the same door those people do. Europe feels the pull from the other side, its deepest research base, anchored in London, and its national champions in France steadily losing graduates and senior staff to better-funded American labs. Treat your key technical people as a strategic dependency you price and plan around, and assume your model vendor's edge can migrate to whoever hires its researchers next.

A model's outputs turned into contested property

The settled view was that a model's moat is its weights, the trained parameters a lab guards like a recipe, and that whatever the model emits through its interface is simply a product sold by the token. A competitor training a cheaper system on those outputs, a practice called distillation, where one model learns to imitate another's answers, counted as a known irritation, the cost of doing business. You stayed ahead by shipping the next model faster than anyone could imitate the last. The outputs were a product to sell, and protecting them was never the point.

On June 24 Anthropic told a US Senate committee that operators linked to Alibaba had run what it called the largest known distillation campaign against its models: roughly 25,000 fraudulent accounts generating 28.8 million exchanges between April 22 and June 5, aimed at copying the model's reasoning, software-engineering and long-horizon planning, per CNBC. The company asked Washington to treat industrial-scale distillation as a national-security matter, enforceable with controls like those already placed on advanced-chip exports. Two US senators, one from each party, moved to attach penalties for adversarial distillation to must-pass defence legislation. The argument is that a model's observable behaviour is now a strategic asset, as worth guarding as the weights themselves.

The uncomfortable group is wide: any company whose advantage can be reached through an interface a competitor is free to query at scale. If six weeks of systematic prompting can transfer a frontier lead, "we have the best model" is a wasting asset and the interface is an attack surface. That reaches well past the labs, to any business selling AI features a rival could reconstruct by watching what they produce. Assume your model-driven differentiation leaks the moment you expose it, and move the durable value somewhere querying cannot reach, into proprietary data, a regulated workflow, or the customer relationship. We argued when the model became a cost line that raw model access was losing its margin; this is the same erosion one layer up, in the model's own behaviour.

Owning the plant beat owning the model

The frontier labs were taken to be software companies. They wrote the models; the layer underneath, the chips and the power, belonged to a chipmaker and the utilities; you rented capacity by the hour and treated it as an abstract, near-limitless utility. Building your own data centres or designing your own silicon looked like a hyperscaler's game, too capital-heavy and too slow to matter to a lab racing on model quality. Compute was a cost you paid and an asset you rented, the last thing you would sell to a direct competitor.

This week put the contest in the physical layer. SpaceX, which had absorbed Elon Musk's AI lab, turned its Memphis data-centre buildout into a merchant-compute business, signing a roughly $6.3 billion capacity deal with one AI startup on top of far larger multi-year contracts with two of its own model rivals, per CNBC on June 22. OpenAI unveiled its first custom inference chip, co-designed with the chipmaker Broadcom over nine months and bound for gigawatt-scale data centres from late 2026, per TechCrunch on June 24. And China drafted a $295 billion plan, first reported by Bloomberg, for a national computing grid required to run on at least 80% domestic chips, writing the largest US chipmaker out of its market.

The exposed party is any AI business that treated compute as someone else's problem. When a company that runs its own frontier model makes steadier money as a landlord to its rivals than from the model itself, and when access to chips and power decides who can serve customers at all, the physical layer stops being a line on the bill and becomes the contest. US energy regulators spent this week ordering grid operators to connect data centres faster, and the binding constraint is now electricity and silicon. Know who owns the compute and the power behind your AI, and whether you would still have capacity if the owner decided to keep it.

Read the three together

The three moves rhyme. One lab lost the people who made its frontier, another accused a rival of copying its model's behaviour wholesale, and the largest players raced to own chips, power and data centres. For two months this category has argued that capability is commoditising and that the value has moved off the model. The value did not move to the "deployment" software everyone pointed at; it moved upstream, to the three inputs a competitor renting the same model cannot copy: the few hundred people who can build a frontier system, the physical plant that serves it, and a model's own outputs before someone strips them. The model is the most copyable layer in the stack. As we argued in defensibility in the AI era, the moats that hold are assembled in sequence from scarce inputs earned over time. The operator question for the second half of 2026 is which scarce input you actually control, now that the model is no longer one of them.