Do AI Products Have a Moat?
Where defensibility of your product actually comes from now
Anything you can fit into a demo, a competitor can clone by Friday.
The model you rent through an API, the chat box, the system prompt you sweated over, the onboarding that felt so clever in the all-hands: all of it is visible, and everything visible is cheap to copy.
That is the AI-moat problem in one sentence.
When the most impressive thing you can show a buyer is also the easiest thing to reproduce, you don’t have a moat. You have a demo.
Out loud, the industry tells the story more kindly.GPT-4-class pricing fell from about $36/M tokens in March 2023 to $4 by the summer of 2024, a drop Andrew Ng put near 79% a year.
So the moat, everyone now agrees, simply moved to your data. Your proprietary knowledge. It is a comforting story, and it just moves the same wish down one floor.
The Demo Test
In May 2023 a Google researcher’s memo leaked out of the building under the title “We Have No Moat, And Neither Does OpenAI.”
Open models were quietly eating both giants, it argued, because people will not pay for a restricted model when a free, unrestricted one is just as good. The memo read as heresy then.
But the deeper reason that using a specific model defends no one is not that open source caught up. It is that a model is, by its nature, a thing you can show.
Whatever dazzles in the fifteen-minute call is, by definition, the part a funded competitor can see, price, and rebuild. Capability this cheap and this visible was never going to be the wall.
The Moat That Moved
So the crowd went looking downstairs and settled on data. Your data is private, the thinking goes, and it compounds: more users, more data, a better product, more users. A flywheel no rival can spin.
I would like to offer a counterpoint:
a16z’s Martin Casado and Peter Lauten, writing in 2019 under the title “The Empty Promise of Data Moats,” found that there generally isn’t an inherent network effect that comes from merely having more data: the cost of more can rise while the value of each new row falls.
And the supposed moat “erodes as the data corpus grows and the competition races to catch up.” Data scale is not a network effect. It is just scale, with the economics running backwards.
So what is the moat now?
If it is not the model and not the data, it helps to see what those two share.
Both are things you own.
The error underneath three years of moat talk is hunting for the moat as a possession at all.
Defensibility is a verb. It is not a thing you hold; it is a loop you have run longer than the other guy.
And the durable ones share a single property - none of them fit in a demo, because each exists only in elapsed time:
The switching cost, which is just the bill a customer pays to leave, run up quietly over years of wiring you into how they work;
The feedback loop, worthless on day one and load-bearing after two years of real production correcting it;
The regulated foothold, the audit passed and the clearance won, which takes the months no amount of compute can compress;
The trust, earned across a hundred uneventful renewals, that makes a buyer keep paying instead of opening a rival’s free trial.
What’s Left Standing
They are the oldest walls in business - lock-in, habit, regulation, trust - the ones software had before a transformer was ever trained.
The models didn’t didn’t give you or anyone else a new kind of defensibility. It commoditized the part of your company a competitor could copy, and left standing only the part that took time.
Which changes the question to ask of any AI product, the one a rival ships or the one you do.
Not “what can it do,” because whatever it does, you can probably match by Friday.
Ask what it would cost a customer to leave. If the honest answer is “an afternoon,” the demo was the whole company.
What I can’t tell you is which of these you are quietly building while the demo dazzles the room. Only that the clock, not the model, is doing the defending.







