Soundings
Our Perspectives and Insights
Anyone Can Build Your Prototype. Nobody Can Rent Your Judgment.
The AI pieces I have written so far follow an arc, and every one of them starts with a prototype already on the table: why most pilots are never allowed to die, what it takes to get one to production, why the right system still fails when it is given to people. In all of them the model was the part that already worked. The hard part came after the prototype.
This piece moves one step earlier, because the model is not the hard part before the prototype either. Anyone can build your prototype now. The frontier model is on sale to your competitor at the same price it is on sale to you, and neither of you owns it. You both rent it by the token. So when a buyer, a board, or a rival looks at what you built, the question is not whether it works. The question is what makes it hard to copy, and the answer is a question of its own: what does this company observe that the model never will, and is it capturing it?
I will get to how I answer that. But first the wrong answer, because it is the one that comes out of almost every mouth, including mine not long ago.
The Moat Everybody Names Is the One the Frontier Eats First
Ask what makes an AI product hard to copy and you will hear one word: data. Proprietary data. Years of history. The corpus nobody else has.
Chegg had all of it. On May 1, 2023, the company’s first-quarter earnings release pointed to thirteen years of improving student outcomes and “the billions of pieces of unique learning content that Chegg owns.” The same document, a few paragraphs earlier, carried this line from CEO Dan Rosensweig: “since March we saw a significant spike in student interest in ChatGPT. We now believe it’s having an impact on our new customer growth rate.” The stock lost nearly half its value the next day.
Chegg had the corpus and it had the position: the student showed up with the homework in hand. What it did not have was anything a general model could not already do, because everything in that corpus was past tense, questions already asked and answered, and a model trained on the whole internet had gotten good enough at answering them. Its experts did add new answers every day, but that did not change the math: fresh answers to questions any model can answer are more of the same inventory. Nothing in that pile recorded what Chegg itself decided and what happened next.
Bloomberg ran the same experiment the clean way. In March 2023 it announced BloombergGPT, a model trained on its own financial corpus. Six weeks later a research team reported that GPT-4, with no access to that corpus, beat it on many of the public financial tasks they tested. The data was real and the advantage was not. A corpus poured into a model does not become a moat. It becomes a snapshot the frontier catches up to.
So while data can be a moat at a point in time, it falls down at the next one. The frontier models consume everything in the public domain and everything on its way there, and what they cannot consume they infer. Nobody has published the formula for Coca-Cola, and you can still find a version close enough to bottle. Proprietary data leaks, gets inferred, or gets matched. A point-in-time moat is real. It is just not an enduring one, and enduring is what a buyer is paying for.
A corpus poured into a model does not become a moat. It becomes a snapshot the frontier catches up to.
A Chart Is Past Tense. A Log Is Future Tense.
Sailors have had this figured out for centuries. The chart is public. Every ship in the harbor carries the same one, and now every model has read it too. The log is not. What separates the captain who has run this coast for ten years from a stranger holding the chart is the log: what the current did at the ebb, where the bottom was not where the chart said, the squall that came in from the wrong quarter, the approach that had to be taken twice. The log gets written one watch at a time, after the fact, and only by the people aboard.
Every business has a log. It is the record of its own decisions and what happened next. The refund exception you made for one customer and how that customer behaved for two years after. The segment where the playbook fails and the workaround the floor invented. The model never sees the decision, and it never sees the outcome. That record is not on the internet, and it is not in anyone’s training set unless you hand it over.
That is the tense shift, and it is the whole argument. A corpus is an inventory of exceptions that have already happened, and the frontier absorbs anything that has already happened and left a public trace. The moat is the exceptions that have not happened yet, that only you will be positioned to see, and that only you will capture if the machine for capturing them is running. The moat is not what your company knows. It is the standing ability to keep learning what nobody else can observe. Call that the enduring moat, to keep it apart from the point-in-time kind: an advantage that gets bigger while the frontier is busy absorbing the rest.
A point-in-time moat is real. It is just not an enduring one, and enduring is what a buyer is paying for.
The Four Things That Make a Moat Endure
Four things, and you need all four. The first is the opening balance, the middle two are the machine, and the last is the running total, worth only what the machine will add to it next year.
- Data you own that a competitor cannot rent. Your history, your records, your corpus. A rival can rent the same model you use. It cannot rent this. Necessary, and nowhere near sufficient: it is what you start with, not what protects you.
- Position in the workflow. Sitting where the decision actually gets made, not next to it. Adjacent tools get swapped on price, and position is also what puts you in the room when the exception happens.
- A feedback loop that is captured. When an operator overrides the system, where does the correction go: into the product, or into somebody’s head? If it does not land in the system, you are standing still while the frontier moves past you.
- Encoded judgment that is still being written. The exceptions, the edge cases, the “we do not do it that way.” Extract it once and you have a project any competitor can also fund. Extract it at every exception, through items two and three, and you have a moat. Item four without item three is a slide deck.
Harvey, the legal AI company, published a benchmark in 2024 that shows the shape of this. The tasks were built from publicly available documents. The proprietary part was the grading: attorneys who had done the work at large firms turned their own time entries into rubrics for what a lawyer-quality work product must contain and must avoid. On those rubrics Harvey’s models produced 74 percent of a finished work product, and the foundation models fell furthest behind on showing their sources. The documents were public. Harvey’s definition of done was the product, but a definition written once is a head start any well-funded rival can match. It becomes a moat only if every correction a lawyer makes lands back in it.
If you want proof the model cannot do this part on its own, look at where the money is going. In September, Accenture and Google Cloud announced a business group built around a thousand forward-deployed engineers, people whose job is to sit inside client operations and build. If the model could pull the judgment out of a company by itself, nobody would pay to put a thousand engineers inside one. Extraction is labor. And notice who employs them: a platform vendor. Ask where the judgment they extract is going to live.
Turn It Into a Screen
Whether you are buying a company, funding a prototype, or sizing up your own, the screen is four questions. What does this company observe that a frontier model never will? Is it capturing that, and where does a correction go when someone overrides the system? Who else sees it? And if the people who hold the judgment walk out the door, what stays behind?
If the honest answer to the first question is nothing, there is no enduring moat, only a point-in-time edge with a clock on it. If the corrections go into someone’s head, there is no enduring moat. If your software vendor’s contract lets it train on your exceptions, you are renting your moat to someone else. And if the judgment leaves with the people, what you have is key-person risk with an AI line in the pitch deck, and that line is a liability, not an asset. A prompt library and a good user interface fail the first question before you finish asking it. So does a proprietary corpus with no answer to the second, and the difference between the two is a matter of months.
If your software vendor’s contract lets it train on your exceptions, you are renting your moat to someone else.
The Bottom Line
I have told people, more than once, that the moat is data and history. I still believe the second half, with a clarification. History is the moat, if by history you mean the log and not the chart: the running record of what you decided and what happened next, still being written, landing in the system instead of in somebody’s head.
The model is the cheapest part of your prototype, and the data is a head start with a clock on it. The log is the part nobody can rent, and it is the only AI moat that lasts, because only you can see it and it is still being written.
A Pilot & Rutter principle.
