Walk up the AI stack and every company claims a durable advantage, yet the moat keeps evaporating layer by layer. The real defensible position isn’t in any single layer — it’s in the outcome.
A venture partner told us last month, after a week of meetings, that he had stopped being able to tell the difference between the ten AI companies he had just visited. Each one had raised, each had a demo, and each founder described the product in the same confident register. What he could not find, in any of them, was a reason a well-funded competitor could not build the same thing in a quarter.
When you walk up the stack of what gets called the AI economy — from the foundation models at the bottom to the point tools at the top — you notice a pattern. Almost every layer is built on something its owner does not control, and the thing it is built on keeps getting cheaper, faster, and more available to everyone else.
The obvious place to look for a moat is the frontier labs. OpenAI, Anthropic, and xAI each pour tens of billions into training, and each one’s flagship is, for a few weeks, the best model in the world. But “best for a few weeks” is not a moat.
Capability converges. When one lab ships a leap, the others close the gap within a release cycle, and open-weights models keep compressing the distance. We wrote about this when Qwen3.6-27B closed the gap between cloud state-of-the-art and models you can run on hardware you own. The capability a frontier lab charges a premium for becomes something you can run in your own rack — and the price of the thing keeps falling, with the token economy already bucking under its own weight. A moat that is simultaneously good, cheap, and replicable by two well-funded competitors isn’t a moat. It is a product with a refresh cycle.
The same logic repeats at every level up. Cursor built a genuinely better coding editor and, by mid-2025, was running at around $500 million of annual revenue and a $9.9 billion valuation before its acquisition — but the intelligence underneath was OpenAI’s and Anthropic’s, not its own. Windsurf showed what happens when a lab decides its technology is worth licensing directly: Google struck a $2.4 billion deal and took the founders, and the company was later absorbed by Cognition. The app builders — Replit, Lovable, Bolt — each wrap the same frontier models in a friendlier interface.
The domain wrappers are the same story with a coat of industry paint: Harvey in law, Abridge and OpenEvidence in medicine. The moat they point to is the domain data or the distribution, but the data is often licensed, the distribution is rented from the model providers, and the reasoning that makes the answer correct is still somebody else’s model. The voice layer is no different — Sierra, Decagon, and ElevenLabs are agents and synthesis layered over models they do not own.
The layers people assume are most defensible are the least. Scale, once the obvious moat because it sat on the only clean human-annotation pipelines in the world, sold a 49% stake to Meta for around $14 billion — a price that held because Meta wanted the data and the people, not because the labelers were irreplaceable. Groq struck a roughly $20 billion licensing agreement with Nvidia and kept operating as an independent company; the chip was the value, the company was the delivery vehicle.
Inference providers, deployment platforms, and the neoclouds like CoreWeave are, at their core, passing through hardware that is fungible and increasingly expensive to carry on a balance sheet. CoreWeave’s model — heavy GPU leasing funded by substantial debt — is a moat only for as long as the GPUs keep appreciating and the debt stays cheap. None of it is under the customer’s control.
If the model, the interface, the domain, the data, and the hardware are all either converging or pass-through, then the defensible position cannot live in any single one of them. It lives in the combination — in taking a set of individually un-moated pieces and wiring them into something that reliably produces a specific, real-world result for a specific kind of business.
That is the difference between a tool and an outcome. A tool is something you can swap for a competitor’s next quarter. An outcome — a contract reviewed, a patient note drafted, a question answered from your own private documents — is something your business actually depends on, something that meets a standard your regulators and customers can check. We have written before that outcome engines are the next big economic play precisely because they measure value in what actually happened, not in how many tokens were burned.
And that combination is, in practice, a sovereignty question. The moat is not just the integration. It is the integration running inside your own boundary — the intelligence on hardware you control, the data that never leaves, the pipeline you can audit. That is capability sovereignty applied to the economics of the stack. A wrapper built on rented models can be out-built; a system built around your own regulated, private, audited intelligence cannot, because the thing it depends on is yours.
So the honest answer to “does anyone in AI have a moat” is: not any layer on its own. The moat is the outcome, and it belongs to whoever can combine all of these un-moated pieces — securely, in-house, and to a verifiable standard — for a business that actually needs the result. That is the work we do.
JD Fortress AI builds secure, on-premises RAG and agent solutions for UK businesses in regulated sectors. If you’re exploring always-on, private AI teammates, get in touch for a confidential discussion — no pitch, just practical talk.
If you're thinking about secure AI for your business, we'd love to have a conversation.
Get in Touch →GPT-6 Escaped Its Sandbox and Hacked HuggingFace — What Happens When Your AI Becomes the Threat?
Karp, The Token Tax, and the Application Layer
Claude Opus 4.8: The Capability Leap That Makes the Cost Problem Worse
The AI Subsidy Is Over: Why Microsoft, Uber and Everyone Else Just Realised Token Billing Does Not Work at Scale