Let me save you a pitch meeting.
If your answer to "what's your moat?" is "our AI," you don't have one.
The model is a commodity. The same API you're calling, your competitor is calling - same endpoint, same price, same docs. "We use GPT" is not a strategy. It's a billing relationship.
And yet half the decks crossing my desk still treat the model as the magic. It isn't. The magic is gone. The intelligence got cheap. What's expensive - what's defensible - is everything that isn't the AI.
The Wrapper Graveyard
We've all watched this movie.
A team spots a gap, wraps a clean UI around a foundation model, ships in a weekend, racks up users. "Chat with your PDF." "AI for your emails." Beautiful traction.
Then OpenAI ships the same feature natively. Free. Built in.
And the startup is gone by Friday.
That's not a freak accident. That's the default outcome for anything whose only value is convenient access to a model. If the foundation lab can erase you with a single release note, you were never a company. You were a feature with a runway.
Here's the reality: a moat made of someone else's intelligence isn't a moat. It's a moat the landlord can drain whenever they feel like it.
Bet on the Problems That Hallucinate
Here's the filter I'd run every AI startup through: is the problem deterministic or not?
If it's deterministic - one right answer, clean input, clean output - the model gets there on its own. So does the next ten teams. No edge. That's the wrapper's grave.
The money is in the non-deterministic problems. The messy, judgment-heavy, no-single-right-answer work where a raw model, left alone, hallucinates with total confidence. Founders treat that as the reason to stay away. It's the opposite. The hallucination is the opening.
Because the only thing that keeps a model honest on a hard, fuzzy problem is deep domain insight and proprietary data wrapped around it - the context, the guardrails, the ground truth the model was never handed. That's the part you build. That's the part nobody replicates by calling the same API.
MedSetGo isn't "AI for doctors." It's deep insight into real-world care delivery - the patient-visit data and domain knowledge that stop a model from inventing a diagnosis. EvenUp isn't a model; it's hundreds of thousands of real injury cases that keep a demand letter grounded in fact instead of fiction. Harvey isn't "ChatGPT for lawyers" - it's the legal context across 59 countries that turns a confident hallucination into a citation a partner can actually sign.
Strip the AI out and each still owns the hard part: the insight and the data that make a non-deterministic problem trustworthy.
Strip the AI out of a wrapper and you have a login screen.
The Four Moats That Actually Hold
When AI isn't the product, defensibility comes from the boring stuff incumbents always knew mattered. Four sources, and the best companies stack them.
1. Data that compounds. Not "we have data." Start on public data if you have to - it's fine for laying the first bricks: shipping v1, proving the wedge, getting the wall off the ground. But everyone can build that same wall. The moat is what you stack after - proprietary insight that gets deeper because customers use you, the kind a new entrant can't buy, scrape, or prompt their way into. Every patient visit MedSetGo runs deepens what it knows about real-world care - making the next one faster, cheaper, sharper - a flywheel that calling the same API gives you zero of. Start with public data to raise the first walls. Then make sure you keep digging deeper - because a wall that stops growing is the same height as everyone else's.
2. Owning the workflow. The durable verticals share a tell: the workflow has ten-plus steps, each touching different data and different people. Wrap one step and you're a feature. Own all ten and you become invisible infrastructure - the thing nobody rips out because ripping it out means rebuilding the whole operation. Switching cost is the moat. It always was.
3. Distribution. Being the best is worthless if you're the best nobody can find. The startup that owns the channel - the integration, the partnership, the place buyers already live - beats the marginally smarter tool every time. AI made building easy and getting noticed brutal. Distribution > model quality, and it's not close.
4. Trust and regulation. The defensive moat nobody wants and everyone needs. In law, health, and finance, the barrier isn't intelligence - it's the certification, the compliance burden, the human sign-off, the years of being the name a regulated buyer is allowed to trust. Slow to build. Brutal to copy. Exactly why it holds.
The first two widen the gap as you grow. The last two slow the competitor down. Stack a generative moat with a defensive one and you've built something a weekend wrapper - and the foundation lab itself - can't casually erase.
The Hardest Moat: Data the Model Can't Reach
Remember what Stripe's moat actually was.
It wasn't the seven-line API. Anyone can write an API. The moat was the years of brutal plumbing into a hostile, fragmented banking system nobody else wanted to touch. The clean API was the wrapper. The misery underneath was the moat.
That pattern is back, and it's the most underrated edge in AI right now.
Look at TeroAI - building pipelines into geospatial data the foundation models never ingested and can't reach. The smartest model on earth can't train on data it was never handed. Or Genloop, fixing what generic LLMs structurally can't: turning a company's proprietary, regulated, locked-down data into a model that actually performs behind their walls.
Neither is "an AI company." Both are doing Stripe's job for data the giants don't get to see - solving the ugly, hard, unglamorous problem on purpose.
That's the moat a weekend wrapper can't speedrun. And the foundation lab can't absorb it, because it can't see the data in the first place. Pick a problem hard enough that the plumbing is the product, and the model getting smarter doesn't touch you.
"But the Model Keeps Getting Smarter"
Steelman the bear case. Every six months the foundation models get better, cheaper, more general. Won't they just swallow your vertical whole? Why won't OpenAI ship "MetSetGo mode" and end it?
It's the right fear. It's why the wrappers died.
But. A smarter model doesn't have your customers' data - that data is locked behind your contracts and their privacy walls, not on the open internet. A smarter model doesn't carry your HIPAA posture, your malpractice tail, your decade of being the trusted name in a room where trust is the whole sale. A smarter model doesn't own the ten-step workflow your product quietly became the spine of.
The foundation lab makes the engine better. It does not, by getting smarter, climb inside your customer's operation and earn what you earned. General intelligence is a rising tide. Moats are built on the land the tide doesn't reach.
What This Means
For founders: stop pitching the model. Nobody's funding the model - you don't own it. Pitch the data flywheel, the workflow you swallow, the channel you own, the regulatory wall you're climbing. If your honest answer to "what happens when the foundation model ships your feature?" is we're done, you're not building a company. Find the painkiller workflow underneath and go own that.
For investors: "proprietary AI" on a seed deck is a yellow flag, not a green one. Ask the only question that matters: what compounds? What can't the next team replicate by calling the same API next quarter? If the founder can't answer, the moat is rented - and rent comes due.
The Bottom Line
AI didn't kill the moat. It killed the fake ones - the thin tech edge, the marginally-better-model, the wrapper dressed as a platform.
What's left is what was always true. Defensibility lives in data that compounds, workflows you own, distribution you control, and trust you earn the slow way.
The intelligence got commoditized. The moat went back to being a business problem.
Which is good news - because that's a game discipline wins, and discipline is the one thing you can actually build.