
In our view, AI startup moats in 2026 tend to come from what a model cannot easily copy: deep workflows that run across several parties, network effects between users and their agents, data and context that make the product measurably better, and switching costs that survive an AI-assisted migration. Code on its own is rarely a moat now, because agents can write it in days.
Definition: An AI moat is a structural advantage that lets an AI company keep its customers and margins even when a frontier lab, an incumbent or a well-funded clone ships a similar model-powered product.
"Our AI" is not an answer to "what's your moat?" It's a description of your vendor.
That's our take on why your AI is not your moat, and this guide turns it into something you can build and measure. Our approach: find something customers depend on first, then build defensibility around it. Below are five moats, the weak ones we'd avoid pitching, a scorecard and a script for the question most AI founders now get. For the economics side (inference bills, gross margin and pricing), read the companion guide on AI gross margins and inference costs.
Why the old AI moats stopped working
Our read: assume anything you can describe in a demo can be rebuilt. It's uncomfortable, but investors tend to trust that starting point more than a founder insisting the product is unique. Three shifts got us here.
- Models turn over constantly. OpenRouter, which routes requests across many different models, launched 70 new ones in July 2026 alone, about one every 10 hours, by its cofounder Alex Atallah's count. A model advantage this quarter may well be matched next quarter, and the products most at risk are the ones model labs come to see as strategic to their own plans.
- Software got cheap to produce. When an agent can write a credible first version of your app over a weekend, the code itself tends to protect very little. What protects you, in our view, is everything around it: the workflow, the data, the relationships and the reliability earned in production.
- Migration got cheap too. Switching costs used to come from data trapped in a system of record. An LLM can now map and move that data in weeks, so a customer who felt stuck for years can leave in a quarter.
Cheap models. Cheap code. Cheap switching.
The money explains why investors keep pressing. Menlo Ventures' State of Generative AI in the Enterprise report (December 2025) counted $37 billion of enterprise generative AI spend in 2025, up from $11.5 billion in 2024, with $19 billion at the application layer. Startups took 63 percent of that application market, up from 36 percent a year earlier. Budgets that big and that fast attract labs, incumbents and clones all at once. So we care less about the size of your share than how long you can hold it.
Five AI startup moats worth building
We group defensibility into five moats. The names are ours; the idea that moats come in distinct structural types goes back to Hamilton Helmer's 7 Powers, and our list is one reading of that lens applied to AI applications in 2026. Other investors slice it differently (our blog essay leans harder on distribution and trust, which sit under cornered resources here). Notice what isn't on the list: the model.
1. Workflow depth
Own a job that crosses roles, teams or companies. A single prompt for a single user is easy to copy. A workflow where in-house counsel, outside firms and the client all touch the same matter, each with different permissions and context, is not. The hard part is usually the last few percent of reliability on real edge cases, and that tends to take months in production to earn.
Menlo Ventures partner Matt Murphy offers a useful test here: if a general model can take your market, your application probably was not defensible to begin with. It's blunt, and it works. If a better base model would make you unnecessary, you may have a feature with a fundraise rather than a company.
2. Multiplayer and agent network effects
This moat comes from a product that becomes more valuable as more people and agents use it together. The newest form is agent to agent: your assistant asks a coworker's assistant when it lacks an answer, or a buyer's agent negotiates with a supplier's. Once a whole team or transaction chain runs through your product, leaving means everyone leaves at once. Few AI products seem to have cracked multiplayer yet, which is exactly why we'd design for it early.
3. Compounding data and context
Data counts when it compounds into a better product. Customer-permissioned data, evaluation sets built from real cases, and memory about how a specific user or organization works all qualify, provided you can show that more of it produces better answers. The more context a product holds about a customer, the easier the next right answer gets, and that stickiness can become the moat. Frontier labs are likely to build memory and context into their own models too, so it helps if the context is specific to a workflow they are unlikely to prioritize.
4. Earned switching costs
We tend to favor switching costs built from configuration rather than captivity. Months of onboarding that tune an agent's logic to one company's operations, dozens of integrations, approved playbooks and learned preferences are expensive to rebuild even when the raw data moves easily. This is the kind of lock-in that gets stronger as data export lock-in gets weaker.
Measure it before you claim it. Track how long onboarding takes, how many integrations and custom rules an average account carries after six months, and what share of accounts would need a project plan (not a CSV export) to move. If a new customer is fully live in an afternoon, your switching costs are probably low, however loyal that customer feels today. Easy in, easy out. That isn't fatal early on, but it tells you where to invest next.
5. Counter-positioned pricing
Price in a way incumbents can't copy without hurting themselves. A clear AI case: incumbents that charge per seat lose revenue when their own agents remove seats, while a startup can charge per task or per outcome from day one. Counter-positioning also covers product quality in a narrow segment that a larger rival will not prioritize. The check: what would the incumbent have to give up to match you? If only engineering time, you're probably not counter-positioned. If it's a revenue line, a channel partner or a pricing model its sales team depends on, you may well be.
Two supporting moats
Speed and brand matter most at the very start, when you have little else: ship faster than incumbents and become the default name in a niche. Cornered resources and scale economies (regulatory clearance, exclusive distribution, a large fixed investment reused across customers) are rarer for early AI apps but worth claiming when they are real.
Weak moats we would be cautious about pitching
These sound like moats and behave like head starts. Lead with one and an investor may discount the rest of your pitch.
- The model as the moat. A fine-tuned model can help, but base models leapfrog each other every few weeks. We'd weight the workflow, the data and the customer relationship far more.
- Hypergrowth as proof. Fast revenue from a product customers can leave in a week may not be durable. Aaron Katz, CEO of ClickHouse, makes the point well: revenue durability is the most underestimated risk in fast-growing AI companies, and switching costs can be very low for agentic apps. Gross retention and cohort curves tend to be more persuasive; our guide to cohort retention explains how.
- A pile of logs. If more usage does not visibly improve results, you have storage, not a data moat.
- A point feature in a compound market. The first wave of AI app builders was easy to clone early on; the ones that lasted became broad, complex products that are hard to copy in full. If a competitor can bundle your feature into a suite, expand into the adjacent workflow before they do.
- Per-seat pricing. It can quietly cancel your counter-positioning against incumbents. See how pricing choices affect both moat and margin in the AI gross margins guide, and how services-heavy models hold up in AI-enabled services.
"But the next model will do all of this anyway"
It's the strongest objection. Every few months base models get cheaper, broader and better at the reasoning your product was built to supply. If the trend holds, why wouldn't a lab absorb your vertical, workflow and all? Plenty of early AI apps found out the trend was real.
But a better model doesn't arrive holding your customers' permissioned data, your eval set built from their edge cases, or the months of configuration that tuned the product to how one company actually works. It doesn't carry your compliance posture through a regulated buyer's procurement review, or join the multi-party workflow your product quietly became the backbone of.
A smarter model raises the floor for everyone. Thin products get erased; products built on context, relationships and reliability tend to stay standing, and often get cheaper to run. We could be wrong about how far the floor rises, which is one more reason to build more than one moat.
Where views differ on the contested questions
Serious investors disagree on three points. Here's our read on each, with the other side's case; your market may point elsewhere.
Are data moats real? Partly. a16z's Martin Casado and Peter Lauten made the skeptical case in The Empty Promise of Data Moats (May 2019): most claimed data network effects are really scale effects, and unique data gets more expensive to acquire while each new piece adds less. Other investors put proprietary data and context at the center of AI defensibility. We think both are describing different data. Data tends to act as a moat when it is hard to get, stays fresh and produces a quality gain you can measure. Otherwise it can behave more like a cost center.
Are switching costs rising or falling? Both, depending on the kind. Lock-in from trapped data is falling, because agents can migrate it. Lock-in from configured agent logic and accumulated memory is rising, and several investors now describe context and memory as the next generation of moats. Our leaning is toward building the second kind.
Should you talk about moats at all? Before product-market fit, barely. Some investors are openly put off by founders who spend a pitch on five-year moat theory, and we think picking between ideas on forecast moats can be a mistake, though others value early moat thinking. After fit, expect the question, and answer it with what customers already rely on rather than a strategy slide.
An AI startup moat scorecard
One approach is to score each moat 0 to 3 on evidence rather than intentions. The weights are only our suggestion for a B2B AI application; adjust them for your market.
| Moat | Weight | 0 means / 3 means | Evidence to cite |
|---|---|---|---|
| Workflow depth | 3 | Single prompt for one user / multi-party workflow with measured reliability | Accuracy on production cases, roles in the workflow |
| Earned switching costs | 3 | Customer could move in a week / months of configuration and learned context | Onboarding length, integrations per account, gross retention |
| Compounding data and evals | 2 | Public data, no eval set / permissioned data that visibly lifts results | Eval set size, quality lift over time |
| Multiplayer and agent network effects | 2 | Single player / value rises as teammates, agents or counterparties join | Seats or agents per account, cross-user actions |
| Counter-positioned pricing | 2 | Same model and pricing as incumbents / a model incumbents cannot copy | Pricing unit versus incumbent's, win rates |
| Cornered resource | 1 | None / regulatory access, exclusive data or distribution | Certifications, contracts, partnerships |
| Speed and brand | 1 | Slow release cadence, unknown / category default, ships fastest | Release frequency, share of inbound demand |
| Scale economies | 1 | Costs scale linearly / fixed investment reused across customers | Cost per task falling as volume grows |
The maximum weighted score is 45 (15 weight points times 3).
Illustrative worked example. A hypothetical seed-stage legal workflow startup scores 3 on workflow depth, 2 on switching costs, 2 on data and evals, 1 on network effects, 2 on counter-positioning, 1 on cornered resource, 2 on speed and brand and zero on scale economies. Weighted, that is (3x3) + (3x2) + (2x2) + (2x1) + (2x2) + (1x1) + (1x2) + (1x0) = 28 out of 45, or about 62 percent. Its story rests on workflow depth. The two cheapest points to add in the next six months are network effects (bring opposing counsel or clients into shared workspaces) and switching costs (deeper integrations with document management systems).
Treat the score as a plan, not a verdict. It earns its keep in three places: quarterly planning, your data room, and the moats slide in your pitch deck.
How to answer the OpenAI question in a pitch
Many AI pitches hit some version of the same question: what stops OpenAI, Anthropic or Google from doing this? It isn't a trap. Investors don't expect proof that a lab won't; they want to see you've thought about it and that your evidence points to lasting value. A common approach is 60 to 90 seconds in four moves.
- Accept the premise. They might build a version of this, and you plan as if they will.
- Name the moat and back it with a number. For example (placeholder figures): the product runs a workflow across three parties, getting it right took 14 months of edge cases, and accuracy on production matters is X percent against Y percent for the general tools you tested.
- Show switching costs or network effects in data. The average customer has 11 integrations and six months of configured playbooks, gross revenue retention is Z percent, and 40 percent of active users collaborate with someone outside their company inside the product.
- Explain why a lab will not prioritize it. Your market needs forward deployed engineers, compliance work and domain evals. A lab can ship a general feature, but the last 10 percent of reliability in your niche is unlikely to be where it spends its engineers.
If your honest answer today is speed and a head start, say so, and show what you're building behind it. Incumbents tend to copy rather than invent mainstream products, so a fast release cadence can be a credible early defense as long as your changelog shows it.
Build order: one possible AI moat plan after product-market fit
- Prove the pain first. Find a customer with a severe problem and solve it. Speed is often your main moat at this point.
- Instrument reliability. Build an eval set from real customer cases and track accuracy weekly. That is the start of workflow depth and a data flywheel.
- Go deeper into the workflow. Map every role that touches the job and extend to the next one. Many AI companies do this with forward deployed engineers inside customer accounts; our enterprise sales guide covers the motion.
- Make it multiplayer. Add features where value rises with more teammates, agents or counterparties.
- Accumulate context. Memory, playbooks and configurations that beat a fresh install, which also blunts AI-assisted migration.
- Price where incumbents cannot follow. Per task or per outcome, wherever you can deliver it reliably.
- Re-score every quarter with the scorecard and put the evidence in your investor updates.
Moat evidence also changes how investors price your round. At today's valuations a seed investor typically needs a very large outcome, and durable revenue makes that outcome believable; our guide to high seed valuations and venture return math shows the numbers.
If you are building an AI-native company that already has real traction, 1752vc's Lightning Round is one place to test your moat answer under pressure: it is a pitch competition for those startups, and the OpenAI question is likely to come up. To tighten the moats slide first, 1752vc Pitch Review gives slide-by-slide feedback and a prioritized list of fixes.
Where we land
Build the product customers can't do without first. Then stack at least two moats on purpose, measure them, and put the evidence where investors can see it.
That's our answer, not everyone's. In a regulated market, trust and certification might outweigh everything on our list. In a consumer product, brand and speed might carry more of the load than any scorecard weight suggests.
For founders: pitch the evidence, not the endpoint. An eval curve and a retention cohort tend to say more than a model name.
For investors: ask what a well-funded competitor with the same model access couldn't rebuild in a quarter. If that list is thin, we'd treat "proprietary AI" as a question rather than a strength.
The bottom line
AI made the thin moats visible and pushed defensibility back toward the unglamorous work: workflows, context, reliability and relationships that take time to earn.
You rent the model.
You earn the moat, one integration and one edge case at a time.
Key takeaways
- In our view, code alone is a weak moat in 2026; the more durable ones tend to be workflow depth, multiplayer and agent network effects, compounding data and context, earned switching costs and counter-positioned pricing.
- A useful model test: if a better general model would make your product unnecessary, you may have a feature, not a moat.
- Hypergrowth is not the same as durability; gross retention and cohort curves are stronger evidence of a moat.
- Lock-in from trapped data is fading, while lock-in from configured logic and accumulated context is growing.
- The OpenAI question tends to be best answered with evidence (accuracy, retention, integrations, multiplayer usage) rather than a five-year theory.
Frequently asked questions
A moat for an AI startup is a structural advantage that keeps customers and margins when a frontier lab, incumbent or clone ships a similar product. In our view, the durable ones in 2026 are deep multi-party workflows, network effects between users and agents, data and context that measurably improve the product, and switching costs built from customized logic. Access to a model is not a moat on its own.
A thin wrapper that adds a prompt and an interface to someone else's model usually has little moat, and it is exposed whenever a model lab moves into applications. A product becomes more than a wrapper when it owns a complex workflow, integrates deeply into customer systems, learns from customer-specific data, and grows more useful as more people or agents use it.
Sometimes. Proprietary data tends to be a moat when it is hard to obtain, stays current and visibly improves results, ideally through an evaluation and feedback loop. a16z's 2019 analysis showed that data often brings diminishing returns and rising acquisition costs. We would treat data as one part of your defensibility and show investors a measurable quality gain from it.
A common approach is to accept that a lab might build something similar, then give evidence: the workflow depth your product handles, accuracy on real customer cases, retention, integrations and multiplayer usage. Explain why a lab is unlikely to invest in the last stretch of reliability for your niche. Many founders keep the answer to about 90 seconds and avoid claiming a fine-tuned model alone protects them.
Yes, though they look different from social networks. In AI they show up as usage data that improves models and evals, and increasingly as multiplayer features where agents act for different users, such as an assistant that asks a coworker's assistant for an answer. Once a whole team works that way, the product usually becomes much harder to leave.
Sources
- 20VC: Matt Murphy, Menlo Ventures (August 2026)
- 20VC: Jean-Denis Greze, Town (September 2026)
- 20VC: Anastasios Angelopoulos, Arena (August 2026)
- 20VC: Nikesh Arora, Palo Alto Networks, and the weekly roundup (June 2026)
- 20VC: Aaron Katz, ClickHouse, and Rory O'Driscoll and Jason Lemkin (September 2026)
- 20VC: Alex Atallah, OpenRouter (August 2026)
- Y Combinator: The 7 Most Powerful Moats For AI Startups (Garry Tan, Jared Friedman, Diana Hu, Harj Taggar)
- a16z: The Empty Promise of Data Moats
- Bessemer Venture Partners: The State of AI 2025
- Menlo Ventures: 2025, The State of Generative AI in the Enterprise
Disclaimer: This guide is for general education only and is not legal, tax or investment advice. Laws, market data and program terms change, so it may not reflect the latest developments or fit your situation. Treat it as a starting point, not a source of truth, and talk to a qualified lawyer, accountant or financial adviser before you make decisions.


