
The uncomfortable question every AI founder now faces is simple: if a foundation model can do the impressive part, what stops a competitor, or the model provider itself, from doing what you do? For thin application layers the honest answer is nothing, and the market has started pricing that in. The companies that are defensible are the vertical ones, and their defensibility does not come from the model. It comes from a data advantage that compounds with use, a place inside a specific workflow that is painful to leave, and a level of domain trust a general-purpose tool cannot earn. This is what a real data moat in vertical AI looks like, why a raw dataset is not one, and how domain-focused companies build the kind foundation models cannot copy.
Why the model is not the moat anymore
Start with the shift that reset the board. The capability that felt like magic in 2023 has become a commodity input. The price of a given level of model inference has fallen dramatically over the last few years, and open and closed models now cluster close enough in capability that a feature built purely on top of a base model can be matched quickly. When the impressive part is available to everyone at a falling price, building on it is necessary but confers no lasting edge. Analyses of what still defends an AI product in 2026, such as Valtorian's breakdown of AI moats, keep arriving at the same place: features and model access are not defensible, and the moat has to live somewhere the model cannot reach.
This is exactly why horizontal, general-purpose tools are so exposed and why narrow, domain-deep ones are not. The argument for that focus is laid out in what vertical AI is and why it beats horizontal AI in the enterprise, and the sharper version, that the only defensible AI companies being built right now are hyper-vertical, is the case in riches in the niches. The common thread is that defensibility and vertical focus are the same conversation.
The data-moat paradox: why a dataset alone defends nothing
Founders hear "data moat" and reach for the wrong thing: a big proprietary dataset, hoarded. A static pile of data is a depreciating asset, not a moat. It can be matched, licensed, scraped, or rendered irrelevant by a better base model. Proprietary data becomes defensible only when it changes the product's behavior in a loop: use generates data, the data improves the output, and the better output attracts more use. That flywheel, not the dataset, is the moat, and it is living and compounding rather than fixed.
The distinction matters because it tells you what to build. You are not trying to accumulate data; you are trying to design a product where every interaction leaves it measurably better for the next user, in a way a competitor starting today cannot shortcut because they do not have the usage. The clearest treatment of this is Avante Ventures on data network effects as the real moat in vertical AI, which draws the same line between a dead dataset and a compounding flywheel. The test is concrete: if your product would be exactly as good tomorrow with zero additional usage, you do not have a data moat yet.
The three moats that actually hold in vertical AI
Defensibility in a vertical AI company tends to come from three reinforcing sources. None of them is the model.
| Source of defensibility | Why it holds | How you build it |
|---|---|---|
| Data flywheel | Usage generates data that improves the product, which attracts more usage; a late entrant lacks the loop | Instrument the product so every interaction produces labeled, reusable signal that feeds back into output quality |
| Workflow integration | Once the product is embedded in how work actually gets done, switching cost is high and rising | Solve the whole job, not one step; connect to the systems of record and become the place the work happens |
| Domain trust and compliance | Regulated buyers need accuracy, auditability, and accountability a general tool cannot prove | Earn it with domain-correct behavior, verifiable outputs, and the guardrails the specific industry requires |
Each one is stronger in combination. A flywheel embedded in a workflow that regulated buyers trust is far harder to displace than any single element alone. And notice that all three are inherently vertical: the useful data, the specific workflow, and the trust standards are all defined by one domain. That is why a focused company can build them and a horizontal one struggles to.
Why vertical focus is what makes the moats reachable
Generality is the enemy of every one of these moats. A horizontal tool sees shallow data across many domains and deep data in none, so its flywheel never compounds in a way that matters to any single buyer. It sits beside workflows rather than inside them, because no general tool can own the specific system of record for an industry it only partly understands. And it cannot make the domain-specific accuracy and compliance guarantees a regulated buyer demands, because those guarantees are different in lending than in healthcare than in logistics.
A vertical company inverts all three. It sees deep, structured data in one domain, which makes the flywheel sharp. It can own the whole workflow because it only has to understand one. And it can meet the trust bar because it is built to one industry's rules. This is the practical reason the market has tilted toward vertical AI, and why building narrow is not a limitation but the source of the advantage. It is also why the work of getting from an industry insight to a defensible product, described in the -1 to 1 playbook, is really the work of building these moats deliberately from the start.
What this means for how you build
The strategic implication is that the moat is not something you find, it is something you engineer into the product from day one. Three moves follow. First, instrument for the flywheel: make sure every use of the product produces signal you can feed back into quality, and measure whether the product is actually getting better with usage, because if it is not, you do not have the loop yet. Second, aim to own the workflow rather than a single step, so the product becomes the place the work happens and the switching cost climbs over time. Third, treat domain trust as a feature, building the accuracy, auditability, and compliance behavior the specific industry requires, because in a regulated vertical that trust is both the hardest thing to copy and the reason a buyer chooses you.
At gAI Ventures we co-found vertical AI companies in financial services, enterprise productivity, and commerce, and this is the substance of that work: not wrapping a model, but building the data flywheel, the workflow ownership, and the domain trust that make a company hard to displace. That conviction runs through our vertical AI investment theses and the gAI Ventures manifesto, and it shows up in the companies we build alongside expert operators across the gAI Ventures portfolio. The operators and builders behind that are on the gAI Ventures team page, more thinking is on the gAI Ventures blog, and the broader picture of how we work is at gAI Ventures. If you are an expert operator sitting on a domain insight, the defensible version of your company is the one where the data, the workflow, and the trust all compound in your favor.
Frequently asked questions
- Is proprietary data a moat for an AI company?
- Only when it is part of a living loop, not when it sits as a static pile. A fixed dataset can be matched, licensed, scraped, or made irrelevant by a better base model, so on its own it is a depreciating asset. It becomes a moat when usage generates data that measurably improves the product, and the better product attracts more usage. The flywheel is the defensible thing, not the dataset. A quick test is whether your product would be any better tomorrow with zero additional usage; if not, the moat is not there yet.
- Why isn't building on a foundation model enough to be defensible?
- Because model capability has commoditized. The cost of a given level of inference has fallen by orders of magnitude, and models now cluster close enough that a feature built purely on top of a base model can be matched quickly, including by the model provider. Access to a strong model is table stakes rather than an advantage. Defensibility has to come from somewhere the model cannot reach: a compounding data flywheel, deep integration into a specific workflow, and domain trust that a general-purpose tool cannot prove.
- What makes vertical AI more defensible than horizontal AI?
- The three durable moats, a data flywheel, workflow ownership, and domain trust, are all specific to a domain, which a vertical company can build and a horizontal one cannot. A general tool sees shallow data everywhere and deep data nowhere, sits beside workflows instead of inside them, and cannot make the accuracy and compliance guarantees a regulated buyer needs. A vertical company sees deep data in one domain, can own the whole workflow, and can meet one industry's trust bar, so its moats compound where a horizontal tool's do not.
- How do you actually build a data moat?
- You engineer it into the product rather than accumulate it. Instrument the product so every interaction produces labeled, reusable signal that feeds back into output quality, and track whether the product measurably improves with usage. Aim to own the entire workflow rather than a single step, connecting to the systems of record so the product becomes where the work happens and switching costs rise. And build the domain trust, accuracy, auditability, and compliance behavior the specific industry requires. Done together, these create a loop a later entrant cannot shortcut because they lack the usage.
- Does a vertical AI company still need the best model?
- It needs a good-enough model, not a uniquely best one, because the model is the commoditized input rather than the differentiator. What matters is what surrounds the model: the proprietary feedback loop, the workflow integration, and the domain-specific guardrails. A vertical company should stay able to adopt whichever base model is strongest over time, while investing its real effort in the data flywheel and workflow ownership that competitors cannot copy by swapping in the same model. The defensibility lives in the system around the model, not the model itself.
End of article · #008
