Blog Post

Moats in the Age of AI

Daniel Malinovski

·

Co-Founder, Simplicity Group

·

Moats in the Age of AI

For two decades, software companies competed primarily on speed of execution. Build the MVP faster, ship features faster, iterate to product-market fit faster. The orthodox playbook was clear: the first team to compound improvements through user feedback won the market. AI has now broken that playbook. When a solo developer can replicate a core SaaS feature over a weekend, dev velocity is no longer a moat; it is the floor every serious team operates on. The question for 2026 is what actually defends a software business once code itself has become free, fast, and infinite.

This piece walks through what the old moat was, why AI dismantled it, what the new moats look like, and how the two firms with the loudest views on this topic, a16z and Paradigm, are framing the shift.

IThe Old Moat: Dev Speed and Shipping Speed

When Marc Andreessen wrote that software was eating the world in 2011, he was implicitly making a thesis about shipping velocity. The winner in any vertical was whoever deployed code into the market fastest, then compounded improvements via real-time user feedback. Slack out-shipped HipChat and Yammer on real-time messaging between 2014 and 2016. Notion out-iterated Confluence and Quip on the document-database hybrid. Figma reached parity with Sketch and Adobe XD in roughly 24 months by shipping browser-native every week. The implicit assumption underneath all of this was that if you could ship 2x faster than the next entrant, you held a permanent head start.

The benchmark was reasonable as recently as 2023: a five-person product team needed roughly three months to ship a meaningful new SaaS feature. By 2024 that compressed to between two and six weeks. The cost of writing software was high, the talent supply was thin, and the gap between "idea" and "shipped product" was measured in months. That gap is where defensibility lived.

How AI Collapsed the Build Cycle

AI coding tools have compressed the build cycle from months to hours. The numbers tell the story. The same SaaS feature that took 5-person teams three months in 2023, and 2 to 6 weeks in 2024, now ships in a day, sometimes in hours, using Cursor, Bolt, Lovable, and Claude. Steven Cen put it bluntly: when a solo developer can replicate your core feature in a weekend, what exactly are you defending?

The proof points sit in the AI-native tooling layer itself. Cursor reached USD 500 million in ARR within 36 months. Lovable hit USD 100 million in ARR eight months after crossing USD 1 million, then doubled to USD 200 million ARR four months later, making it the fastest-growing startup on record by ARR pace. Vercel's v0 has 3.5 million unique users; Windsurf reached USD 100 million ARR in 18 months. This compression is now visible at the product level too. David George at a16z framed it by stating “a strong software product used to have ten years of runway, then five years; now it has maybe five weeks before competitors catch up.”

The implication of AI is that shipping speed is now the floor, not the ceiling. Every serious team can ship at AI-native pace. Speed can no longer act as a moat by itself. This is why the venture commentary has shifted from "build fast and iterate" toward "what compounds that AI cannot copy in a weekend?"

The New Moats

The defensible advantages now live outside the code. They sit in assets that take time, trust, or legal permission to accumulate. Three categories matter most: data, distribution, and the legal stack of licences and IP. Each is necessary, but none are individually sufficient. The strongest companies in 2026 are stacking all three.

A. Data

A common piece of received wisdom in the past 18 months is that data is no longer a moat. This view is wrong, and worth taking apart, because acting on it leads founders toward the wrong defensibility plan.

The "data is dead" thesis rests on three claims: foundation models have already absorbed most useful public datasets; synthetic data can fill the gaps; and retrieval-augmented architectures can pull context from public sources at query time. Each is true in isolation. None of them undermines the moat once the question shifts from public data to proprietary, real-time, behavioural, or permissioned data, because that is the data foundation models cannot get to.

The naive version of "data as a moat", raw volume of generic data, is dead. The version that still works is a proprietary data flywheel where every user interaction generates feedback that the product alone has access to. Bloomberg, Palantir, and Tesla are the canonical proof that this version of the moat compounds for decades. Bloomberg's terminal moat is built on four decades of proprietary financial data feeds licensed under contracts no entrant can replicate. Palantir's defensibility comes from being inside the customer's data infrastructure, not from owning a smarter model. Tesla's autonomy progress comes from real-world driving data only Tesla generates.

a16z's own 2019 essay The Empty Promise of Data Moats still applies, and it is consistent with the case for data as a moat, not against it. Casado and Bornstein argued that most claimed data network effects are scale effects with diminishing returns, and beyond roughly 40 percent of common queries there is no advantage to collecting more data at all. The implication is not that data is dead. It is that data only acts as a moat when it is generated inside the product, high-resolution and structured, tied to specific workflows, compounding with usage, and legally fenced.

The clearest live examples of compounding data assets in 2026: Reddit disclosed USD 203 million in aggregate licensing contracts in January 2024, including roughly USD 70 million annually from OpenAI and USD 60 million annually from Google, and is now the most-cited source in AI-generated answers, roughly 3x Wikipedia, according to Profound AI. News Corp signed a USD 250 million-plus, five-year deal with OpenAI; Meta added a separate content license worth up to USD 50 million per year. The New York Times secured USD 20 to 25 million annually from Amazon for AI training rights covering its core newsroom, NYT Cooking, and The Athletic. Harvey, the legal AI now valued at USD 11 billion, builds firm-specific embeddings inside each law firm's security perimeter; generic LLMs cannot replicate the corpus because access is contractually fenced. Motorq pulls direct OEM telemetry no competitor can access; Inspiren's senior-living sensors capture privacy-protected behaviour data unique to each facility.

The right founder question is not "how much data do you have?" but "what data do you generate that no one else can?"

B. Distribution

A second piece of received wisdom in 2026 is the inverse of the first. It says that distribution is the only moat. The strongest version of this thesis comes from a16z's Bryan Kim: in consumer AI, momentum is the moat. The framing has spread far enough that founders increasingly treat product moats as obsolete and pour everything into reach.

This view is half right. Distribution genuinely matters more in the AI era because foundation models are commoditised, capability gaps close in weeks, the cost of building has collapsed, and the cost of being heard is rising. AI-mediated discovery, through ChatGPT, Perplexity, Gemini, and Claude are becoming a fundamental new distribution layer in its own right.

The shape of the chatbot market is the cleanest example. ChatGPT's chatbot market share fell from 87.2 percent to 68.0 percent in twelve months according to Similarweb. Gemini moved from 5.4 percent to 18.2 percent over the same window, roughly 237 percent year-on-year growth, driven almost entirely by Android's default integration rather than product superiority. Pure product quality lost to platform-owned distribution.

The strong version of "distribution is the only moat" is wrong, however. Distribution is necessary; it is not sufficient. Companies that own distribution but no compounding asset underneath erode quickly when the next platform shift arrives. Jasper held the dominant distribution position in early consumer AI in 2022 before ChatGPT shipped a competing product and collapsed Jasper's traffic and revenue inside two quarters. Quibi spent USD 1.75 billion acquiring distribution and audience attention with no compounding asset and shut down in six months. Friendster and MySpace each held early consumer-internet distribution and were displaced inside months once Facebook combined distribution with a stronger network effect.

Distribution amplifies whatever sits underneath it. If the layer underneath is a real product moat, distribution compounds the lead. If it is a thin wrapper over a foundation model, distribution buys time, not defensibility. The right framing is that distribution is the multiplier, while data flywheels, embedded workflows, and licences are the underlying asset. Companies winning in 2026 are running both.

The three working layers of the distribution moat in 2026 are default positioning (Google Search, iOS Siri, Android Gemini, Microsoft Copilot inside Office, where owning the default is owning demand); generative engine optimisation, or being the source AI engines cite in answers (Reddit, Stack Overflow, Wikipedia, government datasets, top-tier publications, where the new "page one of Google" is being inside the generated answer); and founder-led trust and network, where in B2B a credible operator shortcuts CAC by orders of magnitude because trust is the scarcest resource.

C. Licensing and IP

The third category is the most under-discussed and the most structurally durable. It covers any moat that derives from a legal mechanism rather than a technical one. In any sector where AI cannot operate without legal permission, the legal asset itself becomes the moat. Four forms matter: content licences (paid, exclusive, or first-look access to a proprietary training corpus); regulatory approval (clearance to operate in a regulated industry through bodies such as the FDA, FINRA, SEC, MHRA, MAS, FCA, or under MiCA); industry compliance certifications (HIPAA, SOC 2, ISO 27001, FedRAMP, GDPR-aligned data residency); and intellectual property (patents, trademarks, copyright, trade secrets).

This category is durable for one reason: the asset is created through calendar time and legal process, not through capital. Approvals, registrations, patents, and corpus deals run on timelines that cannot be accelerated by money. Most regulatory clearances take 12 to 36 months even for well-funded entrants. Patent prosecution averages 24 to 36 months at the USPTO. Compliance work compounds; once established, every additional product feature ships under the same wrapper. The cost is not money; it is years.

The live examples on the licensing side are stacking up. By mid-2026 the disclosed AI content-licensing market sits at roughly USD 1 billion in annual run-rate across Reddit, News Corp, NYT, AP, Stack Overflow, Shutterstock, and others. In healthcare, FDA clearance for diagnostic AI tools (Aidoc, Paige.ai) gates the market for years; competitors face full clinical-trial cycles before they can ship. In legal AI, Harvey's contract architecture inside each law firm is itself a moat. In fintech, broker-dealer or investment-adviser registration creates the same structural barrier; in tokenisation specifically, MiCA in Europe, FINMA in Switzerland, and MAS in Singapore are hardening the moat for licensed players.

On the IP side, the pattern splits into three. Trade secrets are the practical moat for foundation-model labs. Sam Altman has publicly stated that trade secrets are OpenAI's primary moat; the engineering recipe to make a transformer work at scale (training-data curation, RLHF processes, evaluation harnesses) is not in any paper. Anthropic's Constitutional AI methodology is similarly closely held. The structural reason is that the public architecture has been free since the original transformer paper in 2017; only the implementation is proprietary. Patents work best as defensive insurance and in adjacent sectors: ARM Holdings runs a pure IP licensing business in which every smartphone, server, and AI accelerator pays ARM royalties, and the company re-listed in 2023 at a USD 65 billion valuation on this model alone. In hardware AI, Cerebras, Groq, and Etched hold chip-architecture patents that create supply-side moats. In AI-native drug discovery, Recursion and Insilico Medicine are racing to patent novel AI-generated molecules; each granted patent creates a 20-year exclusivity window worth billions if the molecule reaches market. Trademarks and brand IP are durable when established and fragile when challenged: OpenAI lost its USPTO trademark application for "GPT" because the term was deemed generic, but its "ChatGPT" mark is now one of the most valuable brand IP assets in technology.

The clearest historical example is Coca-Cola. The formula is a trade secret protected for over 130 years; the brand is global trademark IP; the bottling rights are licensed regionally. IP is the substrate; licensing is the revenue model on top. For AI in 2026, the same pattern is repeating: trade secrets and brand IP are the substrate, regulatory clearance and content licences are the revenue mechanisms, and the combination is what a foundation model cannot replicate over a weekend.

Wilson Sonsini's 2026 outlook frames the regulatory side directly: compliance requirements demand deep domain investment up front, which compounds into a durable moat that general-purpose entrants cannot shortcut. Menlo Ventures' parallel framing for vertical AI is that every company should run two moats at once. A defensive moat (regulatory, compliance, certification, IP) buys time; a generative moat (data flywheel, embedded workflow) does the long-term work.

For Digital Assets and tokenisation specifically, this combined licensing-and-IP moat is arguably the strongest of the three categories. Regulated rails, real-world assets, securities tokens, and payments cannot be vibe-coded around, and the legal architecture protecting them (entity licences, custody approvals, IP held by infrastructure providers) takes years to assemble.

What a16z Says

a16z has been the most prolific public voice on this question, and their framing is best understood as a recalibration of the classic moat checklist rather than its abandonment.

In their consolidated view, network effects strengthen in the AI era because AI amplifies coordination value across platforms such as Salesforce and Stripe. Switching costs weaken because AI agents reduce migration friction; competitors will increasingly target the core modules of an incumbent rather than just the edges. Brand strengthens because more market noise raises the trust premium for known names. Process power is the biggest winner; deep, embedded workflows are now the strongest defensibility (Harvey, Decagon, Filevine). Cornered resources, including proprietary data, remain real but only in narrow domains.

David George's Two Paths Left for Software thesis pushes the implication into operating reality. Every existing software company must either accelerate growth (10-plus percentage points of YoY revenue growth from genuinely new AI-native products inside 12 to 18 months, with executive-team rebuild, 50 percent of R&D moved to new AI surfaces, and a shift from seat-based to token- or outcome-based pricing) or maximise profitability (rebuild to 40-percent-plus operating margins, 50 percent ideally, inside 12 to 24 months). The middle ground (steady SaaS growth at 20 percent with 25 percent margins) is gone.

Bryan Kim's Momentum is the Moat essay argues that in pure consumer AI no real moat exists yet other than launch velocity, distribution capture, and continued shipping pace. The flock-of-pigeons metaphor: launch together, those who climb fastest stay highest.

Two earlier essays still inform the current view. The Empty Promise of Data Moats (Casado, Bornstein) warns that most data moats are scale effects with diminishing returns; real data moats need proprietary sources, first-mover lock-in to embedded expertise, or quality-critical applications. Trading Margin for Moat argues that the most defensible AI startups should accept Palantir-style lower gross margins in order to embed via Forward Deployed Engineers and build workflow lock-in. Salesforce burned USD 52 million to generate USD 22 million in early revenue and is now worth USD 254 billion; the comparable AI-era playbook is FDE-heavy implementation rather than pure self-serve.

The composite a16z view is straightforward: the moat is not the model. The moat is the workflow, the data, the integration, and the trust. Anyone who picks one of those four can be replicated; companies that own all four win.

What Paradigm Says

Paradigm's view is structurally different from a16z's because Paradigm is building the thesis at the AI x crypto intersection rather than at the application layer.

Founded in 2018 by Matt Huang and Fred Ehrsam, the firm was originally crypto-native with USD 2.5 billion-plus AUM. In Q1 2026 it raised USD 1.5 billion for a new fund explicitly extending into AI, robotics, and frontier tech. Huang publicly framed the move as additive infrastructure rather than a pivot, writing that "Paradigm has never been more dedicated to crypto."

The core thesis is that the durable moats live in the rails, not the models. Models are commoditising; the AI agents on top of them will need infrastructure to transact, identify, settle, and coordinate at machine speed. Crypto provides the permissionless rails (programmable money, verifiable identity, settlement finality) that autonomous AI agents need. AI provides the demand crypto has been searching for: genuine high-frequency, machine-driven economic activity rather than speculation.

The concrete bets follow the thesis. Tempo, launched in September 2025, is a payments-focused blockchain co-built with Stripe and explicitly designed for global payments, remittances, microtransactions, and agentic payments (machine-to-machine settlement). EVMbench, built with OpenAI in 2025, is an open evaluation framework that tests AI agents on detecting, patching, and exploiting smart-contract vulnerabilities; it positions Paradigm as the trusted neutral party for AI x crypto safety benchmarks. The firm continues to back stablecoin infrastructure, restaking, and MEV-aware execution layers, the parts of the stack that AI agents will route trades through.

Huang's framing on defensibility, from his Colossus interview, is the cleanest summary: defensibility cannot be retrofitted; deep tech founders must commit to it from day one; even "picks and shovels" providers become commodities without proper moats. In AI x crypto, the moats sit at the protocol layer (settlement, identity, trust, neutrality), not at the application surface.

The implicit conclusion is that there are two layers of moat in the AI era. Application-layer products will fight on speed, distribution, and data flywheels (the a16z view). Infrastructure-layer plays (the Paradigm view) compete on protocol adoption, neutrality, and developer ecosystem; once a stablecoin payment rail or an AI-agent identity standard hits critical mass, the moat behaves more like a Layer-1 network moat than a SaaS moat. The AI-crypto agentic web is the next "interoperability is the moat" story; the analogy Paradigm uses internally is email and TCP/IP.

Conclusion

The old moat (dev speed, shipping speed) is now table stakes; AI made it free.

The new moats are non-software. Data flywheels compound through proprietary use (Reddit, Harvey, Inspiren, Motorq). Distribution surfaces capture mindshare and defaults (ChatGPT, Gemini, Perplexity, founder-led B2B trust). Licences and IP gate the market through content rights, regulatory clearance, patents, trade secrets, and brand IP (News Corp, NYT, FDA-cleared health AI, MiCA-licensed tokenisation, ARM, OpenAI's training-recipe trade secrets, the ChatGPT trademark).

Two pieces of received wisdom are worth pushing back on. "Data is no longer a moat" is wrong. Public data is commoditised; proprietary, real-time, behavioural, and permissioned data is more defensible than ever, and the firms accumulating it (Bloomberg, Palantir, Tesla, Reddit, Harvey) are doing so under structurally widening leads. "Distribution is the only moat" is also wrong. Distribution is the multiplier; without a compounding asset underneath, it erodes the moment the next platform shift arrives, as Jasper, Quibi, and MySpace each demonstrated.

a16z's framing: process power, network effects, and brand strengthen; switching costs weaken; data moats only work where data is proprietary and compounding. Paradigm's framing: at the infrastructure layer, the moats live in protocol-level settlement, identity, and AI-agent rails; crypto and AI converge because each provides what the other has been missing.

The founder test for 2026: if a competitor cloned the product over a weekend, what would still be different on Monday? In 2026 the answer is a dataset, a distribution surface, or a licence; and almost never a feature.

Sources: a16z (Andreessen, Casado, George, Kim, Bornstein), Paradigm (Huang, Ehrsam), Insight Partners, Menlo Ventures, Wilson Sonsini, Profound AI, Similarweb, TechCrunch, Bloomberg, Sacra, Steven Cen.

Co-Founder of Simplicity Group. MSc Economics. Advises digital asset and AI businesses on distribution and token economy design; speaker at 25+ conferences across 10+ countries.

Category

Go To Market

Read Time

Go To Market

Brief

Analysis of defensible software moats as AI reshapes code, distribution, and data advantages.

Copy Link

Copied!

Share with founders, operators, and teams building in crypto.

Put this into practice

If this article raised questions about your own token or go-to-market plan, our team can help you work through them.

Latest insights

Bottom Row

Simplicity Group provides strategic consulting and advisory services only. Nothing on this website constitutes financial, investment, or legal advice, nor should it be construed as a solicitation or offer to buy or sell any digital asset or security. Digital assets involve significant risk, including the possible loss of principal. Past results do not guarantee future outcomes. Simplicity Group is not a registered investment advisor, broker-dealer, or financial institution. Consult a qualified professional before making any financial decisions.

Simplicity Group operates through Simplicity Blockchain Consultancy Ltd (United Kingdom) and Simplicity Consultancy FZ-LLC (RAKEZ, United Arab Emirates).


© 2026 Simplicity Group. All rights reserved.

Bottom Row

Simplicity Group provides strategic consulting and advisory services only. Nothing on this website constitutes financial, investment, or legal advice, nor should it be construed as a solicitation or offer to buy or sell any digital asset or security. Digital assets involve significant risk, including the possible loss of principal. Past results do not guarantee future outcomes. Simplicity Group is not a registered investment advisor, broker-dealer, or financial institution. Consult a qualified professional before making any financial decisions.

Simplicity Group operates through Simplicity Blockchain Consultancy Ltd (United Kingdom) and Simplicity Consultancy FZ-LLC (RAKEZ, United Arab Emirates).


© 2026 Simplicity Group. All rights reserved.

Bottom Row

Simplicity Group provides strategic consulting and advisory services only. Nothing on this website constitutes financial, investment, or legal advice, nor should it be construed as a solicitation or offer to buy or sell any digital asset or security. Digital assets involve significant risk, including the possible loss of principal. Past results do not guarantee future outcomes. Simplicity Group is not a registered investment advisor, broker-dealer, or financial institution. Consult a qualified professional before making any financial decisions.

Simplicity Group operates through Simplicity Blockchain Consultancy Ltd (United Kingdom) and Simplicity Consultancy FZ-LLC (RAKEZ, United Arab Emirates).


© 2026 Simplicity Group. All rights reserved.

Bottom Row

Simplicity Group provides strategic consulting and advisory services only. Nothing on this website constitutes financial, investment, or legal advice, nor should it be construed as a solicitation or offer to buy or sell any digital asset or security. Digital assets involve significant risk, including the possible loss of principal. Past results do not guarantee future outcomes. Simplicity Group is not a registered investment advisor, broker-dealer, or financial institution. Consult a qualified professional before making any financial decisions.

Simplicity Group operates through Simplicity Blockchain Consultancy Ltd (United Kingdom) and Simplicity Consultancy FZ-LLC (RAKEZ, United Arab Emirates).


© 2026 Simplicity Group. All rights reserved.

1400

The best time to focus on revenue was on day one.
The second best time is now. 

Book a call today and we will tell you exactly what is holding your growth back. 

Bottom Row

Simplicity Group provides strategic consulting and advisory services only. Nothing on this website constitutes financial, investment, or legal advice, nor should it be construed as a solicitation or offer to buy or sell any digital asset or security. Digital assets involve significant risk, including the possible loss of principal. Past results do not guarantee future outcomes. Simplicity Group is not a registered investment advisor, broker-dealer, or financial institution. Consult a qualified professional before making any financial decisions.

Simplicity Group operates through Simplicity Blockchain Consultancy Ltd (United Kingdom) and Simplicity Consultancy FZ-LLC (RAKEZ, United Arab Emirates).


© 2026 Simplicity Group. All rights reserved.