The AI moat is not the model

Ismail El HoucheimiAI strategy6 min read

By Ismail El Houcheimi

For a couple of years the implicit assumption in AI was that the best model wins. It was a reasonable assumption when capability gaps were large and obvious. It has stopped being reasonable, and you can read the shift most clearly not in benchmark tables but in the commercial behaviour of the frontier labs.

Three things have been happening at once: monetization is being tightened, the labs are shipping applications rather than only capabilities, and there is a sustained push to stop competitors training on frontier outputs. These look like separate stories. I think they are one story, and it is a story about where the defensible value actually sits.

A lead is not a moat

A moat is something that makes an advantage expensive to copy. Model quality does not qualify, for a straightforward reason: the gap between the frontier and competent open weights has been closing on a rhythm of roughly six to twelve months, and it has done so repeatedly. Being ahead on capability is a real advantage with a short half-life. Every month you are not converting it into something more durable, it is depreciating.

This is not a prediction that models stop mattering. It is an observation that model quality behaves like a fast-moving commodity input rather than a structural advantage. The things that resist copying are more boring: who has the distribution, who is trusted with sensitive work, and how much product surface area sits between the user and the raw capability.

First move: closing the cheap paths in

A flat consumer subscription used as a de facto cheap API, routing a personal plan through third-party tooling to get inference at a fraction of metered cost, has been steadily shut down. Terms of service have been clarified to prohibit sharing credentials, programmatically extracting outputs, and using outputs to train competing models. Verification requirements have appeared for access to more advanced capabilities.

Read narrowly, this is revenue protection: stop the arbitrage, make builders pay metered rates. Read in context, it is the first half of a strategy. Every leak is a path by which someone else builds a competing product on your capability while you carry the cost of producing it.

Second move: shipping into categories rather than enabling them

The more consequential shift is what the labs now ship. Not better chat, but products that occupy whole categories: security tooling that scans for vulnerabilities and proposes patches, legacy-code modernization, AI embedded directly into the documents and presentations where work output actually lives, multi-agent development environments bundled into consumer plans.

The pattern worth noticing is the positioning. These are not features demonstrating what a model can do. They are attempts to become an operating layer for knowledge work. And when markets have repriced incumbents on the back of these announcements, that reaction is the tell: participants are reading them as category entry, not as capability news.

Third move: why the distillation fight is the same fight

Labs have publicly accused competitors of industrial-scale distillation, systematically using frontier outputs to train cheaper models that approximate the same capability. Taken on its own this reads as an IP dispute. Placed next to the other two moves, it is the load-bearing piece.

The logic runs like this. The application-layer strategy only works if the capability underneath stays scarce for long enough to build distribution and trust on top of it. If anyone can distill their way to good-enough capability at negligible cost, then anyone can build competing applications on open weights, and the head start evaporates before it has been converted into anything durable. Anti-distillation is not really about protecting the model. It is about buying time for the layer above it.

Which is why the subscription crackdowns and the distillation accusations are two sides of one coin: reduce leakage below, capture value above. They only look like separate stories if you assume the model was supposed to be the moat.

What this implies if you are building

The strategic reading is reasonably clear, and it is not "avoid AI" or "build your own model." It is also the bet behind Serena AI: own the context and the workflow, and treat the model as a swappable input.

  1. Own something the model does not give you

    Proprietary context, workflow depth, integrations, a trusted position in a regulated process. If your product is a thin wrapper over a prompt, you have no answer to the supplier shipping the same thing. Owning the execution graph is one concrete version of this.

  2. Treat model choice as replaceable

    Assume you will change providers. Designing for that is cheap early and expensive later, and it converts supplier risk into a procurement decision.

  3. Compete on trust where you can

    In domains where being confidently wrong is costly, the willingness to show reasoning and accept review is a product advantage, not overhead.

  4. Rebuild processes rather than bolting AI on

    Adding a generate button to an unchanged workflow produces a demo. Redesigning the workflow around what is now cheap produces a different cost structure.

The response I would argue hardest against

There is a framing of all this that leads somewhere I think is simply wrong: if AI absorbs the work, reduce the headcount doing it. It looks decisive and it shows up immediately in a cost line.

It misreads what actually became cheap. What got cheaper is producing output: drafts, code, summaries, first passes. What did not get cheaper is judgment: knowing which output is worth having, which is subtly wrong, what the customer actually meant, which tradeoff the business can live with. Cut the people holding that judgment and you have not automated the work, you have removed the only part that was hard to replace while keeping the part your competitors can also now buy.

There is a genuine divide in how AI is being framed right now: replacement on one side, augmentation and keeping humans in the loop on the other. I am firmly on the second side, and not for sentimental reasons. The more compelling version, and the one that holds up commercially, is AI that helps people do better work, make better decisions, and move faster without removing human judgment from the loop. The organizations that pull ahead will be the ones that turned their people into force multipliers, not the ones that got smaller fastest.

Key takeaways

  • Model quality is a lead with a six-to-twelve-month half-life, not a moat.
  • Subscription crackdowns, application-layer expansion, and anti-distillation are one strategy: reduce leakage below, capture value above.
  • If you build on a frontier model, expect your supplier to enter your category with better margins.
  • Own the context, workflow, and trust the model cannot supply; treat the provider as replaceable.
  • What got cheap is producing output, not judgment, which is why cutting headcount is the wrong read.

Frequently asked questions

Does this mean model quality is irrelevant now?

No. It means it is an input rather than a defence. A materially better model still produces a materially better product, and being on a weak one is a real disadvantage. The claim is narrower: capability alone will not keep anyone out, so it should not be the thing you are counting on.

Should we build on open weights to avoid supplier risk?

It changes the risk rather than removing it: you trade a supplier who might compete with you for the operational cost of running and improving models yourself. For most application companies that is a worse trade. The useful hedge is architectural: make the provider swappable, not vertical integration.

How do you tell a thin wrapper from a real product?

Ask what survives if the underlying model were freely available to everyone tomorrow. If the answer is "nothing much", the product was the access. If the answer involves accumulated context, workflow depth, integrations, or an earned position inside a process someone depends on, that part is yours.

Is the augmentation position just a more comfortable thing to say?

It would be, if it were only a values claim. The commercial argument is that the scarce input shifted rather than disappeared: output is cheap, judgment is not, and judgment is what your competitors cannot also buy off the shelf. An organization optimizing away its judgment is optimizing away its remaining differentiation.

Put this into practice

Serena keeps tasks, notes, projects, and your calendar in one workspace, so the plan you make in the morning is still readable when the day changes.
Sign Up for Free!