When every competitor can rent the same frontier model, the model itself no longer sets you apart, and five other things step in. Proprietary data with a feedback loop gives your system lessons nobody else's has seen. Workflow position places your product where the work already happens. Domain evaluation tells you, in numbers, whether the system is right for your task. Trust, security and compliance open the door to buyers who cannot take the risk. Cost and latency engineering determines whether the product makes money at scale.
A rival can copy your prompts in an afternoon. The five above cannot be copied that way, since each is made of time, permission and operating history, and none of it is code.
This article is written for founders, product leaders and CTOs deciding where the next year of AI budget should go. Every figure was checked on 1 October 2026 wherever its source page could be opened, with the date and sample size noted beside it. If a primary page could not be opened, the figure is credited to the secondary report that quotes it. A popular statistic with no traceable source has been left out and named.
Key Takeaways
The models have converged. In the Stanford 2026 AI Index, four labs sit within 25 Elo points of each other on the Arena leaderboard, and the top 15 models span roughly 46 points. The report says pressure is shifting to cost, reliability and domain-specific performance.
The Stanford data is a March 2026 snapshot. Open models trail the best closed model by 49 Arena points. A gap that small does not protect anyone.
Adoption is not profit. In McKinsey's August 2026 survey of 1,719 respondents (as summarised by The Register), 37% attribute any EBIT impact to AI and only 6% qualify as high performers.
Public text is finite. Epoch AI (June 2024 estimate) puts the usable stock at around 300 trillion tokens, with a fully-used date somewhere between 2026 and 2032. Private data is what stays scarce.
Price per unit of capability is falling about 13x a year, per Epoch AI (22 September 2026). That helps you and every competitor equally, so the moat sits in how you use it.
Breaches now reach AI systems. IBM's 2026 report (602 organisations) found more than 20% reported a breach targeting AI models or applications, at a global average cost of $4.99M.
EU high-risk AI obligations moved to 2 December 2027, but transparency duties under Article 50 still started on 2 August 2026.
Frequently Asked Questions (FAQ)
Yes. The moat is the five advantages around the model, and none of them requires owning it. The Stanford 2026 Index shows four labs within 25 Arena points, so the model is increasingly an interchangeable input. You need the ability to switch models cheaply, which depends on having your own evaluation set, along with the data, workflow position and trust that the model vendor does not supply.
Let's connect and create something amazing together!
Got an idea or project in mind? Whether it's custom software, a dedicated dev team, or help with digital transformation, we're here for it. Reach out—we'll bring your vision to life.
Contact us
Prefer to speak directly? You’ll find our address, email, and contact details right here.
Office Location
Block A1 Third Floor, Rathinam TechZone, SEZ Campus Pollachi Main Road, Eachanari, Coimbatore, Tamil Nadu 641021, India
Thinking through a new idea or stuck with a challenge? Drop us a message—we'll listen, brainstorm, and help move things forward.
Every figure above is sourced inline in the sections below, with the date each source was read.
Why "Identical Models" Is the Right Starting Assumption
Plan on the assumption that the model is a commodity, since the evidence points that way.
The 2026 report is the latest edition of the Stanford AI Index. It measures model quality with the Arena platform, where people vote blindly between two models' answers and the votes become Elo ratings. According to its technical-performance chapter, the top models as of March 2026 come from Anthropic (1,503), xAI (1,495), Google (1,494) and OpenAI (1,481), all within 25 points of one another. Alibaba (1,449) and DeepSeek (1,424) come next. The chapter also says the top 15 models cover only about 46 points and that confidence intervals overlap for many of them, so "no single model dominates the leaderboard."
Source: Stanford HAI, 2026 AI Index Report, chapter 2 (Technical Performance), Arena Leaderboard values as of March 2026; read 1 October 2026. The bars start at 1,400 to make the differences visible, so their lengths do not show proportional quality. This is the most recent edition; the 2027 report is not yet out.
The Index says competitive pressure is moving toward "cost, reliability, and domain-specific performance." Open models are close behind as well, with the top closed model ahead of the best open one by 49 points in March 2026. That is roughly the outline of this article: if the model separates nobody, whatever separates companies must sit somewhere else.
What Counts as a Moat Here
Here, a moat is an advantage a well-funded competitor cannot reproduce just by signing up for the same API. A simple test helps. Suppose your rival had your model, your prompts and a large budget: how long would matching you take, and what would they need that money cannot directly buy?
The usual answers fall away under that test. A clever system prompt can be rewritten from a few screenshots, and a model choice can be matched the day the vendor ships a better one. A polished chat window takes a design sprint. The things that survive share a trait: they need calendar time, somebody else's permission, or a record of your own operations.
Candidate
Fails the test because
Survives if
Prompts and system instructions
Reproducible from outputs in days
They encode a proprietary process that also lives in your data
Choice of model
Every vendor's model is available to everyone
You can swap models cheaply and have the evaluations to know when to
A chat interface
Copyable in a sprint
It sits inside a workflow people cannot leave
Being first
Speed decays once the category is obvious
First position produced data, integrations or trust that compound
1. Proprietary Data and the Feedback Loop
Proprietary data is information your competitors cannot obtain, and a feedback loop is the mechanism through which using your product generates more of it. Together they come closest to a classic moat in AI, and they are also the one people fake most often.
Why public data stops being the differentiator. The base models were trained on roughly the same public internet. Epoch AI, which tracks AI inputs, estimated in a June 2024 paper that the effective stock of quality-adjusted, human-generated public text is around 300 trillion tokens, and that it will be fully used "at some point between 2026 and 2032" (an 80% confidence interval). The same publication names what lies beyond public text: images and video, "private data such as instant messaging conversations," and synthetic data. The estimate is more than two years old, and it is the most recent edition of that specific analysis we found, so read the window as a planning range instead of a forecast for this year.
In practice, anything on the open web is already inside every frontier model. What sits behind your login, in your contracts, in your support history or in your machines' sensor logs is not.
What makes data proprietary in practice
Volume alone does not qualify a dataset. Four properties decide whether it is a moat or a storage bill:
Exclusivity. You hold it through a contract, a position or physics, and no competitor can license the same thing.
Outcome labels. The data records what happened next, such as the claim being paid, the part failing or the customer renewing. Raw logs without outcomes teach a model little.
Rights. You are legally allowed to use it for this purpose. Customer data often carries purpose limits, and teams tend to find this one late.
Freshness. New data keeps arriving. A static archive loses value over time.
The feedback loop is the part that compounds
A dataset bought once gives you a head start, while a loop works as an engine. Its shape is fixed. The product does something, the user accepts, edits or rejects it, and that reaction is recorded as a labelled example that improves the next attempt.
Several things have to hold for this to work. Use has to be daily, otherwise the loop turns slowly. The reaction has to be captured in structured form, because an edit left in a free-text box is lost. And you need permission to learn from it. A rival with a bigger model but no users has nothing to feed in.
2. Workflow Position and Distribution
Workflow position means your product sits at the point where work actually gets done, so leaving it costs the customer something. Distribution means you already reach customers through existing contracts, integrations or habits, so a new feature arrives with an audience.
Incumbents have this moat and start-ups envy it, and the survey data backs it more directly than any of the others.
The adoption-profit gap
Nearly everyone has adopted the technology, and few have captured the value. McKinsey's State of AI in 2026 survey was published in August 2026 and gathered responses from 1,719 people between 4 May and 8 June 2026. McKinsey's own page did not load when we checked, so the figures below come as summarised by The Register. The headline numbers are:
80% of respondents who use AI in their roles say it has raised their individual productivity
37% say AI has contributed to their organisation's EBIT, essentially unchanged from a year earlier
6% qualify as "AI high performers", meaning organisations that attribute 5% or more of EBIT to AI and call the value significant, also unchanged
Taken together, the three numbers show individuals feeling faster while 63% of respondents do not attribute any EBIT impact to AI. Access to a model cannot explain that gap, since the respondents reporting nothing have the same models as those reporting a lot.
One plausible reading is that value leaks away between the individual and the enterprise. That is our interpretation of the pattern and not McKinsey's claim. A person drafts faster, and then the draft enters the same approval queue, the same system of record and the same handoff as before. The product that fixes this is the one placed inside the queue.
Why position is hard to copy
A standalone AI tool competes on output quality, and output quality is converging. A tool embedded in a workflow already holds the customer's state: the open cases, the approvals in flight and the fields that feed downstream reports. Replacing it means migrating that state, retraining people and renegotiating integrations, and that switching cost has nothing to do with how good the model is.
Distribution runs through the same channel. A vendor with, say, 2,000 customers can switch an AI feature on for all of them next quarter, while a new entrant with a better demo needs as many sales cycles.
3. Domain-Specific Evaluation and Quality
Evaluation is the discipline of measuring, with realistic test cases and a scoring method you trust, whether your AI system is right for your specific task. It is the least glamorous item on this list, and it most reliably separates teams that ship improvements from teams that ship regressions.
Generic benchmarks tell you little about your task
Public benchmarks measure public tasks, and the Stanford Index is frank about their limits in the technical chapter cited above. It notes that developers' reporting is increasingly opaque and that "third-party evaluations have documented cases where models perform more poorly in independent testing compared to developer-reported results." Contamination, meaning models being exposed to test data during training, "can lead to falsely inflated scores", it says, and audits of widely used benchmarks found many "poorly constructed, with inadequate documentation, no reporting of statistical significance, and a lack of replication scripts."
The report also says benchmarks get used up quickly. Frontier models gained 30 percentage points in a single year on Humanity's Last Exam, a test built to be hard for them. A benchmark that saturates within months cannot say which of two models is better for your contracts, your claims or your maintenance records.
Domain tasks are still hard, and unevenly so
The same chapter offers a clear example. Finance Agent v1.1 is a benchmark of 537 questions designed with Stanford researchers, a global systemically important bank and industry experts to mimic the work of an entry-level financial analyst. The report gives 63.33% as the leading score (Claude Sonnet 4.6) and 50.62% for the lowest of the models it charts (Kimi K2.5), "a spread of about 13 percentage points." It observes that even the top score "sits below two-thirds accuracy." The benchmark's host, Vals AI, shows a newer top score of 64.37% for Claude Opus 4.7 on its version 1.1 leaderboard, updated on 4 June 2026.
The pattern matters more than the brand names. On a realistic professional task, leading models fall in a wide band, none comes close to perfect, and the ranking shifts with each release. A team that can run its own version of that test on its own documents against every new model within a day holds information nobody else has, and that information is the moat.
A rival cannot download an evaluation set of real cases, scoring that matches how customers judge quality, and a record of past failures. It also makes the other moats safe to use. Switching models to save cost (moat 5) is only responsible if you can prove the cheaper model does not hurt quality, and a feedback loop (moat 1) can only be trusted if you can tell whether the model is improving.
4. Trust, Security and Compliance
Trust is the set of assurances that lets a cautious buyer say yes: security controls, data handling promises, audit trails, regulatory standing and a record of behaving as described. It works as a moat because a sprint cannot ship it. Certifications take months of observed operation, a clean history takes years, and a buyer's confidence, once lost, does not come back with a press release.
The risk is now about AI systems themselves
For several years AI security mostly meant worrying about what employees pasted into a chatbot. The 2026 data concerns systems under attack. IBM's Cost of a Data Breach Report 2026 was researched by the Ponemon Institute across 602 breached organisations between March 2025 and February 2026 and published on 29 July 2026. It reports:
a global average breach cost of $4.99 million, described as a 12% increase and a record high
one in four malicious breaches were AI-enabled, up 56% on the prior year, at an average of $6 million
more than 20% of organisations reported a breach that targeted AI models or applications
The last item matters most to product builders. If you sell an AI feature, your customers' security teams now assume it is an attack surface and will ask you to show otherwise. IBM's companion analysis names prompt injection and model inversion among the costliest AI-specific incidents, at average costs of $5.89 million and $6.07 million respectively.
Two cautions apply. The sample covers breached organisations only, so it shows how costly breaches are once they occur and not how often they hit a given company. IBM also sells security products, so the findings are informed but not neutral.
Regulation adds a second layer, with a moving calendar
The EU's Digital Omnibus on AI, Regulation (EU) 2026/1744, was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. It moved the application date for high-risk AI systems listed in Annex III (employment, credit, education and similar uses) to 2 December 2027, and for systems governed through Annex I product legislation to 2 August 2028. Providers who already had generative systems on the market before 2 August 2026 also received four months from that date to meet the content-marking duty in Article 50(2), which runs to 2 December 2026.
Two points follow. A delay is not a repeal, since the obligations are postponed and not withdrawn. And transparency duties under Article 50 began to apply on 2 August 2026, so some obligations are already live. We are not lawyers, so take the exact scope of any obligation to counsel who can read your facts.
Part of a compliance posture can only be supplied by time, such as certifications that need observed operation and reference customers in regulated sectors. When the buyer is risk-averse, trust serves as the entry ticket, and whoever holds it faces less competition than the feature list suggests.
5. Cost, Latency and Integration Engineering
Cost and latency engineering is the work of delivering a given quality of AI output quickly and at a price that leaves you a margin. It includes choosing which model handles which request, caching, batching, trimming context, and designing the system so that one provider's failure does not become your outage.
This moat sounds dull next to "proprietary data", yet it is where many AI products quietly succeed or fail.
The price of capability is collapsing for everyone
The best recent primary data comes from Epoch AI's The Plunging Price of Thought, by Luke Emberson and David Roodman, published on 22 September 2026. It uses five benchmarks over roughly three years (AIME, chess puzzles, FrontierMath tiers 1 to 3, GPQA Diamond and mystery game puzzles) and finds that the cost of a given level of AI performance has fallen about 47% per quarter, or 13x per year, since 2023.
Source: Epoch AI, "The Plunging Price of Thought" (22 September 2026), read 1 October 2026. The 13x per year rate is Epoch's; the $100, $7.70 and $0.59 bars are our compounding of it, for illustration. Epoch's own caveats: benchmarks are an imperfect proxy for useful work, the estimate assumes users always pick the cheapest adequate model while "real users do not switch models so often," and different ways of averaging give between 42.9% and 58.0% decline per quarter.
An earlier Epoch analysis, published in March 2025, saw the same pattern from another angle. The price to reach a given performance level fell between 9x and 900x per year depending on the milestone, and 40x per year for GPT-4-level performance on PhD-level science questions. The authors noted then that the fastest drops were recent and might not persist. The September 2026 paper is newer and is the one to quote, and the earlier one only shows that the direction has held.
Why cheap tokens do not remove the moat
A falling price looks like the end of cost as an advantage, since everyone gets the discount. Two facts point the other way.
First, costs still bind. In McKinsey's State of AI 2026 survey (n=1,719), as summarised by The Register, about 20% of respondents said AI-related operating costs, including token costs, have constrained how much they use AI. Cheaper units have not removed the constraint, most likely because usage grows alongside them, though that explanation is our reading and not a finding of the survey.
Second, the price decline applies to a fixed level of performance, and products rarely stand still at a fixed level. They move to the newest capability, which is where prices are highest. Epoch's own caveat points the same way, since it assumes users always switch to the cheapest adequate model, and "real users do not switch models so often." The winning teams can tell which requests need the frontier and which can run on an older, cheaper model.
Routing, caching, low-latency design and provider fallbacks can all be learned, and none is secret. What a competitor cannot do quickly is accumulate your production traffic, your failure history and your tuned routing rules. The operating experience is the moat.
How the Five Moats Fit Together
Each moat is weak alone and strong in combination, and the links between them explain why copying one rarely copies the set.
Moat
What it feeds
What feeds it
Proprietary data and feedback loop
Evaluation cases, product quality
Workflow position (the loop only runs if people use the product daily)
Workflow position
Data capture, switching cost
Trust (buyers let you into critical systems only if they trust you)
Domain evaluation
Safe cost cutting, safe model swaps
Data (real cases come from real operations)
Trust and compliance
Access to regulated buyers and their workflows
Evaluation (you can evidence behaviour) and architecture
Cost and latency engineering
Margin to keep investing
Evaluation (the quality bar that routing is tested against)
The table reads as a chain and not a menu. A workflow position generates data, data builds the evaluation set, and the evaluation set makes cost reductions and model upgrades safe. Safe operation builds trust, which gets you into more sensitive workflows. A competitor who copies only the top of the chain has a product without the loop that sustains it.
Things That Look Like Moats but Are Not
Part of the value of a list like this lies in saying what to leave off it.
"We fine-tuned a model." Fine-tuning is a technique and not an advantage. Its value depends entirely on the exclusive data behind it, and when the base model improves, a fine-tune on commodity data can often be overtaken within one release.
"We have the best prompts." Anyone who can see your outputs can read your prompts, and their value declines as models improve.
"We were first." That counts only if first position converted into one of the five. Otherwise the head start expires.
"We use the best model." The Stanford data shows "best" is a narrow and shifting lead, and everyone can switch to it.
"Our team is smarter." Possibly true and worth having, but talent moves, and a moat should still stand when a key person leaves.
We also left out one popular claim on purpose. Articles on this topic often say a specific percentage of AI start-ups are "just wrappers", or that a specific share will fail within a set number of years. We did not find a primary study with a stated method and sample behind those figures. No credible number exists to quote, so we do not quote one.
A Self-Audit You Can Run This Week
Score each moat from 0 to 3 for your own product, then fold the results into a wider AI strategy for your software company. The score is for your own use; no published benchmark exists for it, and we do not claim one.
Moat
0
3
Data and loop
We use only public or licensed data anyone can buy
We hold exclusive, outcome-labelled, rights-cleared data that grows with use
Workflow position
Users reach us in a separate tab
We are part of a daily process and hold customer state
Evaluation
We judge quality by eye
We run a domain test suite on every model or prompt change
Trust
We answer security questionnaires ad hoc
We hold the controls and certifications our target buyers ask for
Cost and latency
We have never modelled unit cost at volume
We route by task, cache, and can swap providers within days
A zero on any row is the first place to spend money, since the moats depend on each other.
The Bottom Line
The claim that an AI product's advantage is its model gets harder to defend every quarter. Four labs within 25 Elo points, open models 49 points behind the best closed one, and per-unit prices falling about 13x a year all say the same thing: the model is a component anyone can rent.
What stays scarce is slower to build. Data your competitors cannot get, plus a loop that keeps producing more. A position inside the workflow where the work is done. A test suite that tells you, on your own cases, whether a change made things better. The trust of buyers who cannot afford to be wrong. And the operating skill to deliver all of it at a cost that leaves a margin. Each takes months or years to build, and each strengthens the others.
If your current plan rests on a model choice, a prompt or a launch date, test it against the five and find the lowest-scoring row. The next quarter's budget belongs there. For a second opinion on where your product stands, read how we approach AI strategy for software companies or get in touch.
Will AI replace software development companies? What the 2026 data shows AI is taking from agencies, what it cannot, and how buyers should change what they buy.