What could actually be defensible
Nine candidate moats tested against the two things that kill companies here: frontier labs shipping your feature, and commoditizing capability.
A moat in this market has to survive two specific attacks, not a generic competitor. The first: a frontier lab ships your core feature as a bundled capability — Aardvark went from private beta to broad enterprise rollout in roughly four months (What the frontier labs do themselves). The second: the capability you depend on commoditizes underneath you — open-weight models closed from 6–10 months behind the frontier to 4–7 in a single year (Is frontier-lab gating a real wedge?).
Most claimed moats in AI security fail one or both. Below, nine candidates tested against exactly those two attacks.
#The candidates
#1. Model capability
Fails both. You are renting capability from a supplier who also sells your product, and the commodity tier behind it is closing fast. No post-trained security model publicly beats frontier-plus-scaffolding on agentic tasks (Open-weight security models).
There is one narrow exception worth naming: a model that can be deployed where frontier APIs cannot go. That is not a capability moat, it is a deployment moat, and it is discussed as #6 below.
#2. Prompt and scaffold craft
Fails both. It is real skill and it is visibly commoditizing — open-source projects replicate it, AIxCC open-sourced a lot of it, and the labs ship it as features (The open-source stack).
#3. Verification infrastructure
Survives both. This is the strongest candidate in the research.
A frontier lab shipping a better model does not give you reproducible builds across thousands of inconsistent real repositories, sandboxed execution with genuine isolation, proof-of-concept reproduction, regression-test discovery and patch validation at scale. Those things do not come with a model upgrade; they are a systems-engineering asset that takes years and does not appear in a demo.
Commoditizing capability makes this moat stronger, not weaker: as reasoning gets cheap, the differentiator moves to what you can verify, and verification is the scarce half (Where value accrues).
Cost to replicate is the real test. AIxCC needed seven funded teams and a DARPA program to get to 86% found and 68% patched on synthetic targets, with zero real-world C bugs patched (AIxCC: the closest thing to a proof). That is the replication cost, and it is high.
#4. Proprietary data that compounds
Survives, conditionally. Three data assets accumulate rather than being purchasable (Data, and whether a moat is possible):
- Agent trajectories — what your system tried, in what order, and whether it worked
- Verified exploit/patch pairs on real code, with reproduction proofs
- Human triage decisions with outcomes — which findings were acted on and which were dismissed, and whether that was right
The condition is important: these only accumulate as a by-product of real usage. There is no way to buy them and no way to bootstrap them before you have customers. That makes this a second-order moat that the wedge product creates, not a moat you can start with. Static data — scraped exploit archives, customer code — is spend-replicable and not a moat at all.
#5. Regulatory and evidentiary lock-in
Survives the lab attack, partially survives commoditization. If your output is the artifact a company files to satisfy a CRA Article 14 obligation, switching vendors means re-establishing an audit trail, and audit trails are sticky (EU regulation as a demand engine).
The weakness is that this is workflow defensibility rather than technical defensibility, and a determined incumbent with distribution can copy it. Its real value is different: it changes who buys and why, from a discretionary engineering purchase to a compliance obligation with a named owner and a deadline (Who buys, and what they pay).
#6. Deployment constraints
Survives both, in a narrow segment. Air-gapped, on-premises and sovereign-hosted buyers cannot send code to a US inference API. No wrapper can serve them, and no frontier lab product will. This is the one place where a post-trained model is structurally necessary rather than an optimization (Post-training playbook).
Narrow, high-value, and real — particularly in European finance, defense and public sector. It is a phase-two moat because it requires having the customers first.
#7. Measurement credibility
Survives the lab attack; unusual properties. In a market where every precision claim is self-reported on a self-chosen set, the group that publishes methodology, held-out sets and reproducible harnesses occupies a position with almost no competition (Cyber benchmarks and evals, Where the gaps actually are).
Reputational moats are slow to build and slow to erode, which is the right shape for a company that will be smaller than its competitors for years. The catch: it is not a business by itself and it does not convert to revenue directly. It converts to inbound, recruiting and lab access — which is precisely what a cold-start European lab needs (The AI cyber lab category).
#8. Distribution and channel
Survives, unavailable. Real, and owned by the platform incumbents. It is the reason this category exits by acquisition (Who funds this and at what price). Not accessible to a seed-stage company without a sales organization; open-source adoption and published research are the partial substitutes (Go to market).
#9. Talent concentration
Weak as a moat, strong as a constraint. The person who can do both security research and post-training is genuinely scarce (Talent: the actual constraint). Assembling a few of them is an advantage, but people leave and the pool is growing. Treat it as an execution requirement rather than something to tell investors is defensible.
#Scored against the two attacks
| Moat | Survives lab shipping it | Survives commoditization | Available now | Verdict |
|---|---|---|---|---|
| Verification infrastructure | Yes | Strengthens | Yes | Primary |
| Compounding data | Yes | Yes | No — needs usage | Secondary, follows from primary |
| Measurement credibility | Yes | Yes | Yes, cheaply | Primary for cold start |
| Regulatory lock-in | Yes | Partly | Yes | Commercial layer |
| Deployment constraints | Yes | Yes | No — needs customers | Phase two |
| Distribution | Yes | Yes | No | Exit path, not strategy |
| Talent | No | No | Partly | Constraint |
| Scaffold craft | No | No | Yes | Not a moat |
| Model capability | No | No | No | Not a moat |
The three moats available to a cold-start European lab — verification infrastructure, measurement credibility, and regulatory lock-in — happen to reinforce each other. The verification harness makes the measurement credible; the measurement gets you the customers; the customers generate the compliance evidence and the compounding data. That is the strategy in The three ideas, judged, derived independently from the defensibility side.
#The moats that are illusions
Named explicitly, because each is commonly claimed in this market:
- "We have frontier model access." A relationship, not a moat, and one the counterparty can revise. Also not a safety claim to make to customers, given 2026's containment record (Dual-use risk and what it costs you).
- "We have the most GitHub stars." The most-starred offensive agent scored 1 out of 20 on an independent benchmark (Strix).
- "We found N vulnerabilities." Discovery without validated conversion is half a product, and the AIxCC data shows the gap between the halves is where the difficulty lives (AIxCC: the closest thing to a proof).
- "We're first." In a market where a supplier can ship your feature in four months, being first is a head start, not a moat.
#What this means for us
- Build layer-5 verification infrastructure as the deliberate long-term asset, and accept that it will look like slow progress for two quarters (Where value accrues, The first 90 days).
- Start the measurement-credibility moat in the first 90 days because it is nearly free and it is the only one available before you have customers.
- Treat the data moat as an output of the product rather than an input to it. Any plan that requires proprietary data before launch is describing a company that cannot start.
- Do not claim model capability as a differentiator to investors or customers. It invites a benchmark challenge you will lose, and the honest version — deployment economics and verification rigor — is a better story anyway (Post-training playbook).