Landscape

Where value accrues

Seven layers from silicon to signed contract, which are commoditized, and the two where a small lab can hold ground.

evidence: medium8 minupd 2026-08-29strategymoatsvalue-chain

Every AI security product is an assembly of the same seven layers. The question that decides whether a company is defensible is not which segment it sells into but which layer it actually owns. Most startups in this market own layer four and believe they own layer five.

#The seven layers

Layer What it is Who owns it Commoditized?
1 Compute Nvidia, hyperscalers, neoclouds Yes, and priced accordingly
2 Base models OpenAI, Anthropic, Google, Meta, Qwen, DeepSeek Frontier gated at the top, commodity below
3 Domain post-training Cisco, Trend Micro, a few labs Barely occupied — and barely proven
4 Agent scaffolding Every startup in this market Rapidly commoditizing
5 Verification and execution infrastructure Almost nobody No
6 Workflow and evidence Incumbents partially Partially
7 Distribution and trust Platform incumbents, channel No, but expensive

#Layer 1 — Compute

Not a place to compete. Relevant only as a cost line, and the 2026 pricing spread across providers is wide enough to matter to a training budget (Unit economics and the compute bill).

#Layer 2 — Base models

The layer everyone talks about and almost nobody occupies. The gated tier — Mythos-class, Astra-class — is genuinely closed to everyone, which makes it a moat for its owners and irrelevant as a strategy for anyone else. Below that tier, capability is commoditizing fast: UK AISI puts open-weight models 4–7 months behind on cyber at up to 45x lower cost (Is frontier-lab gating a real wedge?).

The strategic implication is uncomfortable and important: capability is not where you differentiate, because you are renting it from someone who also sells your product.

#Layer 3 — Domain post-training

Sparsely occupied, and the evidence suggests that is because the returns are not there yet rather than because nobody thought of it. No post-trained model publicly beats frontier-plus-scaffolding on agentic security tasks (Open-weight security models, Post-training playbook).

Where this layer does confer real advantage is narrow: air-gapped and on-premises deployment where frontier APIs are prohibited, cost at high volume, and latency. Those are real, defensible advantages — they are just economic and regulatory advantages rather than capability ones, and they only bind once you have the customers who need them.

#Layer 4 — Agent scaffolding

Where almost every company in Offensive AI security companies and AI code security companies actually lives: prompt engineering, tool orchestration, context management, output formatting. It is genuinely skilled work and it is genuinely commoditizing. Open-source projects replicate it, frontier labs ship it as product features, and the AIxCC systems open-sourced a great deal of it (The open-source stack).

The tell that a company lives here: it cannot explain what breaks if you swap its underlying model.

#Layer 5 — Verification and execution infrastructure

The layer nobody owns, and the argument of this entire research.

This is: reproducible build environments across thousands of messy real repositories, sandboxed execution with isolation good enough that a frontier lab's failures do not become yours, proof-of-concept generation and reproduction, regression-test discovery, patch validation, and flake management at scale.

It is unowned because it is expensive, unglamorous, and invisible in a demo. It is defensible for exactly the same reasons. AIxCC is the proof it can be built and the proof of how much machinery it takes — seven teams, DARPA funding, and still zero real-world C bugs patched (AIxCC: the closest thing to a proof).

It is also the layer that compounds. Every verification run produces trajectory data, verified exploit/patch pairs, and human triage decisions with outcomes — the three data assets that structurally accumulate rather than being purchasable (Data, and whether a moat is possible).

So what

Layer 5 is the only layer in this stack that is simultaneously unowned, expensive to build, hard to demo, and generative of proprietary data. Those four properties together are the definition of a moat in this market (What could actually be defensible).

#Layer 6 — Workflow and evidence

Where the finding becomes an action someone takes and a record someone keeps: ticketing integration, ownership routing, SLA tracking, and — the underbuilt part — the compliance artifact. The CRA turns vulnerability handling into an evidentiary obligation, and nobody has built the product that emits that evidence as a by-product of the security work (EU regulation as a demand engine, Where the gaps actually are).

Moderately defensible through workflow lock-in. More importantly, it is what converts a technical product into a budget line with a regulatory owner.

#Layer 7 — Distribution and trust

The layer the platform incumbents own and the reason this category exits by acquisition rather than IPO (Who funds this and at what price). For a startup, partial and slow substitutes exist: open-source adoption, published research, independent evaluations, and disclosed vulnerabilities. That is the credibility ladder in The AI cyber lab category, and it is the only version of layer 7 available without a sales organization.

#The strategic conclusion

Rented capability at layer 2, commoditizing craft at layer 4, incumbent ownership at layer 7. What is left for a small team is layers 5 and 6, with layer 3 as a later economic optimization and layer 7 substituted by published credibility.

That is not a compromise position. It is the position with the most durable properties available, and it happens to be the one the demand side independently points at in Where the gaps actually are.

Caution

The failure mode to name explicitly: a company that believes it is at layer 5 because it calls an execution sandbox, when it is really at layer 4 with a container. The test is whether the verification survives contact with a thousand real repositories that build inconsistently, have no tests, or take forty minutes to compile. That is the actual work.

#What this means for us

  • Build the answer to "what breaks if you swap the model" into the architecture on purpose. If the answer is "nothing," you are at layer 4 and so is everyone else.
  • Layer 5 investment looks irrational for the first six months — it produces no demo and no feature list — and it is the entire bet. Plan for that to be uncomfortable, and plan for The first 90 days to make it measurable early.
  • Layer 6 is what makes layer 5 sellable in Europe. The verified defect and the CRA evidence artifact should be the same object, designed together from the first week.
  • Layer 3 is a month-nine decision gated on volume, not a founding differentiator (The three ideas, judged).