Where value accrues
Seven layers from silicon to signed contract, which are commoditized, and the two where a small lab can hold ground.
Every AI security product is an assembly of the same seven layers. The question that decides whether a company is defensible is not which segment it sells into but which layer it actually owns. Most startups in this market own layer four and believe they own layer five.
#The seven layers
| Layer | What it is | Who owns it | Commoditized? |
|---|---|---|---|
| 1 | Compute | Nvidia, hyperscalers, neoclouds | Yes, and priced accordingly |
| 2 | Base models | OpenAI, Anthropic, Google, Meta, Qwen, DeepSeek | Frontier gated at the top, commodity below |
| 3 | Domain post-training | Cisco, Trend Micro, a few labs | Barely occupied — and barely proven |
| 4 | Agent scaffolding | Every startup in this market | Rapidly commoditizing |
| 5 | Verification and execution infrastructure | Almost nobody | No |
| 6 | Workflow and evidence | Incumbents partially | Partially |
| 7 | Distribution and trust | Platform incumbents, channel | No, but expensive |
#Layer 1 — Compute
Not a place to compete. Relevant only as a cost line, and the 2026 pricing spread across providers is wide enough to matter to a training budget (Unit economics and the compute bill).
#Layer 2 — Base models
The layer everyone talks about and almost nobody occupies. The gated tier — Mythos-class, Astra-class — is genuinely closed to everyone, which makes it a moat for its owners and irrelevant as a strategy for anyone else. Below that tier, capability is commoditizing fast: UK AISI puts open-weight models 4–7 months behind on cyber at up to 45x lower cost (Is frontier-lab gating a real wedge?).
The strategic implication is uncomfortable and important: capability is not where you differentiate, because you are renting it from someone who also sells your product.
#Layer 3 — Domain post-training
Sparsely occupied, and the evidence suggests that is because the returns are not there yet rather than because nobody thought of it. No post-trained model publicly beats frontier-plus-scaffolding on agentic security tasks (Open-weight security models, Post-training playbook).
Where this layer does confer real advantage is narrow: air-gapped and on-premises deployment where frontier APIs are prohibited, cost at high volume, and latency. Those are real, defensible advantages — they are just economic and regulatory advantages rather than capability ones, and they only bind once you have the customers who need them.
#Layer 4 — Agent scaffolding
Where almost every company in Offensive AI security companies and AI code security companies actually lives: prompt engineering, tool orchestration, context management, output formatting. It is genuinely skilled work and it is genuinely commoditizing. Open-source projects replicate it, frontier labs ship it as product features, and the AIxCC systems open-sourced a great deal of it (The open-source stack).
The tell that a company lives here: it cannot explain what breaks if you swap its underlying model.
#Layer 5 — Verification and execution infrastructure
The layer nobody owns, and the argument of this entire research.
This is: reproducible build environments across thousands of messy real repositories, sandboxed execution with isolation good enough that a frontier lab's failures do not become yours, proof-of-concept generation and reproduction, regression-test discovery, patch validation, and flake management at scale.
It is unowned because it is expensive, unglamorous, and invisible in a demo. It is defensible for exactly the same reasons. AIxCC is the proof it can be built and the proof of how much machinery it takes — seven teams, DARPA funding, and still zero real-world C bugs patched (AIxCC: the closest thing to a proof).
It is also the layer that compounds. Every verification run produces trajectory data, verified exploit/patch pairs, and human triage decisions with outcomes — the three data assets that structurally accumulate rather than being purchasable (Data, and whether a moat is possible).
Layer 5 is the only layer in this stack that is simultaneously unowned, expensive to build, hard to demo, and generative of proprietary data. Those four properties together are the definition of a moat in this market (What could actually be defensible).
#Layer 6 — Workflow and evidence
Where the finding becomes an action someone takes and a record someone keeps: ticketing integration, ownership routing, SLA tracking, and — the underbuilt part — the compliance artifact. The CRA turns vulnerability handling into an evidentiary obligation, and nobody has built the product that emits that evidence as a by-product of the security work (EU regulation as a demand engine, Where the gaps actually are).
Moderately defensible through workflow lock-in. More importantly, it is what converts a technical product into a budget line with a regulatory owner.
#Layer 7 — Distribution and trust
The layer the platform incumbents own and the reason this category exits by acquisition rather than IPO (Who funds this and at what price). For a startup, partial and slow substitutes exist: open-source adoption, published research, independent evaluations, and disclosed vulnerabilities. That is the credibility ladder in The AI cyber lab category, and it is the only version of layer 7 available without a sales organization.
#The strategic conclusion
Rented capability at layer 2, commoditizing craft at layer 4, incumbent ownership at layer 7. What is left for a small team is layers 5 and 6, with layer 3 as a later economic optimization and layer 7 substituted by published credibility.
That is not a compromise position. It is the position with the most durable properties available, and it happens to be the one the demand side independently points at in Where the gaps actually are.
The failure mode to name explicitly: a company that believes it is at layer 5 because it calls an execution sandbox, when it is really at layer 4 with a container. The test is whether the verification survives contact with a thousand real repositories that build inconsistently, have no tests, or take forty minutes to compile. That is the actual work.
#What this means for us
- Build the answer to "what breaks if you swap the model" into the architecture on purpose. If the answer is "nothing," you are at layer 4 and so is everyone else.
- Layer 5 investment looks irrational for the first six months — it produces no demo and no feature list — and it is the entire bet. Plan for that to be uncomfortable, and plan for The first 90 days to make it measurable early.
- Layer 6 is what makes layer 5 sellable in Europe. The verified defect and the CRA evidence artifact should be the same object, designed together from the first week.
- Layer 3 is a month-nine decision gated on volume, not a founding differentiator (The three ideas, judged).