The term defensibility gets thrown around by a lot of VCs and founders alike, and you’re probably wondering how anything is defensible when Anthropic ship model updates every other minute.  

A very valid concern. 

 Before we jump into it, there is an uncomfortable truth to all of this: we are undergoing a paradigm shift in what constitutes a genuine “defensible moat”, and the market is moving faster than the language being used to talk about it. Most of what gets pitched as a moat is calibrated for a world where software was the unit of value, and that world looks like it’s finished. The agent now does the work, and the unit shifts from tool to outcome, where frontier labs will absorb most of what currently looks defensible. 

 Sequoia put the cleanest version of this on paper in March, summarised by the following sentence: “if you sell the tool, you are in a race against the model”. However, the harder question I want to try and address is what specifically holds when the agent is the worker, the buyer, and increasingly the user? I believe three moats hold deeply, and a fourth holds for now. 

1. Embedded judgement 

 Selling the work is necessary, but even that isn’t everything. An Autonomous Agent only holds the SLA if its outputs are reliable, and reliability comes from subject-matter-expert judgement encoded into the workflow, not basic labels/annotations on a training set, but rather live correction loops that shape what the agent does next. That liability you assume is the moat, and it compounds as every closed loop becomes proprietary judgement data the foundation model never sees. 

 The near-term winners won’t be foundation labs racing toward more general agents. They will be operators redesigning specific workflows around expert feedback. A radiology autonomous agent beats a generalist medical agent because radiologists have shaped its trajectory hour by hour. A Big Four audit autonomous agent beats a generalist accounting agent because auditors have shaped it’s trajectory. This is the version of "human-in-the-loop" that compounds: embedded judgement, where the expert's correction is the product's training signal in a domain that the foundation model has no way in. 

 This is also the moat with the most mythology and the least proof. “We hold the SLA, so we hold the moat” is a claim that can only be validated over time, so we won’t really know if this sticks until some point in the future. What we know for now, is that the companies that will actually own this moat are the ones building the contractual scaffolding to make liability real - performance bonds, indemnification floors, outcome-based pricing with downside, captive insurance arrangements - tangible stuff that stretches far beyond an autonomous agent. When diligencing any “outcome-as-product” company, the difference between a tool wearing autonomous agent clothing and a real autonomous agent is in the contract. 

 Crosby is doing this with NDAs, Anterior with medical coding, and WithCoverage with insurance brokerage. In Europe, a younger company called HyperGTM is doing the same thing but for sales meetings with executives at the world's biggest companies. Most companies that help with sales sell software, i.e. a tool you use yourself to find customers, whereas HyperGTM delivers the actual meetings with senior decision-makers, using three things: events, executive dinners, and incredibly personal gifts in the mail. All held together with genuine contractual outcome-based pricing. 

2. Domain depth the labs won't replicate 

 The data moat conversation is stuck in 2022. Two versions of it still hold. 

 The first is: rights-cleared corpora in domains the labs are barred from. 

 Music, film, scientific publishing, broadcast journalism, medical imaging - basically, anywhere the labs are either being sued for prior scraping or now legally fenced out by licensors who have organised. The labs cannot acquire what they are being sued for using. Adobe Firefly’s licensed-only training set is the canonical incumbent move, and Enterprise AI data specialists like Beatpulse Labs are the latest example of building something you cannot replicate quickly: licensed, human-generated, stem-level multi-modal data with full provenance, and subject matter expert judgement embedded into the data sold to model developers who can no longer scrape or synthesise their way around the rights regime. The EU AI Act's Article 53 disclosure requirements make this a structural requirement rather than a contingency. 

 The second is sharper and less discussed: low-status problems the labs will not solve. 

 The foundation labs operate on prestige gradients. Their researchers want to publish, and their executives want to talk about how AGI is happening tomorrow. They will not spend three years on how Outlook 2007 renders HTML, or how German VAT rules interact with Czech invoicing, or how a specific laboratory information system speaks HL7 v2.5.1. These problems are domain-deep, chaotic, jurisdiction-specific, prestige-poor and some of the most defensible places to build. 

 Migma.ai is the example I keep coming back to. Email looks like a solved category from the outside, but  from the inside, it's a forty-year-old rendering surface where every message has to survive dozens of incompatible engines, none of which behave like a browser. The labs treat that as plumbing. Migma built the compiler that makes generated email actually deliverable, and that compiler is the moat not the model on top of it. Other examples include EvenUp in legal damages calculation and Stripe before payments became prestige work. 

 The principle is simple. Founders should look for problems on the wrong side of the labs' prestige gradients, i.e. sufficiently boring, sufficiently chaotic, sufficiently domain-specific and difficult to achieve.  

 The true threat to this moat comes from application-layer incumbents like Salesforce Agentforce, SAP Joule, Microsoft Copilot, Workday’s agent stack and ServiceNow’s Now Assist. These vendors will absolutely spend years on jurisdictional invoicing because their customers demand it, and they have GTM, contractual and trust advantages no startup matches.  

 The startup case here only holds where the vertical is genuinely fragmented across no dominant SaaS layer (Migma’s email problem) or where the incumbent is too slow to ship credibly (most of them, most of the time, but not forever). Founders building here have a window measured in quarters to make themselves either uncopiable or acquirable. 

 3. Regulated trust 

 The mantra - build things that solve very hard problems - rings most true here. 

 Distinct from generic "regulatory capture" specific surfaces: financial services licences, healthcare credentialling, legal bar admission, EU AI Act high-risk classifications under Annex III. 

An agent that can legally take an action in a regulated workflow is worth orders of magnitude more than one that can only suggest it. Again, the liability and actionability are the moat here. The foundational labs cannot move in this direction quickly, and are already being shut out by large, regulated enterprises. Just speak to anyone wanting to use Claude in Investment Banking. Anthropic and OpenAI will not become broker-dealers or medical providers and the licence is the structural barrier which accrues to whoever does the regulatory work first in each jurisdiction. 

 The principle applies beyond pure-play AI. Mercury did this in deposit-banking infrastructure, and Modulr did it in UK e-money. Paypercut is doing it in Central Eastern European Buy-Now-Pay-Later aggregation, where local regulatory navigation is a moat the global aggregators have to rebuild jurisdiction by jurisdiction. The same dynamic “local regulation as a moat” will define agentic financial services across emerging markets long after the foundational labs have commoditised the underlying intelligence layer. 

 For a fund deploying across UK, Europe, GCC and Asia, the operational question is fast developing from “where is the talent” to also consider “where can the agent legally act first.” That is a different question than the market is currently optimising for, and it has consequences for domiciling, hiring, and which regulator you build a relationship with on day one.  

 4. System of record - the contested moat 

 The old distribution moat was inbox, browser, app store and the new one is being inside the SAP, Epic, Bloomberg or core banking system where work actually lives. An agent that can write back, post, settle or reconcile inside the system of record beats one that has to be opened in a separate tab. The integration relationship, once established, is sticky in a way consumer distribution never was. The agentic-era equivalent of an enterprise contract is an agent that writes back into the system of record without human intervention.  

 This is the shallowest of the four moats, included because it is real today, rather than it being durable tomorrow. 

 The contested part here, is the incumbent platform vendors that are competing for the same layer. Their native agents will ship into the workflows their customers are already in, with distribution advantages no startup can match on price or trust. Founders building here have a window measured in quarters to install themselves before the incumbents arrive in force. The right strategic posture is to treat system-of-record distribution as the wedge rather than the destination - wide enough to build the deeper moats above, and sharp enough to win the customer first. 

 What erodes this, and how fast 

The four moats above are durable to the extent that today’s inference economics are durable. The two real near-term threats to those economics are not what most people lead with. 

 The first is the open-source floor. Llama, DeepSeek, Qwen and the next two generations of each are dragging API pricing power down incredibly fast. The “race against the model” frame is incomplete if you only mean closed-source frontier as free open-source models are raising the floor fast.  

The second is algorithmic efficiency. Speaking to builders in the space, it’s clear that mixture-of-experts, distillation, speculative decoding and KV-cache compression have done more for inference cost in the last twelve months than any hardware roadmap. Crucially, much quicker too.  

 Neither of these collapses the four moats completely, if anything, cheaper and better generalist agents make the embedded-judgement moat more important because the discriminator becomes which agent makes fewer expensive mistakes in a regulated workflow. They erode moat four (system of record) faster than the others, which is part of why I hold it loosest. 

 Photonic compute and neuromorphic substrates could eventually collapse all of this in one sweep. However, the path from demonstration to deployed inference is gated by fab capacity for silicon photonics integrated with electronic logic, thin-film lithium niobate and indium phosphide supply, mature design tooling and IP libraries. None of these are solved by capital alone; they are solved by years of industrial build-out. That scenario is further out than the loudest voices in the market are pricing. 

 We believe that companies built on the four moats above have a window measured in years. The ones that close that window do it by turning the embedded-judgement loop into a real liability transfer, by getting domain depth to compound before the SaaS incumbents arrive, and by being the first to move legally in a regulated jurisdiction.  

 As one door closes, another one opens but it’s important to remember that none of this is infinite. 

 Beatpulse Labs, Migma.ai, Paypercut and HyperGTM are Arāya Ventures portfolio companies. Crosby, Anterior, Harvey, Abridge, Adobe Firefly, EvenUp, Stripe, Sierra, Decagon, Glean, Mercury and Modulr are not.