The One-Degree Dispatch

What Actually Makes an AI Business Defensible

2025 · The Nature of Intelligence · 3,836 words

True AI business defensibility lies in swiftly closing the loop between data, action, and learning, not in overstated model claims or proprietary data hoarding.

proprietary intelligence must therefore be building durable advantage. That belief sounds reasonable in a market awash in money and motion. Stanford’s 2025 AI Index shows why the temptation is so strong. Private investment in generative AI reached $33.9 billion in 2024, and 78 percent of organizations reported using AI, up from 55 percent the year before. In a market like that, volume can masquerade as inevitability, and speed can masquerade as depth. But the more serious question is not whether most AI moat claims are weak. Many are. The more serious question is why so many leaders are still looking for the moat in the wrong place. They are still evaluating advantage from inside a 1st Gen AI worldview. They are still asking what software helps people work through more friction, rather than what architecture removes the friction that should not exist at all. That is the line that matters now. Public writing on the divide between first generation and second generation AI makes the distinction plain. First generation systems made the enterprise more legible. Second generation systems begin to reason, act under permission, measure consequence, and learn from the result.

The friction economy still looks like discipline

1st Gen AI did important work. It turned scattered records into searchable memory. It made patterns easier to see. It improved forecasting, summarization, recommendation, and the speed with which people could inspect a problem. It gave the enterprise a mirror. Many firms needed that mirror because they were still operating with blind spots large enough to hide cost, waste, and delay in plain sight. But 1st Gen AI, for all its value, mostly left the old operating bargain untouched. The system could tell you more. It still could not carry the burden of consequence. That older bargain produced what can be called a friction economy. In a friction economy, value is created by helping people cope with distance. Distance between the signal and the decision. Distance between evidence and the person allowed to act. Distance between the worker who sees the problem and the function that owns the budget. Distance between what the customer needs and what the internal approval ladder will permit. Companies then build dashboards, workflow systems, escalation routines, and review rituals to help humans live inside that distance. The software gets better. The distance stays. That is why so much enterprise AI has felt helpful without being decisive. The human remains the translator between information and consequence. A manager still has to read the signal, decide whether it matters, secure approval, route the task, and then confirm whether the outcome changed. The software informs. The organization still pays for the time between knowing and doing. That time rarely appears under its real name. It is called governance. It is called alignment. It is called diligence. It is called proper review. “What would have to be true for this outcome to keep repeating.” That sentence belongs near the start of any serious AI strategy discussion because it forces the right diagnosis. If the same delays, cost overruns, missed interventions, and fading advantages keep showing up, then the issue is not simply model quality or user adoption. The issue is the system in which judgment lives, permission is granted, and action is delayed.

The software gets better. The distance stays

The market’s language around moats has not caught up to this. It still assumes that advantage is most likely to reside in what the software is made of. A proprietary model. A better prompt layer. A cleaner user experience. A tighter retrieval stack. A slightly better fine tune. A modest head start in labeled data. Itamar Novick is right to reject most of these claims. In the post that prompted this discussion, he argues that 95 percent of AI startups are thin wrappers on OpenAI or Anthropic APIs and that many so called proprietary data claims are nothing more than short leads built on scraped or weakly relevant information. His negative test is sound. Most of what founders describe as a moat would not survive a stronger model release or a determined competitor. But the positive test needs to be harder. It is not enough to say that real moats are rare. Leaders need a sharper explanation of what becomes defensible once the architecture of work begins to change. That is where the move from 1st Gen AI to 2nd Gen AI matters. In 2nd Gen AI, the point is not simply to produce better interpretation. The point is to reduce the distance between evidence, reasoning, permission, action, and learning. Once that distance starts to collapse, the moat moves with it. Itamar’s own test is useful here because it names the few moat categories that still deserve to be taken seriously. Proprietary data can matter when it cannot be replicated because it is exclusive, protected, or accumulated over years in ways competitors cannot quickly reproduce. Data network effects can matter when each new user, correction, or deployed agent improves the system for all users and leaves new entrants behind. Vertical integration can matter when the full stack, including proprietary hardware or installed infrastructure, would be expensive and time consuming to rebuild. Regulatory capture can matter when approvals, permissions, or exclusive rights create a barrier measured in years, not months. If a company has none of these conditions, then it should stop pretending a wrapper, a prompt layer, or better retrieval is a moat. It may still build a real business, but it should think like a feature with distribution, not like a company with durable defensibility.

Artificial governance is purchased delay

This is where the conversation becomes politically expensive. Companies do not merely suffer from technical friction. They suffer from artificial governance controls and authority gates that were built to compensate for earlier limits and then hardened into permanent architecture. Years ago, many of those controls made sense. Information arrived late. Systems did not carry context well. Errors were costly and hard to reverse. Managers could not rely on real time signals, and leaders could not trust local decisions without manual review. Under those conditions, more checkpoints looked like prudence. Over time, however, those checkpoints became something else. They became purchased delay. The organization kept paying for them long after the original reason had weakened or disappeared. A signal appeared, but the signal had to wait. The likely action was obvious, but the

action had to wait. Someone higher up needed to be informed. Another function wanted review. A meeting had to happen because the decision “crossed a line.” A budget owner wanted optionality. A senior leader wanted cover. The queue lengthened. The value of acting decayed. Everyone involved could still describe the process as responsible. That description did not make it cheap. Public writing on permission architecture has pushed directly at this point. The question is not whether governance matters. It does. The question is whether the delay purchased by a gate is buying something real. If the answer is safety, law, irreversible exposure, or a truly material capital decision, the gate may be justified. If the answer is habit, status protection, weak architecture, or fear of blame, then the firm is paying for time as if time were free. It is not. The rationale for these gates is always polished. We need proper oversight. We need consistency. We need accountability. We need executive visibility. We need compliance review. We need one version of the truth. We need to prevent bad decisions. Each phrase can be sensible. That is why the system survives. But these rationales often conceal another reality. The organization does not trust local decision rights. It does not trust its own data to travel with the problem. It does not trust the system to hold boundaries. So it makes people into bridges. It converts architecture weakness into managerial work and then calls the extra labor discipline. Ask the question plainly. When a decision sits in queue for three days, what exactly was purchased with those three days. Was there a real reduction in risk. Was there a real improvement in outcome. Or was the time mainly spent preserving rank, giving people a chance to be seen in the loop, and converting uncertainty into social negotiation. If the honest answer is the third one, then the firm is not governed for consequence. It is governed for comfort. This is the part most companies will resist hearing, because they have spent years teaching themselves the opposite. They have taught themselves that control means touch. If enough people review the decision, control feels intact. If a senior enough person is involved, control feels legitimate. If authority climbs the ladder before action happens, control feels responsible. That made sense in a world of slow signals and weak systems. It makes much less sense in a world where the signal, the context, the reason, and the guardrails can travel together. Many firms are not governed for consequence. They are governed for comfort.

The moat moves when distance collapses Once that is clear, the next part becomes easier to see. The real break between 1st Gen AI and 2nd Gen AI is not bigger models. It is the collapse of distance. The system no longer sits one or more layers away from the outcome that matters. It reasons closer to the event. It acts under explicit permission. It measures what happened. It learns from consequence rather than only from interaction.

That changes the economics of defensibility. A thin wrapper is not a moat because it lives at the surface of friction. A workflow shell is not a moat if the workflow itself is mostly a map of inherited delay. A modest data lead is not a moat if the data can be copied or if the data never sits inside a loop where more use makes the product materially better. Even technical novelty starts to decay more quickly when the pace of foundation model releases compresses the shelf life of surface differentiation. The moats that remain are tied to position in the stream of consequence. This is where the old argument about data needs to be tightened. Andreessen Horowitz warned several years ago about the empty promise of data moats, arguing that many founders treat data as a magical source of defensibility when it often fails to function that way in practice. That warning has aged well. Data matters. It can matter a great deal. But the relevant question is not whether a company has data. The relevant question is whether the company has access to the moments where consequential data is born, and whether that data compounds through real action and real learning. Otherwise it is just stored potential. The strongest evidence for this does not come from slideware. It comes from systems that already live inside consequence. Waymo’s public reporting is useful here, not because it provides a universal template, but because it shows what defensibility looks like when the loop is real. Waymo says its driver is informed by more than 200 million fully autonomous miles and more than 20 million rides served. That matters because the data is born inside a live system tied directly to physical consequence, safety performance, operating permission, and public trust. The advantage is not “the model” by itself. The advantage is the closed loop between sensing, acting, measuring, and improving inside the real world. This is the positive test that most AI strategy work still misses. The real moat in 2nd Gen AI is the system that can turn evidence into authorized action, and action into verified learning, faster and more safely than its rivals. That is the control point that becomes hard to copy. Not because nobody else can code the interface. Not because nobody else can call the model. But because the company has occupied privileged ground in the chain of consequence. That privileged ground usually has four traits. It has access to the event that matters. It has causal relevance, not just descriptive visibility. It has permission structures explicit enough to allow action without fresh social negotiation every time. And it has a learning loop tied to outcome rather than just user behavior. A company that has none of these may still have a useful product. A company that builds all four has the beginnings of something harder to dislodge. What does that mean on Monday morning. It means the question is no longer whether the product generates a good answer. The question is whether the answer can move the operating object that matters without climbing a staircase of artificial authority. It means the issue is not whether the AI can summarize the case well. The issue is whether the case still has to cross five desks before anyone is allowed to act. It means the issue is not whether the product helps the worker think faster. The issue is whether the company still forces the worker to carry the burden of conversion all the way to the end.

Most firms are still building 1st Gen businesses

This is the strategic trap. Many companies believe they are building for the future because they have inserted AI into an existing process. In practice they are often building 1st Gen AI businesses inside a 2nd Gen market turn. They are making old work easier to tolerate. They are reducing search time, cutting document labor, improving recommendations, and polishing interfaces that still assume the human will remain the integration layer. That may create a real business. It may even create a good one for a while. But it does not necessarily create a durable position once customers begin asking a harsher question. Why am I still paying for all this friction. That is why the collapse of distance is not a technical metaphor. It is a balance sheet issue. Every authority gate, every interpretive handoff, every extra review cycle, every delay between knowing and doing carries cost. Some of that cost hits revenue because the window for action narrows or closes. Some of it hits margin because labor is consumed by the act of carrying context across boundaries. Some of it hits capital because decisions arrive too late to preserve option value. Some of it hits competitiveness because rivals learn faster from the same class of event. If that sounds abstract, ask a simpler question. In your company, where does permission actually live. Does it live in the system, with explicit thresholds, clear rights, and bounded actions. Or does it live in people’s calendars, inboxes, habits, and private sense of risk. Does the event travel with enough context to justify local action. Or does the context have to be re-litigated at every layer because the organization cannot tell the difference between governance and delay. Those questions are readable aloud in any executive meeting because they go straight to mechanism. Ask another. When a problem appears, how many times must the organization translate it before someone is allowed to change the outcome. How many approvals are truly about law, safety, capital exposure, or irreversible risk. How many are there because one function does not trust another, because a manager wants to remain necessary, or because the company has never done the harder work of defining permission in advance. If the answer is not clear, the moat is not the model. The moat is whatever architecture will remove those translations first. The moat is whatever architecture will remove those translations first. A fair counterargument belongs here, because not every gate is artificial and not every speed gain is worth taking. In medicine, nuclear operations, aviation, defense, and parts of finance, deliberate friction can protect human life, public trust, or legally mandated controls. Some decisions should be slow. Some should remain human. Some should be designed to resist local improvisation because the downside is catastrophic. That does not break the argument. It sharpens it. The issue is not whether all friction must be erased. The issue is whether the friction that remains is tied to real consequence and explicitly designed for it, rather than inherited from weaker systems and defended by habit. That distinction matters because the market will increasingly sort companies on it. By 2030, a large share of AI firms that win early attention through copilots, wrappers, or workflow

convenience will either be absorbed into larger platforms, pushed toward commodity pricing, or forced to retreat into niche service economics unless they own some part of the permissioned consequence loop. That is an embarrassing prediction if wrong, which is why it is worth making. The path of least resistance in AI is getting more crowded, not less. The path tied to authority, trust, and loop closed learning is harder to build and much harder to dislodge. Public writing on the end of friction as a moat has already pushed this conclusion. When intelligence gets cheaper, ease of use alone stops being sufficient. Markets reprice around what remains scarce. Trusted access remains scarce. Permission remains scarce. Consequence bearing action remains scarce. Learning from real outcome remains scarce. Those are the assets that get harder to buy once a rival has occupied them.

What boards should actually look for

Boards and executive teams are now at risk of buying the wrong kind of progress. They will hear that a product improves productivity, reduces search time, lowers documentation burden, accelerates reporting, or provides better recommendations. Those things may all be true. The harder question is whether the tool reduces the time between evidence and authorized action, or whether it merely makes the old staircase a little nicer to climb. The answer to that question will do more to determine long term advantage than almost anything else. This is where a practical topic becomes unavoidable. The topic is not AI in the abstract. The topic is whether a company is removing purchased delay from the places that determine margin, service, safety, capital use, and learning rate. An executive team that cannot speak plainly about that issue is not having a technology conversation. It is having a theater conversation. The point of AI is not to impress the organization with fluency. The point is to reduce the bill created by artificial distance. That bill shows up in more places than most firms admit. It shows up in the maintenance event that becomes a shutdown because approval came late. It shows up in the commercial signal that never becomes action because pricing authority sat three layers away. It shows up in the tutor recommendation that never helps the student because the system still depends on the teacher to be the only activation point. It shows up in the claims workflow, the supply exception, the defect review, the customer recovery path, the capital request, and the compliance queue. The domain changes. The mechanism repeats. This is why the phrase “agent” needs discipline. If a system cannot shape an outcome under permission, it is not an agent in the economically relevant sense. It may be an assistant. It may be a narrator. It may be a fluent layer on top of process debt. But if the burden of conversion still sits with the user, the organization is still living in 1st Gen logic. That is not a moral failure. It is just a fact about where the work still resides. The practical implication is severe. A company that wants to become defensible in the next era must stop asking only what the model can do and start asking what the organization will allow the system to do, under what rules, with what evidence, and with what feedback from reality. That is not a compliance afterthought. It is the architecture of speed. The firms that build this

well will look faster, but speed is not the deepest truth. They will be less dependent on retranslation. They will carry less managerial drag. They will learn from real consequence at a higher rate. That is what compounds. The point of AI is not to impress the organization with fluency. So the article that began as a warning about fake moats lands somewhere more practical and more difficult. The real risk is not only that founders overstate defensibility. The real risk is that incumbents mistake incremental convenience for strategic position. They invest in better mirrors while a different class of company is building systems that can act through permission and learn from the result. One class of firm improves the experience of living with friction. The other begins to remove the friction that should never have been there. That is the line between 1st Gen AI and 2nd Gen AI. One class helps the enterprise describe itself. The other begins to let the enterprise govern itself at the speed of its own evidence. Once that line is crossed, the moat changes. It is no longer mainly about the artifact. It is about the authority path. It is about whether the system lives close enough to consequence to matter. It is about whether governance is explicit enough to permit action without recurring social negotiation. It is about whether learning comes from the real world rather than from clicks alone. The companies that get this early will stop treating artificial governance as a sign of maturity. They will treat it as an expense to be justified. They will stop confusing human touch with control. They will stop assuming that more eyes on a decision mean better stewardship. They will ask a colder question. What part of this delay protects something real, and what part exists because we have not rebuilt the architecture yet. That is the question that will separate firms that merely use AI from firms that gain durable advantage from it. It is also the question that will expose how much of the modern enterprise has been paying for time without ever booking the cost honestly. Delay is no longer prudence. It is a bill.

References

This argument draws on Itamar Novick’s recent LinkedIn post on false AI moats for the negative test of defensibility, Stanford HAI’s 2025 AI Index for the current scale of AI investment and adoption, Andreessen Horowitz’s warning about the empty promise of data moats for the limits of treating data as magic, Waymo’s public reporting for a live example of loop closed learning tied to consequence, and Michael Carroll’s recent public writing including The End of Friction as a Moat, The One-Degree Architecture, The Next Divide, The Line Item Every CEO Pretends Not to See, and The Architecture of Permission No One Admits They Are Running, which together sharpen the practical distinction between first generation AI that improves interpretation and second generation AI that reduces the distance between evidence, permission, action, and learning. The wider logic also rests on Ronald Coase on transaction costs, Herbert Simon on

bounded rationality, Oliver Williamson on governance, W. Edwards Deming on variation and control, and Judea Pearl on causal reasoning, because the problem at hand is not model theater. It is how organizations decide where judgment lives, how delay gets justified, and who captures advantage when consequence moves closer to the signal.

Topics: synthetic-agency, causal-aiOpen in the Radiant ↗All dispatches