Retep Advisory
Commercial architecture

AI Moat or AI Leak?

Most AI programs improve productivity. Few create defensibility.

Try the interactive framework

AI does not create moats by itself. A company compounds advantage only when it owns the evaluation function, captures its decision trajectories, and operates in a domain where knowledge decays slowly. Get those three things and the AI you run becomes a durable asset. Miss any one of them and you are financing productivity gains that accrue to someone other than you.

The starting point is Satya Nadella's June essay, A frontier without an ecosystem is not stable. His central claim is right: the durable advantage in an AI-driven economy is not the model. Models get cheaper, better, and more interchangeable every quarter. The advantage is the loop that runs on top of one — human judgment setting direction, AI executing, evaluation scoring the output against outcomes that matter, the result accruing back as an asset that sharpens the next decision. He calls it a hill-climbing machine.

He names the machine. What the essay leaves implicit is the variable that decides whose machine it is: ownership. Nadella describes the loop as though owning it were the default. For most companies it isn't — the loop runs on rented rails, the compounding accrues to whoever holds the evaluation layer and the trajectory data underneath, and the company paying for inference keeps the productivity and none of the defensibility.

The framework

Two axes, four positions

Ownership decides whether the loop compounds for you. Decay rate decides whether it is worth compounding at all. Tap a quadrant to explore it, or score your own loop below.

Loop rented / shared
Loop owned
Fast decay  ↑  Knowledge decay rate  ↓  Slow decay

Score your loop

Three levers, read off the same two axes as the grid.

Loop ownership
Evals, trajectory data and judgment held by you
Rented Owned
Knowledge durability
How slowly your domain's patterns go stale
Fast Slow
Signal capture
Does the improvement land on your balance sheet
Leaks out Accrues
Verdict

What owning the loop actually means

The loop is not one asset. It's three, and who holds each one decides who captures the compounding.

The first is the evaluation function — the definition of "good" for your domain. Whoever sets the optimization target controls what the system learns to do. Score your AI against public benchmarks and you're optimizing for a target someone else defined and everyone else shares. Score it against your own outcomes — loss ratio, claims leakage, fraud-catch rate, retention of profitable accounts — and you're optimizing for something proprietary. The eval function is the most underrated piece of the loop because it's the quietest. Nobody writes "we own our evals" in a board deck, and it's the piece most often left in the provider's hands.

The second is the trajectory store — the record of how your people actually decide. Every underwriting call, every claims adjudication, every override of a model recommendation is a trace. Captured systematically and tied to outcomes, those traces are training signal. Left uncaptured, they're institutional memory that walks out the door when the underwriter retires.

The third is encoded judgment — the tacit knowledge of the in-house veteran, made explicit and queryable so it survives both employee churn and model swaps. This is the litmus test: can you switch your base model and keep the expertise embedded in your learning system? If the answer is no, the expertise was never in your system. It was in someone else's.

If switching providers resets you to parity with anyone who can sign the same contract, you never had a moat. You had a subscription.

Own all three and the loop is yours; the compounding lands on your balance sheet. Rent any one and you are contributing to a loop you don't control.

The objection, and the part that survives it

A sophisticated reader will object here: providers generally don't train their foundation models on enterprise traffic, so where's the leak? The objection is correct and it misses the point. This was never primarily about a provider retraining a model on your prompts.

The leak is simpler and harder to escape: without owned evals and captured trajectories, the proprietary asset never forms on your side in the first place. The compounding doesn't have to flow to the provider for you to lose — it's enough that it never accrues to you. Your usage produces productivity immediately. But the evaluation logic, the decision traces, and the accumulated judgment either become assets you hold, or they remain features of infrastructure you rent. In the second case your dashboards improve and your defensibility doesn't move.

The globalization parallel Nadella reaches for works better at the operator level than the macro one. Outsourcing produced national accounts that looked healthy right up until they didn't; aggregate output held while the industrial knowledge beneath it hollowed out. The company-level version is the dashboard that looks fine while the judgment that justified your margins quietly fails to accrue anywhere you own. The tell is one question: can you change base models next quarter and keep the advantage you've built? If not, you built productivity, not a moat.

Underwriting, traced end to end

Take a property and casualty underwriting loop through the three sub-assets.

The evaluation function is loss ratio by cohort, measured against the risks you actually wrote and the outcomes they produced. No public benchmark touches this. A general-purpose model has no idea whether a submission was priced well, because "priced well" is defined by your book, your appetite, and your reserve development over time. Build the eval against realized loss and you're optimizing for something no competitor and no provider can replicate, because none of them have your claims history.

The trajectory store is the record of underwriter decisions — every account bound, declined, or referred, with the reasoning and the eventual outcome attached. A senior underwriter's sense of which submissions in a soft market are worth writing is exactly the tacit pattern recognition Nadella puts at the center of human capital. Captured as outcome-tied traces, that judgment becomes signal that improves risk selection. Left uncaptured, it's a person who eventually leaves with the loop's most valuable input.

The encoded judgment is the accumulated appetite and the felt sense of a deteriorating risk, made queryable and portable so it persists across both retirements and model swaps. Build this and the model becomes a swappable component sitting under assets you control.

Place it on the grid and underwriting lands in the moat quadrant. Loss patterns in most P&C lines decay slowly; a well-built book compounds its informational advantage over years. This is the concrete form of the claim that the model is the moat — except the moat isn't the model, it's the owned loop the model runs inside.

One quadrant to the left sits the same architecture applied to fraud. The build is nearly identical; the decay rate isn't. Adversaries adapt, so fraud patterns have a shorter half-life and the trajectory store ages faster — same loop, shorter compounding window, a temporary lead rather than a durable one. The decay axis doesn't just sort companies. It sorts the loops inside a single company.

This decay dynamic has a formal backing worth naming. Zhang and Zhang model AI capability as an asset that depreciates not physically but relative to the frontier — the moment a competitor or a base model improves, your accumulated advantage is worth less even though nothing in your system changed. They show a market bifurcates when a firm's learning accumulates faster than its domain decays. That bifurcation is the line between the moat and the sprint, derived as economics rather than asserted as strategy. Tassilo Klein reaches the same place from the theory of the firm: where knowledge decays quickly, organizations face a "Red Queen effect" and must run ever faster simply to hold their position.

Where the loop is unlikely to become the moat

This framework is not universal. It matters most where competitive advantage comes from learning that compounds over time and can be captured. It matters less when:

The question is not whether work is repeatable. The question is whether judgment can be observed, evaluated, and accumulated.

Two questions before the next AI initiative

The structural response follows from the diagnosis. Own your evaluation function — define "good" in your own outcome terms, not benchmark scores anyone can match. Capture trajectories as an asset rather than exhaust; the data already exists, most companies just let it evaporate. Encode judgment before the veteran leaves. And test portability deliberately: if you can't swap the base model and keep the gain, you're renting the loop and calling it equity.

Then match the build to the domain. Over-investing in a fast-decaying loop is as much a misallocation as under-investing in a slow one. The discipline isn't "build the loop everywhere." It's "build it deepest where the domain rewards owning it."

Before approving another AI initiative, ask two questions. If we switched models tomorrow, what advantage survives? And is this domain stable enough for learning to compound? The answers tell you whether you're building an asset — or financing someone else's.

Where does your loop sit?

Curious whether you're building a moat or a leak? Let's map it.