
Every portfolio company now claims an AI advantage. Almost none of them have one.
According to McKinsey's 2025 research on generative AI, 79% of organizations report that competitors are making similar AI investments, while only 23% believe they are building anything sustainable from those investments. That 56-point gap is the single most important number in enterprise AI right now, and it is the number most investment committees are not yet pricing into their models.
The reason is structural, not competitive. Model access no longer determines winners. Frontier models are available to every well-funded company on roughly equivalent terms, which means owning one confers no lasting edge: advantage dissolves within weeks of a competitor matching the implementation. What survives that commoditization is the question this article answers: what remains valuable after the model itself becomes a commodity?
That remainder is the moat. And for investors, scoring it is no longer optional due diligence. It is the diligence.
Why "We Use AI" Is No Longer a Differentiator

Roughly nine in ten organizations now use some form of AI in at least one business function. At that level of saturation, AI presence has stopped functioning as a signal. A target citing "AI-powered" in its pitch deck is describing table stakes, not defensibility.
This matters directly to deal screening. The diligence question has to shift from does the target use AI to what proprietary asset does their AI compound, because the first question is now answered "yes" by nearly every company in the pipeline, and it tells you nothing about which of them will still be differentiated in eighteen months.
What follows is a working taxonomy of the seven assets that do create durable advantage, drawn from the current McKinsey QuantumBlack framework on AI moats and extended with the operational and diligence angles that matter specifically to investors evaluating targets and portfolio companies.
The 7 Sources of AI Moat

1. Proprietary Data Flywheels
Not all data is a moat. Volume is not the asset; compounding is. A genuine data flywheel is one where usage generates data that improves outcomes for the next customer, not just the current one, and where that data is structurally inaccessible to competitors.
Most targets will claim a data advantage. Few can describe the loop that closes it. The diligence question worth asking directly: when a customer uses the product, what gets measurably better for someone else as a result? If the honest answer is "nothing," the data asset is inventory, not a moat.
2. Embedded Workflow Integration
Classic switching-cost moats, the kind that made Salesforce and Oracle durable, now have an AI-native equivalent: AI woven into the operational fabric of how work gets done, rather than layered on as a discrete feature.
The clearest illustration comes from healthcare technology. Microsoft's Dragon Copilot, embedded directly in clinical documentation workflows within electronic health records, has cut documentation time by roughly half. The moat there is not the underlying model; it is the depth of integration into a workflow a hospital cannot easily unwind.
This is a clean diligence filter: is the target's AI a SKU that could be disabled in a product settings menu, or infrastructure that would require re-architecting the customer's operations to remove? The former is a feature. The latter is a moat.
3. Network Effects at the AI Layer
The most durable moats compound relationally, not just technically: behavioral data, ecosystem breadth, and multiple customer touchpoints reinforcing one another over time in a way a single competitor feature cannot replicate. This is the pattern that turned an early recommendation algorithm into the enduring value of a subscription ecosystem. The algorithm mattered at launch, but the moat came from a business model built around data, integration, and lifetime customer value.
For investors, this is the hardest moat to diligence quickly and the most valuable one to find, because it cannot be copied by hiring away a data science team. It has to be built over years of compounding usage.
4. Trust and Regulatory Credibility
In regulated, high-stakes verticals, finance, healthcare, identity, trust is not a soft differentiator. It is a gatekeeper to adoption, and it functions as a structural moat because it is slow to build and difficult for a fast-follower to shortcut.
JPMorgan Chase offers the clearest proof point available: it has ranked first on the Evident AI Banking Index for four consecutive years and is among the only banks publicly reporting realized AI returns, which now approach $2 billion. That combination of performance and transparency reinforces both regulatory standing and investor confidence in a way a newer entrant cannot manufacture quickly.
For portfolio companies in healthcare SaaS or financial services specifically, governance maturity, including audit trails, explainability, and compliance-by-design, should be scored as an asset in the moat framework, not filed away as a compliance cost center.
5. Learning Velocity
AI performance improves with experimentation and data, which means organizations whose rate of learning and iteration consistently outpaces their peers build a moat almost by default, one that compounds independently of any single feature or dataset.
This is difficult to fake and easy to diligence if you ask the right question. Roadmap slides describe intentions. Release cadence and the ratio of experiments run to experiments shipped describe actual velocity. A target with a slower learning loop than its category leader is losing ground every quarter, even if its current product looks comparable.
6. Custom Infrastructure and In-House Systems
Tools and applications can be copied within a budget cycle. What cannot be copied as easily is the underlying infrastructure: the systems, workflows, and data architecture a company builds around AI that a competitor would need years, not weeks, to reconstruct.
This is also the moat most prone to overstatement in founder narratives. The useful diligence tell: ask what breaks if the underlying model vendor changes pricing, deprecates an API, or is swapped out entirely. If the answer is "everything," the target has built a thin wrapper, not infrastructure. If the answer is "very little, because the value sits in our own architecture," that is a real moat.
7. Business-Model Reinvention Around AI
The most valuable moat is also the least visible on a product demo: a business model rebuilt around AI rather than one with AI bolted onto an existing model. This is the pattern that separates efficiency gains from structural advantage.
The economic evidence is now substantial. Companies that genuinely rewire operations around AI, rather than simply deploying tools inside an unchanged operating model, see EBITDA improvements of 10 to 30%, averaging close to 20%. That is not a productivity statistic. It is a valuation statistic, and it is the reason this particular moat deserves the most direct attention in any AI-related investment thesis.
Why Most Companies Will Never Build One

Return to the opening gap: 79% of organizations report matching competitor investment, and only 23% believe they are building anything sustainable from it. The threat is structural: barriers to basic AI adoption are lower than in any previous technology wave, which means tactical implementations can be matched within weeks by any adequately funded competitor.
That gap is precisely why moat-scoring now belongs in the standard diligence workflow rather than functioning as a bonus qualitative note in the investment memo. A target that cannot articulate which of the seven moats above it is building is, by definition, in the 79%, competing on access to the same models as everyone else, with no durable reason its current advantage survives contact with a well-capitalized fast follower.
A Diligence Lens for Investors
Applied practically, the seven-moat framework functions as a scoring rubric rather than a descriptive essay. For each target or portfolio company, the useful exercise is scoring zero, one, or two points per moat (evidence absent, evidence partial, evidence strong), producing a 14-point composite that can be tracked across a portfolio and compared across a deal pipeline.
This is not a theoretical exercise for the market this framework serves. Roughly 59% of PE-backed companies have already adopted AI in some form, and AI is increasingly treated as a third lever of portfolio value creation alongside revenue growth and margin expansion, with medium-term margin uplift projected above 10% where it is applied well. The firms capturing that value are not the ones with the newest model subscription. They are the ones whose targets score high on the moats above, and whose diligence process can tell the difference before capital is committed, not after.
The Moat Question Belongs in Every AI-Adjacent Deal Thesis

The model layer is settled. Every well-capitalized company in your pipeline has access to comparable AI capability, and that access will keep getting cheaper and more commoditized every quarter. The differentiation, and the return, lives entirely in the seven assets above: the data that compounds, the workflows that can't be unwound, the trust that can't be shortcut, the velocity that can't be borrowed, the infrastructure that can't be copied, and the business model that was actually rebuilt rather than merely AI-enabled.
Scoring which of those a target actually has, rather than which of them it claims, is the diligence discipline that increasingly separates the winning theses from the rest of the portfolio.
See the Moat Before You Write the Check

Evermethod AI turns the framework above into a quantified score: AI disruption exposure and resilience analysis built for the deals where "AI-powered" is a claim, not yet a fact.
The moat isn't in the pitch deck. It's in the score.
Request a sample resilience report and see where your next target, or your last one, actually stands.
Get the latest!
Get actionable strategies to empower your business and market domination

.png/preview.png?t=1721195409615)
