I’ve always loved how history has a habit of informing the future. If we pay attention, we notice that patterns often repeat. The name changes, but the shape of the story rhymes.
For roughly four hundred years, the moat was the apex of defensive design. A wide ring of water around a castle, paired with stone walls twenty feet thick, created a near-impregnable position. Attackers could not scale the walls without crossing the water first. They could not dig tunnels under the foundations, because the water flooded the works. They could not rush the gate without being funneled into a narrow killing zone at the drawbridge. Castles with good moats held out against sieges that lasted months or years. The defensive calculus was so well understood that entire military doctrines were built around it.
Then gunpowder arrived, and the calculus stopped working.
The first cannons were crude, unreliable things. But by the middle of the 15th century, they were accurate enough and powerful enough to knock down walls from a distance the defenders could not reach. The moment that made the shift undeniable was Constantinople in 1453. The city’s Theodosian Walls had stood for a thousand years, repelling every invader that reached them. The Ottoman army, with its massive bombards, brought them down in fifty-three days.
The moats were still there. The walls were still there. The defenders were still there. What had changed was the attack vector. You did not need to scale the wall. You could stand half a kilometer back and reduce the entire defensive structure to rubble. You could now cross the moat.
Within a century, European military architecture had been reinvented. The star fort, with its low, thick, angled walls designed to absorb and deflect cannon fire, replaced the medieval castle. The moats that remained were no longer the primary defense.
The lesson is not that moats failed. The lesson is that moats were made irrelevant by a change in how value was attacked.
Your business has a moat. Your profession has a moat. Both were designed for a world before AI. Those conditions are changing fast.
Let’s explore what that could mean for us all.
Businesses have moats for the same reason castles did. Something has to make it hard for attackers to take what’s yours. In business, the attackers are competitors, and the moat is whatever makes your business hard to copy.
Warren Buffett made the term famous. Hamilton Helmer did the most rigorous modern mapping in his book 7 Powers. Between his framework and the investor-lens version Pat Dorsey built, we end up with roughly nine sources of durable advantage:
Switching costs - the pain of leaving a provider
Economies of scale - large teams driving down the unit cost of output
Proprietary technology - code, patents, and know-how competitors can’t easily copy
Brand - being known as the best in your field
Distribution - owning the customers or the channels that reach customers
Cost advantage - lower costs from scale, geography, or process
Network effects - the product gets more valuable as more people use it
Regulatory protection - licenses and approvals that block new entrants or project job / status quo
Counter-positioning - a business model incumbents can't copy without damaging themselves
For fifty years, these were the answer to “why won’t a competitor eat our lunch?” They were taught in classrooms, baked into valuation models, and quoted in board papers. They worked, giving businesses protection and certainty.
Then AI arrived. Capability that used to take years of code, headcount, or accumulated know-how can now be reconstituted in weeks. The game on the field has changed. Some of these moats are cracking under pressure that didn’t exist five years ago. A couple are actually getting stronger. And the shift is happening in real time, which is what makes it hard to see clearly.
The table below runs through all nine. What each moat is, why it worked, and where it stands in the post-AI world.
Read the above table as one signal. The moats built on friction, artificial complexity, and pure-software advantage are eroding. The moats built on trust, structural positioning, and things the real world still cares about are deepening.
That is the whole shift, in one sentence: friction-based moats are draining, trust-based moats are deepening.
If your defensibility story still leans on switching costs or proprietary tech that does not compound with use, you have a problem you have not yet priced in. If your defensibility story leans on licensed standing, network effects, or a business model your incumbent competitors cannot adopt without gutting themselves, you are in better shape than you think.
But the more interesting question isn’t how the old moats are faring. It’s what new moats are forming to replace the ones that have drained.
Particularly for knowledge work, four new moats are emerging, and they all converge on the same endpoint:
Accurate, reliable agents in production, delivering certified outcomes for customers.
That is the prize all businesses now seek.
Each moat on its own gets you part of the way. The real power is in the combination of all four:
Already captured distribution gives you the right to deploy on scale.
Relationship and context gives you the precision to deploy AI accurately.
The data flywheel gives you the compounding, AI self-improvement over time.
Regulated trust gives you the certification-in-the-loop that makes the output count.
All four new moats, working together, produce a compounding outcome that will help companies be ‘first and best’ in their chosen market, and almost impossible to displace.
Let’s unpack these new moats in detail, as I see them playing out:
This is not the old distribution moat. The old one was about reach, having the sales force to win new customers. That is weakening. The new distribution moat is about deployment, owning the trusted channel into customers you already have.
You already own the channel to the end customer. In a world where anyone can build a capable agent in weeks, the scarce resource is not the software, it’s the trusted path to the user.
Incumbents who turn their install base into an AI delivery channel deploy agents into real workloads from day one. That deployment is what produces certified outcomes at scale. Challengers with better tech but no distribution never get the reps. They end up selling to early adopters while the incumbent quietly upgrades every one of their existing customers to AI-native delivery and compounds the advantage.
This is why some of the biggest winners in the agent era will be boring logos you already know. They will not be the best at AI, but they will be the best at deploying AI into books of business they already own.
Persistent context and relationship memory. Whoever holds the richest accumulated understanding of a customer, their history, preferences, edge cases, systems, people, can aim agents with a precision competitors cannot match.
Generic agents produce generic outputs. Agents armed with deep customer context produce outputs accurate enough to be certified and trusted. The distinction matters enormously. A generic output is a starting point someone has to review, rework, and sign off on. A contextually-aware output is a higher quality, finished piece of work.
Static data is not the moat. The living, updating operational context is. The businesses that know not just what a customer bought, but how they prefer to be communicated with, what they tried last quarter, which of their team members signs off on what, and what went wrong the last time something similar was attempted, is building something a new entrant cannot replicate by pointing a better model at a cold dataset.
Data generated by doing the actual work, feeding back into agents that get measurably better at the work.
Every execution becomes training signal. Every reconciliation, every review, every client interaction, every correction. Agents get sharper with every cycle, and the cycles compound. Competitors without the live workflow cannot replicate the loop because the loop requires real customers doing real work in real systems.
This is different from “we have a big dataset.” Datasets are static. Flywheels are live. A dataset is a point in time photograph. A flywheel is a video, and the video gets higher resolution every time it plays.
The output is agents whose accuracy and reliability compound over time. That compounding is what makes certified outcomes economically viable. Once, as a demo. Then frequently. Then at scale, self improving. Then as the default state.
Highly regulated industries where licensed humans remain the gatekeepers.
When tech becomes abundant, regulatory standing becomes scarce. The licensed professional is not going away. They are becoming the certification layer around the agent. The signature, the sign-off, the accountability. The person whose name goes on the work and whose license is at risk if it’s wrong. In the era of abundant intelligence, customers will want to buy human accountability.
Without this layer, an agent’s output is a draft. With it, the output is certified and actionable. Something a customer can actually rely on in a court, a tax filing, a clinical decision, a financial audit.
Businesses with deep regulatory standing and licensed workforces turn agent output into outcomes customers can trust. Pure AI players cannot cross this moat without acquiring one. It’s a structural advantage, not a technical one, which is precisely why it will endure.
If you run a business, pause on two questions.
First, which of the old moats were you actually relying on? Be honest. If the answer is switching costs, proprietary tech, or the scale advantages of a large knowledge-work team, your defensibility is eroding whether or not you’ve felt it yet. The castle walls are still standing. The attack vector has changed.
Second, of the four new moats, how many do you have? If you have one, you have a starting position. If you have two, you are competitive. If you have three or four, you have the beginnings of something genuinely hard to displace. The winners of the next decade will have built multiple on purpose.
If you are thinking about your own work and career, the frame is similar but more personal.
As an employee, your profession had a moat too. For most knowledge workers, that moat was some mix of expertise, relationships, and accumulated context. Expertise is being commoditised fast. Relationships and context are not. If your work is mostly the application of expertise to generic problems, your moat is draining. If your work is the application of expertise inside deep relationships, with accumulated context, and under some form of accountable sign-off, your moat is deepening.
The question to sit with is this: in three years, will the work you do today still require you?
Or will AI be capable of mastering it (plus the context, trust, and accountability that the others can provide to an agent)?
If the answer is yes, start changing how you think about your work. Be proactive, don’t wait for it to come to you.
Moats do not fail because they stop being moats. They fail because the attack vector changes, and the old defences stop being relevant.
With AI reshaping knowledge work, we are facing these difficult discussions right now. Not in five years. Now.
The question is not whether your current moat is deep. The question is whether it is still the right one, in a future where the cost of intelligence falls to the cost of energy.
The walls we have stood behind are being knocked down and rebuilt. Worth thinking about how safe the ground you’re standing on really is.
If this resonated, share it with someone who is navigating the same shift. Best, Thomas
No posts

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.