AI moats require rights to learn from workflow data

Product & strategy SeedlingPlanted Sep 2026

AI moats require the right to learn from workflow data, not merely access to it. I can embed an agent deeply in customer operations, collect years of task histories, and still build no compounding advantage if the provider may use those records only to complete the current customer’s work. The strategic asset is therefore not “data” in the abstract. It is permission to convert production evidence into better memory, evaluations, policies, retrieval, or model behaviour at an explicitly agreed scope.

The agent data flywheel makes that distinction unavoidable. Real workflows produce signals that generic usage metrics cannot: which task succeeded, which tool sequence failed, where knowledge was missing, when a person intervened, and whether the downstream result was accepted. These are unusually valuable labels because they describe capability, not attention. Yet signal quality does not settle who may learn from it. Customer confidentiality can constrain reuse, especially in legal, clinical, and financial work. A dataset can be unique and high-signal while remaining contractually unusable outside the transaction that created it.

I would separate three learning rights in the product contract. Tenant learning lets the agent retain a customer’s preferences, procedures, and history for that customer. Cohort learning permits suitably governed patterns to improve service for an agreed group, such as customers in the same vertical. General learning allows evidence to improve the shared product. These scopes create different economics. Tenant learning deepens accumulated memory and switching cost. Cohort or general learning can create the network-enhanced flywheel in which one deployment improves later deployments. Calling all three “our data moat” conceals the most important constraint.

This changes how I evaluate a product wedge. I do not ask only whether the workflow is frequent or valuable. I ask whether it yields verifiable outcomes, whether expert corrections can be captured systematically, and whether the company has negotiated a lawful path to reuse the resulting signal. Human review becomes moat-building only when edits, escalations, approvals, and rejections are labeled and connected to a change mechanism. Without that structure, review is operating cost. Without learning rights, even a well-structured feedback pipeline may create value solely inside one tenant.

The same logic changes what “proprietary” means. Deep API access and validated enterprise integrations can be durable because permissions, system knowledge, and migration risk are hard to reproduce. They also place the product where consequential workflow evidence is generated. That position is not automatically a learning licence. Access answers whether the agent may read a record or take an action; learning rights answer whether the resulting trace may shape future behaviour. I want those questions resolved before the roadmap assumes cross-customer compounding.

I would treat these rights as a product dependency, not a legal clean-up task. The team needs to know which feedback can update tenant memory, which examples can enter a domain evaluation set, which patterns can inform shared policies, and which records must remain isolated. That knowledge determines architecture, packaging, customer promises, and even which market segment can support the intended business model. A company planning a shared domain model while selling contracts that prohibit shared learning has not found a moat. It has created a strategy–permission mismatch.

There is one precise concession: a product can remain defensible without rights to cross-customer learning when exclusive tool access and deeply validated integrations impose meaningful replacement cost. In that boundary, position and switching friction can support the business even while every customer’s data remains isolated. I would describe that honestly as an access-and-integration moat, not claim a data flywheel that the contracts prevent from turning.

My diligence question is therefore simple: show me the chain from workflow event to permitted improvement. Which outcome is observed? Who supplies the label? At what scope may it be reused? Which product mechanism changes because of it? Domain fine-tuning, evaluation frameworks, structured human feedback, and accumulated memory can all compound, yet only inside the rights envelope customers have granted. The strongest AI company does not merely sit close to valuable work. It earns the trust and permission to learn from that work, then builds the machinery that makes every permitted lesson count.