Vertical agents win on domain constraints, not model quality

Product & strategy Seedling Planted Aug 2026 · Tended Aug 2026

Every vertical agent pitch I hear leads with the model. The model is the least defensible thing in the deck. Whatever model you're using, a generic assistant can call the same one tomorrow at the same price. What it can't cheaply replicate is everything you wrapped around it — and that wrapper, the encoded constraint set of a professional domain, is the actual product.

The formal definition of a vertical agent makes this concrete: a tuple of policy model, memory, tools, verifiers, and evaluation framework. The model is one component of five, and it's the swappable one. The other four are where a domain lives. Memory means the corpus and ontology of the profession. Tools mean its systems of record. Verifiers mean its rules about what must never happen. Evaluation means its professional standards rather than generic benchmarks. Build those four well and the model becomes a replaceable engine inside a vehicle only you know how to build.

What encoded constraints actually look like

The pattern repeats across every vertical I've studied. ChemCrow, the chemistry agent, ships eighteen tools — and the interesting ones are the safety tools: a mandatory pre-synthesis gate that screens every compound against controlled-chemical databases before any synthesis step runs. That gate is not a prompt; it's architecture. Legal AI carries a documented fabrication problem — benchmarks put citation hallucination at worse than one in six — so serious legal agents are built around section-aware chunking of statutes, jurisdiction-separated infrastructure for data residency, and citation verification as a hard step. Healthcare agents run PHI de-identification pipelines and attribute-based access control before a token ever reaches the model, because HIPAA doesn't accept "the prompt said not to." Financial agents pin temperature low for deterministic compliance outputs and route models through independent validation crews mapped to regulatory guidance. And across all of them, autonomy is bounded by the same three variables: materiality, reversibility, regulatory consequence.

None of that is model capability. All of it is domain knowledge, expensively acquired, encoded as structure. A horizontal assistant vendor could replicate any single piece — but replicating the whole set, for every vertical at once, while carrying the liability posture each vertical demands, is exactly the kind of unglamorous work platform companies don't do. Add the feedback loop — every correction from a professional user is proprietary training signal a generic tool never sees — and the moat deepens with usage.

Where the thesis needs honesty

Two concessions. First, model quality is a floor even if it isn't a moat: the clinical agent literature shows orchestrator model choice swinging tool-call accuracy from under 10% with small models to nearly 90% with frontier ones. Constraints wrapped around a weak model produce something worse than useless — confidently wrong within guardrails. You need a good model; you just can't defend on it. Second, frontier models keep absorbing capability that used to require vertical engineering. Structured extraction, long-document reasoning, even some compliance awareness — each release eats a layer of wrapper. The durable constraints are the ones models can't absorb by getting smarter: access to proprietary data, integration into regulated workflows, audit trails a compliance officer will sign, and someone to sue when it goes wrong.

So when I evaluate a vertical agent product — mine or anyone's — the question isn't "how good is the model." It's "what does this system refuse to do, what does it verify before acting, and who trusts it enough to plug it into their system of record." The constraint set is the product. Price it accordingly.