Agent moats come from embedded workflow data, not model exclusivity

Product & strategy SeedlingPlanted Sep 2026

Agent moats come from embedded workflow data, not model exclusivity. Preferential access to a capable model can create a launch window, but it rarely creates a durable business. The advantage compounds only when the product sits inside real work, observes what happens next, and turns verified outcomes into better decisions that a new entrant cannot reproduce from the same foundation model.

The useful distinction is between data volume and learning position. An agent does not become defensible because it has processed many prompts. It becomes defensible when the workflow produces signals with meaning: which recommendation was accepted, which exception required escalation, which tool call caused a reversal, which approval condition mattered, and whether the downstream outcome was actually good. Those labels exist because the product owns a seam in the work—not because the model generated text.

This is why the AI flywheel is a data architecture. The loop needs an event model, identity across runs, outcome joins, delayed-label handling, and a governed path from production evidence back into evaluation, retrieval, policy, or training. “More usage improves the product” is not a strategy until the system can say what was learned, from whom, at what scope, and where that learning is allowed to propagate.

Scope matters because not every feedback loop is a network effect. Within-user learning makes one customer’s agent more personalized and raises switching costs, but it does not automatically improve the product for the next customer. Across-user learning can compound more broadly, yet it requires transferable task structure, normalized outcomes, and permission to reuse signals. Physical and highly local workflows often resist that transfer. A thousand site-specific lessons may remain a thousand local advantages rather than one global moat.

The strongest products therefore design the learning surface alongside the workflow. They capture the decision state before an action, the intervention during it, and the outcome after it. They separate implicit behavior from explicit human judgment. They retain provenance so a bad update can be traced and reversed. And they feed improvements into the narrowest appropriate layer: a tenant’s memory, a shared retrieval corpus, a policy threshold, an evaluator, or a model adaptation. Data products fail at lifecycle; moat data does too when collection is celebrated but ownership, quality, retirement, and rollback are ignored.

This reframes product strategy. The wedge should not merely be a task the model performs impressively. It should be a workflow where repeated use creates exclusive, decision-relevant evidence. Domain constraints matter because they define what counts as success, which exceptions are expensive, and which feedback is trustworthy. That is the durable part of the vertical-agent advantage: not a domain-flavored prompt, but accumulated operational understanding encoded in data and controls.

There is one precise concession: exclusive model access can be a real moat while the capability gap is large, contractually protected, and difficult for competitors to route around. It can buy distribution and time. But the protection decays when comparable models arrive, providers expose the same capability, or customers demand portability. If that window was not used to embed in workflow and build an evidence loop, the moat expires with the exclusivity.

I would judge an agent business by the data it becomes uniquely positioned to create, not the model logo on its architecture diagram. An operating envelope makes the product’s current reliability legible; workflow data makes that envelope capable of expanding without guesswork. Models supply capability. The owned loop from action to verified outcome is what compounds.