主题综述

AI 时代的护城河 · AI Moat 2026

主题综述

更新日志

主流共识

第一点:"data moat" 在大多数场景下不存在。a16z 的 Alex Rampell 把这个常识破除得最直接:

"It's almost like gravity. Gravity actually, like one atom actually exerts gravity on you, but you only really see it at like very, very large scale. … when you've seen 4 billion people and like these people are bad, now you can sell each incremental customer … because you've seen more customers and you can get actually better results. But the challenge is that a lot of these moats only really are evident at mega, mega, mega scale."
「它确实有点像引力。引力就像一个原子一样对你施加引力,但你只有在非常大的规模下才能真正看到它。……当你见过 40 亿人,并且知道这些人很糟糕时,现在你可以向每个增量客户出售服务……因为你见过更多的客户,所以你可以获得更好的结果。但挑战在于,很多这些护城河只有在非常非常大的规模下才会真正显现出来。」

第二点:软件本身在做工作——这把"软件的市场"从 IT 预算扩到劳动预算,但也制造了无限竞争。

"The thing that is fundamentally different about this product cycle is that the software itself can actually do the work."
「这个产品周期最根本的不同是:软件本身真的能完成工作。」
Why AI Moats Still Matter · Why AI Moats Still Matter
"The same force creating infinite competition is also creating trillion dollar opportunities in places nobody's looking."
「制造无限竞争的同一股力量,也在没人看的地方创造万亿美元的机会。」
Why AI Moats Still Matter · Why AI Moats Still Matter

第三点:"AI 解决了 bootstrap 问题,没解决 retention 问题"——这条 a16z 自己提出来的判断在多个阵营都被回应。

"A really hard thing about building any startup or software is the bootstrap problem. How do you get the first 100, 200 customers? And AI actually solves that problem. It just solves the bootstrap problem. … But what's also clear is that doesn't solve your retention problem if you're a software company."
「建立任何创业公司或软件真正难的地方是 bootstrap 问题——怎么获得最初的 100、200 个客户?AI 确实解决了那个问题。它只解决 bootstrap 问题。……但同样清楚的是,如果你是软件公司,留存问题它解决不了。」

分歧在哪

阵营 A · "传统软件护城河仍然适用,只是要重新挣得"——a16z / Sequoia 主流派

a16z 的 panel 给的最完整版本:

"The defensibility of a software product resides, in my opinion, from owning the end-to-end workflow, from the context in which that it's applied, becoming the system of record, having a network effect, deeply embedding yourself within your customer."
「我认为软件产品的防御性来自:拥有端到端的工作流、被应用的上下文、成为系统记录、网络效应、深度嵌入客户。」
Why AI Moats Still Matter · Why AI Moats Still Matter

但他们也明说"GPT wrapper" 不是 thing:

"We've kind of come to the opinion that there is no AI. There's like a bunch of subspaces that are totally different that all require their own strategy."
「我们的结论是:不存在 'AI'——而是一堆完全不同的子空间,每个都需要各自的策略。」
Martin Casado · The State of AI

Sequoia 的 David Cahn 押一个 a16z panel 没强调的具体子轴——建造本身就是护城河:当所有人同时抢建数据中心时,"能真的把数据中心建出来"这件事的难度被严重低估(他在姊妹主题 ai-capital-cycle 里那条"硬件去商品化 + 风险传递链"的逐字分析是这条的延伸)。

但他也是 Camp A 内部最公开质疑"垄断式护城河"叙事的人——他认为市场高估了 AI 业务的垄断性:跟大科技时代"垄断在没人注意时悄悄建起"不同,这一轮所有人都盯着同一块地,反而更难形成那种隐秘的垄断。

注意——Cahn 这个论点和 a16z 在 State of AI 里展示的数据存在张力:Sarah Wang 的大意是,头部 frontier lab 的收入爬坡不仅超过了历史上最好的 SaaS 公司的早期爬坡,还开始超过 hyperscaler 的早期爬坡——收入正在以空前速度向少数实验室集中。Camp A 内部并不统一。

2026-08-24 · 终局之争的第三个投票人:Benchmark 的 Eric Vishria 用云的韵脚投了寡头稳态一票——2014 年"AWS 将吞掉一切"的叙事错在 Azure/GCP 后来崛起、Snowflake/Datadog 们在 Amazon 之上反杀,最终是 40-30-20 的分账外加 Cloudflare 这类 $100B 级的场外赢家。对着主持人抛来的"Anthropic's going to do everything":

"Really? Is that really right? To me, that view that it's just like, oh, this one company is going to eat it all doesn't hold. … It feels to me like we're going to end up with an oligopoly of winners. I really believe they will be these like $100 billion crazy, smaller winners."
「真的?这是真的吗?对我来说,这种观点就像,哦,这家公司将吞下所有,不成立。……我觉得我们最终会有赢家的寡头垄断。我真的相信它们会是这些价值 1000 亿美元的疯狂小型赢家。」

这个立场恰好卡在 Wang 的"收入向少数实验室集中"与 Cahn 的"市场高估垄断性"之间:集中,但集中成多家寡头而非一家通吃。Camp A 内部的终局光谱现在有三档。

2026-08-24 · 压力测试升级:switching cost 这根柱子被 agent 拆了。Camp A 清单里的"成为 system of record + 深度嵌入客户"隐含一个前提:迁移贵到没人敢做。Vishria 拿软件史上最黏的品类——数据库——正面拆这个前提:

"Migrating an app from one database to another database was a giant project that was like very, very difficult to do. So these were unbelievably sticky businesses … Now, you don't have a developer building against the database interface. You have Claude or Codex building against the database interface … agents don't get tired of monotonous work of translating one specification to another. So it turns out that now, all of a sudden, database migration, which used to be the number one thing you would not do in software, is kind of critical."
「将一个应用程序从一个数据库迁移到另一个数据库是一个巨大的项目,非常困难。所以这些都是不可思议的粘合业务……现在,您没有开发者在数据库接口上进行开发。您有 Claude 或 Codex 在数据库接口上进行构建……代理对单调的工作不会感到疲倦,比如将一个规范转换为另一个。所以现在,数据库迁移突然间变得至关重要,这曾是您在软件中不会做的第一件事。」

他的结论不是"数据库不重要了",而是竞争前沿整体改判:赢家标准从"许可证+嵌入深度"换成 cost-to-serve、zero-to-infinity scaling、迭代速度。对照他给存量 SaaS 管理层的那句话——

"…hey, every single day that you are hitting your plan, you are destroying equity value."
「嘿,您每一天按照计划行事,您就会毁坏股权价值。」

这不算否定 Camp A 的"重新挣得",是把"重新挣得"的利率调高了一档:如果 switching cost 被 agent 批量拆解,清单里剩下的 workflow、context、network effect 要独自承重——而这恰好为下面阵营 H 的激进版铺了路。

阵营 B · "Vertical integration is the only real moat"——SpaceX 派 / 硬件操作派

Scott Nolan (General Matter) 给的是最 SpaceX 化的版本:

"Many different sectors where subcontracting is the norm and you're going to subcontract a subsystem to somebody who subcontracts a component and then that component has different inputs and they subcontract that all the way down. … [Cost-plus gives you] layers of subcontractors, dozens deep, and no ability for anyone to do something really novel."
「很多行业里外包是常态——你把一个子系统外包给某人,他再把一个零件外包出去,那个零件又有不同的输入、又外包下去,一路到底。……(cost-plus 体制下)一层层分包商,深达十几层,谁都没法做出真正新颖的东西。」
"I think the thing that's most linked to stagnation is probably being a cost plus industry where there's very little incentive for progress, not much incentive to bring the cost structure down."
「我认为最容易导致停滞的大概是 cost-plus 行业——几乎没动力进步,也没什么动力降本。」

Evan Spiegel (Snap) 在硬件方向给的是同结论:

"We have a developer ecosystem, so hundreds of thousands of developers who have built millions of lenses on our developer tools. When they build those experiences, they run on our rendering engine, which is really deeply integrated into our operating system. And they see and experience those AR objects through our glasses using our own optical engine, meaning the piece of glass in the glasses and the little projector, we design and build ourselves."
「我们有一个开发者生态——几十万开发者在我们的开发工具上做了上百万个 lens。这些体验跑在我们自己的渲染引擎上,而渲染引擎又真正深度地集成进我们的操作系统。用户透过我们的眼镜、用我们自己的光学引擎去看到并体验这些 AR 物体——也就是眼镜上的那块玻璃、那个小投影仪,都是我们自己设计和制造的。」

David Cahn 帮 Camp B 提供了一句话框架:

"People were thinking very abstractly, sort of in a bit's perspective about AI, but they should be thinking in an atom's perspective about AI."
「人们一直用 bit 的视角抽象地想 AI——其实应该用 atom 的视角想。」

阵营 C · "软件层 above commoditized models 是护城河"——Baseten 立场

Tuhin Srivastava 的论点跟 Camp B 在物理方向上对立——他不押"往下"垂直整合,押"往上"软件层(逐字稿末尾的 "modes" 是 "moats" 的听写误差):

"And to the extent that that is encoded in a model, I think a lot of their business will be at risk, but to the extent that it is encoded in workflows, that is where they will be able to develop modes."
「如果这些信号只编码在模型里,我认为他们的业务将面临很大风险;但如果信号编码在工作流中,他们就能建立起护城河。」

那个存在性问题——独立的应用层到底还能不能在大实验室面前存在——其实是主持人 Sarah Guo 抛给他的("does the independent application layer get to exist at all versus the labs?")。Tuhin 的正面回答:

"I think the application layer will exist for a number of reasons. One is because I think this idea that what is valuable to a company is the user signal that they can gather, that only they can gather."
「我认为应用层会存在有几个原因。首先,我认为对于企业来说,唯一有价值的是他们能收集到的独家用户信号。」

2026-08-24 注:这个阵营迎来了一次内部对撞——新开的阵营 H(Fireworks/Mercor)接受 Tuhin 的前提(独家用户信号有价值),但反对他的结论(编码进工作流),主张编码进自有模型权重。分歧细节见阵营 H。

阵营 D · "品牌 / 设计 / 客户爱是新护城河"——Cannon-Brookes / Spiegel 路线

Mike Cannon-Brookes 押设计:

"I do think it makes design more valuable. Good design. Scarce resources probably get more valuable and I think good design is quite scarce. … When you have any major technological transition, we're back to an era of fundamental design."
「我确实认为这让设计更值钱。好设计。稀缺资源大概率会更值钱,而我认为好设计相当稀缺。……每逢重大技术变革,我们就回到一个'基础设计'的时代。」
Mike Cannon-Brookes · 20VC: Atlassian CEO

Evan Spiegel 押的是平台级生态系统:

"Pretty early on, we learned that we had to start working on things that were a lot more complicated and hard to copy. Stories are very easy to copy. That's a feature in our app. Of course, we have the patents or whatever, but it's very difficult to enforce software patents."
「很早我们就明白,必须去做那些复杂得多、难以复制的东西。Stories 太好抄了——它只是我们 app 里的一个功能。我们当然有专利之类的,但软件专利极难维权。」

David Cahn 把这个观点压回到一个朴素的检验上:

"If you have real customer love and you've built something that people absolutely need, you're going to be able to navigate through any market environment."
「如果你有真实的客户爱、做出了人们绝对需要的东西,你就能穿越任何市场环境。」

阵营 E · "Agent-led distribution 正在改写"——Profound 的第三维度

James Cadwallader (Profound) 提出的是上述四个阵营里没人正面接住的一个不同的题目:

"It's not so much that the front door of the internet has changed; it's the person going through the door that has changed."
「不是互联网的前门变了——是穿过门的'人'变了。」
James Cadwallader · From SEO to Agent-Led Growth
"In the old world of SEO, you were building content designed to be picked up by an algorithm but consumed by a human. In this new world, you are building content designed to be discovered and consumed by an agent."
「在旧的 SEO 世界里,你做的内容是被算法抓取、被人类消费。在新世界里,你做的内容是被 agent 发现、被 agent 消费。」
James Cadwallader · From SEO to Agent-Led Growth

如果这个判断成立,Camp D 的"品牌"概念会被重新定义——agent 不会被海报和广告"打动",但会被 schema、可解析性、引用频次"打动"。这条线在其他阵营里没被认领。

2026-08 补充:Modal CTO Akshat Bubna 把 Cadwallader 的判断从内容分发延伸到了基础设施——穿过门的"人"变了,不止改写营销,也在改写开发者平台的产品定义。他们把整个 SDK 团队的目标从 DX 改成了 AX:

"We've actually changed our SDK team to think of an agent experience instead of a developer experience. And we think that the same benefits that apply for DX also actually apply for AX, which is why would you have an agent read through hundreds of Kubernetes files and like write YAML that's not even typed when it can basically make a couple of changes in a decorator and it gets this sort of self-provisioning runtime of Being able to see its changes live in action."
「我们实际上改变了我们的 SDK 团队,将重点放在代理体验上,而不是开发者体验。我们认为适用于 DX 的相同好处同样适用于 AX,这就是为什么要让一个代理阅读数百个 Kubernetes 文件并编写没有类型的 YAML,当它其实可以在装饰器中做几处更改,并获得这种能够实时看到其变更的自我供给运行时。」

这意味着 Camp E 的"为 agent 重新设计"逻辑至少已在两层出现:内容层(Profound:schema、可解析性)与基础设施层(Modal:agent 可自助操作的 runtime)。如果 agent 成为软件的第一用户,"用户体验"作为护城河的定义会整体位移。

阵营 F · "Outlier founder 属性"——Kalshi 的元论点

Tarek Mansour (Kalshi) 给的是另一种维度——护城河不在产品也不在分发,在谁能突破市场对其的天然抗拒

"A startup is intrinsically something that the world does not want to exist."
「初创公司本质上是这个世界并不希望存在的东西。」
"I think if you want to achieve outlier results, you need some sort of outlier. I'm going to call it imbalance. You need some sort of outlier, unusual thing that is part of your history, something."
「要做出 outlier 的结果,你需要某种 outlier 的东西。我会叫它'不平衡'。某种异于常人、属于你个人历史的东西——某种什么。」

这条不是"什么是护城河"的回答,是"在 AI 时代谁能挖出护城河"的回答。它跟其他五个阵营是元层级关系,不是平行关系。

阵营 G · "数据的复仇"——专有数据生成派(2026-08 新增)

共识第一点(Rampell:data moat 只在 mega-scale 显形)在这里遭到正面回击——而且回击者换了标尺。Rampell 度量的是数据的*网络效应*(见得多→做得好),这个阵营度量的是数据的*排他性*(谁能拿到或生成只有自己才有的数据)——data moat 不需要 40 亿用户,只需要排他性。

Radical AI 的 Joseph Krause 在材料科学给出这个立场最极端的版本:模型全部开源也无妨,因为护城河根本不在模型里。他预测五年内多数模型开源(逐字稿里 "we actually don't think models are remote" 的 "remote" 是 "the moat" 的听写误差——与 Tuhin 那句 "modes" 同款):

"And that's why we open source for the community to get better ideas and to really understand that we think experiments or really push that we think experiments are the moat, not the model itself."
「这就是为什么我们要开源,以便社区能获取更好的想法,并真正理解我们认为实验是护城河,而不仅仅是模型本身。」

Krause 的数字让这个立场可检验:自驾实验室 5-6 个月合成 1200 种合金(其中 300 种文献未见)、单次实验成本 $60-300——护城河是"生成实验数据的物理通量",不是数据存量。注意这个阵营和 Camp C 的暗合:Tuhin 的"只有你能采集的用户信号"与 Krause 的"实验",是同一个论证在用户数据、物理实验数据两种介质上的变体——护城河从数据的占有移向数据的生成权。它与 Rampell 引力论的真正分歧在于:数据的价值曲线是规模递增(引力),还是排他即成立(产权)。两边都还没拿出对方尺度上的证据。

2026-08-24 补充:从单源恢复为多声部,生成介质再添两种。Mercor 的 Brendan Foody 把"专有数据生成通量"做成了明码标价的市场:单季 250 万专家小时流过其人才网络、单任务定价 $50–$10,000、frontier lab 一个月买 5 万个任务——Krause 的"实验通量"(材料科学的物理实验)在白领知识工作上的对应物,是"专家×验证器"的生产通量(律师写数据室、教授式 rubric 给模型轨迹打分)。他的论证核心与 Krause 同构——为什么这种数据只能被"生成"而不能被模型自产:

"But the reason that humans are still an essential component of the process that's incredibly differentiated is that you need humans almost definitionally to measure what is beyond the frontier of the model capabilities."
「但人类之所以仍然是这个过程的一个至关重要的组成部分,且具有独特性,是因为几乎可以定义为您需要人类来衡量超出模型能力边界的东西。」
Brendan Foody · RL Environments Explained

Vishria 则在机器人介质上补了一个投资人样本:Sunday Robotics 用与机器手同构设计的数据手套做遥操作采集,把机器人、模型、数据采集垂直整合成一个飞轮——他明说这是从 Tesla/Waymo 学来的教训(两者都以自有车队采集高质量数据来 bootstrap 模型)。这是 Camp B 的垂直整合与 Camp G 的数据生成权在同一家公司会合:垂直整合的目的从"控制成本结构"变成"控制数据生成"。至此生成权论点已横跨四种介质:物理实验(Krause)、用户信号(Tuhin)、专家小时(Foody)、遥操作硬件(Sunday)。老警示照旧:Foody 在卖数据、Vishria 是 Sunday 的投资人——这个阵营的每个声音都有仓位,只是可检验的数字变多了。

阵营 H · "Own your intelligence"——自有权重派(2026-08 新增)

Fireworks CEO Lin Qiao 与 Mercor CEO Brendan Foody 在同一场活动先后登台(主持人介绍 Lin 是 Brendan 的 "close friend and collaborator"),合力把一个新立场推上台面:应用层本身守不住了,护城河要沉到你自己拥有的模型权重里。Lin 先把 Camp C 赖以成立的"软件层"判了缓刑:

"Because it's very easy to clone and copy application as is, as you all know, right? … So from screenshot, boom, generate the same or even better app. So that's very scary that application itself. Is kind of the mode is being reduced."
「因为像大家所知道的那样,克隆和复制应用程序是非常简单的,对吧?……从截图开始,生成相同或甚至更好的应用程序。所以这让人非常害怕,应用程序本身的情况。这种模式正在被削弱。」

("the mode is being reduced" 是 "the moat" 的听写误差——本语料第三例,与 Tuhin 的 "modes"、Krause 的 "remote" 同款。)她给的出路不是更厚的工作流,是后训练:

"So then post-training becomes a very appealing solution because post-training allows you to basically encode, codify your unique taste Into a model that no one can steal from."
「因此,后训练成为一个非常吸引人的解决方案,因为后训练让你基本上能够将你独特的品味编码成一个无人可以窃取的模型。」

与 Camp C 的分歧精确到"存放地点":Tuhin 说信号编码在(实验室的)模型里是风险、编码在工作流里才是护城河;Lin 说工作流/应用一张截图就能克隆,能守住的是你自己拥有的权重。两人共享同一个前提——只有你能采集的用户信号(Lin 的版本:product-market fit 之后从产品表面采到的高质量生产数据才是燃料)——分歧只在把这笔存款存进谁的金库。Lin 还补了第二重动机:后训练把推理成本压低 5-10 倍,"不要 scale into bankruptcy"不只是 startup 的事——incumbent 的 CFO 正因为成本卡着 AI 功能不放行。在这个立场里,护城河与单位经济是同一件事;这也顺带给共识第三点(AI 不解决 retention)提供了目前语料里最正面的候选答案:retention 的新来源 = 自有权重的质量×成本差,且它是复利的——生产数据回流、权重变强、成本再降。

Foody 从数据供给侧给出同一结论的时间表:

"And I believe that over the next 12 months, there's going to be dozens of examples just like that, where companies own their own intelligence. And that is the key source of the modes that they're building."
「我相信在接下来的 12 个月中,会有十几个这样的例子,企业拥有自己的智能。这就是他们构建模式的关键来源。」
Brendan Foody · RL Environments Explained

("modes" 又是 "moats"——第四例。)他的三支柱框架(compute、算法、数据集,"数据往往是最有差异化的那个")解释了为什么这条路此刻通了:compute 与算法在商品化,专家生成的数据集不在。与 Camp G 的关系是上下游:G 回答"只有你能生成什么",H 回答"生成出来的东西存进哪里才偷不走、才复利"。合起来才是 "own your intelligence, not rent" 的完整链条。

折扣同样要打:这个阵营的两位主唱一个卖后训练平台、一个卖专家数据,与 Radical 卖自驾实验室是同一种当事人结构。目前最像第三方证据的展品是 Cursor——Lin 与 Foody 各自独立引用其自训模型路线(Composer 到 Composer 2.5、目标与 frontier 质量打平)。这条线是否成立,最终要看这类公司离开供应商的讲台后,权重优势能不能在 frontier 每次升级后活下来。

都没说透的

我的看法

判断(不是事实):这场争论的关键不是"哪一种护城河是真的",而是护城河的层级开始按客户类型分裂——B2B 企业客户的护城河大概率是 Camp A + Camp C 的组合(workflow + system of record + retention),消费类 AI 产品的护城河大概率是 Camp D(品牌、设计、生态)+ Camp E(agent-friendly 分发)的组合,硬件 / 物理基础设施的护城河仍是 Camp B(垂直整合)。所谓"AI 护城河"作为单一概念正在解体——这本身就是这一轮变化的重要信号。

我对这个判断的把握:中等。最强的支撑是 a16z 已经自己说出了"there is no AI, there's like a bunch of subspaces"——这等于承认护城河不是单一概念;最弱的环节是 Camp E(agent-led distribution)——我把它当成会成立的趋势,但实证还不够支撑判断它会重要到改写 B2C 护城河结构。

2026-08 增补(原判断保留):新料没有推翻上面的分裂判断,但暴露了它漏掉的一根轴。按客户类型的分裂描述的是*需求侧*——护城河建在哪类客户关系上;语料里另有一个*供给侧*命题在反复出现:护城河建在"只有你能生成的数据"上——Tuhin 的用户信号、Krause 的实验通量。这条轴横切所有客户类型。修订后的判断:AI 护城河 = 需求侧的嵌入位置 × 供给侧的专有数据生成权,缺一则护城河退化为"跑得快"。把握仍是中等——供给侧这半边目前几乎全是当事人自述(Radical 就在卖这个故事),缺第三方验证;Camp E 的实证短板未变,但 Modal 把 agent-first 从营销层扩到基础设施层,趋势线略有增强。

2026-08-24 增补(前两段保留):供给侧那半边这次补上了结算层。08-10 的修订说护城河 = 需求侧嵌入位置 × 供给侧专有数据生成权,但没回答"生成出来的数据存到哪里才不被偷走"——阵营 H 的答案是:蒸进自有模型权重(后训练),让品味与专有数据变成克隆不走的资产,还顺手把单位经济做顺(5-10 倍成本差)。与此同时需求侧那半边被 Vishria 打薄了一角:switching cost / system of record 的嵌入正在被 agent 拆解(数据库迁移从禁忌变例行),需求侧嵌入的半衰期在缩短。判断的结构不变,但权重移动:需求侧嵌入仍然必要,但越来越像租约;供给侧"生成权 × 权重沉淀"更像产权。把握仍是中等——卖铲人偏置比上月更集中了(Fireworks 卖后训练、Mercor 卖数据、Radical 卖实验室,全是当事人),唯一的缓解是 Cursor Composer 被多方独立引用,开始有准第三方样本的样子。

还想知道什么

取材