AI due diligence: finding real moats, not AI wrappers
The easiest AI company to build is a wrapper. Take a foundation model. Add a narrow interface. Connect a few APIs. Create a workflow demo. Call it a vertical AI product.
Some wrappers become useful products. A few may become good businesses. But many will not become defensible companies. For investors, corporates, and strategic acquirers, this creates a diligence challenge. The demo may look impressive. The market may be large. The team may be strong. The product may work. But the deeper question remains: is this a real AI-native company, or a thin layer on top of someone else's model?
Why traditional SaaS diligence is not enough
Traditional SaaS diligence focuses on familiar questions: is the market large, is the product differentiated, is revenue growing, are customers retained, are gross margins attractive, is the team strong. These still matter. But AI startups add new dimensions: model dependency, data rights, prompt and workflow defensibility, inference cost, evaluation quality, security exposure, governance readiness, regulatory risk, output reliability, and vendor concentration. A startup can look strong under SaaS diligence and weak under AI diligence.
The wrapper risk
A wrapper is not automatically bad. In the early days of every platform shift, wrappers are natural — they test demand quickly and help founders discover workflows. The risk is when the wrapper has no path to becoming more than a wrapper. Common warning signs include no proprietary data, no workflow ownership, no technical differentiation, no switching cost, no governance layer, no distribution advantage, no customer-specific learning, no evaluation system, and no clear path beyond the current model provider. If a competitor can recreate the core product in weeks using the same model and public APIs, the company may have utility but limited defensibility.
What creates a real AI moat
AI moats are rarely based on model access alone. Foundation models are powerful, but access is broad and capabilities diffuse over time. Real moats are more likely to come from six sources.
1. Workflow ownership
The company owns a critical workflow inside the customer's organization — stronger than owning a feature, because it creates usage frequency, integration depth, and organizational dependency. The question is: would the customer's work break or materially slow down if the product disappeared?
2. Proprietary data loops
The product improves because it sees unique data, feedback, corrections, decisions, and outcomes. This does not always mean owning a massive dataset; it can mean owning high-quality workflow data competitors cannot easily access. A good diligence question: what does the company learn from every customer interaction that improves future performance? If the answer is unclear, the moat may be weak.
3. Evaluation and reliability systems
Many AI startups can produce outputs. Fewer can systematically evaluate output quality. A serious AI company needs evaluation infrastructure: golden datasets, task-specific benchmarks, human review loops, failure-mode tracking, regression tests, confidence calibration, and production monitoring. Without evaluation, the company cannot know whether it is improving.
4. Governance and trust
Enterprise AI adoption depends on trust. A product that can show evidence, permissions, audit trails, approval gates, and data boundaries is more likely to survive procurement and scale inside regulated, high-stakes environments. This matters especially because Gartner has warned that agentic AI projects without clear value and risk controls face cancellation risk. Governance is not only a compliance feature — it can be a moat.
5. Distribution advantage
Some AI products are technically good but commercially weak. A company may have a moat if it has privileged access to a buyer segment, embedded partnerships, domain credibility, community, channel advantage, or a wedge into an existing workflow. AI does not eliminate go-to-market difficulty; in crowded categories, distribution may be the difference between survival and irrelevance.
6. Economic advantage
AI products have cost structures that differ from traditional SaaS. Inference, model routing, hosting, data processing, human review, and customer-specific customization all affect margins. Diligence should examine gross margin under real usage, cost per workflow, model-cost sensitivity, scaling economics, the ability to use smaller or specialized models, and pricing power relative to value delivered. A product can be loved by users but economically fragile if every workflow is expensive to run.
The AI diligence scorecard
A practical process examines eight areas:
- Problem quality — is the problem painful, frequent, expensive, and urgent?
- Workflow depth — is the product embedded in a real workflow or sitting on the edge as a productivity tool?
- AI necessity — does AI create a step-function improvement, or a marginal enhancement?
- Data advantage — does usage create proprietary learning or merely process generic inputs?
- Technical architecture — is the system robust, modular, observable, secure, and adaptable to model changes?
- Evaluation discipline — can the company measure quality, reliability, and failure modes?
- Governance readiness — can the product support permissions, evidence, auditability, approvals, and compliance?
- Business-model durability — can the company scale revenue faster than costs while maintaining differentiation?
This scorecard helps separate hype from substance.
Questions investors should ask founders
What happens if a major model provider improves this capability tomorrow? What proprietary data do you generate? How do you evaluate output quality? What are your top failure modes? Where does human review enter the workflow? How do gross margins behave at 10x usage? What customer system do you become part of? Why will customers not switch to a cheaper model-native feature? What do you know after 12 months of usage that competitors will not? Strong founders welcome these questions. Weak companies retreat into demo language.
Questions corporates should ask before acquisition or partnership
Can the product meet our security requirements and run in our environment? Who owns customer data? Are model providers contractually acceptable? Can outputs be audited? Is there IP beyond prompts and glue code? What liabilities arise from wrong outputs? Can the team support enterprise-grade deployment? An AI acquisition can look attractive strategically but become expensive if the product cannot survive integration.
The Meta3Ventures view
We evaluate AI startups through a builder's lens, not only an investor's. The key question is not "is this company exciting?" but "can this become a durable AI-native company with workflow ownership, data advantage, governance, distribution, and scalable economics?" That is the difference between a promising demo and a venture-scale opportunity.
The AI market will produce many impressive products. Some will become features, some tools, some services, and some will disappear. A smaller number will become companies. Due diligence exists to tell the difference. Real AI moats are built from workflow depth, proprietary learning, trust, distribution, and economics — not from hype, not from model access alone, and not from a beautiful demo.
Related reading: Where AI creates defensible advantage · Why data loops are the new distribution moat
In the ecosystem: GenovateAI — the AI Due-Diligence Memo
---
*We evaluate AI companies through this lens. Read the thesis or reach out.*