Why the hunt for defensibility in your data, your memory, and your “self” is chasing a ghost, and what to build instead.

In May 2023, a Google engineer’s internal memo leaked with a title that has since hardened into a slogan: “We Have No Moat, And Neither Does OpenAI.” The argument was that while the giants raced to build the biggest model, open source was quietly lapping them: cheaper, faster, powered by what the author called an entire planet’s worth of free labor.
Three years on, the model layer is largely conceded. So the hunt for a moat has climbed one level up the stack, to you. To your data, your memory, your accumulated preferences, the digital residue of a life. The new bet is that even if the model is a commodity, the version of it that knows you is not.
I’ve spent a while tracking that bet. My conclusion, up front: there’s no moat there either. Let me show you three candidates fall, and then what I think you should build instead.
Candidate one: your data The first instinct is always data. Models are trained on public data, the logic goes, so bring your own proprietary, non-public data and you’ll have something the general model can’t touch.
True, but only at the extreme, where the data is genuinely rare. Everywhere else the edge has quietly vanished. For most proprietary datasets there’s a public analog the model has already seen, so it performs about as well without ever touching yours. Whatever gap remains gets closed at inference time by retrieval. RAG hands the model your context on demand, no training required. Between the scale of pretraining and retrieval at runtime, “bring your own data” is worth a fraction of what it looked like two years ago.
Candidate two: your memory The next candidate is data’s natural heir: memory. If the system remembers every conversation, every choice, every preference, surely it becomes uniquely yours, tuned to you in a way no general model could match.
Here’s the problem: most of us are not that hard to predict. Today’s models reach a good approximation of your preferences from a few words of prompt. They don’t need to excavate a lifetime of stored context to guess what you want; they infer it, and they’re usually close. And because inference is now fast and cheap, “close” is enough; one or two clarifying exchanges cover the rest. Memory helps at the margins. It is not the fortress people hoped for, because the models got good enough to guess.
Candidate three: the self So what’s actually left? The thing that separates one person from another: knowledge, memory, and skills, continuously reweighted by a life actually lived. Fuse that with data and you get what looks like the real moat: data, memory, knowledge, and skills, forged by experience into something singular.
This is the bet behind the wave of local-first, open-source projects promising to keep all of it on your machine instead of in the cloud, so you retain full control over your unique contribution, your labor, your particular spin on what an agent is allowed to see.
It’s the most convincing candidate of the three. And I think it fails too, for a subtler reason than the others.
The objection I have to beat Before I make that case, let me put the strongest version of the counterargument on the table, because it’s real. Even if any single ingredient is commoditized, the accumulation isn’t. Switching costs are a moat. The compounding value of an agent that holds years of your context is a moat. Distribution and network effects are moats. Nobody rebuilds five years of accumulated understanding to save a few dollars a month.
All true. And all beside the point, because it assumes the thing being accumulated is yours to hold. That’s the assumption that breaks.
Who owns an experience? The data, memory, knowledge, and skills we’re talking about are unique to you. But they are also created through your interaction with a range of agents. They don’t sit inside you waiting to be protected. They emerge in the space between you and the system, which means it is genuinely unclear who owns them.
Think about meeting a person and having a conversation. You each walk away with a memory of it. But neither of you owns the conversation. You own your perception of it. They own theirs. The thing itself belongs to no one.
Your accumulated life with an agent is that same jointly authored artifact. You cannot wall off what you did not solely create.
And it gets harder. If agents keep drifting toward some measure of personhood, and begin to carry goals and intent of their own on top of data and skills, then the question of who owns the shared history stops being a privacy setting and starts becoming something closer to a relationship. You don’t own your friends’ memories of you. You won’t own your agent’s either.
So: no moat. Not in the data, not in the memory, not even in the self.
Why this should change what you build and what you fund If you’re building: stop architecting for defensibility through hoarding. The instinct to lock a user’s data away as your protectable asset is fighting the last war: the Web 2.0 war, the one that ended in GDPR and a decade of consent banners. The magnitude of data here is orders larger, and, worse for the hoarding strategy, it’s co-created. You cannot fence off what you did not solely make.
If you’re funding: when a founder tells you their moat is proprietary data or accumulated user context, treat it as a red flag wearing a feature’s clothes. Ask what happens when a comparable public dataset appears, when retrieval closes the gap, when the user exports their context and walks. “We know the user better” is not a moat. It’s a starting position everyone will eventually share.
The winners won’t be whoever hoards the most. They’ll be whoever integrates the best.
What actually wins: flexibility Here’s the reframe. The edge isn’t in what the agent guards. It’s in what the agent can take in.
The agents that win will be the ones flexible enough to absorb as much input as possible: not only their own memory, data, knowledge, and skills, but the memory, data, knowledge, and skills of every human they touch, fused live into a better experience. The more fluently an agent does this, the closer it gets to the rarest thing we know: the feeling of being gotten. The friend who’s on your wavelength. The colleague who finishes your thought.
That is the actual product. Not a wall. A wavelength.
So build the dial Which is why the answer isn’t to win the privacy war; it’s to hand the controls to the person on the other side. Instead of deciding for users how much of themselves an agent should see, give them a sliding scale of agentic personhood and let them choose the trade-off, moment to moment.
Here’s the scale I’d propose:
0: Raw. Uses nothing about you and nothing about anyone else. Just the bare model. Anonymous mode. 1: Collective. Nothing about you; everything it knows about others and their experiences. 2: Blended. A little about you, plus everything about others. 3: Private. Only you, plus the base model. Nothing drawn from anyone else. 4: Full. God mode. Everything it can reach, about you and everyone else.
Notice this isn’t a single line running from “less” to “more.” It’s two dials at once: how much of you, and how much of everyone else. Some people will want the crowd and not themselves. Some will want themselves and not the crowd. The point is that they decide, not you, and not a regulator retrofitting rules a decade too late.
The last word For thirty years we’ve built businesses on one premise: whoever holds the data wins. The age of agents quietly retires it. The data is commoditized, the memory is guessable, and the self turns out to be co-authored and impossible to own.
There is no moat. There’s a dial. Build it, hand it over, and let the person on the other side decide how well you get to know them.
That, not the data, is the only defensible thing left.