top of page

Defensible AI: What Questions Should an LP Ask a Fund Manager?

Sep 18
10 min read

An AI venture capital fund presents three startups. All have strong teams, interested customers and convincing demos. They use models their competitors can also access and solve similar problems. One could become a significant business. The investor’s challenge is to understand what makes it possible to recognise that company today.

This is where the discussion about Defensible AI becomes useful for an LP, or limited partner investing in a fund. The question cannot stop at “Do your portfolio companies have a moat?” It needs to reach the manager’s decision process: which advantages they identify, how they test them and what they pay to take the risk.

AI businesses whose products initially have little defensibility will also win. They may do so through distribution, execution, timing or the ability to turn early adoption into a more durable advantage. Others may build profitable businesses while continuing to operate in highly competitive markets.

Weak structural protection therefore does not rule out commercial success or a good outcome for investors who enter on the right terms. It can make the outcome more dependent on execution and on the timing of entry and exit.

Greater exposure to clones, however, makes selection at pre-seed more uncertain. Knowing that a category will produce winners is different from having sound reasons to back that particular team, at that price, with that share of the fund.

The following questions help make this distinction testable.

1. When you say “defensible”, which advantage exists today and which are you still financing?

Defensibility is the ability to protect an economically attractive position over time. It is not synonymous with complex code, a patent or a proprietary model. A product can be technically sophisticated and commercially replaceable; a service built on third-party models can become difficult to displace.

Investors should look for barriers in the characteristics of the industry, observing that software complexity offers a different kind of protection than it once did. This is useful for an LP: “AI” describes the technology, but does not explain who will retain the economic value.

An LP should ask the manager to separate three things: the advantage observable today, the advantage that could accumulate through use, and the conditions required for that to happen.

For example, a relationship with an initial customer provides commercial access. It becomes something more if it enables verified outcomes, product improvements and subsequent customer acquisition with less work. That sequence needs evidence: none of the steps is automatic.

Ask: “For a recent investment, show me which part of the thesis was already demonstrated when you wrote the first cheque, and which milestone should validate the rest.”

At pre-seed, it is unreasonable to demand the evidence of a mature company. It is reasonable to expect a manager to distinguish a future possibility from a barrier already built.

2. If a copyable product can win, why did you choose this particular team?

It is undoubt that today very quickly an extraordinary demo can become ordinary. Deeter sees the same acceleration as an opportunity for teams that iterate better and faster. Both perspectives can hold: competition erodes the existing advantage while creating opportunities to build a new one.

For an LP, however, “We back the best founders” is an incomplete answer. Which signals distinguished those founders from the alternatives before the outcome became obvious?

Useful signals may include the ability to identify an error the customer considers decisive, gain access to a process that is difficult to observe from the outside, or change a technical decision after encountering contrary evidence. The number of features shipped tells us much less if it does not improve usage, quality or the cost of delivering the service.

Ask: “Which alternatives did you evaluate at the same time, why did you prefer this company, and what evidence would have led you to choose another?”

This comparison reduces the risk of reconstructing the manager’s skill with hindsight. It does not eliminate uncertainty; it can make that uncertainty more transparent.

Waiting also has a cost. A manager who invests after stronger evidence emerges may reduce some risks while paying a higher valuation. An LP should understand how the fund trades uncertainty against price, without assuming that entering earlier or later is always better.

3. How long does it take to copy the product, and how long to replace it at the customer?

To assess a fund, I suggest distinguishing three timelines: replicating a demonstration; matching the service under real operating conditions; and persuading the customer to replace the supplier.

A competitor can recreate an interface without matching its reliability on difficult cases. Or it can match the product but still need access to distribution channels. The reverse can also happen: a feature that is difficult to copy can lose value if a less sophisticated alternative satisfies the customer on better terms.

Ask: “Who can neutralise the advantage: another startup, the model provider, an existing supplier to the customer, or the customer itself? With what product, channel and economic incentive?”

The comparison needs a concrete competitor. A clone without distribution and an incumbent bundling a feature into an existing contract do not exert the same pressure.

Also distinguish retaining existing customers from winning new ones. A product can be expensive to replace for those already using it, yet uncompetitive for the next buyer. Strong retention in the installed base does not automatically solve the growth problem.

4. What does each customer help accumulate, and who actually owns it?

“We have proprietary data” should open the discussion. It is necessary to understand which data, which rights of use and which effect on the product.

Martin Casado and Peter Lauten questioned the automatic connection between accumulating data and network effects back in 2019: the value of additional data can diminish while collecting new examples becomes more expensive. Their analysis predates the current generative AI cycle. It is useful for testing a mechanism; it does not demonstrate that data advantages are impossible. a16z, The Empty Promise of Data Moats.

An LP should ask the manager to reconstruct the whole chain: a customer decision produces information; the startup has the right to use it; that information changes the system; and the change improves an outcome someone pays for. Storing conversations or consulting an archive does not, by itself, demonstrate that this improvement cycle exists.

If the data remains confined to an individual customer, it can create personalisation and switching costs. It does not, on its own, prove that the product improves for other customers. If the customer can supply the same archive to a competitor, exclusivity must be found elsewhere: in the quality of the information captured, the outcomes observed or the ability to turn them into improvements.

Ask: “Which outcome do these data allow you to achieve that you could not achieve with available alternatives? And which part of that advantage remains if the customer changes supplier?”

Cost requires a further check. If every new implementation takes weeks of bespoke work, integration may make customers loyal without making the business more scalable. The manager should show which work is reused and which starts again from zero.

5. Does the next improvement in models increase the portfolio company’s value or transfer it elsewhere?

A better model can reduce costs and open new possibilities. It can also eliminate the technical difficulty around which a product was built. Both can happen at the same time.

In their 2023 reassessment of the generative AI thesis, Sonya Huang and Pat Grady noted that future models could erode some applications’ data advantages. The enduring point is methodological: an AI thesis must incorporate progress in the underlying technology, rather than assume its current state will persist. Sequoia, Generative AI’s Act Two.

Ask: “What happens to the competitive advantage if models improve dramatically? And if they improve more slowly than expected?”

In the first scenario, examine what continues to justify a specialist supplier. In the second, examine whether the company can still bear its computing, review and support costs without the technological improvement assumed in its plan.

I suggest two separate tests. The first replaces the model used by the startup to assess its dependence on a provider. The second compares the complete product with a simpler solution built on the best available model and the same data the customer can legitimately supply.

The first test concerns the replaceability of infrastructure. The second concerns the need for the product. Passing the first does not automatically mean passing the second.

6. What have you tested beyond the demo?

An LP does not need to become a research laboratory. It can, however, check that the manager knows how to request appropriate tests and involve independent expertise when needed.

Anthropic’s guide to agent evaluations distinguishes what a system claims to have done from the outcome actually achieved. It also emphasises repeatable tests for identifying regressions and assessing the adoption of new models. This is a methodological foundation, not a certification of commercial defensibility. Anthropic, Demystifying evals for AI agents.

Ask: “Who selected the test cases? Do they represent the work the customer pays for? Which errors remain, and what do they cost?”

An average can hide the economic problem. Ten errors that require little work to fix may matter less than a rare error that blocks the entire process. The need for supervision also changes the outcome: a correct output after extensive human correction is not equivalent to the same output delivered autonomously.

The test should distinguish the contributions of the model, specific data, software and human work. If the technical advantage disappears, the investment may still have a valid commercial thesis. The manager must describe that thesis accurately.

7. Has retention already faced a credible alternative?

Ask: “Which customers renewed after they had the opportunity to try a competitor that was better, cheaper or included in another contract?”

At pre-seed, this evidence often does not yet exist. The absence of a competitive shock is not a rejection criterion, but it prevents the product’s resilience from being described as proven.

For more mature portfolio companies, an LP can ask how the manager separates renewals, actual usage, discounts and revenue concentration. Expansion at one large customer can offset many losses in the accounts without demonstrating that the advantage is broadly distributed.

It is also useful to look for customers using multiple suppliers in parallel. A customer may keep a subscription while gradually moving important activities elsewhere. The contract remains; the product’s centrality declines.

8. Who retains the economic benefit of AI?

A product can create substantial value and retain little of it. Savings may accrue to customers through lower prices, to model providers or to acquisition channels.

Sarah Tavel developed the thesis of selling work outcomes and clarified that human involvement in delivery does not invalidate it. This makes it essential to measure the human work that remains and who bears its cost. Sarah Tavel, update on the “Sell Work, Not Software” thesis.

Ask: “Why should margins improve? Which part depends on the company’s decisions, and which on suppliers, competition or customer behaviour?”

The relevant cost covers complete delivery: models, failed attempts, supervision, checks, support and implementation. Also separate costs borne by the startup from those left with the customer, which affect willingness to pay.

A purely illustrative example: €100 of revenue with €40 in delivery costs leaves €60. If the cost falls to €20 but the competitive price falls to €60, the percentage margin rises from 60% to 66.7%, while the euro margin per unit of service falls to €40. Falling technical costs alone do not determine the outcome for shareholders.

Nor is the entire human labour budget available to capture. Automating one stage does not mean eliminating the cost of an employee, and a customer may prefer to use the time released to produce more. The manager must identify the benefit being purchased and the budget that actually funds adoption.

9. What does it cost to build the defence, and what return remains for the fund?

A barrier can be real and still require too much capital, too much time or too small a market for the fund’s strategy. Certifications, facilities, integrations and exclusive channels can protect a business; they can also lengthen the path to cash distributions to investors.

Ask: “If the business thesis works, how much ownership do you expect to retain, and how much can the exit contribute to the fund?”

A hypothetical example: a €50 million fund invests €500,000 at a €10 million post-money valuation, acquiring 5%. After subsequent rounds, it retains 2%. A sale with €500 million available for pro-rata distribution to shareholders produces €10 million for the fund: 20 times the initial cheque, but only 0.2 times the size of the fund.

This calculation simplifies share rights, costs, taxes, management fees and carried interest; it does not represent a net return for the LP. Its purpose is to show why an excellent company outcome must be connected to portfolio mathematics.

The same applies to timing. A greater-than-expected capital requirement can reduce final ownership precisely as it strengthens the company. An LP should see dilution scenarios and liquidity timelines alongside the defensibility thesis.

10. If selection is difficult, how is the fund built to accommodate mistakes?

Investing in easily replicated applications can be a deliberate choice. It requires a coherent explanation of selection, number of positions, price and available capital.

Ask: “How much of the fund depends on identifying the winner before visible barriers emerge? And how does portfolio construction change to reflect that exposure?”

Counting companies or sectors is not enough. Ten portfolio companies in different markets may be vulnerable to the same change: a platform incorporating their function, the loss of a distribution channel or service economics that fail to improve.

The manager should distinguish company-specific risks from shared risks, identifying how much capital and portfolio value is exposed to each. Diversification by company name does not ensure economic diversification.

Follow-on policy matters too. A fund with reserves can wait for new signals before increasing exposure, but must explain why those signals justify the new price. A fund without follow-ons can have a coherent strategy, provided its initial selection and expected dilution support it. It cannot base its answer on later concentrating capital it has not allocated.

11. What evidence made you change your mind?

Due diligence becomes particularly informative when a manager shows cases that challenged its method.

Ask: “Show me a company you backed whose advantage weakened, one you rejected that succeeded, and how you changed your process after those experiences.”

The objective is not to demand perfect forecasts. It is to examine the discipline with which the manager separates what it knew, what it hypothesised and what it learned.

A memo written at the time of the decision, recording alternatives considered and reasons to change one’s mind, is worth more than an explanation reconstructed after a new round. A positive valuation markup must also remain distinct from evidence about the product and realised liquidity.

Public benchmarks require the same care. Bessemer’s 2025 report studies twenty AI companies selected for growth and quality: it is useful for understanding possible trajectories, but does not provide the success rate of a population of pre-seed startups. Bessemer, The State of AI 2025.

A young fund may lack a long track record. An LP can still examine the consistency of its memos, the quality of its checks and its ability to update decisions, without treating this evidence of process as proof of future returns.

What to take away from the meeting with the manager

By the end of the conversation, an LP should be able to reconstruct four steps: why the customer chooses the product; what makes it harder to replace; why the manager could recognise that trajectory; and how the fund participates economically.

A startup without established barriers can successfully navigate this path. One with exclusive technology may fail to complete it for commercial or financial reasons. The word “defensible” is useful only if it makes assumptions, tests and capital decisions more precise.

The final question for the manager is: “What needs to become true for this advantage to turn into a return for the fund, and how will you recognise in time if it is not happening?”

To discuss the evaluation of AI venture capital funds, contact Vitantonio Santoro on LinkedIn or email vitantonio.santoro@atlassgr.com.

Comments


bottom of page