Thought leadershipAnnual outlook2026

The model is not the moat.

Access to a frontier model stopped being a differentiator the moment every serious competitor had the same access. What separates companies in 2026 is the layer above it — the context, the workflows and the governance that turn a general-purpose model into something that does your work.

11 min read

The model layer commoditized.

Model capability keeps climbing, and each release feels less dramatic than the last. Both of those things are true at once, and together they are the definition of commoditization: the thing keeps improving, it just stops being the thing you win with.

The competitive question has moved accordingly. It is no longer which model you have access to — your competitor has the same one, at the same price, this afternoon. It is how well that model is wired into the way your business actually runs, what it costs you per unit of useful output, and whether anyone can be held accountable for what it does.

What that asks of you

  1. Integrate and optimize

    Put models inside existing business processes rather than beside them, and tune the data pipelines that feed them. Most of the cost and most of the disappointment live here.

  2. Build internal expertise

    Develop the in-house ability to customize, evaluate and fine-tune for your own work. Outsourcing this entirely means outsourcing the part that differentiates.

  3. Govern deliberately

    Establish the ethical framework and the governance policy before scale forces the question. Retrofitting governance onto a deployed system is the expensive order to do it in.

  4. Reskill the workforce

    Train for human-AI collaboration specifically — delegation, verification, knowing when not to use it. Fluency is an organizational property, not an individual one.

So whatIf your AI strategy is a procurement decision about which model to standardize on, you are competing on the one dimension where you have no advantage. Everything that differentiates sits above the model.

The moat moved to the context layer.

As models commoditize, advantage shifts to the context layer — the structured knowledge, the business ontology, the workflow awareness and the role-specific understanding that turn a general-purpose model into business-specific intelligence.

The same model produces dramatically different results depending on how deeply it understands how work actually flows through your organization, who holds which decision rights, and what actually matters when the two conflict. That understanding is not something a vendor can ship you.

Both start here

The same frontier model

Available to you, to your competitor, and to the company that has not started yet — at the same price, this afternoon.

Given a prompt

  • A well-written question
  • Whatever the model learned from the public internet
  • No idea who is asking or why

What comes backA confident, general answer that sounds right and cannot be acted on without someone senior checking it first.

Given your business

  • Your ontology — entities, workflows, roles
  • Your authoritative knowledge, with permissions
  • Your decision rights and your exceptions
  • The role of the person asking

What comes backAn answer in your own terms, against your own rules, that the person who asked can act on without escalating it.

No quantities and nothing measured — the claim is structural. The model is the constant in this diagram. The context is the variable, and it is the one you own.

What a context layer is made of

  1. Business ontology

    Define the entities, workflows, roles and decision rights systematically, in the terms your business already uses, rather than leaving the model to infer them.

  2. Authoritative knowledge

    Centralize and curate what the system is allowed to read and act on. Name one system of record per domain and mean it.

  3. Role-specific experiences

    Design interactions around what a particular function actually does, not a generic chat box that leaves every user to reinvent the prompt.

  4. Standardized patterns

    Build agent patterns tied to real accountability structures, so the same work happens the same way regardless of who triggered it.

So whatThis is unglamorous work and it is the work that decides the outcome. Organizations that get the right information to a model at the right moment will outperform organizations with better models and worse data — consistently, and by more than the model gap.

From advice to action.

Agents are moving out of advisory roles and into operational execution — triggering workflows, completing defined steps, taking action inside guardrails rather than recommending that someone else does.

The pattern that is actually working is managed autonomy: humans delegate specific, bounded tasks; agents execute them precisely; humans keep approval authority over anything consequential. It is the fastest route to measurable value and the safest one, which is a rare combination and worth taking seriously.

  1. 2024

    Analysis

    AI produces recommendations and insight. Every action is still taken by a person.

  2. 2025

    Assisted execution

    AI performs routine tasks under heavy human oversight, one step at a time.

  3. 2026

    Managed autonomy

    Agents carry defined workflows through multiple steps. Humans delegate and approve.

    Where most organizations are now.

  4. 2027+

    Expanding scope

    Agent capability widens as governance frameworks mature enough to hold it.

A sequence, not a menu. Each stage depends on the controls built in the one before it — an organization that has never run an agent under supervision has no basis for letting one transact.

Implementation framework

  1. Start with real workflows

    Pick one or two high-volume processes where an agent can execute work rather than analyze it — service triage, invoice processing, data reconciliation.

  2. Define action boundaries

    State explicitly where the system may act and where it may only advise, particularly anywhere customer-facing, financial or policy-sensitive.

  3. Assign human ownership

    Every agent has a named human owner accountable for its performance, its risk and its outcomes. No exceptions, including for the ones that work well.

  4. Ensure complete visibility

    Every action logged, reviewable and reversible. Auditability is not a phase-two feature; a system you cannot reconstruct is one you cannot defend.

  5. Redesign roles around judgment

    Move human work from executing tasks to handling exceptions, overseeing quality and making the decisions that carry consequences.

So whatThe organizations getting value from agents are not the ones that gave them the most freedom. They are the ones that defined the narrowest useful lane and then widened it on evidence.

Software gets built, not bought.

AI-assisted development by people who are not engineers has moved out of prototypes and into production systems, in legal, HR, marketing and operations. A business function can now build the tool it needs instead of waiting two quarters for engineering capacity.

That is a real unlock and a real exposure. The same velocity that produces a useful internal tool in an afternoon produces undocumented, unreviewed, data-exposed systems at the same rate — and at a scale that makes them hard to find later.

At the same time the buy side of the equation is under pressure. Organizations increasingly build narrow internal tools rather than license broad SaaS products they use a fraction of, because building is now fast enough to be the sensible option. Expect harder questions about renewals when the alternative can be built in days.

The build-versus-buy line

Build

Internal-facing, low-risk, and using less than about a third of what the product does — build it.

Buy

Customer-facing, regulated or mission-critical — buy it, and govern it through normal procurement.

The four guardrails this needs

  1. An approved tools list

    A curated catalog of sanctioned platforms and frameworks, so "which tool did you use" is never an investigation.

  2. Data handling rules

    Explicit protocols for what data may be used in AI-generated code, written before someone needs them.

  3. A security review path

    Lightweight but mandatory checkpoints before anything reaches production. Lightweight is what makes it mandatory in practice.

  4. Reusable components

    Shared connectors, templates and patterns, so the tenth tool is faster and safer than the first rather than merely newer.

And the loop it runs in

  1. Encourage micro-tools in a governed sandbox

    Internal-only, limited data access, clear ownership from day one.

  2. Track usage and measure outcomes

    Adoption, efficiency gained, user satisfaction. Measured, not assumed.

  3. Standardize what works

    Promote the successful patterns and retire the experiments that did not earn their keep.

So whatBanning this does not stop it; it moves it somewhere you cannot see. A governed sandbox with a short path to production is the only version of this policy that survives contact with a motivated operations team.

What this asks of a chief executive.

AI is becoming an operating layer rather than a set of tools — something that shapes how work flows, how decisions get made and how coordination happens. Bolting it onto legacy workflows returns less every quarter. Redesigning work with AI assumed to be always on is where the outsized gains are.

  1. Redesign the work, not the tooling

    Take five to seven mission-critical processes and rebuild them with AI embedded from the start. Then remove the handoffs and approval layers that slow the result back down.

    ActName the processes this quarter. A list of candidate use cases is not a redesign.

  2. Treat decision velocity as the constraint

    AI now delivers insight faster than most organizations can act on it. The bottleneck moves from analysis to approvals and hesitation, and a slow decision structure becomes a measurable liability once cycles compress from weeks to hours.

    ActFlatten approval layers, clarify decision rights, and move from annual to rolling planning.

  3. Own governance at the executive level

    AI increasingly influences pricing, hiring, customer experience and operational risk — often invisibly. Boards, regulators and customers all expect a named accountable executive. The absence of governance produces either paralysis or unmanaged exposure.

    ActAssign executive ownership and review AI impact at board level quarterly.

  4. Shift security from prevention to resilience

    AI lowers the barrier to sophisticated attacks and raises the speed at which failures propagate. Assume a breach will happen and optimize for detection, response and reversibility.

    ActProtect the proprietary data used in AI systems and train teams on AI-enabled threat scenarios.

The advantage compounds, which is why the clock matters.

The last point is the one that decides the others. AI advantage compounds: an organization that starts learning earlier improves faster, and reinvests those gains sooner, which widens the gap rather than closing it.

What late adopters miss is not a feature set — features can be bought. What they miss is the organizational learning curve, and that is the part with no shortcut. Speed of learning matters more than the sophistication of where you start.

The question is not whether to move. It is how fast, and on which two things first.