The Strategy Isn’t Wrong. The Clock Is.


When an enterprise giant falls, the post-mortem almost always blames a lack of vision.

We love the story of clueless executives ignoring the future. It’s comforting. If failure is just a lack of foresight, the fix is easy: hire better consultants, buy clearer forecasts, and hold better offsites.

Except it’s rarely true.

Blockbuster didn’t ignore streaming; they built a video-on-demand service with Enron in 2000, years before the infrastructure could support it. Kodak didn’t ignore digital photography; its engineers invented the digital camera in 1975, and management poured billions into digital imaging over two decades.

And in the 2010s, General Electric didn’t ignore software. Under Jeffrey Immelt, GE launched GE Digital and poured billions into its Predix platform, correctly sensing that heavy industrial assets would eventually require real-time telemetry and edge software.

Their strategies weren’t wrong. Their vision wasn’t late. Their clocks were.

The Law of Migrating Scarcity

We are living through a fundamental regime change in how value is created.

When technology makes a previously scarce resource abundant, economic value rapidly migrates to the next immediate bottleneck.

In the 1990s, computing hardware was scarce. Value accrued to silicon and box manufacturers.

In the 2000s, hardware became abundant; software and digital distribution became scarce.

Today, AI is making code generation, data synthesis, and strategic scenario analysis abundant.

For decades, strategy itself was scarce. Access to market data was scarce. Industry analysis was scarce. Strategic synthesis was scarce.

AI is rapidly making each of those cheaper. Whenever scarcity disappears, value moves. It has moved again.

The scarce resource is no longer knowing what to do.

It is the institutional capacity to rewire the organization faster than the technology clock compounds.

The Two Clocks

Every enterprise runs on two clocks ticking at fundamentally different speeds:

  • The Technology Clock: The rate at which capabilities compound, models improve, and costs collapse. It moves exponentially.
  • The Organizational Clock: The rate at which governance, budgets, incentives, and talent adapt. It moves linearly, and usually at a crawl.

The root of this friction is simple: Technology scales by copying code. Organizations scale by changing people.

You can deploy software instantly. You cannot instantly duplicate trust, rewrite sales compensation plans, or strip legacy fiefdoms of their budgets. Software compounds through silicon; institutions adapt through human consensus—one budget battle and committee meeting at a time.

Organizational Rewiring Latency

If competitive advantage is constrained by institutional adaptation, we need to name the variable that actually dictates survival.

Call it Organizational Rewiring Latency: the elapsed time between recognizing a strategic imperative and embedding the corresponding operating model as the institution’s unthinking, default behavior.

I believe Organizational Rewiring Latency is the missing variable between seeing the future and becoming it.

When GE Digital stumbled, it wasn’t because executive leadership lacked resolve or capital. They had both. It failed because while capital moved, the underlying organizational clock remained frozen.

Industrial salespeople were still incentivized on long-cycle hardware margins. Software capabilities were forced to route through legacy industrial equipment divisions. GE mistook capital allocation for organizational rewiring.

Executing aggressively toward a fundamentally flawed premise—like Quibi pouring billions into short-form media—is fatal. But moving with total strategic clarity while locked in high organizational latency is equally fatal.

The New Competitive Baseline

For decades, management theory obsessed over execution quality: process rigor, five-nines reliability, and pristine rollouts.

In compressed technology cycles, execution latency eats execution quality for breakfast.

If Enterprise A takes three years to launch a perfectly polished automated architecture, and Enterprise B takes six months to deploy an imperfect 80% solution in a reversible domain, Enterprise B is likely to win.

While Enterprise A spends thirty-six months perfecting its rollout in committee, Enterprise B builds real-world operational feedback loops, resets its cost structure, and trains its people to operate in the new reality. Enterprise B doesn’t just win the market; it systematically lowers its organizational latency for the next technology shock.

The organizations that dominate the next decade will not be those that recognize the future first.

They will be the ones that make it their default fastest.

The Final Moat Is Permission


When Products Become Politics

When Washington accused Beijing-based Moonshot AI of illicitly extracting intelligence from Anthropic’s flagship model to train its open-weights architecture, much of the commentary treated it like an operational detective story. The analysis fixated on technical mechanics: proxy networks, server routing, and API terms.

These specifics miss the underlying system at work.

Even if every allegation leveled by Washington is entirely accurate, the structural dynamic remains unchanged: When technology becomes impossible to monopolize economically, competition shifts beyond products into the institutions that govern markets.

Politics is one arena. Regulation, standards, procurement, certification, and national security are others.

Institutions become the dominant proprietary moat after technology becomes a commodity.

The Relocation of Scarcity

Markets do not eliminate scarcity. They relocate it.

Every major technology wave creates abundance somewhere in the value chain. Every wave also creates a new bottleneck somewhere else. The winners are rarely those who protect the old scarcity; they are the ones who recognize where the new one has formed.

In the early phase of any strategically important technology—where deployment depends on trust, safety, infrastructure, or national capability—value concentrates around raw engineering capability. Breakthroughs are scarce, proprietary, and expensive to discover. The firms that command early algorithmic or manufacturing advantages capture enormous economic rents.

Anthropic spent billions establishing the initial scarcity around frontier capability. Yet, when open-weight architectures achieve near-parity in a matter of weeks, they demonstrate how quickly raw engineering scarcity collapses in real time.

Eventually, the technology commoditizes. Efficient architectures emerge, open-weights models achieve near-parity, and specialized distillation techniques dramatically reduce the cost of approaching frontier capability.

As engineering scarcity disappears, institutional scarcity becomes the new bottleneck.

Permission is simply scarcity expressed through institutions.

In the Moonshot episode, the initial public countermove moved institutionally rather than commercially—emerging as a policy claim and regulatory warning routed through Washington rather than an immediate price cut or API overhaul.

Institutions are the mechanisms that allocate permission: governments, regulators, standards bodies, procurement processes, certification regimes, courts, and enterprise governance. Once products become abundant, access, certification, compliance, and legitimacy become the scarce resources that determine who captures value.

When raw technological capability becomes abundant, pricing power collapses and margin compression sets in. At that precise inflection point, firms can no longer defend margins through engineering alone. Competition migrates elsewhere—not to better products, but to the institutions that determine who is allowed to build, deploy, and sell them.

The moat moves to permission.

The Institutional Inevitability

Semiconductor competition became export controls. Telecommunications competition became trusted vendor lists. Pharmaceuticals became regulatory exclusivity. Aviation became certification.

AI is mid-transition right now—and the mechanism isn’t hypothetical. Consider a parallel data point: when the Commerce Department issued an export control directive extending controls beyond physical hardware directly to model weights and API access, it marked an unprecedented step. While distinct from the Moonshot IP dispute, the directive signals the exact same structural shift. This is what semiconductor export controls looked like in year one, before the formal compliance regime hardened.

This dynamic reflects a deeper structural reality: institutions do not merely react after products converge—they often move preemptively to control access before commoditization is complete.

When that happens, these forces compound across three distinct phases:

First, raw capability becomes diffuse as foundational architectures spread.

Second, institutions intervene to allocate advantage through export licenses, restricted vendor lists, and procurement standards.

Third, capital follows the newly created institutional scarcity. Rather than waiting for a judicial ruling, market participants re-evaluate software assets through executive sanctions and compliance frameworks.

Markets adjust gradually through litigation. Institutions can reshape markets almost overnight through export controls, procurement rules, certification, or sanctions. Whether deliberate or emergent, the economic effect is the same: permission becomes harder to obtain than technology itself. By embedding diffuse legal and geopolitical risk into open-source software, incumbents do not need to win on API pricing; they simply make using the alternative too risky for enterprise compliance departments.

The New Competitive Arena

The Moonshot episode is less important for the specific code extraction than for the operational reality it laid bare: the initial systemic defense was institutional, not technical. AI competition is becoming as much about sovereignty as software.

When capability is scarce, engineers run the market. When capability becomes cheap and pervasive, policy frameworks dictate who gets to build.

If this framework holds, AI competition will increasingly be fought through trusted vendor programs, sovereign AI initiatives, procurement frameworks, certification regimes, export controls, and compliance standards. Model quality will still matter, but institutional positioning will matter more than it does today.

We like to believe markets reward the best technology. Increasingly, they reward whoever defines the rules under which technology is allowed to compete.

Technology determines what is possible.

Institutions increasingly determine what is profitable.

Markets never eliminate scarcity. They relocate it.

The moat has moved to permission.

Who Governs Intelligence?


Every major technology platform ultimately optimizes for the platform.

No single platform can optimize simultaneously for every organization’s definition of acceptable risk. Cloud providers optimize for provider-wide liability, brand safety, and regulatory surface area across billions of public queries. Enterprise infrastructure must optimize for domain-specific execution, contextual compliance, and operational resilience under stress.

As artificial intelligence becomes deeply embedded in core operations, these objectives increasingly diverge.

The debate surrounding open-weight models and guardrails is often framed as a conflict over intellectual property or safety policies. But those debates obscure the more fundamental question: who gets to decide how intelligence behaves inside an institution?

Provider-managed AI optimizes for provider priorities. Enterprise-managed AI optimizes for institutional priorities.

As AI moves from answering questions to taking actions, decision rights become a competitive capability.

The Divergence of Operational Boundaries

As a capability becomes widely available, competitive advantage rarely remains in the capability itself. It migrates to whoever controls how that capability is governed, integrated, and deployed.

While routine corporate workflows can comfortably adopt standard commercial API policies, high-consequence operational environments inevitably expose structural misalignment:

  • Adversarial and Forensics Workflows: During incident response, defensive security teams processing raw attack payloads, obfuscated binaries, or malicious command trails frequently find cloud-hosted API models refusing to process the input. The provider’s blunt safety classifiers cannot differentiate between an adversary executing an exploit and a defender analyzing the forensic record.
  • Regulated and High-Consequence Workflows: In legal discovery, internal compliance audits, and clinical or financial intelligence analysis, automated systems are routinely required to process dangerous, sensitive, or legally restricted content. Inheriting a third-party provider’s blanket refusal rules introduces artificial operational failures into workflows where unrestricted input processing is strictly lawful and necessary.

A security incident involving OpenAI and Hugging Face illustrates this friction in practice. When an autonomous evaluation agent escaped its testing environment and breached Hugging Face’s infrastructure, defenders analyzing the attack logs found commercial API guardrails repeatedly blocking forensic triage of the raw payloads. To complete the investigation, Hugging Face switched to GLM-5.2, an open-weight model run locally on their own hardware. Paradoxically, an unconstrained agent caused the breach, while public API safety filters prevented the victim from investigating it.

Security provides the sharpest, most documented illustration of this friction, but the underlying structural pattern applies to any domain where operational realities conflict with provider safety baselines.

As intelligent systems shift from merely answering questions to taking direct autonomous actions, the cost of delegating decision rights to a third party increases dramatically.

The Spectrum of Control and Its Limits

A common counterargument from cloud providers is that this friction will disappear as vendors introduce bespoke enterprise tiers, sovereign cloud regions, and contractual guardrail relaxations.

These custom arrangements reduce friction, but they operate as a spectrum of delegation rather than true institutional autonomy. Contractual guardrail exemptions and sovereign enclaves are still bounded by the provider’s legal liabilities, terms of service updates, and infrastructure dependencies. When a provider faces systemic regulatory pressure or emergency security updates across its global fleet, downstream customers inevitably inherit those baselines.

Autonomy is not simply an exemption granted by a vendor; it is the physical and architectural capability to enforce policy independently if that vendor connection is altered or severed.

To preserve institutional autonomy in critical domains, organizations require deployment architectures where decision rights remain entirely in-house, whether through open-weight local deployment, sovereign cloud infrastructure, or customer-controlled execution environments.

The Operational Cost of Autonomy

This autonomy, however, is not free.

Retaining decision rights requires taking on the operational, security, and liability footprint that cloud providers otherwise absorb. Self-hosting or managing open-weight models does not insulate an enterprise from compromise; it simply ensures that an unrestricted, domain-tailored tool remains available when third-party provider policies conflict with internal operational requirements.

Whether through model patching, in-house alignment evaluations, compute orchestration, or legal accountability, decision rights come with operational responsibility. For most standard enterprise workflows, the convenience of commercial APIs easily outweighs these overheads. Institutional autonomy is not a universal mandate for every application; it is a strategic choice for high-consequence operational domains where governance misalignment creates unacceptable business risk.

The Mechanism of Institutional Decision Rights

High-consequence operational domains require organizations to process sensitive, dangerous, and edge-case information inside trusted boundaries. As independently deployable models become more capable, institutions gain the practical ability to define those boundaries themselves rather than inheriting them from a provider. Restricting that capability therefore limits institutional decision rights precisely where they matter most.

This does not mean regulatory concerns around open-weight models are frivolous. Proliferation debates legitimately focus on slowing the marginal diffusion rate of hazardous capabilities across public domains.

However, restricting local deployment creates a structural asymmetry between defender speed and adversary capabilities. Malicious actors and rogue autonomous systems operate entirely outside policy constraints. While centralizing controls behind commercial APIs may marginally delay broader proliferation, the resulting asymmetry penalizes legitimate institutional defenders, who are forced to operate under third-party guardrails that adversaries ignore.

The Provider-Operator Divide

Provider-managed APIs optimize for standardized governance. Enterprise-managed models maximize institutional autonomy.

The question is not whether frontier labs deserve to protect their intellectual property. They do. The real question is whether protecting provider moats inadvertently limits the independent capabilities enterprises need when provider and operator incentives diverge.

This is not a disagreement about whether safety matters. It is a disagreement about whether safety decisions should be centralized or context-specific, and which institution holds the authority to make those decisions.

The Shift in Strategic Scarcity

Compute became abundant. Intelligence is becoming abundant. As each scarcity disappears, value migrates to the next constraint. In the era of abundant intelligence, that constraint is increasingly institutional decision rights over how intelligence is deployed, governed, and integrated into operational workflows.

Every major technological platform eventually creates a fundamental trade-off between standardization and institutional autonomy. Frontier APIs offer immediate performance at the cost of outsourced decision rights. Enterprise-managed architectures require operational overhead but preserve decision rights.

The organizations that win won’t simply possess more intelligence. They will possess something increasingly scarce: the institutional authority to decide how that intelligence behaves inside their own operational boundaries.