Private equity and portfolios
Proprietary data as an AI moat: how sponsors test it in diligence
By SourceX Editorial · Updated
Short answer
Sponsors test a proprietary data moat in diligence with four questions: are the records unique, connected, rights-clear and refreshable? A moat claim that fails any one is a story, not an asset. Licensing the same records out need not weaken the moat when field-of-use, exclusivity and scope terms protect what powers the product.
Key takeaways
- A data moat claim holds only if the records are unique, connected to outcomes, clear of third-party rights and still being generated.
- Ask for system inventories, date coverage and contract versions, not row counts and dashboard screenshots.
- Customer content used without clear permission turns a moat claim into a liability.
- Licensing records to AI developers can coexist with a moat when field-of-use limits and scope exclusions protect the product's edge.
What makes proprietary data an actual AI moat?#
Proprietary data is an AI moat only when a competitor could not assemble the same records, the records link decisions to outcomes, the company has the right to use them, and the business keeps producing more. Volume alone does not create a moat, and neither does the phrase proprietary data in a management presentation.
Deal teams hear the claim often because AI has made it fashionable in teasers and CIMs. The test below turns it into four questions that can be answered with documents rather than adjectives. It works for software targets and for operators such as service, logistics or manufacturing companies whose records come from daily work.
The four-question moat test#
The four-question moat test asks whether records are unique, connected, rights-clear and refreshable, and it ties each question to evidence a target can produce without moving customer records. Score each question pass, partial or fail, and write down the evidence behind every score.
A target that passes all four has a defensible data position. A target that fails on rights has a problem that grows with every product feature or model built on the records, so that failure belongs in the risk section of the investment memo.
| Question | What to request | Passes when | Fails when |
|---|---|---|---|
| Unique: could a competitor get the same records? | Record families, their sources and how each was created | Records come from the company's own operations and customer interactions | Records were bought from list vendors, scraped, or are widely available |
| Connected: do records link actions to outcomes? | Field lists, schemas, linkage between systems | Requests, decisions and results join through shared IDs or threads | Isolated files, logs or transactions with no outcome attached |
| Rights-clear: may the company use them as planned? | Customer contracts, terms of service versions, privacy notices, vendor terms | Contracts permit the use, or records are the company's own work product | Customer content is used without clear permission, or terms are silent |
| Refreshable: will new records keep arriving? | Current monthly volumes, system roadmap, retention policy | Daily operations keep generating the same record types | The archive is historical only, or a system retirement ends capture |
Illustrative pass and fail cases for each question#
Illustrative: unique. A fictional elevator service company passes because its work orders, technician notes and callback history come from its own maintenance contracts. A fictional lead-generation software company fails because most of its database came from list vendors that also sell to its competitors.
Illustrative: connected. A fictional fleet maintenance software vendor passes because support tickets link to engineering issues, code changes and release notes. A fictional distributor fails because its order history and its customer service email never shared an order number, so problems cannot be tied to fixes.
Illustrative: rights-clear. A fictional field inspection software company passes for its own engineering records but only partially for customer inspection reports, because older terms of service were silent on secondary use. A fictional staffing firm fails for candidate files, which center on personal data collected for placements.
Illustrative: refreshable. A fictional HVAC contractor passes because every job adds estimates, dispatch notes and invoices. A fictional software company sunsetting a legacy product fails for that product, since capture ends when the last customer migrates, even though the closed archive may still be licensable.
What evidence should sit in the data room?#
The evidence that settles a moat claim is mostly descriptive, so a target can provide it without exposing customer records. Request it early, because gaps here usually take longer to close than the commercial questions, and a missing terms-of-service history cannot be recreated after the fact.
- A system inventory naming each platform, the record families it holds and the date range still accessible.
- Field lists or schemas showing how records link across systems.
- Every version of the terms of service and privacy notice, with the dates each applied.
- Customer contract templates plus negotiated data or AI clauses from the largest accounts.
- Vendor terms for the platforms that hold the records, including export rights.
- Any existing data licenses, data sharing agreements or AI vendor arrangements.
- Retention and deletion policies, and notes on past system migrations.
Does licensing the data give the moat away?#
Licensing records to AI developers does not give the moat away when the license is scoped around what makes the product hard to copy. The tension is real: a moat is about keeping something scarce, and a license puts a copy in someone else's hands. Contract structure decides which way it falls.
The useful line runs between records that teach general skills and records that power the company's own features. A software company can license prepared engineering and support records for general coding and support agents while keeping product-specific customer data out of scope. The terms below are the usual tools for drawing that line.
| Term | What it protects | Trade-off |
|---|---|---|
| Field-of-use limit | Bars the buyer from building a competing product in the company's market | A narrow field can reduce buyer interest |
| Non-exclusive grant | Keeps the company free to license again or use the records itself | Some buyers value exclusivity and price its absence accordingly |
| Bounded exclusivity | Grants exclusivity only for a defined use or period | Blocks other deals in that use while it lasts |
| Scope exclusions | Keeps product-differentiating records and customer content out | A smaller package |
| Competitor restriction | Prohibits sublicensing or transfer to defined competitor categories | Needs careful drafting to be workable |
Red flags that turn a moat into a liability#
Some findings turn a moat claim into a liability, and they usually trace back to how records were collected or how terms changed over time. Each one below calls for counsel's review and, where it is confirmed, a specific protection in the purchase agreement.
- Customer content already used to train models under terms that did not clearly allow it.
- Records copied from public websites or third-party sources without a license.
- Key history held only in a vendor platform whose terms limit export.
- History lost in a past migration, so the claimed depth does not exist.
- Client-owned deliverables counted as company records.
- An existing exclusive data license that blocks the sponsor's own plans.
How SourceX supports a moat test#
The SourceX Enterprise Data Value Framework, a qualitative SourceX methodology rather than an industry standard, overlaps with the moat test. Its drivers of uniqueness, rights and recency map to the unique, rights-clear and refreshable questions, while reproducibility, which reduces value, is the flip side of uniqueness. Sponsors can use it to compare targets and portfolio companies on one basis.
When a company licenses records, SourceX documents each package in a SourceX Evidence Packet covering provenance, licensing rights, permitted use, the privacy record and release authorization. That packet later gives an acquirer a clean account of what was licensed and on what terms.
Frequently asked questions
Is a large dataset a moat on its own?
No. Size helps only when the records are also distinctive, linked to outcomes and clear of third-party rights. A large archive of disconnected logs or purchased lists can be copied or bought by a competitor, while a smaller archive of linked decisions from the company's own operations is much harder to replicate.
Should a sponsor discount a moat claim if the terms of service changed recently?
Look closely rather than discount automatically. New terms may cover data collected after the change, but whether they reach older records depends on the original wording and how customers were notified. Counsel should confirm which records each version covers before the claim goes into the model.
Can a services company have a data moat, or only software companies?
Services companies can. Contractors, logistics operators, manufacturers and consulting firms create records of decisions every day, such as job notes, exception threads, NCRs and project reviews. Those archives are often more distinctive than software telemetry, provided the company owns them and they link to outcomes.
How does an existing data license affect a moat assessment?
It can strengthen the case by showing that buyers value the records, or weaken it if the license is exclusive or broad. Read the grant, field of use, exclusivity and term, and confirm what remains available to the company and its future owners.
Who on the deal team should run the moat test?
Pair a deal team member with technical diligence for the unique, connected and refreshable questions, and counsel for rights. Each question needs a named owner and evidence, so the conclusion in the investment memo rests on documents rather than management assertions.
Related resources
See if your company qualifies
A short company assessment. No data uploads are needed.