A single line from a group of digital health investors should unsettle any executive who still believes their AI is a competitive edge. As first-half 2026 funding in the sector reached $7.4 billion — with a handful of megadeals absorbing nearly half of all capital — founders and financiers landed on the same blunt conclusion, reported by MedCity News: "The moat is no longer technological." AI, they agreed, has become table stakes. The real differentiator is now domain expertise.
That is not a health-sector curiosity. It is the through-line connecting nearly every serious governance story this week — from Microsoft's sales floor to the developer's laptop to the incident response war room. The technology that organizations spent a decade treating as a source of advantage is collapsing into a commodity. And when the tool stops differentiating you, the question governance has always asked — how well do you actually control this? — becomes the only question that matters.
The tell: when leaders sell on price, the category has commoditized
Watch what Microsoft is doing rather than what it says. TechCrunch reports the company is coaching its salespeople to talk down OpenAI and Anthropic and to pitch Microsoft's in-house models as more efficient and cost-effective. Sit with that. Microsoft poured billions into OpenAI and built much of its enterprise story around frontier capability. Now it is competing on cost against the very frontier it helped fund. When the market leader shifts its pitch from "ours is smarter" to "ours is cheaper," you are watching a category commoditize in real time.
The same gravity is pulling at the infrastructure layer. Data Engineering Central notes that Cloudflare — a company most people still think of as a content-delivery and edge-security provider — is now positioning itself as a data platform. Everyone is becoming a data platform. Capability that was scarce and defensible three years ago is now a checkbox. The moat drains out of the technology and pools somewhere else.
The uncomfortable corollary: your attackers shop the same shelves
Commoditization is usually framed as a market story. In security, it is a threat story. If frontier capability is cheap and widely available, adversaries have it too.
That is precisely what this week's security coverage describes:
- CSO Online reports that AI-powered breaches are undoing years of hard-won progress on detection and response, as threat actors automate the slow, manual, living-off-the-land techniques that once bought defenders time.
- A survey of large language models in cybersecurity catalogs the dual-use reality directly: the same models that power defensive tooling also generate malware, lower the skill floor for attackers, and scale reconnaissance.
- The Megalodon campaign, which injected malicious GitHub Actions workflows and pulled the software supply chain all the way down to the developer's workstation, shows how quickly commoditized automation weaponizes the ordinary.
For years, a well-resourced enterprise could assume a technological edge over most attackers. That assumption is gone. You now rent the same GPUs, fine-tune the same open weights, and automate against the same playbooks. This is why another CSO Online piece argues the industry has leaned too hard on cure and not enough on prevention — you cannot out-detect an adversary who moves at machine speed with your own tools. When capability equalizes, the advantage moves to whoever has the better discipline: known-good baselines, enforced boundaries, and deployments you can actually account for.
What is still defensible when the tool is not
If the model is not the moat, what is? The answer running underneath every one of these stories is the same one the digital health investors named: domain expertise, operationalized as governance.
Consider the contrast. Celcuity just won FDA approval for a genuinely first-in-class breast cancer drug — a novel mechanism addressing a pathway implicated in many cancers, per MedCity News. That is a real moat, and notice what built it: years of specific scientific and regulatory domain work, not generic capability anyone can rent by the hour. Meanwhile, CSO Online's profile of elite security engineers describes their edge almost entirely in terms of judgment, context, and traits — not access to tools everyone already has.
Governance is domain expertise applied to risk. It is the institutional knowledge of what your data actually means, where your regulatory obligations bind, which use cases are acceptable in your context, and which are not. That knowledge does not commoditize, because it is specific to you. It is also exactly what regulators are about to demand. Compliance Week's guidance that healthcare organizations should prepare now for near-certain AI legislation is a preview of the broader pattern: the winners will be the ones who have already mapped their clinical, operational, and regulatory context onto their AI deployments — not the ones with the flashiest model.
What governance professionals should take from this
The reframe is significant, and it favors you. For years, governance was treated as friction — the tax you paid for the privilege of shipping. When technology was the moat, that framing almost held. It does not hold anymore. If the technology is a commodity that your competitors and your attackers both possess, then the quality of your governance is one of the few things that is genuinely yours.
Three shifts follow from that:
- Stop treating tool acquisition as risk reduction. "We bought the platform" is no longer an answer to "are we secure" or "are we compliant." The platform is table stakes; the control is in how you deploy, constrain, and verify it.
- Invest in domain-specific governance, not generic policy. A control that reflects your actual data, obligations, and threat model is defensible in a way a boilerplate framework never will be. Domain expertise is the moat precisely because it cannot be copied off a shelf.
- Move budget from cure to prevention. If detection and response are eroding under machine-speed attacks, the marginal dollar buys more in prevention, baselines, and constrained deployment than in another layer of after-the-fact monitoring.
The strategic picture is consistent across sectors. Capital is consolidating around scale and specialization — nearly half of digital health funding went to megadeals — while raw technical capability spreads to everyone, including the people trying to breach you. In that world, the organizations that pull ahead will not be the ones with the best models. They will be the ones who best understand what they are doing with them, why, and within what limits. That understanding has a name. It is governance — and for the first time in a decade, it is the most defensible asset you own.
Sources
- AI-powered breaches provide wake-up call for incident response — CSO Online
- 7 skills and traits of elite security engineers — CSO Online
- Why Developer Workstations Have Become a Critical Part of the Software Supply Chain — DevOps.com
- Cloudflare as a Data Platform? — Data Engineering Central
- Cybersecurity needs more prevention and less reliance on cure — CSO Online
- Regulators are likely to pass laws on AI use in healthcare. Here’s how to prepare — Compliance Week
- Large Language Models (LLMs) and Generative AI in Cybersecurity and Privacy: A Survey of Dual-Use Risks, AI-Generated Malware, Explainability, and Defensive Strategies — arXiv — Artificial Intelligence (cs.AI)
- Microsoft is reportedly training salespeople to talk down OpenAI and Anthropic — TechCrunch
- ‘The Moat is No Longer Technological’: How Digital Health Fundraising Changed in H1 — MedCity News
- Celcuity’s First-in-Class Drug Gets FDA Approval in Most Common Type of Breast Cancer — MedCity News