# Founder-Capital Durability in the Age of Copyable Software

## Why a blind reverse marketplace may be the most AI-resilient attainable digital business model

**Working paper — Version 1.10 — September 2026**

## Abstract

In 2026, producing software functionality is becoming faster and cheaper. This does not make all software valueless, nor does it mean every production system can be reproduced instantly. It does mean that code and features alone are becoming weaker sources of lasting differentiation.

This paper asks a founder-level question:

> If a competitor reproduces the software and reaches feature parity tomorrow, how much of the founder's accumulated work still survives?

The answer depends on whether years of effort were stored primarily in reproducible code or in assets that do not transfer with a code copy: trusted distribution, brand, network liquidity, proprietary outcome data, participant relationships, regulatory access, operating knowledge and switching costs.

The paper proposes that a blind reverse marketplace in a high-value, locally regulated service market can combine more of these durable assets than most business models that remain attainable to a capital-constrained founder. Infrastructure, protocol and sovereign monopolies can be still more durable, but normally require capital, licences, coordination or legal authority outside the founder's feasible set.

The thesis is not that such a marketplace is impossible to disrupt. The thesis is that its accumulated founder capital may be unusually difficult to erase through software copying alone. The analysis separates that replication shock from a second AI shock with two mechanisms: substitution of economic work and autonomous-agent bypass of discovery, transaction and fulfilment channels.

## 1. The founder's real problem

A founder may spend years building a software product and still face a competitor that:

- reproduces its principal features;
- launches with a more polished interface;
- prices below it;
- uses a stronger existing audience;
- purchases more distribution; or
- bundles the feature into a larger product.

If the original business stored most of its value in features, technical parity can destroy much of the founder's accumulated advantage. The relevant distinction is therefore not “software versus marketplace.” It is:

> **Reproducible product output versus accumulated non-transferable business assets.**

The purpose of the paper is to compare general business-model architectures by the durability of the assets in which founder effort accumulates.

## 2. Replication is not displacement

Three events must be separated:

1. **Code replication:** a competitor reproduces the software implementation.
2. **Product substitution:** customers regard the competitor's product as an adequate alternative.
3. **Business displacement:** customers, suppliers and cash flow move to the competitor.

AI may sharply reduce the cost of the first event. It does not guarantee the second or third.

Let:

```text
P(displacementₘ) = P(code parityₘ)
                    × P(substitutionₘ | code parityₘ)
                    × P(migrationₘ | substitutionₘ)
```

A defensible business is one in which software parity does not automatically produce substitution and migration.

This is why the sentence “every software product can be copied” is a useful stress-test but an insufficient theorem. A codebase can be reproduced while its installed workflows, brand, demand channel, exclusive data or network remain with the incumbent.

## 3. Founder capital

Founder capital is the stock of work, money, knowledge and relationships accumulated inside a business:

```text
Fₘ(t) = Cₘ(t) + Gₘ(t) + Nₘ(t) + Tₘ(t) + Dₘ(t) + Rₘ(t) + Oₘ(t) + Pₘ(t)
```

where:

- **C:** software and product capital;
- **G:** distribution, audience and brand capital;
- **N:** network liquidity;
- **T:** trust and reputation;
- **D:** proprietary transaction and outcome data;
- **R:** participant and institutional relationships;
- **O:** operating knowledge and repeatable processes; and
- **P:** permissions, licences, contracts and regulatory position.

These terms must ultimately be expressed as shares of total accumulated founder work, using a consistent measure such as replacement effort. Simply adding arbitrary scores would not be a measurement.

## 4. The software-parity shock

Consider a shock at time **t** in which a well-funded entrant can reproduce the observable software and features at negligible cost.

Let **sₖ ∈ [0, 1]** be the proportion of asset class **k** retained by the incumbent after that shock. Founder-capital durability is:

```text
       Σₖ sₖ × Fₘ,ₖ(t)
Φₘ(t) = ───────────────
          Σₖ Fₘ,ₖ(t)
```

Interpretation:

- **Φₘ ≈ 0:** feature parity erases most accumulated advantage;
- **Φₘ ≈ 1:** most accumulated advantage remains after feature parity.

For source code and observable interface functionality, **s꜀** may decline as replication becomes cheaper. For trusted distribution, effective liquidity, verified relationships and private outcome data, retention may remain substantially higher.

Software copying is only the first shock. The AI-agent shock has two different mechanisms that must be applied to every model:

- **Uₘ ∈ [0, 1]: AI-function retention** — the fraction of the underlying economic function still required after AI can perform relevant production and service tasks;
- **Aₘ ∈ [0, 1]: autonomous-agent channel retention** — the fraction of that remaining function still mediated or governed by the business after agents can search, compare, contact, buy or coordinate alternatives directly. This explicitly includes control of the transaction, fulfilment, guarantees and remediation;
- **Ψₘ = Uₘ × Aₘ:** total retention after both AI mechanisms.

The combined shift-resilience score is:

```text
Ωₘ = Φₘ × Uₘ × Aₘ
   = Φₘ × Ψₘ
```

The multiplication models three sequential filters within the paper's two high-level shocks. First, software parity removes reproducible accumulated work. Second, AI production removes functions that no longer need the business. Third, autonomous agents remove channel value by reaching alternatives without the business. Thus **Ωₘ** is the fraction of accumulated founder work remaining relevant after software copying and the complete AI-agent shock.

The central ranking is therefore:

```text
m* = the model with the highest Ωₘ among all models in the comparison set
```

Revenue, profit, CAC, founder hours and probability of commercial success are deliberately outside this ranking. They may determine whether somebody chooses to build the model, but they do not answer which architecture best sustains software copying and AI task substitution.

## 5. General business-model comparison

The following table compares idealised models. Real companies normally combine several rows.

| Business model | Where value accumulates | Vulnerability after software parity | Potential durable complements | Main limitation |
|---|---|---|---|---|
| Pure feature / AI wrapper | Code, UX, speed to market | Very high when customers can switch easily | Brand, integrations, distribution | Features can converge rapidly |
| Paid macOS / Windows desktop app | Installed base, reviews and one-time licence sales | High | Brand, native integration and direct distribution | Weak recurring revenue and operating-system dependence |
| Paid mobile app | App-store installs, ratings and one-time sales | Very high | Ranking, reviews, brand and installed base | Low price ceiling, store commission and weak recurring revenue |
| B2C subscription software / app | Subscribers, habit and stored user state | Medium–high | Retention, brand, personal data and notifications | Churn and low switching costs |
| Freemium software / app | Large free-user funnel | High until conversion scale exists | Distribution, user-generated data and habit | Support cost and very low paid conversion |
| Advertising-supported app | Attention and audience scale | High | Engagement data and distribution | Low revenue per user and ad-platform exposure |
| In-app-purchase content app | Catalogue, users and purchase history | Medium–high | Exclusive content, progression and collections | Store commissions and content-production burden |
| Mobile game | Game content, player community and live operations | Very high before scale | Social graph, virtual economy, brand and events | Hit risk and rapid attention decay |
| App-enabled marketplace | Mobile distribution plus transactional network | Low once liquid | Cross-side effects, trust and transaction data | Cold start, store dependence and leakage |
| Platform-integrated utility | Native workflow and ecosystem integration | Medium | Installed base, permissions and deep integration | Operating-system owner can copy or restrict it |
| B2B self-serve / PLG SaaS | Product-led adoption and smaller customer accounts | Medium–high | Integrations, collaborative data and expansion | Lower contracts and easier switching |
| B2B enterprise / vertical SaaS | Workflows, stored data, integrations and contracts | Medium | Switching costs, compliance, embedded process | Long sales cycle and costly implementation |
| Content or media | Audience and catalogue | Software parity is mostly irrelevant | Brand, attention, archive, community | Platform dependence and content commoditisation |
| Digital agency / remote professional service | People, expertise and client relationships | High when agents perform delivery directly | Reputation, proprietary distribution and accountability | Routine SEO, advertising, analytics, content and development can be automated |
| Ecommerce / DTC brand | Brand, product, supply chain | Low–medium | Distribution, repeat purchase, sourcing | Margin pressure and paid-acquisition dependence |
| Proprietary data / API | Data rights and integration | Medium | Exclusive data, workflow embedding | Data may become public or substitutable |
| Community business | Social graph and identity | Low–medium | Belonging, reputation, member relationships | Moderation and multihoming |
| Open marketplace | Liquidity, trust and transactions | Low once liquid | Cross-side network effects, reviews, payments | Leakage, multihoming and expensive cold start |
| Managed marketplace | Liquidity plus transaction and fulfilment control | Low | Dispatch, payment, standards, guarantees, remediation and fulfilment data | High capital, liability and operating intensity |
| Physical or franchised network | Locations, supply and procedures | Very low | Real assets, territory and operating system | Capital intensity and slower scaling |
| Blind reverse regulated marketplace | Demand, qualified local supply, controlled information, private transaction data and operations | Potentially very low | Private competition and optional transaction governance | Trust friction, thin markets, provider resistance and limited fulfilment control |
| Infrastructure or protocol | Underlying rails and standard | Very low | Integration depth, regulation and coordination | Extremely difficult to establish |
| Sovereign or statutory monopoly | Legal authority | Minimal conventional competition | Law and exclusive authority | Not privately attainable |

The paper's candidate is not compared only with other marketplaces. It is compared with the broader set of ways a founder can organise a digital business.

## 6. Why pure feature businesses become psychologically fragile

Suppose a founder invests **Iₜ** in each period and the survival rate of that period's investment after future technology shocks is **qₜ**. Expected durable accumulation is:

```text
A(H) = Σ from t=0 to H of: δᵗ × Iₜ × qₜ
```

When the founder believes **qₜ** is low, additional effort feels temporary: improvements may increase current value without increasing durable advantage. This can rationally reduce willingness to invest for a long horizon.

The psychological problem is therefore connected to asset structure, but it is not proof that a founder's brain can accurately identify business quality. Founders can underestimate distribution, exaggerate copy risk, or use “no moat” as a reason to avoid market execution.

The practical objective is to choose a model in which observable progress increases assets that a feature clone does not inherit.

## 7. Why network effects matter

In a two-sided market, participants on each side may increase utility for the other side. A copy of the software begins without the incumbent's active demand and qualified supply.

Raw user counts are not sufficient. Let **pᵢⱼ** be the probability that provider **j** is eligible, available and acceptable for request **i**. Expected fulfilled requests are:

```text
E[M] = Σ across requests i: [1 − Π across providers j: (1 − pᵢⱼ)]
```

This quantity is bounded by demand and provider capacity and normally exhibits diminishing returns. **D × S** counts possible pairs; it is not automatically enterprise value and does not establish quadratic growth.

### Proposition 1 — Network survival after code parity

Let an incumbent and replica have identical software and matching rules. If the incumbent retains a strictly larger set of eligible, responsive providers in a positive-demand segment, and participant migration is not instantaneous, then software parity alone does not give the replica equal expected fulfilment in that segment.

This proposition explains why founder effort stored in effective liquidity survives a code copy. It does not make the network impossible to overcome through subsidies, bundling, superior distribution or exclusive supply.

## 8. Why marketing and distribution matter

Strong distribution can protect almost any business model. An audience, search position, brand, partnership channel or embedded workflow is not transferred with source code.

Let demand acquisition be:

```text
Dₜ = g(Gₜ, priceₜ, productₜ, competitionₜ)
```

where **Gₜ** is accumulated distribution capital. A copycat with better features but **Gₜ = 0** may still fail. Conversely, an entrant with superior distribution can defeat a technically stronger incumbent.

Marketing is therefore both:

- an independent moat available to many models; and
- a necessary input for the blind reverse marketplace.

The proposed BRM does not replace marketing. Its advantage is that acquired demand can generate transactions, data, provider participation and trust, allowing one unit of distribution effort to strengthen several asset classes.

## 9. Why the blind reverse marketplace is different

A blind reverse marketplace combines mechanisms that are usually distributed across separate models:

1. **Buyer-initiated aggregation:** a buyer submits one structured request instead of searching many providers.
2. **Qualified local supply:** only suitable providers receive the opportunity.
3. **Sealed competition:** providers do not observe competing offers before submitting.
4. **Controlled identity disclosure:** neither side receives the other's identity before a defined conversion event.
5. **Observed transactions:** the platform sees current offers, response behaviour and outcomes.
6. **Real-world completion:** regulated or local execution remains necessary.
7. **Software leverage:** matching, routing, comparison, payment and communication can become increasingly automated.

The software implementing these rules is copyable. The accumulated system around it is not copied at the same time.

## 10. The compound-moat mechanism

Let the non-code asset state be:

```text
Zₜ = (Gₜ, Nₜ, Tₜ, Dₜ, Rₜ, Oₜ, Pₜ)
```

and let completed marketplace activity be **Mₜ**. A successful transaction can update several assets simultaneously:

```text
Zₜ₊₁ = ρ × Zₜ + B(Mₜ) − Depₜ
```

where:

- **ρ** represents persistence;
- **B(Mₜ)** is the vector of asset gains produced by marketplace activity; and
- **Depₜ** is depreciation, churn and knowledge obsolescence.

A completed request can create:

- revenue;
- new price and scope data;
- evidence of provider responsiveness;
- a buyer outcome;
- greater provider willingness to participate;
- reputation or referral value;
- improved matching rules; and
- a more repeatable operating process.

### Proposition 2 — Multi-asset accumulation

If each completed match produces positive increments in at least two persistent non-code asset classes, then the transaction enlarges the stock of founder work that a software replica does not inherit.

This is the paper's compounding argument. It is stronger than claiming that participant counts grow quadratically.

## 11. Three productive information asymmetries

### 11.1 Buyer–provider asymmetry

The platform knows both identities before the parties know one another. This can protect buyer privacy, reduce unsolicited contact and allow the platform to monetise the connection.

### 11.2 Provider–provider asymmetry

Providers submit sealed offers. Under suitable procurement-auction assumptions, this can improve competitive price discovery. It can also produce under-scoping, adverse selection or winner's-curse effects when service quality and cost are uncertain.

### 11.3 Platform–entrant asymmetry

The platform observes non-public, current signals:

- actual quoted prices and scopes;
- provider response speed and capacity;
- buyer selection behaviour;
- completion and failure outcomes;
- market-specific exceptions; and
- changes in local administrative practice.

The useful data stock may evolve as:

```text
Dₜ₊₁ = ρᴅ × Dₜ + η × Mₜ × qₜ
```

where **qₜ** is observation quality. Data becomes a moat only when it is captured lawfully and improves decisions. Unused records are not defensibility.

## 12. AI resistance comes from the non-code remainder

The cost of creating a competitively meaningful replica is:

```text
Kₘ(A) = Kcode,ₘ(A) + Kdistribution,ₘ + Knetwork,ₘ + Ktrust,ₘ
        + Kdata,ₘ + Krelationships,ₘ + Kregulation,ₘ + Koperations,ₘ
```

AI capability **A** may reduce **Kcode,ₘ(A)**. The business remains resistant only to the extent that the other terms are positive and necessary for customer value.

### Proposition 3 — Complementary-asset resilience

If AI drives code-reproduction cost towards zero for all models, the difference in replication cost between a BRM and a code-only product converges to the BRM's required non-code complements:

```text
As Kcode approaches 0:

KBRM − Kfeature → Kdistribution + Knetwork + Ktrust + Kdata
                  + Krelationships + Kregulation + Koperations
```

The proposition is conditional on those complements being genuinely necessary. If customers can obtain equivalent outcomes without them, their nominal existence does not create a moat.

## 13. Leakage is only one reinforcement

A direct pre-conversion bypass requires the parties to identify one another (**E**), establish an outside channel (**R**), and prefer bypassing after costs and risks (**A**):

```text
P(direct leakage) = P(E ∩ R ∩ A)
```

Perfect pre-conversion concealment implies:

```text
P(direct leakage) ≤ P(E) = 0
```

This only eliminates the direct-identity channel before conversion. Inference, external discovery, collusion, abandonment and post-match repeat leakage remain possible.

Leakage control matters because it helps the platform retain enough value to finance qualification, matching, trust and data capture. It is one reinforcement inside the compound moat, not the paper's main conclusion.

## 14. Real-world friction as stored capability

Relocation and other regulated local services may require licensed advice, identity verification, certified documents, property access, government submissions, banking relationships or physical presence.

AI can reduce research, translation, document preparation and support costs. Under the model's institutional assumptions, it does not independently perform every accountable or physical action.

Real-world friction has two sides:

- it raises the replication cost for a code-only entrant;
- it also raises the incumbent's operating cost.

Friction becomes a moat only after the platform converts it into relationships, verified supply, data and repeatable procedures. Unsolved complexity is a burden, not an asset.

## 15. Participation constraints

The business cannot survive merely by protecting the platform. It must create non-negative expected utility for all required participants.

Buyer utility:

```text
Ubuyer = Vservice − Pservice − Csearch − Cspam − Crisk
```

Provider utility:

```text
Uprovider = P(win) × (Pservice − Cdelivery) − Cbid − Fplatform
```

Platform utility:

```text
Uplatform = Fbid + Fmatch + Ftransaction
            − Cacquisition − Cverification − Coperations − E[loss]
```

Necessary participation conditions are:

```text
Ubuyer ≥ 0,  Uprovider ≥ 0,  Uplatform ≥ 0
```

Blindness is harmful when the trust or information it removes reduces buyer or provider utility more than it increases privacy, competition or efficiency.

### 15.1 The win–win–win condition

Let **Uᵢ⁰** be participant **i**'s best outside option and **Uᵢᴮᴿᴹ** its utility inside the blind reverse marketplace. A transaction is individually rational for buyer, provider and platform only if:

```text
ΔUbuyer    = Ubuyer,BRM    − Ubuyer,outside    ≥ 0
ΔUprovider = Uprovider,BRM − Uprovider,outside ≥ 0
ΔUplatform = Uplatform,BRM − Uplatform,outside ≥ 0
```

and it creates additional total surplus only if:

```text
ΔW = ΔUbuyer + ΔUprovider + ΔUplatform > 0
```

For the buyer, reduced search, spam and discriminatory-pricing risk must exceed any trust loss caused by hidden identities. For the provider, qualified demand and lower selling effort must exceed bid fees and bid preparation cost. For the platform, monetisation must exceed acquisition, verification, support and expected dispute cost. This formalises the proposed win–win–win result; it does not assume it.

## 16. Why stronger models may be unattainable

Infrastructure networks, dominant protocols and sovereign monopolies can retain even more value after a software-parity shock. They control underlying rails, standards, licences or law.

Let initial establishment cost be **Kₘ⁰**. A model is feasible only if:

```text
Kₘ⁰ ≤ B
```

If an infrastructure or sovereign model requires **K₄⁰ > B**, institutional authority unavailable to the founder, or a coordination threshold that cannot be reached within **H**, it is excluded:

```text
Model 4 ∉ founder-accessible set F(B, H, O)
```

The relevant question is not whether a BRM is harder to disrupt than Visa or a government. It is whether another realistically attainable model lets a founder accumulate more valuable capital that survives software parity.

## 17. Combined shift-resilience theorem

### The answer in plain language

Imagine that a founder spends five to seven years building a blind reverse regulated marketplace. Treat everything accumulated during that period as **100 units of founder work**.

Those 100 units are not all stored in the software. They are distributed across eight asset classes.

#### Step 1: Where the 100 units accumulate

| Accumulated asset | Work before copying | Retained after copying | Work that survives |
|---|---:|---:|---:|
| Software and visible product | 10 units | 8% | 0.80 units |
| Distribution and brand | 15 units | 95% | 14.25 units |
| Network liquidity | 20 units | 95% | 19.00 units |
| Trust and reputation | 10 units | 90% | 9.00 units |
| Private transaction data | 12 units | 95% | 11.40 units |
| Participant relationships | 15 units | 95% | 14.25 units |
| Operating knowledge | 10 units | 95% | 9.50 units |
| Permissions and regulatory position | 8 units | 98% | 7.84 units |
| **Total** | **100 units** | — | **86.04 units** |

The asset weights describe where the founder's accumulated work is stored. They are not recommended weekly time allocations. The retention percentages describe what remains with the founder immediately after a competitor reproduces the complete visible software.

#### Software and visible product: 10 units

This includes the intake form, interface, matching workflow, dashboards, messaging, bidding rules and payment logic.

A competitor reaching feature parity receives almost all of this functionality. Only a small part remains useful as incumbent-specific integration and operating history.

```text
10 × 8% = 0.80 surviving units
```

This is the deliberately fragile part of the BRM. The thesis does not depend on secret code.

#### Distribution and brand: 15 units

This includes search authority, useful published material, direct traffic, referrals, partnerships, recognition and the habit of beginning a relocation request with the platform.

A copied application does not inherit search history, referral relationships, audience attention or trusted demand channels.

```text
15 × 95% = 14.25 surviving units
```

A competitor can build or purchase distribution, but software parity alone does not transfer it.

#### Network liquidity: 20 units

This is the largest component. It includes active buyer demand, verified local providers, geographic coverage, provider availability, response behaviour and the probability that a real request receives suitable offers.

A replica receives the matching code but begins without the incumbent's functioning market.

```text
20 × 95% = 19.00 surviving units
```

The important asset is not the number of registered accounts. It is effective liquidity: qualified participants who reliably create successful matches.

#### Trust and reputation: 10 units

This includes verified histories, completed outcomes, reviews, fraud controls, complaint handling and confidence that the platform will disclose identities fairly.

A competitor can copy trust badges and page language. It cannot copy the events that made those claims credible.

```text
10 × 90% = 9.00 surviving units
```

Some trust may still migrate if the copycat has a stronger existing brand, which is why retention is not assumed to be 100%.

#### Private transaction data: 12 units

This includes actual quoted prices, scopes, response times, acceptance behaviour, completion outcomes, exceptions and changes in local service conditions.

This data is current, behavioural and largely unavailable from public websites.

```text
12 × 95% = 11.40 surviving units
```

A competitor can copy a database schema. It does not receive the incumbent's historical records or the learning derived from them.

#### Participant relationships: 15 units

This includes relationships with law firms, relocation specialists, accountants, notaries, property professionals, banks, insurers and other locally necessary providers.

The accumulated asset includes qualification history, responsiveness, capacity knowledge and mutual willingness to transact through the platform.

```text
15 × 95% = 14.25 surviving units
```

A replica can contact the same firms, but it does not instantly acquire the incumbent's history, confidence or active participation.

#### Operating knowledge: 10 units

This includes vetting standards, exception playbooks, routing rules, fraud signals, escalation procedures and tacit knowledge about how real cases fail.

Some procedures may be inferred from the product. Much of the knowledge comes from incidents and completed transactions that are invisible to outsiders.

```text
10 × 95% = 9.50 surviving units
```

This component survives only when the founder records and operationalises learning. Undocumented personal intuition is much less durable.

#### Permissions and regulatory position: 8 units

This includes contracts, licences, consent structures, data-processing arrangements, professional limitations and accepted ways of working with local institutions.

These positions cannot be acquired by copying interface code.

```text
8 × 98% = 7.84 surviving units
```

They are not perfectly permanent: laws, contracts and institutional policies can change.

#### Step 2: Add the software-parity survivors

```text
 0.80  software and product
14.25  distribution and brand
19.00  network liquidity
 9.00  trust and reputation
11.40  private transaction data
14.25  participant relationships
 9.50  operating knowledge
 7.84  permissions and regulatory position
─────
86.04  units survive complete software copying
```

Rounded to the central scenario:

```text
ΦBRM ≈ 86%
```

The competitor receives the visible product but does not receive the functioning network and institutional system accumulated around it.

#### Step 3: Model the autonomous buyer-agent threat

Now imagine that AI agents are mainstream. A client can instruct an agent to search Google, Google Maps, directories and provider websites; extract contact details; send emails or forms; follow up; and compare the replies.

This is a genuine substitute for part of the marketplace. The BRM must not assume that buyers remain because searching manually is inconvenient.

Because submitting a BRM request is free, buyer price is equal in the comparison:

```text
Client price of BRM request = 0
Assumed marginal price of buyer-agent search = 0
```

Price therefore does not protect either option. The client chooses according to outcome quality, effort, privacy, trust and response reliability.

A direct buyer-agent route must complete a chain:

```text
Direct-agent outcome =
provider discovered
× provider contactable
× provider responds
× provider is actually qualified
× offer is comparable
× client trusts the outcome
```

The agent can make discovery and outreach extremely cheap. But sending more messages does not guarantee qualified responses, standardized scopes, accountability or privacy.

The BRM route has a different chain:

```text
BRM outcome =
structured request
× verified suitable supply
× provider willingness to respond
× comparable sealed offers
× controlled identity disclosure
× trusted completion
```

The buyer agent is strongest when nearly all useful providers are public, their services are standardized, they respond reliably to automated outreach and the client does not value identity protection or platform accountability.

The BRM is strongest when provider quality is difficult to verify, scopes differ, response rates are uneven, local capacity changes, privacy matters, some supply is non-public and transaction history improves matching.

#### Step 4: What an autonomous agent replaces

The table treats the BRM's client-facing function as another 100 units and asks how much remains necessary when the client has a capable autonomous agent.

| BRM function | Function weight | Retained against buyer agent | Function that remains |
|---|---:|---:|---:|
| Public provider discovery | 10 units | 10% | 1.00 units |
| Outreach and follow-up | 5 units | 20% | 1.00 units |
| Structured intake and comparison | 10 units | 60% | 6.00 units |
| Verified supply and response incentives | 15 units | 90% | 13.50 units |
| Privacy and controlled identities | 15 units | 95% | 14.25 units |
| Private network and current capacity | 15 units | 95% | 14.25 units |
| Trust, outcomes and accountability | 15 units | 90% | 13.50 units |
| Regulated and physical coordination | 10 units | 100% | 10.00 units |
| Private transaction intelligence | 5 units | 95% | 4.75 units |
| **Total** | **100 units** | — | **78.25 units** |

##### Public discovery: mostly replaced

An autonomous agent can search public listings faster and more broadly than a person. The BRM retains little advantage if its provider list is merely a copy of Google Maps.

```text
10 × 10% = 1.00 surviving unit
```

##### Outreach and follow-up: mostly replaced

An agent can send emails, complete contact forms and chase replies. Basic outreach is therefore not a moat.

```text
5 × 20% = 1.00 surviving unit
```

The remaining value comes from providers choosing to prioritize a known source of structured, qualified requests instead of responding to unrestricted automated outreach.

##### Structured intake and comparison: partly replaced

An agent can interview the client and normalize offers. The BRM still retains some value from a shared request schema, historical scopes and comparison rules learned from completed cases.

```text
10 × 60% = 6.00 surviving units
```

##### Verified supply and response incentives: largely retained

Google can reveal that a provider exists. It does not prove current availability, suitability, response discipline or willingness to serve the specific request.

The BRM can route only to verified providers and use participation rules, bid commitments and reputation consequences to encourage serious responses.

```text
15 × 90% = 13.50 surviving units
```

As automated outreach becomes widespread, providers may receive more low-quality machine messages. A trusted channel for qualified demand may become more valuable rather than less valuable.

##### Privacy and controlled identities: largely retained

A buyer agent must normally disclose enough information for providers to respond. It may distribute personal circumstances across many websites, inboxes and tracking systems.

The BRM can send one structured, minimized profile while concealing the buyer's identity until a defined commitment event. It also conceals provider identities before that event.

```text
15 × 95% = 14.25 surviving units
```

The free buyer request strengthens this advantage: the client does not have to sacrifice money to obtain the privacy-preserving route.

##### Private network and current capacity: largely retained

An agent can search public providers. It cannot automatically access providers, availability signals or commercial willingness that exist only inside the platform.

```text
15 × 95% = 14.25 surviving units
```

This advantage disappears if the BRM has no meaningful private participation and merely republishes public listings.

##### Trust, outcomes and accountability: largely retained

An agent can summarize public reviews, but reviews do not reveal every completed scope, failure, refund, dispute or verified outcome.

```text
15 × 90% = 13.50 surviving units
```

The BRM must actually observe outcomes and enforce standards. A logo or unverified rating is not enough.

##### Regulated and physical coordination: retained

Agents can prepare and communicate, but some services still require licensed responsibility, identity checks, original documents, physical access or interaction with local institutions.

```text
10 × 100% = 10.00 surviving units
```

If regulation and physical requirements disappear, this factor must be reduced.

##### Private transaction intelligence: largely retained

An agent searches information that is available to it. The BRM observes live quotes, accepted scopes, response behavior, completion outcomes and local exceptions that may never be published.

```text
5 × 95% = 4.75 surviving units
```

This is durable only if the platform captures lawful, accurate outcomes and uses them to improve routing or verification.

#### Step 5: Calculate AI-substitution retention

Add the surviving client-function units:

```text
 1.00  public discovery
 1.00  outreach and follow-up
 6.00  structured intake and comparison
13.50  verified supply and response incentives
14.25  privacy and controlled identities
14.25  private network and current capacity
13.50  trust, outcomes and accountability
10.00  regulated and physical coordination
 4.75  private transaction intelligence
─────
78.25  units remain necessary despite a buyer agent
```

For the BRM central scenario, the regulated and physical relocation outcome remains necessary even if AI performs administrative tasks, so **UBRM = 100%**. The table measures how much of the platform's role remains when the buyer's agent can bypass public discovery and outreach, giving **ABRM = 78.25%**. Therefore:

```text
ΨBRM = UBRM × ABRM
     = 100% × 78.25%
     = 78.25%
```

This is materially lower than the paper's earlier 95% assumption. The correction recognizes that autonomous agents can replace most public discovery and outreach and part of intake and comparison.

#### Step 6: Combine software copying and buyer-agent substitution

After complete software copying, 86.04 of the founder's original 100 units remain. The autonomous-agent threat leaves 78.25% of those survivors relevant:

```text
86.04 × 78.25% = 67.3263
```

Rounded:

```text
ΩBRM ≈ 67.3%
```

> **Out of every 100 units of work accumulated by the BRM founder, approximately 67.3 units remain relevant after both complete software copying and mainstream autonomous buyer agents.**

The lost 32.7 units consist mainly of reproducible software, public discovery, automated outreach and parts of qualification and comparison.

The surviving 67.3 units are concentrated in effective liquidity, verified participation, privacy, trust, private data, relationships, institutional knowledge and real-world completion.

#### Step 7: The strategic implication

The BRM cannot defend itself by being a nicer search interface. A buyer agent will reproduce that function.

It must accumulate assets the agent cannot obtain from the public web:

- providers who actively respond through the platform;
- current availability and qualification signals;
- non-public or platform-prioritizing supply;
- standardized offers tied to one structured request;
- privacy-preserving controlled disclosure;
- verified completion and dispute history;
- private transaction and outcome data; and
- local institutional and regulatory capability.

The strongest response is not to block client agents. It is to let them submit structured requests to the BRM. The BRM can become the trusted transaction and supply infrastructure used by both humans and agents.

In that architecture:

```text
Client agent handles personal assistance and public research.
BRM handles verified supply, sealed competition, privacy, trust and outcomes.
```

#### Transaction and fulfilment control

An additional distinction is how much of the actual transaction and fulfilment the business controls. This is one of the strongest protections against autonomous-agent bypass.

| Architecture | Discovery and comparison | Transaction control | Fulfilment control | Consequence for agent bypass |
|---|---|---|---|---|
| Open marketplace | Public | Usually limited | Usually none | Agent can often find and contact the same provider directly. |
| App-enabled marketplace | Platform-mediated | Partial | Limited | Agent bypass is possible, although payment and reputation may retain activity. |
| Blind reverse marketplace | Private before disclosure | Structured request and sealed offers | Usually limited after introduction | Agent cannot reproduce private competition easily, but post-disclosure bypass remains possible. |
| Managed marketplace | Platform-controlled | Strong | Strong dispatch, standards, guarantees or remediation | Agent may select the marketplace, but cannot reproduce its managed execution merely by contacting providers. |

This is why the generic managed marketplace receives **A = 92%**, compared with **A = 78.25%** for the BRM. The managed marketplace controls more of the outcome after discovery. The BRM controls information and competition strongly but, in its current definition, does not control the entire delivery.

Transaction and fulfilment control is treated as an explicit subcomponent of **A**, not multiplied as another independent factor. Adding it again would count the same anti-bypass protection twice.

The BRM can strengthen this component without becoming a fully managed operator by adding:

- binding provider response and scope commitments;
- platform payment or escrow;
- standardized milestones and completion evidence;
- verified outcome records;
- service guarantees or narrowly defined remediation;
- dispute handling; and
- provider consequences for non-performance.

These mechanisms move the BRM from merely generating introductions toward governing the transaction. Their legal, operational and capital costs must be measured rather than assumed away.

#### Step 8: The comparison result

The updated stress test ranks the BRM behind sovereign monopolies, infrastructure protocols, physical networks and capital-intensive managed marketplaces.

Among founder-accessible models, the BRM remains first:

```text
BRM combined resilience = 67.3%
Next founder-accessible model, community business = 56.7%
Difference = 10.6 percentage points
```

This lead is much narrower than before the autonomous buyer-agent threat was modeled. If the BRM fails to build private participation, verified outcomes, response incentives and controlled disclosure, a buyer agent can reduce or eliminate that lead.

The exact failure boundary is useful. With software-parity retention fixed at **86.04%**, the BRM must retain more than the following share of its function to remain above the community model's **56.7%** combined score:

```text
Required ΨBRM > 56.7% ÷ 86.04% = 65.90%
```

The central **78.25%** assumption is 12.35 percentage points above that boundary. The modeled bypass risk remains **material**: it is not fatal by definition, but the BRM loses its first-place founder-accessible ranking if the complete AI-agent shock reduces its retained function below approximately **65.9%** while the other assumptions remain unchanged.

This is a structural threshold, not a probability that clients will bypass the platform. Estimating that probability requires observed experiments comparing the direct-agent and BRM routes.

The arithmetic is exact given the stated weights. The weights are scenario assumptions and must be tested with real provider-response, completion, privacy and agent-bypass data.

Consider the set **F** of business-model architectures under comparison. For every model **m**, define:

- **Φₘ:** accumulated founder work retained after a competitor reproduces the software and reaches complete feature parity;
- **Uₘ:** retained underlying function after AI production and task substitution;
- **Aₘ:** retained channel role after autonomous agents can discover and coordinate alternatives;
- **Ψₘ = Uₘ × Aₘ:** retained relevance after the complete AI-agent shock; and
- **Ωₘ = Φₘ × Uₘ × Aₘ:** accumulated founder work remaining relevant after all three filters.

### Proposition 4 — Conditional resilience dominance

If:

```text
ΩBRM > Ωₘ  for every other model m in F
```

then the BRM is the uniquely most shift-resilient model in **F**.

**Proof.** By definition, **Ωₘ** is the surviving fraction after both shocks. If the BRM's fraction is strictly greater than every alternative's fraction, it is the unique maximiser:

```text
BRM = the model with the highest Ωₘ in F
```

□

This theorem does not refer to profit, revenue, CAC, five-year returns or probability of commercial success. Its conclusion is only about structural survival through software copying and AI task substitution.

### 17.1 Deterministic resilience stress test

The reproducible implementation in `scripts/simulate_business_models.py` compares 23 archetypes. For every model—not only marketplaces—it declares low, central and high scenarios for **Φ**, **U** and **A**, then calculates:

```text
Ωₘ,scenario = Φₘ,scenario × Uₘ,scenario × Aₘ,scenario
```

The scenarios are not probabilities or financial forecasts. They are explicit assumptions that can be challenged and replaced with observed asset-retention measurements.

The autonomous-agent channel factor **A** is applied to all 23 models. Its central value asks how much of the model's remaining role survives when a client agent can discover, compare, contact, purchase and coordinate alternatives:

| Model | Central A | Why autonomous agents do or do not bypass it |
|---|---:|---|
| Sovereign / statutory monopoly | 100% | An agent cannot route around legal authority. |
| Infrastructure / protocol | 98% | Agents usually consume the established rail rather than reproduce it. |
| Physical / franchised network | 97% | Agents can choose operators, but physical assets and territorial execution remain. |
| Managed marketplace | 92% | Direct search does not reproduce dispatch, standards, fulfilment or accountability. |
| Blind reverse regulated marketplace | 78.25% | Public search is bypassable; private supply, privacy, sealed comparison, response incentives and outcomes remain. |
| Community business | 90% | Agents can find information but do not reproduce member identity, relationships and belonging. |
| Proprietary data / API | 90% | Agents often become customers of exclusive data rather than substitutes for it. |
| B2B enterprise / vertical SaaS | 90% | Contracts, stored records, permissions, integrations and embedded workflows restrict bypass. |
| App-enabled marketplace | 65% | Agents can source visible providers directly, while some liquidity and transaction trust remain. |
| Open marketplace | 60% | Public identities, listings and multihoming make direct agent contact comparatively easy. |
| Ecommerce / DTC | 78% | Shopping agents increase comparison and channel substitution, while brand and controlled supply remain. |
| Mobile game | 92% | An agent can recommend or purchase the game but does not replace entertainment and social play. |
| B2B self-serve / PLG SaaS | 75% | Agents can select, combine or recreate tools; integrations and collaborative state preserve part of the channel. |
| In-app-purchase content app | 75% | Agents can find substitutes, while exclusive catalogues, progression and collections retain users. |
| Platform-integrated utility | 75% | The operating-system agent can absorb the interface, but permissions and deep integration preserve part of the utility. |
| B2C subscription software / app | 70% | Personal agents can reproduce or assemble many functions; habit, state and brand retain part of the relationship. |
| Freemium software / app | 65% | Agents can route users among interchangeable free tools with little switching friction. |
| Content / media | 50% | Agents can search, summarize and synthesize public content without sending the audience to its source. |
| Advertising-supported app | 55% | Agent-mediated answers reduce direct attention and therefore weaken the advertising channel. |
| Paid macOS / Windows desktop app | 65% | System agents can perform or orchestrate many utilities without opening the application. |
| Digital agency / remote professional service | 60% | Client agents can coordinate tools and specialists after production work itself has already been automated. |
| Paid mobile app | 60% | Mobile agents and operating-system features can route around standalone app interfaces. |
| Feature / AI wrapper | 60% | Agents can call the underlying capability or substitute another implementation directly. |

These **A** values are independent of **U**. For example, people may still need ecommerce products (**U** remains high) while shopping agents weaken the merchant's direct customer channel (**A** falls). Conversely, agency work is hit twice: AI reduces how much external production is required (**U** falls), and client agents reduce the need for agency coordination (**A** also falls).

| Rank | Model | Φ | U | A | Combined Ω |
|---:|---|---:|---:|---:|---:|
| 1 | Sovereign / statutory monopoly | 99% | 99% | 100% | **98.0%** |
| 2 | Infrastructure / protocol | 94% | 95% | 98% | **87.5%** |
| 3 | Physical / franchised network | 88% | 97% | 97% | **82.8%** |
| 4 | Managed marketplace | 82% | 95% | 92% | **71.7%** |
| 5 | **Blind reverse regulated marketplace** | **86%** | **100%** | **78.25%** | **67.3%** |
| 6 | Community business | 70% | 90% | 90% | 56.7% |
| 7 | Proprietary data / API | 75% | 70% | 90% | 47.2% |
| 8 | B2B enterprise / vertical SaaS | 65% | 80% | 90% | 46.8% |
| 9 | App-enabled marketplace | 70% | 90% | 65% | 41.0% |
| 10 | Open marketplace | 72% | 92% | 60% | 39.7% |
| 11 | Ecommerce / DTC | 55% | 88% | 78% | 37.8% |
| 12 | Mobile game | 42% | 80% | 92% | 30.9% |
| 13 | B2B self-serve / PLG SaaS | 58% | 65% | 75% | 28.3% |
| 14 | In-app-purchase content app | 48% | 65% | 75% | 23.4% |
| 15 | Platform-integrated utility | 60% | 50% | 75% | 22.5% |
| 16 | B2C subscription software / app | 50% | 55% | 70% | 19.2% |
| 17 | Freemium software / app | 48% | 50% | 65% | 15.6% |
| 18 | Content / media | 55% | 55% | 50% | 15.1% |
| 19 | Advertising-supported app | 42% | 65% | 55% | 15.0% |
| 20 | Paid macOS / Windows desktop app | 40% | 50% | 65% | 13.0% |
| 21 | Digital agency / remote professional service | 55% | 35% | 60% | 11.5% |
| 22 | Paid mobile app | 35% | 40% | 60% | 8.4% |
| 23 | Feature / AI wrapper | 12% | 45% | 60% | 3.2% |

#### Founder-accessible digital-model ranking

The overall ranking includes architectures that ordinarily require sovereign authority, institution-scale coordination, extensive physical capital or responsibility for managed fulfilment. Removing those access classes leaves the models that a capital-constrained digital founder could reasonably attempt to establish:

| Founder-accessible rank | Business model | Combined Ω | Eligibility |
|---:|---|---:|---|
| 1 | **Blind reverse regulated marketplace** | **67.3%** | Eligible |
| 2 | Community business | 56.7% | Eligible |
| 3 | Proprietary data / API | 47.2% | Eligible |
| 4 | B2B enterprise / vertical SaaS | 46.8% | Eligible |
| 5 | App-enabled marketplace | 41.0% | Eligible |
| 6 | Open marketplace | 39.7% | Eligible |
| 7 | Ecommerce / DTC | 37.8% | Eligible |
| 8 | Mobile game | 30.9% | Eligible |
| 9 | B2B self-serve / PLG SaaS | 28.3% | Eligible |
| 10 | In-app-purchase content app | 23.4% | Eligible |
| 11 | Platform-integrated utility | 22.5% | Eligible |
| 12 | B2C subscription software / app | 19.2% | Eligible |
| 13 | Freemium software / app | 15.6% | Eligible |
| 14 | Content / media | 15.1% | Eligible |
| 15 | Advertising-supported app | 15.0% | Eligible |
| 16 | Paid macOS / Windows desktop app | 13.0% | Eligible |
| 17 | Digital agency / remote professional service | 11.5% | Eligible |
| 18 | Paid mobile app | 8.4% | Eligible |
| 19 | Feature / AI wrapper | 3.2% | Eligible |
| Not eligible | Managed marketplace | 71.7% | Capital-intensive |
| Not eligible | Physical / franchised network | 82.8% | Capital-intensive |
| Not eligible | Infrastructure / protocol | 87.5% | Institution-scale |
| Not eligible | Sovereign / statutory monopoly | 98.0% | Sovereign-only |

The non-eligible architectures are deliberately shown at the end rather than silently removed. Their scores remain higher where indicated; their placement at the end means “outside this feasibility set,” not “weaker.” “Founder-accessible” is a feasibility filter, not a claim that eligible models are easy or inexpensive. It excludes the managed marketplace because taking responsibility for fulfilment, guarantees and remediation normally creates materially greater operating capital, staffing, insurance and liability requirements. A sufficiently financed founder could still attempt it.

### 17.2 Interpretation

Across every benchmark, statutory monopoly ranks first, infrastructure/protocol second and physical/franchised networks third. These models depend on legal authority, underlying rails or substantial physical coordination and are not ordinary founder-accessible digital architectures.

The **blind reverse regulated marketplace ranks fifth overall and first among founder-accessible models**. Under the central assumptions, 67.3% of accumulated founder work remains relevant after both complete feature parity and mainstream autonomous buyer-agent substitution.

Its result follows from the conjunction of:

- low dependence on unique visible software;
- accumulated demand and qualified local supply;
- network liquidity and trust;
- private transaction and outcome data;
- participant and institutional relationships;
- controlled information flow;
- repeatable operating knowledge; and
- regulated or physical completion that AI agents cannot entirely substitute.

The managed marketplace retains 71.7% but requires greater operational control, capital and liability. Community businesses retain 56.7%, 10.6 percentage points below the BRM. Open marketplaces fall to 39.7% because buyer agents can search their public supply directly; visible identities and multihoming make bypass easy. Digital agencies retain only 11.5% because AI can perform much of the delivery and client agents can also replace agency coordination.

### 17.3 What remains to be proved empirically

The arithmetic ranking is exact given the stated inputs. The inputs themselves are not yet facts. To turn the conditional result into an empirical proof, the paper must estimate for every model:

1. the share of accumulated founder effort stored in code, distribution, network, trust, data, relationships, operations and permissions;
2. the retention of each asset after complete software parity; and
3. the share of the surviving system's underlying function that AI agents cannot substitute.

For marketplaces in particular, the test must also measure provider discovery coverage, valid contact coverage, response rates, qualification accuracy, offer comparability, buyer privacy, completion reliability and the share of supply or outcome data unavailable to a general web-search agent. Otherwise **Ψ** merely assumes the answer to the buyer-agent threat.

The conclusion changes only if revised measurements cause another model's **Φₘ × Uₘ × Aₘ** to exceed the BRM's. This makes the thesis falsifiable without introducing profitability or commercial-success probabilities.

## 18. Why the model may justify long-term founder investment

Under the thesis, a year of work is not stored mainly as another set of features. It is distributed across:

- search authority and trusted demand channels;
- active, verified providers;
- request and pricing history;
- observed outcomes;
- local institutional knowledge;
- matching accuracy;
- operating procedures; and
- market reputation.

A competitor can copy the intake form, bidding workflow and interface without acquiring those assets. The founder can therefore continue investing even while assuming that all visible software will eventually be reproduced.

This does not remove business risk. Demand can fail, regulations can change, providers can multihome, an incumbent can enter, and operations can become uneconomic. It changes the dominant risk from “someone copied my feature” to harder business problems whose solutions can themselves accumulate as assets.

## 19. Strongest arguments against the thesis

1. **The word “all” is too broad.** Many attainable businesses have durable brands, exclusive rights, physical assets, communities or switching costs without using a marketplace.
2. **Blindness is copyable.** An entrant or established directory can adopt the same disclosure mechanism.
3. **Distribution may dominate architecture.** A competitor with an existing audience can acquire both marketplace sides faster.
4. **Trust may require identity.** Buyers of consequential services may refuse to compare anonymous providers.
5. **Strong providers may not bid.** Firms with sufficient inbound demand may avoid opaque or paid opportunities.
6. **Local markets fragment network effects.** Andorran supply does not automatically strengthen Cyprus or Dubai liquidity.
7. **Relocation is often one-time.** Low transaction frequency weakens retention and some conventional network effects.
8. **Real-world friction can become pure burden.** The same complexity that deters entrants may consume effort without creating a reusable asset.
9. **AI may move beyond code.** It may increasingly automate research, qualification, matching, documents, sales and parts of professional service delivery.
10. **Managed marketplaces may capture more value.** Taking responsibility for price and fulfilment can produce stronger retention, although with much higher capital and liability.
11. **No architecture creates demand.** A durable marketplace with uneconomical acquisition is not a valuable business.
12. **A focused SaaS can be highly durable.** Systems of record, regulated software and deeply integrated workflow products may have very high switching costs.

A credible paper must try to defeat the thesis with these cases rather than define them away.

## 20. Empirical research programme

### Establish the 2026 software premise

- measure time and cost for independent teams to reproduce bounded product functionality with and without AI;
- separate prototype parity from secure, compliant production parity;
- measure feature convergence and customer switching, not only generated code;
- repeat the experiment as tooling changes.

### Estimate founder-capital durability

- estimate replacement cost for each asset class;
- simulate a competitor receiving the full observable product specification;
- estimate which assets remain exclusive after 30, 180 and 365 days;
- estimate customer and provider migration under feature and price improvements;
- calculate low, central and high measurement cases for **Φₘ**.

### Estimate AI task substitution

- decompose each model's delivered outcome into tasks;
- test which tasks an autonomous agent can complete without the incumbent;
- distinguish technical automation from legally accountable or physical completion;
- estimate low, central and high cases for **Ψₘ**; and
- calculate the surviving founder-work fraction **Ωₘ = Φₘ × Uₘ × Aₘ**.

### Run the autonomous buyer-agent bypass test

- give independent agents the same buyer request and permit them to search Google, Google Maps, directories and provider websites;
- let the agents contact providers by email and website form, follow up, qualify replies and normalize offers;
- compare their provider coverage, response rate, time to usable offers, offer comparability, privacy exposure and completed-service quality with the BRM route;
- measure the share of payments, milestones, completion evidence, guarantees, disputes and remediation actually governed by each marketplace;
- repeat the test for public providers, verified BRM providers and providers that prioritize or participate only through the platform; and
- replace the assumed **78.25%** BRM task-retention value with the observed retained function.

### Test the BRM mechanisms

- randomise identity-disclosure levels and measure trust, conversion and bypass;
- compare sealed and visible bidding on price, scope and realised quality;
- estimate effective liquidity as qualified supply grows;
- measure whether private data improves matching or fraud detection;
- track provider participation, multihoming and churn.

### Compare general models

- apply the same asset decomposition to SaaS, agencies, ecommerce, data businesses, communities, open marketplaces and managed marketplaces;
- compare software-parity retention, AI-function retention, autonomous-agent channel retention and combined resilience;
- publish cases that contradict the proposed ranking;
- report sensitivity to alternative asset weights and substitution assumptions.

## 21. Provisional conclusion

The paper's strongest defensible conclusion is:

> As software reproduction becomes cheaper and AI agents substitute digital work, long-term founder security depends on the fraction of accumulated work that survives both shifts. A blind reverse marketplace in a high-value, locally regulated market preserves network liquidity, trust, proprietary data, local relationships, controlled information flow and operational knowledge while its underlying real-world function remains necessary. Its durability increases further to the extent that it governs payment, milestones, completion evidence, guarantees and remediation rather than stopping at an introduction.

Under the stricter central scenario that includes autonomous buyer agents, the BRM retains **ΩBRM = 67.3%**. It ranks behind sovereign/statutory monopoly, infrastructure/protocol, physical/franchised networks and a capital-intensive managed marketplace, but ahead of every founder-accessible digital model in the comparison.

That lead is conditional, not automatic. A BRM that is only a free search form over publicly discoverable providers can be bypassed by a client agent. The defensible version must accumulate private or platform-prioritizing supply, current qualification and capacity data, provider response incentives, comparable sealed offers, controlled identity disclosure, verified outcomes and accountable completion. Its strongest strategic position is to accept requests from client agents and become their trusted supply-and-transaction infrastructure rather than compete with them as another search interface.

The arithmetic proves that ranking given the stated inputs. Establishing it as a real-world result requires empirical estimates of **Φ**, **U** and **A**, including observed transaction and fulfilment control, using the same two shocks for every competing model.

## 22. Next extensions

- Formalise observable weights for each founder-capital component.
- Specify customer and provider migration after a software-parity shock.
- Specify task-level substitution tests for AI agents.
- Derive equilibrium provider participation under sealed pay-per-bid procurement.
- Model local-market fragmentation and cross-market data transferability.
- Build a reproducible comparison dataset covering general business-model families.
- Replace scenario assumptions with measured retention and substitution ranges.

## 23. Mathematical validity of the motivating formulas

The original concept supplied useful intuitions but several illustrative equations must be treated as hypotheses rather than proofs:

1. **Exponential SaaS decay.** `V₀ × e^(−α × KAI × t)` assumes the decay law and its rate. It can be fitted to observations, but choosing `KAI = 0.95` and `α = 1.5` does not demonstrate that code loses 75% of its value. The present paper instead measures asset retention after an explicit parity shock.
2. **The D × S network score.** This counts possible demand–supply pairs under strong homogeneity assumptions. It is neither euro value nor proof of quadratic growth. Section 7 replaces it with expected feasible fulfilment using match probabilities.
3. **The leakage fraction.** `Ivisible ÷ (Tfee + Ftrust)` divides a unitless visibility index by monetary quantities and therefore cannot be a probability without calibration. Zero visible identity removes the direct pre-disclosure contact route, but does not eliminate inference, external discovery, collusion or post-match bypass.
4. **The autonomy ratio.** Founder hours divided by total system uptime mixes unlike units. Autonomy may be operationally relevant, but it is not part of the paper's shift-resilience metric.
5. **The replication-resistance ratio.** Real-world operations and specialist knowledge can increase replication cost, but multiplying subjective zero-to-one scores and dividing by an undefined number of developers does not yield an identified economic quantity. Section 12 uses observable replacement-cost components instead.

Correcting these formulas does not weaken the motivating thesis. It converts it from persuasive numerology into a falsifiable claim with explicit assumptions, units and measurements.

## References

1. Rysman, M. (2009). [The Economics of Two-Sided Markets](https://doi.org/10.1257/jep.23.3.125). *Journal of Economic Perspectives*, 23(3), 125–143.
2. Hagiu, A. & Wright, J. (2024). [Marketplace Leakage](https://doi.org/10.1287/mnsc.2023.4757). *Management Science*, 70(3).
3. Teh, T-H., Liu, C., Wright, J. & Zhou, J. (2023). [Multihoming and Oligopolistic Platform Competition](https://doi.org/10.1257/mic.20210324). *American Economic Journal: Microeconomics*, 15(4), 68–113.
4. Athey, S., Levin, J. & Seira, E. (2011). [Comparing Open and Sealed Bid Auctions: Evidence from Timber Auctions](https://doi.org/10.1162/REST_a_00069). *Quarterly Journal of Economics*, 126(1), 207–257.
5. Cui, K. Z. et al. (2026). [The Effects of Generative AI on High-Skilled Work: Evidence from Three Field Experiments with Software Developers](https://doi.org/10.1287/mnsc.2025.00535). *Management Science*.
6. Becker, J. et al. (2025). [Measuring the Impact of Early-2025 AI on Experienced Open-Source Developer Productivity](https://arxiv.org/abs/2507.09089). Randomised study illustrating that AI-development effects remain task- and context-dependent.

These references establish surrounding theory and evidence. None independently proves the proposed durability ranking.
