AI feature or AI wrapper: a decision test an investor can run
An AI wrapper is a product whose value is the model's value with a user interface on it, so that a customer with a prompt or the model provider with a feature launch could replace it. An AI feature is a product where the model does one job inside a workflow the company owns, with data, integrations and controls a competitor would have to rebuild. The distinction decides the price, because Foundation Capital's September 2026 analysis says out loud what every wrapper investor fears: the model provider that powers you can turn around and compete with you. This page gives a decision test an investor can run in an hour, using the trace and the invoices rather than the pitch.
Published September 17, 2026. Editorial.
Key takeaways
- Ask what the product is with the model removed. If the answer is a prompt and a screen, the company sells distribution, and distribution is what the model providers are now buying with their own application launches.
- The trace and the invoice classify the product faster than the deck: a wrapper has one model call per user action and an inference bill that tracks revenue one to one.
- Enterprise buyers already use many models, 37 percent running five or more according to a16z's June 2025 CIO survey, so a product whose value is one model's output has customers who can switch the model out.
- A wrapper can still be a good investment when it owns distribution, a workflow or a data loop the provider will not build; the test is whether that ownership shows up in the retention and the margin.
An AI wrapper is a product whose value is the model's value with a user interface on it. An AI feature is a product where the model does one job inside a workflow the company owns, with data, integrations and controls that a competitor, including the model provider, would have to rebuild. The difference is what an investor is paying for: in the first case, distribution; in the second, a product.
The word "wrapper" is used as an insult, and that is unhelpful, because a wrapper with distribution can be a fine business and a feature with no customers is worthless. This page gives a test that classifies the product from evidence and then asks the only question that matters for the price: what does the company own that the model provider does not?
Why does the distinction decide the price?
The distinction decides the price because the model providers are moving into applications, and a company whose product is the model's output with a screen on it is competing with its own supplier. Reveneau's diligence classifies every AI target on this axis before the margin work starts, because the classification decides which margin is being rebuilt: a wrapper's gross margin is the provider's price list, and a feature's is a design choice.
Foundation Capital's September 2026 piece on model providers and application startups makes the argument from the provider's side. Providers have a view across everything built on their APIs, can identify which use cases work, and have already shipped products that compete with companies built on them; the piece names OpenAI's agent products and Anthropic's Claude Code as examples and describes the "Windsurf saga" as a case of preferential treatment followed by competition [1]. Its conclusion is that the startups that survive own high-exception workflows, subjective success criteria and fragmented legacy systems, which is a description of the things a provider will not build.
Two buyer-side surveys show the other half. Menlo Ventures' December 2025 survey of enterprise decision-makers found 76 percent of enterprise AI solutions were bought rather than built internally, up from 53 percent in 2024 [2], which says buyers will pay for a product on top of a model. a16z's June 2025 survey of 100 CIOs found 37 percent running five or more models in production, up from 29 percent, and reported that differentiation by use case is the main reason buyers use several vendors [3]. Buyers are willing to pay for the layer above the model and are also comfortable swapping the model underneath. That combination is good for a feature and bad for a wrapper.
The decision test
The test takes an hour and uses three artefacts: the product itself, the trace from a live run, and the model-provider invoices. Run it after the claim test on how to verify an AI claim, because the trace from that session is the input here.
- Remove the model in your head. Describe the product with the model call replaced by a black box that returns nothing. What is left? A data pipeline, integrations, a permissions model, a workflow, a customer's history, a review queue? Or a text box? Write the list.
- Count the model calls per user action. From the trace. A wrapper makes one call and shows the result. A feature makes several, with retrieval, tool use and checks between them, and the user never sees most of them.
- Ask where the input comes from. If the customer types it, the product is one step from a chat window. If the product assembles it from systems the customer already runs, the integration is the asset.
- Ask where the output goes. If the user reads it and leaves, the product is a viewer. If the output writes into a system of record, triggers a workflow, or becomes training data for the next run, the product is embedded.
- Read the invoice against revenue. From rebuilding inference gross margin from invoices. A wrapper's inference bill tracks revenue one to one because every unit of value is a model call. A feature's bill is one line among several.
- Ask what changed when the model was swapped. Every company has swapped a model at least once in the last year; Anthropic and OpenAI both publish retirement schedules and both retired models in 2026. If the swap was a config change, the model is a component. If the swap broke the product, the model was the product.
- Write the classification and the reason. Wrapper, feature, or in between, with the evidence from the six steps above. The classification goes in the report next to the claim table.
What does a wrapper look like in the evidence?
A wrapper looks the same in the trace, the invoice and the retention data, and the table below is the shape to look for.
| Evidence | Wrapper | Feature |
|---|---|---|
| Model calls per user action | One, result shown directly | Several, most invisible to the user |
| Input source | Typed by the user | Assembled from customer systems |
| Output destination | Read on screen | Written to a system of record or a workflow |
| Inference bill against revenue | Tracks one to one | One cost line among several |
| Effect of a model swap | Product changed or broke | Config change, evals re-run |
| Prompt as share of the codebase | Most of the logic | A small part of a larger system |
| What a churned customer replaces it with | A chat window, or the provider's own app | A rebuild of the integrations |
The last row is the one to test against the churn data. Ask where the churned customers went. If they went to the model provider's own product or to a general chat interface, the product was a wrapper in the customer's eyes whatever the deck said.
When is a wrapper still a good investment?
A wrapper is a good investment when it owns something the provider will not build: a distribution channel into a specific buyer, a workflow with enough exceptions to need a specialist, a data loop that improves with use, or a regulatory or trust position the provider does not want. The test for each is whether the ownership shows up in the numbers.
Bessemer's August 2025 State of AI describes the fastest-growing group of AI companies as having explosive adoption, low switching costs and margin compression, and gives its gross margin as 25 percent, often negative, against 60 percent for the steadier group [4]. Low switching cost is the wrapper's weakness. Growth at 25 percent gross margin with customers who can leave for a prompt is growth the provider can take back at will. Growth at 60 percent with customers whose integrations would take a quarter to rebuild is a business.
So the questions for a wrapper's investor are: is the retention consistent with switching cost, is the margin consistent with a price above the model's price, and is there anything in the product a provider's feature launch would not cover? Data moat claims covers the data-loop version of that question, and model dependency risk covers what happens to a wrapper on the day the provider changes the price.
ICONIQ's July 2026 survey adds one detail: the companies it surveyed run 3.3 models on average and nearly half use two or more model types [5]. A product that is genuinely a feature usually shows that pattern, a cheap model for routing, a strong one for the hard step, a different one for embeddings. A product that runs one model for everything has a simpler architecture and a simpler dependency.
What if the target is a vendor rather than a startup?
If the company you are checking is a services firm claiming to be AI-native, the questions are different, because there is no product to classify and the claim is about how the work is done. Ten questions that expose a fake AI-native claim is the list for that case, and we ask people to use it on us.
What to write in the report
Write the classification, the seven pieces of evidence, and the one-line consequence for the valuation. "Wrapper: one model call per action, inference bill tracks revenue at 0.4, model swap in March broke the product for a week, churned customers report moving to the provider's app. Price as a distribution business with a supplier who is also a competitor." Or: "Feature: five model calls per action, inference at 12 percent of revenue, model swap was a config change verified by the eval suite, churned customers cite price. Price as software."
The AI startup due diligence guide treats this classification as the link between the engineering read and the money read, because the answer decides which margin you are rebuilding and how much of the technical work is worth doing. If you are building an AI product yourself and want the feature side of this line, building AI products is the guide for that.
Best for
- Any AI deal where the pitch says 'AI-powered' and the product has a text box
- A deal team deciding how to value a fast-growing product with thin margins
- A founder who wants to know which side of the line investors will put them on
Avoid if
- The company trains and serves its own models, in which case the dependency question is different
- The AI is an internal tool and the product sold is conventional software
Verify before you commit
- Count model calls per user action from a real trace, not from the architecture slide
- Rebuild inference cost against revenue for the last twelve months
- Ask churned customers, or the churn notes, what replaced the product
Common questions
What is an AI wrapper?
An AI wrapper is a product whose value is the model's output with a user interface on it, so a customer with a prompt or the model provider with a feature launch could replace it. In evidence it shows as one model call per user action, an input typed by the user, an output read on screen, and an inference bill that tracks revenue one to one. Foundation Capital's September 2026 analysis describes the risk plainly: the provider that powers you can turn around and compete with you.
How do I tell an AI feature from an AI wrapper in due diligence?
You tell an AI feature from an AI wrapper by removing the model in your head and listing what is left, then checking the trace, the invoice and the churn data. A feature has several model calls per action, inputs assembled from customer systems, outputs written into a workflow, and an inference bill that is one line among several. a16z's June 2025 survey found 37 percent of enterprise CIOs run five or more models, so a product whose value is one model's output has customers able to swap it.
Is an AI wrapper always a bad investment?
No, an AI wrapper is a good investment when it owns distribution, a workflow with many exceptions, a data loop or a trust position the model provider will not build, and when that ownership shows up in retention and margin. Menlo's December 2025 survey found 76 percent of enterprise AI solutions were bought rather than built, so buyers pay for the layer above the model. The test is whether churned customers replace the product with a chat window or with a rebuild.
Why does the model-provider invoice help classify the product?
The model-provider invoice helps classify the product because a wrapper's inference bill tracks revenue one to one, every unit of value being a model call, while a feature's inference is one cost line among several. Bessemer's August 2025 data gives the fastest-growing AI companies a gross margin of 25 percent, often negative, with low switching costs; that combination of thin margin and easy exit is what a wrapper looks like in the accounts. Rebuild the margin per customer from the invoices.
What does it mean if a model swap broke the product?
If a model swap broke the product, the model was the product, and the company is a wrapper whatever the architecture slide says. A feature treats the model as a component: the swap is a configuration change, the eval suite is re-run, and the product behaves the same. Both major providers retire models on published schedules, Anthropic with at least 60 days' notice and OpenAI with at least 6 months for generally available models, so every company has had, or will have, this test forced on it.
Do enterprise customers care whether a product is a wrapper?
Enterprise customers care about the outcome, and their behaviour shows they can swap models underneath a product: a16z's June 2025 survey of 100 CIOs found 37 percent running five or more models in production, up from 29 percent, with use-case fit the main reason for using several vendors. ICONIQ's July 2026 survey found companies running 3.3 models on average. A product whose value is one model's output is exposed to that switching; a product whose value is the workflow is not.
Can the model provider compete with a startup built on its API?
Yes, the model provider can compete with a startup built on its API, and Foundation Capital's September 2026 analysis argues it is already happening: providers see what works across everything built on them, and have shipped agent products and coding tools that overlap with companies on their platforms. The piece names OpenAI's agent mode and Anthropic's Claude Code as examples. The startups it expects to survive own high-exception workflows and fragmented legacy systems that providers will not prioritise.
How many model calls per user action should a real AI product make?
There is no correct number of model calls per user action, but the count is a fast classifier: one call with the result shown directly is the wrapper pattern, and several calls with retrieval, tool use and checks between them is the feature pattern. Read it from a real trace, not the architecture diagram. ICONIQ's July 2026 survey found nearly half of AI companies use two or more model types, which usually shows up as a cheap model for routing and a strong one for the hard step.
What should the diligence report say about an AI wrapper?
The diligence report should state the classification, the evidence from the trace, the invoice and the churn data, and the one-line consequence for the valuation: a wrapper is priced as a distribution business with a supplier who is also a competitor, and a feature is priced as software. Bessemer's August 2025 finding that the fastest-growing group runs at 25 percent gross margin with low switching costs is the benchmark for what a wrapper's numbers look like when the growth is real.
Is a prompt a moat?
A prompt gives no lasting advantage, because it is text that a competitor can approximate in an afternoon and that the next model version can make redundant. A company whose codebase is mostly prompt has told you where its value sits. What holds is what a provider will not build: Foundation Capital's September 2026 piece lists high-exception workflows, subjective success criteria and fragmented legacy systems, and Menlo's December 2025 data shows buyers pay for products above the model.
References
- Foundation Capital, When model providers eat everything: a survival guide for service-as-software startups, September 2026
- Menlo Ventures, 2025: The State of Generative AI in the Enterprise, 9 December 2025
- a16z, How 100 Enterprise CIOs Are Building and Buying Gen AI in 2025, 10 June 2025
- Bessemer Venture Partners, The State of AI 2025, 13 August 2025
- ICONIQ Growth, State of AI 2026: The Builder's Economy, July 2026
- Anthropic, Model deprecations (Claude Platform docs), read 17 September 2026
Related reading
Speed of execution is the moat now
Being first used to be a defensible lead. When any capable team can build the same thing in a week, the advantage moves to how fast you ship, learn, and ship again.
An AI demo is not a product
A convincing AI demo takes an afternoon. Turning it into something people trust in production is where most of the work, and most of the failures, live.
More in Start here
What changes in diligence when the target is an AI company?
Three things change in due diligence when the target is an AI company: the product claim becomes something you can test live and something regulators now enforce, the codebase was probably written mostly by a model so the usual quality signals mean something different, and the cost of goods is a monthly invoice from a model provider that can change its price. Everything else in a technical review stays the same. This page sets out each of the three changes, what it does to the engagement plan, and which page of this guide covers the method for it.
How to verify an AI claim with a test instead of a demo
To verify an AI claim, replace the demo with a test: supply an input the team has never seen, watch the product process it live with the trace visible, and score the output against what the claim said would happen. The test takes an hour in a screen share and needs no code access. It is necessary because a demo shows what the team chose to show, and because the SEC and the FTC now treat a false AI claim as fraud: the SEC fined two advisers a combined $400,000 in March 2024 and charged the former CEO of Nate in April 2025, alleging its app ran on contract workers. This page gives the protocol.