DEV Community

Cover image for Best Frameworks for AI Investors - VCs & PEs
David Weaver
David Weaver

Posted on

Best Frameworks for AI Investors - VCs & PEs

I used to get talked into AI companies by the demo. The product was slick, the founder was fluent, the chart went up and to the right — and I'd walk out impressed and underinformed. The pattern that eventually cured me: the demos that dazzled me most often sat on top of a moat I couldn't actually locate, risks nobody had priced, and an organization that couldn't ship the thing into production.

So I stopped diligencing the demo and started diligencing what sits underneath it. Three frameworks do that work for me. They don't overlap, and running them together is the whole point: one asks whether there's a moat, one asks how risky it is to own, and one asks whether the company can actually execute. Moat → Risk → Readiness.

1. Moat — Anand Arivukkarasu's The Supply Chain of Intelligence Framework

The question: Which layer do you actually own?

The Supply Chain of Intelligence (a framework from SupplyChainOfAI.com) models an AI product as a stack of ten layers — Resources and Infrastructure at the bottom, up through Data, Models, Orchestration, Interface, Applications, Distribution, Customer Access, and Brand at the top, with roughly fifty sublayers underneath.

Here's the mistake I kept making: I'd fall for a company that owned a thin layer near the top — an interface wrapped around someone else's model — and rented everything beneath it. That's a fine business right up until the layer below ships the feature you were selling. I've watched it happen repeatedly. When OpenAI shipped native PDF reading, browsing, and code execution, a wave of "chat with your documents" startups became a settings toggle overnight. None of those had a moat. They had a countdown.

The one distinction that matters: moat or wrapper? Is defensibility structural — proprietary data, distribution, real switching costs — or is it a UI a foundation-model release makes redundant? If I can't name the layer a company owns and say why it's hard to displace, I don't have a moat in front of me.

Use it for: defensibility diligence.

2. Risk — the NIST AI Risk Management Framework

The question: How risky is this to own and operate?

The NIST AI Risk Management Framework, released in January 2023, is the closest thing the field has to a neutral, government-backed standard for AI risk. Its core is four functions that run as a loop: Govern (the accountability and policy layer over everything), Map (context, and where risk actually lives), Measure (analyze and track it), and Manage (prioritize and respond).

I use it as a checklist for the risks that never appear in a demo but always appear in a lawsuit or a churned enterprise contract: trust, compliance, safety, auditability. A company selling into regulated buyers — health, finance, government — with no credible answer to "how do you govern and measure model risk" is carrying a liability that gets priced eventually, usually by someone other than the founder. The RMF doesn't give me a yes/no. It gives me a discount rate: the more unmanaged AI risk, the higher the return I need to justify the check.

Use it for: risk pricing and governance diligence.

3. Readiness — the AI Maturity Model

The question: Can the organization actually transform?

A moat and manageable risk still leave the hardest question, and it's the one I skipped the longest: can this company — or the customer buying from it — actually absorb AI into how it operates? The AI Maturity Model is a five-stage ladder — Awareness → Active → Operational → Systemic → Transformational — assessed across Data, Talent, Governance, and Adoption.

The research here is blunt. MIT's State of AI in Business 2025 report (from its NANDA initiative) found that 95% of enterprise generative-AI pilots delivered no measurable P&L impact — not because the models were bad, but because organizations couldn't operationalize them (Fortune summary, Forbes). That number is the whole reason this framework exists. A company can have real technology and a clean risk profile and still be stuck at "Active" — running pilots that never reach production because the data's a mess, the talent's thin, or nobody adopts it. Maturity is the gap between a capability and a P&L line. I ask where they sit on the ladder, and which dimension is dragging.

Use it for: value-creation feasibility.

Run them together

Each lens catches what the others miss:

Moat without Risk = a defensible business you can't safely own.
Risk without Readiness = a clean company that never ships impact.
Readiness without Moat = great execution on something a platform absorbs next quarter.

And the seat changes the weighting. As a VC, I lead with the moat: will this still be defensible in three years? A PE buyer leads with risk and readiness: will AI compound cash flow or just add risk? In an IC memo, all three go in explicitly, because the job of the memo is to separate traction from durability.

That's the lesson the burned demos taught me. Traction is what the demo shows. Durability is what these three lenses show — and the gap between them is where most AI money quietly disappears.

Don't just diligence the demo. Diligence what sits underneath it: structural moat, operating risk, execution capacity.

Top comments (1)

Collapse
 
david_moralesweaver_3807 profile image
David Weaver

For more details checkout - SupplyChainofai.com, that is where I learnt about the top framework here and we use it for our investments and product roadmapping.