Anthropic, Glean & OpenRouter: How AI Moats Are Built with Deedy Das of Menlo Ventures
Summary
Glean’s real moat is accumulated enterprise drudgery, not an “AI search” slogan. Deedy Das says enterprise search “shut down the conversation” at Bay Area parties in 2019, but three years of permissions, connectors, ranking, freshness, evaluation, and adoption work positioned Glean for ChatGPT to accelerate its go-to-market. At a $7 billion valuation and several hundred million dollars of revenue, his formulation is blunt: “The moat is just we did the hard work.”
Anthropic’s revenue curve exceeded even its investors’ most optimistic case. Menlo first invested at roughly a $4 billion valuation when Anthropic had no revenue; Deedy describes a climb from $0 to $100 million in one year, $100 million to $1 billion in another, and a public projection from $1 billion to $9 billion this year. His call is that Anthropic is “the fastest growing software company of all time,” while explicitly conceding that nobody predicted this outcome.
Enterprise API share suggests durable model plurality, but Deedy would not underwrite a round north of $170 billion on share alone. Menlo’s surveyed spend data put OpenAI at roughly 50% and Anthropic at 12% in 2023, versus 25% and 32% respectively by mid-2025; these are enterprise LLM API dollars, not token volumes. At today’s scale, “revenue, margin and trajectory” matter more, alongside credible new markets and products.
The discussion weighs model-layer defensibility against thinner app-layer moats. Deedy’s asymmetric test is that Anthropic could enter an application category more readily than an app company could become Anthropic, especially while most AI apps still lack a sufficiently “meaty layer” above the models. Claude Code strengthens the case through usage and data flywheels, but he rejects the idea that it is universally preferred and warns that labs may eventually compete with businesses generating their token demand.
The $100 million Anthology Fund is a model-provider ecosystem fund designed to avoid conventional corporate-venture incentives. Menlo manages it externally because internal funds tend to prioritize “who uses my stuff the most,” while Anthology can back strategically important companies, heavy Claude users, or exceptional early founders without requiring any particular model. It has funded about 40 companies, with checks from $100,000 to $20 million; Deedy says its companies graduate to subsequent rounds at a significantly higher rate.
OpenRouter is Deedy’s exemplar of a PLG infrastructure moat built from annoying details others underestimate. The host says the company takes roughly 5% of routed spend; Deedy emphasizes its mindshare, provider-level performance data, privacy routing, and a product developers can use without sales calls. Its real risks are equally concrete: falling token prices compressing the fee pool, hobbyist churn, and enterprises using it for evaluation before contracting directly with a model provider.
The research portfolio is a set of hedged bets on futures that might become necessary, not confidence that every architecture wins. Goodfire’s mechanistic interpretability is “brain surgery for LLMs” aimed at making consequential model decisions inspectable; the host frames diffusion language models as delivering 80–90% of current quality at one-tenth the cost and latency; and the discussion identifies distributed training, talent access, and a broader vision as possible Prime Intellect upside. Deedy repeatedly stresses that strong technology can still lose to timing and market structure.
Coding agents create a paired security and human-capital risk: people may execute code they cannot inspect while losing the ability to reason through it. A host recounts a purported fake interview repository that allegedly concealed a data-exfiltration link inside a byte array, which Cursor reportedly detected; the same tools can become a “constant slot machine” of “please fix” prompts. The hosts’ proposed counter-model is fast, human-in-the-loop assistance that helps engineers read the right files while they still write and understand the code.
Deep dive
1. Glean’s moat is the unglamorous work competitors avoided
Deedy’s retrospective begins in 2019, when saying “enterprise search” at Bay Area parties would immediately shut down the conversation. Glean spent the unfashionable years building the underlying retrieval system; ChatGPT’s arrival in December 2022 accelerated its sales motion rather than rescuing a product that had never worked.
The business he describes is attractive for conventional enterprise reasons: top-down sales, easy contract expansion, painful rip-and-replace dynamics, and a TAM spanning virtually every knowledge worker. He remains comfortable owning Glean stock partly because its valuation is about $7 billion, “not $100 billion,” with considerable room left to grow.
Deedy rejects the compressed venture narrative that Glean built failed search and then attached AI. His less glamorous explanation is that the company handled the integrations, permissions, customer-specific exceptions, and “last mile stuff” before the category became crowded: “It’s not a moat. The moat is just we did the hard work.”
2. Data gatekeepers and frontier labs do not automatically erase Glean
On SaaS vendors restricting API access, Deedy questions the first-principles business logic. Glean only exposes Slack results to users who already hold the relevant permissions; it neither resells one licensed seat to a thousand people nor removes revenue from Slack. More use of Slack data could, in his framing, support additional seat sales.
His second defense is diversification: Glean has thousands of integrations. Slack may be critical for many enterprises, but one provider closing access is less damaging than a coordinated shutdown across the ecosystem—an outcome he acknowledges “could be more problematic.”
Customers supply the third pressure point: they believe they bought the software and own the resulting data. Their objection is straightforward—“You don’t own the data”—so blocking an API that connects their information to another purchased product creates conflict with the customer, not merely with Glean.
Anthropic or OpenAI can build a semireasonable enterprise-search tool, but Deedy doubts they will fund the depth required. A $100,000, $200,000, or even seven-figure customized sale barely moves a company with $5 billion-plus revenue, while requiring big sales teams, large FTE teams, and extensive customization. “You joined a big AI lab to work on models, not to build Google Drive connectors.”
3. Enterprise search requires different ranking signals and forced distribution
Consumer search improves through immense behavioral datasets—clicks, hovers, dwell time, and repeated queries. At a 10,000-person enterprise, even two to five searches per employee per day produce too little feedback to power the same machinery, forcing Glean to invent a different signal stack.
Enterprise queries are also fresher and less head-heavy. Beyond shared terms such as “benefits” or “payroll,” employees search for highly specific material tied to distinct jobs, so the distribution lacks the repetitive consumer head that makes conventional ranking easier.
Evaluation becomes unusually opaque because engineers often cannot understand the customer’s query, documents, or correct ordering. Deedy recalls teams examining specialized customer data and admitting, “We have actually no idea what we’re doing”—not because ranking was arbitrary, but because ground truth lived inside an unfamiliar business domain.
Adoption was as hard as relevance. Productivity tools are retained because employees like them, not because buyers prove a precise ROI, yet search lacks Slack’s network effects. Glean therefore asked what it had to do to “earn the right” to own the new-tab page and used a Chrome extension to replace native Google Drive search after evaluating itself as better.
4. Anthropic paired an unprecedented curve with an unusually permissive culture
The hosts remember Claude’s earliest interface as tagging a bot inside Slack: Claude 1 arrived in March 2023 and Claude 2 in July 2023. That awkward Slack-based beginning contrasted with the later products that conventional product management might never propose.
Menlo first invested when Anthropic had no revenue at roughly a $4 billion valuation. Deedy cites $0 to $100 million in one year, $100 million to $1 billion in the next, and a public $1 billion-to-$9 billion projection this year; the result was “beyond our wildest expectations.”
Deedy saw an idealistic research team with an unusually wide distribution of outcomes: the same traits could have made Anthropic “fizzle to the ground” or produce a generational company. The host points to Claude Code as a rare post-chat product innovation delivered through a terminal, “every PM’s nightmare,” while Deedy’s own explanation is that good talent given room and many tokens tends to build good things.
The culture appears freer and less prescriptive than other labs, with cited estimates putting one-year employee retention around 80%. Anthropic can omit image generation and an IMO gold-medal model, sell out “thinking caps,” and still gain affection by doing its own thing; meanwhile, the honest billboard “My boss really wants you to know that we’re an AI company” captured widespread workplace confusion.
5. Market share measures the opportunity, while economics underwrite the valuation
Menlo’s enterprise survey showed OpenAI moving from about 50% of LLM API spend in 2023 to 25% by mid-2025, while Anthropic moved from 12% to 32%. The hosts emphasize two caveats: this is enterprise API spend—the market Anthropic targets—not token share, and it is estimated by surveying many enterprise users.
The more important conclusion is plurality, not an OpenAI collapse. Enterprises now have several credible frontier choices, and once a model fits a production workload they often reserve long-duration compute or dedicated instances. That commitment makes enterprise behavior far stickier than hobbyist developers switching between whichever model looks best that week.
Asked how a current investor should evaluate Anthropic, Deedy strips away the vanity metrics: “Here’s the revenue, here’s the margin and here’s the trajectory.” Market share mostly helps estimate the TAM ceiling; underwriting a round north of $170 billion also requires believable markets the company is entering or preparing to enter.
His temperament remains deliberately paranoid: a strong current result prompts “Great, now let’s make it last” and “What’s next?” The value lies in future models, products, distribution, and further share gains—not celebrating today’s percentage as if it were an irreversible “flippening.”
6. Coding keeps model intelligence monetizable while application moats remain thin
Deedy argues that better general intelligence may no longer improve retention for most consumer chat users. Perhaps fewer than 10 million need frontier reasoning, while many of ChatGPT’s cited 800 million users want help fixing a dishwasher or rewriting an email—tasks already handled well enough. In that qualified sense, OpenAI “kind of won” consumer chat.
Coding is different because its quality frontier may keep moving indefinitely. Anthropic can translate better models into better coding products and additional revenue in a way that another increment of intelligence might not move a mature consumer assistant; still, Deedy warns that cost and the quality-price Pareto frontier remain material.
He declines to discuss Claude Code’s margins, but frames Anthropic’s broad strategy as “scale fast, keep it cheap, get everybody on it.” Cheap access supports Cursor, Devin, Cognition, Bolt, Lovable, and other businesses; it also gives Anthropic a usage-and-data flywheel for improving its own product.
The host calls Claude Code the best way to use Claude; Deedy pushes back that Cursor and Devin retain loyal users. His broader moat test survives the disagreement: current app layers are not yet thick enough to block a well-distributed lab from entering, whereas an app cannot readily recreate the model lab. The long-run Amazon-style risk is that the owner of production eventually enters customers’ categories.
7. Rahul Patil’s rise challenges credential-driven ceilings
Deedy describes Indian academics as culturally comparable to American sports because education is widely treated as a route to social mobility. Roughly one million people take the JEE engineering exam, the top 10,000 enter IIT, and only about 200 reach computer science—an extreme ranking system whose labels can follow people for years.
His concern is both institutional and psychological. Some workplaces judge workers by what they previously achieved rather than the quality of present work, while people internalize early rejection: “I couldn’t get into a good college, therefore I am stupid, and therefore I should not work that hard.”
Rahul Patil becoming Anthropic’s CTO despite not attending what Deedy considers a top Indian university represents a counterexample. The host adds an important qualification: escaping the credential path also requires selecting strong companies, opportunity, and luck. Deedy’s narrower claim is that meritocratic environments can let sustained work overturn early constraints.
8. Anthology separates ecosystem strategy from investment judgment
Menlo and Anthropic established the $100 million Anthology Fund around the beginning of the prior year. They deliberately kept it outside Anthropic because an internal corporate-venture team would require separate staffing and might optimize for usage of the parent company’s product rather than investment returns.
The portfolio now contains about 40 companies, including OpenRouter, Goodfire, Prime Intellect, and Wispr Flow. Deedy says the rate of companies progressing to another round is significantly higher for Anthology Fund companies.
Its mandate has three buckets: strategically important businesses, companies using Claude heavily that are compelling in their own right, and very early founders with high potential. Anthology does not require a specific model and can write anything from a $100,000 participation check to a $20 million lead.
Smaller initial checks let Menlo build relationships before potentially leading later rounds, while events connect founders directly with Anthropic founders and executives. Anthropic’s evolution from unknown lab to major platform now reduces the informational advantage of mere proximity, so the fund is still reconsidering how to remain useful to both sides.
9. Research investing works backward from a necessary future
Deedy calls research investing extremely difficult but potentially remarkable. The recurring board-level tension is whether to monetize a promising capability at a few million dollars of ARR or continue funding research that might yield a much larger product: “Do I start doing something, or do I keep the research bet running?”
His method is to follow unusually capable people, then fast-forward ten years and ask what is highly likely to exist. If the future need is persuasive and the team is moving toward one plausible path, he can draw a “dotted line” between today’s research and a future business without pretending the route is certain.
Goodfire fits because consequential models remain black boxes whose evaluations describe outputs rather than internal causes. For loans, insurance, or legal decisions, “the model said so” is inadequate. Mechanistic interpretability may detect sycophancy, lying, theft, or persuasion inside the model; Deedy’s shorthand is “brain surgery for LLMs.” Scale is not the bottleneck, but access to weights is.
Prime Intellect carries the risks that initially made the hosts dismiss distributed AI, and Deedy refuses to shill it as inevitable. The discussion identifies distributed training, access to talent, and a broader unrealized vision beyond compute as possible upside. In a market changing every three or four weeks, Deedy says he would be foolish to specify exactly what it becomes.
10. OpenRouter compounds developer mindshare through operational detail
OpenRouter was Deedy’s “darling deal”—the company he wished he had built when entering venture. Its founder had previously built OpenSea, whose valuation Deedy says exceeded $10 billion at its peak, then pursued a problem engineers initially assume is easy: maintaining reliable, nuanced access to many changing models.
Deedy believed any viable gateway had to be product-led: users should self-serve without speaking to sales. OpenRouter’s developer-first homepage, usage data, and absence of generic enterprise navigation signaled that its founder understood the audience. Deedy traveled to New York and sent “love letters” after being ignored, promising to make a future financing happen.
The host says the current model takes roughly 5% of routed volume. Its two clearest risks are declining model prices shrinking that fee pool and weak retention: hobbyists churn, while enterprises may use OpenRouter to compare models and then contract directly with the winner.
Against Vercel’s AI Gateway, Deedy argues gateways will remain secondary for broader platforms, while OpenRouter already owns mindshare and neglected details. Users can route only to providers that do not retain data and compare the same model across context window, quality, latency, and throughput. Leaderboards add distribution, though free launches such as Grok Code Fast can inflate apparent popularity.
11. Wispr and diffusion models test whether execution can beat commoditization
Wispr Flow operates in seemingly commoditized voice dictation, but Deedy considers it the fastest, most accurate, and most delightful implementation. Holding a function key produces text, self-corrections such as “I didn’t mean that” are resolved automatically, and its internal “zero edit rate” is reportedly north of 80%.
The hosts press on Superwhisper, Granola, Notion, and ChatGPT adding adjacent features. Deedy does not offer a categorical moat claim; he points instead to user love, retention, and the possibility that reliable speech finally makes talking—a faster activity than typing—a comfortable primary interface.
The other bet is discussed without naming it publicly as “Stealth Co.” The host frames it as a diffusion-model approach and estimates current diffusion systems at 80–90% of current quality for one-tenth the cost and latency, potentially valuable for high-volume applications that need speed and acceptable quality rather than frontier performance.
Code may suit diffusion because dependencies are bidirectional: programmers move up and down a file, checking variables and structure, rather than reasoning strictly left to right. The host counters with the transformer “hardware lottery”—four extra years down one research path may be unrecoverable. The discussion concludes that markets routinely reward technology with momentum, not necessarily the intrinsically best idea.
12. Market timing and capital can manufacture the winner they anticipate
The hosts’ market-dynamics metaphor is a runner inside a tunnel that is closing toward the light: even the fastest runner may not escape. A founder can have an excellent idea and execution yet lack enough time to wedge into a market before larger forces shut the opening.
MosaicML illustrates the timing problem: a strong fine-tuning team faced weak open models, poor customer data, and limited expertise, although acquisition could still generate an excellent outcome. New RL environments and RFTs might reopen the window, but the original market was not ready simply because the technology was good.
AI rollups expose category arbitrage. A buyer might acquire a human-operated company with $1 million ARR for $2 million, promise automation, and receive a $100 million “AI company” valuation before delivering it. The hosts’ pushback is substantive: customers and domain expertise are the hard assets, and new equity can fund the engineers who make the original belief true.
That is reflexivity: capital can validate a narrative, recruit employees, deter competitors, and create the winner it assumed. The same debate surrounds compute: the discussion cites OpenAI spending $7 billion in a year, with $2 billion on inference and $5 billion on R&D, and asks whether future demand will justify the infrastructure being built.
13. Compute abundance still needs an economic-demand loop
The hosts see a vast physical commitment—chips, land, power, Amazon infrastructure for Anthropic, and Stargate-scale plans—as evidence that sophisticated actors expect demand. Unlike labor-heavy speculation, data-center investment can be modeled as tangible infrastructure.
Deedy works backward from the demand side: even 800 million weekly ChatGPT users do not currently require that much inference because many requests are basic Q&A. Reaching “a GPU for every human” would require far more agentic work or substantially better models that create new usage.
The unresolved wager is that more compute produces better models, which create more demand, which finances still more compute. The risk is explicit: if incremental research spending fails to deliver meaningful intelligence or economic gain, the enormous capacity may not be justified merely by today’s Claude Code, Codex, ChatGPT, Sora, and API workloads.
The disruptive opening would therefore be research efficiency: doing to OpenAI what OpenAI did to larger incumbents that were already spending heavily but did not ship the breakthrough. “Your margin is my opportunity” becomes “your R&D inefficiency is my opportunity,” though nobody claims the next lab necessarily succeeds.
14. Coding agents can weaken both software security and engineering judgment
A host recounts a purported job interview that instructed a candidate to clone a repository, run it, and make an edit. Cursor reportedly found a byte array compiling into a link that would exfiltrate private information. AI detected the trap, but developers who execute unfamiliar generated code without inspection create a much larger attack surface.
The deeper concern is craft. Engineering once built skill through prolonged frustration followed by the satisfaction of solving a hard problem; agents replace that loop with a “constant slot machine” of “Please fix, please fix, please fix.” Deedy agrees with the concern and likens it to “a cigarette for your brain.”
The hosts resist a purely abstinence-based answer: teams still must close tickets and merge pull requests. Their discussion contrasts Claude Code’s highly asynchronous behavior with fast agents that stay in a mind meld with the human during difficult reasoning and provide unobtrusive assistance.
Their proposed performance formula is simple: find the right files, then write the right files. A heads-up-display agent can improve reading and comprehension while leaving writing to the human; Cursor’s visible diffs and final acceptance offer another human-in-the-loop pattern. Deedy remains most worried about an 18-year-old student who cannot yet recognize when the model creates four unnecessary files and learns that mistake as normal engineering.