Why the Moat Isn't the Software — It's the Standard

By Anushka Appala and Dr. Janio Rosales

Ask what makes a government-technology company defensible and the instinct is to point at the software: the model, the interface, the pipeline that turns a citizen's question into a drafted form. We want to argue that this instinct, however natural, is already out of date. The software layer is commoditizing in real time. The durable position — the one worth building an institution around — is not owning the best implementation. It is defining the standard that everyone else must implement.

The commodity layer

Consider what is actually novel today and ask how long it will stay that way. A chatbot that answers questions in natural language? Available as a hosted service, improving monthly, priced toward zero. Retrieval-augmented generation over a document store — the technique that lets a model ground its answers in a specific corpus of law or policy? A well-understood pattern with open-source implementations. A dashboard that visualizes program data? A solved problem with a dozen vendors.

We say this without cynicism. These are genuinely useful capabilities and NaciluzIA uses all of them. But a capability that any competent team can assemble from off-the-shelf parts is not a moat. It is table stakes. Any government-technology strategy whose defensibility rests on "we built a better chatbot" is building on sand, because the ground under a better chatbot erodes every quarter. The market for AI in government and public services is projected to reach roughly US$98.1 billion by 2033 (Grand View Research, 2024), and a market that large does not leave a software feature undifferentiated for long. Capital floods in, the capability commoditizes, and the advantage evaporates.

Where the durable value sits

If the implementation commoditizes, what does not? The rules that govern it. When a state decides how an algorithm may participate in a public decision — what the AI is permitted to do and forbidden to do, how a binding rule must be published and versioned, what a signature must attest to, what an audit trail must contain — it is defining a standard. And a standard, once adopted, is far stickier than any single piece of software, because everything built afterward has to conform to it.

This is the position NaciluzIA is built to hold. Our core architecture is not a product to be sold and locked in. It is an open, auditable standard: AI recommends, policies decide, officials oversee, audits verify. The AI surfaces evidence and drafts; the binding action runs through a deterministic, published, versioned rules engine; a named official signs; every step lands in a tamper-evident, hash-chained ledger valid under Guatemala's electronic-signature law (Decreto 47-2008). Any vendor can build against that standard. That is the point. We are not trying to be the only company that can serve the state. We are trying to define the shape of the box that every serious company must build inside.

An open standard sounds, at first, like giving away the advantage. It is the reverse. The organization that authors the standard, stewards it, and is trusted to keep it honest occupies a position no individual application can dislodge. Implementations compete and get cheaper. The standard endures, and whoever defined it sits at the center of the market it organizes. That is why our steward is a nonprofit, co-built with UVG and USAC and the Academia de Lenguas Mayas, with a for-profit delivery arm underneath. The public interest owns the rules. The rules are the moat.

An empty rulebook, waiting to be written

Timing is what turns this from a nice idea into an opportunity. Only seven Latin American countries currently have a national AI strategy (OECD). Read that number carefully. It means the regional rulebook for how intelligence may participate in public authority is very nearly empty. There is no settled standard for what a government AI may do, no established answer for what an auditor should be able to demand, no default that vendors must conform to. The page is blank.

Blank pages do not stay blank. The rules for algorithmic governance in Latin America will be written this decade — by someone. If no one writes them deliberately, they will be written by default, one procurement at a time, in the shape of whatever autonomous decision engine happened to win the demo. That is the worst outcome: a de facto standard, assembled by accident, optimized for the vendor rather than the citizen, with no line the machine cannot cross.

The alternative is to write the rulebook on purpose, in the open, with accountability designed in from the first line — and to prove it works before asking anyone to adopt it. That is why our first step is not a regional framework but a single three-month MVP: one MIDES social program, one municipality, Spanish and Q'eqchi', simulated data, application time cut from weeks to minutes with 100% of decisions kept human. A standard earns adoption by working somewhere real first.

The software will commoditize; we are counting on it. What will not commoditize is the trusted, open, auditable standard for how a state lets intelligence into its decisions. In a region whose rulebook is still mostly blank, authoring that standard is not one advantage among several. It is the whole game.

Cada decisión, a la luz.

Anushka Appala and Dr. Janio Rosales