If you have sat in an American boardroom in the past two years, you have heard some version of the same pitch: we added AI, our product is now defensible. The framework we are describing here exists to answer that claim with a structural question instead of an enthusiastic one. Not "do users want this?" — the Jobs to Be Done literature has handled that for twenty years — but "why won't OpenAI, Microsoft or Google ship this as a checkbox next quarter and take the revenue with them?"
The Supply Chain of Intelligence is the framework's answer. It was published as a versioned paper by Anand Arivukkarasu, a product leader and angel investor based in San Francisco who previously worked on product growth at Meta across Instagram and Messenger. He gave it away, explicitly in the tradition of Wardley Maps and Clayton Christensen's disruption work: a free, citable reference rather than a consulting funnel.
The name confuses people at first, so it is worth clearing up early. This has nothing to do with freight, warehouses or container ships. "Supply chain" is the analogy, not the subject.
The one-sentence version
Intelligence is a supply chain, and value accrues at the bottlenecks — not at the most visible node.
That is the whole thesis. Everything else in the framework is the machinery for finding the bottleneck in a specific market and deciding whether you own it, rent it, or are about to be eaten by whoever does.
The analogy the author uses is gold. A gold ring involves land and mineral rights, then mining equipment, then raw ore, then a smelter, then an assay office that stamps the purity, then railroads, then a master jeweler, then a store, then the moment you wear it. Nine steps, and almost nobody in that chain owns more than one of them. The consumer only ever sees the last one. Ask where the profit sits and the answer is rarely the shop window — it is wherever supply is constrained.
The ten layers, from the ground up
The framework maps generative AI onto ten layers, numbered L-1 through L8, each subdivided further into fifty sublayers. Read from the bottom, because that is where the analogy does its work.
L-1 Resources — energy and grid interconnection, cooling water, foundry capacity, critical minerals, and the electricians and HVAC technicians who physically build data centers. American readers watching utility interconnection queues stretch past five years in Northern Virginia and Texas already know this layer is real. Nothing above it moves faster than the megawatts arrive.
L0 Infrastructure — silicon and high-bandwidth memory, data centers, interconnect fabric, and edge compute. The shovel sellers. Nvidia, AMD, TSMC, CoreWeave, Equinix.
L1 Data — public data, proprietary data, behavioral and sensor data, outcome data, synthetic data. The raw ore. Bloomberg and ZoomInfo live here.
L2 Models — foundation and multimodal models, fine-tuned specialists, embeddings, routing. The smelter. OpenAI, Anthropic, Google DeepMind.
L3 Gates — compliance and export controls, quality gates, safety and provenance, editorial and distribution gates. The assay office that stamps the gold. Vanta, Drata, OneTrust.
L4 Access — APIs, agent interface protocols, access governance, agent identity and provenance. The railroads.
L5 Execution — domain tool use, reasoning scaffolds, retrieval workflows, operating playbooks. The master jeweler. Harvey, Sierra.
L6 Orchestration — agent loops, human-in-the-loop review, task decomposition, context and state management. The workshop.
L7 Surface — conversational and visual interfaces, embedded copilots, transaction surfaces. What users touch. ChatGPT, Gemini, Copilot.
L8 Memory — session memory, user profiles, aggregated network learning, institutional knowledge, learned world models. The record book that compounds.
Those ten group into three tiers with wildly different shelf lives. The Surface is durable in weeks, because platforms ship interfaces for free. Workflow (L4–L6) is durable in months, and only if you truly own the workflow. Substrate (L-1, L0, L1, L2, L3, L8) is durable in years, because proprietary data, trust gates and compounding memory are slow to build and awkward to copy.
Four laws that do the predicting
The framework's most useful section is not the taxonomy — it is the four laws, each stated to be falsifiable, meaning a counter-example mechanism forces an amendment rather than a shrug.
One: intelligence commoditizes downward. If your product depends only on generic model capability, the layer below eventually absorbs it. The canonical American example is Jasper, valued at $1.5 billion as a writing wrapper on GPT before ChatGPT shipped the same capability directly. Wrappers do not survive; wrappers become features.
Two: value accrues at bottlenecks. Not in the model, not in the UI, but wherever supply is scarce — proprietary data, workflow control, verification, distribution, memory, compliance. Nvidia at L0. Vanta at L3. Bloomberg at L1.
Three: the surface captures attention; the chain captures power. A beautiful interface gets users. Companies that last own something deeper. The framework contrasts a slide-generation tool sitting purely at L7 with Replit, which owns agent loops, code generation, hosting, auth and database — the same prompt-to-output category, structurally different fate.
Four: generation and verification must stay separate. Where output carries fiduciary, regulatory, safety or reputational weight, the generator and the verifier have to be different economic entities. The model cannot audit itself, the code generator cannot certify itself, the drafter cannot approve itself. This is why the Big Four still audit companies that run SAP, why security review vendors sit above coding assistants, and why L3 is the one layer platforms structurally cannot swallow.
The patterns that read like field notes
Underneath the laws sit repeatable market patterns, and these are the parts an operator can use in a Monday meeting.
The Two-Vendor Rule: enterprises will pay for two vendors when one vendor's mistake is unrecoverable. No CISO in the United States accepts the same vendor writing the code and certifying its security. Buyers pay a duplication tax to avoid a single-point-of-failure tax.
Regulatory Half-Life: models cycle every six months; SOC 2, HIPAA, the EU AI Act and FDA clearance cycle every five to ten years. The more regulated the industry, the longer the compliance layer outlives model churn.
The Bundling Asymmetry: foundation model labs expand upward into execution, orchestration and surface, because buyers accept it. They do not expand across the trust boundary into auditing themselves. OpenAI will ship agents. OpenAI will not issue its own SOC 2 report.
Memory Is Not Truth: remembering what a user said and did is a clean moat. Making a claim about what is true — a diagnosis, a legal position, a valuation — inherits a regulator and needs a verifier above it. An AI medical scribe is valuable; the same scribe issuing a diagnosis triggers a very different regime.
Distribution Eats Generation: once models commoditize, the surplus flows to whoever owns the moment of use. The model behind a coding assistant is interchangeable; the editor window is not.
How it differs from the AI stack diagrams you have seen
There is no shortage of AI stack diagrams. The framework's argument against them is specific: a stack shows the parts and a value chain shows the flow, but neither has a vocabulary for gatekeeping, absorption risk, capital and attention currents, compounding flywheels across sublayers, vertical differences between legal and health and fintech, or timing — when each layer commoditizes and what survives the compression.
Put plainly: the AI stack explains how intelligence is built. This framework tries to explain where intelligence becomes economically defensible. Those are different questions, and the second one is the one a board is actually asking.
Where it is weakest
Two honest cautions. First, the layer model is a claim about structure, and the author says so — the paper is versioned precisely because the taxonomy may become twelve layers as the field moves. A framework that reserves the right to renumber is intellectually honest, but it also means any single company placement is a snapshot, not a verdict.
Second, laws stated as falsifiable still need adversarial testing, and most of the published evidence is illustrative case selection rather than a dataset. The strongest of the four — separation of generation and verification — has decades of audit and safety-engineering precedent behind it. The weakest is timing: knowing a layer will commoditize is easier than knowing when, and in AI the difference between those two has ended plenty of companies.
How to use it this week
Take your own product and place it on one layer. Not the layer you wish you were on — the one your revenue actually depends on. Then ask three questions. If the platform below you shipped your core capability for free tomorrow, what remains? Which scarce thing do you own that a competitor with money cannot buy in a quarter? And does anything in your product compound — data, memory, outcome records — or does every customer start you back at zero?
If all three answers point at the surface, the framework's prediction is uncomfortable and probably correct. If any of them point at data, a workflow you genuinely own, a verification role, or memory that accumulates across customers, you have something to defend.
The framework and the full paper are published free at supplychainofai.com, alongside a sortable classification of notable AI companies by layer and archetype, long-form case studies, and a running feed of analysis. It is worth an hour with the ten-by-fifty grid printed out and a pen — which is, judging by the author's instruction to print it and mark it up, exactly how it was meant to be read.

