The repeatable way App Economy values AI exposure once "build vs rent" gains a third variable — regulatory-shutdown risk. Not what to buy, but how to price who can keep their model online.
1. Score every AI player on the build-vs-rent axis — then add shutdown risk
The repeatable method
- For any company with AI exposure, classify it: does it build a frontier model or rent one? Building buys control and upside; renting makes the model a swappable component.
- Add the third variable the old framework missed: regulatory-shutdown risk — the chance a government can pull a deployed model from the market overnight.
- Re-rate accordingly: a builder carries more upside but more concentration risk; a renter sheds the CapEx arms race and most of the shutdown exposure, at the cost of differentiation.
Here: pure-play builders Anthropic and OpenAI = maximum upside, maximum shutdown exposure; AAPL (renting Gemini) = minimal control, minimal exposure — the two ends of the same axis.
Watch for
- A company whose entire value rests on one model it owns, versus one that can swap models — the tell for where shutdown risk concentrates.
2. Apply the "cushion test" to a frontier-model owner
The repeatable method
- For a model owner, ask: if the model were switched off tomorrow, what revenue would still be standing?
- A diversified owner (search, app store, cloud, ads) has a cushion that absorbs the blow; a pure-play lab has none — the model is the business.
- Discount the pure-play's valuation for that single point of failure even when its model is the best.
Here: GOOGL owns Gemini but cushions it with Search/Android/Cloud; for Anthropic / OpenAI the frontier model is the whole company — a $965B valuation with one off-switch.
Watch for
- The share of a model owner's revenue that survives a model recall; concentration into a single deployed asset.
3. Read AI lateness as a possible hedge, not just a miss
The repeatable method
- When a company is behind in AI, check whether it solved the gap by renting a model rather than building one.
- Quantify the rent (the annual fee) against the CapEx it avoids — a ~$1B/yr bill versus tens of billions of data-center spend can be a feature.
- Credit the renter for sidestepping commoditization and shutdown risk; debit it for losing control of the core experience and any region where the deal can't ship.
Here: AAPL's slipped Siri became a hedge — it rents a custom ~1.2T-param Gemini for ~$1B/yr, skips the arms race, but no longer controls its flagship's brain and excludes Siri AI from the EU.
Watch for
- A laggard quietly licensing a rival's model; the annual fee vs the avoided CapEx; regions where the rented feature can't legally launch.
4. Track the regulatory-recall precedent as a new systemic variable
The repeatable method
- Treat the first government recall of a deployed commercial AI as a precedent that re-prices every frontier owner, not a one-off.
- Monitor three signals: how fast the affected model's access is restored, whether other labs receive similar directives, and whether the government formalizes a repeatable model-recall framework.
- Widen the risk discount on pure-play owners as those signals harden; narrow it if the episode proves isolated.
Here: an export-control directive forced Anthropic to disable Fable 5 and Mythos 5 worldwide — the first such recall; the watch-list is restoration speed, spread to other labs, and a formal recall framework.
Watch for
- A second lab receiving a directive, or a written model-recall rule — either turns a one-off into a sector-wide risk premium.
5. Flag dual-use capability as the trigger for intervention
The repeatable method
- Gauge how close a model's capabilities sit to genuine national-security concern (e.g. finding exploitable flaws in operating systems and browsers).
- The more dual-use the capability, the higher the odds of an off-switch — capability and regulatory risk rise together for a frontier owner.
- Note who the vetted partners are: a model restricted to a small defensive program signals the capability regulators most fear.
Here: Mythos 5 reportedly found flaws in every OS/browser tested and was limited to ~50 "Project Glasswing" partners (Apple, Google, Microsoft, CrowdStrike) — the dual-use profile that invited the directive.
Watch for
- Frontier capabilities with offensive-security uses; access deliberately gated to vetted partners — the marker of a model a government may pull.
Methods distilled from the public App Economy Insights newsletter (article text in transcript.txt) for personal study. Not investment advice. © App Economy Insights for source material.