WiseTech's moat is regulatory, not code. That raises the stakes on the code.
CISO AI · 5 Sept 2026 · Analysis
Two things WiseTech's new chief executive said on ABC Business Daily last week are both true, and the space between them is worth an Australian business owner's attention.
The first is that AI has changed how the company builds software. About 1,700 role exits over 14 or 15 months, in his words "in large part because of the power of AI". About 90% of the code in the CargoWise part of the business is now written or assisted by AI. Individual engineering productivity up about 45%. Support ticket resolution improved about 20%.
The second is his answer when Alan Kohler asked whether Claude, or a Chinese model, could do what CargoWise does.
"Not even in the realm of possibility."
The moat is not what people assume
The interesting part is that Zubin Appoo does not argue his code is hard to write. He says the opposite, plainly:
"We've never said that our source code or the code that is CargoWise is our moat."
What he claims instead is the ecosystem. Integrations with 400 airlines and 150 shipping lines. Customs authorities in enough of the world that, on his numbers, 80% of manufactured trade flows can pass through the system. Capability built across 193 countries over three decades.
Kohler pushed back well, and it is the best moment in the interview. He pointed out that he used to work for newspapers when Seek and realestate.com started up, and that the newspaper owners were "as adamant as you are now" that nobody could replicate their ecosystem.
Appoo conceded the capability point immediately. Models are improving exponentially, they leapfrog each other constantly, they compete on price. Then he moved the argument somewhere more solid:
"What we do is we operate in some of the most highly regulated environments in the world... software that ensures sanctions are not breached, that embargoes are not breached, that freight forwarders and importers and exporters don't ship to terrorists, that they don't breach restricted party lists, that they pay the right duties and taxes to governments... These are not software problems. These are actually integrations with government and with regulators."
That is a much better answer than the newspapers gave, and it holds up. A model can write an integration in an afternoon. It cannot get the Australian Border Force to certify it. Regulators move slowly, deliberately, and do not hand out production access to whoever asks. That is a real moat and a durable one.
But notice what the moat is made of
If the defensible thing is no longer the difficulty of writing the software, and is instead sanctions screening, embargo enforcement, restricted party list matching, duty calculation and modern slavery checks in supply chains, then the value of the system sits almost entirely in whether that logic is correct.
And this is compliance logic, which fails in a particular way. A sanctions screening false negative does not throw an exception. Nothing goes red. A shipment clears that should not have, and the first sign of trouble is a regulator, months later, asking why.
WiseTech has not said the compliance layer specifically is 90% AI-assisted. The figure he gave covers the CargoWise part of the business, and it would be unfair to read more into it than that. Nor is AI-assisted code inherently worse than the alternative. Plenty of it is better, and the company reported these numbers as an achievement, which on productivity they plainly are.
The point is narrower. When your moat moves from "this is hard to build" to "this is correct in ways regulators depend on", assurance of the code becomes the thing that carries the value. And the assurance question gets harder, not easier, when a large share of the code is machine authored, review capacity has not grown at the same rate, and the headcount that used to do the reviewing is down by 1,700.
Why this matters if you have never heard of CargoWise
Most Australian businesses will never buy this software. Many of them depend on it anyway, because their freight forwarder or customs broker runs on it. That is third party risk in its most ordinary form: a system you did not choose, cannot inspect, and would notice only when a shipment is held or a penalty arrives.
The questions worth asking your logistics providers are not technical:
- Which platform performs your sanctions and restricted party screening?
- When that screening logic changes, who reviews the change, and against what?
- If a screening miss were found six months later, how would you know, and how would we?
None of those require you to understand the code. They require the provider to be able to answer.
The broader pattern
This is not really a WiseTech story. It is the shape of a question that is going to arrive for every regulated software vendor over the next few years, and it is one CISO AI has been tracking across the news: AI written code, the assurance gap behind it, and the supply chain that inherits both. It is the single densest tag in our own coverage: AI security runs to well over a hundred briefings and grows most weeks, which is not an accident.
The version of this question worth asking in your own organisation is simple. If your product's defensibility rests on being correct rather than on being hard to build, what is the control that proves it is still correct? If the honest answer is "the engineers who wrote it would have noticed", it is worth checking how many of them are still there, and how much of it they wrote.
Source: WiseTech's new CEO on recovering from scandal, ABC Business Daily, 4 September 2026. Quotations are from the broadcast interview between Alan Kohler and Zubin Appoo. Figures are as stated by Appoo on air.
Nick Forshteyn · 13 September 2026
The strongest objection I have heard to this piece is that I have the risk backwards: a 45% productivity gain means more engineers reviewing more code, not fewer, and a compliance engine that has been in production across 193 countries for decades has been tested by reality in a way no review process can match. On that reading, AI-assisted code is entering the safest part of the system, not the most fragile.
I think that is half right. Reality tests the paths that get exercised. A sanctions rule that quietly stopped matching a new entity format has not been tested by reality until the day it matters, and that day arrives with a regulator attached.
But I would rather be argued out of it than be right by default. If you run or buy compliance software, where does that reasoning break?