New startup ideas · AI for people who run the AI themselves · Shadow AI made sanctioned

startup concept

Daylight

Self-serve shadow AI registry and policy for companies with no security team

An ops lead at a 20-200 person company sends one link; each employee self-declares the AI tools they actually use and optionally installs a browser extension for usage counts.

5

similar startups, last 2 years (11 all-time)

yes

3 matching federal grants and programs

Direction supported by government programs and grants

Test it before you build it

$700 · 4 weeks · 20 prospects

Proves that ops leads at no-CISO companies will pay monthly, not once, for a living shadow-AI registry, for $700 in 4 weeks.

Riskiest assumption · An ops lead with no security team will keep paying monthly for a living registry and gap reports, rather than paying once for the policy document and never coming back.

1Focus group: who and where

The ops lead, or the founder doing ops, at a 20-200 person US agency or startup with no security hire, who this month is answering a customer security questionnaire or a cyber-insurance renewal that asks what AI tools employees use, and whose honest answer is a guess.

where to find 20 · The Bureau of Digital Slack (community of digital agency owners and ops leads), local SHRM chapter meetings (events where the people who own company policy actually show up), r/startups and r/humanresources threads about AI acceptable-use policies (channels), plus local EO chapter members for warm intros.

2Sell first, build later

A done-with-you shadow-AI registry: within 14 days of payment we run the employee survey, map every declared tool to a data rule, deliver an acceptable-use policy employees sign in the same flow, and start monthly gap reports on the allowlist.

the ask · $99 per month per company at a founding price locked for 12 months, offered against a $299 one-time alternative on every call

a real yes · A real yes is a first month charged or the $299 paid today; 'send me the deck', 'we will do this after our SOC 2', and warm compliments from the SHRM meeting are not

3Small experiments

The first one attacks the riskiest assumption; each ends with a number that says whether to run the next.

  1. 1. Recurring versus one-time price test

    $200 · 14 days

    Book 20 calls with ops leads from Bureau of Digital, one SHRM chapter meeting and subreddit threads. Walk through the survey-to-policy flow on slides, then present two prices side by side: $299 one-time for the policy package, or $99 a month for the policy plus the living allowlist and monthly gap reports. Ask them to pay on the call and record which price they pick.

    keep going if · 6 of 20 pay something, and at least 4 of the payers choose $99 monthly over $299 one-time

  2. 2. Priced landing page

    $200 · 10 days

    Put up a one-page site with both tiers priced and a 'run the 10-minute survey' button that collects the company email and chosen tier. Post it in Bureau of Digital and the subreddit threads already discussing AI policies. Count tier selections, not visits.

    keep going if · 10 tier selections with company emails in 10 days, majority on the monthly tier

  3. 3. Manual pilot and week-3 pulse

    $300 · 21 days

    For every paying company, run the whole product by hand: a Google Form survey to employees, a spreadsheet inventory mapped to data rules, a policy doc from a template signed in the same flow, then a gap report in week 3 comparing declared tools to what employees mention since. Measure whether anyone reads and acts on the week-3 report - that is the churn question in miniature.

    keep going if · 4 of 6 paying companies respond to the week-3 gap report and confirm the next month

4Collect a deposit up front

Tesla took $1,000 refundable reservations for the Model 3 and $100 for the Cybertruck before building either: the deposit is the measurement, not the revenue.

$99

per prospect, refundable

how · First month prepaid on the call at the $99 founding price, charged by invoice or card link the ops lead approves themselves, chosen because a sub-$100 monthly tool sits inside an ops lead's own spending authority and prepayment is the only honest test of the recurring-value risk set up: Stripe Invoicing

what it reserves · A slot in the 10-company founding cohort, the $99 price locked for 12 months, and survey launch within 14 days

refund · Full refund within 30 days if the survey, policy and allowlist are not delivered or the buyer is not satisfied; cancel anytime after.

target · 6 payments from 20 calls within 28 days, at least 4 of them monthly

Go: build it if

6 or more companies pay with at least 4 choosing monthly over one-time, and 4 of 6 engage with the week-3 gap report: the recurring value is real, build it.

Kill: stop if

Fewer than 3 payments from 20 calls, or 5 of 6 payers pick the $299 one-time option, or nobody opens the week-3 gap report: this is a policy generator, not a subscription - stop.

5 Scripts to run itoutreach message, landing copy, deposit terms · click to open

outreach message

You are the person a 40-person company points at when a client questionnaire asks what AI tools employees use - and right now the honest answer is a guess. I run a 10-minute employee survey, map every declared tool to a data rule, and hand you a signed acceptable-use policy plus a living allowlist within two weeks, $99 a month at a founding price, cancel anytime. Can I take 20 minutes this week to walk you through it?

landing page

Every AI tool your team actually uses, on one signed policy $99 a month: the survey, the policy, the allowlist and monthly gap reports - or $299 one-time for the policy alone Run the 10-minute survey with your team this week

deposit terms

Your first $99 is charged today and locks the founding price for 12 months. It covers the employee survey, your acceptable-use policy, the tool allowlist and your first gap report, delivered within 14 days. Full refund within 30 days if you are not satisfied; cancel anytime after that.

Would you run this test?

One tap. The yes-share feeds the Demand pillar of this idea's score; nobody sees who answered.

Budgets are out-of-pocket estimates for a team of one to three, US market. Size the deposit to the deal, and check the terms before taking money in a regulated line.

Scorecard

Ranked against every idea in the catalog: trend, demand and 100x potential from the corpus, competition relative to the other ideas. A generated concept has no judges or swipes yet, so its pillars use the data signals only.

31

Idea Score, 0-100 · raw 19.0 x 1.61

Active

competition: more crowded than 62% of ideas · headwind x0.69

+2.1

government priorities, secondary (3 matching grants)

Trend

47

Is the wave forming now? 2025-26 entrants vs 2023-24, rounds since 2025, the sector's live-batch direction, the 2026 trend analyst.

  • Entrants 2025-26 vs 2023-24 (similar companies)92
  • Rounds announced 2025+ in the sector0
  • Sector direction (live batch)50

Demand

61

Does anyone want it? YC's current RFS, companies already paid for something similar, the operator judge, founders' yes-rate in decks, readers who would run the test.

  • YC asks for it (current RFS: idea / sector)30
  • Someone already pays (similar companies, recent / all-time)92

100x potential

5

Can it return a fund? The venture judge (double weight), market-size and moat axes, neighbours still alive, the technologist judge.

  • Neighbours still alive5

Score = 100 x cbrt(Trend x Demand x 100x) x (1 - 0.5 x crowding) + government bonus (max 5), calibrated so the 95th-percentile idea scores 90 (order never changes). A geometric mean: a weak pillar cannot be papered over. Percentiles are among the 382 ideas in the catalog; the terms matched were self-serve, shadow, registry, policy, security, ops, lead, 20-200.

The concept in full

What
An ops lead at a 20-200 person company sends one link; each employee self-declares the AI tools they actually use and optionally installs a browser extension for usage counts. Daylight maps every declared tool to a data rule, generates an acceptable-use policy and a living allowlist, and flags gaps between policy and observed use. In the first hour the owner runs the survey, sees the real tool inventory, and publishes a policy employees sign in the same flow.
Grounded in (2025-2026 signals)
MIT NANDA (published August 2025): more than 40% of knowledge workers use personal AI tools at work; Gallup Q4 2025: 26% of US employees use AI at least a few times a week and 12% daily, while 49% never do, meaning usage is concentrated in a visible minority a survey can actually capture.
What it rides
'The GenAI Divide: 95% of pilots return nothing, workers run their own tools' (MIT NANDA, August 2025): the shadow economy is the real deployment, and small companies need to see it before they can sanction it.
Why now
Gallup's Q4 2025 numbers show AI use concentrated in about a quarter of employees while MIT's August 2025 report puts personal-tool use above 40% of knowledge workers; small companies now know they have a shadow inventory and have no tool sized for them to surface it.
Wedge: first customer and entry point
Founders and ops leads at US startups and agencies with no CISO, reached through the same self-serve motion as HR policy tools; $99-$300 a month per company.
Closest real companies, as the generator saw them
Cotool (yc X25) builds agents for security operations teams, which assumes a SOC exists; Daylight serves companies whose entire security function is one ops person and a Google form.
Main risk
The product collapses into a one-time policy generator with nothing recurring, and churn kills it after the first renewal.

Similar startups in the directory

Companies whose pitch matches most of the concept's terms (self-serve, shadow, registry, policy, security, ops, lead, 20-200).

  • Anylensalchemist Alchemist Class 41 · 2026 · Security and complianceunchecked

    AI Governance Gateway

  • Wayfoundplugandplay PnP 2026 · 2026 · Agent infrastructurealive

    Wayfound is a platform that manages, monitors, and governs enterprise AI agents in real time, ensuring compliance, performance, and explainable behavior.

  • Vallumplugandplay PnP 2026 · 2026 · B2B SaaSalive

    Vallum optimizes enterprise AI usage by measuring ROI, boosting adoption, and governing interactions.

  • Further AIplugandplay PnP 2025 · 2025 · Vertical AI agentssite down

    FurtherAI provides AI Agents for Commercial P&C Underwriting, Claims, and Compliance Automation.

  • Golfyc X25 · 2025 · Security and compliancealive

    Agentic AI Security and Governance

  • Aona AIantler Antler Australia 2023 · 2023 · Security and compliancealive

    Securing advanced AI access, boosting business productivity, prioritizing privacy & trust.

  • FutureAdvisoryc S10 · 2010 · Fintechacquired

    The online financial management service for everyone.

  • BlockReplugandplay · Fintechunchecked

    BlockRe is the world’s first and leading cryptoasset insurance company, and a provider of a comprehensive underwriting and risk assessment tool designed to aid in the issuing of insurance policies in the cryptoasset and blockchain space.

  • Federatopear · Fintechalive

    The AI-native insurance platform designed for the full policy lifecycle

  • Resilienceplugandplay · Security and compliancealive

    Resilience is a cyber insurance provider that offers organizations the tools, guidance, and solutions to insure and secure their data.

  • Laminiplugandplay · AI infra and computeunchecked

    Production LLM pods for every engineer to build enterprise LLM experts at scale, no labeling, just code.

Public money in this direction

US federal grants and open opportunities matched to the concept's terms.

Other concepts in this collection

Fictional concept generated 2026-08-26 by claude-fable-5 from the collection's brief and MarkosWeb data. Treat it as a research prompt, not a plan.