New startup ideas · AI for people who run the AI themselves · Shadow AI made sanctioned
startup concept
Daylight
Self-serve shadow AI registry and policy for companies with no security team
An ops lead at a 20-200 person company sends one link; each employee self-declares the AI tools they actually use and optionally installs a browser extension for usage counts.
- Software subscription
- Small business
- 'The GenAI Divide
5
similar startups, last 2 years (11 all-time)
yes
3 matching federal grants and programs
Direction supported by government programs and grants
Test it before you build it
$700 · 4 weeks · 20 prospects
Proves that ops leads at no-CISO companies will pay monthly, not once, for a living shadow-AI registry, for $700 in 4 weeks.
Riskiest assumption · An ops lead with no security team will keep paying monthly for a living registry and gap reports, rather than paying once for the policy document and never coming back.
1Focus group: who and where
The ops lead, or the founder doing ops, at a 20-200 person US agency or startup with no security hire, who this month is answering a customer security questionnaire or a cyber-insurance renewal that asks what AI tools employees use, and whose honest answer is a guess.
where to find 20 · The Bureau of Digital Slack (community of digital agency owners and ops leads), local SHRM chapter meetings (events where the people who own company policy actually show up), r/startups and r/humanresources threads about AI acceptable-use policies (channels), plus local EO chapter members for warm intros.
2Sell first, build later
A done-with-you shadow-AI registry: within 14 days of payment we run the employee survey, map every declared tool to a data rule, deliver an acceptable-use policy employees sign in the same flow, and start monthly gap reports on the allowlist.
the ask · $99 per month per company at a founding price locked for 12 months, offered against a $299 one-time alternative on every call
a real yes · A real yes is a first month charged or the $299 paid today; 'send me the deck', 'we will do this after our SOC 2', and warm compliments from the SHRM meeting are not
3Small experiments
The first one attacks the riskiest assumption; each ends with a number that says whether to run the next.
1. Recurring versus one-time price test
$200 · 14 days
Book 20 calls with ops leads from Bureau of Digital, one SHRM chapter meeting and subreddit threads. Walk through the survey-to-policy flow on slides, then present two prices side by side: $299 one-time for the policy package, or $99 a month for the policy plus the living allowlist and monthly gap reports. Ask them to pay on the call and record which price they pick.
keep going if · 6 of 20 pay something, and at least 4 of the payers choose $99 monthly over $299 one-time
2. Priced landing page
$200 · 10 days
Put up a one-page site with both tiers priced and a 'run the 10-minute survey' button that collects the company email and chosen tier. Post it in Bureau of Digital and the subreddit threads already discussing AI policies. Count tier selections, not visits.
keep going if · 10 tier selections with company emails in 10 days, majority on the monthly tier
3. Manual pilot and week-3 pulse
$300 · 21 days
For every paying company, run the whole product by hand: a Google Form survey to employees, a spreadsheet inventory mapped to data rules, a policy doc from a template signed in the same flow, then a gap report in week 3 comparing declared tools to what employees mention since. Measure whether anyone reads and acts on the week-3 report - that is the churn question in miniature.
keep going if · 4 of 6 paying companies respond to the week-3 gap report and confirm the next month
4Collect a deposit up front
Tesla took $1,000 refundable reservations for the Model 3 and $100 for the Cybertruck before building either: the deposit is the measurement, not the revenue.
$99
per prospect, refundable
how · First month prepaid on the call at the $99 founding price, charged by invoice or card link the ops lead approves themselves, chosen because a sub-$100 monthly tool sits inside an ops lead's own spending authority and prepayment is the only honest test of the recurring-value risk set up: Stripe Invoicing ↗
what it reserves · A slot in the 10-company founding cohort, the $99 price locked for 12 months, and survey launch within 14 days
refund · Full refund within 30 days if the survey, policy and allowlist are not delivered or the buyer is not satisfied; cancel anytime after.
target · 6 payments from 20 calls within 28 days, at least 4 of them monthly
Go: build it if
6 or more companies pay with at least 4 choosing monthly over one-time, and 4 of 6 engage with the week-3 gap report: the recurring value is real, build it.
Kill: stop if
Fewer than 3 payments from 20 calls, or 5 of 6 payers pick the $299 one-time option, or nobody opens the week-3 gap report: this is a policy generator, not a subscription - stop.
5 Scripts to run itoutreach message, landing copy, deposit terms · click to open
outreach message
You are the person a 40-person company points at when a client questionnaire asks what AI tools employees use - and right now the honest answer is a guess. I run a 10-minute employee survey, map every declared tool to a data rule, and hand you a signed acceptable-use policy plus a living allowlist within two weeks, $99 a month at a founding price, cancel anytime. Can I take 20 minutes this week to walk you through it?
landing page
Every AI tool your team actually uses, on one signed policy $99 a month: the survey, the policy, the allowlist and monthly gap reports - or $299 one-time for the policy alone Run the 10-minute survey with your team this week
deposit terms
Your first $99 is charged today and locks the founding price for 12 months. It covers the employee survey, your acceptable-use policy, the tool allowlist and your first gap report, delivered within 14 days. Full refund within 30 days if you are not satisfied; cancel anytime after that.
Would you run this test?
One tap. The yes-share feeds the Demand pillar of this idea's score; nobody sees who answered.
Budgets are out-of-pocket estimates for a team of one to three, US market. Size the deposit to the deal, and check the terms before taking money in a regulated line.
Scorecard
Ranked against every idea in the catalog: trend, demand and 100x potential from the corpus, competition relative to the other ideas. A generated concept has no judges or swipes yet, so its pillars use the data signals only.
31
Idea Score, 0-100 · raw 19.0 x 1.61
Active
competition: more crowded than 62% of ideas · headwind x0.69
+2.1
government priorities, secondary (3 matching grants)
Trend
47
Is the wave forming now? 2025-26 entrants vs 2023-24, rounds since 2025, the sector's live-batch direction, the 2026 trend analyst.
- Entrants 2025-26 vs 2023-24 (similar companies)92
- Rounds announced 2025+ in the sector0
- Sector direction (live batch)50
Demand
61
Does anyone want it? YC's current RFS, companies already paid for something similar, the operator judge, founders' yes-rate in decks, readers who would run the test.
- YC asks for it (current RFS: idea / sector)30
- Someone already pays (similar companies, recent / all-time)92
100x potential
5
Can it return a fund? The venture judge (double weight), market-size and moat axes, neighbours still alive, the technologist judge.
- Neighbours still alive5
Score = 100 x cbrt(Trend x Demand x 100x) x (1 - 0.5 x crowding) + government bonus (max 5), calibrated so the 95th-percentile idea scores 90 (order never changes). A geometric mean: a weak pillar cannot be papered over. Percentiles are among the 382 ideas in the catalog; the terms matched were self-serve, shadow, registry, policy, security, ops, lead, 20-200.
The concept in full
- What
- An ops lead at a 20-200 person company sends one link; each employee self-declares the AI tools they actually use and optionally installs a browser extension for usage counts. Daylight maps every declared tool to a data rule, generates an acceptable-use policy and a living allowlist, and flags gaps between policy and observed use. In the first hour the owner runs the survey, sees the real tool inventory, and publishes a policy employees sign in the same flow.
- Grounded in (2025-2026 signals)
- MIT NANDA (published August 2025): more than 40% of knowledge workers use personal AI tools at work; Gallup Q4 2025: 26% of US employees use AI at least a few times a week and 12% daily, while 49% never do, meaning usage is concentrated in a visible minority a survey can actually capture.
- What it rides
- 'The GenAI Divide: 95% of pilots return nothing, workers run their own tools' (MIT NANDA, August 2025): the shadow economy is the real deployment, and small companies need to see it before they can sanction it.
- Why now
- Gallup's Q4 2025 numbers show AI use concentrated in about a quarter of employees while MIT's August 2025 report puts personal-tool use above 40% of knowledge workers; small companies now know they have a shadow inventory and have no tool sized for them to surface it.
- Wedge: first customer and entry point
- Founders and ops leads at US startups and agencies with no CISO, reached through the same self-serve motion as HR policy tools; $99-$300 a month per company.
- Closest real companies, as the generator saw them
- Cotool (yc X25) builds agents for security operations teams, which assumes a SOC exists; Daylight serves companies whose entire security function is one ops person and a Google form.
- Main risk
- The product collapses into a one-time policy generator with nothing recurring, and churn kills it after the first renewal.
Similar startups in the directory
Companies whose pitch matches most of the concept's terms (self-serve, shadow, registry, policy, security, ops, lead, 20-200).
AI Governance Gateway
Wayfound is a platform that manages, monitors, and governs enterprise AI agents in real time, ensuring compliance, performance, and explainable behavior.
Vallum optimizes enterprise AI usage by measuring ROI, boosting adoption, and governing interactions.
FurtherAI provides AI Agents for Commercial P&C Underwriting, Claims, and Compliance Automation.
Agentic AI Security and Governance
Securing advanced AI access, boosting business productivity, prioritizing privacy & trust.
The online financial management service for everyone.
BlockRe is the world’s first and leading cryptoasset insurance company, and a provider of a comprehensive underwriting and risk assessment tool designed to aid in the issuing of insurance policies in the cryptoasset and blockchain space.
The AI-native insurance platform designed for the full policy lifecycle
Resilience is a cyber insurance provider that offers organizations the tools, guidance, and solutions to insure and secure their data.
Production LLM pods for every engineer to build enterprise LLM experts at scale, no labeling, just code.
Public money in this direction
US federal grants and open opportunities matched to the concept's terms.
National Science Foundation · IUSE · $400K
National Science Foundation · Info Integration & Informatics · $526K
National Science Foundation · Networking Technology and Syst · $675K
Other concepts in this collection
- SkillproofRegression testing for the Agent Skills you actually depend on
- ProvenaryScan third-party skills and MCP servers before you let them touch your data
- LedgerkitVersioned skill packs that make a solo CPA's assistant work like a tax practice
- VendfoldLicensing, signing and auto-update infrastructure for people who sell Agent Skills
- PackroomOne shared skill library for a team where everyone runs their own agent
- TokentabPer-skill cost, routing and drift telemetry for the person who runs AI all day
- ThreadkeepA memory vault you own that every assistant you run can read
- RelayfileHand a running task from Claude Code to Codex without losing state
- MeterhouseOne budget, meter and kill switch for every agent you run
- AttestlyAudit trail and approval inbox for the agents you run at work
- SkillvaneVersion control and regression tests for the skills your agents load
- CrewlineA shared board where each teammate's agents pick up each other's work
- WardkeySecurity scanner that finds and fixes exposed keys in vibe-coded apps
- StillupUptime and error monitoring that answers in fix prompts, not stack traces
- CopystoneAutomatic backups and one-click restore for apps built without engineers
- GroundskeepMonthly maintenance for shipped vibe-coded apps, applied as reviewable patches
- TillhousePayments, sales tax and refunds as one drop-in for non-developer founders
- SpendgateMeter, cap and route the AI spend inside apps vibe coders shipped
- DryloopRehearsal mode for the automations a small business owner builds alone
- MeterlyOne metered key with spend caps for every AI step you run
- FlowmedicWatches your automations, explains failures in plain English, proposes the fix
- ScrubdeckA data-cleaning step any workflow can call, with rules the owner keeps
- OpshandTurns your written SOPs into versioned Agent Skills with tests included
- CrewtraceShared visibility when five people at one business each run their own automations
- VeraciteCitation verification and AI work records for solo attorneys who draft with Claude
- TickstoneTurns a solo CPA's AI sessions into reviewable workpapers with tickmarks and source trails
- ChartproofA verification layer for physicians who use AI on clinical notes under their own license
- CoverlensPolicy-form verification for independent insurance agents who quote with AI
- MethodkitSolo consultants package their methodology as versioned Agent Skills they own and resell
- AttestrailTamper-evident logs of every AI action, built for licensed professionals' liability files
- ScrublineLocal redaction proxy that makes your personal AI accounts safe for work data
- StipendlyTurn personal Claude Max and ChatGPT Pro seats into managed employer stipends
- TollgateA policy gateway between your assistant and every MCP server it touches
- SkillvetScan, pin and approve Agent Skills before they touch company data
- LedgerlineRightsizing dashboard for everyone paying for AI out of their own pocket
- SwitchyardOne metered endpoint with routing, fallback and per-person caps for tiny teams
- HearthmeterUsage budgets and one bill for the household that shares AI plans
- SeatcaseMeasures who on your team earns a Max seat and who wastes one
- TokencairnProfiler that shows what each installed skill and MCP server really costs
- FusegateBudget caps, fallback and kill switches for automations you run yourself
- SkillbenchRegression testing for Agent Skills before every model and skill update
- CitelockVerifies every citation in AI-drafted work before a licensed professional signs it
- MiddlegateA local gateway where you set the rules for what your MCP servers can do
- DriftwatchCatches output drift in the automations small operators wired themselves
- ShipcheckPre-launch review gates non-technical builders run on their own vibe-coded apps
- TracelineA claim-level provenance trail for every number in an AI-assisted report
- DrillyardScored practice repos where you learn to drive coding agents well
- PassrateA proctored AI operation exam scored from your real agent transcripts
- PatchcraftDebugging drills that teach non-technical builders to maintain what they vibe coded
- SkillsmithA workshop for writing, testing and versioning Agent Skills that actually hold up
- TickmarkSynthetic client caseloads where CPAs drill AI-assisted work before trying it on real clients
- PostgameAn MCP server that scores your own agent sessions and drills your weakest habits
- CitegridEvery number in your published research links to a source snapshot you verified
- MnemosYour research corpus as a private MCP server every assistant can query
- MeterlineModel routing and cost accounting for one person's AI research pipeline
- SkillcaskVersion, test, and sell your expertise as licensed Agent Skills
- StackfeedA personal data pipeline that repairs itself when sources change
- ClaimboardA shared evidence ledger for small teams where everyone runs their own agent
Fictional concept generated 2026-08-26 by claude-fable-5 from the collection's brief and MarkosWeb data. Treat it as a research prompt, not a plan.