We said SKIP on August 1, 2026. Not settled — due August 1, 2027.
Read this with the caveat. We tested the engine that produced this verdict against 292 launches whose outcomes we already knew, and could not show it predicted which survived. Some of its data sources were also dead at the time of scoring. The verdict stays up, dated and unedited, because a record you can quietly revise is not a record — but it is worth less than it looked when it was written.
AI security is a hot, growing space with paying incumbents, but demand for the specific 'model weights' sub-niche is inferred rather than demonstrated, and the actual buyers are enterprises and frontier labs. A solo founder with no audience faces a brutal trust-and-distribution problem selling security to that audience; the only credible wedge (an open-source repo) has weak monetization. This is a SKIP for the default operator.
Real commercial activity exists (SentinelOne, Palo Alto, Edgeless charging in adjacent AI security) and search is growing, but the signal for model-weight-security specifically is thin — social chatter is generic 'what is AI security' talk, not weight-theft pain.
Every named competitor targets enterprise/frontier labs, and model-weight security is a trust-heavy, high-stakes enterprise sale with long cycles — a solo founder with no audience and no distribution has no realistic path to the first 10 paying customers here.
The genuine gap is real: nobody ships an open-source reference implementation for weight encryption, access control, and exfiltration detection, and 'github'/'example' search intent suggests developers want exactly that. A solo founder could win developer mindshare with a free repo first, then monetize a managed/hosted detection layer — the incumbents' enterprise-only, non-product focus leaves the self-serve small-team segment genuinely open.
What is worth more than this page. The register records what became of 6,266 real launches. No engine has to be right for that to be true.