Build or Skip

AI security for model weights

We said SKIP on August 1, 2026. Not settled — due August 1, 2027.

Read this with the caveat. We tested the engine that produced this verdict against 292 launches whose outcomes we already knew, and could not show it predicted which survived. Some of its data sources were also dead at the time of scoring. The verdict stays up, dated and unedited, because a record you can quietly revise is not a record — but it is worth less than it looked when it was written.

AI security is a hot, growing space with paying incumbents, but demand for the specific 'model weights' sub-niche is inferred rather than demonstrated, and the actual buyers are enterprises and frontier labs. A solo founder with no audience faces a brutal trust-and-distribution problem selling security to that audience; the only credible wedge (an open-source repo) has weak monetization. This is a SKIP for the default operator.

Was there demand

5out of 10

Real commercial activity exists (SentinelOne, Palo Alto, Edgeless charging in adjacent AI security) and search is growing, but the signal for model-weight-security specifically is thin — social chatter is generic 'what is AI security' talk, not weight-theft pain.

Could a builder win it

3out of 10

Every named competitor targets enterprise/frontier labs, and model-weight security is a trust-heavy, high-stakes enterprise sale with long cycles — a solo founder with no audience and no distribution has no realistic path to the first 10 paying customers here.

The case against this verdict

The genuine gap is real: nobody ships an open-source reference implementation for weight encryption, access control, and exfiltration detection, and 'github'/'example' search intent suggests developers want exactly that. A solo founder could win developer mindshare with a free repo first, then monetize a managed/hosted detection layer — the incumbents' enterprise-only, non-product focus leaves the self-serve small-team segment genuinely open.

Who was already there

  • RAND CorporationPurely research/policy-focused — publishes threat models and reports but offers no actual product, tooling, or implementation. Academic and dense, not actionable for practitioners.
  • SentinelOneContent is generic educational SEO material (CISO guide) rather than a dedicated model-weight-protection product. Broad AI security focus dilutes specialization on weights specifically.
  • Palo Alto NetworksCyberpedia entry is top-of-funnel definitional content, not a specialized weights-security solution. Enterprise-only focus ignores smaller AI teams and independent developers.
  • Edgeless Systems (Privatemode)Narrow technical approach (confidential computing / encryption at inference). Requires specific infrastructure adoption; may be complex to integrate. Lesser-known brand with limited search presence.
  • METR / LessWrong communityCommunity commentary and advocacy, not a product or service. Niche AI-safety audience, no commercial offering, no implementation tooling.

Other verdicts

What is worth more than this page. The register records what became of 6,266 real launches. No engine has to be right for that to be true.