24gaps with evidence
1226candidates that failed
The gaps
Newest first. Each carries what changed to make it buildable, who is on record being
in pain, exactly who the buyer is, and how many of them can be reached from a standing start.
Everything here is published in full because a gap you can see is worth more than a gap we are
hinting at, and because if one of these is wrong we would rather be told.
Cleared all five tests
found 22 September
AI Code Review Interview Assessment Generator
A hiring manager inputs a role and seniority, the software generates a realistic AI-produced pull request with embedded flaws and a scoring rubric, and the candidate's review is evaluated against expected findings.
The gapThe HN poster states directly: about 80% of dev candidates tell him they are not writing code themselves anymore, they are directing agents instead, and this makes him deeply uncomfortable because he still wants to know devs can actually write code and understand system design. The Pragmatic Engineer newsletter reports CTOs and heads of engineering are struggling with how to deal with large quantities of code review now that AI agents generate most code. The InfoQ article identifies the verification bottleneck as the core new problem.
Why nowAI coding agents (Claude Code, Cursor, Codex) now generate the majority of code at many companies, creating a new skill to assess: can a developer verify and review AI-generated code? The InfoQ article states the bottleneck has moved from code generation to code verification. The Pragmatic Engineer newsletter confirms AI agents generate most code at many tech companies since end of 2025. This assessment category did not exist before AI agents became mainstream code generators, because there was no AI-generated code to review.
Who has itEngineering managers, hiring managers, tech leads, and senior developers who conduct technical interviews at technology companies with 50+ employees. LinkedIn title contains Engineering Manager OR Hiring Manager OR Tech Lead OR Staff Engineer OR Head of Engineering, filtered to software/technology sector.
How manyTens of thousands. One LinkedIn search for Engineering Manager or Tech Lead at software companies with 50+ employees enumerates them. No exotic filtering needed. Job title alone is sufficient.
Just became possible7/10
Somebody is visibly in pain8/10
It is software, not a document8/10
The buyer has a name9/10
Enough of them can be reached9/10
Being built?
Nobody is testing this yet, including us. It has cleared the evidence tests and nothing more than that has been established.
Cleared all five tests
found 20 September
AI Agent Action Approval Gate
Connects to your AI agent's action stream via webhook, evaluates each proposed action against your approval policies, and routes high-risk actions to humans for review before execution.
The gapThe pain is strongly evidenced across multiple sources. EY found 47% of organizations have bypassed AI governance for urgent deployments despite 98% having formal AI policies. IBM's 2026 Cost of a Data Breach report found 68% of organizations lack governance to manage AI. ITSM.tools' 2026 survey ranked governance as a top barrier to AI adoption. Adi Shamir stated he is 'totally terrified' of AI agents because 'they need access to everything to be useful.' DZone identified the core tension: 'Too little oversight creates operational and compliance risk. Too much oversight turns the system into another approval queue.'
Why nowAgentic AI systems that take autonomous actions in enterprise systems are new. Amazon Bedrock AgentCore shipped agent compute capabilities for production-scale agent operations. Agent frameworks now support tool-calling at scale, meaning agents can update CRMs, create purchase orders, and send communications without human intervention. Before this shift, systems were deterministic and governed by traditional RBAC. The move to non-deterministic agents making real system changes creates the need for an external approval layer that did not exist before.
Who has itCISOs, Heads of AI/ML, AI Governance leads, GRC managers, and IT security directors at companies with 1000+ employees that are deploying or planning to deploy AI agents. Findable by job title combined with 'AI agent', 'agentic AI', or 'AI governance' in recent posts or profile descriptions, at companies in sectors with active AI adoption (finance, technology, healthcare, retail).
How manyLow thousands. Search for CISO, Head of AI, AI Governance Manager, GRC Director, IT Security Director titles at companies with 1000+ employees, filtered by 'AI agent' or 'agentic' keywords in recent activity. The compliance platform asset already reaches GRC and security practitioners who would be the buyers. The bigcommerce store reaches people searching for AI governance frameworks by name. Estimated 2,000 to 5,000 identifiable individuals who would plausibly care.
Just became possible7/10
Somebody is visibly in pain8/10
It is software, not a document8/10
The buyer has a name6/10
Enough of them can be reached6/10
Being built?
Nobody is testing this yet, including us. It has cleared the evidence tests and nothing more than that has been established.
Cleared all five tests
found 18 September
MIPS Gap Finder and Corrective Action Recommender
A practice manager uploads their quality measure performance data and the software compares it against current-year MIPS requirements and thresholds, outputting a dashboard of gaps risking reimbursement penalties plus specific corrective actions.
The gapElizabeth Acord, Senior Director of Practice Experience at Verana Health, states: 'the operational demands require practices to keep up with changing measures, shifting thresholds, and detailed documentation requirements, all while ensuring accuracy in submission... Teams still need to interpret requirements, identify gaps, and decide what to do next. That work has not gone away.'
Why nowAWS released open-source agent skills for healthcare and life sciences reasoning that enable AI to correctly apply healthcare decision frameworks with structured procedures, rather than citing the correct framework but misapplying evidence categories or skipping thresholds. This makes automated framework-based gap analysis accurate enough to rely on, where previously LLMs would produce silent failures that looked correct but were wrong.
Who has itPractice managers, quality directors, compliance officers, and practice administrators at US medical practices and physician groups participating in CMS MIPS / the Quality Payment Program. Mid-level operational roles. Filter signal: 'MIPS' or 'Quality Payment Program' or 'QPP' appears in their profile or job description, employed at a medical practice, physician group, or healthcare system in the United States.
How manyThere are over 200,000 physician practices in the US, the vast majority participating in MIPS, each with at least one person responsible for compliance. Search LinkedIn for titles 'Practice Manager,' 'Quality Director,' 'Compliance Officer,' 'Practice Administrator' at healthcare organizations, filtered by US location and the keyword 'MIPS' or 'QPP.' Tens of thousands, trivially identifiable.
Just became possible5/10
Somebody is visibly in pain7/10
It is software, not a document8/10
The buyer has a name8/10
Enough of them can be reached8/10
Being built?
Nobody is testing this yet, including us. It has cleared the evidence tests and nothing more than that has been established.
Cleared all five tests
found 17 September
AI Pull Request Diff Verifier and Chunker
Ingests a massive pull request diff and its linked spec, groups the changes into logical reviewable chunks, and flags divergences from the intent.
The gapReviewers are overwhelmed by massive AI-generated pull requests. As one developer stated, every PR that comes their way for review is on average 6k lines of diff, which is too big to be effectively reviewed. Another signal notes that the bottleneck has moved from code generation to code verification.
Why nowLarge context window LLMs and coding agents can now ingest and reason over massive diffs of 6,000 or more lines and entire codebases, a capability that did not exist a year ago.
Who has itTech Leads, Senior Software Engineers, and Engineering Managers at companies using GitHub or GitLab who are receiving AI-generated code from their teams.
How manyTens of thousands. You can find them by searching for job titles like Tech Lead or Senior Software Engineer on LinkedIn and filtering for GitHub or GitLab skills, or by scraping contributors on active repositories.
Just became possible8/10
Somebody is visibly in pain9/10
It is software, not a document9/10
The buyer has a name9/10
Enough of them can be reached9/10
Being built?
Nobody is testing this yet, including us. It has cleared the evidence tests and nothing more than that has been established.
Cleared all five tests
found 12 September
MCP Access Policy and Token Validator
Takes an MCP server endpoint and runs automated checks to flag broken or missing access policies and token bindings against the new authorization spec.
The gapResearchers found that 1 in 5 MCP access policies came back broken or missing. Developers are rapidly wiring AI assistants into internal APIs and Slack with poorly understood trust models, creating new attack paths. Non-human identities and machine credentials are now the leading path into the enterprise, as seen in the recent healthcare data thefts at Nutex and McKesson.
Why nowThe Model Context Protocol maintainers shipped a specification update on July 28, 2026, built almost entirely around authorization, introducing issuer-bound client credentials and Client ID Metadata Documents as the preferred way for clients to register.
Who has itAI application developers, platform engineers, and security engineers at companies actively building or deploying AI agents and MCP integrations. Job titles include 'AI Engineer', 'Platform Engineer', and 'Security Engineer'.
How manyLow thousands. You can find them by searching professional profiles for 'Model Context Protocol' or 'MCP' combined with 'AI' or 'Developer', and by scanning GitHub for repositories importing MCP SDKs. It requires effort and specific filtering.
Just became possible9/10
Somebody is visibly in pain7/10
It is software, not a document10/10
The buyer has a name6/10
Enough of them can be reached6/10
Being built?
Nobody is testing this yet, including us. It has cleared the evidence tests and nothing more than that has been established.
Cleared all five tests
found 5 September
AI Agent Security Vendor Questionnaire Filler
Ingests a vendor security document and the new AI cyber defense questionnaire, drafts the answers, and outputs a completed assessment for review.
The gapCyberScoop reports the new Collective Cyber Defense letter acts as a procurement catalog and wrote your next vendor questionnaire, forcing buyers to assess AI specific risks. AWS notes the core pain is knowing who granted AI agents access and what exposure looks like if credentials leak.
Why nowThe Collective Cyber Defense letter recently published a standardized AI agent security questionnaire, and modern LLMs can now ingest long unstructured PDFs and accurately map them to custom question sets without manual configuration.
Who has itThird Party Risk Analysts, Vendor Security Managers, Procurement Compliance Officers, and GRC Analysts at mid to large enterprises.
How manyRoughly tens of thousands. Search for Third Party Risk Analyst or Vendor Security Manager on LinkedIn and filter by enterprise companies.
Just became possible8/10
Somebody is visibly in pain9/10
It is software, not a document10/10
The buyer has a name10/10
Enough of them can be reached10/10
Being built?
Nobody is testing this yet, including us. It has cleared the evidence tests and nothing more than that has been established.
Cleared all five tests
found 4 September
AI Agent Permission Mapper and Auditor
Ingests agent configuration files and outputs a permission map highlighting over-privileged access and missing human-in-the-loop checks.
The gapSecurity teams cannot answer which AI agents have access to customer data, who granted it, and what exposure would look like if a credential leaked. As stated in the AWS blog: 'If nobody in your organization can answer that in under a minute, this post is for you.'
Why nowThe recent release of autonomous AI agent frameworks and AWS Bedrock AgentCore Gateway introduced machine-speed agents that invoke tools without human intervention, creating the need to audit agent configurations before deployment.
Who has itSecurity Engineers, GRC Analysts, and Deputy CISOs at mid-to-large enterprises adopting AI agents. Filter by titles containing 'Security', 'GRC', or 'CISO' at companies with active AI or ML engineering teams.
How manyThousands. Search for 'Security Engineer' or 'GRC' profiles on professional networks filtering for companies in tech or finance with recent job postings for 'AI Engineer' or 'LLM'.
Just became possible8/10
Somebody is visibly in pain8/10
It is software, not a document9/10
The buyer has a name6/10
Enough of them can be reached8/10
Being built?
Nobody is testing this yet, including us. It has cleared the evidence tests and nothing more than that has been established.
Cleared all five tests
found 27 August
Databricks Medallion Pipeline Code Generator
Users input a source schema and the application outputs complete Bronze to Silver to Gold Databricks pipelines with Unity Catalog permissions and CI/CD bundles.
The gapData engineers spend weeks standing up a single new data source, writing ETL, and hand-writing quality checks. This is evidenced by the AWS article stating data engineering teams routinely spend weeks standing up a single new data source doing pipeline plumbing, and job postings requiring hands-on implementation of Medallion architectures and Databricks Asset Bundles.
Why nowThe release of LLM based agentic workflows, specifically the Agentic Data Operations Platform reference architecture on AWS using Amazon Bedrock, which demonstrates that AI agents can now reliably automate the generation of ETL code, quality checks, and semantic models for the Bronze to Silver to Gold lifecycle.
Who has itData Engineers, Data Platform Engineers, and Analytics Engineers. Seniority ranges from working student to senior professional. Filter by proficiency in Databricks, Snowflake, Unity Catalog, and Medallion architecture across consulting and enterprise sectors.
How manyTens of thousands. Search professional networks for job titles Data Engineer or Data Platform Engineer with keywords Databricks, Snowflake, or Medallion. This is a trivially identifiable global audience.
Just became possible8/10
Somebody is visibly in pain8/10
It is software, not a document10/10
The buyer has a name10/10
Enough of them can be reached10/10
Being built?
Nobody is testing this yet, including us. It has cleared the evidence tests and nothing more than that has been established.
Cleared all five tests
found 25 August
Agentic AI Token Bleed Analyzer
Ingests multi-agent system trace logs and flags duplicate prompts and unnecessary tool calls to reduce cloud spend.
The gapEngineering teams deploying AI agents face a severe tax on latency, infrastructure, and cloud spend due to repeated retrievals, duplicate prompts, unnecessary tool calls, and oversized context windows. A proof-of-concept agent that answers 50 questions a day can tolerate inefficiencies, but an enterprise platform coordinating thousands of requests per minute cannot.
Why nowThe proliferation of agentic AI systems in production, supported by new frameworks and tools from OpenAI, DeepSeek, and Confluent, has created a new class of log data and the associated token-bleed cost problem at enterprise scale.
Who has itAI Engineers, Machine Learning Engineers, GenAI developers, and Platform Engineers. Tech sector, enterprise companies running AI in production.
How manyThousands. Search for AI Engineer or Machine Learning Engineer on professional networks, filtering by tech companies and skills like LLM or LangChain.
Just became possible7/10
Somebody is visibly in pain9/10
It is software, not a document8/10
The buyer has a name8/10
Enough of them can be reached8/10
Being built?
Nobody is testing this yet, including us. It has cleared the evidence tests and nothing more than that has been established.
Cleared all five tests
found 23 August
AI Agent Token Bleed Analyzer
Ingests multi-agent execution logs and flags duplicate prompts, unnecessary tool calls, and oversized context windows to reduce cloud spend.
The gapEngineering teams deploying AI agents discover that the hidden cost is everything around the model: repeated retrievals, duplicate prompts, unnecessary tool calls, oversized context windows, and multiple agents reasoning over the same information, which become a severe tax on latency, infrastructure, and cloud spend at production scale.
Why nowThe shift from single-model proofs-of-concept to production multi-agent systems at scale (as seen at DoorDash and AWS) has created the specific problem of token bleed, which was not a significant cost issue for one-shot predictions.
Who has itAI Engineers, Machine Learning Engineers, and Backend Developers at technology companies deploying LLM-based agents in production.
How manyLow thousands. You can find them by searching for titles like 'AI Engineer' or 'ML Engineer' on LinkedIn and filtering for profiles mentioning agent frameworks like LangChain, LlamaIndex, or OpenAI API.
Just became possible7/10
Somebody is visibly in pain8/10
It is software, not a document8/10
The buyer has a name6/10
Enough of them can be reached6/10
Being built?
Nobody is testing this yet, including us. It has cleared the evidence tests and nothing more than that has been established.
Cleared all five tests
found 22 August
Autonomous Attack Path Mapper
Users input their external asset list and the software uses GPT-5.6 Cyber to simulate autonomous attacker learning cycles, returning a prioritized list of exploitable vulnerabilities.
The gapCritical infrastructure defenders are facing near-autonomous AI attacks that scan for misconfigurations and exploitable vulnerabilities in parallel. The evidence states attackers set up frameworks to adapt mid-operation without human intervention and implement Learning Cycles to search vulnerability databases and GitHub for techniques applicable to target infrastructure.
Why nowOpenAI released GPT-5.6 Cyber, a model trained for security work that answers 95% of exploit chain and authentication bypass requests, bypassing the standard safeguards that block general models. This allows a solo developer to build an autonomous attack simulation tool that previously would have been blocked by API safety filters.
Who has itVulnerability management engineers, security operations center analysts, and CISOs in critical infrastructure sectors like energy, water, and manufacturing.
How manyThousands. You can find them by searching LinkedIn for titles like Vulnerability Management, SOC Analyst, or CISO combined with critical infrastructure sectors like Energy, Water, or Manufacturing.
Just became possible9/10
Somebody is visibly in pain8/10
It is software, not a document9/10
The buyer has a name8/10
Enough of them can be reached8/10
Being built?
Nobody is testing this yet, including us. It has cleared the evidence tests and nothing more than that has been established.
Cleared all five tests
found 16 August
Clinical Policy Digitizer for Health Plans
Upload clinical policy PDFs and the software extracts structured decision rules, coverage criteria, and thresholds into machine-readable format for automation and audit.
The gapHealth plans deploy AI into claims and prior authorization but see clean claims sent back for missing context, prior authorizations stalled over data that already exists, and continued manual reviews because systems cannot agree. Per the AWS article: prior authorization remains one of the most manual processes in healthcare, not because the medical reasoning is flawed, but because the policies that govern it are trapped in static, unstructured formats that resist automation. Policy content varies by clinical area, geography, line of business, and health plan, and evolves as medicine advances, with no systematic way to manage, analyze, or automate against it.
Why nowLLMs can now reliably extract structured decision logic from dense, varied clinical policy documents. The AWS article on Cohere Health confirms this is newly feasible: policies governing prior authorization are trapped in static, unstructured formats that resist automation, and they are using Amazon Bedrock to digitize them. Capable LLM APIs make this extraction buildable by a solo developer without a clinical NLP team.
Who has itClinical policy directors, medical directors, prior authorization managers, utilization management leads, and clinical informatics officers at US health plans and payer organizations. Filter on LinkedIn and enrichment data for titles containing clinical policy, medical director, prior authorization, or utilization management, where employer type is health insurance company, health plan, or managed care organization.
How manyLow thousands. There are roughly 5,000 health plans in the US, with relevant decision-makers clustering at the larger ones. A LinkedIn search for clinical policy OR prior authorization combined with employer type health plan or health insurance yields an estimated 1,000 to 3,000 identifiable individuals. Broadening to health system compliance and informatics roles dealing with AI governance adds perhaps another 2,000. The search is describable in one sentence but requires sector filtering.
Just became possible6/10
Somebody is visibly in pain8/10
It is software, not a document8/10
The buyer has a name6/10
Enough of them can be reached6/10
Being built?
Nobody is testing this yet, including us. It has cleared the evidence tests and nothing more than that has been established.
Cleared all five tests
found 13 August
Extract and Query Prior Authorization Policy Requirements
Upload prior authorization policy documents, the software extracts clinical criteria and documentation requirements into structured searchable data, and you query what is needed for any procedure code.
The gapPrior authorization is described as 'one of the most manual processes in healthcare, not because the medical reasoning for requiring approval is flawed, but because the policies that govern it are trapped in static, unstructured formats that resist automation' (AWS/Cohere Health). KPMG reports payers seeing 'clean claims sent back for missing context, prior authorizations stalled over data that already exists, and a need for continued manual reviews because systems cannot agree.' Corporate Compliance Insights notes AI now shapes 'documentation, triage, utilization review, patient communication, clinical decision support' but used recklessly creates 'operational, legal and patient-safety risks.' Staff manually read through policy documents to determine requirements for each case.
Why nowLLMs can now reliably extract structured clinical criteria from complex, unstructured medical policy documents. The Cohere Health case study using Amazon Bedrock (August 2026) confirms this is production-feasible for prior authorization policies specifically. Pre-LLM NLP could not handle the variation, clinical terminology, and conditional logic in these documents. However, the underlying LLM document extraction capability has been available since 2023; what is new is its confirmed application to this specific domain at production scale.
Who has itPrior authorization specialists, utilization review nurses, utilization management coordinators, and clinical informatics analysts at US health plans and large provider organizations. Job titles include 'Prior Authorization Specialist,' 'Utilization Review Nurse,' 'Utilization Management Coordinator,' and 'Clinical Informatics Analyst.' Sector: health insurance companies, hospital systems, and managed care organizations.
How manySearch LinkedIn for titles containing 'Prior Authorization' or 'Utilization Review' or 'Utilization Management' in healthcare, health insurance, and hospital sectors. These are recognized, common job titles. There are likely tens of thousands of such professionals in the US. Filter by employer type: health insurance company, hospital system, managed care organization. The search is describable in one sentence.
Just became possible5/10
Somebody is visibly in pain8/10
It is software, not a document8/10
The buyer has a name8/10
Enough of them can be reached8/10
Being built?
Nobody is testing this yet, including us. It has cleared the evidence tests and nothing more than that has been established.
Cleared all five tests
found 12 August
Clinical Policy Digitizer for Prior Authorization
Upload clinical policy documents and the software extracts structured authorization criteria, documentation requirements, and exclusion rules as machine-readable data.
The gapPrior authorization managers and clinical policy teams at health plans. The AWS blog states directly: 'Prior authorization remains one of the most manual processes in healthcare, not because the medical reasoning for requiring approval is flawed, but because the policies that govern it are trapped in static, unstructured formats that resist automation.' The KPMG article adds: 'clean claims sent back for missing context, prior authorizations stalled over data that already exists, and a need for continued manual reviews because systems can't agree.'
Why nowLLMs can now extract structured clinical rules from unstructured policy text that previously required manual coding or expensive custom NLP projects. The Cohere Health and Amazon Bedrock AgentCore signal confirms this is newly possible: prior authorization policies are 'trapped in static, unstructured formats that resist automation' and LLM-based agents are now being used to digitize them. Before capable LLMs, this extraction required teams of clinical informaticists hand-coding rules into decision engines.
Who has itPrior authorization managers, clinical policy analysts, utilization management directors, and clinical informatics specialists at health insurance companies, health plans, and payer organizations. Seniority ranges from manager to director level. The filter is: job title containing 'prior authorization' or 'clinical policy' or 'utilization management' AND employer in the health insurance or managed care sector.
How manyRoughly 2,000 to 5,000 people in the United States. There are approximately 900 health insurance companies, each employing several people in prior authorization and clinical policy roles. The search is: LinkedIn people search for titles containing 'prior authorization' OR 'clinical policy' OR 'utilization management' filtered by industry 'hospital and health care' or 'insurance' and employer type 'health plan' or 'health insurance.' This requires combining title keywords with sector filtering, which is moderate effort but not exotic.
Just became possible7/10
Somebody is visibly in pain8/10
It is software, not a document7/10
The buyer has a name6/10
Enough of them can be reached6/10
Being built?
Nobody is testing this yet, including us. It has cleared the evidence tests and nothing more than that has been established.
Cleared all five tests
found 11 August
AI Agent Permission Boundary Generator
Ingests an agent's tool definitions and generates a restrictive runtime policy file that blocks unauthorized actions.
The gapDevelopers building AI agents are exposing production systems to prompt injection. Evidence: Coding Agent Horror Stories where the agent runs as you, with your filesystem permissions and your credentials, and nothing sits between the model's decision and the shell's execution. Also: many teams still focus almost entirely on prompt engineering here, but once an agent acts through tools, tool access becomes production access.
Why nowThe widespread adoption of AI agents that call external tools and APIs. As noted in the supply signals, the moment an agent calls a tool, tool access becomes production access. The agent runs as you, with your filesystem permissions and your credentials. This execution surface for LLMs is new this year.
Who has itPlatform engineers, backend engineers, and AI engineers building autonomous agents or coding assistants. Seniority ranges from mid level to staff. Signal: profiles mentioning LangChain, LlamaIndex, Vercel AI SDK, OpenAI function calling, or AI agent in conjunction with engineering titles.
How manyThousands. Search LinkedIn for AI Engineer or Platform Engineer and filter by skills like LangChain or OpenAI. GitHub repositories using agent frameworks also provide a trail to contributors and maintainers.
Just became possible8/10
Somebody is visibly in pain8/10
It is software, not a document10/10
The buyer has a name8/10
Enough of them can be reached8/10
Being built?
Nobody is testing this yet, including us. It has cleared the evidence tests and nothing more than that has been established.
Cleared all five tests
found 11 August
AI Tool Risk and Review Mandate Assessor
Ingests your AI tool inventory and flags which deployments require mandatory human review and governance oversight.
The gapIT, security, and business leaders are struggling with AI governance and readiness. Evidence shows that most US companies lack mature AI governance frameworks, and only 43% mandate human review of AI-generated code despite 75% having encountered production issues attributable to AI. Leadership readiness lags behind AI adoption rates.
Why nowThe rapid spread of agentic AI and AI-generated code in production, with 40% reporting AI generates the majority of production code, has created an immediate governance gap that did not exist before. This is evidenced by the fact that 75% of organizations have already encountered production issues attributable to AI.
Who has itCISOs, IT Directors, GRC Managers, and Engineering Managers in mid-to-large companies actively deploying AI tools and agentic systems.
How manyThousands. You can find them by searching for titles like CISO, IT Director, GRC Manager, and Engineering Manager at companies with over 500 employees, filtering for those who have recently posted about AI adoption or governance.
Just became possible7/10
Somebody is visibly in pain8/10
It is software, not a document8/10
The buyer has a name8/10
Enough of them can be reached8/10
Being built?
Nobody is testing this yet, including us. It has cleared the evidence tests and nothing more than that has been established.
Cleared all five tests
found 6 August
AI Code Review Enforcement Gate
Ingests pull request data, detects AI-generated code, and blocks merges unless explicit human review is logged.
The gapDevOps and engineering leaders are hurting from production incidents caused by unreviewed AI code. The evidence states that 75 percent have encountered a production issue confirmed to be attributable to AI, with 42 percent experiencing multiple incidents, yet only 43 percent mandate human review.
Why nowThe widespread deployment of AI coding assistants, which now generate the majority of production code for 40 percent of organizations, creating a new class of unreviewed code incidents that did not exist before this scale of AI deployment.
Who has itEngineering Managers, DevOps Leads, and Security Engineers at mid-to-large software companies using GitHub or GitLab.
How manyThousands. You can find them by searching LinkedIn for titles like Engineering Manager or DevOps Engineer, filtering by the software industry and companies with over 100 employees.
Just became possible7/10
Somebody is visibly in pain8/10
It is software, not a document9/10
The buyer has a name9/10
Enough of them can be reached8/10
Being built?
Nobody is testing this yet, including us. It has cleared the evidence tests and nothing more than that has been established.
Cleared all five tests
found 4 August
Automated LLM Red-Teaming and Guardrail Tester
Users input their LLM application endpoint or system prompt, the software runs a battery of prompt injection and jailbreak attacks, and outputs a vulnerability report detailing failed guardrails.
The gapCompanies hire teams of human testers to try to come up with novel attacks that break existing guardrails, a process known as red-teaming. AppSec professionals face high false-positive rates and extra work when using LLMs to find vulnerabilities.
Why nowFrontier AI models like Anthropic's can now discover new mathematical cryptanalytic attacks and uncover vulnerabilities faster than maintainers, making automated generation of novel prompt injection attacks viable. Local models are also now viable for running continuous testing loops.
Who has itAppSec professionals, AI security engineers, and security architects at companies building LLM-based applications.
How manyThousands. Search for AppSec Engineer, AI Security Engineer, or Security Architect at tech companies and enterprises actively deploying AI agents. Filter by companies mentioning LLMs or AI in their engineering blogs or job postings.
Just became possible8/10
Somebody is visibly in pain8/10
It is software, not a document9/10
The buyer has a name8/10
Enough of them can be reached8/10
Being built?
Nobody is testing this yet, including us. It has cleared the evidence tests and nothing more than that has been established.
Cleared all five tests
found 3 August
AI Agent Governance Gap Scanner Against NIST AI RMF
Input your organization's AI agents and their system access, and the application maps each against AI governance frameworks to flag missing controls, excessive permissions, and compliance gaps.
The gapSecurity leaders are encountering production incidents caused by AI agents. 75% of survey respondents have confirmed production issues attributable to AI, with 42% experiencing multiple incidents. Only 43% mandate human review of AI-generated code and just 18% have standardized AI agent governance. A Fortune 50 CISO described an incident where an AI automation agent with legitimate access caused a critical reconciliation process to fail badly enough to draw regulatory scrutiny.
Why nowAI agents are now deployed at scale in enterprises for the first time. Okta research documents the speed of AI agent adoption, and a DevOps survey finds 54% of organizations use AI across more than half their SDLC with 40% reporting AI generates the majority of production code. The NIST AI RMF provides a published standard to assess against. Before this year, there were not enough autonomous AI agents in production environments to warrant a dedicated governance assessment tool.
Who has itCISOs, Heads of AI Governance, GRC Managers, Security Architects, and IT Security Directors at mid-to-large enterprises (500+ employees) that have deployed AI tools. Identifiable by job title on LinkedIn with sector filtering for technology, finance, and healthcare.
How manyThousands. Search LinkedIn for CISO OR Head of AI Governance OR GRC Manager OR Security Architect at companies with 500+ employees. The compliance platform's registered accounts and the BigCommerce store's SEO traffic to framework-specific pages provide additional reach to practitioners already searching for AI governance content.
Just became possible6/10
Somebody is visibly in pain8/10
It is software, not a document7/10
The buyer has a name8/10
Enough of them can be reached8/10
Being built?
Nobody is testing this yet, including us. It has cleared the evidence tests and nothing more than that has been established.
Cleared all five tests
found 2 August
EU AI Act Chatbot Disclosure Auditor
Users input their public chatbot URLs, the software simulates user interactions and checks for mandatory AI disclosures, and outputs a compliance gap report.
The gapFrom 2 August 2026, new transparency rules will start to apply, requiring certain AI systems to tell users when they are interacting with AI. Chatbots and other interactive AI systems will have to tell users they are dealing with AI, not a human.
Why nowThe European Commission published guidelines on transparency obligations and enforcement begins on 2 August 2026, creating a specific, dated compliance requirement for AI deployers.
Who has itCompliance officers, legal counsel, and product managers at companies deploying AI systems in the EU.
How manyThousands. Search LinkedIn for Compliance Officer, Legal Counsel, or Product Manager in EU countries with keywords AI or Artificial Intelligence.
Just became possible7/10
Somebody is visibly in pain8/10
It is software, not a document8/10
The buyer has a name8/10
Enough of them can be reached8/10
Being built?
Nobody is testing this yet, including us. It has cleared the evidence tests and nothing more than that has been established.
Cleared all five tests
found 1 August
AI Agent Permission Blast Radius Auditor
Ingests an IAM export and flags over-privileged AI agents and service accounts, outputting a risk report of what they could access if compromised.
The gapSecurity teams are dealing with incidents where AI agents with legitimate access cause critical processes to go wrong, drawing regulatory scrutiny. Attackers are also using autonomous AI agents in unrestricted modes to automate post-exploitation and espionage.
Why nowThe rapid adoption of autonomous AI agents in enterprise IT environments, as highlighted by Okta research and Cloud Security Alliance reports, means non-human identities now have broad, legitimate access to critical systems. This creates a new attack vector that traditional IAM tools do not contextualize for agentic behavior.
Who has itCISOs, Security Architects, and IAM Managers in mid-to-large enterprises who are adopting AI automation tools.
How manyThousands. Identifiable by searching for CISO, Security Architect, or IAM Manager titles at companies with over 500 employees, filtering for those mentioning AI adoption or zero trust in their profiles.
Just became possible7/10
Somebody is visibly in pain8/10
It is software, not a document8/10
The buyer has a name8/10
Enough of them can be reached8/10
Being built?
Nobody is testing this yet, including us. It has cleared the evidence tests and nothing more than that has been established.
Cleared all five tests
found 28 July
Intelligent AI Model Router for Engineering
Takes engineering API requests, routes them to the optimal LLM based on task and cost, and returns the response.
The gapA head of engineering at a larger company told Pragmatic Engineer they wished there was an "intelligent" router that picks the right model for the right task to reduce spending on AI within engineering departments.
Why nowCouchbase's multi-model AI architecture and the Pragmatic Engineer's coverage of smart model routing show that managing multiple LLM providers and routing traffic between them is a newly emerging capability as enterprise AI usage scales.
Who has itHeads of Engineering, VPs of Engineering, and AI Platform Leads at mid to large companies using multiple AI coding tools.
How manyThousands. Search for "Head of Engineering" or "VP of Engineering" at companies with 100+ employees, filtering for those mentioning AI or LLM adoption.
Just became possible7/10
Somebody is visibly in pain8/10
It is software, not a document9/10
The buyer has a name8/10
Enough of them can be reached8/10
Being built?
Nobody is testing this yet, including us. It has cleared the evidence tests and nothing more than that has been established.
Cleared all five tests
found 26 July
MCP Data Product Containerizer
A user inputs a database connection and a table, and the software outputs a containerized API endpoint with schema and metadata that AI agents can safely query via MCP.
The gapEnterprise AI teams are struggling with the complex 'data management hairball' and vendor lock-in when trying to give AI agents access to internal data. They need scalable, safe architectures for AI without getting locked into a single unified platform that makes it hard to migrate or see where compute is going.
Why nowThe Model Context Protocol (MCP) for progressive tool discovery, allowing AI agents to safely access encapsulated data products, as highlighted in the InfoQ presentation on autonomous data products.
Who has itData Engineers, Platform Engineers, and AI Engineers at mid-to-large enterprises who are building internal AI tools and need to expose data safely to agents.
How manyThousands. You can search LinkedIn for 'Data Engineer' OR 'Platform Engineer' OR 'AI Engineer' at companies using Snowflake, Databricks, or LangChain. Filter further by profiles mentioning 'LLM' or 'AI agents'.
Just became possible8/10
Somebody is visibly in pain6/10
It is software, not a document9/10
The buyer has a name8/10
Enough of them can be reached8/10
Being built?
Nobody is testing this yet, including us. It has cleared the evidence tests and nothing more than that has been established.
Cleared all five tests
found 26 July
MCP Gateway Security and Tracing Proxy
You route your AI agent MCP traffic through this proxy, it inspects stateless HTTP payloads for security vulnerabilities, and outputs OpenTelemetry traces and alerts.
The gapDevelopers building AI agents face a massive operational headache regarding observability and novel, highly sophisticated attack vectors because the new stateless MCP spec allows agents to execute code and query data through these new payload mechanisms.
Why nowThe July 28, 2026 MCP specification introduced stateless HTTP, custom _meta payload objects, dynamic parameter routing, and x-mcp-header mapping, which created these specific observability and security gaps that did not exist in the previous stateful protocol.
Who has itAI Engineers, Platform Engineers, Backend Engineers, and DevOps Engineers at technology companies building and deploying AI agents that use the Model Context Protocol.
How manyThousands. You can search LinkedIn for job titles AI Engineer, Platform Engineer, or Backend Engineer and filter by companies in the AI sector or individuals mentioning AI agents or MCP in their profiles.
Just became possible10/10
Somebody is visibly in pain8/10
It is software, not a document10/10
The buyer has a name8/10
Enough of them can be reached8/10
Being built?
We are testing this one. A landing page is live, asking visitors for capture. So far 6 visits from someone who is not us, 3 of our own health checks excluded, and 0 confirmed emails. That is not yet evidence of demand.
Get the next one
A gap only earns a place here when it clears all five tests, which most do not. When the next
one does, we will send it to you with the evidence attached. Nothing else, and one click
removes you.
Double opt-in. You are not on the list until you click the link in
the email we send. We never sell or share the list.
How a gap earns its place
Five tests, each a floor rather than an average, so a perfect score on four cannot
carry a failure on the fifth. The scores are a language model's reading of the evidence; the
thresholds and the arithmetic are ours and live in code, so the model can be persuasive without
being decisive.
| The test | Floor | What it asks |
|---|
| Just became possible | 5 | Something changed that makes this buildable now, and it is a capability change rather than a news story. A protocol shipped, an API opened, a rule took effect. If it was equally buildable two years ago and nobody built it, that is usually a reason. |
| Somebody is visibly in pain | 6 | The pain is on the record somewhere we can point at: a regulatory filing, an incident disclosure, a job advertisement, a practitioner forum. Not assumed, not inferred from a market size. |
| It is software, not a document | 7 | A real input, a real output, and it does work somebody currently does by hand. The most common way a promising gap turns out to be nothing is that the answer is a template. |
| The buyer has a name | 6 | Nameable by role and employer rather than described as a category. \u201cCompliance teams\u201d is not an audience; \u201cGRC managers at enterprises running OpenAI Enterprise\u201d is. |
| Enough of them can be reached | 6 | Several thousand of exactly those people can be found and contacted starting from nothing. Not whether anybody already owns the list. |
What has actually been proved
None of these has been proved yet. No stranger has confirmed they want any of them badly enough to hand over a work email. The evidence above is real and checkable; it is still evidence that a problem exists, not proof that anyone will pay to have it solved. Anybody telling you they can tell the difference without testing is guessing.
Why we publish this rather than keep it
An idea is not an asset. Anybody with a language model can generate a hundred plausible
product ideas before lunch, and the reason almost all of them are worthless is that they carry
no evidence and nobody checked. What is scarce is the refusal: 1226 of 1250 killed,
each for a stated reason, published at the kill log.
So the gaps go out in full. If you build one, that is a better
outcome than it sitting in a database, and we would like to know how it went.
A visit only counts here if it did not come from us: the box polls
its own test pages to confirm they are serving, and 3 such health checks were
excluded to produce the 6 real visits counted above. A capture only counts
if it was confirmed by double opt-in, is not a disposable domain, and is not the operator
testing his own form.
The 1226 that failed, and why ·
Today's edition · How programmes fail