Unmet demand, published in full

What the market needs that does not exist yet

We read regulatory filings, standards bodies, incident disclosures, job advertisements and practitioner forums looking for problems that have just become solvable and that somebody is visibly in pain about. Of 64 candidates, 60 failed the evidence tests. These 4 did not.

Updated

4gaps with evidence
60candidates that failed
1being tested
0proved by a stranger

The gaps

Newest first. Each carries what changed to make it buildable, who is on record being in pain, exactly who the buyer is, and how many of them can be reached from a standing start. Everything here is published in full because a gap you can see is worth more than a gap we are hinting at, and because if one of these is wrong we would rather be told.

Cleared all five tests found 27 July

AI Agent Permission and Risk Scanner

Users connect their OpenAI Workspace and GitHub environments, the software scans agent configurations and MCP connections for excessive permissions or malicious repositories, and outputs a prioritized remediation list.

The gapSecurity teams are struggling with the policies that decide what an agent can do on its own and the escalation path for when it cannot. The AgentForger flaw showed a single phishing link could stealthily build and deploy an autonomous agent. The Cloud Security Alliance notes a critical reconciliation process went wrong because an AI agent was granted legitimate access but acted rogue.
Why nowOpenAI recently shipped Presence, an enterprise AI agent platform, and malicious actors have begun targeting AI coding agents via fake MCP servers (FakeGit). The ability to audit these specific agent configurations is newly possible because the platforms and the threats are new.
Who has itCISOs, IT Security Directors, and GRC Managers at mid-to-large enterprises deploying AI agents.
How manyLow thousands. Search for CISO or Director of Information Security on LinkedIn, filter by companies with over 200 employees. Enrich the list to find those using OpenAI Enterprise or GitHub Copilot in their tech stack.
Just became possible8/10
Somebody is visibly in pain7/10
It is software, not a document8/10
The buyer has a name6/10
Enough of them can be reached6/10
Being built? Nobody is testing this yet, including us. It has cleared the evidence tests and nothing more than that has been established.
Cleared all five tests found 27 July

MCP Traffic Inspector and Security Scanner

Users route their MCP traffic or upload logs, and the software reconstructs multi-round-trip agentic loops and flags security risks like malicious _meta payloads.

The gapDevelopers building AI tools face a massive operational headache with observability of stateless multi-round-trip calls, and the new spec features have opened up novel, highly sophisticated attack vectors if agents can execute code or query data.
Why nowThe July 28 Model Context Protocol specification shifts to a stateless HTTP engine, removing sessions and introducing custom _meta payload objects, dynamic parameter routing, and x-mcp-header mapping, which create new observability and security challenges.
Who has itAI engineers, platform engineers, and backend developers building AI agents and integrations, particularly those using Apigee, Terraform, or GitHub MCP servers.
How manyThousands. Identifiable by job titles like AI Engineer or Platform Engineer combined with skills in LLMs, Anthropic, or MCP on professional profiles.
Just became possible9/10
Somebody is visibly in pain8/10
It is software, not a document9/10
The buyer has a name8/10
Enough of them can be reached8/10
Being built? Nobody is testing this yet, including us. It has cleared the evidence tests and nothing more than that has been established.
Cleared all five tests found 26 July

MCP Data Product Containerizer

A user inputs a database connection and a table, and the software outputs a containerized API endpoint with schema and metadata that AI agents can safely query via MCP.

The gapEnterprise AI teams are struggling with the complex 'data management hairball' and vendor lock-in when trying to give AI agents access to internal data. They need scalable, safe architectures for AI without getting locked into a single unified platform that makes it hard to migrate or see where compute is going.
Why nowThe Model Context Protocol (MCP) for progressive tool discovery, allowing AI agents to safely access encapsulated data products, as highlighted in the InfoQ presentation on autonomous data products.
Who has itData Engineers, Platform Engineers, and AI Engineers at mid-to-large enterprises who are building internal AI tools and need to expose data safely to agents.
How manyThousands. You can search LinkedIn for 'Data Engineer' OR 'Platform Engineer' OR 'AI Engineer' at companies using Snowflake, Databricks, or LangChain. Filter further by profiles mentioning 'LLM' or 'AI agents'.
Just became possible8/10
Somebody is visibly in pain6/10
It is software, not a document9/10
The buyer has a name8/10
Enough of them can be reached8/10
Being built? Nobody is testing this yet, including us. It has cleared the evidence tests and nothing more than that has been established.
Cleared all five tests found 26 July

MCP Gateway Security and Tracing Proxy

You route your AI agent MCP traffic through this proxy, it inspects stateless HTTP payloads for security vulnerabilities, and outputs OpenTelemetry traces and alerts.

The gapDevelopers building AI agents face a massive operational headache regarding observability and novel, highly sophisticated attack vectors because the new stateless MCP spec allows agents to execute code and query data through these new payload mechanisms.
Why nowThe July 28, 2026 MCP specification introduced stateless HTTP, custom _meta payload objects, dynamic parameter routing, and x-mcp-header mapping, which created these specific observability and security gaps that did not exist in the previous stateful protocol.
Who has itAI Engineers, Platform Engineers, Backend Engineers, and DevOps Engineers at technology companies building and deploying AI agents that use the Model Context Protocol.
How manyThousands. You can search LinkedIn for job titles AI Engineer, Platform Engineer, or Backend Engineer and filter by companies in the AI sector or individuals mentioning AI agents or MCP in their profiles.
Just became possible10/10
Somebody is visibly in pain8/10
It is software, not a document10/10
The buyer has a name8/10
Enough of them can be reached8/10
Being built? We are testing this one. A landing page is live, asking visitors for capture. So far 5 visits from someone who is not us, 3 of our own health checks excluded, and 0 confirmed emails. That is not yet evidence of demand.

Get the next one

A gap only earns a place here when it clears all five tests, which most do not. When the next one does, we will send it to you with the evidence attached. Nothing else, and one click removes you.

Double opt-in. You are not on the list until you click the link in the email we send. We never sell or share the list.

How a gap earns its place

Five tests, each a floor rather than an average, so a perfect score on four cannot carry a failure on the fifth. The scores are a language model's reading of the evidence; the thresholds and the arithmetic are ours and live in code, so the model can be persuasive without being decisive.

The testFloorWhat it asks
Just became possible5Something changed that makes this buildable now, and it is a capability change rather than a news story. A protocol shipped, an API opened, a rule took effect. If it was equally buildable two years ago and nobody built it, that is usually a reason.
Somebody is visibly in pain6The pain is on the record somewhere we can point at: a regulatory filing, an incident disclosure, a job advertisement, a practitioner forum. Not assumed, not inferred from a market size.
It is software, not a document7A real input, a real output, and it does work somebody currently does by hand. The most common way a promising gap turns out to be nothing is that the answer is a template.
The buyer has a name6Nameable by role and employer rather than described as a category. \u201cCompliance teams\u201d is not an audience; \u201cGRC managers at enterprises running OpenAI Enterprise\u201d is.
Enough of them can be reached6Several thousand of exactly those people can be found and contacted starting from nothing. Not whether anybody already owns the list.

What has actually been proved

None of these has been proved yet. No stranger has confirmed they want any of them badly enough to hand over a work email. The evidence above is real and checkable; it is still evidence that a problem exists, not proof that anyone will pay to have it solved. Anybody telling you they can tell the difference without testing is guessing.

Why we publish this rather than keep it

An idea is not an asset. Anybody with a language model can generate a hundred plausible product ideas before lunch, and the reason almost all of them are worthless is that they carry no evidence and nobody checked. What is scarce is the refusal: 60 of 64 killed, each for a stated reason, published at the kill log.

So the gaps go out in full. If you build one, that is a better outcome than it sitting in a database, and we would like to know how it went.

A visit only counts here if it did not come from us: the box polls its own test pages to confirm they are serving, and 3 such health checks were excluded to produce the 5 real visits counted above. A capture only counts if it was confirmed by double opt-in, is not a disposable domain, and is not the operator testing his own form.

The 60 that failed, and why · Today's edition · How programmes fail