RSS Amplifier

Endwise · Aug 11, 2026

Startup Funeral: Human-Led Assurance

0
Sign in to vote or save

Joseph Bianchi 🤺 · Endwise

Vanitas Still Life. Pieter Claesz, 1630. Mauritshuis, The Hague.

On the twenty-seventh of July my company died.

In the morning I ran my consulting practice’s cold client persona against Y Combinator’s Fall-2026 Requests for Startups, and found the thesis I had been building for a month sitting inside three of their requests at once: Proving You’re Human, AI-Native Compliance Infrastructure, and the physical-world operating-systems theme underneath both. One idea, three market wrappers, and I took it the way it felt: as a massive validation, from the largest founder funnel in technology.

And in the afternoon I paid roughly forty-four cents to have two adversarial models and a live competitive scan try to kill it, and they killed it at every node I had. There was no build to stop, no team to tell, no investor to email. The whole company existed for about four weeks, entirely inside a research file, and its biggest expense was an afternoon.

I want to hold a funeral for it, publicly. Startup post-mortems are a well-populated genre, and almost every one is written after the money: after the seed round, the two years, the wind-down email thanking the team for believing. The sunk cost is what makes the piece feel earned. It is also what makes it useless. By the time a corpse is expensive enough to eulogize properly, every decision that killed it is years behind the reader, wrapped in circumstances that will not recur. What almost nobody writes is the other kind: the idea that died on time, cheaply, while the founder still had every option open. Nobody writes it because it does not feel like a death. It feels like nothing happened. That is exactly the problem. The ideas that cost you the most are the ones that never got a funeral, because they never got a body.

The idea was Human-Led Assurance: certifying human authorship of judgment work in an economy where faking it had become free.

Frankly, I think the lineage of the idea was solid. Start with Coase and Williamson, by way of an argument Noah Smith published at the end of June: firms exist because some transactions are cheaper to run in-house than at arm’s length, so when the cost of verifying a counterparty rises, work retreats inside the firm, where you can supervise instead of verify. Generative models raise that cost across every domain where the product is judgment rather than an object—they do not only analyze information, they manufacture it, and they are inconsistent enough that trust has to be re-established from scratch each time you transact. Smith’s forecast is not plain consolidation. It is a split:

“a vast horde of solopreneurs, and a few monster companies employing huge numbers of wage earners.”

Solo where long-term trust does not matter; salaryman where it does.

That split has a hole in the middle, and the hole was the whole business. Smith reaches the split by assuming verification must be internalized: you either supervise the person or you do without the trust. There is a third way to produce trust between strangers, and it is not exotic. An external certifier, which is what auditors, ratings agencies and professional licensure already are. If an independent party could make arm’s-length trust cheap again, then the solopreneur is not confined to the work where trust happens to be irrelevant, and the consolidation is not inevitable. That was the wedge. I spent a month on it, and the research verdict on the thirtieth of June was not vapor: the idea had “crossed from mostly theory to a real, specific, defensible wedge.”

The same sentence has a second half. The wedge was defensible contingent on one external legal fact. I wrote that qualifier myself, in June, and then spent a month treating it as a detail to be resolved later rather than as the load-bearing element it was. The verdict was favorable, the verdict carried its own defeater in the subordinate clause, and I read past it.

Three candidate shapes for the business, three separate causes of death.

  1. The first was a credential attached to a person: certify that this operator’s judgment is their own, tested by live examination. It dies on the predicate. Human-led is not observable. A live viva can test whether someone retains what they claim to know and can defend it under pressure, which is a real and valuable thing to test (and how you solve AI in schools right now is with simple classical oral exams), but it does not test provenance. A competent person can use a model heavily, internalize the output, understand it completely, and pass the examination honestly.

    There is no violation to catch, and sampling cannot deter what it cannot detect. The credential would have certified something true (good for education) but something other than what it advertised.

  2. The second was a root of trust for AI agents: some authority attesting that an examined human stands behind an agent’s actions. It dies on the market, and for a better reason than the one I wrote down at the time. I had assumed the industry was building agent identity with no person in it—organizational authorization, machines answering for machines. That is not what happened.

    The shipped identity products and the standards drafts both carry the human principal down the delegation chain wherever one exists, and the drafts make carrying it faithfully a requirement. There is a person in the rails. The question is what the rails say about that person, and they say exactly two things, both of them entitlements. Whether the agent is permitted to take this class of action. Whether the human it acts for is entitled to this particular resource. Permitted and entitled are not competent, and nothing in that stack is trying to be.

    So the incumbents shipped the cheap half of my second node as table stakes, inside products they already sell, and left on the floor the half that was never observable to begin with. A new entrant would own neither the identity layer nor the transaction layer it would need to sit between, and what it brought to the middle was the one claim nobody has figured out how to make. That is not a moat with a competitor in it; it is a competitor with no moat in it. My second business was my first business wearing a different hat.

  3. The third was an attestation bound to an artifact: a signed claim that a specific document was human-reviewed and that someone bears liability for it. It dies on a dilemma. Write the attestation weakly and it is an approval receipt, which DocuSign and Adobe and GitHub can bundle into one release whenever they notice. One of them had noticed six months before I started. The standards group that handles creator identity for content provenance ratified an identity assertion in December that lets a named person assert their role in a file, and Adobe had already shipped it.

    Write it strongly, with real personal liability attached, and adoption collapses, because no employee, no counsel and no insurer wants to sign new personal exposure into existence. Liability-bearing is a legal and commercial arrangement. It is not a cryptographic property, and building it as though it were is a category error with a nice logo.

Underneath all three sits one finding, and it is the only part of this worth carrying away. AI opens an evidence and traceability gap, not a new liability gap. The contracting party was already liable for the work it delivers, and remains liable whether or not a model was involved; what the model changes is how hard it is to show who reviewed which version of what. That is an evidence problem, and evidence problems belong inside the quality and compliance systems that already exist, not in a new horizontal vendor selling certificates to everyone.

And in the case where an attestation would be genuinely valuable, the party who ought to own it is the one who prices the downside. Which is to say: buyers do not want verification, they want risk transfer. The insurer is the economic principal, and I had designed a business that sold the insurer’s product without the insurer’s balance sheet. That is not a gap you close by being clever about it; balance sheets are capital and regulation, and a certifier who acquires both has stopped being a certifier and become a small, badly capitalized insurance company.

At which point the obvious objection arrives, and it is the one I should have run at myself in June, because it is sitting inside my own first movement. Auditors exist. Ratings agencies exist. Licensure exists. These are enormous, durable businesses built on selling verification, and I had cited them as proof the third path was real. So how can it be true that buyers only want risk transfer?

The answer I wanted was compulsion. Every certifier sits behind a statute, an exchange rule, a counterparty who will not sign; nobody buys an audit for the pleasure of being audited; the certifier’s revenue is real and its demand is borrowed. It is a clean story and the evidence does not support it. English firms were buying audits in the fourteenth century, five hundred years before any government required one. Before the securities laws of the early 1930s made it compulsory, roughly half of over-the-counter firms and four-fifths of firms listed on the New York Stock Exchange bought an audit nobody was making them buy. About a third of global sustainability reports were voluntarily assured in the early 2000s, and the share was rising. Voluntary verification markets are not a theoretical possibility waiting on a regulator. They are older than the regulations people assume created them.

So the third path is real, my first movement was right about it, and the sentence I put in bold three paragraphs ago is too strong. Buyers of the thing I was selling would have wanted risk transfer. Buyers in general have demonstrably paid for verification alone, unforced, for six centuries. Narrowing that claim is what makes the death worth writing down, because what kills the business is not the absence of a mandate. It is who walks in when there isn’t one. The research is unusually specific here:

Firms buy assurance nobody requires when they have an absent principal to answer to, when they are about to ask someone for money, when the balance sheet needs explaining, when they already pay the provider for something else.

And, the finding that should have stopped me cold, when they are doing badly. Performance is negatively associated with buying a voluntary audit. The uncompelled market is bought under pressure, not out of prestige. I had specified my buyer as the board or general counsel of a well-capitalized, well-run organization, which is a precise description of the party least likely to buy. And where the mandate is taken away the market does not settle at a lower level, it drains: British firms released from audit kept it at 71 percent in the first year, 60 in the second, 52 in the third, still falling when the study ended. Real, and leaking.

Which means the question I needed was never is this valuable, and it was never even what compels the purchase. It was who buys this when nobody makes them, and is that person my buyer. I had the machinery to answer that in June. I spent the month answering a different question, rigorously, at length.

One more thing died in that session, and founders keep repeating it to each other as wisdom. An inattentive incumbent is a good sign. It is not. Inattention compounds into advantage only behind a moat that accrues while the incumbent is not looking. Absent that, inattention means the opposite of what it is read to mean: nobody has built it because nobody is asking for it, and the day someone asks, it ships as a feature in the next release of a product the buyer already owns.

Which leaves a fair objection, since I have now used incumbent attention to kill one shape and incumbent inattention to kill another. If both readings are fatal, the framework can never say build. It can, and the condition is narrow: a clock running for the buyer that the incumbent’s roadmap does not reach in time, with something that accrues to you while it runs. That case is rare and it is checkable, which is the entire argument for checking before you start rather than after.

Three independent adversarial passes converged on the same verdict; a convergence is not a theorem.

Here is the part that is actually embarrassing. The analysis was competent. It was thorough, it was sourced, it flagged its own weak points honestly, and it answered the wrong question with real rigor. The defect was upstream of every finding: it was the order in which I asked things. I reasoned fit-first. I started from what I uniquely see, the odd overlap of philosophy, venture work and institutional trust, and went looking for the market that would pay for it. That is a comfortable direction to reason in, because it begins with your own strengths and every step feels like insight. It also cannot fail early. Fit-first reasoning has no gate: there is always another market to check, always a wrapper in which your edge looks decisive, and the search terminates when you get tired rather than when you get an answer.

I can even date the moment the reasoning found its frame, because the record does it for me. Smith published his outsourcing argument on the twenty-ninth of June. Every written trace of my wedge is dated the same day. I remember the idea as older than that, and I may even be right; the file system declines to confirm it. An argument that arrives the day its confirming frame is published has not been tested by the frame. It has been dressed in it.

The correction is to reverse it. Necessity is the filter; fit is the selector. Necessity is not enthusiasm, and it is not a large addressable market. It is a triad:

  1. a buyer whose hair is on fire

  2. an exogenous clock that sets the deadline for them rather than for you

  3. and an economic principal who actually prices the risk.

Run that as a filter and most ideas die in minutes, which is the point of a filter. Fit only gets a vote afterward, on the survivors, where it belongs.

I ran that screen properly two weeks later, and the result is why I trust it. Fourteen raw candidates, six live regulatory-clock hunting grounds, two sweeps of who was actively buying. Seven were cut at selection. Seven were gated and given an adversarial reviewer whose only job was to kill them, working from primary sources. Six died at high confidence. One cleared necessity outright—a narrow desk handling carbon-border certificate liability—and then died on fit, because the right founder for it is a customs broker with a compliance background, and I have never been mistaken for one.

Zero candidates cleared the full screen.

An essay that ended and then I found the real one would be a better story and a lie. The honest conclusion was that the services I already sell were the investment, and there was no venture worth diverting runway toward. The venture died, not the work. Human-Led Assurance survives as a consulting line: live examination, run for the party who commissions it. Whether anyone will pay for the assurance specifically rather than for the consulting wrapped around it is a test I have not run yet. Three paid engagements will answer it. That is the honest status, and an essay about mistaking validation for viability has no business claiming better about itself. What died was the belief that it wanted to be a company.

There is a version of the reader who has been waiting several hundred words to say that a man who never built anything has no standing to write a post-mortem. I want to grant most of it. I risked nothing, I lost nothing, and nobody’s salary depended on my being right. But the conclusion does not follow, and the reason it does not follow is the whole argument. If the only people entitled to write about why ideas die are the ones who spent years finding out, then the genre is permanently restricted to the survivors of the most expensive possible method, and the lesson always arrives priced at a seed round. I would rather be the cheap data point. The alternative on offer is that I go build it for two years first, and then tell you the same three things.

I wrote an essay in February about proxy metrics, arguing that modern systems get better at their metrics while getting worse at their aims. The proxy eats the purpose. I have been citing that argument at institutions for months, mostly at other people, and it took me until July to notice it had a startup-shaped instance and that I was standing in it. Founder-market fit is a proxy. It is a reasonable one, as proxies go: it correlates with persistence, with judgment inside the domain, with the founder’s ability to hear what customers are actually saying. But it is a proxy for viability, and it is not viability, and if you optimize it hard enough you get exactly what I got. An idea with immaculate fit and no principal. A thesis so well-matched to its author that no one else was required for it to feel true.

The Y Combinator list is the same machine one layer up. It is a genuinely useful document, and it is honest about what it is: a map of what a particular set of investors would like to see funded. Read correctly, it tells you where founders will cluster next year. Read the way almost everyone reads it, it becomes a map of what will work, and those are different documents with the same words on them. My idea appeared on it three times because the list is good at describing the shape of a problem, and I read three appearances as three votes. It was one observation, counted three times. The list said nothing whatsoever about whether anyone would pay to have that problem solved by me, and it was never pretending to.

So the funeral is not for the company, which never existed in any sense that would let it be mourned. It is for the belief that validation and viability are the same variable. They are not, and the entire startup-idea genre depends on your not noticing, because validation is cheap to manufacture and viability is not.

What survived is smaller than a company and better than one. Detection is dead; anything that tries to identify machine-generated work after the fact is fighting a losing war on a schedule set by the other side. What survives is witnessed process, and the crucial thing about witnessing is what it can actually see. It sees defense. It sees whether a person can stand behind the judgment they are selling, under questioning, in real time. It does not see provenance and never will.

Someone will object that provenance is already solving this, and the objection is good enough to answer properly. Cryptographic content credentials are shipping and they work: they establish that a file carries a signed history and has not been altered since it was signed. That is origin and integrity, which is not authorship, and the gap between those two is where the whole business would have had to live. A provenance chain can tell you a document left a camera or an editor unmodified. It tells you nothing about who did the thinking before the file existed, and it binds at all only if you control the capture surface. Judgment work has no capture surface. There is no keystroke trail on a decision, and the keystroke-replay products that tried to manufacture one are defeated by retyping. The second half of the answer is the worse half: the marking is machine-checkable by construction, so it needs no attester and no examination—the same automation that makes provenance universal leaves a certifier nothing to charge for.

What is left is a seam rather than a company. If every machine-made artifact ends up marked, the unmarked ones start carrying an implicit claim, and those same rails will carry human-authored, attested by as readily as they carry AI-generated. That is a good place to stand on someone else’s infrastructure. It is not a thing to found.

None of that is a business. It is a diagnosis, and it was worth considerably more than forty-four cents.

Read the original on bianchi.substack.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.