AI code provenance is a real problem. Whether it's a real business is a harder question.
There's a moment that keeps coming up in compliance conversations right now. An auditor asks a fintech engineering VP: "Show me the change management evidence for this commit." The VP pulls up the PR, shows the diff, the review, the approval. Then the auditor asks: "Was any of this AI-generated?" The VP says yes. The auditor asks: "Show me the prompt. Show me which model. Show me that a human reviewed and accepted this specific output." The VP opens their mouth. Nothing comes out.
That's the gap. And it's real.
The pain here isn't manufactured. If you spend thirty minutes in ISACA Slack or reading G2 reviews of Vanta, you find compliance officers asking the same question over and over: how do we handle AI-generated code in our next SOC2 walkthrough? The Reddit thread that surfaced as proof of demand, the one titled "I'm tired of trying to make vibe coding work for me," is full of developers at regulated companies describing exactly this tension. They're shipping AI-assisted code because they have to stay competitive, and they have no trail to show anyone.
Vanta and Drata are the obvious places this should be solved, and neither of them has solved it. That's a documented gap, not a hypothesis. Their customers are publicly complaining about it. That's a rare thing in B2B: a named, specific deficiency in a category-leading product, with buyers who are already paying $20K+ per year and trusting that platform with their audit evidence.
The business model makes sense too. Compliance tooling has genuinely high retention because switching mid-audit-cycle is painful in a way that switching email tools isn't. If your evidence format is embedded in two years of audit records, you don't just churn because a competitor offers 10% better UX. The LTV math here, roughly $48K over three years per customer, is plausible for the category. And the distribution angle of targeting companies already listed as Vanta customers via their public trust pages is actually clever. You know they care about compliance, you know they're spending money on it, and you have a specific, named gap to lead with.
The AI contribution percentage idea is genuinely interesting too. Not just "AI was used" but "here is a reproducible semantic similarity score between the AI suggestion and what shipped." That's the kind of defensible metric that could become a standard if the right auditor firms start citing it.
Here's the thing about timing arguments: "regulators are starting to ask" is doing a lot of work, and it shouldn't be trusted to carry this much weight.
There's a version of this market that materializes fast. Regulators publish guidance, auditors start citing AI provenance as a specific control deficiency, companies start failing audits, procurement cycles compress because the pain is acute. In that world, being first matters enormously, and the moat from getting auditors to accept your report format is real.
There's another version where the regulatory pressure stays diffuse for two or three years. Compliance officers feel vague anxiety. They mention it in conversations. They say "yes, absolutely, we'd pay for that" in validation interviews, and they mean it in the moment, but when renewal comes around and their last two audits didn't flag AI provenance specifically, they deprioritize it. That's the survival verdict being "vulnerable" in plain language: the demand signal might be real without being urgent enough to sustain a company through the sales cycles required to reach break-even.
Fourteen customers at $12K each before you're covering a two-person team sounds achievable until you remember that enterprise compliance sales take six to twelve months per deal. The math on "design partner" arrangements at $5-10K to survive that valley is the right instinct, but it assumes you can close five or six of those in the first ninety days. That's a lot of outbound working before you have a product.
GitHub Copilot Enterprise already stores interaction logs server-side. Microsoft has enterprise relationships with the exact companies this tool is targeting, has financial incentive to close this gap, and has the engineering capacity to ship "auditor-ready provenance report" as a feature in a single quarterly planning cycle. They won't announce it. You'll just read a blog post one day.
The proposed response, win 20+ customers on annual contracts before Microsoft ships it, is the right strategy. It's also the kind of strategy that requires everything to go right at exactly the right speed. Enterprise compliance buyers don't move fast. A 60-70% chance Microsoft ships something meaningful within 18 months, combined with 6-12 month sales cycles, means the window for building a defensible position before the floor disappears is genuinely narrow.
The counterargument is that Microsoft won't own the whole market. Cursor, Codeium, Claude Code users aren't on Copilot. That's real. But a standalone tool that works for non-Copilot AI coding workflows is a much smaller market, and it doesn't get easier to sell when Microsoft is offering provenance logging "for free" to its existing enterprise customers.
The Vanta/Drata partnership channel risk is also genuinely dangerous. Not just that they'll build competing features (they will), but the timeline. If you build distribution through their marketplace and they delist you eighteen months in when they ship their own module, you've spent your sales energy building a channel that evaporated. The customers you landed through that channel might feel Vanta-native loyalty, not tool-native loyalty.
Then there's the Big 4 problem. Deloitte, PwC, EY, and KPMG are all building internal AI governance tooling. If they develop proprietary assessment frameworks and recommend those to enterprise clients, you're blocked at the auditor relationship layer before you even get to the procurement conversation. Getting auditor firms to accept your report format is the right moat, and it's also the hardest thing to do with no existing relationships and six months of runway.
One more thing nobody talks about enough: large regulated enterprises already have Splunk. They have QRadar. They have security teams who know how to write custom parsers. "Just add AI metadata to the existing SIEM" is a four-week internal project for a competent security team with audit pressure. That's not a competitor you can out-feature. That's a very reasonable thing for a compliance officer to say to their security team before signing a new vendor contract.
I genuinely don't know whether to build this or not. That's not a cop-out; it's the accurate answer.
The problem is real. The gap is documented. The business model for compliance tooling is historically solid. The insight about leading with Vanta/Drata's specific, named deficiency is good. The AI contribution percentage metric, if it lands with one Big 4 firm as an accepted standard, could be genuinely defensible.
But the timing risk is brutal in a specific way. This idea needs regulatory urgency to materialize faster than Microsoft moves. That's a race between two things you can't control.
If I were building this, I would not target enterprises first. I would go after 200-500 person fintechs that are already in a SOC2 renewal cycle and have a specific, named compliance officer with an audit scheduled in the next six months. Get three of those on design partner agreements at $7K upfront before writing a single line of extension code. Not to validate the concept. To validate that real money moves for a real audit date, not for theoretical future regulatory pressure.
I would also spend significant time before launch trying to get one mid-tier audit firm (Baker Tilly, RSM, Moss Adams) to say on record that they will accept your report format as evidence. Not Big 4. They're too slow and too conflicted. But a respected regional firm that audits exactly the 200-500 person fintechs you're targeting. That one relationship changes the sales conversation from "this might help" to "your auditor will accept this."
The developer prompt capture resistance is real and the local-first architecture is the right answer, but build it first. Don't offer it as an enterprise add-on. Make it the default. IP-sensitive companies, which is most of your market, will not route raw prompts through a third-party SaaS. Don't give them a reason to say no early.
Is it worth building? Maybe. With real customer commitment before you build, a specific auditor relationship before you launch, and a clear-eyed view that you have roughly 18 months before the platform players close the gap, there's a real business here. A small one, probably, but real. Without those three things, you're betting on regulatory timing and hoping Microsoft is slow. That's not a foundation. That's a wish.