securitylab_n•July 12, 2026•🇷🇺Translated from Russian

Why Simple ChatGPT Wrappers Are Losing Value: AI Model Makers Integrate Features, Pushing Startups to Control Full Industry Processes

Early startups that attempted to wrap access to large language models like ChatGPT and sell them as standalone products are quickly losing relevance. Developers of foundational AI systems are now integrating the very capabilities that once formed the core of these young companies' offerings.

According to the venture capital firm NFX, startups should abandon simple overlays on third-party models and instead seize control of entire industry processes. Rather than building narrow tools for lawyers, companies are creating comprehensive AI-powered legal services, and instead of isolated procurement applications, they aim to manage full supply chains.

The first wave of such wrappers emerged shortly after the launch of ChatGPT. These tools generated advertising copy, responded to customers, supported sales teams, and extracted information from legal documents. The companies behind them assumed that base models would remain unable to handle specialized tasks independently for a long time.

That calculation did not hold. OpenAI, Anthropic, and other model developers began transforming their systems into complete working products. Features that assist with programming, document work, and content creation have become native parts of major platforms, stripping smaller single-task companies of their primary differentiation.

One of the most prominent examples is Jasper. In 2022 the company raised $125 million at a $1.5 billion valuation and was viewed as a leader in AI advertising copy generation. It later lowered its annual revenue forecast, reduced headcount, and shifted direction, now attempting to evolve into a full marketing platform.

More durable approaches have come from companies that treat AI as the foundation of an entire service rather than a single feature. The legal platform EvenUp focuses on personal injury cases and has expanded to prepare documents, process case materials, and manage additional workflow stages. NFX reports that more than 2,000 law firms now use the service.

Another example is Blitzy, which builds enterprise software to replace contractor teams. The system analyzes a customer's entire codebase, breaks large projects into smaller tasks, and selects appropriate models for each step, capturing internal dependencies that generic models might overlook without domain-specific preparation.

The mortgage service Tomo has gone further by automating sales, borrower verification, and daily operations. The company states that 77% of its clients receive better interest rates than those offered by traditional mortgage providers, demonstrating a strategy of replacing legacy processes rather than layering new software on top of them.

Seso has adopted a similar model for managing seasonal agricultural workers in the United States. Previously, employee records, visa information, and documentation were scattered across law firms, office software, and paper files. With more advanced models, Seso now also handles transportation, housing, business insights, and personnel decision support.

Large organizations can also integrate AI directly with model developers. The law firm Freshfields, for instance, has partnered with Anthropic to build specialized tools, although such initiatives demand substantial compute spending and dedicated technical staff, and automation remains only one part of their traditional business.

NFX believes younger companies can still win by specializing deeply in narrow niches. Industry expertise, accumulated data, established sales relationships, and control over every stage of a service are significantly harder to copy than isolated software functions. As universal models grow stronger, the value of simple wrappers diminishes, making the ability to convert AI capabilities into complete, operational businesses increasingly critical.

Related articles

Securitylab•Other

Inside the Fortress: Why Perimeter Security Tools Fall Short and How Microsegmentation Protects Networks Internally

Companies invest heavily in perimeter defenses such as firewalls and intrusion detection systems, yet these measures no longer guarantee safety as attackers increasingly operate from within networks. Traditional L2 domains leave virtual machines unisolated, enabling traffic interception, lateral movement, and malware spread similar to an apartment building with poor soundproofing. Microsegmentation powered by SDN divides VLANs into isolated microsegments down to individual VM ports, enforcing granular policies based on ports, IP addresses, and protocols. This approach implements Zero Trust by placing virtual packet filters directly at VM network interfaces on the hypervisor, independent of guest OS actions. Performance remains high because filtering runs on powerful virtualization servers, and scaling occurs naturally as additional hypervisors absorb new workloads without extra configuration. A real-world case from the oil and gas sector shows one customer creating up to 5,000 new microsegmentation rules per week via open REST API. The technology complements rather than replaces perimeter firewalls, delivering both strict internal controls and operational agility.

Habr•Other

Good Bear 1.0 Released: Firefox-Based Browser with Isolated Russian PKI Trust Container

Good Bear 1.0 is a Russian-language browser built on Firefox 156.0 that provides an isolated container for handling Russian PKI certificates without mixing trust contexts or user data with the standard browsing session. The release includes .deb packages for Ubuntu 24.04 LTS amd64 and Windows x64 installers, using Mozilla Public License 2.0 and reproducible build processes from pinned Firefox sources. Instead of globally importing root certificates, the browser performs secondary chain validation only inside a dedicated userContextId container with strict OriginAttributes isolation for caches, storage, and connections. Password autofill and sensitive session data are disabled in the container when separation cannot be guaranteed, and POST requests trigger explicit user choice before reopening in the isolated context. The interface shows both a persistent container marker and a separate RU indicator only when Russian PKI is actively used, along with detailed security panels explaining the trust source. Updates, crash reporting, and automatic MAR mechanisms are intentionally omitted to avoid creating unverified trust chains for the distribution itself.

Habr•Other

Survey of 254 Russian Domains Shows 89% DMARC Adoption but Highlights Gaps in Reporting and Subdomain Policies

A manual review of public DNS records across 254 prominent Russian domains from 17 sectors found strong baseline adoption of email authentication mechanisms. MX records appeared in 96.1% of domains, SPF in 93.7%, DMARC in 89.0%, and DKIM records via common selectors in 62.2%. Among domains with DMARC, 40.7% published a reject policy and 42.9% used quarantine, while 16.4% remained at none. Notably, 19% of DMARC-enabled domains lacked any rua address for aggregate reports, including 33 domains enforcing reject or quarantine. The study also identified cases of inconsistent policies between parent domains and subdomains, as well as SPF records ending in ~all paired with strict DMARC settings. Researchers emphasized that DNS data alone cannot confirm actual mail flow alignment or report consumption.

AntiMalware•Other

Server Outage Halts Vehicle Registration Across Smolensk Region

A technical failure on a unified server has temporarily suspended vehicle registration services in the Smolensk region of Russia. The outage affects the interdistrict traffic police department No.1 located on Lavochkina street, preventing new registrations from being processed. Regional UMVD officials confirmed that the problem impacts the single server used for the entire oblast's registration system. According to department head Maxim Zykov, the disruption is considered temporary, though no precise restoration timeline was provided. Applicants who submitted requests through the Gosuslugi portal will receive services in the first working days after the system is restored. The UMVD plans to issue an additional announcement once operations resume.