AI-Driven Businesses: You Can Build More Than a Career

16 min readBy Nathan House

An AI-driven business could sell something customers have bought for decades: legal advice, insurance brokerage, regulatory support or cyber security. What changes is how much work a small team can deliver, and how the company operates behind it.

If you have professional expertise, that is an opportunity worth understanding. You could use AI across your own consultancy, or build a firm whose delivery, sales, support and administration are designed around it from the beginning. Customers would still pay you to solve their problems. You would build the systems that let you serve them.

Y Combinator is making a serious case for this model. Companies are already applying parts of it. Let's look at what they are doing, where the commercial opportunity sits, and what it could mean for your own business.

The services company YC wants founders to build

In How to Build an AI-Native Services Company, Y Combinator describes businesses that deliver professional services with AI doing much of the work and people providing expertise and judgement where needed.

The customer buys a completed service. Behind it sits software, an operating process and the people accountable for the result.

Think about a company that needs a contract reviewed. One supplier sells its legal team software to help with the review. Another takes responsibility for delivering the reviewed contract. Both may use the same underlying models, but they sell different things to different buyers.

Sequoia investor Julien Bek puts the distinction neatly in Services: The New Software:

“A copilot sells the tool. An autopilot sells the work.”

You will also encounter the term service-as-software for this commercial model. It describes delivering work through software-heavy operations rather than selling the software for someone else to operate.

AI-native business is broader. It describes how the company is organised. A company can sell services, sell a product, or combine the two while building its operations around AI.

For someone considering independent consultancy, the appeal is straightforward. The limit on what you can deliver may become less tightly tied to your personal working hours. For a founder, it raises the possibility of growing a business without adding people in direct proportion to every new customer.

Traditional service delivery and AI-supported delivery both end in reviewed work, with people accountable

That is the opportunity YC is discussing. Its video also spends considerable time on the work required to make it happen.

Source: Y Combinator, How to Build an AI-Native Services Company. Embedded for discussion; this does not imply endorsement of StationX.

AI throughout the business, rather than one automated task

A consultant who uses AI to draft reports may save time. The rest of the business can still depend on manual research, scattered client notes, repeated onboarding questions and a founder remembering every outstanding commitment.

YC partner Diana Hu describes a more substantial change in How To Build A Company With AI From The Ground Up:

“It should be the operating system your company runs on.”

Hu discusses making company information usable by AI across sales, engineering, hiring and operations. Work produces records. Those records give the system context. Results feed back into the next round of work.

Consider how that could work in a small security consultancy. This is an illustrative operating model, not a claim about a particular firm's results.

Part of the businessWork AI could supportWhat the responsible person retains
Finding clientsResearch suitable companies and prepare relevant outreach draftsChoosing the market, approving claims and building relationships
Scoping an engagementExtract requirements from agreed meeting notes and draft the proposalScope, pricing, promises and contractual responsibility
OnboardingRequest required evidence, organise records and identify missing informationPermissions, client boundaries and sensitive-data decisions
Delivering the workAnalyse evidence, run authorised tools and prepare findingsProfessional judgement, validation and approval of consequential actions
Keeping clients informedMaintain status reports, draft responses and flag commitmentsDifficult conversations, interpretation and service accountability
Routine administrationPrepare draft invoices from approved engagement records and agreed billing termsChecking amounts and contractual milestones, resolving discrepancies and approving invoices before sending
Improving operationsIdentify recurring errors, delays and repetitive stepsDeciding which changes are safe and whether they actually improve delivery
Seven connected business functions share context with permissions, client boundaries and human approval

These functions become more useful when they share accurate context. The proposal should reflect what the client requested. Delivery should reflect the agreed scope. Reporting should reflect what was actually done.

There is a security constraint here that matters particularly for our readers: a shared company knowledge system does not mean every agent gets unrestricted access to every client. Permissions, separation of client data, retention and approval controls are part of the design. Recording meetings also requires appropriate notice and consent where applicable.

YC offers an internal example in How to Build a Self-Improving Company with AI. The speaker describes an agent that answers questions using YC's data, followed by a monitoring agent that identifies failed queries and helps improve the system. The talk also describes using recorded office hours to refresh internal founder guidance.

Those are reported operating examples. The same speaker explicitly says they are unsure whether anyone has a truly self-improving company in every function. We can take the direction seriously without pretending the final version already exists everywhere.

Source: Y Combinator, How To Build A Company With AI From The Ground Up. Embedded for discussion; this does not imply endorsement of StationX.

The four tiers: how far you have built around the AI

We have a model for what Hu is describing, and it is the one we teach. The power does not come from a better model or a cleverer prompt. It comes from how much system you have built around the AI. There are four tiers, and most people only ever see the first.

The four tiers drawn as an iceberg: Tier 1 Harness is the visible tip used by the mainstream, with Tier 2 Personal AI, Tier 3 AI Infrastructure and Tier 4 Shared AI Infrastructure below the waterline, each tier built around the one above it

Tier 1 is the harness. Claude Code, Codex, Cursor, Gemini CLI: a language model with tools bolted on so it can read code, run commands, edit files and call other systems. Powerful, and where most people live. It forgets you the moment the session ends.

Tier 2 is a personal AI. You bolt real parts onto the harness: a memory of your standards and decisions, an identity, and skills it builds up over time. It stops being a blank harness every morning and starts being yours.

Tier 3 is AI infrastructure. The AI stops being an assistant you talk to and becomes a system that runs your operation: orchestration to run a fleet of agents, governance to stop them doing damage, and everything you have solved once kept as a permanent capability. This is where I work.

Tier 4 is shared infrastructure. The same brain, memory, tools and commands, shared with a team so everyone builds on it. This is what runs StationX.

Tiers 3 and 4 are the AI-native organisation. Hu's operating system, the closed loops in the YC talk, the companies in the next section: each of them is an organisation that has climbed to the point where the infrastructure runs the work and the people direct it. The route from one tier to the next is the same for a one-person consultancy as for a company with staff. You climb it by building, and each tier makes the next one cheaper.

Companies are already selling the work

The clearest evidence comes from what firms offer customers today. Their public pages cannot reveal every internal process, but they can show whether the customer is buying software or a professional service.

Crosby: legal work delivered by lawyers and agents

Crosby describes itself as “A law firm, not an AI tool.” Its site also states that human attorneys review all work, manage agents and ensure quality.

The offer is completed commercial legal work. The lawyers remain responsible for it. That combination is more useful to understand than the idea of a fully autonomous lawyer: AI participates in production, while the firm supplies professional accountability.

General Legal: defined work with published prices

General Legal describes its approach as combining attorneys with AI-native execution. Its published pricing includes $500 for a standard contract review covering 3 to 25 pages, with initial review and redlines, one round of internal revisions and initial negotiation guidance.

That is a concrete service a customer can buy. It also shows how a defined deliverable can be priced separately from the hours involved in producing it.

The price does not tell us General Legal's margin, nor establish what another firm should charge. It demonstrates the offer structure.

WithCoverage: insurance and risk management

WithCoverage describes AI helping its team analyse and compare policies, make recommendations and provide advice. Customers buy insurance brokerage and risk-management services, supported by a team of specialists.

The professional service remains familiar. AI changes how the provider gathers information and performs the work behind it.

Panacea: regulatory consultancy

Panacea, a YC-backed company, combines experienced regulatory experts with AI tools built for FDA workflows. It describes payment against completed, defined deliverables.

This is particularly relevant to consultancy. Specialist knowledge and software work together to deliver something a client already needs.

Be precise about the promise: a completed regulatory deliverable is not a guaranteed FDA approval. The provider can define and deliver its work without controlling every decision an external regulator makes.

These are company descriptions of real offers, not independent audits of their performance. They establish that this model is being used. They do not establish that the entire organisations are autonomous or that they earn software-like margins.

Company-described offers: Crosby legal work, General Legal services, WithCoverage insurance and risk, and Panacea regulatory consultancy

Where the market actually is

The market is the work customers already need done.

For context, Oxford Economics' 2026 research for the Management Consultancies Association reports £10.9 billion in fee income for MCA member firms in 2025. It estimates the total UK consulting market at approximately £21.8 billion, based on members representing around half the industry.

That is existing consulting spending, not a valuation of the AI-native opportunity. It would be wrong to treat all of it as available to a new founder. The same research reports that 46% of comparable members experienced declining fee income.

The more practical market question is narrower: which customers already pay for work that your expertise and AI infrastructure could deliver well?

Bek's outsourcing argument helps here. A customer already using an external provider has accepted external delivery and has a budget for it. A new firm can compete for that contract. It still has to win trust and meet the customer's requirements, but it need not persuade the buyer to invent an entirely new category of spending.

YC's services video adds useful characteristics: much of the work can be broken into repeatable tasks, judgement can be concentrated at particular points, and the overall service is difficult enough to remain valuable.

For a specialist, that may be an encouraging combination. You do not have to abandon the field you know to become a general-purpose AI consultant. Your understanding of the customer's problems can be the starting advantage.

What this could mean for a cyber security consultancy

Cyber security contains recurring work, existing outsourcing relationships and consequential decisions. It also contains activities that are unsafe to delegate without careful boundaries. The opportunity depends on distinguishing them.

Take vulnerability management. A client can own scanners and still struggle to decide what to fix. Evidence arrives from different systems, findings need context, and remediation has to be followed through.

An AI-driven consultancy could organise a service around maintaining that process: gather authorised evidence, investigate findings, prepare priorities, coordinate approved work and verify the result. The expert handles uncertain conclusions, business context and consequential decisions.

Illustrative vulnerability-management workflow: authorised evidence, investigation, priorities, approved work and verification, with expert judgement throughout

The offer is an ongoing security service. Its internal systems could also support proposals, onboarding, client reporting and renewal reviews. That is the whole-business connection.

Other possible applications include:

Compliance operations: maintain evidence, track control changes, coordinate owners and prepare material for review. An independent audit remains a separate responsibility where required.

Security questionnaire support: maintain evidence-backed answers and route exceptions for approval, rather than generate confident answers unsupported by the client's controls.

Authorised testing and retesting: combine tools with professional scoping, validation and remediation guidance. Testing permissions and safety limits remain explicit.

These are proposed service shapes, not claims that every one is a proven opportunity for every reader. Existing AI security tools can supply parts of the delivery system. The provider still has to make those parts work together reliably.

Nor does every consultancy need to become a large company. An independent professional may want a manageable client base and more capacity without hiring a large team. Someone else may want to build a repeatable service business, then develop a product from what they learn. Both fit the opportunity.

The economics depend on the operation

A fixed-fee service creates room to benefit from better delivery. If the accepted work takes less effort to produce, the firm can retain some of that saving, invest it in quality or use it to offer more to customers.

But the invoice for the model is only one cost. Human review, rework, software licences, onboarding, support and the effort of winning the customer all count.

Seven delivery cost components: model usage, human review, rework, software licences, onboarding, support and winning customers; no relative cost proportions implied

A report generated in minutes is not a fast service if an expert spends the next day correcting it.

YC's original video emphasises consistency, throughput and cycle time. It also warns against accepting so many pilot customers that the founders become trapped in manual delivery and never improve the system.

For an early consultancy, that suggests a practical approach: deliver a tightly scoped service to a small number of customers, observe where the work actually goes, and improve the recurring process. Measure the accepted result, including corrections, rather than how quickly the first draft appears.

Pricing can follow the deliverable, a defined recurring service or another unit the buyer understands. A fixed monthly fee for a clearly bounded service is different from promising an ultimate outcome outside your control. Neither requires a claim that AI eliminates the human work.

Four gates before you commit to an opportunity

At StationX, we use a four-gate business assessment. It is useful here as a check on a particular idea, alongside the wider opportunity.

GateWhat to establish
Market QualityCustomers have a pressing problem, purchasing power, identifiable ways to reach them and a growing market worth serving.
DefensibilityThere is a reason to choose and stay with your firm beyond access to models competitors can also buy.
Unit EconomicsAcquisition and delivery costs leave a viable business after human oversight, rework and support.
Capital EfficiencyYou can afford the setup, sales cycle and operating costs until customer receipts support the business.
Four business gates: Market Quality including a growing market, Defensibility, Unit Economics and Capital Efficiency

An attractive AI demonstration does not answer those questions. Neither does an investor predicting a huge market.

Use evidence where you have it and mark assumptions where you do not. The purpose is to decide what needs testing before you commit more money and time, not to manufacture a reassuring score.

We are already running StationX this way

StationX is not a bystander in this. HAL, the AI infrastructure I have built, is the execution layer for most of the business. My own estimate is that it carries around 80% of the work that runs StationX day to day: research, content, security operations, customer systems, internal tooling and much of the administration behind them. I direct it, review its output and make the decisions. It does the work.

I am not going to put precise percentages on the results, because we have not audited them to that standard. What I can tell you from running the company is that the cost of producing things has fallen a long way, our output has risen by far more than our headcount, and we are selling more as a direct result. Work that would have needed a team, a budget and a calendar now gets done by one person directing a system. The HAL page explains how it is put together.

The mechanism is the one Diana Hu describes. Every request goes through the same loop: the system reads what the company already knows, finds the relevant procedure, carries it out through the tools it has permission to use, checks the result and saves what it learned. Nothing is bolted on to the side of a chat window. The knowledge sits in the system, and the system gets better with each job.

The HAL request loop, a circular diagram with seven stages: a request comes in, the system loads its context, searches its skills, reads the matched procedure, carries it out with its tools and reasoning, runs its checks, and files what it learned to memory. Centre label: everything compounds HAL hub-and-spokes network diagram: a central HAL hub with seven capability areas radiating out, covering cloud and infrastructure, security and defence, development and engineering, data and research, content and communication, commerce and finance, and operations and workflow

This article is the example

Take the article you are reading. My contribution was the idea, the direction, the corrections and the decisions: the topic, what the argument was and was not, the title, which claims were safe to make, and what to publish. Around that, HAL did the work that used to need a small production team.

Research. Pulled the YC transcript, searched the wider material, found three more YC talks on the same subject, and captured the primary sources so every figure could be checked against the page it came from.

Writing. Drafted the article, then put it through a review panel of independent AI reviewers across four model families, with a validator and a referee, before I read it.

Editing. Applied the review findings, checked the argument end to end, and ran a structural check for prose that reads as machine-written.

Graphics. Generated the diagrams and the hero image, produced the optimised web formats, and animated the header.

Engineering. Built the page, registered the route, wrote the tests, ran the full suite of more than 5,000 tests, checked accessibility on desktop and mobile, and staged the result for my sign-off.

That would once have involved a writer, an editor, a researcher, a designer and a developer, plus the time it takes for five people to pass work between them. Here it was one person and a system, over the course of a day, with me looking at the result rather than producing it. The one thing HAL did not do is publish. Nothing goes to production without my go, and that is deliberate.

How this article was made: direction and decisions on one side (the idea, the direction, the corrections, the title, which claims were safe to make, what to publish) and the work HAL carried on the other (research, writing, editing, graphics, engineering), with the line that nothing goes to production without a human go

How we build: six steps, every time

The other half of the model is the process. An AI-native organisation that builds carelessly just makes mistakes faster. So nothing here is invented: we take the disciplines serious organisations have used for decades to ship software that cannot fail, and wrap them for use with AI. That wrapper is the AI-driven part, and I describe it in six steps.

The six steps on a whiteboard: Screen asks how risky, Frame asks whether it is worth it, Spike finds the riskiest unknown, Build builds it right, Verify asks whether it is safe to ship, Gate is the go or no-go decision, then Ship

Screen sizes up what could go wrong before a line is written. Could this leak data? Could it hurt someone? How much rigour does it need?

Frame asks the blunt question: is this worth building at all, or should you be building something different?

Spike tests the single riskiest unknown, cheaply, before you commit. Fail now in a few hours, not later in a few weeks.

Build lets the AI run at full speed, from a spec, not a vibe.

Verify has other agents tear the work apart hunting for what is broken or insecure. AI checking AI.

Gate means nothing ships until it is proven safe to your level of risk tolerance, and a human says go.

This article went through all six. It was screened for what could go wrong (the claims about real companies and about our own results), framed against the goal you read at the top, spiked by getting the evidence before a word was drafted, built to the page standard, verified by two review panels and a code review that found a real bug in the listen bar before it shipped, and gated on my go. Every service Titus delivers and every bug-bounty finding goes through the same six, because the discipline is what lets a small team put its name to the output.

Security is where we apply it hardest

Two of our own projects show what the model looks like when the work is security.

Titus is continuous vulnerability management for fintech software companies. Rather than a penetration test once a year, it reviews code, dependencies, servers, cloud and build pipeline every day, connects what it finds (a vulnerability in code matters far more when the server that runs it is exposed to the internet), and gives a prioritised view of what to fix first rather than a list of every CVE. The published severity of a finding is kept separate from our assessment of the actual risk in that environment, and a human reviews every assessment before anything is closed or accepted. At its core is the vulnerability register we use to manage StationX's own findings; we run the service on ourselves. The Titus page describes the offer.

Bug bounty research is the offensive counterpart. HAL runs a pipeline over publicly available WordPress plugin source: static analysis to find candidate flaws, a reasoning layer that judges whether a flaw is reachable without logging in, a local lab to prove it, and adversarial review panels before anything is submitted. Scope rules and an already-reported check are enforced in code, because an agent that re-finds a bug proves the bug is real, not that it is new. When we tested the system against a plugin with more than four million installs and a known, since-patched critical flaw, the pattern scanner returned nothing; the reasoning layer found it. Findings from the live pipeline have since been filed with a bug bounty programme, and I make every submission decision myself.

Source: StationX, My AI Hacked a Plugin Running on 4M WordPress Sites. From the StationX YouTube channel.

Neither of these is a demonstration. The bug-bounty pipeline is live, and the Titus register manages our own vulnerabilities today. Both are the kind of service a small AI-driven consultancy could offer a client.

Two security applications side by side: the Titus daily loop (code, dependencies, servers, cloud and pipeline, then assessment, contextual risk, human review and a live dashboard) and the bug bounty research pipeline (static analysis, reachability reasoning, lab proof, scope gate, adversarial review and human submission)

The capability behind the opportunity

That is why I am interested in this beyond what investors are saying. I founded StationX in 1999, and the business now runs the way this article describes.

The persistent infrastructure matters. It holds working context, connects to tools and supports repeatable ways of getting things done. A fresh chat window does not know the customer's agreed scope, which source is authoritative or what went wrong on the previous job unless someone supplies that context.

Our AI-Driven Engineering approach develops the capability to direct AI, design a solution and verify the result. Building a commercial business adds customer relationships, operating discipline and responsibility for the service you sell.

The AI Master's Program already supports employed, independent-consultant and business-founder paths. Members build their own AI infrastructure and work toward a real security solution, with mentorship and the Inner Circle around them. The same capability can serve an employer, a client or a company of your own.

It does not guarantee customers. It gives you something useful to bring to them: the ability to build and operate solutions, with the judgement to know whether the work is good enough.

For an experienced practitioner, I think that is the most interesting part of this opportunity. You can take a problem you understand, build the business around a different way of doing the work, and compete on what you deliver.

Frequently asked questions

Does an AI-driven business have to sell AI services?

No. It can sell established services such as security, insurance brokerage or legal work. AI-driven describes how the business operates. Selling AI implementation or automation advice is a different, though potentially overlapping, business.

Is service-as-software the same as an AI-native company?

They overlap. Service-as-software describes selling completed work through software-heavy delivery. AI-native company describes an organisation designed around AI across its processes. An AI-native company can also sell software or other products.

Can one person run this kind of consultancy?

Some narrowly scoped services may suit a solo practitioner with AI support. Capacity still depends on complexity, review requirements and service commitments. Do not infer that one person can safely provide unlimited support or round-the-clock incident response.

Where do people remain necessary?

The examples above retain qualified experts for judgement and accountability. People also handle relationships, ambiguous requirements and consequential decisions. How much work can be delegated varies by service and must be tested.

Does using AI mean software-company profit margins?

No. The outcome depends on pricing and all the costs of acquiring and serving customers. The company pages cited here do not establish audited margins. Lower task costs can improve the economics, but that is something to measure.

Does StationX run this way itself?

Yes. HAL, our AI infrastructure, is the execution layer for most of the business, on my estimate around 80% of the day-to-day work, with me directing and reviewing it. This article, the vulnerability register at the core of our Titus service and our bug-bounty research pipeline are all produced that way. The cost, output and sales improvements I describe are my first-hand account of running the company, not audited figures.

Is this only an opportunity for venture-backed founders?

No. The model can inform an independent practice, a small service firm or a larger business. YC discusses venture-scale opportunities; an individual consultant may choose a much smaller target and a different growth strategy.

Source note: company descriptions and advertised pricing were checked on 24 September 2026. YC talks and Sequoia's essay are attributed viewpoints and reported examples. Oxford Economics provides a separately scoped estimate of UK consulting spending. Suggested security offers and the operating-workflow table are applications of the model, not measured case studies. Statements about HAL, Titus, bug-bounty research and the production of this article are Nathan House's first-hand account of StationX's own operations; the "around 80%" figure is his estimate, and the cost, output and sales improvements are not audited measurements.

About the Author

Nathan House

Nathan House, Founder & CEO of StationX

Nathan House has 30 years of hands-on cybersecurity experience and is Cambridge-educated, holding CISSP, CISA, CISM, OSCP, CEH, and SABSA. He founded StationX in 1999 — one of the UK’s first cybersecurity companies — and has secured £71 billion in UK mobile banking transactions and the London 2012 Olympics, advising clients including Microsoft, Cisco, BP, Vodafone, and VISA. He authored the world’s most popular cybersecurity course — a #1 Udemy bestseller taken by over 500,000 students — and was named Cyber Security Educator of the Year 2020, AI Security Educator of the Year, and a UK Top 25 Security Influencer 2025. A DEF CON speaker and featured expert on CNN, Fox News, NBC, and the BBC, Nathan leads StationX’s training of more than half a million students worldwide.