THE COMPANY-BUILDING FIELD NOTEBOOKRESEARCH EDITION / SEPTEMBER 2026
Startup
Research.
Search
RESEARCH LIBRARY / Risk & failure

See the failure modes earlier

Warning signs, flawed assumptions, risk checklists, and a framework for deciding whether to build.

Research date: September 15, 2026. Every figure, ruling, fine and shutdown count below was checked against its source on or before this date. Enforcement actions, litigation outcomes and shutdown statistics move quickly; anything here that matters to a decision you are about to make should be re-checked at the primary source before you rely on it.

This chapter is not legal advice. It describes publicly reported regulatory actions, court rulings and industry practice. Several sections — privacy compliance, securities and cap-table structure, copyright and training data, regulated-industry entry, employment classification — describe areas where the cost of a mistake is high, sometimes personal, and occasionally irreversible. Those sections are written to help you recognise when you need a qualified professional, not to substitute for one. Where counsel is genuinely required rather than merely advisable, the text says so explicitly.

How this chapter fits the library. Chapter 3 covers idea validation; Chapter 5 covers founder dynamics, hiring and go-to-market mechanics. This chapter does not re-teach those — it covers what goes wrong, how to see it coming, and two decision tools. Where a topic is treated at length elsewhere, only the failure mechanism appears here.


How to read the evidence in this chapter

Four labels are used throughout:

  • [Verified] — documented in a primary source: a court ruling, a regulator's own press release, a government statistical series, a company filing, or a dataset with a published method.
  • [Self-reported] — a founder's, company's or survey respondent's own account of events. Useful, but subject to motivated reasoning. Post-mortem data is almost entirely of this kind.
  • [Estimate] — a derived or partially-disclosed figure. Directionally useful, not precise.
  • [Analysis] — the author's interpretation, kept separate from the evidence.

Three biases that distort everything written about startup failure

1. Survivorship bias. The standard problem. Advice is written by and about the people who made it, so the traits of survivors get coded as causes of survival when they may be irrelevant or even harmful on average. "Ignore the doubters and keep going" is excellent advice given by the small number of people for whom it worked, and terrible advice on the base rate.

2. Hindsight bias — the specific problem failure analysis has. Once a company is dead, everyone involved can construct a clean causal story, and it will be wrong in a predictable direction: over-weighting decisions that were visible and discrete (a bad hire, a pricing change, a pivot) and under-weighting conditions that were diffuse (the market was smaller than anyone knew, the timing was two years early, the founders never actually liked each other). Post-mortems are reverse-engineered narratives written by people who know the ending, not measurements. [Analysis]

3. Self-serving attribution. Founders writing post-mortems want to raise again, be hired again, or be thought well of. This biases stated causes toward the blameless and external — "the market wasn't ready," "we were too early," "macro conditions" — and away from the embarrassing: we could not sell; we shipped something bad; my co-founder and I stopped speaking in month fourteen.

A fourth, quieter problem: the denominator is unknown. Nobody has a census of startups. Companies that quietly wind down, get acqui-hired for less than they raised, or shrink into a lifestyle business are inconsistently classified. Every failure rate you will read is a rate over a sample that somebody chose, and the choice of sample usually determines the answer.


PART A — What the data actually says about why startups fail

A1. The "90% of startups fail" figure and where it comes from

The number is everywhere and has no single source. It is best understood as folklore that acquired a citation trail rather than a finding that acquired evidence.

What can be traced:

Shikhar Ghosh (Harvard Business School, ~2012). The most commonly cited academic anchor. Ghosh's analysis of venture-backed companies is usually reported as finding that roughly three in four VC-backed startups fail to return investors' capital, and that the figure rises to around 90–95% if "failure" is defined as failing to hit the projected return. Crucially, Ghosh's work was reported through the press (notably a 2012 Wall Street Journal piece) rather than published as a peer-reviewed paper with a released dataset, so the method has never been fully auditable. [Estimate, method not public] Note also what it measures: failure to return capital to venture investors, not company death. A company that sells for $40m after raising $30m has failed by this definition while being a life-changing outcome for its founders.

Startup Genome (2011–2019). Produced the "1 in 12 entrepreneurs succeed" framing and the premature-scaling work discussed in Part B. Self-selected survey sample; see B26 for the methodological criticism.

The honest summary: no study establishes "90% of startups fail." Several studies measure different things on different populations and produce numbers in the 70–95% range depending on how you define "startup" and "fail." The figure survives because it is memorable, roughly consistent with the base rates, and useful to everyone who repeats it. [Analysis]

The definitional problem. Before any failure rate means anything, three choices must be made:

Choice Options Effect on the rate
Population All new businesses / All tech startups / VC-backed companies / Companies that raised a priced round All businesses gives ~50% at 5 years; VC-backed gives much higher "failure" rates on return-based definitions
Definition of failure Ceased operations / Failed to return invested capital / Failed to hit projected returns / Founders stopped working on it Return-based definitions produce the highest numbers
Time horizon 1, 5, 10 years, or "ever" Longer horizons always produce higher failure rates; "ever" approaches 100% for all companies

A claim like "90% fail" that specifies none of these is not a statistic. It is a vibe.

A2. The baselines that are actually measured

BLS: all new US establishments

The Bureau of Labor Statistics tracks establishment survival in its Business Employment Dynamics series — a census-grade administrative dataset, not a survey, covering essentially all private-sector employer establishments. This is the single most reliable failure baseline available, with the caveat that it covers all businesses (restaurants, contractors, salons) rather than startups in the venture sense.

From the BLS survival table (establishments by year opened, data through 2025) [Verified]:

Cohort (opened March) Survived 1 year Survived 5 years Survived 10 years
2015 79.6% 50.2% 34.7%
2022 76.3%
2023 78.2%
2024 77.9%

Source: BLS, Business Employment Dynamics — survival of private sector establishments by opening year.

So: roughly one in five businesses dies in year one, half are gone by year five, two-thirds by year ten. These have been remarkably stable across decades and recessions — the BLS observes that survival curves follow a similar path regardless of birth year, which suggests failure is driven more by a constant background rate of ordinary causes than by macro conditions. [Analysis] Note that "not surviving" includes voluntary closure, sale and merger; it is not synonymous with bankruptcy or founder ruin.

Carta: funded startups

Carta administers cap tables for tens of thousands of venture-backed companies and can observe when a company formally dissolves or is marked as shut down. This is the best available window into funded startup mortality, with an important limitation Carta itself acknowledges.

[Verified] Shutdowns among Carta-tracked companies: 769 in 2023, 966 in 2024 — a 25.6% year-over-year increase, reported in TechCrunch's January 2025 analysis of Carta data.

Peter Walker, Carta's head of insights, made two points in that reporting that matter more than the headline count:

  1. The denominator moved. "There were more companies funded (with bigger rounds) in 2020 and 2021. So we would expect shutdowns to increase." A rising absolute shutdown count from a much larger funded cohort is not necessarily a rising failure rate. [Verified quote]
  2. The data undercounts. "I bet we're missing a good chunk" — companies leave Carta without saying why, and a company that simply stops operating without formally dissolving may never be recorded. [Self-reported limitation]

Walker's causal read is worth quoting because it is the clearest statement of the pattern this whole chapter is about: "Running out of cash is typically the proximate cause. But the underlying reasons are likely some combination of lack of product-market fit, lack of ability to get to cash-flow positive, and overvaluation." [Verified quote]

Market conditions as of Q1 2026. Carta's State of Private Markets: Q1 2026 reports the down-round rate at 11.4%, down from a 2023 peak of roughly 22% and back in line with 2019–2020 levels. [Verified] [Analysis] A normalising down-round rate does not mean the failure wave is over; it means the companies that could not clear a flat or up round have largely already been resolved one way or the other. The 2021-vintage cohort has now mostly either raised, been sold, or died. What remains to be seen is how the 2024–2025 AI vintage behaves.

A caution about 2025–2026 shutdown reporting. Several widely-circulated summaries of "2025 shutdown data" trace to vendor press releases rather than published datasets, with undisclosed methodology. Treat any 2025–2026 shutdown number without a named method as [Estimate] at best.

A3. CB Insights' post-mortem analysis — useful, and systematically misread

CB Insights' failure analysis is the most-cited source on why startups fail. Its current edition, Why Startups Fail: Top Reasons (published 5 March 2026, updated 6 March 2026), analysed 431 VC-backed companies that shut down since 2023, of which 385 had identifiable failure reasons. The reasons were drawn from "public post-mortems, founder interviews, and shutdown announcements." [Verified — sample and method as stated by CB Insights]

Headline results (companies can have multiple reasons, so these do not sum to 100%):

Reason Share
Ran out of capital 70%
Poor product-market fit 43%
Bad timing / macro conditions 29%
Unsustainable unit economics 19%

CB Insights' own framing is the important part, and it is more honest than most of the coverage that cites it: running out of capital is the final cause, not the root cause. A company runs out of money because something else was wrong for long enough.

The methodology limits, stated plainly

1. The sample is self-selected in a specific direction. To be in this dataset, a company had to publish a post-mortem, give an interview, or make a shutdown announcement. Companies that die quietly — the majority — are invisible. The ones that write post-mortems skew toward founders who are visible, well-networked, comfortable in public, and intending to remain in the ecosystem. Those founders have the strongest incentive to frame the failure charitably.

2. The reasons are self-reported by the person with the most to lose from candour. This is the single most important caveat and it is routinely dropped when the chart is reproduced. A post-mortem is a reputational document.

3. It is VC-backed only. 431 venture-funded companies is not a sample of startups; it is a sample of a particular financing arrangement. Bootstrapped failure looks different — typically slower, smaller, and caused by founder exhaustion or opportunity cost rather than by a failed fundraise.

4. Multi-attribution muddies causality. A company tagged with three reasons tells you nothing about which was upstream.

5. It is a post-2022 cohort. Companies shutting down from 2023 onward are disproportionately 2020–2021 vintage, funded in the cheapest capital environment in modern history at valuations that later became unclearable. "Bad timing / macro conditions" at 29% partly measures when these companies raised, not a general truth.

Why "no market need" is the most misleading line item in startup research

Earlier editions of the CB Insights analysis led with "no market need" at 42%, and that figure has been reproduced in thousands of articles and pitch decks. It deserves specific scepticism.

[Analysis] "No market need" is what a founder says when the honest answer is one of the following, all of which are harder to write down:

  • There was a need; we built the wrong solution to it.
  • There was a need; we could not reach the people who had it at a cost that worked.
  • There was a need; someone else served it better and we lost.
  • There was a need, but not urgent enough that anyone would change their behaviour or their budget line for it.
  • We never seriously tested whether there was a need, and by the time we found out we had spent the money.
  • We knew by month six and kept going because stopping was unbearable.

Each of these is a different problem with a different prevention. Collapsing them into "no market need" produces advice that is true and useless: validate demand. Everyone already agrees with that. The operational question — which of the six things above is happening to you, right now — is precisely what the aggregate category erases.

There is also a structural reason to distrust the category: it is the only failure reason that assigns blame to the universe rather than to the team. A founder can say "no market need" in a fundraising conversation for the next company and it costs them nothing. Saying "I could not close enterprise deals" costs them the round. [Analysis]

How to use it properly. Treat it as a map of what founders are willing to say — useful, because it reveals which failure modes are socially acceptable to admit and, by omission, which are not.

A4. The academic work

Tom Eisenmann, Harvard Business School — Why Startups Fail (2021). The most systematic academic treatment. Eisenmann surveyed roughly 470 early-stage founders and defined failure as ventures where "early-stage investors did not or never will make money." He identified six recurring patterns [Verified — as described in secondary summaries of the book; the underlying survey data is not public]:

Pattern Mechanism
Bad bedfellows Wrong co-founders, employees or investors. Case: Quincy Apparel — founders without industry experience, unclear leadership, VC capital where patient capital was needed.
False starts Skipping customer discovery to rush into building. Eisenmann's formulation: "move fast when you can, but take your time when you need to."
False positives (also rendered "false promises") Early adopters give misleading signals. Contrast: Dropbox designing for the mainstream user versus Fab.com customising for enthusiasts and losing the mainstream.
Speed trap Scaling too aggressively creates an LTV/CAC squeeze — each new cohort is less interested and more expensive to acquire — while rapid hiring introduces cultural and process failure.
Help wanted Missing senior functional leadership at the point where scale requires it.
Cascading miracles The venture requires several independent breakthroughs — technical, behavioural, regulatory, financial — to all land. Any one failure kills it.

Eisenmann's contribution is that he separates early-stage failure patterns (bad bedfellows, false starts, false positives) from late-stage failure patterns (speed trap, help wanted), which the single-list format of CB Insights obscures. A company that dies at 8 people and a company that dies at 300 people did not die of the same thing.

What Eisenmann's work shares with the rest: it is retrospective, the failure definition is investor-return-based, and the survey sample is founders willing to respond. It is better-constructed than the post-mortem literature but it is not immune to the same three biases.

Two other academic anchors. Research on serial entrepreneurship finds a modest but real performance premium for founders who previously succeeded, and a much smaller or absent premium for those who previously failed — cutting against the "failure is valuable experience" folklore [Estimate — effect sizes vary by study]. Work on founder age (Azoulay, Jones, Kim and Miranda, using US Census data) put the mean age of founders of the fastest-growing new ventures at around 45, contradicting the young-founder narrative [Verified — Census administrative data].

A5. What the evidence base actually supports

Stripping out everything that is folklore, self-serving, or unfalsifiable, here is what survives:

  1. [Verified] About half of all new US businesses are gone within five years; about two-thirds within ten. This is stable across decades.
  2. [Verified] Venture-backed failure rates are higher than general business failure rates on return-based definitions, because the bar is higher, not necessarily because the companies are worse.
  3. [Verified] Running out of cash is the mechanism of death in the large majority of funded failures. It is never the cause.
  4. [Estimate] The most common root causes cluster into: no durable demand, inability to acquire customers economically, and inability to reach positive unit economics before capital ran out. Everything else is either a contributor or a consequence.
  5. [Analysis] The failure-reason literature systematically under-reports interpersonal and executional causes, because those are the ones founders will not put in writing.

The rest of this chapter is organised around mechanisms rather than around the survey categories, precisely because the survey categories are the part of the evidence base that is least trustworthy.


PART B — The failure modes

Each entry follows the same structure: mechanism (what causes the damage), warning signs (what is observable before it is fatal), examples (documented where possible), and prevention. They are grouped by where the damage originates, because failure modes cluster — a company with one usually has two or three of its neighbours.

Where a named company appears, the claim is restricted to what the cited source documents. Attributing a company's death to one cause is exactly the hindsight bias described above; the cases illustrate a mechanism, not an explanation of a company. [Analysis]


Group 1 — Demand and problem selection

B1. Building without demand

Mechanism. The founder converts an assumption into a product without an intervening test. The cost is not the wasted build time; it is that building creates commitment. Once a product exists, the question silently changes from "does anyone want this?" to "how do we get people to want this?" — and the second question has no falsifying answer, so it can absorb years.

Warning signs. You cannot name five specific people — not personas, people with surnames — who have said they would pay. Your evidence for demand is that "there's nothing like this on the market," usually evidence that others tried and failed. Validation consists of people saying the idea sounds interesting.

Example. Fast, the one-click checkout company, raised $124.5m and reached roughly six-figure 2021 revenue while burning approximately $10m per month before shutting down in April 2022 (TechCrunch, 5 April 2022). [Verified]

Prevention. Sell before you build; Chapter 3 covers the validation ladder. The highest-value discipline is a written falsification condition with a date, set before you start: "if by March 30 we do not have three signed pilots at $500/month, we stop."

B2. Weak founder-market fit

Mechanism. Founder-market fit is not passion; it is unfair access to information and to people. A founder who has spent six years inside a problem knows which of the twenty visible pain points has a budget attached, and can get a meeting with whoever controls it. A founder without that knows only what is publicly visible — which is the part of the market everyone can see, and therefore the crowded part.

Warning signs. You cannot get warm introductions to buyers. You are learning the industry's vocabulary from your own customer calls. Your differentiation rests on the industry being "behind" rather than on a mechanism you understand.

Example. Quincy Apparel is Eisenmann's canonical case: founders without fashion-industry experience could not build supplier relationships, misjudged production complexity, and had no clear leadership structure (Underscore VC summary of Why Startups Fail). [Verified as reported]

Prevention. Either acquire the fit — work in the industry, or do the job for three months — or buy it by recruiting a co-founder who has it, on real equity, before committing capital. Do not substitute an advisory board; advisors do not take calls at 11pm. Chapter 5 covers the co-founder decision.

B3. Solving a low-value problem

Mechanism. The problem is real, it is just not expensive. People experience it as a mild annoyance rather than a cost with a number attached. This produces a deceptive pattern: warm interest, high signup rates, enthusiastic feedback, and no willingness to pay or change behaviour. A company can survive years on this signal, because the signal is genuinely positive — it is just not monetisable.

Warning signs. Prospects say "this is cool" rather than "how soon can we have it." Nobody currently spends money or staff time on the problem, so there is no budget line to displace. Your buyer cannot say what the problem costs them. Free-trial conversion is under 2% among active trialists.

Prevention. Quantify before you build. Ask every prospect: what does this cost you per month, in money or hours, and who signs off on fixing it? If they cannot answer within a factor of ten, the problem is not yet expensive. A workable B2B threshold: if the annual cost of the problem is not at least 5–10× your intended annual price, inertia beats you.

B4. Poor customer research

Mechanism. Not the absence of research but the presence of bad research, which is worse because it produces confidence. The standard failure is hypothetical, leading questions — "would you use a tool that did X?" — which measure politeness, not demand. The second is talking to the wrong role: users who love the product but cannot buy, or executives who can buy but will never use.

Warning signs. Your notes contain "would" more often than "did." You are hearing what you expected. Nothing anyone said surprised or upset you. Nine of ten interviewees were friendly acquaintances.

Prevention. Ask only about the past and the concrete: what did you do last time this happened, what did it cost, what did you try, why did you stop. The Mom Test (Rob Fitzpatrick) is the standard reference and its rule is: talk about their life, not your idea. Sample for disconfirmation — interview five people you expect to say no, and weight their reasons above your yeses.


Group 2 — Product and engineering

B5. Feature creep

Mechanism. Every feature has three costs, two invisible at the moment of decision: the build (visible), the permanent maintenance and support burden, and the cognitive cost to every future user who now has more to understand. Feature creep usually originates in sales — a prospect will buy if you add X — so it feels like customer-led development while actually substituting several half-products for one product.

Warning signs. Onboarding needs a tutorial. New-user time-to-value has risen for two quarters. Your roadmap is a list of named customers.

Prevention. Make maintenance cost explicit: every proposal carries an ongoing-cost estimate, not just a build estimate. Distinguish a customer-specific request from a market request — the test is three unrelated customers asking unprompted. Build a deprecation habit early, because a company that has never removed a feature will not manage it when it must.

B6. Overengineering

Mechanism. Building for a scale, generality or failure mode that has not arrived. The damage is not mainly wasted time; it is that abstraction built before the requirements are known is usually the wrong abstraction, and wrong abstractions cost more to remove than missing ones cost to add. Microservices at ten users, multi-region failover, a plugin architecture with no plugins — each bets that the future matches your current guess.

Warning signs. Infrastructure work outweighs user-facing work in your commit history for more than a sprint or two. You are optimising for load you have never seen. "When we scale" appears in architecture decisions.

Prevention. Ship the boring version: monolith, managed database, one region, one cloud. The credible reasons to build for scale early are hard regulatory requirements, genuine physical constraints (real-time, embedded), or SLAs already signed. Otherwise every scaling investment should be forced on you by a measurement, not chosen in advance.

B7. Platform dependence

Mechanism. Your acquisition, distribution or core capability runs through an intermediary that can change terms unilaterally, has its own strategic interests, and may eventually want your margin or your category. The asymmetry is total: the platform's decision is a line item in a quarterly review; for you it is existential. The danger is not malice — it is that platforms optimise for themselves and your business is a rounding error in that optimisation.

Documented cases:

  • Twitter/X API repricing, 2023. Twitter ended free API access and introduced roughly $100/month Basic with tight caps and approximately $42,000/month enterprise, with no viable middle. Multiple small products and research tools announced closure within weeks; TechCrunch's 30 March 2023 reporting names @accountanalysis, Targum, Mailclipperhq and others. [Verified] The detail that matters is speed: third-party clients had API access revoked in January 2023 with essentially no notice.

  • App Store policy. Apple's rules are a moving floor. After contempt findings in Epic Games v. Apple, Apple was ordered in April–May 2025 to stop charging commission on purchases completed outside the App Store and to stop restricting how developers link to external payment (CommLaw Group summary); the Ninth Circuit affirmed the civil contempt finding on 11 December 2025. [Verified] [Analysis] The lesson cuts both ways: your app-store economics can move by 30 percentage points because of litigation you are not party to.

  • Google search and AI Overviews. Pew Research tracked 900 US adults across 68,879 Google searches in March 2025. Users clicked a traditional result on 8% of searches showing an AI summary versus 15% of those without; only 1% clicked a link inside the summary (Pew Research Center, 22 July 2025). [Verified] For a business acquiring through organic search, that is a structural halving of the channel that no amount of SEO skill reverses.

  • The 2025–26 version: thin wrappers on model APIs. Three risks stack. Pricing and terms risk: your unit economics are set by a supplier who can reprice in either direction. Deprecation risk: OpenAI's published policy promises at least six months' notice for generally available models, at least three months for specialised variants, and as little as two weeks for previews (OpenAI deprecations) — so a product tuned to one model's behaviour faces forced migration on a six-month clock, repeatedly. [Verified] Absorption risk: the platform ships your feature. A wrapper whose only assets are a prompt and a UI has no defence against any of the three.

Warning signs. More than ~40% of new customers arrive through one channel you do not control. Gross margin depends on a price list you cannot negotiate. One provider's terms could make your core feature non-compliant.

Prevention. (1) Own the relationship even if you rent the channel — capture email, build an owned audience, make the customer's account with you the thing of value. (2) Abstract the dependency behind your own interface from the start; for model APIs, keep an evaluation harness so a substitute can be benchmarked in days. (3) Build what the platform will not — proprietary data, workflow depth, integrations, compliance posture, human service.


Group 3 — Economics

B8. High customer acquisition cost

Mechanism. CAC is not a marketing metric; it is the price at which your market is willing to be reached, set largely by competitors bidding for the same attention. The failure is structural, not tactical: a company enters a market where acquiring a customer costs more than that customer will ever be worth, then tries to fix it with better ad creative. CAC also rises with scale, because the cheapest customers — those already looking — are acquired first.

Warning signs. CAC payback exceeds 24 months for a company without 24 months of runway. Blended CAC rises as paid volume rises. The only channel that works is paid.

Benchmark. Benchmarkit's 2025 SaaS Performance Metrics report found median CAC payback had lengthened 12.5% since 2022, with the new-customer CAC ratio rising 14% in 2024 to $2.00 of sales-and-marketing spend per $1 of new ARR. [Reported — vendor benchmark, method partially disclosed] [Analysis] Acquisition has been getting more expensive across software, so CAC assumptions imported from 2021-era writing are systematically optimistic.

Prevention. Measure CAC payback rather than LTV/CAC — payback is observable within a quarter and requires no guess about lifetime. Establish the channel before raising money to scale it. If the only viable channel is paid and payback exceeds 18 months, the business needs a higher price, a longer-lived customer, or to be a different business.

B9. Weak retention

Mechanism. Retention is the only metric that cannot be bought, and therefore the only reliable indicator that the product matters. Weak retention is fatal arithmetically: growth requires acquiring the same customers repeatedly, so acquisition spend buys a treadmill rather than an asset. Worse, it is frequently masked by growth — aggregate numbers look healthy while every cohort decays, and the mask comes off exactly when growth slows and you have least room to respond.

Warning signs. You report monthly actives but not cohort retention curves. Your curve never flattens, meaning no segment has found durable value. Logo churn is acceptable but the customers who stay are small.

Benchmark. Benchmarkit reported median net revenue retention at 101% and gross revenue retention falling to 88% in 2024, from around 90% previously. [Reported]

Prevention. Instrument cohort retention from your first hundred users and study the shape, not the average. Define one activation event that predicts month-3 retention and drive new users to it. Interview churned customers personally within a week, not by survey.

B10. Bad pricing — especially underpricing

Mechanism. Pricing errors compound faster than almost any other because price flows through every other number. Underpricing is the far more common error among technical founders and does four things at once: destroys the margin that would fund acquisition; attracts the customers who care most about price and churn hardest; signals low value, which lengthens enterprise sales cycles; and makes every later increase a negotiation with your installed base. A company underpriced by 2× does not have a revenue problem — it has a CAC problem, a churn problem and a hiring problem that all look separate.

Warning signs. No prospect has ever pushed back on price. You set the price by undercutting a competitor. Your price has never changed.

Prevention. Treat price as a variable in the early weeks — quote different numbers and watch where resistance starts. Price against the value of the problem (B3), not competitors' lists. Expect to raise prices and build the mechanism in from the start by pricing on a metric that grows with customer value (seats, usage, transactions), so revenue expands without renegotiation.

B11. Underestimating the cost of support

Mechanism. Support is the part of unit economics founders reliably forget, because in month one the founder does it free and the cost is invisible. It becomes visible at the worst moment — when volume grows. Support cost per customer is driven by product complexity (B5), underpricing (B10: cheap plans attract high-touch customers), and reliability. In AI products it is worse: failure modes are probabilistic, so a customer cannot tell whether an answer is wrong and escalates everything ambiguous.

Warning signs. Founders still do all support at 200+ customers. Tickets per customer per month is flat or rising rather than falling. There is no self-serve documentation.

Prevention. Track tickets per account per month as a first-class metric and treat a rising number as a product defect, not a staffing problem. Put support cost explicitly into gross margin. Fix the top three ticket drivers in the product before hiring a second support person.


Group 4 — People

B12. Hiring too early

Mechanism. Headcount added before the work is understood converts flexible cash into fixed cost and, worse, into organisational commitment. A five-person team pivots in a week; a thirty-person team pivots in a quarter, if at all, because thirty people have roles and roles are arguments against change. Early hiring also imports process: once you have managers you have meetings, and once you have meetings the founder stops talking to customers.

Warning signs. You hired a VP of Sales before a founder closed ten deals personally. You are hiring against a plan rather than a nameable bottleneck. Burn multiple (net burn ÷ net new ARR) exceeds roughly 2× at early revenue scale.

Example. Eisenmann's "speed trap" describes this compound: aggressive scaling drives a CAC/LTV squeeze while rapid hiring introduces process and cultural friction, each reinforcing the other (Underscore VC summary). [Verified as reported]

Prevention. Hire against a bottleneck that has persisted six weeks and that you have personally tried and failed to relieve. Founders should do each function badly themselves first — you cannot write a job description for a job you have never done. Use contractors for episodic work.

B13. Hiring too late

Mechanism. The mirror error, less discussed because "stay lean" is fashionable, and genuinely damaging. The founder becomes the bottleneck on a function they are bad at and cannot delegate, because they never built the system. Common shapes: a technical founder selling badly for two years; no finance function until diligence exposes that the numbers were never right; no security or compliance owner until a customer questionnaire stops a deal.

Warning signs. A critical function lives entirely in one person's head. Founders are doing urgent execution rather than the two or three things only they can do. Deals slip for reasons a competent specialist would resolve in a week.

Examples. Eisenmann's "help wanted" pattern — absent senior functional leadership when scale demands it; his Dot & Bo case required three attempts to find the right VP of Operations while logistics failures accumulated. [Verified as reported] Builder.ai reportedly operated without a CFO from 2023 until its 2025 collapse, a period in which revenue was later reported as inflated (Rest of World, 2025). [Verified as reported]

Prevention. Name the two functions where you are the bottleneck and set a trigger — a revenue level, a headcount, a customer count — at which you hire. Decide it when calm, not in the middle of the crisis the gap causes.

B14. Founder conflict

Mechanism. Founder conflict rarely destroys a company through one dramatic rupture. It destroys it through decision latency: two people who disagree fundamentally stop making decisions, and a startup that cannot decide dies of ordinary causes while everyone is distracted. The precipitating disagreements are almost always about role and authority rather than strategy — who decides, whose name is on what, who is really CEO — and they surface when the company either succeeds enough to be worth fighting over or fails enough to require blame.

Warning signs. Decisions get re-litigated after they are made. Employees route around one founder. There is no agreed tiebreaker.

Prevention. The structural protections — vesting with a cliff, a written founder agreement covering decision rights and departure, a named tiebreaker per domain, a scheduled review of the equity split — are covered in Chapter 5, sections A4–A6 and A12. The behavioural protection is more prosaic: a recurring private conversation between founders about how the partnership is going, separate from any conversation about the business. Conflicts that are discussable stay survivable.

B15. Poor hiring

Mechanism. Distinct from B12/B13, which are about timing; this is about selection. In a ten-person company a bad hire is 10% of capacity and a larger share of culture, and the cost is asymmetric: a mediocre hire is worse than an empty seat, because the empty seat is visible while the mediocre hire absorbs management attention and produces work that must be redone. The commonest selection errors are hiring for credentials or company brand rather than the specific work, and hiring someone whose last job was at a scale where the systems already existed.

Warning signs. Interviews are conversations rather than work samples. You are hiring people you like. Reference checks are pro forma or skipped for speed.

Prevention. Use paid work trials or realistic work samples for every early hire — the single highest-value process change most small companies can make. Write the 90-day success definition before opening the role and show it to the candidate. Do back-channel references, not only the listed ones.

B16. Founder burnout

Mechanism. Usually framed as a wellbeing issue; its business mechanism is that it degrades judgement before it degrades effort. An exhausted founder keeps working and keeps shipping but loses the capacity to reassess whether the plan is right. The result is sustained activity, deteriorating decisions, and an unwillingness to consider stopping at exactly the point where stopping has become correct. Burnout is structural rather than a matter of individual resilience: unbounded hours, identity fusion with the company, isolation, and outcomes dominated by factors outside one's control.

Evidence. The most cited study is Freeman et al., Are Entrepreneurs "Touched with Fire"? (2015): 242 entrepreneurs against 93 comparison participants, with 72% of entrepreneurs self-reporting mental health concerns, 49% reporting one or more lifetime conditions, 30% depression and 29% ADHD, each significantly above the comparison group (study PDF). [Self-reported; small sample; non-random comparison group; 2015 vintage — suggestive, not a prevalence estimate.] The 2025–26 "founder burnout statistics" pages circulating online deserve more scepticism still; most trace to marketing surveys with undisclosed sampling.

Warning signs. You no longer take a full day off. Decisions that took an hour now take a week or are made impulsively. You are irritable with the people whose judgement you most need.

Prevention. Separate identity from outcome early — write down, before you start, what you will have gained even if it fails. Keep at least one relationship (peer group, therapist, coach, co-founder) where you can say the true thing. Set a personal runway alongside the company's, and treat hitting it as a decision trigger rather than a reason for more effort. If you are in crisis, that is a matter for a qualified professional, not a business framework.


Group 5 — Capital

B17. Excessive dilution

Mechanism. Dilution is an accumulation, and founders underestimate it because they model it per-round rather than compounding. The failure mode is not that founders own less; it is that at low ownership the incentive structure inverts — expected value from a mid-sized exit falls below opportunity cost, which makes founders behave in ways rational for them and destructive for the company. Structure matters as much as percentage: heavy preference stacks and participating preferred can leave common stock worth nothing in an outcome that looks like success.

Benchmark. Carta's Founder Ownership Report 2026 (12 March 2026, covering rounds raised 2021–2025) reports median founder ownership of 56% at seed, 36% at Series A, 27.3% (AI) / 21.8% (non-AI) at Series B, and 16.1% at Series C — where the median employee option pool (16.8%) overtakes median founder ownership. [Verified — Carta platform data]

Warning signs. You cannot produce a pro-forma cap table two rounds out. You have stacked SAFEs at different caps without modelling aggregate conversion. You accepted unmodelled terms because you were low on cash.

Prevention. Model the full waterfall — proceeds at several exit values, not just ownership percentage — before signing. Sequential uncapped or high-cap SAFEs can produce surprise dilution at conversion. Raise to a milestone, not to the maximum offered. This is an area where a startup-experienced lawyer is genuinely required: the terms that matter most do nothing in the good case and everything in the mediocre one.

B18. Overfunding — "too much money too early"

Mechanism. Counterintuitive enough to state precisely. Excess capital does not cause failure directly; it removes the constraint that would have forced discovery. A company with eighteen months of runway must find out whether customers will pay. A company with five years can spend three of them building, hiring and generating impressive activity without testing the core assumption.

Documented cases:

  • Fast raised $124.5m, reached roughly six-figure annual revenue, burned approximately $10m/month, and shut down in April 2022 (TechCrunch). [Verified]
  • Convoy raised over $836m before winding down in 2023; CB Insights' post-mortem collection records founders without trucking experience attempting to make a structurally money-losing model profitable as demand fell (CB Insights post-mortems). [Verified as reported]
  • Olive AI raised $850m and shut down citing "challenging economic conditions, evolving customer expectations, and management missteps." [Self-reported failure reason]
  • Hyperloop One raised $472m and never secured contracts for an operational system — Eisenmann's "cascading miracles," where technical, regulatory and commercial breakthroughs all had to land. [Verified as reported]
  • Builder.ai raised approximately $445m at a $1.5bn peak valuation and entered insolvency in May 2025 after Bloomberg reporting on inflated revenue and alleged round-tripping, with former employees stating that humans performed the large majority of work marketed as AI-automated (Rest of World). [Verified as reported; the round-tripping allegations were denied by the counterparty]
  • Scale context: PitchBook counted roughly 3,200 US venture-backed startups failing in 2023, having raised $27.2bn collectively (Entrepreneur's summary of PitchBook data); PitchBook noted the figure likely understates the total. [Verified as reported]

Warning signs. You raised more than the plan required because it was available. Headcount grows faster than revenue or than validated learning. Your valuation implies an exit you cannot name a buyer for.

Prevention. Raise against a milestone. Before the round closes, write down the three things this capital must prove and the date by which you will know. Keep the burn decision separate from the balance decision.

B19. Overspending

Mechanism. Distinct from overfunding — a company can overspend on any amount of capital. Overspending is rarely extravagance; it is unexamined recurring commitment: a stack of SaaS subscriptions, cloud resources provisioned for load that never came, an office sized for a headcount plan, agencies retained past their usefulness. Each was defensible alone. Together they set a burn rate that requires a fundraise, and that requirement converts a spending problem into an existential one.

Warning signs. Nobody can list your recurring costs from memory or find them in one place. Cloud spend is not attributed to features or customers. You do not know your burn multiple.

Prevention. Keep one cost register, reviewed monthly, with an owner and renewal date per line. Compute burn multiple and treat it as a top-line metric. Default to no on new recurring commitments.

B20. Weak financial controls

Mechanism. Controls are dismissed as bureaucracy and their absence is invisible until one of three things happens: a fraud, a diligence process, or a tax or payroll obligation that has been accruing unrecognised. The common concrete failures are payroll tax mishandling, sales-tax nexus discovered years late, contractor misclassification, incorrect revenue recognition, and no second pair of eyes on outgoing payments. What turns these into company-killers is that they surface during a fundraise or acquisition — exactly when a clean balance sheet is the thing you are selling.

Warning signs. One person can initiate and approve a payment. Books are reconciled quarterly or "when needed." The founder cannot state cash, burn and runway without opening a file. Sales tax / VAT treatment has never had professional review.

Example. Builder.ai reportedly lacked a CFO from 2023, and after Bloomberg's March 2025 report on inflated revenue a lender seized most of the company's cash — a controls failure and a financing failure arriving as one event (Rest of World). [Verified as reported]

Prevention. Separate initiation from approval above a low threshold, from month one. Use a bookkeeper monthly rather than an accountant annually. Reconcile monthly and produce a three-statement view even if it is small. Get professional review of payroll tax, sales-tax nexus and worker classification once you have employees or multi-state customers — these are where small companies most often accrue material liability unnoticed, and they need a qualified professional, not a template.


Standing caveat: none of this is legal advice. It describes documented enforcement actions and rulings to show what the risk looks like in practice. Every area below turns on the specifics of your product, jurisdiction and customers, and the cost of guessing wrong runs to six or seven figures and occasionally personal liability.

B21. Regulatory mistakes

Mechanism. Regulatory failure in startups is rarely deliberate law-breaking. It is one of three things: not knowing a regime applies; assuming a partner is handling compliance for which you are jointly responsible; or building a product whose core value proposition is the regulatory arbitrage, so compliance and the business model are directly opposed. The third is most dangerous, because fixing it means ending the company.

The partner-responsibility trap is the commonest startup-specific version: a fintech assumes its banking-as-a-service provider owns compliance; a health product assumes its cloud vendor's HIPAA posture covers it. In both cases obligations are shared and the startup cannot see whether they are being met.

Documented case — Synapse. Synapse Financial Technologies provided middleware between fintech apps and partner banks, and filed Chapter 11 in April 2024. The CFPB alleged it violated the Consumer Financial Protection Act by failing to maintain adequate records of the location of consumers' funds and failing to reconcile with partner banks. A shortfall of $60–90 million emerged between what banks held and what Synapse's records said consumers had; consumers lost access to funds for weeks or months and many did not recover full balances. The stipulated final judgment (entered 12 September 2025) included injunctive relief and a $1 civil money penalty, structured at $1 so the CFPB could direct victim-relief funds toward restitution (CFPB enforcement record). [Verified — regulator's own record] [Analysis] The point for founders is that downstream fintechs which had done nothing wrong had their customers' funds frozen because of a partner's records failure. Your compliance risk includes your vendors' compliance risk.

Related enforcement. The FTC's "Operation AI Comply" (launched September 2024, continued since) targets overstated AI claims: Click Profit drew over $20m in judgments (March 2025) over an "AI-powered system" where roughly 20% of customers earned nothing; Workado was ordered into compliance monitoring (April 2025) over a claimed 98% accuracy rate for AI-detection software whose actual rate was 53%; DoNotPay and Rytr were among the initial 2024 actions (Benesch, 2025). [Verified as reported] The rule: claims about what your AI does face substantiation requirements like any other product claim.

Warning signs. Nobody can name which regimes apply to you. Legal review happened once, at incorporation. Your model depends on a classification (not a broker, not a lender, not a medical device, not an employer) a regulator might read differently.

Prevention. Identify applicable regimes before you build, not before you launch — a half-day with a specialist lawyer, and the cheapest legal spend you will make. Where you rely on a partner for regulatory cover, get the allocation in writing and ask for evidence of performance, not assurances. Counsel is genuinely required for financial services, health data and medical claims, insurance, employment/gig classification, children's data, anything touching securities, and cross-border data flows.

B22. Security breaches

Mechanism. For an early startup a breach is rarely fatal through the fine; it is fatal through the enterprise-sales consequence. Afterwards every security questionnaire contains a question you must answer badly — and the customers about to sign are the security-conscious ones. Second-order damage comes from the response: companies without an incident plan respond slowly and communicate badly, turning an incident into a trust event.

Evidence. IBM's 2025 Cost of a Data Breach Report puts the global average breach cost at $4.44m (down 9% from $4.88m), with mean time to identify and contain at 241 days. Two findings are specific to now: "shadow AI" — unsanctioned employee use of external AI tools — added an average $670,000 to breach cost; 13% of surveyed organisations had suffered an attack affecting their AI models or applications, 97% of those lacked proper AI access controls, and 63% had no AI governance policy. [Reported — IBM/Ponemon survey; the average is dominated by large enterprises and is not a small-company estimate]

Warning signs. No one owns security. Production credentials sit in a shared document or in source control. Every engineer has production database access.

Prevention. The early-stage list is short and cheap: SSO with mandatory MFA, a secrets manager, least-privilege access with production gated, centralised logging, tested backups, dependency scanning, and a one-page incident response plan naming who calls whom. Write an AI-tool policy before you need one. Get a security review before your first enterprise deal rather than during it.

B23. Privacy violations

Mechanism. Privacy failures differ from security failures: you can have perfect security and still violate privacy law, because the violation concerns what you collect, why, who you share it with, and whether people can opt out. The startup-specific pattern is that privacy obligations attach to the marketing stack — analytics, ad pixels, session recorders, CRM integrations installed early and never reviewed — rather than to the product, so they are invisible to engineering and owned by nobody.

Enforcement, with amounts:

GDPR. The CMS GDPR Enforcement Tracker records approximately €6.11bn across ~2,685 recorded fines, average €2.28m — heavily skewed by a handful of mega-fines. Largest: Meta Platforms Ireland €1.2bn (2023), TikTok Technology €530m (2025), Meta Platforms Inc. €405m (2022), Meta Platforms Ireland €390m (2023), TikTok Limited €345m (2023). Ireland's DPC issued nine of the top ten. [Verified — tracker compiled from published decisions] [Analysis] The distribution matters more than the average: Spain alone has issued over a thousand fines at far lower amounts. Realistic startup exposure is a five- or low-six-figure fine plus mandated remediation — but a remediation order can force you to delete data or stop a processing activity your product depends on.

CCPA / California. Two recent reference points:

  • Healthline Media, $1.55m — then the largest CCPA settlement, announced by California AG Bonta on 1 July 2025. Allegations: failure to honour opt-outs of targeted advertising; violation of the purpose-limitation principle by sharing article titles revealing a likely medical diagnosis with advertisers; missing CCPA terms in third-party contracts; and a consent banner that did not function. Injunctive terms include a first-of-its-kind ban on sharing article titles that reveal a diagnosis (California AG press release). [Verified — regulator's own release]
  • Tractor Supply Co., $1.35m — the California Privacy Protection Agency's largest action, announced 30 September 2025. Findings: a "Do Not Sell" link that did not stop third-party sharing; failure to honour Global Privacy Control signals until July 2024; a privacy policy unchanged since November 2021 despite an annual-update requirement; missing job-applicant notices; and third-party contracts lacking required CCPA provisions (White & Case summary). Earlier CPPA actions: Honda $632,500 and Todd Snyder Inc. $345,000. [Verified]

[Analysis] Read those two actions as a checklist, because they are unusually explicit about what regulators look at: does the opt-out work, do you honour Global Privacy Control, is the policy updated annually, do job applicants get notice, and do vendor contracts contain the required terms. Four of the five are documentation problems fixable in a week. The fifth — whether the opt-out actually stops data flowing — requires someone to test it.

Warning signs. You cannot produce a data map. Your privacy policy was copied from another company. Marketing added tags without review.

Prevention. Build a data inventory early and collect less. Review the marketing stack as a privacy surface on a schedule. Test your own opt-out end to end and honour GPC. Counsel is genuinely required if you handle health, biometric, financial, precise-location or children's data, or if you have EU/UK users.

Mechanism. Two risks founders often conflate. Input risk: whether the data used to train or fine-tune a model was lawfully obtained and used. Output risk: whether what your product generates infringes, and who bears liability. A startup that fine-tunes on scraped data carries input risk directly.

Where the law stands as of September 2026 — genuinely unsettled:

  • US — Bartz v. Anthropic. Judge William Alsup held that training an LLM on lawfully-acquired copyrighted text was fair use, while separately finding that downloading books from pirate sources (LibGen and similar) to build a training library was not. Anthropic settled for $1.5bn, structured at approximately $3,000 per work across an estimated 500,000 works; final approval came on 20 July 2026 (TechCrunch). [Verified] Critically, this was a district court decision that was settled rather than appealed, so it is not binding precedent, and litigation against other model developers continues.

  • UK — Getty Images v. Stability AI. The English High Court delivered the UK's first substantive judgment on generative-model training in November 2025. Getty dropped its primary training and output copyright claims during trial, largely on evidential grounds about where training occurred; the secondary copyright infringement claim failed; Getty won only a narrow trademark finding on watermark reproduction (Bird & Bird; Mayer Brown). [Verified] [Analysis] The judgment resolved far less than either side wanted; read it as a map of what is hard to prove rather than a rule about what is lawful.

What this means concretely for a startup building on generative models:

  1. Provenance of anything you train on is your problem. The Anthropic outcome suggests the decisive distinction was acquisition, not use. If you fine-tune, document where every dataset came from and what licence permitted it; "we found it on Hugging Face" is not a provenance record.
  2. Indemnities are a real, checkable asset. Major model providers offer customer indemnification for copyright claims arising from outputs, but scope, caps and conditions differ and several require you to have used specified safety features. Read yours; if there is none, price the risk.
  3. Output-side hygiene. Do not build a product whose appeal is generating work in a named living artist's style or reproducing protected characters. The Getty trademark finding on watermarks is a small warning about a large surface.
  4. Your supplier's litigation is your business risk. A model you depend on could be enjoined, repriced, or have its corpus changed — another instance of B7.

Warning signs. You cannot document the provenance and licence of every dataset you trained or fine-tuned on. You have not read your model provider's indemnity, or there is none. Your product's marketing invokes a named living artist, author or franchise.

Prevention. Keep a dataset register with source and licence for anything you train on. Check and, where possible, negotiate output indemnification. Avoid style- or character-imitation as a value proposition. Counsel is genuinely required here: the area is unsettled, jurisdictionally fragmented and moving, and anyone telling you the law on AI training data is clear is selling something.

B25. AI hallucinations and reliability failures in production

Mechanism. A generative system produces confident, fluent, wrong output and the surrounding product treats it as authoritative. The failure is architectural rather than a model defect: the model is doing what it does, and the company built no verification layer, no confidence surface, and no human checkpoint where output becomes a commitment. Two harms follow. Legal: statements your system makes can bind you.

Documented incidents:

  • Moffatt v. Air Canada (BC Civil Resolution Tribunal, February 2024). Air Canada's website chatbot told a customer he could apply for a bereavement fare retroactively. He could not. Air Canada argued that "the chatbot is a separate legal entity that is responsible for its own actions." The tribunal rejected this: a chatbot "is still just a part of Air Canada's website. It should be obvious to Air Canada that it is responsible for all the information on its website." It found negligent misrepresentation and awarded approximately CAD $650 plus interest and fees (ABA Business Law Today; McCarthy Tétrault). [Verified] [Analysis] The damages are trivial; the holding is not. The tribunal also found consumers cannot be expected to cross-check a chatbot's answer against other parts of the same website — which forecloses the "our terms said to verify" defence.

  • Legal-citation sanctions. The best-documented category of AI production failure, because courts write it down. Damien Charlotin's AI Hallucination Cases database recorded 2,041 cases across more than 50 jurisdictions as of 14 September 2026 — 1,396 in the USA, 217 in Canada, 110 in Australia, 69 in the UK. Monetary sanctions are mostly modest (the largest shown is $8,000, in Booker v. The Kroger Co., N.D. Ga., 28 August 2026), but professional and reputational consequences are not. [Verified — public database of court decisions] The relevance for founders building legal, medical, financial or research tools is direct: your users submit your output into contexts with verification regimes, and when it is wrong it is discoverable.

  • Cursor / Anysphere, April 2025. Cursor's AI support bot invented a policy restricting users to a single device and told customers this was "expected behaviour." Users cancelled subscriptions over a rule that did not exist. Co-founder Michael Truell confirmed publicly that "we have no such policy," attributed the underlying logouts to a session race condition, refunded the affected user, and committed to labelling AI-generated support responses (The Register, 18 April 2025). [Verified] [Analysis] Note the shape: the bot did not merely give a wrong answer, it invented policy — the class of output a customer reasonably treats as authoritative, because only the company can know it.

Warning signs. AI output is shown without provenance or citation. There is no human review where output becomes a commitment (a price, a policy, a legal statement, a medical suggestion). You have no evaluation suite and no regression tests on model behaviour.

Prevention. Constrain the domain: retrieval over sources you control beats open generation for anything factual. Show provenance. Put a human in the loop wherever output creates an obligation — that is the line, not "high stakes" in the abstract.


Group 7 — Structural and strategic

B26. Scaling before product-market fit

Mechanism. Scaling multiplies whatever the company currently is. If the product does not yet retain customers, scaling multiplies the leak: more spend acquiring customers who churn, more staff supporting a product that does not work, more organisational commitment to an unvalidated direction. It persists because scaling is the only available action that looks like progress when the founder does not know what else to do — and because the capital structure strongly encourages it.

The Startup Genome research, with vintage and criticisms. The most-cited source is the Startup Genome Report Extra on Premature Scaling (2011), reporting that 74% of high-growth internet startups fail due to premature scaling, from a dataset of roughly 3,200 startups. It defined premature scaling as any behavioural dimension — acquisition spend, hiring, product build-out — running ahead of the company's actual stage.

[Vintage: 2011. Treat with substantial caution.] The specific problems:

  1. Self-selected survey sample — founders who chose to complete an online assessment, skewing toward the engaged and self-aware.
  2. Self-reported stage and self-reported failure — both variables come from the respondent.
  3. Undisclosed thresholds. The report states: "In order to not bias the startups taking the survey we will not publish the thresholds and milestones we use for the stage assessment." A classification whose criteria are secret cannot be checked or replicated.
  4. No longitudinal data — acknowledged in the report, along with limited market assessment and inability to place startups on the adoption curve.
  5. Circularity risk. "Scaled before it was ready, and failed" is close to definitionally true.
  6. It is fifteen years old, from an era of different capital costs, different channels and no generative AI.

[Analysis] The concept is sound and matches Eisenmann's independently-derived speed trap. The 74% figure should not be cited as a measurement. Use the idea; drop the number.

Warning signs. You are hiring salespeople before a founder has closed repeatedly. Paid acquisition scales while cohort retention is flat or declining. You have a growth plan and no retention curve.

Prevention. Define a PMF gate in advance and refuse to scale until it is met — something observable, such as a flattening retention curve in at least one identifiable segment, plus a repeatable sales motion a non-founder has executed at least three times. Scale one variable at a time so results can be attributed. Treat a worsening cohort as a stop signal, not a marketing problem.

B27. Vendor lock-in

Mechanism. Lock-in is the gap between what a service costs and what it would cost to leave. It accrues quietly through proprietary interfaces, data formats you cannot usefully export, operational knowledge, and switching costs that rise with volume. The business consequence is not the direct cost but the loss of negotiating position: a vendor that knows you cannot leave has no reason to hold pricing, and a vendor that fails has no substitute ready.

Warning signs. You have never tested an export of your own data. A core capability depends on a proprietary API with no equivalent. The vendor raised prices and you did not negotiate.

Prevention. Distinguish acceptable lock-in (managed database, payments, auth — where operational leverage is worth it) from unacceptable lock-in (anything touching your core differentiation, or any single point of total failure). Keep an interface layer between your application and any swappable dependency, especially model APIs. Export and verify your own data quarterly; the first attempt always reveals something.

B28. Lack of distribution

Mechanism. The most under-weighted failure mode relative to how often it is decisive. A company with a mediocre product and excellent distribution beats a company with an excellent product and none, reliably, because distribution compounds and product quality does not. Founders under-weight it because building is legible and controllable while distribution is not — and because "if we build something great people will find it" is a comforting belief that was never true and is emphatically not true now that AI has made building cheaper and therefore made everything more crowded.

Warning signs. Your go-to-market plan is a list of channels rather than a hypothesis about one. "Word of mouth" is a plan rather than an outcome. You have no owned audience and no relationship with anyone who has one.

Prevention. Choose a distribution hypothesis before you choose a product, and let it constrain the product — a business you cannot afford to reach is not a business. Build an owned audience early, however small; it is the only acquisition asset that appreciates. Treat distribution as an equal claim on founder time from week one.

B29. Confusing attention with traction

Mechanism. Attention is a spike in awareness. Traction is a sustained increase in the rate at which people adopt, retain and pay. They look identical for about two weeks — precisely long enough to make a bad decision (hire, raise, scale spend) on a number that is about to decay. The confusion is actively encouraged: press coverage, a Product Hunt placement, a viral thread and a waitlist count are all showable to investors and all trivially inflatable.

Attention, not traction: waitlist signups, social followers, press mentions, launch-day rankings, "users" who signed up once, free-tier accounts, LOIs with no commercial terms, app downloads, GitHub stars, demo requests with no second meeting.

Traction: cohort retention curves that flatten, repeat purchase, paid conversion from free, revenue that recurs without being re-sold, organic referral persisting after the spike, and — most underrated — usage frequency rising within a cohort over time.

Warning signs. Your metrics deck leads with cumulative totals rather than cohorts and rates. Your best month was your launch month and you mention it often. You cannot say what percentage of launch-week signups were active at day 30.

Prevention. Instrument cohorts before you launch, so the spike is measurable rather than memorable. Set the success criterion for any launch in advance, in retention terms — "X% of launch-week signups still active at day 30" — and hold to it. Treat every spike as an experiment that generates a cohort to study.


PART C — Two working frameworks

Both tools below are designed to be used, not admired. They share one design principle: a question is only useful if a "no" changes what you do tomorrow. Every item therefore states its implication.

A caution about both. These frameworks encode the failure modes in Part B, which were derived from retrospective data subject to the three biases in the introduction. They are decision aids, not oracles. Several of history's best businesses would have scored poorly on Framework 2 at inception — the correct response to a low score is usually "find out more" or "change the plan," not "abandon." Where a framework would have you kill an idea, ask first whether you have evidence or only an absence of evidence. [Analysis]


Framework 1 — The startup risk checklist, by stage

Use it as a periodic review, not a one-time gate. Score each question yes / no / unknown. Treat "unknown" as "no" — an unknown risk is an unmanaged one. The "so what" column is the point of the exercise.

Stage 0 — Pre-idea (before you commit to a direction)

# Question If NO
0.1 Can I name a specific group of people, by role and situation, whose problem I understand better than most people do? You are choosing from the publicly visible opportunity set, which is the crowded one. Get inside a domain before committing capital. → B2
0.2 Do I have access — introductions, credibility, or employment — to at least ten of those people this month? Your research will be slow and biased toward whoever will talk to you. Fix access first; it is also your first distribution test. → B2, B28
0.3 Have I decided what kind of company this should be (venture-scale, bootstrapped, services, lifestyle) and does that match my financial situation? You will default to the venture path because it is the loudest, and it may be wrong for you. See Chapter 1.
0.4 Do I know my personal runway in months, and what I will do when it ends? You will make decisions under financial panic, which is where the worst ones get made. → B16
0.5 If I have co-founders: have we discussed equity, roles, decision rights and what happens if one of us leaves? You are accumulating an unexploded problem that detonates exactly when the company becomes worth fighting over. → B14, Chapter 5 A4–A6
0.6 Have I written down what would make me stop, and by when? You have no exit condition, so you will exit only when forced — by money running out, which is the most expensive possible trigger.

Stage 1 — Pre-launch (idea chosen, nothing shipped)

# Question If NO
1.1 Have I talked to 20+ potential customers about what they did, not what they would do? Your demand evidence is hypothetical. → B1, B4
1.2 Can I state what this problem costs a customer per month, in money or hours, with a number they gave me? The problem may be real but not valuable. → B3
1.3 Is that cost at least 5–10× the annual price I intend to charge? Inertia will beat you. Either the price is wrong or the problem is. → B3, B10
1.4 Do I know who signs the cheque, and is it the same person who feels the pain? Your sales cycle is longer and your close rate lower than you have modelled.
1.5 Has anyone paid, pre-paid, or signed a commercial LOI? You have interest, not demand. Do not build further until someone commits something costly. → B1, B29
1.6 Do I have a specific distribution hypothesis — one channel, one reason to believe it works for this customer? "We'll figure out marketing later" is the most common unforced error in the list. → B28
1.7 Can I describe the smallest thing that would let a real customer get real value, and is it under 8 weeks of work? You are about to overbuild. Cut scope until the answer is yes. → B5, B6
1.8 Have I identified which regulatory regimes apply and confirmed with someone qualified? You may be building a business whose core model is non-compliant. Cheapest legal spend you will make. → B21
1.9 Do I know what happens to this business if my main platform, supplier or channel changes its terms? You have an unpriced existential dependency. → B7
1.10 Is the company properly formed, with founder IP assigned and vesting in place? Every future financing and acquisition will surface this, expensively. Chapter 5 A5.

Stage 2 — Post-launch (shipped, early customers)

# Question If NO
2.1 Do I have cohort retention curves, and does any cohort's curve flatten? You do not know whether the product matters. Nothing else should be scaled. → B9
2.2 Is CAC payback under 18 months, measured not modelled? Growth spend is destroying value. Fix price, retention or channel first. → B8
2.3 Have I changed price at least once, and did anyone resist? You are probably underpriced, and underpricing is masking a CAC problem you will misdiagnose. → B10
2.4 Do I know support tickets per account per month, and is it falling? Support cost is about to eat your gross margin as you grow. → B11
2.5 Can I name the single activation event that predicts month-3 retention? Your onboarding is guesswork and your retention work has no target. → B9
2.6 Do I know gross margin including inference, infrastructure and support? For AI products especially, your margin may be structurally below SaaS norms — a16z's analysis put AI-company gross margins at 50–60% versus 60–80%+ for SaaS. → B11
2.7 Is more than 40% of new business arriving through one channel I do not control? Concentration risk. Start a second channel now, while you can afford the learning. → B7, B28
2.8 Is customer data inventoried, are opt-outs tested end to end, and do we honour Global Privacy Control? These are the exact items regulators cited in the 2025 Healthline and Tractor Supply actions. → B23
2.9 Are the security basics in place: SSO+MFA, secrets manager, gated production access, tested backups, logging, written incident plan? You will fail your first enterprise security review, and an incident will be unrecoverable. → B22
2.10 If we use generative models: is there an evaluation harness, provenance on outputs, and a human checkpoint wherever output creates an obligation? You are one confident fabrication away from a Moffatt-style liability or a Cursor-style trust event. → B25
2.11 Are books reconciled monthly, and can I state cash, burn and runway right now without opening a file? You are flying on instruments you do not read. → B19, B20
2.12 Is every founder still able to say the uncomfortable thing to the others? The conflict is already happening; it is just not being discussed. → B14

Stage 3 — Scaling (repeatable motion, growing team)

# Question If NO
3.1 Has someone who is not a founder closed at least three deals end to end? The sales motion is not repeatable; it is you. Do not hire a sales team. → B26
3.2 Is net revenue retention above 100%, and is gross retention stable? You are scaling a leak. Median NRR was ~101% and GRR ~88% in the 2025 Benchmarkit data — below that, expansion will not save you. → B9, B26
3.3 Are new cohorts performing at least as well as older ones? You are into Eisenmann's speed trap: buying worse customers at higher cost. Stop scaling spend. → B8, B26
3.4 Is burn multiple (net burn ÷ net new ARR) under ~2×? You are buying growth at a price that will not clear the next round. → B12, B19
3.5 For each critical function, is there an owner who is not a founder? Founders are the bottleneck and quality is degrading in the gaps. → B13
3.6 Do we use work samples or paid trials for hires, with a written 90-day success definition? Your hiring is a series of likeability judgements. → B15
3.7 Have we removed a feature in the last year? Feature creep is now permanent, and your onboarding and support costs will keep rising. → B5
3.8 Can we model our cap table two rounds forward, including the proceeds waterfall at three exit values? You do not know what you own or what you would receive. → B17
3.9 Is spending decided by bottleneck rather than by available balance? Capital is substituting for evidence — the overfunding pattern. → B18
3.10 Do we have a tested migration path off each critical vendor, and do we know the cost in weeks? You have no negotiating position and no failover. → B27
3.11 Is someone accountable for compliance across every regime we touch, including our partners' obligations? Synapse's downstream fintechs did nothing wrong and their customers still lost access to funds. → B21
3.12 Do the founders have lives, relationships and identities outside this? Judgement degrades before effort does, and you will not notice. → B16

How to use it

Run Stage 0–1 once, honestly, before committing. Run the stage you are in monthly with your co-founders, and keep the scores — the trend matters more than the level. Any question answered "no" three months running is either an accepted risk (write down why you accept it) or a project with an owner and a date. There is no third option; "we know about that" is how companies die of things they knew about.


Framework 2 — "Should we build this?"

A gated scoring framework. It runs in two parts: four gates that are pass/fail, then six dimensions that are scored. The gates come first because a failure on any of them cannot be compensated for by strength elsewhere — that is what makes it a gate rather than a weight.

Part 1 — The gates (all four must pass)

Gate 1 — Problem severity. Is the problem expensive enough that someone is already spending money or significant time on it, imperfectly? Pass test: you can name the current alternative (a competitor, a spreadsheet, an agency, a person's job) and estimate what it costs. Fail: nobody currently spends anything, and you are arguing they should.

Gate 2 — Reachability. Can you reach enough of these customers, affordably, through a channel you can actually operate? Pass test: you can name one channel, one reason it fits this buyer, and an estimate of cost per acquired customer that is less than a third of first-year revenue per customer. Fail: the buyer exists but is unreachable at a price the business supports. A market you cannot reach is not your market.

Gate 3 — Willingness to pay. Will they pay, at roughly the price your model requires? Pass test: at least three prospects have committed something costly — money, a signed pilot, a scheduled implementation. Verbal enthusiasm is not a pass. Fail: interest without commitment.

Gate 4 — Survivable regulatory and legal exposure. Is there a lawful version of this business, and can you afford compliance? Pass test: you have identified the applicable regimes and, where they are material, confirmed with qualified counsel that a compliant version exists at a cost you can bear. Fail: the business model is the arbitrage, or the compliance cost exceeds plausible early revenue.

A failed gate is not necessarily a dead idea. It is a dead plan. The correct response is to change the customer, the channel, the price or the product until the gate passes — or to go and find out, if the honest answer is "I don't know."

Part 2 — The scored dimensions

Score each 0–5. Definitions matter more than precision, so the anchors are given.

Dimension 0–1 2–3 4–5
Market size and growth Small and shrinking; or a TAM figure with no bottom-up derivation Real but modest; or large and static Large enough for your model bottom-up (customers × price), and growing for a structural reason you can name
Founder fit No domain experience, no access, learning from customer calls Adjacent experience; some access Deep domain knowledge or unusual access; you know which of the visible problems is the one with budget
Distribution advantage No audience, no channel insight, plan is "content and ads" A plausible channel, unproven An existing audience, a channel you have operated successfully, a partner with reach, or a genuine product-led loop
Capital requirement fit Needs far more than you can raise or fund; long pre-revenue period Moderate; one round of dependency Can reach evidence of demand on money you control or can raise easily; revenue arrives early
Defensibility Anyone can clone it in a weekend; a thin wrapper on someone else's API Some execution or integration advantage Accumulating advantage: proprietary data, switching costs, network effects, regulatory position, workflow depth
Timing "Too early" with no forcing function; or late into a consolidated market Plausible but no specific reason it is now A specific, nameable change — a cost curve, a regulation, a platform shift, a behaviour change — that made this possible recently and has not yet been exploited

Scoring guide (out of 30), after all four gates pass:

  • 24–30 — Strong. The main risk is execution and your own discipline.
  • 18–23 — Worth pursuing with a named plan to raise the two weakest dimensions. Write that plan down.
  • 12–17 — Borderline. Proceed only with a time-boxed experiment that directly tests the weakest dimension, with a stop date.
  • Below 12 — The plan is wrong. Change something structural or choose differently.

Two hard overrides, regardless of total:

  1. Distribution advantage scoring 0–1 caps the whole assessment at "borderline." Distribution is the most common decisive failure and the least compensable. → B28
  2. Defensibility scoring 0–1 and a single-supplier dependency is a fail, not a score. That is the thin-wrapper position described in B7: no pricing power, no protection from absorption, and a forced-migration clock on someone else's deprecation schedule.

Worked example A — PASSES

Idea. Compliance-evidence automation for mid-sized US medical device manufacturers. Founder spent nine years as a quality manager at two device companies and personally assembled FDA and ISO 13485 audit evidence packages by hand.

Gates. Severity — pass: these firms employ 2–5 quality staff whose main job is assembling evidence; audit preparation costs a documented 400+ hours per cycle. Reachability — pass: ~2,000 addressable firms in the US; the founder knows roughly 60 quality managers personally and the industry has three conferences and two active professional associations. Estimated CAC well under a third of a $30k ACV. WTP — pass: three former colleagues at different companies have signed paid pilots at $2,000/month. Regulatory — pass: the tool produces evidence for the customer's own regulated process; it is not itself a regulated device. Counsel confirmed the boundary and the conditions that would cross it.

Scores. Market size 3 (2,000 firms × $30k = $60m bottom-up; growing modestly with regulatory burden). Founder fit 5. Distribution 4 (existing network plus an association channel). Capital fit 4 (revenue from month two; buildable by two people). Defensibility 4 (accumulating library of validated evidence templates, deep workflow integration, high switching cost once an audit cycle has run through it). Timing 3 (no dramatic forcing function, but AI makes document assembly newly tractable). Total 23/30 — pursue.

What would change the answer. If the founder could not get pilots signed, Gate 3 fails and the whole thing stops regardless of the 23. The score is contingent on the gates, not a substitute for them.

Worked example B — FAILS

Idea. An AI assistant that summarises meeting notes into task lists, sold to knowledge workers at $12/month. Two technical founders, no specific domain.

Gates. Severity — marginal: people do waste time on notes, but most already have a partially adequate solution bundled into tools they pay for. Nobody has a budget line for this. Reachability — fail: the buyer is "any knowledge worker," which means the channel is paid acquisition against well-funded incumbents. At $144 annual revenue per customer, sustainable CAC is roughly $40; blended paid CAC for consumer-prosumer productivity tools is not close to that. WTP — fail: no one has paid; the evidence is 900 waitlist signups, which is B29 (attention, not traction).

Result: two gates fail. Scoring is unnecessary, but for illustration: Market size 4 (huge), Founder fit 1, Distribution 0, Capital fit 3, Defensibility 0 (a prompt and a UI over a third-party model, which every meeting tool and every model provider can ship as a feature), Timing 1 (this became possible in 2023 and is now thoroughly exploited). Total 9/30, with both hard overrides triggered.

What the framework is actually telling you. Not "AI note-taking is a bad idea" — it is telling you that this plan has no reachable buyer, no willingness to pay, no distribution and no defensibility. A version of the same technical capability sold into a specific regulated vertical, by someone with access to that vertical, at $500/month, could pass every gate. The gate that killed it was reachability, and reachability is a choice about who you sell to.

Worked example C — BORDERLINE

Idea. A marketplace connecting independent physiotherapists with small employers offering on-site sessions. One founder is a former physiotherapist; the other ran operations at a staffing company.

Gates. Severity — pass: employers buy wellness benefits already, and musculoskeletal claims are a documented cost line for employers with physical work. Reachability — marginal pass: two sides to acquire; the supply side is reachable through professional networks (founder's own), the demand side requires HR and benefits buyers, where the founders have no access. WTP — pass, thinly: two employers have committed to paid three-month pilots, but at a price that does not yet cover fully-loaded delivery. Regulatory — pass with cost: professional licensing and liability insurance are handled by the practitioners, but worker-classification exposure is real if the platform controls scheduling and pricing — counsel flagged this as a live risk requiring structural care. → B21, Chapter 5 A9.

Scores. Market size 3. Founder fit 3 (strong on supply, absent on demand). Distribution 2 (one side only). Capital fit 2 (marketplaces need liquidity in a geography before they work, which means a real cash requirement before revenue). Defensibility 2 (local network effects eventually, nothing early). Timing 2 (no specific forcing function). Total 14/30 — borderline.

The correct action. Not "go" and not "stop." The framework identifies exactly one thing to test first: demand-side access. Time-box eight weeks to establish whether the founders can reach HR and benefits buyers repeatably — and set the stop condition in advance: five qualified meetings and one paid pilot at a price covering delivery, or the idea is shelved. Everything else is downstream of that. The classification question goes to counsel before, not after, the pilots — because the answer may determine the operating structure.

Using Framework 2 honestly

Three failure modes of the framework itself:

  1. Scoring your hopes. If you cannot cite evidence for a score, it is a 2 by default. Have someone who does not want the idea to succeed score it independently and reconcile the differences — the gaps are the research agenda.
  2. Treating the total as the answer. The total is a summary. The gates and the lowest two dimensions are the decision. A 23 with a 1 in distribution is worse than a 19 that is even.
  3. Using it once. Re-run it after every significant piece of evidence. The scores should move; if they never do, you are not learning anything.

And the standing limitation: this framework rewards legible, defensible, well-distributed ideas. Some genuinely great businesses looked illegible at the start, and the framework would have scored them low on timing and defensibility because the evidence did not exist yet. It is a tool for avoiding predictable failure, which is most failure. It is not a tool for identifying the rare, unpredictable success. [Analysis]


Closing note

The uncomfortable synthesis of Part A is that we do not actually know why startups fail, in the rigorous sense. We know how they die — they run out of money — and we have a large body of retrospective accounts about why, written by people who knew the ending and had reasons to shade the telling. The failure modes in Part B are best understood as a catalogue of things that are known to be dangerous, assembled from imperfect evidence, rather than as a ranked list of causes.

That should not be paralysing. Most of the items in Part B share a property that makes them worth attending to even under uncertainty: they are observable in advance and cheap to check. You can test whether your opt-out works. You can compute CAC payback. You can ask three customers what the problem costs them. You can read your own vendor contracts. None of that guarantees survival, and the base rates in Part A are what they are. But the failures that are avoidable are disproportionately the ones that were visible and unexamined — and the frameworks in Part C exist to make the examining routine rather than heroic.


Sources

Failure-rate baselines and shutdown data

Post-mortem and academic analysis

Unit economics and benchmarks

Platform dependence

Company failures

Regulatory, privacy and security

AI copyright and reliability