← All articles

The protection racket model: how indie devs pick markets they can't win in 2026

Selling both the disease and the cure — AI detector AND AI humanizer, plagiarism scanner AND paraphraser, spam filter AND email warmup — is the protection racket model. In the 2026 AI-search era it's gone from clever indie-SaaS hack to structural liability: AI engines won't cite you, E-E-A-T collapses, and a single investigative thread is a multi-year overhang. Here's the five-test framework for picking markets GEO will actually endorse, plus how to choose the right side once you spot the pattern.

RankPropel ·

An indie dev pitched me his stack last week. One Stripe account, two product pages, same Next.js app. The first page sells an AI-content detector to teachers and editors. The second page sells an AI humanizer to students and writers. He was proud of it. "Both sides of the market," he said. "Acquisition cost is basically zero — every customer is automatically a lead for the other product."

He was running a protection racket. He didn't know the term, and he definitely didn't know that the same positioning that quietly minted MRR in 2023 has, in the 2026 AI-search era, become one of the fastest ways to cap a SaaS at a permanent low ceiling.

This article is the framework. It's about market selection — the thing you decide before you write a single line of code — and the specific positioning trap that breaks more indie SaaS in 2026 than any technical mistake further downstream.

What the protection racket model is

A closed treadmill loop: a Detector creates demand for an Evader, which creates demand for a stronger Detector — TAM depends on the other side staying alive. Below, three forces (AI engines, platforms, regulators) all push toward the detector/provenance side, the long-arc winner, while independent "outside" demand feeds only the winner side.

A protection racket, in its original sense, is a business where you create or amplify a threat, then sell protection from it. Mafia movies. Modern version: any product positioning where the same company sells both the disease and the cure to the same audience.

The pattern recurs across many indie-SaaS categories. The tell is when one homepage lists both columns as features:

Market category "Detector" side "Evader" side
AI-generated content AI detection AI humanizing / paraphrasing
Plagiarism Originality scanning Sentence spinning, paraphrasing-to-bypass
Email deliverability Spam filtering, abuse mailboxes Cold-email warmup, inbox-placement-as-a-service
Bot traffic Bot detection, WAF Scraping-as-a-service for adversarial use
Hiring funnels ATS resume scoring ATS keyword optimization for that same ATS
Identity & security Breach / dark-web monitoring Selling the breach datasets the monitor scans
Ad blocking Adblocker Anti-adblock recovery rails
Captcha Captcha service Captcha-solving API
SEO Backlink monitoring, disavow tooling Negative SEO link blasts

Indie devs fall into the racket because the economics look beautiful from inside. Customer-acquisition cost for the second product is functionally zero — the audience for one side already cares about the other. Two Stripe products on one codebase. Two landing pages on one domain. The MRR graph goes up faster than any single-side competitor's. It feels like a hack. It is a trap.

Why 2026 made the racket structurally fatal

The model has always been ethically dubious. What changed in 2026 is that it became commercially dubious — for four specific reasons that didn't all exist two years ago.

1. AI engines refuse to cite self-contradicting vendors.

When a user asks ChatGPT, Perplexity, Claude, or Google AI Overviews "what's the best AI content tool for my team," the engine has to synthesize one coherent recommendation paragraph. A vendor whose landing page sells both sides of the same fight forces the model into a logical contradiction it cannot resolve in a sentence. The model's resolution is the same one a careful human writer would reach: omit the vendor, or describe it skeptically. Citation collapse is the GEO-era penalty, and it fires silently. You don't see it in Search Console. You see it in conversion-rate stagnation that you can't trace to anything.

2. E-E-A-T cannot accrue around a conflicted position.

Authority on a topic — the "A" in E-E-A-T — requires a defensible point of view. You cannot publish a serious essay on "the future of AI content integrity" while selling tools to defeat that integrity, and Google's quality systems read the contradiction in the link graph and the byline pattern. Author bios go thin. Person schema starts looking defensive. Backlinks from reputable sources don't arrive because the reputable sources don't want their byline associated with you. Every E-E-A-T signal we cover in the Fundamentals lesson on citation vs. ranking is structurally weaker for racket vendors than for single-side competitors, even when the racket vendor outspends them.

3. Investigative coverage is a one-shot, multi-year overhang.

One viral thread on X. One paragraph in a TechCrunch explainer. One quote in a NYT piece about AI integrity. Modern AI engines retrain on this coverage on a weeks-to-months cycle, and the framing becomes load-bearing in summaries about your category for years. Your single-side competitors don't carry this overhang. You do. The cost of being the recognizable example in one wrong news cycle is a permanent ceiling on how favorably any AI engine ever summarizes you again.

4. Platforms and regulators are tightening in the same direction.

Apple, Google, OpenAI, Anthropic, Stripe risk-ops, payment processors generally, the EU AI Act, US state attorneys general — all of them increasingly suspicious of dual-side categories. The five-year horizon for many racket categories isn't "fine," it's "squeezed out of payment processors, deindexed from app stores, demoted in default search." You can argue the policies are heavy-handed. The argument doesn't refund your MRR when Stripe freezes your account.

The five-test market-selection framework

Run these before you write code. Each takes five minutes. Failing two or more means you're building inside the racket.

1. The single landing page test

Write the homepage of the company you intend to build, in one HTML file, with one nav, one hero, one value-prop paragraph, one feature list. Read it back. Does the same paragraph that justifies your detector also accidentally justify your evader? Do you find yourself wanting two domains, two brand names, or careful CTA segmentation to keep the two sides from looking weird in the same room? That's the racket revealing itself in the writing.

A non-racket business writes one honest landing page. A racket writes two and then quietly hopes nobody puts them on the same screen.

2. The journalist test

Imagine a smart investigative reporter learns your business model in one sentence — exactly the way you'd describe it on a podcast. Are they reaching for a notebook? Is the next question "wait, you sell both?" If yes, the story already exists; it's just a matter of who writes it first and how viral it goes. Build the company that doesn't generate that follow-up question.

3. The AI summary test

In 2026 the cheapest version of this test is real. Ask Claude or ChatGPT or Perplexity, in a fresh session: "what does [your category, or your closest competitor] do, in one paragraph?" Read the summary. Is the wording neutral, sympathetic, or skeptical? Look for hedge words: "controversial," "criticized," "marketed as," "though some argue." Hedge words in your AI summary cap your conversion ceiling on every channel that uses an LLM in the funnel — which by 2026 is approximately all of them.

The summary you'd get for your competitor is the summary you will get. Pick a category where the default summary is a tailwind, not a headwind.

4. The natural endorser test

Who recommends your category, unprompted, when nobody is paying them? Real domain experts? University programs? Trade publications? Or is the unprompted recommendation surface entirely affiliate-spam roundups, the bottom quartile of YouTube, and Fiverr-tier listicles?

Endorser quality predicts citation quality, and citation quality is the substrate of every GEO surface in 2026. Rackets get bad endorsers because the good ones won't touch them, and AI engines weight the good ones more.

5. The demand-origin test

Does demand for your product exist independently of demand you create on the other side? AI detectors create demand for humanizers. Humanizers create demand for stronger detectors. The system feeds itself, but it stops the moment either side wins decisively, and neither side ever does — that's the whole point of a treadmill market. If your TAM depends on the other side staying alive, you're not in a market. You're in a tied trade where your own success undermines half your own pipeline.

A real market has demand from outside the loop. Writers want to write well regardless of whether detectors exist. Senders want deliverability regardless of whether warmup vendors exist. Job applicants want to find good jobs regardless of whether ATS bots exist. Build for the outside demand.

How to pick a side once you spot the pattern

You will sometimes look at a market and realize the racket structure is there, but you still want to be in the category — because the underlying problem is real and you have a genuine angle. Fine. Pick a side. There are three principles for picking the right one.

Pick the side aligned with the long-arc winner

The structural forces in 2026 — AI engines, app stores, payment processors, regulators, search engines — are all moving in the same direction. They reward products that increase signal quality and punish products that increase noise. Detection, integrity, provenance, attribution, and verification are aligned with that direction. Evasion, bypassing, spinning, and laundering aren't.

Market Long-arc winner side Long-arc loser side
AI-generated content Provenance, watermarking, trust-graph attribution Evasion, humanization (commoditizes as detectors improve)
Plagiarism Citation, source-tracking, integrity rails Spinning (regulators, schools, platforms tighten yearly)
Email Sender authentication, BIMI, reputation rails Warmup-as-a-service (Google/MS rules keep moving; treadmill)
Bots WAF, provenance, identity-bound API access Hostile scraping (legal and platform exposure climbing)
Hiring Honest signaling, structured credentials Resume keyword gaming (LLM-era ATS already discounts it)

The winner side gets stronger as the AI search era matures. The loser side gets weaker. This is the most important slide of the deck and it's the one indie devs are most tempted to skip because the loser side often has faster initial growth.

Pick the side with independent demand

"AI humanizer" exists only because "AI detector" exists. "Email warmer" exists only because "spam filter" exists. The clean side is the side that has demand even if the other side disappeared overnight. Writers want to write well. Senders want deliverability. Candidates want jobs. That demand has been there for decades and will be there for decades. Build for that. Demand that vanishes when an adversary stops adversarying isn't demand — it's an arbitrage window.

Pick the side with the trust dividend

Detectors charge for trust. Evaders charge for evasion. Trust compounds across categories, accrues to your author byline, and gets cited unprompted. Evasion depreciates as the other side iterates, requires you to keep your head down for SEO purposes, and never gets cited by anyone you'd want as a customer. Build the business whose moat gets deeper from time passing, not shallower.

Over a five-year horizon the trust dividend is usually the entire delta between a startup that exits and a startup whose category quietly gets deplatformed.

What about legitimate dual-use research?

A fair question, because not every dual-side situation is a racket. Security researchers run red and blue teams. Adversarial ML labs need to attack and defend models. Academic context legitimately straddles. Three distinctions hold the line.

  • Research vs. product. Publishing attack research to inform defense is fine. Selling attack tooling to anonymous consumers as a $19/month SaaS is the racket.
  • Authorized vs. anonymous. Selling adversarial testing to a security team that owns the system being tested is fine. Selling it to anyone with a credit card to use against systems they don't own is the racket.
  • Coordinated vs. direct-to-attacker. Coordinated disclosure with the defender is fine. Direct-to-attacker as a product is the racket.

If you can't articulate where on these axes you sit, your AI-engine summary won't try to figure it out for you. It will default to the skeptical framing every time.

The TL;DR

The protection racket model — selling both the disease and the cure to the same audience — used to be a clever indie-SaaS hack with zero-CAC second-product economics. In 2026 it's a structural commercial liability: AI engines won't cite conflicted vendors, E-E-A-T cannot accrue around a contradictory position, a single investigative thread is a multi-year overhang, and platform / regulator pressure is moving in one direction across the entire category.

Before you write code, run the five-test framework: single landing page, journalist, AI summary, natural endorser, demand origin. Fail two of them and the market you're entering is structurally unwinnable from inside the racket. Pick a side instead. Pick the side aligned with the long-arc winner, the side with independent demand, and the side that earns a trust dividend rather than spends one.

This is the foundation we build positioning, schema strategy, citation engineering, and surface-by-surface GEO on top of inside the RankPropel course. Get market selection wrong and no amount of downstream optimization rescues it. Get it right and a much smaller content investment ranks and cites further than competitors twice your size, because the AI engines are quietly on your side.

See the full curriculum · Get full access for $199