AI App Radar DACH
How are AI-built apps doing in Germany, Austria and Switzerland?
Every three months we passively scan — the way a browser would — the discoverable population of AI-built web apps with a German, Austrian or Swiss connection and publish the shares. No hostnames, no screenshots, nothing attributable to a single site: only numbers over groups of at least 20 apps, citable under CC-BY 4.0.
n = 484 discoverable AI apps with a DACH connection · run DACH 2026-09 Lauf 7 · closed on 8 September 2026
100% of the 484 scheduled targets were reachable; only reachable apps count.
0%
2 apps
86%
417 apps
13%
65 apps
What stands out
The most common findings across the whole sample. The share says how many of the n apps triggered the rule — not whether the finding holds in any individual case.
- RSC-SEC-092No CAA record99%
- RSC-SEC-003No Content-Security-Policy97%
- RSC-SEC-005No clickjacking protection90%
- RSC-ARC-005Non-existent paths answer with 20071%
- RSC-ACC-004Accessibility violations in the rendered state65%
- RSC-SCL-004No caching strategy63%
- RSC-ARC-004No canonical link45%
- RSC-SEC-087DMARC with `p=none`38%
- RSC-PRV-001Google Fonts loaded at runtime36%
- RSC-SEC-024No Referrer-Policy33%
- RSC-PRV-022Contact data in the shipped JavaScript32%
- RSC-SEC-004MIME sniffing not disabled32%
- RSC-PRV-006Data sent to third-country services29%
- RSC-SEC-093No security.txt — no contact for vulnerability reports26%
- RSC-ARC-001Content rendered client-side only24%
By platform
| Platform | Apps | Stop | Iterate | Go |
|---|---|---|---|---|
| Lovable195 apps | 195 | 0% | 81% | 19% |
| Base44133 apps | 133 | 0% | 92% | 8% |
| Bolt123 apps | 123 | 1% | 90% | 9% |
| No builder detected28 apps | 28 | 4% | 79% | 18% |
By jurisdiction
| Jurisdiction | Apps | Stop | Iterate | Go |
|---|---|---|---|---|
| Germany188 apps | 188 | 0% | 83% | 17% |
| Austria74 apps | 74 | 0% | 82% | 18% |
| Switzerland215 apps | 215 | 1% | 91% | 8% |
Groups with fewer than 20 apps are not shown — not as “0%”, but not at all. From that few rows a single app could be picked out.
Run by run
Each run is one quarter. Shares only appear once a run reaches the threshold of 20 apps; the sample changes from run to run, so trends are hints, not proof.
| Run | Closed | Apps | Reachable | Stop | Iterate | Go |
|---|---|---|---|---|---|---|
| DACH 2026-09 Lauf 34 September 2026 · 78 apps · 100% reachable | 4 September 2026 | 78 | 100% | 0% | 77% | 23% |
| DACH 2026-09 Lauf 44 September 2026 · 118 apps · 100% reachable | 4 September 2026 | 118 | 100% | 0% | 73% | 27% |
| DACH 2026-09 Lauf 78 September 2026 · 484 apps · 100% reachable | 8 September 2026 | 484 | 100% | 0% | 86% | 13% |
Methodology
The radar measures what is discoverable: apps in builder directories, on builder subdomains (such as *.lovable.app or *.bolt.host) and with a recognisable builder fingerprint, supplemented by certificate transparency logs and the Common Crawl index. Apps on their own domain without markers are under-represented. Before scanning, we check reachability and DACH connection with a single request to the start page: a .de, .at or .ch domain ending, German page language, or a link to Impressum and Datenschutz — only such apps enter the sample. The correct reading is therefore “x% of the n discoverable apps with a DACH connection”, never “x% of German Lovable apps”. Attribution to DE, AT or CH happens after the scan via domain ending and legal findings; whatever cannot be attributed counts as not attributable and serves as a control group.
The scan is passive and browser-equivalent: it loads what any browser loads when opening the site, clicks nothing, fills in no form and creates no account. The user agent names us and this page, and robots.txt is respected — anyone who excludes us there is skipped.
What is loaded
- HTML, bundles and HTTP headers
- the page in a headless browser: trackers before consent, cookies, accessibility
- publicly served source maps
- robots.txt, sitemap and linked legal pages
Never
- sensitive paths such as /.env or /.git
- backend probes — database schema, row counts, buckets
- creating accounts or testing login throttling
Only shares over groups of at least 20 apps are published. No hostname, no URL, no screenshot and no finding attributable to a single site. Internally the raw data carries a hash that never leaves the database; the target list expires 90 days after the last scan.
Before every publication the field sweep runs against a control group of well-maintained professional sites — any severe hit there is a false-alarm candidate. The last sweep (24 August 2026) found five errors in platform detection; all are fixed. The false-alarm estimate per rule is stated in the quarterly report. The numbers here are shares over a sample, not proof about any individual app.
If you do not want your domain in the radar, remove it: prove control via DNS TXT, file or meta tag — we then delete all observations and the target and exclude the domain from every future run. Without DNS access, an email is enough.
Remove your domainHow to cite
decivo AI App Radar DACH, run DACH 2026-09 Lauf 7, methodology 2026.17, decivo.de/scan/radar
Numbers and JSON are available under CC-BY 4.0. Please cite as “decivo AI App Radar DACH” with a link. Raw numbers as JSON