Why .AI and .IO took off
.AI (Anguilla) and .IO (British Indian Ocean Territory) are country-code domains that got adopted as tech-industry defaults by accident of branding — "AI" and "IO" both read as tech shorthand regardless of what the letters originally stood for. Demand followed the AI boom and the startup naming trend that made short, ambiguous TLDs feel premium instead of obscure.
The catch: they're still ccTLDs
Both are managed by their national registries, not ICANN's standard gTLD process. Anguilla can (and has) changed .AI pricing and policy unilaterally. There's no UDRP guarantee in the same form as .COM, and renewal pricing has already climbed well above traditional TLDs. Treat the underlying registry risk as real, not theoretical — a policy change at the country level is outside any registrar's control.
Where the actual opportunity is
Short, brandable .AI names in the 3-5 character range still trade at a premium and the buyer pool is genuine — funded startups need a name today, not a trademark fight in six months. Longer, generic .AI strings ("bestchatai.ai") are oversaturated; thousands were registered speculatively in 2023-2024 and most are sitting unused. The same logic applies to .IO, one cycle behind.
New gTLDs beyond .AI/.IO
.XYZ, .APP, .DEV, and .SHOP are true gTLDs (ICANN-governed, standard UDRP, predictable renewal terms) — lower risk than ccTLD speculation but also lower ceiling. .APP and .DEV enforce HTTPS at the registry level, which developer-facing brands sometimes value; that's a real differentiator, not marketing.
Bottom line
New gTLD speculation works the same as any drop-catching strategy: short + brandable + real buyer demand beats generic + long + hope. The ccTLD registry risk on .AI/.IO is the one variable traditional .COM investing doesn't have — price it in before you build a portfolio around it.