Imagine the last morning of the financial quarter. At 8:57, a finance director asks an AI agent to help close the books. The agent reads invoices, checks contracts, queries a data warehouse, opens an approval, updates the ERP system and sends a summary to management. The director never opens five of the applications that made the work possible. Yet each vendor behind them still wants to be paid. In that quiet minute, the software industry’s business model is put on trial.
This is the AI software debate in one scene. If an agent can perform the work of several people while bypassing the screens they once used, what happens to software sold by the seat? Does value migrate to the model that receives the instruction, remain with the application that owns the records, or move to the platform that controls data, permissions and execution?
The answer is not that software disappears. AI is making software easier to create while making dependable enterprise automation harder to govern. That combination is hostile to thin interfaces and simple workflow tools, but favourable to platforms that own trusted data, business state, identity, approvals, audit trails and the right to write back into critical systems. The old toll booth charged for human access. The new one will charge for governed machine work.
The false choice between AI and SaaS
The bearish case begins with something real. Generative AI has sharply reduced the cost of producing code, interfaces, reports and automations. A capable user can describe a process in ordinary language and build a serious prototype without assembling a conventional software team. Agents can also sit above existing applications, call their APIs and spare users from visiting each interface.
That weakens an old SaaS proposition: pay us because building the workflow yourself is difficult. It also threatens the relationship between customer headcount and software revenue. If an agent handles the work of ten support representatives, a vendor cannot assume that ten human seats will remain forever.
But the strongest version of the bear case confuses creating an application with operating an enterprise system. The code behind a prototype may now be cheap. The expensive part is establishing which record is true, who can change it, which approval is required, how exceptions are handled, what happens when a step fails, and how every action is reconstructed for an auditor. AI can generate a finance workflow quickly. It does not make tax rules, master data, segregation of duties, uptime obligations or legal accountability disappear.
The early productivity evidence is also more nuanced than either side admits. A field experiment covering 7,137 knowledge workers across 66 firms found that users with generative AI spent about two fewer hours on email each week, but the researchers did not detect a broader shift in the quantity or composition of their work during the study. That suggests individual efficiency can arrive before companies redesign jobs, headcount or processes around it. The economic gain is possible; its translation into company-wide margins is not automatic. See the NBER working paper.
The clean conclusion is therefore selective. AI compresses software whose value lies mainly in displaying information or making a basic workflow easier to build. It strengthens software that governs risky actions across messy organisations. The moat moves away from code creation and toward control.
The software story now sits on top of a physical AI cycle
Classic software economics were beautifully simple: write the product once, distribute it cheaply and sell another licence at very high incremental margin. Frontier AI is different. Models must be trained, served, refreshed and surrounded by accelerators, high-bandwidth memory, networking, data centres, power and cooling. The software layer is now attached to an industrial-scale capital cycle.
The Stanford AI Index 2026 estimates that global AI compute capacity grew 3.3 times per year from 2022, reaching 17.1 million H100-equivalents, and describes a buildout driven by hyperscaler data-centre expansion and demand for both training and inference. The investment question is not whether the buildout exists. It is whether enough profitable usage appears above it.
Training creates spectacular but episodic demand. Inference is the recurring economic layer. Every prompt, retrieval step, model call, database query, tool call, safety check and retry consumes resources. As agents move from answering questions to completing multi-step work, a single request becomes a chain of hidden computation.
Microsoft illustrates both the scale and the tension. In its July 2026 earnings call, it said Azure had passed $100 billion in annual revenue and Microsoft 365 Copilot had exceeded 30 million paid seats. It also expected more than $50 billion of capital expenditure in the following quarter and described ongoing work to improve model throughput and hardware efficiency. The demand signal is powerful, but so is the amount of capital required to serve it. Read the Microsoft FY26 results and call.
Falling inference costs cut both ways. They improve the gross margin of AI features and make more use cases economical. They also make it cheaper for a new agent or application to challenge an incumbent. The more interchangeable models become, the less defensible the intelligence layer is on its own. Value then migrates toward distribution, proprietary context, workflow rights, governance and cost control. If the model is swappable but the permissioned business process is not, the process owner has the stronger toll booth.
When the human user disappears the meter has to move
Per-seat pricing linked software revenue to the number of employees using a product. Agentic AI breaks that relationship. Fewer people may touch the interface even as the underlying platform performs more work. Vendors therefore need a second meter: credits, actions, assists, workflow executions, model calls or eventually business outcomes.
| Commercial model | What gets metered | Why vendors want it | What buyers fear |
|---|---|---|---|
| Per seat | Authorised human users | Predictable recurring revenue and simple procurement | Paying for licences that agents make redundant |
| Seat plus allowance | Users plus a bundled pool of AI work | Protects the subscription while opening a consumption path | Low allowances that turn ordinary adoption into overage |
| Credits or actions | Prompts, agent steps, assists or completed skills | Revenue grows with machine activity rather than headcount | Opaque conversion rates and retry loops that consume budget |
| Infrastructure consumption | Compute, storage, queries, tokens, traces or traffic | AI becomes another workload on an existing meter | Volatile bills and aggressive optimisation |
| Outcome proxy | Cases resolved, tasks completed or hours saved | Captures part of the customer’s labour saving | Disputes over quality, attribution and whether the outcome was truly delivered |
The transition is already visible. Salesforce meters Agentforce through Flex Credits, with actions drawing from a shared pool. SAP sells AI Units that can be consumed across products and mapped to requests, users, records and other metrics. Microsoft’s Copilot Credits are pooled at tenant level and vary with the complexity of a response or action. Workday Flex Credits explicitly charge for work completed rather than employee count. Atlassian’s Rovo credits meter AI interactions and access to enriched Teamwork Graph context.
This is not yet pure outcome pricing. A Salesforce action can be billed even if a wider business process ultimately fails. A Microsoft agent can consume models, runtime, context and tools before reaching its answer. Credits are mainly a way to translate variable technical consumption into something procurement can buy. The language is value-based; the meter is still largely usage-based.
That creates an AI version of FinOps. One apparently simple request may trigger retrieval, several model calls, an API action, logging, evaluation and retries. Customers will need budgets by agent, team and workflow; alerts before a balance disappears; cheaper-model routing; and cost attribution to a business outcome. Cloudflare’s AI Gateway spend controls, for example, can apply dollar budgets by model, provider or agent metadata and block or redirect traffic when a threshold is reached.
The pricing winner will not be the vendor with the cleverest name for a credit. It will be the vendor that makes the unit understandable, prevents accidental consumption and demonstrates that a pound of AI spend removed more than a pound of labour, delay, error or risk.
The real moat is governed action
A system of record stores the official state of the business. A system of action decides what happens next, applies policy, obtains approval and changes that state. AI shifts bargaining power toward whichever platform controls the second role.
If an external agent reads Salesforce data, drafts an offer elsewhere and writes only the final result back, Salesforce may retain the record while losing part of the user experience, intelligence and economic value. If the agent must execute inside SAP because that is where financial controls, master data and approval hierarchies live, SAP retains more power. The crucial distinction is not where data rests, but where authorised action must occur.
Four assets make that control point defensible. First is trusted context: the clean, permissioned history required to answer a business question correctly. Second is identity: the ability to determine which human authorised an agent and what the agent may do. Third is writeback: the right to alter a consequential record or launch a workflow. Fourth is accountability: logs, approvals, policy and rollback when automation goes wrong.
This is why enterprise incumbents are not standing still. ServiceNow’s new product tiers move from AI skills to agentic workflows and autonomous specialists, while AI Control Tower discovers, governs, observes and measures AI assets. Oracle’s Fusion Agentic Applications operate inside existing data, permissions, policies and approval hierarchies. The strategic message is the same: the application is trying to become the approved environment in which agents act, not merely the database they consult.
Open protocols such as MCP make this contest more intense. They lower the friction for agents to discover and call tools across vendors. That can enlarge the market by making enterprise automation practical, but it can also weaken proprietary interfaces. The incumbent’s defence cannot be “our API is hard to reach.” It has to be “our governed execution, context and accountability are worth paying for.”
Where the principal platforms are placing their bets
| Company or group | Inherited control point | AI-era monetisation | Central investment debate |
|---|---|---|---|
| Microsoft | Cloud, productivity, identity, developer tools and distribution | Copilot seats, pooled credits, Azure consumption and agent services | Its breadth is unmatched; the test is whether product revenue and efficiency justify extraordinary infrastructure intensity. |
| ServiceNow | Enterprise workflow, IT operations, CMDB and approvals | AI-native tiers, assists, agents and cross-vendor governance | Strong if agent sprawl increases the value of orchestration; weaker if simple workflows are rebuilt outside Now. |
| SAP | ERP process logic, master data and high-risk writeback | Bundled Joule access plus AI Units for premium usage | Probably the deepest application moat, but complex consumption can create budget resistance. |
| Salesforce | CRM data and front-office workflow | Flex Credits, conversations and agent licences | Immediate language-heavy use cases are attractive; CRM context is more portable than core ERP state. |
| Workday and Oracle | HR, finance, payroll, ERP and transactional policy | Workday credits; Oracle embeds many agents into Fusion subscriptions | Governed back-office action is durable, but different pricing strategies may reset what customers expect AI to cost. |
| Snowflake | Governed analytical data and enterprise permissions | Consumption from Cortex, agents, queries and connected workflows | Wins if models become inputs to a governed data control plane; loses leverage if hyperscalers bundle the same layer. |
| MongoDB | Live operational data and application state | Atlas compute, storage, retrieval, search and agent memory | AI application creation can drive workloads, but databases and vector search remain highly competitive. |
| Datadog | Production telemetry and observability | Infrastructure usage and billable LLM spans | Agents create more traces, cost and failure modes; customers will also optimise the telemetry bill aggressively. |
| Cloudflare | Internet traffic, edge execution and security | Workers, agent runtime, gateway services and potentially content access | A neutral traffic control point is valuable, but many AI services remain early and hyperscalers own the largest compute pools. |
| Cyber and identity | Endpoints, network policy, credentials, data and recovery | Agent security, machine identity, runtime controls and automated response | AI expands the attack surface, but vendors must prove incremental budget rather than merely relabelling existing controls. |
Enterprise suites have the safest writeback
SAP, Oracle and Workday are strongest where errors have financial, legal or operational consequences. Payroll, procurement, tax, accounting and supply-chain changes require more than a plausible answer. They require correct master data, permissions, approvals and an auditable transaction. AI may reduce the value of surrounding reports, custom extensions and consulting work, but replacing the core control environment is much harder.
The pricing tension is revealing. Workday wants to meter agent skills through credits; SAP uses a common AI currency across its suite; Oracle has promoted many Fusion AI agents as included at no additional cost. Oracle’s bundling can accelerate adoption and pressure rivals to include more intelligence in the base subscription. It can also delay proof that AI is incremental revenue. The best commercial model is not obvious yet.
Workflow platforms want to govern the digital workforce
ServiceNow’s opportunity is not that it can build a ticketing agent. Many vendors can. Its opportunity is to become the operating layer that inventories agents, connects them to business services, applies approvals and measures whether they delivered value. The more fragmented the agent estate becomes, the stronger this orchestration thesis is. The counter-risk is that Microsoft, cloud platforms and application suites each attempt to govern the same agents from their own control plane.
Salesforce has a faster route to visible automation in customer service, sales and marketing because the work is language-heavy. But it must prevent Agentforce from becoming a convenient layer on top of data that external agents can copy, analyse and selectively update. SAP’s process data is harder to move and more dangerous to change. Salesforce’s market can grow faster while its toll booth remains more contestable.
Data platforms sell context rather than the smartest model
Snowflake does not need to win the frontier-model race. Its bet is that enterprises will bring models to governed data and pay for the queries, retrieval, policy and execution around them. Snowflake now describes Intelligence and Cortex Code as parts of a control plane for the agentic enterprise. That positioning becomes stronger as customers use multiple models and treat each as replaceable.
MongoDB occupies a different layer. It is closer to the live application: user state, operational documents, retrieval and persistent agent memory. Its August 2026 releases placed embeddings, reranking and real-time context directly beside operational data. The bull case is reflexive: cheaper software creation produces more applications, and more applications produce more database workload. The bear case is that agents may default to Postgres, a cloud-native service or whichever database is easiest for their framework to provision. See MongoDB’s production AI update.
Machine activity favours usage-native infrastructure
Datadog and Cloudflare are attractive because they do not need human-seat growth to monetise AI. An autonomous service can produce more traces, logs, requests and security events than a human-operated application. Datadog’s Agent Observability traces model calls, tools, latency, cost, quality and failures, and charges on LLM spans. Its risk is not seat cannibalisation; it is that customers sample, route and retain less telemetry to control consumption.
Cloudflare can monetise the path between applications, agents, models and the public internet. AI Gateway observes and routes model calls; Workers and the Agents SDK host code and state; security products inspect traffic. Its experimental Pay Per Crawl goes further by trying to turn machine access to web content into a paid transaction. That could create a new internet toll booth, but it still depends on publishers and AI companies accepting common rules at scale.
The winners and the exposed
The strongest software exposure is not simply “companies with AI”. Every software vendor has AI features. The stronger group owns something an external agent cannot safely reproduce: regulated process logic, permissioned enterprise data, writeback rights, security policy, production telemetry or distribution embedded in daily work.
- Most defensible: mission-critical ERP, payroll, finance, identity and regulated vertical systems where a wrong action is expensive and control matters more than interface elegance.
- Strategically attractive: workflow orchestration, governed data, observability, cybersecurity and edge or gateway platforms that benefit from the volume and complexity of machine activity.
- Contestable: CRM, collaboration and horizontal productivity products with valuable context but data that can be copied or reached through open APIs.
- Most exposed: thin workflow interfaces, simple CRUD tools, basic dashboards and low-integration products whose main historical advantage was saving a customer from writing straightforward code.
Small-business software is particularly vulnerable. A smaller company has fewer legacy systems, approval layers and regulatory constraints. It may be willing to replace a narrow SaaS product with a custom AI workflow or an AI-native challenger. Large enterprises move more slowly not because they cannot generate code, but because their organisational state is distributed across contracts, permissions, committees, databases and controls.
Cybersecurity deserves a separate qualification. More agents create more machine identities, tool calls, data access and opportunities for automated mistakes. That is structurally supportive for identity, endpoint, network, data-security and recovery vendors. But risk growth does not guarantee new budget. The CISO may have to secure AI with an existing platform commitment while the board directs incremental spending toward models and infrastructure. The detailed control-point competition is covered in The AI-security land grab.
The services market is the upside and the trap
The largest long-term opportunity is not merely protecting software revenue. It is allowing software vendors to capture part of the labour and services budgets their products once enabled. Customer-service software can sell automated resolution rather than a screen for support agents. Legal software can perform document review rather than only organise documents. Finance software can reconcile transactions rather than just record them.
That expands the addressable market from tools into work. It also changes the risk. A vendor paid for a seat promises access to a product. A vendor paid for an outcome inherits more responsibility for accuracy, completion and failure. Gross margin may look less like pure software if the service requires repeated inference, human review or remediation. Outcome pricing is economically powerful only when the outcome is measurable and the cost of producing it is controlled.
The transition can therefore produce a difficult middle period. Vendors bundle AI to protect renewals, absorb inference cost before usage is monetised, and risk cannibalising seats before action revenue is material. Investors should not count every AI interaction as new revenue or every saved minute as margin. The bridge must be visible in paid attach, consumption, renewal uplift, gross margin and customer outcomes.
Five questions that decide the investment case
- Where does authorised action occur? If the vendor only stores data while another platform reasons, acts and bills, its strategic position is weaker than its retention rate may suggest.
- What exactly is the new unit of revenue? Credits, actions and assists must be translated into an intelligible business volume. A proprietary unit without a clear conversion is not pricing power.
- Who bears inference and failure cost? The vendor must show how routing, caching, smaller models and efficient infrastructure protect margin—and whether failed attempts consume customer budget.
- Can management prove the result? Useful evidence is a faster financial close, lower case-handling cost, fewer security incidents or higher conversion, not a large count of prompts.
- Can an external agent bypass the interface? Open access can expand usage, but the incumbent must retain policy, writeback, audit or unique context if it wants to retain economics.
Two additional signals matter. Watch whether AI revenue is genuinely incremental or simply bundled into a renewal, and whether customers consolidate around a vendor’s control plane or use interoperability to keep every component replaceable. The former determines near-term revenue quality; the latter determines the long-term moat.
Bottom line
AI is not ending software. It is ending the assumption that the screen, the seat and the software vendor must remain the same economic unit. The interface can move to an agent. The human user can disappear from parts of a process. Code creation can become abundant. None of that removes the need to know what is true, who is authorised, which action is allowed and how a consequential change is reversed.
The winners will turn those responsibilities into a control plane for automated work. They will combine a predictable platform commitment with metered machine activity, make the bill governable and prove that the automation created measurable value. The losers will protect a per-seat model while an agent above them captures the user, the decision and eventually the margin.
The old software industry sold tools to employees. The next one will sell trusted execution to organisations. The toll booth is not disappearing. It is moving deeper into the workflow, closer to the data, the permission and the moment an AI system is allowed to act.