Every few months, someone declares SaaS dead. This time it's AI agents, and the argument sounds convincing until you look at what kind of software actually runs a regulated business.
There's a useful distinction buried in a recent private credit newsletter (Debt Serious) that I think applies directly to security and compliance tooling: the difference between probabilistic and deterministic systems. Large language models are probabilistic. Run the same prompt twice on different days and you'll often get different answers back. Annoying if you're drafting a marketing email, sure — but survivable. It's not fine when an auditor asks why your access logs don't match your incident report.
Compliance software is deterministic by design. A control either passed or it didn't. A policy either mapped to SOC 2 CC6.1 or it didn't. Regulated buyers aren't shopping for something that's right 8 times out of 10 — they're shopping for something that's right every time, with a paper trail proving it. That requirement doesn't go away because a chatbot got good at summarizing text.
This is where the "AI will eat SaaS" narrative breaks down for our category specifically. AI is genuinely useful layered on top of a system of record — surfacing risk, drafting evidence narratives, flagging anomalies. It's much less useful trying to replace the system of record itself, because nobody wants their audit trail generated by something that might answer differently tomorrow.
That gap is the economic wedge worth paying attention to if you're building or evaluating funded B2B security and compliance products right now. The wedge isn't "we added AI." Every vendor added AI. The wedge is owning the deterministic layer — the actual record of controls, evidence, and attestations — and treating AI as a feature that makes that record faster to build and easier to trust, not a replacement for it.
It also explains something buyers in regulated markets already know intuitively: switching costs in this space are brutally high, and that's a feature, not a bug, when you're the incumbent. High Gross Revenue Retention in compliance SaaS isn't inertia. It's a signal that ripping out your control framework mid-audit cycle is a genuinely bad idea, AI hype notwithstanding.
None of this means complacency is warranted. Categories adjacent to compliance — reporting, documentation drafting, first-pass risk triage — are exactly the "probabilistic-friendly" functions that AI tools are going after first. If your product's value prop lives entirely in that zone, the pressure is real. But if your wedge is the deterministic backbone regulated companies can't function without, AI is more likely to be a demand driver than a threat.
The companies that win the next few years in this space probably won't be the ones with the flashiest AI features. They'll be the ones that correctly identified which parts of their product are the system of record — and defended that ground while everyone else got distracted arguing about whether SaaS is dead.
Top comments (0)