When $800 billion evaporated from the SaaS sector in a matter of days in February 2026, boardrooms scrambled for a name for what was happening. The one that stuck — “SaaS-pocalypse” — captured the shock but not the substance.
A GLG AI Leadership Council report, The Great SaaS Reckoning: Perspectives from the Frontlines of an Agentic Enterprise Future, gathered six technology leaders to look past the headline and map what is actually changing in enterprise software risk. Andreas Welsch, an AI leadership expert and former CMO of Business AI and VP of Product Management and GTM at SAP, contributed the report’s analysis on core-versus-peripheral software risk and how AI governance should shape buying and building decisions.
For CIOs, CTOs, and CHROs, the question is no longer whether AI changes the software stack. It is which parts of that stack now carry the risk once assumed by vendors — and what AI governance has to look like once organizations start assuming it themselves.
Original source: The Great SaaS Reckoning, GLG AI Leadership Council
Executive Summary
- AI governance requirements differ sharply between core and peripheral enterprise software.
- Embedded core systems remain resilient; peripheral tools face real build-vs-buy disruption.
- Metered, token-based billing makes cost governance a board-level discipline.
- Organizational maturity, not company size alone, determines governance readiness.
- Hands-on experience with AI building is now a leadership requirement, not optional context.
Key Takeaways
- Core SaaS applications (ERP, CRM, supply chain) stay defensible because they let organizations defer risk, complexity, and compliance burden to a vendor.
- Peripheral software — workflow and productivity tools without deep domain requirements — is where AI-driven build-vs-buy economics shift fastest.
- Replacing a vendor with an in-house or agentic alternative moves accountability for uptime, data security, and compliance onto the CIO or CTO.
- Metered, consumption-based billing is replacing per-seat pricing, and few finance functions yet have reliable usage benchmarks to forecast it.
- Early “token-maxing” missteps at companies including AWS, Microsoft, and Uber show what happens when AI usage outruns cost governance.
- Sandboxes and structured governance processes are what separate safe peripheral AI adoption from unmanaged shadow AI sprawl.
- Leaders who build something with AI themselves develop judgment that panels and vendor briefings cannot substitute for.
What is AI Governance?
AI governance is the set of policies, risk frameworks, and accountability structures an organization uses to manage how AI and agentic systems are built, deployed, and monitored. It covers data ownership and segregation, compliance with AI-specific regulatory standards, cost and usage oversight for metered AI consumption, and clear lines of accountability when a system that was previously a vendor’s responsibility becomes an internal one. As enterprises shift work from licensed SaaS seats to AI-generated and agentic alternatives, AI governance increasingly determines which build-vs-buy decisions actually pay off.
Not All Software Carries the Same Risk
Assessing a SaaS company’s exposure starts with where its software sits inside a customer’s operations, Welsch explains. Core systems that generate invoices, manage inventory, or run HR — ERP, CRM, supply chain platforms — carry a survivability advantage built on three factors: risk delegation, convenience, and the vendor’s capacity to keep innovating on top of an already-trusted foundation.
Key Insight: The software categories most exposed to AI-driven disruption are not the ones running core operations. They are the simpler, less embedded tools sitting on top of them.
Why Core SaaS Is Harder to Displace Than It Looks
Embeddedness remains a real moat. Swapping out a core system for an AI or agentic alternative saves on license cost, Welsch notes, but the full cost runs far beyond the subscription — it includes managing organizational change, not just technical change.
Replacing a vendor also shifts risk deferral back in-house. A vendor absorbs uptime guarantees, contract-backed support, and increasingly, regulatory compliance as new AI rules are published. Build it yourself, and the CIO or CTO now owns ensuring the system works as intended: no data leakage, no agents going off the rails, guardrails actually in place.
Key Insight: Building an AI alternative to a core system does not eliminate risk. It relocates that risk from a specialized vendor to the CIO’s or CTO’s own AI governance function.
Where Disruption Is Real: The Peripheral Software Layer
The layer above core systems — functional enhancements, workflow and project tools — is a different story. These applications are simpler to build and don’t require deep domain knowledge to replicate, so for organizations with capable IT and development teams, building a comparable in-house tool with AI assistance increasingly beats paying recurring subscription fees.
Peripheral tools are also less mission-critical. An imperfect homegrown version causes less disruption than a core system going down, which lowers the value of the guarantees a legacy vendor would have provided in the first place.
The Governance Gap: Organizational Maturity Determines the Calculus
Some observers argue that governance overhead flattens the distinction between core and peripheral software altogether. Welsch’s view is more nuanced: it depends heavily on organizational maturity. Enterprises that have already worked through predictive analytics, machine learning, and generative AI deployments have a real head start on agentic AI governance over organizations just starting out.
Large, well-resourced organizations can build this AI governance advantage whether they build, buy, or partner. Smaller and mid-size organizations face a widening gap between what’s technically possible and what they can responsibly maintain — a dynamic that, paradoxically, strengthens the position of large incumbent vendors serving them.
Key Insight: AI governance maturity, not headcount or budget alone, is becoming the real dividing line between organizations that can safely build their own AI alternatives and those that can’t yet.
How Leaders Should Budget and Implement AI Solutions
For any organization replacing a peripheral SaaS tool with an AI-driven alternative, the evaluation rubric has to expand. IT and procurement still need to vet data privacy and compliance, but AI risk management frameworks now belong in the same conversation: does the provider follow recognized AI risk management standards, who owns the data, how is it segregated?
Budgeting cycles need to evolve too. Most platform offerings are shifting to metered, consumption-based billing — closer to a utility bill than a fixed license. Welsch points to an early cautionary lesson: companies including AWS, Microsoft, and Uber burned through 2026 AI budgets in months after encouraging aggressive AI usage, then had to walk the approach back.
Key Insight: Token and usage budgets now require the same forecasting discipline finance teams apply to any other utility-style cost — and most organizations don’t yet have reliable benchmarks to do it well.
The implementation side matters just as much. Sandboxes and trial environments let internal users, including enterprise architects, build and test safely with company data, paired with a governance process structured enough to prevent unmanaged shadow AI sprawl.
The Case for Hands-On AI Leadership
Vendors and consultancies tend to sell their products as low-touch, particularly to C-suite audiences and investors. The reality, Welsch argues, involves more friction and a steeper learning curve than advertised — not just learning a platform, but learning how to build an agent that reliably does what it’s supposed to.
His recommendation for leaders: start coding with AI directly. Take an idea through the full lifecycle of turning it into a working application. That hands-on experience surfaces things about where the technology performs, where it falls short, and where a leader’s own proficiency is the limiting factor — insight that reading about AI or discussing it on panels no longer delivers. As Welsch puts it in the report, “The time to do that is now.”
Leadership Implications
- Separate core from peripheral before deciding to build. Apply different governance and risk-tolerance standards to systems that run the business versus tools that support it.
- Add AI risk management criteria to every vendor evaluation. Data ownership, segregation, and adherence to recognized AI risk standards now belong alongside price and features.
- Build usage forecasting discipline before scaling token-based tools. Treat metered AI billing with the same rigor as any other variable operating cost.
- Stand up sandboxes with real governance, not just access. Give teams room to build and test safely while preventing unmanaged shadow AI sprawl.
- Get hands-on personally. Leaders who have built something with AI develop judgment about adoption decisions that briefings and demos can’t provide.
Why This Matters
The SaaS market correction that triggered “SaaS-pocalypse” headlines is real, but it isn’t uniform. Treating every software category as equally exposed to agentic AI disruption leads to bad capital allocation and bad build-vs-buy calls. Welsch’s contribution to the GLG AI Leadership Council report gives enterprise leaders a more precise lens: assess exposure by embeddedness and criticality, not by category labels, and build AI governance capacity to match. That framing connects directly to the workforce transformation and enterprise AI strategy questions Welsch addresses across his broader work — where the technology choice is rarely the hard part, and the governance and people choices are.
Conclusion
The seat-based SaaS model is genuinely under pressure, but the “apocalypse” framing obscures more than it reveals. Core, embedded systems remain defensible; peripheral tools face real disruption; and the deciding factor across both is whether an organization has the AI governance maturity to responsibly own what it used to outsource. For CIOs, CTOs, and business leaders navigating the next wave of build-vs-buy decisions, AI governance is not a compliance afterthought — it is the mechanism that determines whether an AI-driven alternative actually pays off.
Related Reading
- AI Governance for Agentic AI in Enterprises — a deeper look at governance frameworks for agentic systems.
- What CIOs Can Learn from Apple’s AI Build-vs-Buy Decision — a related build-vs-buy case study.
- De-Risking the Geopolitical Effects in Your AI Stack with a Multi-Vendor Strategy — on managing vendor and supply-chain risk in the AI stack.
- AI Leadership: Finance Data, Tokens, Metacognition — more on token budgets and AI cost governance.
Frequently Asked Questions
What is AI governance in the context of enterprise software?
AI governance is the set of policies and accountability structures that manage how AI and agentic systems are built, deployed, and monitored across an organization. It covers data ownership, compliance with AI risk standards, and usage cost oversight. As enterprises replace SaaS subscriptions with AI-built alternatives, AI governance shifts from a vendor responsibility to an internal one.
Why did the SaaS market lose $800 billion in value in February 2026?
Investors reacted to signs that AI would reduce the need for per-seat software licenses across the industry. A single user empowered by AI can accomplish more per seat, and organizations began building more of their own software in-house, prompting a sharp SaaS sell-off known informally as the “SaaS-pocalypse.”
Is every SaaS category equally at risk from agentic AI?
No. Core systems like ERP, CRM, and supply chain platforms remain relatively defensible because of embeddedness, risk deferral, and vendor innovation. Peripheral tools — simpler, less domain-specific workflow software — face significantly more disruption from AI-driven build-vs-buy decisions.
What makes core SaaS systems harder to replace with AI alternatives?
Core systems benefit from deep embeddedness, meaning replacement is costly and organizationally disruptive, not just technically difficult. They also let organizations defer risk, compliance, and uptime accountability to a vendor rather than absorbing it internally.
What happens to risk when a company replaces a vendor with an in-house AI system?
The accountability that a vendor previously carried — for uptime, data security, and regulatory compliance — shifts internally to the CIO or CTO. That includes ensuring the system works as intended, that no data leaks, and that AI agents operate within defined guardrails.
How should finance leaders budget for AI tools with metered pricing?
Finance leaders need to build usage forecasting discipline for token-based, consumption billing, similar to how utilities are budgeted. Early missteps at companies like AWS, Microsoft, and Uber — where aggressive AI usage outpaced budgets — show why this discipline can’t be an afterthought.
What is shadow AI sprawl and how can leaders prevent it?
Shadow AI sprawl happens when employees adopt AI and agentic tools outside any formal governance process, creating unmanaged risk. Leaders can prevent it by pairing sandboxes and trial environments with a structured governance process that allows safe experimentation without unchecked proliferation.
Does organizational size determine AI governance readiness?
Not directly. Organizational maturity — prior experience with predictive analytics, machine learning, and generative AI — matters more than size alone. Large, well-resourced organizations do have an advantage in building governance capacity, which can widen the gap for smaller organizations still starting out.
Why does Andreas Welsch recommend that leaders code with AI themselves?
Welsch argues that vendors and consultancies often undersell the friction involved in building reliable AI agents. Personally building something with AI — taking an idea through a full application lifecycle — surfaces where the technology works, where it doesn’t, and where a leader’s own skill gaps lie, in ways that panels and briefings cannot.
What should IT and procurement add to vendor evaluations for AI-driven tools?
Beyond standard data privacy and compliance checks, IT and procurement should evaluate whether a provider follows recognized AI risk management standards, who owns the data, how it’s segregated, and the vendor’s viability and runway if it’s an AI-native startup.

