Why Some SaaS Categories Are Agent-Proof (and Which Ones Aren't)
Not every software category is going to get eaten by AI agents. The ones most exposed are thin layers of UI over a workflow an agent can just do directly. The durable ones own something an agent can't synthesize: a regulated system of record, a multi-party network, deep proprietary data, or liability nobody wants to hand to a probabilistic model. This piece maps the actual defensibility lines, why they hold, and where the "agent-proof" label is wishful thinking. The short version: agents commoditize the *doing*, but they don't commoditize the *trust*, the *data gravity*, or the *accountability* underneath it.
Table of Contents
- The Real Question Behind "Agent-Proof"
- Four Moats Agents Struggle to Cross
- The Regulated System of Record
- Multi-Party Networks and Data You Don't Own
- Liability Nobody Wants to Automate
- Physical-World Integration and Hard Workflows
- The Categories That Are Genuinely Exposed
- A Test You Can Run on Any SaaS Category
- Why "Agent-Proof" Is a Moving Target
- Insights Most People Overlook
- References
The Real Question Behind "Agent-Proof"
The phrase "agent-proof" gets thrown around like it describes a fixed property of a product. It doesn't. What people are really asking is narrower and more useful: which part of the value chain does an agent actually capture, and which part stays put?
Here's the mental model that clears most of the fog. Software historically bundled three things: a system of record (where the canonical data lives), a workflow engine (the steps you take on that data), and a presentation layer (the screens you click). Agents are extraordinarily good at the middle layer, executing multi-step workflows, and they're getting good at replacing the top layer, since a conversational agent can act instead of making you navigate a dashboard. That's the heart of the broader unbundling thesis playing out across the GaaS cluster.
But agents are weak, structurally and probably permanently, at being the system of record under regulatory or contractual conditions. A large language model is a stochastic process. It does not, by itself, hold an immutable ledger, enforce a permission boundary, or sign a contract you can sue over. When a category's value lives mostly in that bottom layer, it's far more agent-resistant than the consensus "SaaS is dead" panic suggests. When the value lives in the screens and steps, it's toast.
So "agent-proof" isn't about being immune to AI. It's about where in the stack your defensibility sits. Categories die when their moat was the UI. They survive when their moat was something agents can ride on top of but never replace.
Four Moats Agents Struggle to Cross
Across the SaaS landscape, four structural moats keep showing up in the categories that aren't getting commoditized. None of them are about having a slicker interface or more features, agents make those irrelevant fast. They're about owning something an agent has to come through you to reach.
The Regulated System of Record
The most durable SaaS categories are the ones that function as a legally meaningful book of truth. Think general ledgers, electronic health records, payroll-of-record, cap tables, KYC/AML compliance records. The defining trait is that someone is regulated based on what's in that record, and the record has to be auditable, permissioned, and stable.
An agent can read a general ledger, propose journal entries, even reconcile accounts faster than a human team. But the ledger itself, the thing an auditor inspects and a regulator holds the company accountable for, has to be deterministic, immutable, and owned by an accountable party. You can't run statutory financial reporting off a model that might hallucinate a transaction. The same logic protects payroll-of-record and EHR vendors: the agent becomes a user of the record, often the best user, but the vendor still owns the record. McKinsey's analysis of the economic potential of generative AI repeatedly lands on this distinction: AI captures task value, but the systems of record and control around regulated processes are where the durable enterprise value concentrates.
This is also why the system-of-record-versus-system-of-action framing matters so much in the agent era. Agents are systems of action. The categories that quietly become more valuable are the ones that own the record the actions get written back to.
Multi-Party Networks and Data You Don't Own
The second moat is the network. Some SaaS categories aren't valuable because of their software at all, they're valuable because they sit in the middle of a transaction between parties who don't otherwise trust each other or talk to each other. Payment rails, ad exchanges, freight and logistics marketplaces, clearing and settlement, interbank messaging, EDI between retailers and suppliers.
An agent on one side of that network can negotiate, request, and transact. But it cannot unilaterally summon the other side's participation, and it cannot recreate the trust and settlement guarantees that took the network decades to build. You can build the smartest procurement agent in the world, but if your suppliers' systems only speak to one network, your agent has to use that network. This is the same data-moat dynamic incumbents are leaning on hard right now, the data and the counterparties live behind walls the agent has to be granted access to.
The subtle point: the network effect doesn't weaken when agents arrive. If anything, it strengthens, because agents increase transaction volume across the network. The agent is a demand multiplier for the rail, not a substitute for it.
Liability Nobody Wants to Automate
This is the most underrated moat, and it's worth dwelling on. A surprising amount of SaaS value is really the sale of someone to blame. When a tax-filing platform gets your return wrong, there's an accountable corporate entity and often an accuracy guarantee. When a medical-coding or e-prescribing system produces an error, there's a liability chain. When an enterprise buys identity and access management, they're buying an auditable, certifiable control, not just convenient login.
Agents are probabilistic. The whole reliability conversation in the GaaS world exists because you can't yet point an agent at a high-stakes, legally consequential task and walk away. As the foundation labs themselves note in their guidance on building reliable agentic systems, the hard part is bounding and verifying behavior, not generating it. Until an agent vendor is willing to underwrite the outcome, to carry the insurance, sign the attestation, accept the regulatory exposure, the category that already carries that liability has a moat the agent can't cross by being smart. It has to cross it by being accountable, which is a business and legal posture, not a model capability.
This is why "agents as opex labor" reframing only goes so far in regulated work. You can replace a seat with an agent. You cannot replace a licensed auditor's signature, a notarization, or a fiduciary duty with a probability distribution, not without someone agreeing to hold the bag.
Physical-World Integration and Hard Workflows
The fourth moat is messier and less glamorous: deep integration into physical operations and idiosyncratic, hard-coded workflows. Manufacturing execution systems, point-of-sale tied to specific hardware, building management, lab information systems, telecom OSS/BSS. These categories are protected less by elegance and more by gnarliness, thousands of edge cases, hardware dependencies, certifications, and decades of accreted process logic.
Agents will absolutely automate pieces of these workflows. But the systems that orchestrate physical machines and carry safety certifications don't get displaced by a chat interface. They get augmented. The integration surface is too specific, too regulated, and too consequential-when-wrong to hand to a general-purpose agent. This is the same reason vertical SaaS in deeply operational niches tends to hold up better than horizontal SaaS, the niche knowledge is the moat, and it's encoded in places agents can't easily reach.
The Categories That Are Genuinely Exposed
To be honest about the flip side: a lot of SaaS is genuinely exposed, and pretending otherwise is how incumbents get blindsided.
The most vulnerable categories share a profile. They are horizontal, workflow-heavy, seat-priced, and thin on proprietary data or regulatory weight. Generic project management, basic CRM data entry, survey tools, simple form builders, single-purpose workflow automation, a lot of low-code "connect app A to app B" tooling, these were always presentation-and-workflow layers over data that lived somewhere else. An agent that can read the data source directly and execute the workflow conversationally doesn't need the app. The browser-agent threat makes this worse, since an agent can drive any web UI without an integration at all.
The tell is the pricing model. As covered elsewhere in this beat, when one capable agent can do the work of a ten-seat team, seat-based pricing breaks, and the categories most dependent on seat expansion for growth are the ones whose revenue model is structurally pointed at the disruption. If your expansion story is "more humans logging in," and agents reduce the number of humans logging in, the math is unkind regardless of how good your product is.
There's a useful contrarian read here from the venture side. Andreessen Horowitz's argument that AI is eating the application layer, that value migrates from rigid SaaS apps toward AI that assembles the workflow on demand, is most true exactly for these thin, horizontal categories. It's least true for the four-moat categories above. The mistake is applying the thesis uniformly. Disruption is not evenly distributed.
A Test You Can Run on Any SaaS Category
Here's a practical filter. For any SaaS category, ask four questions, and count the yeses.
- Does it own a regulated or legally-meaningful system of record? Not "store data", own the canonical, auditable, accountable record someone is regulated against.
- Does its value depend on a multi-party network or counterparties an agent can't unilaterally summon?
- Does the vendor carry liability or accountability that a buyer specifically wants not to own?
- Is it fused to physical operations, hardware, or certifications that resist a conversational interface?
Zero or one yes: that category is on the disruption path. Its defensibility was probably the UI and the workflow, both of which agents commoditize. Build an exit or a pivot.
Two or more yeses: that category is meaningfully agent-resistant. The smart move isn't to fight agents, it's to become the substrate agents run on. Open the API, sell agent access, and let agents drive volume into the moat you already own. The winners in regulated and networked categories won't be the ones that resisted agents; they'll be the ones that became the trusted rail agents have to use.
The framing flip matters: agent-resistant categories should want to be the system of record under a thousand agents. That's a better business than being one of a thousand apps a human clicks through.
Why "Agent-Proof" Is a Moving Target
A caution, because overconfidence here is its own failure mode. None of these moats are permanent in the literal sense. They're contingent on conditions that are themselves shifting.
Regulation can change, if regulators eventually certify agentic systems for specific high-stakes tasks, part of the liability moat erodes. Networks can be disintermediated if a new agent-native protocol convinces enough counterparties to switch rails. Proprietary data advantages decay if the data becomes commoditized or leaks into training sets. And "physical integration is hard" is a moat that shrinks every year as agents get better tool-use and the integration tax falls.
So the honest claim isn't "these categories are safe forever." It's "these categories are defensible for now, and the defense comes from owning trust, accountability, data gravity, and network position, not from owning the interface." The interface was never the moat. Agents are simply the technology that finally makes that obvious. Categories that confused their UI for their value are discovering the difference the hard way; categories that understood what they actually owned are, quietly, fine.
Insights Most People Overlook
-
The agent-proof categories often become more valuable, not just survive. When agents 10x the volume of actions hitting a system of record or a payment network, the rail underneath earns more, not less. Defensibility plus a volume multiplier is the best position in the whole transition, and almost nobody frames "agent-resistant" as "agent-amplified," which is what it often actually is.
-
The liability moat is the one MBAs consistently underprice. Spreadsheet analyses of disruption model features and cost. They rarely model "who gets sued when this is wrong," which is precisely the variable that protects tax, audit, clinical, legal, and compliance software. The moat isn't capability; it's the willingness to be accountable, and agent vendors are structurally reluctant to underwrite probabilistic output.
-
Vertical depth beats horizontal breadth in the agent era, a reversal of the last decade. The 2010s rewarded horizontal platforms with broad TAM. Agents invert it: horizontal-and-shallow is the most disruptable shape, while narrow-and-deep (gnarly regulated niches) is the most defended. Some "boring" vertical SaaS is better positioned than the celebrated horizontal unicorns.
-
Becoming the substrate is a strategy, not a surrender. The incumbents that win won't out-agent the agent startups. They'll publish agent-grade APIs and charge agents for access to the record and network they own, turning every competing agent into a paying customer. Resisting integration is the losing move; gatekeeping-with-a-toll is the winning one.
-
"Agent-proof" is really "agent-positioned." No category is immune. The durable question is where you sit relative to the agent, underneath it as the trusted record/rail (good), or in front of it as the UI it replaces (bad). The same company can move from one position to the other by changing what it sells, which is why this is a strategy problem, not a technology verdict.
References
More in vs SaaS
- The Browser-Agent Threat to Web SaaS: When the App Stops Being the Place You Work
- The "Thin Wrapper" Panic and What Actually Survives It
- Agents vs. Zapier: Why AI Agents Are Coming for the Workflow-Automation Incumbents
- Platform Risk: What You're Really Signing Up For When You Build Agents on a Foundation-Model Provider
- The Quiet Collapse: How AI Agents Are Eating the Low-Code/No-Code Promise