Get your free personalized podcast brief

We scan new podcasts and send you the top 5 insights daily.

As general SaaS growth slows, cybersecurity and vertical software are outperforming. AI agents create new security vulnerabilities, boosting demand for security products. Simultaneously, vertical applications that orchestrate domain-specific AI workflows are proving more defensible than horizontal tools.

Related Insights

The narrative that AI will kill SaaS is flawed. AI is more likely to disrupt vertical SaaS applications that are primarily workflow-based. However, horizontal platforms like Salesforce, which act as the central "system of record," become even more critical as the canonical data source for AI agents, strengthening their moat.

Just as new platforms like operating systems and cloud computing spurred independent security companies, AI is creating a need for third-party safety providers. Even with strong in-house efforts at major labs, there is a distinct market demand for specialized, external security services like those from Gray Swan.

The rapid, often unsecured adoption of AI is creating a massive, urgent need for cybersecurity solutions. This will drive a wave of consolidation in the fragmented cybersecurity market, making it a more significant long-term investment opportunity than AI itself.

Contrary to fears that AI would replace security firms, the consensus has shifted. Analysts now believe AI massively increases the surface area for vulnerabilities, compounding the need for security. This creates a multi-billion dollar opportunity for firms protecting new AI-driven attack vectors, making cyber a resilient software sector.

The threat to SaaS from AI isn't uniform. Foundational 'systems of record' like Salesforce are safe and being built upon with APIs. However, vertical SaaS tools (e.g., for surveys) are being replaced wholesale by custom AI-built solutions, justifying the concern over their declining growth and market caps.

The rapid adoption of "vibe coding" apps by employees using production data has created a new "shadow AI" attack vector. This has spurred a market for enterprise-grade platforms that "harden" these tools by adding permissions, auditing, and IT oversight, turning a security risk into a new B2B software category.

Cybersecurity is no longer separate from data and AI. As companies deploy internal AI agents, these agents generate massive amounts of log data. Securing the enterprise now requires analyzing this data at scale, effectively collapsing the cyber and data/AI markets into a single discipline.

Generative AI's positive impact on cybersecurity spending stems from three distinct drivers: it massively expands the digital "surface area" needing protection (more code, more agents), it elevates the threat environment by empowering adversaries, and it introduces new data governance and regulatory challenges.

In a world where AI agents perform tasks, the value of a SaaS product is no longer its user-friendly interface but the robustness of its APIs. The core differentiator becomes the proprietary business logic, security, and data governance embedded within the API layer.

While AI will increase cyber risk by enabling faster vulnerability scanning and generating potentially insecure code, it will also be the solution. AI agents will be needed to review code and defend systems, creating a massive new market for "agentic security" companies.