George Brocklehurst, VP Analyst at Gartner, published research today describing what he calls agentic arbitrage: the process by which AI agents complete enterprise tasks directly, bypassing the application interfaces that SaaS vendors built their revenue models around. The projection attached to this finding is $234 billion in enterprise application software spend at risk of displacement by 2030 — roughly 20% of the global SaaS market — as autonomous agents route around the dashboards, workflows, and seat-licensed tools that currently mediate how enterprise users interact with their data.
"Agentic AI changes the economics of software. Agentic systems deliver outcomes directly, bypassing traditional user experience-heavy applications and making the software invisible. This breaks the link between user growth and revenue growth for many enterprise software vendors."
George Brocklehurst, VP Analyst, Gartner, July 1, 2026
Every major technology publication will write the vendor disruption story: which SaaS incumbents survive, which new agentic platforms absorb their revenue, what happens to seat-license economics when agents replace the human users those licenses were priced around. That analysis is correct and the stakes for the vendors involved are real. The governance story sits underneath it and is more immediately consequential for the CISOs, compliance leads, and governance program managers whose job is to govern what enterprise software does. When critical workflows move from governed SaaS interfaces into autonomous agents operating across multiple enterprise systems, the governance surface area doesn't compress along with the software bill. It grows in every direction the agent can reach.
$234B Enterprise application software spend at risk from agentic AI by 2030. Source: Gartner, July 1, 2026.
20% Share of global enterprise SaaS spend the Gartner projection represents. The agentic displacement is not a niche risk.
31% Organizations that cannot determine whether they experienced an AI breach in the past year. HiddenLayer, 2026. That figure was measured before agentic arbitrage reached scale.
Agentic Arbitrage Removes the Human From the Interface Without Removing the Access
Traditional SaaS governance works because software is visible and human-operated. A Salesforce license appears in a procurement system. It gets tied to a named user, a cost center, and an access review schedule. When that user leaves the organization, the offboarding process revokes the license. The inventory is bounded because software required a human to operate it, and humans have employment records, access reviews, and offboarding checklists that at least theoretically surface every credential in the environment.
Agentic arbitrage disrupts that model at the foundation. An agent completing a cross-domain workflow doesn't appear as a licensed user in Salesforce, Workday, or SAP. It operates through API credentials, service accounts, or OAuth tokens. One agent touching Salesforce for customer context, Workday for compensation data, SAP for inventory levels, and a document repository for contract terms generates four credential types across four systems in the course of a single task. None of those credentials shows up in a traditional software asset management system, and none of them is covered by the human identity governance process that reviews and revokes human access.
System A
Salesforce: Customer context. Agent accesses via OAuth token. No seat license. No access review.
System B
Workday: Compensation data. Agent accesses via service account. Not in HR system. No offboarding trigger.
System C
SAP: Inventory levels. Agent accesses via API credential. No user tied to the access. No expiration.
System D
Document Repository: Contract terms. Agent accesses with shared key. Provisioned once. Never reviewed.
HiddenLayer's 2026 AI Threat Landscape Report found that 31% of organizations cannot determine whether they experienced an AI-related breach in the past twelve months. That figure reflects current AI deployments, which are still primarily human-supervised. As autonomous agent workflows replace SaaS interfaces at the scale Gartner describes, that visibility gap will get worse before it improves — and it will only improve for organizations that invest in agent-specific inventory infrastructure before those agents become load-bearing parts of the business.
The Platform That Replaces Your SaaS Stack Becomes Your Governance Exposure
Gartner identifies horizontal agentic platforms as the structural winners in the market transition it is describing — systems that orchestrate agents across multiple business domains rather than the separate SaaS applications that currently handle each function independently. These platforms are attractive to enterprise buyers for the same reason Brocklehurst's quote identifies: they deliver outcomes directly without requiring users to navigate multiple interfaces, manage multiple subscriptions, or coordinate workflows across disconnected tools.
"While this shift is posing an existential threat for vendors who are defending legacy dashboards and seat-based models, it creates a substantial revenue opportunity for vendors who are enabling and developing services and platforms to support agentic enabled cross-domain workflows."
George Brocklehurst, VP Analyst, Gartner, July 1, 2026
For governance teams, the concentration that makes these platforms commercially attractive is the same quality that creates the governance dependency. When an organization's most critical enterprise workflows run through a third-party horizontal agentic platform, that platform's governance posture becomes the organization's governance exposure. The EU AI Act's deployer obligations still fall on the organization using the platform. The Federal Reserve's SR 26-2 guidance, which instructs banking organizations to apply their own risk management practices to any tool or system outside the formal rules' scope, still applies. A vendor can absorb the workflow. The regulatory accountability doesn't transfer with it.
Brocklehurst's research also noted that better AI outcomes require systems that retain deep institutional memory and customer context over time. That institutional memory is a governance artifact with legal implications. When an agent carries customer context from a Salesforce record into a Workday compensation workflow, personal data has moved across systems through an AI intermediary. GDPR, the EU AI Act, and CCPA all impose data governance obligations on that movement regardless of whether any human initiated or approved it. Most current data governance programs track human-initiated data transfers. They have no instrumentation for agent-mediated ones.
The Core Problem
The core problem is that The Organizations That Cannot Measure Their AI Are the Same Ones Moving Workflows Into Agents They Cannot See
See, Most enterprise governance programs were designed for a world of human users operating discrete software systems. License inventories track applications. Identity governance tracks people. Access reviews ask a manager to confirm whether a named employee still needs their current permissions. Audit logs capture what happened inside individual applications. Every one of those mechanisms depends on a human as the unit of action — a person who has a job title, reports to someone, and appears in an HR system that other governance processes can read.
Agentic workflows break that assumption at the foundation. There is no human user whose access to review. There is often no single application to audit, because the workflow spans multiple systems simultaneously. The agent doesn't appear in any HR system or employment record. The workflow itself — the sequence of actions the agent took across multiple systems to complete a task — is the unit of accountability, and most organizations have no system of record for it.
Two days ago Gartner published research showing that organizations pursuing AI returns through workforce reductions are failing to see corresponding ROI improvement — in part because they have no measurement infrastructure connecting AI spend to business outcomes. Today Gartner published this projection showing that those same organizations are preparing to migrate their most consequential enterprise workflows into agentic platforms their current governance programs cannot track. The organizations that cannot measure whether their AI investments are producing outcomes are the same organizations now preparing to hand their most important workflows to agents their current governance systems cannot see. That is one problem at two different stages of the same transition, and the organizations encountering it at stage two without having solved it at stage one are in the worst position of all.
Our Take
The AI Governance Take
Gartner's vendor disruption analysis is correct. The $234 billion in SaaS spend moving to agentic platforms over the next four years will produce winners and losers in the enterprise software market, and the incumbents defending seat-license models are in a structurally weaker position than the horizontal agentic platforms taking their place.
The governance question is quieter and more immediate. Every dollar of SaaS spend that migrates to agentic platforms creates a corresponding governance obligation that doesn't come with the platform. The agent replacing a Salesforce workflow has no built-in audit trail, no automatic compliance mapping, and no native mechanism for proving to a regulator that it operated within policy. Those belong to the organization deploying the agent — and they have to be built by that organization, using governance infrastructure that operates above whatever agentic platform is running the workflow.
The organizations best positioned when the migration is complete are the ones that built that infrastructure first: discovery that surfaces agents regardless of which systems they access; identity governance that applies the same lifecycle rigor to service accounts and OAuth tokens that it applies to human users; runtime enforcement that operates on agent actions rather than just on model inputs; and audit trails that capture what an agent did across every system it touched, packaged in a form that answers a regulator's specific question on a specific date. At $234 billion in displaced workflow, the cost of skipping that infrastructure is no longer a compliance risk. It is a business risk.