← All articles

ARTICLE · TODD KELSEY

AI Agent Wars I: Who Owns the Outcome and Permission to Act?

AI Agent Wars: two simultaneous land grabs are reshaping enterprise software.

AI-native startups are attacking the labor and workflow cost hidden inside SaaS—not merely selling cheaper software. They are replacing chunks of customer support, legal review, sales operations, procurement, IT administration, compliance and reporting with agents that can complete the work.

That changes the business model. Instead of charging for seats, these companies can charge for completed outcomes. Sierra, for example, explicitly describes outcome-based pricing: customers pay when an agent resolves the issue, not simply for access to the software.

At the same time, Microsoft and Google are building the governed control plane that regulated institutions will require before agents can act broadly.

Microsoft is assembling identity, permissions, data governance, DLP, audit, retention, eDiscovery, insider-risk controls, compliance management and agent identities through Entra and Purview.

Google is extending Workspace permissions, DLP, information-rights management, encryption and administrative controls to AI, while creating an Agent Gateway for governed access to Workspace data. Its existing HIPAA and FedRAMP High posture gives it a powerful path into healthcare, government, education and other regulated environments.

The emerging division of labor looks like this:

  • Startups own specialized execution and measurable outcomes.
  • Microsoft and Google own identity, data access, permissioning, policy and audit.
  • Existing SaaS companies caught between those layers face the greatest danger.

A startup may replace a $2 million workflow with a $300,000 agent system. But a bank, hospital or university will still insist that the agent enter through a governed doorway. That makes the hyperscaler the tollbooth—even when someone else builds the better agent.

The most vulnerable products are bloated, seat-priced workflow layers with no unique data and no defensible regulatory control plane.

Systems of record will retain leverage. Generic dashboards, routing tools, report generators and administrative interfaces are likely to be hollowed out.

The next enterprise software war may be less about who builds the best model than who owns the outcome—and who controls permission to act.

Continue to Agent Wars II → · Agent Wars III →