AI Agents Won't Kill SaaS. But They May Kill the Seat.
A year ago, the software industry was worried that AI agents would kill SaaS.
We may have gotten the direction of the threat exactly backwards. The competitive risk may not be that your customers stop using your software because of AI. It may be that your customers want their AI agents to use your software — and you won't let them.
A LinkedIn post caught my attention this week. An executive in commercial real estate, logged into CoStar while running Claude's browser extension. Instead of his search results, he got an interstitial:
"AI Agent Activity Detected."
Disable the extension. Restart the browser. Try again.
The comments were predictable. Dinosaur. Monopolist. Ripe for disruption. That was roughly my first reaction too.
Then I read CoStar's contract, and I think something more interesting is going on.
CoStar Knows Exactly What's Coming
On July 6, 2026 — just six weeks ago — CoStar updated its License Agreement Terms and Conditions. The changes around AI are remarkably specific.
The agreement now says passcodes may not be shared with "any third-party AI services," explicitly including AI agents. It adds a broader prohibition against exposing CoStar's product to AI tools outside of CoStar's own product, including using the data as input to generative AI or retrieval-augmented generation.
This isn't dusty boilerplate written before ChatGPT existed. CoStar went into its agreement six weeks ago and deliberately closed the agent door.
But the language itself isn't the interesting part. The remedy is.
Contract drafting tells you what the drafter is actually worried about, because the remedy has to match the injury. If your fear is data theft, your remedy is termination, injunctive relief, deletion, audit. CoStar has all of those elsewhere in the agreement and doesn't hesitate to use them.
The remedy attached to the new AI-agent sentence is none of those. It's the right to increase license fees "to account for any additional users detected."
Read that again. If your agent touches the data, the consequence isn't that you get cut off. It's that you get billed — because the agent has been counted as an additional user.
That's not a data protection clause. That's a pricing clause.
And it lines up with something that's been in CoStar's agreement for years: everyone at a licensed location who benefits from the product must be a named Authorized User, regardless of how much they actually use it. Not per query. Not per session. Per beneficiary.
CoStar isn't confused about what agents are. They've already decided what an agent is worth, and the answer is: one more seat.
Agents Don't Break SaaS Economics. They Break the Proxy.
That distinction matters, because seat pricing was never sacred. It was convenient.
Human attention is finite. People work a relatively predictable number of hours. Counting the number of humans using software was a reasonably good way to approximate how much software an organization consumed. One analyst can only do so much work; add another analyst, add another seat.
Then somebody gives the first analyst an agent. Now she researches more properties, runs more analyses, monitors more markets and generates more reports without adding another human being. The agent severs the relationship between headcount and consumption — permanently, and in the direction that costs the vendor money.
From CoStar's perspective, you can see the problem clearly. One analyst with a capable agent might eventually do the work that previously required three analysts and three licenses. The better the agent gets, the worse the seat performs as a proxy for the value being consumed. Every efficiency gain the customer captures comes directly out of the seat count the vendor bills against.
So perhaps CoStar isn't being technologically naive at all. Perhaps it's just protecting the meter.
The timing supports that reading. CoStar's Q2 revenue grew 18% to $925 million — the 61st consecutive quarter of double-digit growth — and adjusted EBITDA more than doubled to $184 million. Good numbers. But net new bookings came in at $69 million, down roughly 26% year over year, and the company cut full-year revenue guidance.
Revenue growth is the past selling itself: multi-year contracts, automatic renewal, CPI escalators. Bookings are the future. When bookings decay while the contracted base still compounds, there's exactly one place left to find growth — price and seat count on the customers you already have. An agent attacks both at once.
Of course they closed the door. But there's another way to look at exactly the same phenomenon.
What if one customer with ten agents isn't a platform cannibalizer? What if it's an explosion in consumption?
The problem may not be the agent. The problem may be what you're measuring.
We Were Worried About the Opposite Problem
This question feels familiar because a year ago I was writing about whether SaaS would survive AI at all.
The argument, which Satya Nadella had put into circulation on the BG2 podcast in late 2024, made intuitive sense. A lot of SaaS is ultimately CRUD — Create, Read, Update, Delete — wrapped in a user interface and some business logic. If an AI agent can interact directly with databases and execute that logic itself, why does the user need the application?
We took it seriously. RealEstateAPI provides data infrastructure to hundreds of PropTech and FinTech companies, many of them SaaS businesses. If SaaS was facing an extinction-level event, we had a front-row seat. So we analyzed our customer base and built a framework for measuring AI resilience.
Our conclusion was different. The CRUD framework wasn't really the problem — the question was who controlled the logic. As I wrote at the time:
"If a product's intelligence is hardcoded by its developers, AI can likely replicate it. But if users can define and evolve their own logic through custom workflows, tools and services, or conditional automations, then the platform becomes more defensible."
There was a second reason we were skeptical of the extinction thesis. Good vertical SaaS contains an enormous amount of accumulated domain knowledge. A generic AI might know how to query a database. That doesn't mean it understands the trade-offs a loan officer makes when underwriting a borrower, the signals an investor uses when evaluating a distressed property, or the sequence of decisions a transaction coordinator makes to get a deal across the finish line.
Agents wouldn't eliminate those applications. They would need them.
A year later, I think we underestimated the implications of our own conclusion. Because if agents need specialized software, the next question becomes obvious:
Why wouldn't we want them using as much of it as possible?
From Blocking Agents to Recruiting Them
Software companies have three basic choices.
The first is Block — detect agents and shut them down. The second is Tolerate — let customers bring Claude or ChatGPT, authenticate it, establish permissions, and let it interact with the product.
The third interests me much more: Recruit.
Design the product from the beginning on the assumption that some of your most valuable users won't be human. Then go one step further. Don't merely let customers bring agents — give them agents.
Imagine buying a real estate investment platform and, instead of one username and a link to the documentation, receiving a team:
- Research Agent — find potential opportunities
- Underwriting Agent — analyze the economics
- Monitoring Agent — watch properties and markets for changes
- Reporting Agent — prepare investment committee materials
- Workflow Agent — move information between systems and initiate the next action
The customer can still bring Claude; open ecosystems will matter. But the software company has something Claude doesn't have on day one. It knows exactly how its own product should be used.
Think about how much money SaaS companies spend transferring that knowledge. Documentation, webinars, certification programs, customer success teams, implementation consultants, tutorial videos. All of it exists because the vendor possesses knowledge the customer doesn't: how to use the product optimally.
In an agentic world, some of that knowledge becomes executable. Instead of here is our software and 47 pages explaining how to use it, you can say: here is our software, and here is a pod of digital employees already trained to use it.
Your customer's first day no longer begins with an empty dashboard. It begins with a workforce.
And the objective changes. For twenty years we tried to maximize human adoption. In the next era, we may be trying to maximize authorized machine consumption.
CoStar Already Knows This. They're Just Doing It in One Direction.
Here's the part that convinced me the "dinosaur" reading is wrong.
CoStar is not a company that fears AI. They shipped Homes AI. They shipped Apartments.com AI in June and logged more than 500,000 AI sessions within weeks, with users averaging roughly 20 minutes per session — several times longer than non-AI users. Their CEO has told analysts they're capturing more in AI-driven cost savings than they're paying in token costs, and that they're running under budget on inference. Goldman has them tagged as an AI productivity winner.
This is one of the more aggressive AI adopters in real estate.
So look at the prohibition again. It bars exposing the product to AI tools outside of the CoStar Product. That carve-out is the entire clause.
CoStar recruits agents when it owns them and blocks them when you do.
That's not technological naivety. That's a strategic decision that AI is a product they sell rather than an interface they serve. Every argument I just made about recruiting agents, CoStar is already executing — on the consumer side, where the agent drives engagement they monetize. They simply haven't extended it to the professional side, where the agent would compress the seat count they bill.
Which means the capability isn't the constraint. The business model is.
Where I Part Company
This is where I disagree with CoStar's current approach — not because they should let Claude scrape their website indiscriminately. They shouldn't.
Data owners have legitimate interests to protect. We certainly do. We rate-limit access, restrict redistribution, monitor usage, and revoke credentials when necessary. Anyone building valuable proprietary data and letting autonomous agents run wild against it won't have valuable proprietary data for very long.
The answer isn't unrestricted agent access. It's managed agent access.
Agents should authenticate. They should carry explicit permissions. Their activity should be attributable to a customer and logged. Vendors should be able to meter it, rate-limit it, price it, and revoke it.
In other words: don't build a better bot detector. Build a bot-shaped front door — and charge appropriately for what comes through it.
The blocking approach fails on its own terms anyway. Detection at the browser session gives you exactly one bit of information — is something automated touching this page — and one bit in means one bit out. Allow or deny. There's no dial. Detection is probabilistic, so you generate false positives against paying customers doing legitimate work, which is precisely the screenshot that irritated that LinkedIn user. Enforcement is binary, so sophisticated users route around it and compliant users just eat the friction. And you get no telemetry from either. You've traded a measurable problem for an invisible one.
The Part I Have More Trouble With
One provision in the new agreement is harder to reconcile with the idea that this is simply sophisticated protection of proprietary data: the specific prohibition on using CoStar data as input to retrieval-augmented generation.
RAG isn't model training. The model doesn't absorb CoStar's database into its weights. It retrieves information the user is already authorized to access, at the moment it's needed, and reasons over it. That's much closer to reading with assistance.
Prohibiting AI-assisted reading is a different thing from prohibiting data theft. Today that distinction may seem academic. I don't think it will for long. We're approaching a world in which asking an AI to read something, compare it to something else, extract what's relevant and help you reason about it isn't a specialized activity. It's just how we read.
A data company can reasonably say 'you can't copy our database, or you can't train your model on our intellectual property, or you can't resell our data. But you may read this yourself, and the AI working on your behalf may not help you understand it' is going to be an increasingly difficult line to hold.
The Browser Is the Wrong Battlefield
There's a larger implication here for data businesses. For twenty years we competed partly on interfaces. Who has the better search, the better map, the better filters, the prettier dashboard.
Now imagine telling an agent: find every industrial property in Northern New Jersey over 100,000 square feet where rents have increased more than 15% in three years, ownership has held the asset for at least a decade, and the mortgage matures within 24 months.
If the agent can execute that request, I care considerably less about your filter panel.
The interface hasn't disappeared. It has moved. The agent is becoming the interface, and that shifts competitive advantage toward what sits underneath it — proprietary data, domain expertise, unique workflows, user-defined logic, reliable infrastructure, and the ability to expose all of it safely to machines.
Which means companies that embrace agents don't have to give away their moats. They may make those moats considerably more valuable.
SaaS Doesn't Die. But the Seat Might.
A year ago the industry was asking whether agents would kill SaaS. I don't think they will. Agents still need specialized data, domain-specific workflows, business logic, and the accumulated intelligence embedded in good vertical software.
But they will force us to rethink how we package and price access to all of it. The winners won't merely possess things agents need — they'll make those things easy for agents to consume. Eventually the smartest SaaS companies will go further: actively recruiting agents as users, optimizing for machine consumption, letting customers bring their own agents, and handing them preconfigured agents designed to extract more value from the software than a human could alone.
For decades, software companies have asked: who is authorized to access our product?
The more important question for the next decade may be: on whose behalf is the agent acting?
Answer that correctly — technically, contractually, and economically — and the economics start to look very different.
Agents may not kill SaaS. They may kill the seat.
And if software companies learn to meter what replaces it, that might be very good news for SaaS.
Disclosure: I'm the CEO of RealEstateAPI, a property data platform. We operate in adjacent territory to CoStar and have an obvious stake in how this question gets answered. Contract language is quoted from CoStar's publicly posted License Agreement Terms and Conditions effective July 6, 2026, compared against the archived February 2025 version; both are available on costar.com. Financial figures are from CoStar's Q2 2026 earnings call and public market data as of mid-August 2026.