SaaS security and AI governance are rapidly being pulled into the same conversation. On the surface, the connection is clear. AI agents, copilots, OAuth grants, service accounts, SaaS integrations, and human and non-human identities all depend on access to enterprise applications and data, which increasingly are housed in SaaS applications. In addition, the same visibility and control gaps that have long challenged SaaS environments have also become governance gaps for AI. Yet is there a danger of moving too quickly from convergence to market category creation? Are SaaS security and AI governance becoming one durable market category, or are vendors prematurely combining two related but still distinct buyer problems under a single banner?
Why convergence makes sense
The basic logic behind convergence is strong. AI agents and SaaS applications share many of the same risk patterns: human and non-human identities, OAuth tokens and delegated access, inconsistent privilege management, integrations, configuration drift, shadow SaaS, and now shadow AI. Putting a focus on shadow AI, the Cloud Security Alliance reports that 82% of organizations have discovered shadow AI agents in the past year. If an AI copilot can read, write, summarize, or act inside a SaaS application, then its governance depends on understanding what that application can access, what data it contains, what permissions exist, and which identities are involved.
Given this, it means AI governance cannot ultimately be effective if it is detached from SaaS governance. The enterprise AI security conversation often focuses on models, prompts, data leakage, and autonomous behavior. Those are certainly important. But in many organizations, AI tools and agents will act with and within the SaaS layer. If that layer is poorly understood, AI governance will inherit the same blind spots.
The customer’s current SaaS centric reality
However, the current customer reality is less futuristic. Organizations have been deploying SaaS applications for far longer than they have been deploying AI applications and AI agents. Many still struggle with foundational SaaS security questions: Which sanctioned and unsanctioned apps are in use? Who has access to what? Which OAuth grants are risky? Where has configuration drift created exposure? Which data is shared too broadly? Which human identities are overprivileged and under authenticated? Which exposures should be remediated first?
This is where the vendor narrative can get ahead of the buyer's reality. Autonomous AI agents are coming, and in some environments, they have already arrived. But SaaS deployments are already here at most organizations, and their risks are already being exploited. For many security teams, the immediate problem is not how to govern fleets of autonomous agents. It is how to gain control over a SaaS estate that has grown faster than their security processes, identity governance, and data protection practices currently support.
Where vendors may be ahead of the market
Vendors in the SaaS security space are moving quickly to also position around AI security, agent governance, and SaaS-AI convergence. That is directionally reasonable. The emerging AI governance related risks are real, similar in many respects, and increasingly interdependent. A system that observes SaaS identities, permissions, integrations, configurations, and exposures is well placed to extend into AI application and agent governance.
Why this joint category will become sustainable
Over the longer term (only 1 to 2 years in today’s accelerated world), the category logic becomes stronger. As AI agents become operational actors inside environments dominated by SaaS applications, SaaS security tools will need to govern not only users and applications, but also AI agents, their permissions, integrations, and actions. The distinction between “SaaS activity” and “AI-driven SaaS activity” will become less meaningful when the action, permission, and data path all converge inside the same enterprise applications.
In this future, buyers will need a more complete control plane across human users, non-human identities, SaaS applications, and AI agents. The market may not be fully here yet, but it is coming.
What buyers should look for now
Buyers should separate current necessities from future needs. Near-term evaluation criteria for most should remain grounded in immediate SaaS security needs: discovery and inventory, identity and access visibility, OAuth and integration risk management, data exposure monitoring, configuration and posture management, and threat detection and response. AI governance criteria should be added, but with appropriate future leaning expectations. Buyers should ask how products discover AI agents, identify agent activity, inventory agent permissions, detect shadow AI, analyze delegated access, and monitor AI-driven SaaS behavior at runtime. Just as importantly, they should ask whether these capabilities are operational today or are part of a roadmap.
Category or capability?
SaaS security and AI governance are not yet fully one category, but they are not independent problems either. The near-term market remains anchored in SaaS security, because that is where the clearest operational pain already exists. The intermediate opportunity is to connect today’s SaaS security problems to tomorrow’s AI governance requirements in a way that matches each customer’s security maturity, AI deployment speed, and risk tolerance.
Keep an eye out for the publication of our research in this area later this year that will further refine our view of this emerging market. For a related current perspective, see the recent KuppingerCole blog, “From Shadow SaaS to Shadow AI: The Growing Security Gap No One Owns” and join us in Berlin at EIC 2026, where this topic will be discussed.