At the 24 Hours of Le Mans, multiple classes of cars compete at the same time. However, faster car classes do not make the slower classes irrelevant. They do, however, impact the overall speed, strategy, and risk profile of the entire race. LMP1 cars often pass and lap GT cars many times over, but every class is still competing, every driver still matters, and every team still must manage the same track, weather, traffic, and risk.
Something similar is happening in SaaS security
For the past five years, SaaS Security Posture Management (SSPM) has been steadily moving along the security racetrack. It emerged to solve problems created by rapid and often poorly managed SaaS application adoption: unsanctioned applications, inconsistent configurations, excessive user permissions, local accounts outside centralized identity systems, and weak visibility into who was using what, to list just some of the issues. These are not minor security issues. They reflect a fundamental loss of control as business units adopted cloud-based applications faster than IT and security teams could secure and govern them.
SSPM helped organizations regain some of that control. It provided security teams with better ways to discover SaaS applications, monitor configuration hygiene, identify risky permissions, and reduce SaaS-related identity and access weaknesses. Those requirements have not gone away. Organizations still need to know whether critical SaaS applications are configured securely, whether administrators are overprivileged, whether local accounts bypass their identity provider, and whether posture drift is creating new exposures.
But the race has changed.
The faster class of AI security and governance has now entered the track and is setting the pace for the combined new market category of SaaS Security and AI Governance. AI governance is not replacing SSPM. Rather, it is accelerating the need for a broader control plane that includes traditional SSPM but also extends well beyond it into AI.
The reason is straightforward: enterprise AI adoption is following many of the same decentralized processes that created shadow SaaS. Employees are using public AI tools directly from browsers. Business teams are enabling SaaS-native copilots. Developers are connecting AI agents into broader business workflows. Users are granting OAuth access to AI-enabled applications. Increasingly, personal agents and automation tools are being deployed without formal IT onboarding or security review.
Shadow AI is now the next phase of shadow IT
The result is that the SaaS risk surface is no longer limited to applications, configurations, and human users. It now includes embedded AI, shadow AI, AI agents, OAuth integrations, non-human identities, SaaS-to-SaaS connections, sensitive data exposure, and active threats. That is why SaaS application configuration hygiene, while still necessary, is no longer sufficient as the organizing idea for this market.

From SSPM to SaaS Security and AI Governance
Buyers now need to ask broader questions:
- Which SaaS and AI applications are in use?
- Who or what has access?
- What user permissions exist?
- What data is reachable?
- Which integrations are trusted?
- Which tokens are persistent?
- Where is risky behavior emerging?
- Where is there evidence of active threats?
AI agents raise the stakes because they can operate with delegated authority, interact across multiple systems, retrieve data, and act at machine speed. Even when an agent does not have administrative privileges, it may still have enough access to create material risk. It may summarize sensitive content, move data into another system, trigger workflows, or act through permissions granted to a user, service account, or connected application.
OAuth and SaaS-to-SaaS integrations add even more security exposures. Modern SaaS environments are surrounded by marketplace apps, automation platforms, API-driven workflows, copilots, and third-party integrations. These connections may hold tokens, inherit user permissions, synchronize sensitive data, or create indirect access paths into critical business systems. A connected application does not need to be malicious to be dangerous. It can simply be overprivileged, abandoned, poorly monitored, unsanctioned, or under the control of a threat actor.
Data exposure adds further overall enterprise risk. As AI becomes embedded into SaaS workflows, the key question is not only which application is being used. It is what data that application, model, agent, integration, or user can reach. Sensitive data can be placed into prompts, retrieved by copilots, summarized by agents, exposed through public links, or moved through automated workflows. This makes data reachability, sharing exposure, permission context, and activity monitoring central to SaaS and AI governance.
For buyers, the conclusion is not to discard SSPM requirements. It is to expand on them. SaaS discovery, configuration monitoring, and posture management remain foundational. But these now need to be complemented by identity posture, OAuth risk management, AI agent visibility, SaaS-to-SaaS integration risk, data exposure management, threat detection, remediation workflows, audit reporting, and cost governance.
In multi-class racing, the slower classes still matter, but the faster classes change the rhythm and strategy of the entire race. SSPM is still on the track. It remains a necessary class of controls. But AI governance has become the lead driver accelerating adoption of a broader SaaS Security and AI Governance market.
Stay tuned for the upcoming release of our brand-new Leadership Compass on SaaS Security and AI Governance.