The "SaaS-pocalypse" is good clickbait, but it's lazy analysis
The SaaS sector has now shed over $1 trillion in market capitalisation since the start of 2026. The iShares Expanded Tech Software ETF (NYSE: IGV) is down roughly 25% year-to-date. Salesforce (NYSE: CRM) has lost nearly 30%. Microsoft (NASDAQ: MSFT) fell 10% in a single session on what were, by any measure, solid earnings.
The market’s verdict is swift, simple, and almost unanimous: AI code agents are about to commoditise every software product on the planet, and no valuation multiple is safe.
However, this sell-off is analytically lazy. And it’s being driven, at least in part, by the very technology it fears hallucinating on its own research
When the market feeds on its own mistakes
Here’s the issue. The AI systems generating financial commentary, synthesising news flow, and powering sentiment analysis are now producing content that itself becomes the data those same systems consume. It’s a closed feedback loop with no external correction mechanism.
The numbers are striking. OpenAI’s frontier reasoning models have hallucinated in 30–50% of test scenarios. DeepSeek R1 — the model that triggered January 2025’s $589 billion Nvidia single-day wipeout, the largest dollar-loss in stock market history, carried a hallucination rate nearly four times higher than its predecessor. Markets repriced by hundreds of billions on the back of outputs from one of the least reliable AI systems available.
The SaaS sell-off of early 2026 follows an almost identical script. An AI product release triggers a social media firestorm. Sentiment algorithms flag extreme bearishness. Algorithmic trading systems act on those signals. Selling begets selling. The price move gets reported as news. That news is ingested as fresh signal. The cycle restarts. What took days in 2016 now takes minutes — and when the inputs are hallucinated, the repricing can be catastrophic and completely untethered from fundamentals (more details here).
We believe the difference this time is that investors have the opportunity to look through the noise and identify the SaaS businesses where the structural moats are not just intact, they’re actually widening.
The moat was never in the code
Let’s be clear: AI has genuinely destroyed certain competitive advantages in software. Tools like Cursor and enterprise-grade agent frameworks can replicate the majority of standard SaaS functionality within days. Traditional defences built on elegant code, polished UX, or rapid iteration cycles are under real pressure. We don’t dispute that.
But the companies being indiscriminately sold are often those whose actual protection was never in the codebase to begin with. The durable moats live outside the software entirely, in proprietary data rights, regulatory licences, institutional relationships, deep workflow embedding, and sustained frontier research. None of these can be prompt-engineered into existence.
Proprietary private data is the most powerful flywheel. Longitudinal transaction histories, sensor streams, clinical outcomes, and behavioural graphs cannot be scraped or synthesised by frontier models. Bloomberg’s terminal data, Palantir’s (NASDAQ: PLTR) government datasets, Veeva’s (NASDAQ: VEEV) pharmaceutical records — these aren’t features, they’re the product. Every new user enriches the dataset; every richer dataset sharpens the AI inside the platform.
General-purpose models simply lack the consent, the legal right, and the accumulated context to replicate this.
Regulated access and compliance are even harder to replicate. FedRAMP, ITAR, HIPAA, ASIC, CHESS, SWIFT — none of these licenses can be generated by a language model. AI can write compliant code, but it cannot sit in a three-year audit cycle with a government agency, secure institutional relationships, or accept legal liability for a breach. Switching costs in these environments routinely run into the tens of millions and span multi-year implementation timelines. That’s not a feature moat — it’s an institutional one.
Add deep workflow embedding to the mix and the picture becomes clearer still. When a SaaS platform is the system of record inside core banking, hospital EHRs, or government case management, replacement isn’t a technical decision, it’s an organisational trauma. Staff retraining, data migration, permission re-architecture, and regulatory re-certification make a rip-and-replace approach impractical, even when a cheaper AI-built alternative exists on paper.
Who has a Moat?
In this wire, we’ll highlight the names we believe are being mispriced by this sell-off. The scoring table below quantifies where we see the strongest AI-resilient positions across five dimensions: proprietary data, workflow embedding, compliance barriers, domain-specific logic, and frontier research posture.
Our two highest-conviction names are both ASX-listed, and both operating in the kind of regulated, compliance-heavy environments that make them almost impervious to AI disruption.
WiseTech Global (ASX: WTC) is the operating system for global logistics, covering approximately 80% of manufactured trade flows across 170 countries. Its customs compliance capabilities, denied-party screening tools, and government integrations took decades and deep institutional trust to build. AI cannot licence that. The company runs R&D at 34% of revenue, and critically, it’s using AI as an accelerant inside its own platform, not running from it. Agentic workflows and AI classification tools are rolling out across CargoWise in the first half of 2026. This is not a business being disrupted; it’s a business using disruption as fuel.
Technology One (ASX: TNE) tells a similar story. Its “Power of One” ERP holds IRAP PROTECTED accreditation — the highest Australian government security certification, and serves 75% of Australian and New Zealand local government councils. It achieved the world-first ISO 42001:2023 AI Management System certification, and its retention rate sits at 99% with net revenue retention above 115%. When customers are defecting from global SAP and Oracle installations to come to you, you’re not in a commoditisation story. You’re in a moat story.
Further up the global cap stack, Intuit’s financial transaction data flywheel and Salesforce’s enterprise workflow entrenchment reinforce the same thesis, the strongest non-code moat holders are using AI as a tailwind, not navigating a headwind.
AI’s Blindspot doesn’t need to be yours
Not all SaaS is equal, and blanket selling ignores this entirely. Horizontal, lightly regulated point solutions do face genuine pressure. A project management tool with no proprietary data, no compliance certifications, and no deep workflow integration is legitimately threatened by AI-native alternatives. That re-rating is justified.
But any SaaS with proprietary data rights, certified institutional integrations, workflow entrenchment, or regulatory barriers is not being disrupted, it's being fortified.
Non-code moats are the only defensible ones in an AI-saturated landscape. Regulated verticals like finance, healthcare, government — score highest precisely because their defences are legal, relational, and data-sovereign rather than technical.
The market will eventually re-rate on reality rather than on hallucinated narratives. When it does, the spread between AI-vulnerable and AI-fortified SaaS will be the widest we’ve ever seen. The sell-off today is handing patient capital a generational opportunity to buy the latter at a discount, albeit scary (guide to how to approach these markets).
The question is whether you can distinguish between the two before the machines figure out they got it wrong.
5 topics
9 stocks mentioned
1 fund mentioned