Published on: August 5, 2026
โ€ข
7 min read

The SaaSpocalypse, and the bill nobody priced in February.

Written By

Ayush Verma

Talk to an Expert โ†’

One thing before we start.

I’ve been reading two documents side by side for a week and they don’t agree. One is a market that decided in February that software was worth a lot less. The other is a regulation published in July that says building software yourself costs more than anyone budgeted. Both are about the same question. Neither mentions the other. I think the gap between them is the most interesting thing in enterprise software right now, and almost nobody is looking at it.

– Ayush

Monday 2 February 2026. Two things happened.

Anthropic announced a new feature for Claude Cowork, its agent product for knowledge work. A plug-in for legal tasks. Reviewing contracts, drafting NDAs.

That evening, Alex Karp, CEO of the data analytics firm Palantir, got on an earnings call. He said AI had become good enough at writing and managing enterprise software that a lot of SaaS companies were about to look irrelevant.

A legal plug-in and a sentence on a call.

Within twenty-four hours, Fortune reports $285 billion off the market value of tech stocks. Software vendors hardest hit. A separate Fortune piece, filed two days after the fall, puts the figure at $300 billion and hangs it on Karp alone.

Both happened on the same Monday, and the market didn’t politely separate them.

Everyone spent that week arguing about what the software was worth. Nobody asked what the buyer was giving up.

Why the selloff was a repricing and not a panic.

Seven weeks on, software stocks were still sitting around 8% below where they’d ended January.

That’s the number worth holding. A one-day fall is a panic. A seven-week floor is a decision.

So let’s take the disruption at full strength first, because the half-conceded version of this argument is worthless.

I think seat-based pricing is finished as a durable model. If an agent does the work of four licences, you can’t keep billing for four licences. Any vendor that models revenue by multiplying headcount by seat price is missing the real value being delivered. The market saw that and repriced. On the pricing question I think it was right, and I’d rather concede that fully than argue round it.

What it did next was assume the value disappears with the seat.

Bank of America’s Vivek Arya called the selloff “internally inconsistent.” His reasoning matters more than the phrase. The trade required two mutually exclusive futures at once. AI capex deteriorating into weak returns. And AI adoption becoming so pervasive it obsoletes long-standing software business models.

You can’t hold both. (Worth noticing that Arya’s team was defending semiconductors, not software. So this is a chip analyst catching a contradiction, not a friend of SaaS.)

None of this is a new question either. Ronald Coase won a Nobel for explaining why firms exist at all. Back in 1937 he asked why a company buys anything rather than making it itself. The answer has always turned on which contracts you can write and enforce.

Oliver Hart won a Nobel of his own, for the theory of incomplete contracts. That’s the study of what happens when a contract can’t cover every eventuality. He told Fortune that vendor lock-in and exit fees might push some companies to build internally. And that he doesn’t think it’s obvious which way it goes.

Neither do I. February answered a question that’s still open by pricing one side of the ledger and calling the result a verdict.

What the licence fee does not buy.

Before going any further, let me kill the flattering version of my own argument, because it’s wrong and somebody will raise it.

The licence fee does not buy you meaningful compensation.

Enterprise software contracts routinely cap vendor liability at some multiple of fees paid. The standard remedy for a breached service level is a credit against next quarter’s invoice.

So if your CRM falls over during quarter-end close, you don’t get made whole. You get a discount on a bill you were going to pay anyway.

So the money isn’t buying insurance in the ordinary sense.

It’s buying something narrower. And until July there was no public number attached to it.

Five months later, a regulator published the bill.

On 24 July 2026, Regulation (EU) 2026/1744 appeared in the Official Journal. That’s where EU law becomes law. It came into force three days after that. The text justifies the speed as a matter of urgency, because the deadline it was amending fell on 2 August.

What it did was move the AI Act’s obligations for standalone high-risk systems to 2 December 2027. Sixteen months past the date they were due.

AI embedded in regulated products moved separately. From August 2027 to August 2028.

Now, this is one jurisdiction and one regime. Most of the software the market repriced in February is nowhere near a high-risk classification. So the point is narrower than a headline would make it.

What makes it useful, and this is why I keep coming back to it, is that a regulator was forced mid-implementation to write down why.

And they didn’t hide it. The standards weren’t ready. The national competent authorities hadn’t been established. Conformity assessment frameworks didn’t exist in most member states. The result, in the regulation’s own words, was a compliance burden heavier than expected. Maintaining the original date would have risked a significant increase in implementation costs. Costs that couldn’t be justified.

A second softening sits in the same act and makes the point twice. Article 4 originally required providers and deployers to ensure the AI literacy of their staff. It now requires them to take measures to support the development of that literacy.

The stated reason? The original obligation created additional compliance burden, particularly for smaller enterprises.

So the governance layer around AI turned out to be expensive enough to move a statutory deadline by sixteen months. And to water down a training obligation in the same breath.

That’s the first time I’ve seen anyone put a number on it. And the number came from the party with the least commercial interest in inflating it.

Who produces that layer.

A provider of a high-risk system has to generate and maintain, at minimum:

  • Technical documentation demonstrating conformity, to a specification the Act sets out in detail
  • A quality management system, documented and auditable
  • A conformity assessment, sometimes signed off by a notified body. That’s an independent auditor a member state has to designate, and it may not exist yet in your country
  • Post-market monitoring, on a plan you design and defend
  • Registration in the EU database before the system goes live
  • Data governance and bias detection practices, with the records to prove them

Buy the software and that work belongs to your vendor. Produced once, spread across every customer they have.

Build it and the same work is yours alone. Produced once, for one user, at full cost.

February priced the engineering, which AI did make cheaper. It didn’t price this, which AI didn’t touch.

The saving was real. It was booked in the wrong column.

So where is the money moving?

Watch pricing rather than commentary and you can see the first half of the shift under way. I’d been looking in the wrong place for months before I noticed it.

Take Cognition, the AI lab behind Devin. Devin is an autonomous coding agent. It plans, writes and ships software, rather than suggesting snippets to a human.

Cognition meters Devin largely in compute units. That’s a real break from headcount pricing, and a signal about where the unit of value is heading. Be precise about what it is, though. The team tier still carries a per-developer charge alongside the metering. And metered compute bills for inputs rather than outcomes.

A task that burns through units and produces nothing still bills. Cognition isn’t on the hook if the code it wrote breaks in production.

That’s the seat dying, which matters on its own terms. It isn’t yet anybody picking up the liability.

The second half hasn’t happened. Almost nobody is pricing on outcomes with real money at risk. Almost nobody is offering indemnities that would survive contact with a regulator.

Whoever fills that gap is selling something an internal build can’t match, no matter the cost. I don’t know who it’ll be. Which brings the argument back to the question the market never asked in February.

What the buyer gives up, when they stop buying, is a defendant.

Not compensation. The contract caps that to almost nothing, and I said so three sections ago. A named counterparty. An audit trail somebody else maintains. A legal address. And a commercial relationship somebody at the vendor loses if the thing fails badly enough.

When your own system fails a conformity audit, there’s no vendor to call. No contract to invoke. There’s a room with your engineers in it, and a deadline that’s already passed.

Which is the one thing AI never made cheaper. Being the party who has to answer for it.

You cannot indemnify yourself.