For roughly two decades, enterprise software followed a fairly simple model. A company bought software, employees logged into it, and those employees used the software to complete their work. They clicked through menus, entered information, reviewed dashboards, moved data between systems, prepared reports, and decided what needed to happen next.
Software made the work faster and more organized, but people were still responsible for operating almost every part of the process. A customer relationship management system could tell a salesperson what was happening inside an account, but the salesperson still had to research the customer, decide on the next step, write the message, update the CRM, and follow up later. Accounting software could store transactions and produce reports, but accountants still had to investigate exceptions, reconcile records, prepare entries, and review the results.
That model created some of the largest software companies in the world. Salesforce became central to sales operations. Workday became an important system for employee data. ServiceNow organized internal business processes. Oracle, NetSuite, SAP, and hundreds of specialized SaaS companies helped move business operations from local software into the cloud.
Artificial intelligence is now beginning to challenge one of the assumptions underneath that entire model: Does a person still need to operate every step of the software?
AI agents introduce a different possibility. Instead of only giving an employee information or suggesting what to do next, software can increasingly receive a goal, gather the necessary information, use several business systems, complete actions, check the results, and involve a person only when judgment or approval is required.
That changes the role of enterprise software in a fundamental way.
Software is slowly moving from being a tool that employees operate toward becoming an active participant in the work itself.
New York could become one of the most important places to watch this transition. The city already has major enterprise-software companies such as UiPath, Datadog, MongoDB, Yext, Sprinklr, and Ramp. At the same time, a rapidly growing group of younger New York companies is developing autonomous software for accounting, investment banking, compliance, procurement, recruiting, cybersecurity, customer operations, and healthcare.
Our analysis suggests that something more important than another AI feature cycle may be starting.
SaaS is unlikely to disappear. Instead, its role is changing. The basic unit of enterprise software may gradually move away from the number of people using a product and toward the amount of useful work that the software can complete.
If that happens, the economics, design, pricing, security, and competitive structure of enterprise software could all change with it.
The Short Version: SaaS Helped Employees Do the Work, While AI Agents Are Starting to Do Parts of the Work Themselves
Traditional SaaS was largely designed to make employees more productive. An accountant received better accounting software, a salesperson received a better CRM, a recruiter received a better applicant tracking system, and a customer-service representative received a better ticketing platform.
The employee, however, remained at the center of the workflow.
A person still had to notice that something had happened, understand what it meant, decide what should happen next, move information between systems, send messages, request approvals, and confirm that the process had been completed correctly.
AI agents begin to change that operating model because they can potentially take responsibility for several connected steps instead of assisting with only one of them.
A finance agent, for example, could receive an invoice, compare it with a purchase order, check the vendor record, identify any mismatch, apply a company rule, request approval when necessary, and prepare the transaction for payment. A customer-service agent could understand a complaint, inspect the customer record, review the order, apply the company’s refund policy, issue a replacement, update the support ticket, and explain the outcome to the customer.

The important change is not that AI can generate better text. The important change is that software can begin to own a meaningful part of a business process.
That is why the move from SaaS to agents is more important than simply adding a chatbot to an existing dashboard.
NYC Tech Journal Original Research: Tracking Capital Moving Into New York’s Agentic Enterprise Software Market
To understand whether this shift is actually happening in New York, NYC Tech Journal built a new dataset specifically for this article.
We reviewed publicly announced financing events between January 1 and September 20, 2026 involving New York enterprise-software companies whose publicly described products included AI agents, autonomous execution, agentic workflows, or infrastructure designed specifically for AI agents.
We intentionally used a strict inclusion method because the term “AI agent” is now used very loosely. Including every company that mentioned AI would have produced a much larger number, but the result would have said very little about the development of autonomous enterprise software.
How We Built the Dataset
A company had to satisfy three main conditions to be included.
First, we needed credible public evidence that the company was headquartered in New York, based in New York, or running its primary enterprise-software operation from the city.
Second, its product had to serve businesses, professional teams, or enterprise workflows rather than being primarily a consumer AI application.
Third, autonomous or agentic behavior needed to be a meaningful part of the product. We did not include companies simply because they offered AI search, text generation, summarization, or a chatbot inside an existing product.
We also excluded financing rounds where the amount was not publicly disclosed, debt facilities, acquisitions, and companies whose only meaningful connection to New York was a local sales office.
Because of those restrictions, the total below should be treated as a conservative minimum rather than an estimate of every dollar entering New York’s broader AI market.
At Least $767 Million Across 18 Disclosed Financing Events
Our strict dataset identified 18 disclosed financing events across 17 New York companies, representing at least $767 million in announced capital.
The median financing event was $28.5 million, which is useful because it shows that the market is not made up only of a few extremely large rounds. There is also a significant group of younger companies raising meaningful amounts of capital to build specific enterprise workflows around autonomous software.
The location of that capital is even more revealing.
Approximately $646 million, or 84.2%, went to application-layer companies that are trying to automate or transform actual business work.
Only around $121 million, or 15.8%, went into agent infrastructure and security companies in our strict sample.
The numbers suggest that New York’s strongest position may not be in building another general-purpose foundation model. Instead, the city appears to be developing an ecosystem around applying AI to expensive, specialized business processes.
NYC Tech Journal’s 2026 Agentic Enterprise Financing Dataset
| Date | Company | Primary workflow | Layer | Disclosed financing |
| Jan. 27 | Concourse | Finance | Application | $12M |
| Jan. 28 | Rogo | Institutional finance | Application | $75M |
| Feb. 5 | Daytona | Agent execution infrastructure | Infrastructure | $24M |
| Feb. 12 | Didero | Procurement | Application | $30M |
| Feb. 24 | Basis | Accounting | Application | $100M |
| Apr. 29 | Rogo | Institutional finance | Application | $160M |
| Jun. 16 | HeyMilo | Recruiting | Application | $6M |
| Jun. 23 | Attention | Revenue operations | Application | $30M |
| Jun. 25 | Neurometric AI | Agent compute economics | Infrastructure | $4M |
| Jun. 2026 | Norm Ai | Legal and compliance | Application | $120M |
| Jul. 2 | LinqAlpha | Investment research | Application | $22M |
| Jul. 14 | Hadrius | Financial compliance | Application | $27M |
| Jul. 16 | Beacon Security | Cybersecurity agents | Infrastructure | $13M |
| Jul. 28 | Harmony | Enterprise employee service | Application | $34M |
| Jul. 30 | Assured | Healthcare operations | Application | $19M |
| Jul./Aug. | Ellis | Private-credit operations | Application | $11M |
| Sep. 1 | AIR Security | Agent security | Infrastructure | $50M |
| Sep. 9 | Cymphony | Agent identity and security | Infrastructure | $30M |
Source: NYC Tech Journal analysis of company announcements, product documentation, and public reporting available through September 20, 2026. The figures are based only on disclosed financing amounts and should therefore be considered lower-bound estimates.
Funding Arrived Throughout the Year Rather Than Through One Short-Lived Surge
One of the most interesting findings is that financing for New York agentic software did not appear during a single month or around one major announcement. Capital continued to enter the category throughout much of 2026.
Disclosed NYC Agentic Enterprise Funding by Month
January $87M █████████
February $154M ███████████████
March $0M
April $160M ████████████████
May $0M
June $160M ████████████████
July $115M ████████████
August $11M █
September $80M ████████
Total: at least $767M
The monthly pattern matters because it suggests that the category is developing across several business areas rather than being driven by one unusually large deal.
Large rounds clearly matter, but a meaningful middle tier is also emerging.
Five financing events in our sample were worth $15 million or less, while seven fell between $16 million and $30 million. Only three exceeded $75 million.
Funding Event Distribution
| Funding event size | Number of events | Capital |
| $0M–$15M | 5 | $46M |
| $16M–$30M | 7 | $182M |
| $31M–$75M | 3 | $159M |
| $76M+ | 3 | $380M |
The three largest events were Rogo’s $160 million Series D, Norm Ai’s $120 million financing, and Basis’ $100 million Series B. Together, those rounds represented roughly half of the total capital in our dataset.
However, even after removing those three events, the remaining sample still represents approximately $387 million.
That makes the New York agent market harder to dismiss as a story driven by only one or two breakout companies.
Original Finding #1: New York’s Agent Economy Is Primarily an Application Economy
The clearest result from our dataset is that capital is concentrating around companies using AI agents to perform actual business work.
Application Layer Versus Infrastructure
Application software $646M 84.2% █████████████████
Infrastructure/security $121M 15.8% ███
This distribution makes sense when viewed through New York’s existing economic strengths.
The city has deep concentrations of finance, accounting, advertising, healthcare, insurance, property, law, professional services, commerce, and enterprise operations. These industries contain complex workflows where completing the task is economically much more valuable than generating a useful paragraph of text.
A bank does not ultimately want an AI system that can describe a credit review. It wants software that can gather the information, identify concerns, prepare the analysis, document the evidence, and send unusual cases to a human.
An accounting firm does not gain enough value from software that can merely explain reconciliation. The larger opportunity comes when software can perform much of the reconciliation itself and leave the professional to investigate the exceptions.
That difference is central to New York’s opportunity.
Original Finding #2: Nearly Half of the Capital Went Into Finance, Accounting, and Investment Workflows
We also classified each financing event according to the primary business workflow addressed by the company.
The concentration around finance is striking.
Where the $767 Million Went
| Workflow group | Capital | Share of sample |
| Finance, accounting and investment workflows | $380M | 49.5% |
| Legal and compliance | $147M | 19.2% |
| Agent security | $93M | 12.1% |
| Workforce and enterprise service | $70M | 9.1% |
| Procurement and supply chain | $30M | 3.9% |
| Agent infrastructure | $28M | 3.7% |
| Healthcare operations | $19M | 2.5% |
Almost half of the capital in our dataset went into finance, accounting, or investment-related workflows.
That pattern is unlikely to be random.
New York has an unusually dense concentration of investment bankers, portfolio managers, accountants, CFOs, private-equity professionals, lawyers, compliance teams, risk specialists, and institutional investors. These people understand complicated workflows that can be difficult for a general software team to learn from the outside.
AI models are becoming widely available.
Detailed workflow knowledge is not.
New York’s Advantage May Be Workflow Density
The hardest part of enterprise AI is increasingly not getting the model to produce an intelligent answer. The difficult part is understanding everything that must happen before and after that answer.
An enterprise agent needs to know which data it can access, which system it should update, which company rule applies, which approval must happen first, what evidence should be saved, and when the agent needs to stop and involve a person.
Those questions become even more important when the software is working inside a bank, hospital, investment firm, insurer, or accounting department.
New York is full of companies where getting those details right has substantial economic value.
The Broader New York Venture Market Is Also Becoming More AI Heavy
Our dataset covers a deliberately narrow part of the market, but broader funding data points in the same direction.
AlleyWatch reported that New York City companies had raised approximately $19.09 billion across 555 deals through August 2026. In August alone, the publication classified at least 17 of 34 New York financing rounds as companies where AI played a central role in the product.
Our own strict enterprise-agent dataset represented approximately $687 million through August.

That is naturally a much smaller figure because we excluded consumer AI companies, many general automation products, foundation-model businesses, companies where AI was only a feature, and startups without a clearly agentic enterprise product.
The important point is not that every venture dollar in New York is moving toward agents.
The stronger signal is that autonomous software is appearing inside several industries where New York already has deep structural advantages.
SaaS Is Not Disappearing, but Its Job Is Changing
It is tempting to summarize the current transition by saying that SaaS is dying.
That view is too simple.
Companies will continue to need databases, systems of record, workflow engines, permissions, reporting tools, integrations, security controls, and reliable business applications.
Agents do not remove those requirements.
In many cases, they increase their importance.
What changes is the identity of the software user.
A growing share of software activity may eventually be performed by machines acting on behalf of people rather than employees manually navigating every screen.
Traditional SaaS Was Designed Around Human Navigation
Most enterprise applications are still built around a familiar pattern.
A person logs in, sees a dashboard, opens a menu, selects a record, reviews information, and decides what action to take next.
This architecture assumes that a human will be present throughout the workflow.
Agents weaken that assumption.
An AI agent does not necessarily need an attractive dashboard. It needs reliable data, clearly defined tools, permissions, memory, rules, APIs, and a safe way to take action.
As that model becomes more common, some of the most valuable parts of enterprise software may move beneath the visible interface.
The dashboard does not disappear, but its role changes.
The New Interface Is Intent
Imagine a sales leader giving software the following instruction:
“Find the 50 accounts most likely to buy this quarter, identify what changed at each company, update our CRM, prepare personalized outreach, and highlight the ten accounts that deserve my attention.”
The prompt itself is not the interesting part.
The important work begins after the request is made.
The software needs customer records, outside research, account history, permissions, company rules, an account-scoring method, CRM access, and a clear definition of what it is allowed to change without approval.
It also needs to record what happened so that someone can understand its actions later.
That is enterprise software.
The interface is simply moving from navigating menus toward expressing the desired business outcome.
Established New York Enterprise-Software Companies Are Already Adapting
This transition is not limited to early-stage startups.
Several established New York enterprise-software companies are also redesigning their products around agents, autonomous actions, machine access, and orchestration.
How Major NYC Software Companies Are Moving Into the Agent Era
| Company | Observable shift |
| UiPath | Maestro coordinates AI agents, software robots, applications, people, and data across enterprise processes. |
| Datadog | Bits Investigation can investigate production incidents, while Bits Agent Builder allows customers to create agents that work with operational data. |
| MongoDB | MongoDB is making Atlas easier for AI-agent workflows to access through managed MCP infrastructure, application connections, and permission controls. |
| Yext | Yext has expanded toward agentic marketing execution, including systems that can act on recommendations involving search, reviews, and brand data. |
| Sprinklr | Sprinklr is developing AI agents that can autonomously resolve parts of customer-service workflows while adding evaluation and governance capabilities. |
| Ramp | Ramp is building finance agents as well as identity, payment, permission, API, and MCP infrastructure for autonomous software. |
This is an important market signal.
If agents were only a temporary startup trend, we would expect young companies to talk about autonomy while established enterprise platforms continued operating almost exactly as before.
Instead, large software businesses are also changing their architectures.
That suggests the shift is happening below the marketing layer.
The New Enterprise Software Stack Has Four Main Layers
Business leaders often talk about “an AI agent” as though it were one product.
In practice, reliable autonomous software requires several connected layers.
Understanding those layers makes it easier to see where the future enterprise-software market may develop.
Layer 1: Systems of Record
The first layer looks familiar because it includes the systems businesses already depend on.
ERP platforms store financial information. CRMs contain customer records. HR systems contain employee information. Support platforms record customer issues. Data platforms hold business information.
These systems do not become useless when agents arrive.
They can become more valuable because an agent needs accurate, trusted information before it can safely take action.
Layer 2: Intelligence
The second layer is where AI models interpret information and determine what might need to happen next.
The model may read documents, classify information, compare records, identify anomalies, summarize a situation, or decide which tool should be used.
This is the layer most people think about when they hear the term artificial intelligence.
However, enterprise value often depends on what happens after the model reaches a conclusion.
Layer 3: Execution
Execution is where software turns reasoning into action.
The agent might update a CRM record, send an email, create a purchase order, open a support ticket, prepare a journal entry, request missing documentation, or trigger an external application.
Once AI moves from suggesting an action to actually carrying it out, the economic value can increase dramatically.
The risk also increases at the same time.
Layer 4: Control
The fourth layer may become one of the most important areas of enterprise software.
Companies need systems that define what the agent is allowed to do, what information it can access, how much money it can spend, when a human must approve an action, what gets logged, and what happens when confidence is low.
Businesses also need the ability to investigate what happened after an error.
The growth of agent-security companies in our dataset suggests that investors already recognize this need.
New York could therefore develop two major software markets at once: products that allow agents to perform business work and infrastructure that allows companies to control those agents safely.
Enterprise Software Could Move From Seat-Based Economics Toward Work-Based Economics
Traditional SaaS pricing developed around the concept of seats.
If 500 employees needed a system, the business usually bought something close to 500 licenses.
AI agents make that model less straightforward.
One agent may be able to perform work that previously moved through several employees and multiple software applications.
As a result, customers may gradually care less about how many people log into a product and more about how much useful work the software completes.
How the Economic Model Could Change
| Traditional SaaS question | Agent-era question |
| How many users need access? | How much work should software complete? |
| How many seats are active? | How many workflows are resolved? |
| How often is the product opened? | How reliably is the work finished? |
| How much time is spent in the app? | How much human effort is safely removed? |
| How many features are used? | Which business outcomes improved? |
| What is the cost per seat? | What is the cost per completed workflow? |
| Did employees adopt the product? | Did the agent produce correct outcomes? |
This change creates a difficult strategic question for SaaS companies.
Traditional product teams usually want customers to spend more time inside the application because engagement suggests the product is being used.
Agentic software may reverse that logic in some cases.
The best user experience may be one where the employee rarely needs to open the software because the work is already being completed correctly in the background.
Original Finding #3: Most Capital Is Flowing Toward High-Stakes Workflows
Our dataset reveals another important pattern.
When finance and accounting, legal and compliance, agent security, and healthcare operations are grouped together, approximately $639 million of the $767 million sample falls into areas where mistakes can produce serious financial, regulatory, security, or operational consequences.
That is more than 80% of the capital in the dataset.
The categories are our own analytical framework rather than a standard industry classification, but the overall pattern is still meaningful.
New York’s agent market is not developing only around low-risk writing tools.
Capital is moving toward areas where software will eventually need to become reliable enough to handle meaningful business responsibility.
Reliability May Become a More Important Moat Than Raw Intelligence
AI models will continue to improve, and access to powerful models will likely become more widely available.
That could make the model itself less differentiated over time.
The harder advantage may come from everything surrounding the model: proprietary workflow knowledge, clean data, evaluation systems, human-approval rules, integration depth, audit trails, exception handling, security, and customer-specific operating history.
An agent that can produce an impressive answer is useful.
An agent that a bank, hospital, accounting firm, or global enterprise trusts to complete a critical workflow is much more valuable.
Finance May Become New York’s First Large Agent-Native Software Market
Nearly half of the capital in our strict dataset went into finance, accounting, and investment workflows.
The reason becomes easier to understand when the nature of financial work is examined.
Finance combines structured data with repeated judgment. Employees spend enormous amounts of time gathering information, checking documents, comparing records, applying policies, preparing analysis, and escalating unusual situations.
That creates a strong environment for agentic software.
Rogo Is Moving Beyond Search Toward Workflow Execution
Rogo raised a $75 million Series C in January 2026 and another $160 million Series D in April.
The company serves investment banks, asset managers, and private-equity firms, and its product development has increasingly moved toward agentic financial workflows rather than simple information retrieval.
That distinction matters because search improves one part of the analyst’s job, while agentic workflows can potentially change how a much larger part of the job is performed.
Financial institutions are increasingly looking beyond software that merely answers questions. They are beginning to evaluate platforms that can participate directly in the work.
Basis Is Testing Longer-Horizon Accounting Work
Basis raised $100 million in February at a reported valuation of $1.15 billion.
The company develops AI agents for accounting and has demonstrated software completing complex accounting work that involves several connected steps rather than a single prompt.
This is very different from asking an accounting chatbot to explain a rule.
If software can gather evidence, perform calculations, apply accounting logic, identify inconsistencies, and prepare work for professional review, it begins absorbing a meaningful part of the workflow.
Concourse Is Targeting the Finance Department Directly
Concourse is also developing enterprise-grade AI agents for finance teams.
Its software connects with common financial systems and is designed to perform tasks inside the existing finance stack.
The larger pattern is more important than any individual company.
The next generation of finance software is increasingly being designed around the question of what work can be delegated to software rather than what information can be displayed to the employee.
Legal and Compliance Software Could Follow a Similar Path
Law and compliance are also emerging as strong New York categories.
Norm Ai has raised significant capital around agentic legal and compliance systems in which lawyers supervise and calibrate software agents. The company has also explored models where certain legal work can be priced around outcomes rather than only hours.
Hadrius is approaching a similar problem from financial compliance, where software can monitor activity, collect evidence, identify possible issues, and direct higher-risk cases to human reviewers.
These examples matter because professional-services businesses have historically been closely tied to human labor.
If agents begin completing more of the initial research, document preparation, monitoring, and review work, the economics of those services can change.
The business may begin charging for the completed outcome instead of simply selling more professional hours.
Internal Enterprise Service Could Become a Huge Agent Market
Some of the largest enterprise-agent opportunities may initially look unremarkable.
Employees constantly ask for password resets, software access, policy explanations, equipment, purchasing approvals, HR information, expense support, and other routine internal services.
Each request is small, but large organizations may process thousands of them every week.
Harmony, which raised $34 million in July, is building AI agents for internal employee services across functions such as IT, finance, HR, procurement, and legal.

The company illustrates an important point about the agent economy.
The biggest opportunity does not always come from one dramatic task. It can come from thousands of small coordination problems that collectively consume large amounts of employee time.
The SaaS Dashboard May Become a Control Room
Enterprise dashboards are unlikely to disappear, but their main purpose could change.
Instead of being the place where humans manually complete every step, the dashboard may become the place where people supervise software that is already doing much of the work.
A manager may open the interface to see which workflows are currently running, which tasks were completed, where the agent encountered an exception, and which actions require approval.
The dashboard may also show spending, confidence levels, supporting evidence, failed actions, and complete records of what happened.
That experience looks less like operating traditional software and more like supervising a digital team.
Ramp Shows What This Could Look Like
Ramp has begun developing tools that allow software agents to have their own identity, human owner, spending limits, permissions, and audit history.
It also provides ways for agents to interact with financial infrastructure through APIs and MCP-based connections.
This is important because companies already know how to govern people.
Employees have managers, spending limits, access rights, and accountability.
As software agents start taking real actions, businesses will need to recreate similar controls for machines.
Intelligence Is No Longer the Only Difficult Problem
Enterprise leaders should be cautious about confusing an impressive demonstration with a reliable production system.
UiPath surveyed 590 C-suite executives and IT professionals at companies with at least $1 billion in revenue during May and June 2026. Only 31% said AI was fully embedded across their business.
Respondents also pointed to data quality, integration, governance, and compliance as major challenges.
Those findings explain why the move from SaaS to autonomous software will not happen overnight.
The business is not simply replacing one interface with a smarter interface.
It is deciding whether software should be trusted with authority.
Permission Design Will Become a Core Product Decision
Consider a procurement agent.
Allowing the agent to research vendors may be relatively low risk.
Allowing it to request quotes may also be reasonable.
Negotiating terms creates more responsibility.
Signing a contract creates even more.
Paying a $2,000 invoice may be acceptable under certain rules, while wiring $2 million without human approval would be a completely different level of risk.
The important product question therefore becomes much broader than whether the model is intelligent.
Businesses need to decide exactly how much authority the software receives at each stage of the workflow.
That decision should be designed before the agent is placed into production.
Every Agent Needs a Clear Job Description
Before a company deploys an agent, leadership should be able to describe the agent’s job in plain language.
The organization should know what work the agent owns, which systems it can access, what data it can change, which messages it can send, what it can approve, how much it can spend, and when it must stop.
The company should also know who supervises the agent, what evidence must be saved, and what happens when the agent encounters an unusual situation.
If these questions do not have clear answers, the business probably is not ready to automate the full workflow.
That does not mean the project should stop.
It means autonomy should begin at a lower level.
What New York Companies Should Automate First
The best first agent is rarely the most impressive demonstration.
The better starting point is usually a workflow that is expensive, repeated frequently, measurable, and reasonably constrained.
A strong candidate usually has a clear beginning, recognizable inputs, and a clear definition of success. It should occur often enough for improvements to matter, and it should involve enough manual coordination that automation can create a measurable economic benefit.
Errors should also be detectable, while difficult situations should still be easy to send to a person.
Accounts-payable review often fits these conditions.
So do IT requests, controlled customer refunds, document collection, sales research, compliance monitoring, procurement, and healthcare administrative work.
The industries are different, but the structure of the opportunity is similar.
Each workflow contains several small decisions and handoffs that software can increasingly absorb.
Stop Measuring AI Adoption by Logins
One of the biggest mistakes companies can make is applying old SaaS metrics to agentic software.
Traditional enterprise-software teams frequently measure adoption through activation, weekly users, session counts, feature usage, and time spent in the application.
Those metrics become less useful when the software itself is performing the work.
A company should care much more about whether the workflow was completed correctly.
A Better Agent KPI Dashboard
| Metric | What it measures |
| Workflows started | How much work is actually being delegated |
| Workflows completed | Whether the agent reaches the intended outcome |
| Straight-through completion rate | Share completed without human intervention |
| Human escalation rate | How often judgment is still required |
| Exception rate | Frequency of cases that fall outside the normal process |
| Correction rate | How often employees must repair agent work |
| Cost per completed workflow | Whether the economics are improving |
| Median completion time | Whether the process is becoming faster |
| Approval latency | Whether human review has become a bottleneck |
| Material error rate | Whether increased autonomy is creating business risk |
| Evidence completeness | Whether actions can be audited later |
| Business outcome | Whether revenue, cost, risk, or service actually improved |
The most important question is therefore not how many employees used the AI system.
The better question is how much useful work the system completed correctly.
A Practical 90-Day Agent Deployment Plan
Companies do not need to rebuild their technology stack around agents all at once.
A safer and more useful approach is to choose one workflow, establish a baseline, and increase autonomy gradually.
Days 1–30: Map the Workflow Before Buying More Technology
Begin by selecting one important process and documenting how it actually works.
Do not map only the ideal version described in a process manual.
Study the exceptions.
Look for the spreadsheet sitting between two enterprise systems. Find the email an employee sends because the existing application cannot handle a strange case. Identify where information is copied manually from one screen to another.
Those hidden steps often contain the best automation opportunities.
The business should also establish a baseline before introducing AI. Measure current processing time, employee hours, error rates, cost per workflow, and exception rates.
Without a baseline, almost any AI pilot can be presented as successful because there is nothing meaningful to compare it with.
Days 31–60: Let the Agent Observe Before It Acts
The next stage should focus on evaluation rather than autonomy.
Allow the agent to review real cases and recommend what it would have done.
Then compare those recommendations with the actions taken by experienced employees.
The goal is to identify disagreements, edge cases, and failure patterns.
Businesses should collect difficult real-world examples and use them as an evaluation set.
A successful pilot should not prove that the AI looks clever.
It should show where the system is reliable and where it is not.
Days 61–90: Increase Authority According to Risk
Once the business understands the system’s performance, it can begin granting limited authority.
Low-risk actions should come first.
The agent might collect information, prepare drafts, classify requests, or update internal records.
After performance becomes predictable, the organization can consider selected external actions.
Higher-risk activities such as approving transactions, changing critical records, signing agreements, or moving money should require much stronger evidence and controls.
Autonomy should increase because the system has demonstrated reliability, not because the technology is exciting.
The Best Architecture May Combine Rules, Agents, and Humans
It is easy to imagine a future where one highly intelligent agent operates an entire company.
For many enterprise workflows, that is probably the wrong design.
Some business rules are simple and should remain deterministic.
If an invoice above a certain amount always requires a senior approval, there is little reason for a language model to reinterpret that rule every time.
Other situations require judgment.

A vendor may have changed its legal name, a contract may contain an unusual condition, or a customer’s history may justify an exception.
Those are situations where an AI agent may be useful.
The strongest architecture will often combine traditional automation, AI reasoning, and human judgment rather than trying to replace everything with one general-purpose agent.
Systems of Record May Become More Valuable Rather Than Less Valuable
Another popular argument says that agents will make existing business systems irrelevant.
The reality is likely more complex.
Agents need reliable data.
A CRM filled with duplicate accounts and missing fields does not become better because an autonomous system can access it.
It may simply allow bad information to move faster.
The same applies to accounting systems, healthcare records, procurement platforms, and HR databases.
Reliable systems of record therefore remain extremely important.
The strategic danger for SaaS companies is different.
They may continue storing the record while another product takes ownership of the workflow.
The New Competitive Question Is Who Owns the Work
Imagine a company using one CRM as its official customer database.
Historically, employees might spend several hours each day inside that application.
Now imagine another company provides an agent that can read and update the CRM while completing most of the sales workflow from somewhere else.
The CRM remains important because it contains the official customer data.
However, the agent may begin owning the relationship with the employee and the workflow itself.
That creates a new competitive question for enterprise software.
The important issue is no longer only who stores the information.
It is who controls the work that happens around the information.
SaaS Companies Need to Prepare for Software Users
Every enterprise-software company should begin asking an unusual question:
What happens when some of our most active users are no longer people?
That question changes product architecture.
The application needs reliable APIs. Agents require secure authentication. Permissions need to be narrow and easy to control. Every machine action should be traceable.
Businesses also need ways to distinguish human activity from agent activity.
Actions may need to be reversed.
Rate limits may need to account for software operating much faster than a person.
MongoDB’s move toward managed MCP access and Ramp’s work around agent identities show how established software systems are beginning to adapt to this environment.
Enterprise applications that remain difficult for machines to use could eventually lose part of the workflow to products that sit above them.
What New York Founders Should Learn From the Market
New York founders do not necessarily need to build another general-purpose AI agent.
The larger opportunity may come from becoming extremely good at one valuable workflow.
Find a process that is expensive and repeated frequently.
Learn how it works in detail.
Understand where the data lives, which systems employees use, which exceptions cause trouble, which approvals matter, and what outcome creates economic value.
Then build software that gradually performs more of that process.
Domain Knowledge May Become a Stronger Moat Than Model Access
Models will continue changing rapidly.
A startup whose only advantage is access to one particular model can lose that advantage when similar capability becomes widely available.
Workflow knowledge is much harder to replace.
A software company that deeply understands how a private-credit team reconciles information across administrators, bank accounts, servicing platforms, and spreadsheets has accumulated knowledge that cannot be replaced simply by connecting to a newer model.
The same principle applies to tax, insurance claims, healthcare administration, advertising operations, compliance, real estate, procurement, and many other New York industries.
That is one reason the city is so interesting in the agent era.
It has a large supply of people who understand expensive business processes at a very detailed level.
What Investors Should Measure Instead of the Word “Agent”
The word “agentic” is now used so frequently that it is no longer enough to describe a meaningful product advantage.
Investors should look beneath the label.
The more useful question is what the software actually does after producing an answer.
Can it take action?
How many steps can it complete?
How long can it continue working?
How many business systems can it use?
How frequently does it require human intervention?
How difficult are the exceptions?
Can the customer measure the business outcome?
Does the company report correction rates as carefully as it reports successful demos?
Does workflow data make the product better over time?
The strongest enterprise-agent business may not be the company with the most impressive demonstration.
It may be the company that quietly becomes trusted to operate an important process every day.
Security Could Become One of New York’s Biggest Agent-Era Software Markets
Agents introduce a security problem that traditional SaaS did not face in quite the same way.
A human employee can certainly make harmful decisions, but a machine may be able to take actions far more quickly and across several systems at once.
An agent can potentially access sensitive information, call external tools, execute code, move data, change records, or make financial decisions before a person realizes something has gone wrong.
That requires a different security model.
Companies such as AIR Security, Cymphony, and Beacon Security are developing products around controlling agent tools, identities, permissions, data access, and behavior.
The category could eventually become the machine equivalent of identity and access management.
Businesses spent decades learning how to control what human employees are allowed to do.
They may now need to build an equally mature system for software workers.
Agent Governance Could Become Standard Enterprise Infrastructure
Over time, large companies may maintain formal registries of every production agent operating inside the organization.
The registry could show the agent’s owner, business purpose, approved tools, accessible data, spending limit, approved models, required human approvals, current performance, evaluation history, and complete record of important actions.
That may sound overly administrative today.
Identity and access management once seemed like a specialized technical concern too.
When enough agents begin participating in normal business operations, governance will stop being treated as a special AI project.
It will become part of normal enterprise infrastructure.
How Enterprise Jobs Could Change
The most common question about agents is whether they will replace people.
That framing skips an important stage.
Long before entire occupations change, individual jobs can be redesigned around a different division of labor between humans and software.
An analyst who once spent six hours gathering information may instead spend one hour reviewing what an agent collected.
An accountant who once prepared every reconciliation may supervise several reconciliations performed by agents.
A customer-service employee may stop handling routine cases and spend more time resolving unusual situations.
Managers may begin assigning work across both people and software systems.
Managing Agents Could Become a Normal Management Skill
Employees will need to become better at defining tasks, judging evidence, reviewing outputs, and understanding how much authority software should receive.
They will also need to recognize when an agent is producing a confident but incorrect result.
This is a deeper skill than simply learning how to write a good prompt.
The employee becomes a supervisor of automated work.
That could be one of the most important changes in knowledge work over the next several years.
The Bigger Story: Enterprise Software Is Moving From Recording Work to Performing Work
The history of business software can be understood as a series of steps.
Early systems digitized business records.
Cloud software made those records easier to access and connect.
Mobile applications made enterprise software available from almost anywhere.
Generative AI made the information inside those systems easier to understand.
Agentic software adds another layer by allowing the software to act.
That increases the economic ceiling of enterprise software.
A product that helps an employee complete a $100 task can capture some of the value created by that employee.
A product that can safely perform much of the $100 task itself has a more direct relationship with the economic result.
That is why the shift matters so much.
What Could Slow the Move Toward Autonomous Software?
There are good reasons not to assume that every SaaS application will become autonomous within a few years.
Reliability remains uneven.
Enterprise data is often messy.
Legacy integrations can be difficult.
Agent costs can become unpredictable.
Security systems are still developing.
Legal responsibility can be unclear.
Companies need audit trails.
Employees may resist automation that has been introduced badly.
Customers will not accept important mistakes simply because an AI system made them.
These limitations are not minor details.
They are the central engineering and management challenges that will determine how quickly agents move from demonstrations into real enterprise operations.
The transition is therefore unlikely to happen all at once.
The more realistic story is that companies will automate individual workflows first and expand agent authority gradually as reliability improves.
Three Enterprise-Software Models Are Likely to Coexist
The market does not need to choose one single model.
Traditional SaaS, AI copilots, and autonomous agents can all exist inside the same organization.
Human-Operated SaaS
Some work will continue to be performed primarily by people.
The software will organize information and make employees more productive, but humans will remain responsible for the majority of decisions and actions.
This model will continue to make sense in many high-judgment workflows.
Copilot SaaS
The second model uses AI to support the employee without taking control of the process.
The system can summarize information, prepare drafts, search records, suggest actions, and help the employee make faster decisions.
Humans still remain the primary operator.
Agent-Operated Software
The third model gives software responsibility for a meaningful part of the workflow.
The person defines the goal and boundaries, while the agent performs many of the underlying steps.
Humans focus on approvals, exceptions, and difficult decisions.
The same enterprise-software company may eventually offer all three operating modes.
The Most Important Question for New York Business Leaders
Companies should avoid beginning their AI strategy with the question, “Where can we use AI?”
That question is so broad that it often produces disconnected pilots.
A better question is:
Which business workflow would become meaningfully better if software could safely complete more of it?
Once a workflow has been identified, leaders can examine its cost, handoffs, wait times, error rates, systems, approvals, and exceptions.
They can then decide exactly how much authority software should receive.
That approach turns AI strategy into operating strategy.
A Practical Agent Readiness Scorecard
Before investing heavily in an agent project, businesses can evaluate the target workflow against a simple set of conditions.
| Question | Weak candidate | Strong candidate |
| How often does the workflow occur? | Rarely | Frequently |
| Are the inputs identifiable? | Highly unpredictable | Mostly known |
| Can success be measured? | Mostly subjective | Clear outcome |
| Is work spread across systems? | Limited coordination | Heavy coordination |
| How much manual time is required? | Low | High |
| Can errors be detected? | Difficult | Measurable |
| Are common exceptions understood? | No | Yes |
| Can autonomy begin at low risk? | Difficult | Easy |
| Can a person review important cases? | Difficult | Easy |
| Is the economic value meaningful? | Small | Material |
A workflow should not be automated simply because an AI agent can complete a polished demonstration.
The better reason is that automation produces a measurable improvement in economics, speed, quality, or risk.
New York Could Become a Control Layer for the Autonomous Enterprise
New York does not need to dominate every layer of artificial intelligence to become one of the most important cities in the agent economy.
Its opportunity may be more specific.
The city can become a place where general AI capability is transformed into practical enterprise work.
That includes finance agents, accounting agents, compliance agents, procurement agents, legal agents, healthcare agents, sales agents, customer-service agents, and the security and governance systems needed to control all of them.
Our 2026 dataset already shows both sides of that market forming.
Application companies captured approximately 84% of the capital in our strict sample, showing strong demand for products that apply agents directly to business workflows.

At the same time, infrastructure and security companies are building the control systems required to make those applications safer and more reliable.
That combination looks increasingly like an emerging technology stack rather than a collection of isolated chatbots.
Final Takeaway: SaaS Is Becoming the Infrastructure Beneath Autonomous Work
The biggest change in enterprise software may not be a new user interface.
It may be a change in who is responsible for moving work forward.
Traditional software waits for an employee.
The employee opens the application, studies the information, decides what to do, takes the action, and moves the process to the next stage.
Agentic software begins to change that sequence by allowing the software to interpret what is happening, operate within defined limits, take selected actions, evaluate the outcome, and involve a person when necessary.
That is why the transition from SaaS to AI agents deserves more attention than another wave of AI features.
Our original New York analysis already provides meaningful evidence of the change. At least $767 million in disclosed financing moved into 18 agentic enterprise-software financing events across 17 New York companies during the period we studied. Approximately 84% of that capital went into application-layer companies, while nearly half went into finance, accounting, and investment workflows.
At the same time, established New York software companies are redesigning products around orchestration, machine permissions, agent identities, autonomous actions, MCP access, security, and governance.
None of this means SaaS disappears.
The systems of record remain important. Databases remain important. Security remains important. Integrations remain important. Reliable workflow infrastructure becomes even more important.
What changes is the amount of human effort required to operate those systems.
The enterprise-software company that succeeds in the next era may therefore be the company that stops asking only how it can help employees use software more efficiently.
The more important question will be:
How much valuable business work can the software safely, reliably, and measurably complete?



