U.S. SMID-Cap and Global Software competitive moats in an AI-agent world Report Interpretation
Bernstein finds early evidence that AI agents deepen lock-in at customized line-of-business platforms by relying on their workflows, data and permissions. The report distinguishes protected ERP, cloud infrastructure and network-effect cybersecurity from more exposed SMB, simple CRUD and end-user productivity software.
Summary
Bernstein finds early evidence that AI agents deepen lock-in at customized line-of-business platforms by relying on their workflows, data and permissions. The report distinguishes protected ERP, cloud infrastructure and network-effect cybersecurity from more exposed SMB, simple CRUD and end-user productivity software.
- AI agents using project-management platforms reportedly consume less than 50% of the tokens, complete work faster and achieve more successful results.
- Customized workflow integration can create a large and risky switching cost to rebuild an agent on a new system.
- Network effects, regulation and deep infrastructure remain resilient moats in Bernstein's view.
- Dynamic operational data and reinforcement learning may create a new AI-era moat.
- SMB software, legacy applications, simple CRUD tools and some developer-platform advantages face greater disruption risk.
- Bernstein made no changes to models, price targets or recommendations.
Report Interpretation
Overview
This industry note reassesses how generative AI, coding agents and broader enterprise AI-agent adoption could alter competitive moats in software. Bernstein's central conclusion is that AI does not uniformly commoditize software: it may make deeply embedded line-of-business systems more valuable while weakening moats based mainly on user-interface complexity, first-mover status or feature depth.
Core views
Bernstein revisits the concern that AI agents could bypass line-of-business (LoB) applications, reduce them to passive systems of record and make replacement easier. Its early evidence points in the opposite direction. Agents need access to company-specific data, contextual knowledge, permissions, observability, security and compliance controls; they also need to store work in progress, update knowledge bases and graphs, collaborate with people and other agents, and record work in structured processes. These requirements make existing LoB systems useful operating environments for agents rather than obstacles to be bypassed. Once an organization has built an effective agent around customized workflows and interfaces, rebuilding it on another platform becomes a large and risky switching cost. The report cites AI coding-agent use as an early practical example. Agents that work directly with project-management LoB platforms such as Atlassian, Linear or GitLab reportedly use less than 50% of the tokens, take less time to complete tasks and are more likely to succeed. Because the agents also add work and knowledge back into the underlying platform, Bernstein argues that they can increase the value of the platform's records and process graph. Atlassian is viewed as especially well positioned because it already sits at the center of product-team workflows; ServiceNow could gain a similar benefit as business AI agents become more widely used. Datadog is presented as moving toward a LoB role in product and cloud operations. Bernstein separates traditional moats into resilient, evolving and weakening categories. Network effects, regulatory barriers and deep infrastructure remain strong because AI does not eliminate the need for scale, approval processes, installed sensor networks, capital expenditure or operating efficiency. In cybersecurity, CrowdStrike and SentinelOne benefit from endpoint telemetry, Palo Alto Networks and Fortinet from network-security signals, Zscaler and Cloudflare from large proxy networks, and Okta from identity signals and its developer ecosystem. The report also argues that hyperscaler and cloud-infrastructure positions remain difficult to replicate because enterprise data gravity pulls associated AI workloads toward the data. The nature of data-based moats is changing. Bernstein believes that collecting, cleaning and organizing static data has become less defensible as AI and data-cloud tools reduce those barriers. In contrast, proprietary, dynamic operating data and workflow integration become more valuable: vendors can continuously learn from customer use cases, improve workflows and train models using contextual data unavailable to startups or DIY alternatives. This data flywheel and reinforcement-learning dynamic may form a new moat. Datadog is the report's example, as learning from feature requirements can support custom, dynamic code enhancement and faster product improvement. Several traditional protections are judged weaker. Natural-language interfaces may reduce lock-in created by complex user interfaces, dashboards and feature breadth. Faster software creation through coding agents can erode first-mover and "better technology" advantages unless they are backed by another durable moat. AI may also make it easier to modernize entrenched legacy code, weakening proprietary application-development platforms. Bernstein urges caution on incumbent customer ownership, channels and brand: a shift to new AI-related buyers or budgets can create an innovator's-dilemma problem, while legacy branding can become a disadvantage if customers prioritize innovation. The report identifies the greatest disruption exposure in SMB and end-user productivity software, legacy applications and supporting infrastructure, simple CRUD applications, and application- or cloud-security functions that could become natural capabilities of coding copilots and cloud operations pipelines. Smaller organizations often use more standardized, less customizable software to accelerate implementation; Bernstein believes AI-native entrants may offer more customization and therefore challenge those products. It also sees risk for non-system-of-record, non-critical applications that fill narrow organizational gaps and are relatively easy to build or maintain. New entrants are most likely to emerge where AI creates new buyers, budgets or jobs rather than by directly displacing well-embedded LoB systems. Bernstein highlights a potential dedicated "AI-Security" role and budget within CISO organizations, new software-development workflows beyond current CI/CD bottlenecks, greenfield opportunities between existing application categories, and tools for less-critical applications. Existing vendors can retain relevance if they serve the functional system of record and innovate sufficiently. The report views ERP as the most protected enterprise application market, followed by HCM and, to a lesser extent, CRM. It reiterates SAP and Microsoft as the covered companies most likely to be AI winners; it considers Oracle's core SaaS business highly protected and expects OCI success to drive substantial upside. At the company level, Bernstein views Workday's ERP business as resilient and believes HCM demand is more sensitive to global hiring than AI, though point-solution competition requires fast innovation. It argues that CRM platform vendors are unlikely to be displaced even as it questions their ability to capture AI-driven value. HubSpot's broad marketing, service and sales suite is presented as a counterargument to fears that SMB customers will rapidly move to AI-native or self-built applications. For Salesforce, potential Agentforce revenue upside could offset some AI pressure, but Bernstein highlights uncertainty around M&A appetite and whether AI changes the user experience and value proposition in favor of Anthropic. GitLab is characterized as having a weaker, narrower DevOps moat, while Zoom is viewed as relatively stable in market share but constrained by well-funded competitors and limited pricing power.
Analysis framework
Bernstein evaluates software moats by asking whether AI agents reduce or increase switching costs, then tests that logic against early agent-use examples and company-specific product positions. It classifies moats by durability—network effects, regulation, infrastructure, workflow integration, data, product depth and first-mover advantage—and maps likely effects across enterprise applications, cybersecurity, cloud operations and SMB software.
Methodology notes
Competitive-moat analysis
The report compares which sources of competitive advantage remain durable, evolve or weaken as AI agents change software development, adoption and workflow execution.
Workflow and system-of-record positioning
Bernstein examines where vendors sit in customer workflows, data flows, permissions and operational processes to judge whether AI agents reinforce or bypass their role.
Data flywheel and reinforcement learning
The report describes how access to continuous customer operating data can improve models and workflows over time, making it harder for new entrants without comparable data or customer relationships to catch up.
Asset mapping & comparison
Structured mapping from thesis to named assets (strengths, weaknesses, peers, risks).
- Atlassian (TEAM)Line-of-business platform for product teams that can benefit from AI coding-agent adoption.
- Strengths
- Strong point of control in product-team workflows; agents are already showing a preference to work on its platform.
- Comparison
- Viewed as earlier in realizing the LoB-agent benefit than ServiceNow.
- Risks
- Underlying CI/CD tools and team roles can evolve, requiring continued adaptation.
- ServiceNow (NOW)Line-of-business software expected to benefit as business AI-agent use expands.
- Strengths
- Embedded workflow position can support agent integration and switching costs.
- Weaknesses
- Benefit may emerge later than at Atlassian.
- Comparison
- Compared with Atlassian as another example of the LoB moat.
- Datadog (DDOG)Example of an evolving data and workflow-integration moat.
- Strengths
- Dynamic real-time data flywheel and product velocity reinforce its position.
- Comparison
- The report argues its data-driven product velocity is even more important than conventional network effects.
- CrowdStrike (CRWD), SentinelOne (S), Palo Alto Networks (PANW), Fortinet (FTNT)Cybersecurity vendors supported by deployed endpoint or network-security signals.
- Strengths
- Large sensor networks create valuable intrusion-detection and response data.
- Comparison
- Their core businesses are viewed as relatively protected from AI displacement.
- SAP (SAP), Microsoft (MSFT)Bernstein's covered companies most likely to be AI winners.
- Strengths
- SAP benefits from ERP's protected system-of-record role; Microsoft is positioned across deep infrastructure and software ecosystems.
- Comparison
- Both are preferred over more exposed software categories.
- Oracle (ORCL)Protected core SaaS business with OCI as an upside driver.
- Strengths
- Bernstein views core SaaS as highly protected.
- Comparison
- ERP and infrastructure-linked positions are viewed as more protected than less embedded application categories.
- Risks
- OCI execution is central to the report's upside thesis.
- GitLab (GTLB)Narrower DevOps use case with a weaker moat setup.
- Strengths
- Existing strategic position in developer operations.
- Weaknesses
- Potential AI-lab and open-source competition could erode its value proposition.
- Comparison
- Viewed as less protected than workflow platforms such as Atlassian.
- Risks
- A leading AI lab could offer competing capabilities or pursue an acquisition to accelerate its strategy.
- Zoom (ZM)Communication software with infrastructure but limited first-mover protection.
- Strengths
- Some deep infrastructure supports a relatively stable market-share position.
- Weaknesses
- Microsoft and Google can match infrastructure investment, while pricing power remains muted.
- Comparison
- Less protected than vendors with stronger network effects, workflow lock-in or data advantages.
- Risks
- Difficulty improving beyond stable market share amid well-funded competitors.
Key data
- AI-agent platform efficiency<50% of tokensBernstein says coding agents directly using project-management LoB platforms consume less than half the tokens, take less time and are more likely to succeed.
- Bernstein Outperform thresholdMore than 15 percentage pointsUnder the Bernstein brand, Outperform denotes expected relative performance above the relevant market index over 12 months.
- Cloudflare 2026E adjusted P/E331.5xTable value as of 11 September 2026.
- CrowdStrike 2026E adjusted P/E221.7xTable value as of 11 September 2026.
- Oracle 2028E adjusted P/E12.3xTable value as of 11 September 2026.
Impact & implications
The report argues that AI-led disruption should be assessed by a vendor's role in critical workflows rather than by software category alone. Systems of record, customized LoB platforms, security networks and infrastructure may gain value as agents are deployed, while vendors dependent on simpler tools, static data repositories, UI complexity or legacy channel advantages face more pressure.
Risks
- AI-native entrants may gain traction where new buyers, budgets or job roles emerge and incumbents are poorly positioned to serve them.
- SMB software, simple CRUD applications, legacy systems and non-critical applications may be more vulnerable to AI-enabled replacement.
- AI could erode product-depth, user-interface, first-mover and proprietary-development-platform moats unless they are supported by stronger advantages.
- Incumbents may face an innovator's dilemma if AI shifts buying authority or makes legacy brands and channels less valuable.
What to watch
- Whether enterprise AI agents continue to rely on and enrich existing LoB platforms rather than bypassing them.
- Adoption of AI-security roles and dedicated CISO budgets that could create openings for new vendors.
- Whether post-CI/CD development workflows produce new software categories and buyers.
- The pace at which SMB vendors use their domain expertise, semantic knowledge and customer relationships to respond to AI-native entrants.
- Evidence that dynamic customer data and reinforcement learning translate into faster product improvement for incumbent platforms.
- Oracle OCI execution, Salesforce's AI and M&A strategy, and the pace of potential point-solution competition in HCM.