When AI Can Act, Software Moves to the Data
During my last few years at BenchPrep, we built a number of value-added AI capabilities to improve efficiency and create better customer and learner experiences. The business value was usually clear, but the first customer conversations were about data security and governance. Where would the data go? Who could access it? What would be logged? Which systems would the AI touch?
At the same time, I was being pitched strong AI products almost every week, and I found myself asking the same questions. We already had the infrastructure, data controls, and security model. Adding a new product meant another sub-processor, another DPA, another security review, and another environment where company data would travel. Had those products been able to operate inside our environment, I would have looked at them very differently.
I was seeing the same concern from both sides. Customers wanted the value of AI without losing control of their data. As a buyer, I wanted better software without adding another external boundary around the business. That concern becomes much more important as AI moves from answering questions to taking action.
The question is no longer only where the data sits
Data residency is not a new enterprise concern. Companies have spent years deciding where data can be stored, processed, and transferred. Agents introduce a different question: what can the software do on behalf of a person or team?
That means understanding which systems it can reach, whose credentials it uses, which actions it can take, and how those actions are reviewed and recorded. An assistant that summarizes a document creates one kind of risk. An agent that updates a customer record, issues a refund, approves a workflow, or changes a forecast creates another. The deployment model now determines more than where data is stored. It shapes how identity, permissions, and accountability work.
AI changes the SaaS trade-off
The SaaS model became dominant for good reason. Companies gained access to powerful software without having to build and operate it themselves. In exchange, they accepted that the application and much of its data would live in the vendor's environment.
That trade becomes harder when software operates across proprietary data, internal systems, company policies, and business workflows. These applications do not simply display information. They interpret context and take action. A security review is no longer only about whether a vendor stores a dataset. It is about what the application can reach, whose authority it inherits, and whether its actions remain inside the organization's controls.
The closer software gets to the operating core of the business, the less sense it makes to move that software outside the boundaries the company has already established.
Software moves to the data
For years, companies moved their data into applications. Enterprise AI reverses that direction. The software moves toward the systems where the data, identity, permissions, and business logic already live.
This matters because companies will create far more software than they do today. Much of it will be built for one company, one team, or one workflow by the people closest to the problem. Creating a new data store, permission model, and security boundary for every application will not scale.
As AI moves from assisting people to acting on their behalf, the software needs to operate where the company's data and controls already are.