The enterprise knowledge incumbents own is AI's real moat
In this interview, Sheila Zelinger argues the SaaS apocalypse is overblown and that incumbents' true AI moat is their enterprise data and tribal knowledge. She makes a case for skepticism, warning that blindly accepting AI output erodes critical thinking.

Sheila Zelinger advises startups and established companies from Atherton, California, where she works as an independent counselor to founders and boards navigating the shift to artificial intelligence. After nearly two decades inside one of enterprise software's largest platforms, she now trades on pattern recognition: she has watched the industry move from on-premise systems to software as a service, and she reads the current AI moment against that history. Her core argument runs against the panic. The so-called SaaSpocalypse, the notion that anyone can rebuild a software product with internal tools and render the incumbents obsolete, strikes her as overblown. She describes an information environment she calls brain buzz, where everything arrives at once and the temptation is to give up and simply accept whatever the machine says.
Her path to that vantage point began at Accenture, where she rose to associate partner, followed by a stretch inside a couple of startups that taught her the entrepreneurial side of the business. In 2005 she joined SAP and stayed for nearly eighteen years across a range of roles. She served as chief operating officer of an SAP business called Enterprise Collaboration, which eventually merged into the company's platform organization. Most recently she was a global vice president for the Business Technology Platform business, responsible for go-to-market across several lines of business, professional services, and commercialization. On the commercialization side she owned pricing and packaging, and she helped lay the groundwork for the consumption-based pricing models now spreading across AI. She holds an MBA and an undergraduate degree in geology, both from Stanford.
“If we are not careful, AI has the real potential to take away the critical thinking skills we need going forward.”
Zelinger thinks in terms of platforms, and she believes the incumbents hold advantages that the excitement around AI-native startups tends to obscure. Composable processes, she notes, are how the new applications get built, but a platform behind them supplies the consistency, scalability, and governance that real adoption requires. The deeper moat, in her view, is data: models are only as good as what they are trained on, and the enterprise data plus the tribal knowledge buried in emails, notes, and Slack channels belongs to the established players, not the newcomers. She points to research suggesting that roughly three quarters of AI efforts stall in pilot, and she argues that the ones that scale are those tied to cross-organizational processes with genuine return, not isolated experiments in a single corner of the business.
What animates her now is a case for careful skepticism. She uses AI several times a week, and finds it most valuable after she has done the thinking herself, then leans on it to refine rather than to decide. Her worry is that people will blindly accept plausible, general-sounding output and let their own critical thinking atrophy, the way the promise of social connection curdled into the unintended consequences of social media. She takes some hope from the people, including skeptical members of Gen Z, who guard their own reasoning, and from companies that are building governance and policy into their workflows before they scale. For her, the companies worth trusting are the ones chasing genuine customer value and ease of use toward an outcome, not the ones optimizing for attention.
The conversation
In this conversation: Josh Rubin (Host, CTO Studio) and Sheila Zelinger (Independent Advisor).
I am currently an independent advisor for both startups and larger companies. In the past, I was at SAP for nearly 18 years in a variety of roles. Most recently I was a global VP for our Business Technology Platform business, where I was responsible for going to market with several of our lines of business, professional services, and commercialization. For SAP, commercialization was pricing and packaging, and the opportunity to really lay the foundation for some of the pricing we're now seeing with AI. Just prior to that, I was the COO of a business called Enterprise Collaboration, which eventually merged into our platform business. And I held several roles before that, some entrepreneurial, some core business.
So you spent a fair bit of your career in the heart of the SaaS piece, seeing it from earliest conception all the way through some of its major growth.
I did. And I saw it not only from the product, the functionality, and the building of the system, but also from the transition from on-premise to SaaS and what it takes to do a transformation, some of which I think is certainly relevant for AI.
Especially because there's a big argument going around that we're moving in the opposite direction, back to on-prem for data security and air gap. If AI is commoditized, do we want to give all of our data to Claude, or to ChatGPT, or are you working with local models? The one I want to kick off with is the SaaS apocalypse, something talked about with increasing regularity. In capital, for example, they go in and say: right now we look at all the SaaS products in any company that wants our investment or is in the portfolio, and we have a room full of people who ask, can we create a reasonable facsimile of this product with internal tools? And if the answer is yes, we pull our investment. That has massive potential ramifications for the entire software industry. From somebody who worked in it for so long, is it overblown? Where are we going?
I feel that it is overblown, and maybe I'm a little biased. But I see a couple of things happening. The SaaS companies that are well established are strong, and they're moving very quickly in AI. They're not standing still, and they're not looking at the same platforms they had before. The best of them are going to evolve their platforms in a couple of ways. One is to make the software much more composable, a trend we've been talking about for five years, where you have these individual processes, which is essentially how AI-native solutions are developed. But you still have a platform behind it, which I think is critical for consistency and scalability. That's the thing I worry about with some AI-native applications: are they just a bunch of composable processes, and do they have the other aspects of the platform they need for true adoption and scalability? That may mean a platform for how you construct the agents, how you orchestrate them, and how you get enterprise knowledge and tribal knowledge in there. The incumbents have some key advantages if they can evolve their software. It may start with embedding agents in the workflow products and making sure those agents work across the silos of applications. It will be up to them to orchestrate that in a scalable way. So yes, the incumbents are under pressure, but there's a lot of room for them to change and adapt and take advantage of platform consistency and enterprise knowledge, which in the end could be the competitive moat.
But you can't copyright a process in this case, or can you?
We never copyrighted processes. But how you treat the agents, how you look at those processes, where you inject the human in the loop, and how you build trust, the enterprise knowledge behind that that they can draw on, I think is really critical and will actually be a competitive advantage.
When you say enterprise knowledge, do you mean the SaaS company's enterprise knowledge, or all of the data they had access to from their clients?
It's the latter, and data they've gotten approval to use. Even two or three years ago, SAP talked about the tens of thousands of records they had for customers. Records were anonymized, but they could be used to train the AI models. Now we need to expand that definition. It's not just training them on the processes and the data and the trends. These platforms are also able to ingest tribal knowledge: what did you write in your email, what's in your notes, what's in your Slack channel? Picking up all that tribal knowledge of the employees and making it usable and available for the agents, in the end, will be one of the competitive moats versus the native AI companies.
Is that a competitive moat, though? What you're talking about is an API call and an agent interacting with proprietary data. It is not the SaaS company's proprietary data, it is the client's. Their competitive advantage is their experience, their history, their legacy software. But if Claude can walk in and say, you could dump all of your stuff into this system, or you could just dump it into us and we can do it for you, for cheaper, they're going to.
I think we have to separate the models from the processes. Companies are looking at multiple models. They don't want to lock in with the models, and the models are only as good as the data they're trained on, which is that interface data. I don't think the anthropics or the OpenAIs have the same level of data, and API calls alone don't have that knowledge or intelligence. They transfer the data, which is very important. But ultimately we're looking for the combination of the actual structured processes plus the things around it, the ability to access that enterprise context.
Ultimately it's the cost-benefit analysis people are choosing. Am I going to give money to Salesforce, or spend more on tokens and in-house solutions? Everyone will have to make that decision themselves.
Exactly. And several things are changing. One is the value of a platform approach in general, and I don't mean a monolithic enterprise platform. Those platforms are going to be much more composable. But when you want to scale, platforms historically have been the way you scale in a consistent and governed way. That's going to be another advantage for these companies. There's also the question of whether AI is really going to survive or is just a bunch of pilots, and why people aren't able to scale. A couple of studies, I think one was an ECG study, showed that around 74 or 75 percent of what's being done now remains a pilot, never gets beyond that, and doesn't deliver value. It turns out there are things you need to make it scalable. On the company side, you need to look at processes that really have shareholder value or will deliver ROI, both to the customer and the vendor. Those typically cut across the entire organization, whereas many of our pilots have been focused on one small, isolated area. You get more value from something that cuts across, and major processes cut across multiple applications, so this platform notion is going to become more important to help scalability.
You've been working in the Valley a long time. You've seen the rise of software as a service, the rise of social, the delivery of Web 2.0, which created an extraordinary amount of wealth. At this point in your career, are you more optimistic about where things are going, or a bit more trepidatious about what's being developed?
I've got some trepidation about AI in general. If we're not careful, it certainly has the potential to take away some of the critical thinking skills we need going forward. It can be very easy, whether you're a consumer or a business, to just blindly accept what the AI engine tells us. It looks good, it's usually pretty general, it sounds sophisticated, and we go with it. If it's not tied to enterprise knowledge and data in some context, then hallucinations are still there. So I worry about people's willingness to still engage in critical thinking about the output they're getting. There's also this notion of brain buzz, where things are coming at you so fast you kind of give up. What makes it stressful for people is that timelines are getting compressed. It's not that a process is done faster, that's good, you don't want to do the administrative work, but everything is so compressed that you're moving very quickly from one thing to the next, trying to catch up. And we're all human. Can we keep up with that level of change so quickly?
The promise of tech has always been that it'll give you time back, and that never happens. We always fill the time with something else. And on your other fear, I can't remember if it was Socrates or Plato who worried that the written word would make people dumber because they'd stop memorizing the epics. So that seems to be an ever-present human fear. The question always comes down to: is AI different than every other transformative technology before it? You've engaged with it. How often are you using it right now?
I use it multiple times a week on different kinds of activities. I'm not in it directly every day doing a particular set of tasks, but I can tell you where I find it helpful: if I've done the thinking ahead of time, I might use it to help tune or refine things, and it's very good there. Sometimes at the front end it'll help organize things. But there's a very careful balance between letting it do everything and you passively accept it, versus the individual really thinking, applying their knowledge, creativity, and intuition to whether it's right or wrong. I am hopeful in a couple of ways. People are worried about the potential impact of AI, and I think that's a good thing, because it makes us more cautious and more selective about using it. I know a handful of Gen Z people who don't want to touch it that much because they value their thinking and are skeptical of the results. We all have to use it, but that skepticism is good. People don't really want this to go the way of social media platforms. That gets into ethics and judgment, and following the money. I think there's a healthy skepticism from enough people that will hopefully help us avoid blindly accepting and going down the wrong path.
So what you're saying is that fear is actually a good thing. Thinking fear, not unthinking fear, because people tend to make bad decisions when they're afraid. But skepticism, approaching it with both an open and a skeptical eye. Your point about social media is also interesting, because we all approached social media as this wonderful thing connecting us as a society, and we never thought about the second and third order effects. Are there any second or third order effects you're worried about with AI?
I'm worried about the fact that there will likely be second and third order effects, and we don't quite know where they'll go.
Give me your worst case scenario. What's the thought that keeps you up at night?
That people blindly accept it without any governance or policies, and very bad decisions and bad outcomes are made.
You're talking to startup boards all the time. Are you seeing that happen?
They are very concerned about these issues. The thing that gives me hope is that people are thinking about how to govern this, and doing it in a way that will also help boost trust in AI. Going back to platform capabilities, incumbents are thinking about how to build governance, policies, and authorizations into the workflow processes: what agents get to talk to what agents, what data gets passed between agents to keep the policies you want in place. Those are really important. Many companies are lagging, and I don't think AI-native companies are quite thinking that way yet, because they're doing interesting processes, for example in supply chain, but they don't necessarily have the governance platform attached to manage it.
Does that need to be solved by private industry, or is that government regulation?
I'm speaking of it in the context of private industry.
But can private industry do it on its own?
Companies do it today. They have security policies and so on. I think there will probably be a role for government. I'm not a student of exactly what the government should do. At SAP, I was on the receiving end of a lot of European government regulations. Some are good and some are overreach. Overreach can be a big problem, and it can really slow down technological advances, so there's a real balance. I do think there will be some role for government. I personally hope it's not as stringent as Europe has traditionally been, and you have to ask what's necessary and what's the cost.
I'm not particularly concerned about the current administration being super stringent in the policies they put out there.
Well, they did recently talk about having some AI policies. I was shocked. But companies are concerned about that, real, live, operating companies trying to deliver value to their customers.
The value side is also important. Are they more concerned about the value and ROI they're getting out of this new technology, or the potential sociological and security ramifications?
They need to be concerned about both, and established companies who use this technology are concerned about both. In my years in business, before SAP I was at Accenture and then a couple of startups, we never really wanted to break the law or screw the customer. The intent typically was above board and to do the right thing. Maybe I'm more optimistic that way about companies. I am concerned about the ethos of some of our social media companies, and about the ethos of some of our LLM companies, and we're even seeing some differentiation there. So it's not going to be a perfect world. But I'm hopeful that most companies who want a real customer base, who want to grow and deliver customer value, will think about these things, and their customers will too. It costs a lot of money to have a data breach. I don't think people will say I can get two times more efficiency and forget the data breaches. Eventually that hurts the brand. So maybe that's the optimist's side.
Eventually we're going to have to establish some kind of rubric for determining the good actors versus the bad actors. In my mind it comes down to: is the goal of your product to help your customer, or to engage your customer? Those are two very different bottoms of the funnel, because engagement, as we've seen with social, sounds great, but the downstream consequences can be pretty dire.
I think there's also a distinction between B2B and B2C. On the B2C side, the engagement with these algorithms can be very damaging, and we've seen proof of that. On the B2B side, engagement is defined a little differently.
It is, but to a certain extent we're talking about the same thing, the addiction. On the B2C side, how do you attend someone to your platform. On the B2B side, how do you addict a company to your product, the thing they need and cannot give up, and if they give it up it leads to negative consequences.
That could happen at that level. But when I think about an engagement layer from a vendor's perspective, an SAP perspective, or even a retailer, engagement is defined a little differently. Engagement for a SaaS company is a new engagement layer that is conversational. It has entirely different characteristics, enabling someone to develop and create what I'll call an AI app.
It's a UX layer.
It's a new UX layer. And yes, it is designed to pull you in, because it's going to be so easy to engage with these agents, build agents, build assistants, and do all of this. So you want to make it easy. We never loved the UI of SAP software.
Yes, but the product of that engagement is ease of use of the platform for a specific outcome, not, to your point, more attention.
Exactly. It's a different definition of engagement or attention.
Well, Sheila, I really appreciate the time. Thank you so much.
Thank you.
Be part of the
conversation.
Whether you're a CTO who wants to be featured, a company looking to sponsor, or an engineering leader wanting a seat in the room — there's a place for you here.