All documents · Agentic AI market

Agentic AI software market — research memo

Date: 18 September 2026
Scope: SaaS pivot research for a 1-VPS indie product. Not a generic “AI platform.” No quantum. No social network.
Method: Primary sources opened and cited below. Numbers that appear only in secondary recaps are not used. Market-size estimates disagree by definition; that disagreement is the finding.


1. Market size and growth (dated)

Two different “agentic AI” markets

Analysts are not measuring the same thing. Treat every TAM as a definition, not a census.

Source (opened) What it counts 2026 figure Trajectory
Bain & Company, 7 May 2026 (PR Newswire) US SaaS TAM created by automating cross-system human coordination, not replacing systems of record $100B US TAM; vendors capturing $4–6B (~90%+ uncaptured) Canada + Europe + Australia + New Zealand could double to ~$200B
MarketsandMarkets, 20 Aug 2026 (PR Newswire UK) Global “Agentic AI” software/services (platforms, orchestration, prebuilt agents) $19.33B in 2026 (from $11.56B in 2025) $205.88B by 2033, 40.2% CAGR
MarketsandMarkets, 4 May 2026 Agentic AI security only $1.65B in 2026 $13.52B by 2032, 42.0% CAGR
Menlo Ventures, 16 Sep 2026 (GlobeNewswire) Consumer AI spend (assistants + agents), not enterprise SaaS $40B global consumer AI spend in 2026 (from $12B a year earlier) Spend tripled while the user base barely grew

How to use these numbers for a 1-VPS SaaS: Bain is the labor-replacement opportunity incumbents and well-funded natives (Glean, Sierra) are chasing. MarketsandMarkets $19.33B is a vendor-revenue forecast that already includes Microsoft, AWS, Google, Salesforce, ServiceNow, IBM. The addressable slice for an indie is not a percentage of $100B. It is the self-serve remainder: teams who already pay $20–200/mo for coding agents and LLM keys and need a permit / budget / receipt layer those vendors do not sell on a credit card.

Bain, 7 May 2026 — the $100B “glue work” TAM

Bain’s second report in a five-part software-in-the-age-of-AI series (released 7 May 2026, Boston) argues agentic AI does not kill SaaS. It monetizes the human glue between SaaS systems: pull from ERP, reconcile a spreadsheet, interpret a vendor email, decide whether to escalate.

Bain is an opportunity-sizing exercise, not 2026 booked revenue. Do not treat $100B as this year’s invoice.

MarketsandMarkets, 20 August 2026 — $19.33B → $205.88B

Opened PR (Delray Beach, 20 Aug 2026):

Caveat: MarketsandMarkets published a different “Agentic AI Market” note on 17 Aug 2026 ($7.06B in 2025 → $93.20B by 2032, 44.6% CAGR). Same firm, different report IDs and definitions. Use the 20 Aug 2026 $19.33B / 40.2% figure when citing “the” MnM agentic TAM, and flag the collision.

Agentic AI security is a separate, smaller, faster wedge

MarketsandMarkets, 4 May 2026:

This $1.65B is the governance/security envelope a permit-gateway product lives in. It is not the $19B “all agentic software” envelope.

Menlo, 16 September 2026 — consumer spend, not enterprise TAM

Menlo Ventures 2026 State of Consumer AI (nationally representative survey of 5,067 US adults, July 2026; GlobeNewswire 16 Sep 2026):

Implication for $19–99/mo SaaS: the buyer already has a card on file at OpenAI/Anthropic/Cursor. They will add a guardrail or receipt product if it is cheaper than one runaway agent loop and faster than a sales call. They will not add a fourth observability dashboard.

LangChain State of Agent Engineering, 12 June 2026

Opened: langchain.com/state-of-agent-engineering. Public survey 18 Nov–2 Dec 2025, 1,340 responses. Tech-heavy (63% technology; 49% of orgs <100 people). Treat as a builder census, not a Fortune 500 census.

Finding Number
Agents in production 57.3% (up from 51% prior year); another 30.4% actively developing with a deploy plan
Large enterprises (10k+) in production 67%
Small orgs (<100) in production 50%
Top barrier Quality 32% (accuracy, consistency, tone, policy)
Second barrier Latency 20%. Cost dropped vs prior year
At 2k+ employee orgs Quality still #1; security #2 at 24.9%, ahead of latency
Observability 89% some form; 62% step/tool tracing. In production: 94% / 71.5%
Offline evals 52.4%
Online evals 37.3% (44.8% among production teams)
Not evaluating 29.5% overall, 22.8% in production
Multi-model >75% use multiple models
Fine-tuning 57% do not fine-tune
Daily agents (write-in) Coding agents dominate (Claude Code, Cursor, GitHub Copilot, Amazon Q, Windsurf, Antigravity). Then research/deep-research. Then custom LangChain/LangGraph agents
Primary use case (forced single pick) Customer service 26.5%, research/data 24.4%, internal workflow automation 18%. At 10k+: internal productivity first (26.8%)

Read-through: production is real, quality is the killer, observability is table stakes (do not clone Langfuse), evals are the gap, coding agents are the daily habit, and cost is no longer the #1 story for production teams — but spend caps still matter for individuals and small teams whose personal API bills explode (see Menlo $100+/mo cohort).

NIST (voluntary US baseline, not a market-size source)

Opened: NIST AI homepage and NIST AI 100-1, Artificial Intelligence Risk Management Framework (AI RMF 1.0), January 2023 (doi:10.6028/NIST.AI.100-1).


2. Where demand is hottest right now (Sep 2026)

Heat is not evenly distributed. Ranked by what shipped in the last 90 days + what builders already do every day.

2.1 Agent identity, SSO, and “who is this agent?” — boiling

This is the enterprise governance rush the brief flagged. It is real and crowded at the top.

Heat: high. Indie room: low inside Okta/Entra/VMware/IBM. The gap is everyone not on those control planes — developers, agencies, 10-person startups, people pasting API keys into Claude Code.

2.2 MCP as the lingua franca — boiling, shifting from “connect” to “govern and cheapen”

Opened Anthropic, 28 July 2026 (Bringing MCP 2026-07-28 to Claude):

Opened Cloudflare, 14 April 2026 (Scaling MCP adoption):

Heat: the protocol war is over; MCP won. Demand has moved to portals, allowlists, spend, and shadow-MCP detection. Cloudflare/Okta/Anthropic own the enterprise version. Nobody owns a 60-second, English-rule, BYO-key MCP permit for a Cursor/Claude Code user.

2.3 Coding agents — the daily habit, already paid

LangChain write-ins (June 2026 report): Claude Code, Cursor, GitHub Copilot, Amazon Q, Windsurf, Antigravity are the daily agents. Research agents are second; custom LangGraph agents third.

This is the only agent category that already has consumer-grade willingness to pay (Menlo: coding is a default task; 55% of AI users pay; regular agent users 92% pay). It is also the category that pastes MCP servers and API keys into a config file with no Okta in the loop.

2.4 Quality / evals — hot problem, crowded tooling

LangChain: quality is the #1 production killer (32%). Observability 89%, offline evals 52%, online evals 37%. IBM just shipped Custom LLM-as-a-Judge and an AgentOps agent that writes tests and rewrites instructions. LangSmith Engine (Plus+) clusters failures and proposes prompt/code fixes, metered in LCUs. Langfuse has datasets, LLM-as-judge, annotation queues on the $29 Core plan.

Heat: real. New generic eval platform: dead. A wedge only works if it is narrower than LangSmith (e.g. “did this coding-agent diff stay in scope and pass this repo’s tests”) and faster than a SDK.

2.5 Cost — cooled as a production blocker, still hot as a personal bill

LangChain: cost dropped down the barrier list; model prices fell. Menlo: 14% of consumer payers at $100+/mo drive 60% of US consumer AI spend. Cloudflare built Code Mode specifically because MCP tool dumps burn context tokens. Helicone (the proxy people used for cost) is in maintenance mode (see §4).

Heat: medium for enterprises (they have AI Gateway / Copilot credits), high for indies whose Anthropic bill spiked overnight.

2.6 Governance theater vs. receipts

EU AI Act transparency rules are in force as of 2 August 2026 (Commission page, last update 3 Aug 2026). High-risk Annex III is deferred to 2 December 2027 by the AI Omnibus (political agreement 7 May 2026, in force 27 July 2026). Chatbot-style disclosure and “this is AI” labeling are live. Claiming “we make you AI Act compliant” is a landmine (brief constraint #4). Emitting a signed, shareable log of what an agent was allowed to do is a product.

Ninth Circuit, 4 August 2026, Amazon.com Services, LLC v. Perplexity AI, Inc., No. 26-1444 (Cooley alert 6 Aug 2026): when a user directs an agent and traffic is relayed through the user’s machine, the user — not the developer — “accesses” the site under CFAA/CDAFA. The agent is “a tool, not a person.” Direct server-to-server access, or greater developer control, may still be CFAA. ToS/contract claims survive. Do not build a product that logs into third-party sites for users. Do build user-side permits and receipts.


3. Underserved wedges a 1-VPS indie SaaS could own in 90 days

Filter: runs on one Ubuntu VPS (bind 127.0.0.1, nginx 80/443), value in <60 seconds, no sales call, users keep their own LLM keys, not EU Annex III, not a Langfuse clone, not Okta/IBM/Broadcom.

Wedge A — MCP permit gateway for people, not CISOs (strongest)

Job to be done: “I connected Claude Code / Cursor / a custom agent to GitHub, Stripe-test, Notion, and my homelab. I want English rules: allow / deny / ask, a monthly spend cap on my keys, and a signed receipt I can paste to a client or a lead.”

Why it is open: - Okta Agent SSO requires XAA-speaking agents + an Okta tenant. Agent SSO is free if you already pay for Okta. A 4-person agency does not. - Cloudflare MCP portals are excellent and tied to Cloudflare One / Workers. Not a $29/mo indie SKU. - IBM/Microsoft/Broadcom/Dataiku are procurement. - MCP 2026-07-28 made servers ordinary HTTP. A reverse-proxy permit layer is now a weekend-to-MVP, not a protocol science project. - Anthropic’s own spec move to OAuth/OIDC still leaves a hole: tool-level allow/deny/ask and spend, in English, with a playground.

90-day shape: one URL. Paste it as the MCP endpoint. Rules in a textarea. Ask-mode sends a magic link / Slack ping. Receipt is a hash-chained JSON + verify page. BYO keys. No token resale.

Kill risks: becoming “enterprise GRC”; scraping/CFAA agents; selling model access.

Wedge B — agent-permit.yaml in the repo (viral, Dependabot-shaped)

Same enforcement as A, but the policy lives next to the code and the hosted runtime is the default CI/MCP sidecar. A GitHub App comments on PRs that add a new MCP server without a permit. This is how you get distribution without ads: every repo that adds MCP becomes a lead.

Why it is open: GitHub/Microsoft will eventually ship org-level MCP allowlists (Copilot already has enterprise MCP default-deny in docs). They will not ship a pretty, self-serve, cross-IDE policy for a solo Cursor user this quarter.

Wedge C — Spend cap + kill switch for BYO keys (Helicone vacuum)

Helicone processed 14.2T tokens across 16,000 orgs, then Mintlify acquired it 3 March 2026 and put the service in maintenance mode (security, new models, bugfixes; no roadmap). LangSmith LLM Gateway and Cloudflare AI Gateway exist but are platform-tied. LiteLLM is DIY.

A thin OpenAI-compatible proxy: budgets per agent, per project, per day; hard stop; webhook. Do not resell tokens. User’s key, user’s bill, our cap.

Why it is not enough alone: cost is no longer LangChain’s #1 barrier; a pure cost proxy is a feature, not a company. Bundle with Wedge A.

Wedge D — Coding-agent “in-scope” receipts, not generic evals

Do not build another trace UI. Build: given a git diff produced by Cursor/Claude Code, answer in 60 seconds (a) did tests pass, (b) did the diff touch files outside agent-permit.yaml paths, (c) here is a shareable badge. Quality is the #1 production killer; coding agents are the daily habit. LangSmith/Langfuse evals are application-trace evals, not repo-diff evals.

Wedge E — Freelance / client agent receipts (narrow, maybe too narrow)

A signed “this agent, under these rules, spent $X of the client’s key, called these tools, produced this artifact.” Useful for agencies billing AI work. Market is smaller than A–D. Keep as a mode of A, not a standalone company.

Explicitly not wedges (already owned or illegal here)


4. What is already owned

Microsoft — the default control plane for anyone on M365

Product What they own Who it is for Price posture
Copilot Studio Build/publish agents; data policies; connector/MCP governance via Power Platform; credit caps; Purview maker audit; security scan before publish M365 / Power Platform tenants Copilot credits; admin center
Microsoft Agent 365 (GA 1 May 2026) Observe / govern / secure: centralized agent registry, Entra identities for agents, Conditional Access, Purview DLP, Defender Commercial, per-user license, best with E5 Procurement, not $19
GitHub Copilot enterprise policies MCP default-deny, model allowlists, org overrides GitHub Enterprise Seat SKU

They do not own: a self-serve permit URL for a developer who is not in that tenant.

Okta — identity of record for agents that speak XAA

They do not own: tool-call allow/deny/ask for a local Claude Code process using a raw MCP URL.

IBM — agent ops for the Orchestrate estate

They do not own: a $29 developer playground.

Broadcom / VMware — packet-path AgentMinder

Dataiku — KPI control tower

Langfuse — cheap, good-enough traces + evals + prompts (MIT)

Opened langfuse.com/pricing:

Plan Price Notes
Hobby $0 50k units, 30-day data, 2 users
Core $29/mo 100k units, 90-day, unlimited users, in-app support. Overage $8/100k graduated
Pro $199/mo 3-year data, SOC2/ISO/BAA
Teams add-on +$300/mo SSO
Enterprise $2,499+/mo SCIM, audit logs, SLA

Self-host OSS is free. A Langfuse clone is not a genius wedge (brief). They already have tracing, cost, evals, prompts, playground, LLM-as-judge.

Helicone — owned by Mintlify, frozen

Opened Helicone blog, 3 March 2026, Cole Gottdank: acquired by Mintlify; “services will remain live for the foreseeable future in maintenance mode” (security, new models, bug/performance fixes). 14.2T tokens, 16,000 orgs, 33M end users. Gateway-shaped hole in the market, not an observability hole.

LangSmith — the full agent-engineering suite, usage-metered

Opened langchain.com/pricing:

Plan Seat Included
Developer $0 (1 seat) 5k base traces/mo, then PAYG
Plus $39/seat/mo 10k traces, Deployment, Engine, Fleet, Sandboxes, LLM Gateway
Enterprise custom self-host/hybrid, custom SSO, SLA

Usage: LCU $1.50 (compute/work), LSU $1.00 (traces/storage). Plus includes LLM Gateway (cost, rate limit, fallbacks, PII redaction, BYO key, “use Gateway with coding agents”), sandboxes, Fleet (natural-language agents + remote MCP), Engine (autonomous failure clustering). Extended trace retention historically 400 days; SaaS cap moving to 180 days (LangChain changelog 14 Sep 2026 — seen in index, not re-opened here; do not over-cite).

They own: teams already on LangChain/LangGraph who want traces + evals + deploy. They do not own: a policy URL you drop in front of Claude Code without adopting LangSmith.

Others in the blast radius (do not fight head-on)


5. Buyer: who pays $19–99/mo on a card today, no procurement

Procurement is where Microsoft/Okta/IBM/Broadcom/Dataiku live. The card buyer is someone who already pays Anthropic/OpenAI/Cursor and will add a line item the way they added Langfuse Core ($29) or LangSmith Plus ($39/seat).

Primary buyer (best fit)

Individual developers and 2–15 person product teams shipping agents or using coding agents daily.

Evidence:

Persona sketch (concrete):

  1. Indie / agency builder — sells custom GPT/Claude/MCP agents to clients. Needs a URL they can put in front of the agent, a spend cap on the client’s key, and a PDF/JSON receipt. Pays $29–99 of their own money to look professional. No legal review.
  2. Startup platform engineer (5–20 people) — rolled Cursor + Claude Code out to the team. Someone’s Anthropic bill hit four figures. They will pay $39/mo for a shared permit + budget before they will buy Okta for AI Agents.
  3. Power user (Menlo $100+/mo cohort) — already lets agents act without approval (32% have done it once). Will pay for a kill switch the way they pay for 1Password.

Who does not buy at $19–99 on a card

Pricing analog (opened pages)

Conversion motion that matches the buyer

Homepage playground: paste an MCP URL or a sample tools/call JSON → see allow/deny/ask in under 60 seconds → copy a gateway URL. GitHub App optional. Stripe Checkout. No SOC2 claim. No “AI Act compliant” claim. Disclose that the product is software that enforces your rules and emits logs.


6. Five product hypotheses, ranked

Score: Demand (what Sep 2026 buyers already feel) × Ease of adoption (time-to-value, no SDK required) × Low regulation (not Annex III, not CFAA, not money transmission, not fake compliance). Scale 1–5. Rank by product of the three.

Rank 1 — Permit Gateway: English rules + allow/deny/ask + spend cap + signed receipts

Demand 5 × Adoption 5 × Low-reg 5 = 125

Rank 2 — agent-permit.yaml hosted runtime (Dependabot for MCP)

Demand 5 × Adoption 4 × Low-reg 5 = 100

Rank 3 — BYO-key spend cap / kill switch (Helicone-shaped, policy-first)

Demand 4 × Adoption 5 × Low-reg 4 = 80

Rank 4 — Coding-agent in-scope receipt (diff + tests + permit, not traces)

Demand 4 × Adoption 3 × Low-reg 5 = 60

Rank 5 — Agency / freelance agent receipts as a standalone SKU

Demand 2 × Adoption 4 × Low-reg 5 = 40

Hypotheses not ranked (killed)

Idea Kill reason
Langfuse/Helicone/LangSmith clone Crowded, cheap, OSS; Helicone frozen does not mean “rebuild Helicone”
“AI Act / SOC2 compliance” SaaS Legal landmine; Annex III deferred but claiming compliance is still banned by brief
Browser agent that logs into SaaS as the user Ninth Circuit is fact-specific; ToS; CFAA residual; brief explicit kill
Enterprise agent identity Okta Agent SSO is free; Entra Agent 365 is GA
Quantum circuit classroom / QCaaS Demand/monetization kill; no hardware; brief
Social / community for agents Mission: take social out
Generic multi-agent orchestrator ServiceNow, IBM, Microsoft, Salesforce already bought or built this (Moveworks $2.85B, Fin $3.6B)

Implications for the CryptoBook pivot (for PM, not a decision)

  1. The genius wedge is not “governance.” Governance is what Okta, Microsoft, IBM, Broadcom, and Dataiku shipped between May and early September 2026. The genius wedge is governance for people who will never see those products: a drop-in MCP/tool permit with English rules, a spend cap on their own keys, and a signed receipt.
  2. Ship Rank 1 + Rank 2 as one product. Rank 3 is a mode (the proxy). Rank 4–5 are views/exports of the same receipts.
  3. Price like Langfuse Core, not like Agent 365. $19 / $39 / $99, card, BYO keys.
  4. Do not mention quantum. Do not rebuild a social graph. Do not sell tokens. Do not say “compliant.”
  5. Legal posture to print on the site: we enforce your rules on your tools with your keys; we log decisions you asked us to log; we are not your lawyer, auditor, or identity provider; agents that browse third-party sites do so as you (Ninth Circuit, 4 Aug 2026).

Sources actually opened

  1. Bain & Company via PR Newswire, 7 May 2026. “SaaS’ next $100 billion opportunity could come from agentic AI.” https://www.prnewswire.com/news-releases/saas-next-100-billion-opportunity-could-come-from-agentic-ai--bain--co-research-302765161.html
  2. MarketsandMarkets via PR Newswire UK, 20 Aug 2026. “Agentic AI Market worth $205.88 billion by 2033.” https://www.prnewswire.co.uk/news-releases/agentic-ai-market-worth-205-88-billion-by-2033--report-by-marketsandmarkets-302856176.html
  3. MarketsandMarkets via PR Newswire, 4 May 2026. “Agentic AI Security Market worth $13.52 billion by 2032.” https://www.prnewswire.com/news-releases/agentic-ai-security-market-worth-13-52-billion-by-2032--marketsandmarkets-302761232.html
  4. Menlo Ventures via GlobeNewswire, 16 Sep 2026. “2026 State of Consumer AI” ($40B spend; 41% tried an agent). https://www.globenewswire.com/news-release/2026/09/16/3363086/0/en/menlo-ventures-report-consumer-ai-spend-tripled-to-40b-this-year-even-as-user-growth-barely-budged.html
  5. LangChain, 12 June 2026. State of Agent Engineering (1,340 responses, Nov–Dec 2025). https://www.langchain.com/state-of-agent-engineering
  6. Okta, 24 Aug 2026. “Okta brings first-class identity to AI agents with Agent SSO.” https://www.okta.com/newsroom/press-releases/okta-brings-first-class-identity-to-ai-agents-with-agent-sso/
  7. Okta, 27 May 2026. “AI Agents at Work 2026” (Apprize360 survey, March 2026). https://www.okta.com/newsroom/articles/ai-agents-at-work-2026-agentic-enterprise-security/
  8. IBM, 3 Sep 2026. watsonx Orchestrate: AI Gateway, Trace Inspector, AgentOps Agent GA. https://www.ibm.com/new/announcements/new-in-ibm-watsonx-orchestrate-cross-platform-agent-discovery-custom-evaluation-and-agentops-agent-goes-ga
  9. Broadcom via GlobeNewswire, 31 Aug 2026. AgentMinder + vDefend + Avi for agentic AI. https://www.globenewswire.com/news-release/2026/08/31/3353355/19933/en/broadcom-delivers-end-to-end-security-identity-and-observability-for-agentic-ai.html
  10. Dataiku, 9 Mar 2026. “Platform for AI Success” / Agent Management early access. https://www.dataiku.com/company/news/dataiku-launches-the-platform-for-ai-success
  11. Microsoft Learn, Copilot Studio security and governance (updated Aug 2026). https://learn.microsoft.com/en-us/microsoft-copilot-studio/security-and-governance
  12. Microsoft Learn, Agent 365 overview (GA 1 May 2026; page 19 Aug 2026). https://learn.microsoft.com/en-us/microsoft-agent-365/overview
  13. Langfuse pricing (opened 18 Sep 2026). https://langfuse.com/pricing
  14. LangSmith / LangChain pricing (opened 18 Sep 2026). https://www.langchain.com/pricing
  15. Helicone, 3 Mar 2026. “Helicone is joining Mintlify.” https://www.helicone.ai/blog/joining-mintlify
  16. Anthropic, 28 Jul 2026. “Bringing MCP 2026-07-28 to Claude” (400M SDK downloads). https://claude.com/blog/bringing-mcp-2026-07-28-to-claude
  17. Cloudflare, 14 Apr 2026. “Scaling MCP adoption” (portals, Code Mode, shadow MCP). https://blog.cloudflare.com/enterprise-mcp/
  18. European Commission, AI Act overview (last update 3 Aug 2026; Omnibus high-risk dates; transparency in force 2 Aug 2026). https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai
  19. NIST AI 100-1, AI Risk Management Framework 1.0, Jan 2023. https://doi.org/10.6028/NIST.AI.100-1 and https://www.nist.gov/artificial-intelligence
  20. Cooley, 6 Aug 2026. Ninth Circuit Amazon v. Perplexity, No. 26-1444 (opinion 4 Aug 2026). https://www.cooley.com/news/insight/2026/2026-08-06-ninth-circuit-rules-on-ai-agent-access-to-third-party-websites-under-cfaa

Not used as citations (searched but not opened, or blocked): Gartner 25 Jun 2025 “40% of agentic projects canceled by 2027” press page (bot-wall); Menlo 2025 enterprise $37B report body (URL returned title only); Reuters Gartner recap.


Researcher note: if every idea above is later killed, the patch is still Rank 1 with a narrower object — MCP tool-call permits for coding agents only, no generic “agent platform,” no identity-provider claims.