For a while, the market had a simple story about AI agents: they would eat software. Software valuations compressed on the thesis that if an agent can do the job, you no longer need the app that used to do it — and, by extension, you no longer need to pay the app’s subscription. Like most simple stories about a big shift, it’s half right. Agents are absolutely coming for large parts of the stack. But “the app layer thins out” and “all software gets replaced” are very different claims, and the gap between them is where the real architecture — and the real value — lives.

Three layers, eaten unevenly
It helps to picture enterprise software the way it has long been described — in three layers. At the top sit systems of engagement: the interfaces, workflows and applications people actually touch. In the middle, systems of intelligence: the analytics, models and decisioning that turn data into a recommendation or an action. At the bottom, systems of record: the databases of truth — customers, transactions, inventory, ledgers — that everything else depends on.
Agent swarms are not consuming these three layers evenly. They are eating the stack top-down.
Why the top goes first
The engagement layer is the most exposed, because it is the thinnest. A great deal of enterprise software is, functionally, a well-designed form over a database — a way to see, enter and route information. That is exactly the kind of work a capable agent can absorb: understand the intent, gather the context, take the step, and skip the screen entirely. When the interface becomes a conversation and the workflow becomes an agent’s plan, the app that used to mediate it has far less to do.
Intelligence is next, for a related reason. Much of the middle layer exists to compress data into a human-readable answer — a dashboard, a score, a segment — so that a person can decide. Agents shorten that loop: they pull the signal and act on it, or hand the decision to a human at exactly the right moment. The dashboard doesn’t vanish, but its place at the centre does.
Why the system of record holds
The record layer is a different animal, and this is where the “agents replace everything” story breaks down. Systems of record are hard to displace for reasons that have nothing to do with how clever the model is:
- Data gravity. The truth has mass. Decades of customers, transactions and history don’t move because a new interface showed up.
- Correctness is non-negotiable. An engagement layer that’s occasionally wrong is annoying; a record layer that’s occasionally wrong is a failed audit, a misstated quarter, a legal exposure. Probabilistic systems sit uneasily on top of a layer whose entire job is to be exactly right.
- Compliance and audit. The record is where regulation lives. You cannot casually swap the thing that has to be provable, traceable and retained.
- Integration debt and process. The record layer is wired into everything, and decades of embedded process sit around it. The blast radius of replacing it is enormous.
This is why agentic AI is starting at the top two layers and will reach the bottom one last — carefully, if at all. The value is easiest to capture, and the risk lowest, exactly where the software is thinnest.
But stickiness isn’t the same as safety. A passive system of record — a database that only remembers — can still be commoditised; agents are perfectly happy to read from and write to a dumb store. What actually compounds in value is the record made governable: lineage, policy, access control and context layered on top, so the data isn’t merely correct but usable and accountable. The moat was never the table. It’s the governance around it — which is exactly why “the record holds” is really a claim about the substrate, not the database.
What the market got right, and over-read
So the re-rating was both correct and overdone. Correct, because a real portion of the stack — the engagement veneer, and parts of the intelligence layer — genuinely thins out or gets re-fronted by agents, and the subscription logic behind a lot of “software you log into” does weaken. Over-read, because “the app layer thins” quietly became “all software gets replaced,” and those are not the same statement. The record layer doesn’t disappear. Neither does the integration around it, the governance on top of it, or the data inside it. What changes is not whether these things exist — it’s where the value concentrates.
It also matters which software is exposed. “Top goes first” is a statement about thin, pure-play engagement — a nice interface over someone else’s data. The incumbents with real data gravity don’t sit still and get replaced; they defend by owning the workflow and the data, re-pricing for outcomes rather than seats, and quietly moving down the stack toward orchestration and the record. The layer that gets eaten is the veneer. The companies in trouble are the ones that only ever owned the veneer.
The end-state: agent farms on an enterprise data substrate
Play it forward and the shape becomes clear. The enterprise doesn’t become a pile of agents replacing a pile of apps. It becomes something closer to an agent farm running over a governed enterprise data substrate. Many agents — specialised, orchestrated, each doing a slice — operate at the engagement and intelligence layers. Beneath them, the durable foundation is the system of record and the substrate that governs access to it: one place where the data lives, with the lineage, policy and accountability that let a swarm of probabilistic actors work on it safely.
The app layer gets thinner and more fluid. The foundation gets more important, not less. The centre of gravity moves down.
What this means for leaders
If that’s the direction, the implications are unusually concrete:
- Go agentic at the top first. Put agents where the software is thinnest and the blast radius smallest — engagement, and the decision loops inside intelligence. That’s where you capture value now, and where mistakes are cheap.
- Don’t rip out the record — invest in the substrate under it. The winning move isn’t replacing your system of record with an agent. It’s making your enterprise data substrate governed, accessible and accountable enough that agents can safely stand on it: lineage, access control, policy, and an auditable trail of what every agent actually did.
- Treat governance and ROI as first-class. An agent farm without accountability isn’t a strategy; it’s an incident waiting to happen. The enterprises that win won’t be the ones running the most agents — they’ll be the ones that can prove what those agents did, what it cost, and that it was allowed.
- Right-size everything. Not every agent needs a frontier model, and not every layer needs an agent. Match the tool to the task, and keep the deterministic core deterministic.
The durable bet
The temptation, in a re-rating like this one, is to ask which software dies. The better question is which foundation survives — because that’s where the durable value pools. Agent swarms are eating the enterprise stack top-down. Engagement goes first, intelligence next, and the system of record, with the data substrate beneath it, is what’s left standing.
The winners won’t be the ones with the fastest agents. They’ll be the ones who built the foundation those agents can safely stand on.
The Agentic Stack — a five-part series
- Agents Eat the Stack Top-Down — you are here
- The Substrate War
- Buy, Build, or Orchestrate
- Service-as-Software
- The Frontier Labs — Squeezed Middle





Leave a Reply