Back to Blog
September 18, 202610 min read

The SaaSpocalypse: When AI Labs Eat Their Own Customers

Anthropic shipped Claude Design against its own design partner Figma, then shipped Claude Code against Cursor. The SaaSpocalypse is what happens when your AI vendor becomes your competitor while your data sits on their servers.

Share:

I have been watching AI tools closely enough, for long enough, that I stopped assuming any of them are neutral. A few months back a pattern started repeating itself often enough that I went and pulled the timeline together, because I think most people evaluating these tools for their business have not noticed it.

The game changed on a Tuesday in April 2026. Mike Krieger, who co-founded Instagram and became Anthropic's first Chief Product Officer before moving into its experimental incubator, resigned from Figma's board. The departure was disclosed in an SEC filing the same day The Information reported that Anthropic's next model would ship with design tools competing directly with Figma. Three days later, on April 17, Anthropic launched Claude Design from its new Anthropic Labs division, powered by Claude Opus 4.7, turning conversational prompts into designs, prototypes, slide decks, and marketing collateral. It exports to PDF, PPTX, standalone HTML, and notably not Figma.

What changed that made the world's most prominent AI safety company comfortable competing directly with a company its own Chief Product Officer helped govern? I don't have an answer to that. What I know is this: AI labs stopped being neutral infrastructure. They are competitors now, and they sit closer to your data than any vendor you signed with five years ago. If your business has anything unique to it, a process, a client list, a way of doing the work that nobody else has figured out, this is worth ten minutes of your attention.

The Figma Playbook

The timeline is worth laying out carefully. Krieger joined Anthropic in May 2024. By January 2026, he had moved into its experimental incubator while simultaneously holding a seat on Figma's board. April 14, he stepped down. April 16, Anthropic released Claude Opus 4.7. April 17, Claude Design launched.

Figma's stock fell as much as 7.28% that day, closing at $18.84. Figma is now more than 80% off its post-IPO high.

Anthropic publicly framed Claude Design as aimed at people who aren't starting from a design tool. That framing exists because Figma and Anthropic had been partners. Figma shipped Code to Canvas in February 2026, converting Claude Code output into editable Figma designs. Two months later the same partner shipped a product that competes with Figma's core business.

Did Anthropic learn anything from having its CPO on Figma's board? I cannot prove that it did. The timing is extraordinary, and I am not claiming it as fact. But competition with insider perspective is a different thing from competition with a white paper.

The Cursor Playbook

The same pattern plays out in code. Cursor is an AI-native editor built on Anthropic's API, with Claude as its foundational model partner. By March 2026 it had crossed $2 billion in annual recurring revenue, per Bloomberg and TechCrunch, with roughly 120 Fortune 500 accounts running active deployments.

Anthropic's answer was Claude Code, a terminal-native coding agent positioned opposite Cursor's in-editor flow. Both run on the same underlying Anthropic models. Anthropic has not confirmed that Cursor's API spend funded the capability now competing with it. Nobody has to confirm it. Cursor paid for the compute. Anthropic owns the model that compute trained.

Cursor did not stick around to find out how that ends. On June 16, 2026, SpaceX agreed to buy Cursor's parent company, Anysphere, for $60 billion in an all-stock deal, the largest acquisition of a venture-backed startup on record. A company built on top of Anthropic's API decided the safer bet was to stop being independent and fold into a buyer with its own balance sheet and its own compute ambitions. That is not a rebuttal to the argument. It is the argument, running one step ahead of schedule.

The SaaSpocalypse

The term describes the February 2026 software selloff that happened when investors concluded that AI was moving from copilot to operator, and the productivity gains would accrue to model providers rather than software vendors. By February 3, Goldman Sachs' basket of US software stocks fell 6% in a single session, the steepest one-day drop in nearly a year. Roughly $2 trillion in software market cap vanished over twelve months. Workday was down roughly 33%. The iShares Expanded Tech-Software ETF (IGV) fell roughly 18% to 23% depending on when you measure.

Three foundational model providers raised $160 billion in January and February 2026. Eighty-six percent of private deal value in the first half of 2026 went to AI companies. There were no notable SaaS IPOs.

The four patterns are Anthropic building Claude Design against Figma, OpenAI building its own AI products against its API customers, Meta's Llama model deflating hosted-model pricing because when frontier-class capability is available as open weights, paying for hosted API access becomes harder to justify, and Google embedding Gemini directly into Workspace as a built-in bundled feature, pressuring AI-native productivity vendors and pushing the market toward AI-included-in-suite pricing.

By May 2026, some analysts were calling the SaaSpocalypse a market overreaction. Enterprises were deepening their software integration rather than abandoning it, because managing proprietary data, security, and compliance makes building AI yourself more costly and risky than trusting a vendor. A September 2026 CNBC piece noted the SaaSpocalypse trade had legs this one may not. The market may have been too pessimistic about the near term. That does not change the structural conflict of interest sitting at the center of every AI lab's business model.

What "We Don't Train on Your Data" Actually Means

This is the heart of the piece, and most people get it wrong because they stop at the marketing headline.

Anthropic's API default is automatic deletion of inputs and outputs within 30 days, unless a longer-retention service is in play, a zero-data-retention agreement exists, or retention is required for policy enforcement or law. Anthropic states it does not train on enterprise data without explicit permission and never will.

June 9, 2026, changed that. Anthropic launched Claude Fable 5 and Mythos 5 and simultaneously began requiring 30-day data retention on all "Covered Models" (the Mythos-class generation). This applies on every platform, including to customers who had zero-data-retention agreements. Prompts and outputs on covered models are retained for 30 days across Claude Console, Claude Code, AWS Bedrock, Google Cloud Agent Platform, and Microsoft Foundry. The stated rationale is that sophisticated misuse spans multiple sessions and accounts, and detection requires retention long enough to correlate across time.

Even with zero-data-retention agreements, Anthropic retains model inputs and outputs for up to two years when it detects Usage Policy violations, and trust-and-safety classification scores for up to seven years.

September 1, 2026: Enterprise Frontier Safeguards, combining zero-data-retention privacy with misuse detection by storing data in cloud infrastructure the customer controls, under the customer's encryption keys and access policies, with automated safety monitoring and no Anthropic human review required. Developed with 100-plus customers including Salesforce. Still not perfect. It still stores the data. Someone has to own the bucket.

On the OpenAI side, API data sent since March 1, 2023 is not used to train or improve models unless the customer opts in. Abuse monitoring logs are retained for up to 30 days. Zero-data-retention is available by approval, not self-serve, and even under ZDR, CSAM-flagged images are still retained. Private Safety Processing, announced August 19, 2026, extends automated safety monitoring across related interactions while remaining ZDR-compatible, working with content in customer-controlled infrastructure encrypted with customer-controlled keys that OpenAI personnel cannot access.

None of these policies promise that your usage patterns are invisible. Retention windows and safety-monitoring architecture determine whether a lab can see which products are growing and which verticals are heating up. "We don't train on your data" is not the same sentence as "we cannot see what you are building."

The On-Premises Alternative

The people who actually understand these incentives are moving off the cloud. Chamath Palihapitiya reported that AI inference costs at his startup tripled over three months while productivity and profitability did not increase. His July 2026 essay "The Great Descent" argued that AI intelligence is sliding down the same cost curve phones rode, driven by both hardware and model-efficiency curves, and that renting generic AI erases your competitive edge while encoding your own proprietary experience is the real moat.

The on-premises options in 2026, plainly stated:

DeepSeek released V3 and V4 Flash/Pro as open weights on Hugging Face, runnable locally via vLLM, SGLang, and TensorRT-LLM with no API calls required.

Kimi from Moonshot AI is open weights, not open source. The published weights are downloadable, runnable, and fine-tunable under a modified MIT license. The kimi.com app and the Moonshot API are closed software. Moonshot's own deployment guide for K3 recommends at least 64 high-end chips. So the "no data leaves your network" claim is true if you self-host the weights and false if you use their API.

Ollama and llama.cpp give you the practical local-inference path on consumer hardware, running Llama, Mistral, Qwen, Gemma, and open-weight Chinese models quantized.

Apple Intelligence provides on-device processing on the Neural Engine for supported features, with more complex tasks routed to Private Cloud Compute. Legitimate but not a general enterprise substitution.

Palantir and NVIDIA announced an expanded partnership on June 29, 2026 to deploy NVIDIA's open-weight Nemotron models inside Palantir's sovereign AI environments for US government agencies and critical infrastructure. Palantir posted a nine-point AI sovereignty manifesto on June 30 criticizing token-metered business models and urging institutions to own their data, weights, and alpha.

The honest limitation that nobody who wants you to stay on the cloud will mention: frontier coding agents still need cloud-scale compute. The realistic architecture for 2026 is hybrid, not pure local. Send what you can run yourself to local models. Route what you cannot to the cloud. That is the architecture practitioners are actually deploying.

What to Do Right Now

You do not need to move everything off the cloud today. You need to audit what you are already putting in and decide which items actually matter.

First, inventory every prompt containing proprietary information. Product roadmaps. Deal strategy. Legal analysis. Client data. Code that has not shipped. Anything you would not email to a competitor.

Second, review your current data retention settings. Anthropic's June 2026 change means even customers with zero-data-retention agreements now retain data for 30 days on covered models. Check your actual workspace settings. The marketing page and your configuration may not match.

Third, identify which of your AI usage patterns reveal competitive information. Even if individual prompts are deleted, the aggregate pattern of which features you are building, which verticals you are exploring, and which models you are routing traffic to is visible to the provider. Usage patterns are intelligence.

Fourth, separate your workflows into three buckets: safe for any model, needs zero-data-retention, and needs on-premises. Then match your architecture to the bucket.

Fifth, if you have sensitive work, push toward Enterprise Frontier Safeguards or OpenAI's Private Safety Processing where available. Customer-controlled infrastructure is meaningfully better than provider-controlled.

Sixth, build at least one workflow that runs on local hardware this month. Start small. Use Ollama with an open-weight model for drafting and research. Prove the architecture works before you commit more deeply.

Trust Is Not a Data Policy

I did not write this to tell anyone to panic or to swear off these tools. I use them daily, several of them, and they are worth using. I wrote it because I keep running into teams evaluating AI for their business who have not asked the one question that matters: what happens to the thing that makes us different once it goes into someone else's model.

Policies change. Companies pivot. The economic incentive to compete with successful API customers is enormous. Anthropic built Claude Design while one of its own executives sat on Figma's board. OpenAI competes with startups built on its API. Meta open-sourced Llama, which functioned as a deflationary force on hosted-model pricing.

If your data lands on someone else's server, you are betting your business on their restraint. Restraint is a nice word for something that evaporates the moment the math changes.

If you have something proprietary, a process, a client relationship, a body of knowledge nobody else has, that is exactly the material worth protecting before you hand it to a tool that might be your competitor in eighteen months. On-premises is not paranoia. It is the only architecture that guarantees the bet pays off.

TT

Tony Self

AI strategist, speaker, and consultant helping enterprises deploy AI without the risk. Decades of experience in real estate and technology.