SaaS 公司要完了吗:哪些会活下来、哪些会死 | Aaron Levie
Levie 对劳动力的核心判断是:未来5年,AI 会带来更多工程师和律师,而不是更少。 科技业约占GDP的8-15%;如果让其余85%的经济体也用上硅谷级工程能力,开发者就会转向 John Deere、Caterpillar 和 Eli Lilly。AI 也会让律师面对海量合同和备忘录草稿,但法院、专利审批和专业责任仍受供给约束——「人并没有被移出流程,只是改变了他们进入流程的位置」。
企业落地 AI 的瓶颈在组织重构,这可能催生50万至100万个“agent operator”岗位。 这些技术能力很强的运营者需要理解 MCPs、CLIs、skills 和 AGENTS.md,并围绕 agents 重建受监管工作流。由此产生的软件需求,与其说是再做一个手机应用,不如说是「无限量的软件」,用来连接割裂的数据、自动化后台流程。
SaaS 并非整体失去价值:agents 会削弱按钮密集型界面的价值,却会放大 API、专有业务逻辑、治理数据和人工审核的价值。 ERP 的价值不只是数据库,供应链和会计逻辑依然重要;Box 也表示,agents 可能将 API 调用量提升100倍甚至1,000倍。Levie 的要求是:成为「agents 最愿意处理这些数据的地方」。
Token 支出会跳出 IT 预算,变成日常运营费用,全球科技支出可能因此翻倍,而不是扩大10倍。 企业可以在营销活动和自动化之间做取舍,把高价模型配置给价值最高的5-10%用户,甚至像《Shark Tank》的参赛者一样为算力竞标。不同于初创公司,大型企业不能不加区分地“token max”:它们有年度预算,上市公司还有 EPS 承诺。
AI 会结构性扩大网络安全市场,因为 agents 既会生成更多存在漏洞的代码,也会让攻击者更快完成扫描。 当 AI 从编写大部分代码走向编写90%或95%的代码,每增加一个功能,就多一次开错端口或引入漏洞的机会。防御型 agents 可以审查这些产出,但Levie用一句话概括了这个循环机会:「Agents 是 agents 制造的问题的解决方案。」
公开市场仍把软件股不加区分地归为一个板块,但Levie预计未来1至2年会出现分化。 对于应对得当的公司,3倍自由现金流可能“低得激进”;但软件业的一部分此前确实被定价到了难以实现的终局。最终胜者会拥有深度工作流控制权、有价值的数据、适配 agents 的 API,以及可变现的自动化能力。即便如此,他仍认为 Atlassian 可能被过度抛售:更多工程活动应扩大对工程基础设施的需求,尽管其产品也必须进化。
即使主持人提出,要让8500亿美元估值走到2.1万亿美元需要大约3倍空间,Levie 仍会“加仓”前沿模型融资。 他类比云计算:AWS 在2010年的收入只有5亿美元,但15年后云已经形成数千亿美元规模的生态,能够正常运转的市场往往会远超最初预期。OpenAI 和 Anthropic 可以在多模型世界中同时胜出,而跨实验室基础设施——例如 agents 评测——可能催生「12个、24个、50个」新类别。
1. AI 是一场经济竞赛,不是为期1个月的生存冲刺
对于采访后的舆论,Levie 表示自己“可能有80%”站在 Jensen Huang 一边。他的框架是一场“商业和经济竞赛”,安全机制内生其中,而不是一场由某一方领先1至2个月就能永久决定结果的二元竞赛。他也认为 Jensen 对部分环节做了过度简化。
主持人开场时认为 Jensen 的表现很糟;Levie 则称这种反应是检验个人 AI 观念的“罗夏墨迹测试”。复杂系统升级需要多年,不存在某个神奇瞬间,让早期获得模型就等于锁定一切;攻防双方会“直到时间尽头”持续迭代。
Levie 转述称,Jensen 被低估的警告是:把人们吓得不敢学工程、放射学或进入医疗行业,会伤害整个社会。AI 或许会消除对微小中间步骤的审核,但更大的工作成果仍需要有人复核:「我们只是改变了他们进入流程的位置。」
2. 自动化暴露瓶颈,也会推高稀缺专家的需求
Levie 的判断没有留下余地:“5年后,工程师会更多。”拖拉机制造商、银行和制药公司都说工程师不够;云端代码、Codex 及类似工具,可以让约占经济85%的非科技行业达到硅谷级别的自动化能力。
变化更大的是工程技能的去向,而不是技能本身的价值。计算机科学毕业生可能加入 John Deere、Caterpillar 或 Eli Lilly,而不是 Google;他们会自动化药物研发、农业或工业设备,而不是“做一个带几个小按钮的小应用”。
法律行业体现了其中的运行机制:AI 让客户能够生成更多合同、备忘录和案件材料,律师因此会被更多审核工作淹没。法院不会更快批准文件,专利仍需要承担责任的专业人士审核,因此 Levie 愿意“站到另一边”:5年后律师会更多。
主持人追问初级法律岗位是否会消失;Levie 承认,AI 移除传统入门级任务后,律所和银行确实面临学徒培养问题。但患者转诊自动化说明了他的区分:如果专科预约仍要等18个月,真正的约束仍然是医生和机构容量。
3. “Agent operators” 会成为企业新职业
Levie 谨慎地讨论了这一岗位:它可能长期作为全职职位存在,也可能分散到其他工作中;但他对需求规模毫不含糊——某种形式的“agent operator”可能创造50万至100万个岗位。这些人需要理解 MCPs、CLIs、skills、AGENTS.md 文件以及背后的 AI 生态。
这些人会嵌入营销、法律、运营或生命科学研究团队,职责是重构业务流程本身:“工作流需要为 agents 重设计,而不是为人重设计。”核心决策将变成:由人在哪里审核、批准并为 agent 的产出承担责任。
财富1000强企业部署 AI,需要变革管理、结构化数据、系统连接和持续技术维护。新模型的提示词或索引偏好一旦变化,就可能破坏既有工作流;因此人才来源可能是 IT、运营或工程,而不是某个现成职业。
4. 决定 SaaS 价值的是可供 agents 调用的业务逻辑,而非界面数量
Levie 承认,一些按钮密集型 SaaS 产品确实脆弱:拥有“93项功能”的软件,部分价值可能来自用户对界面的熟悉。agents 取代这些点击后,价值会转向 API;但 API 数量本身不如专有逻辑、安全性和权限体系重要。
ERP 不只是数据库,它编码了不会消失的供应链自动化和会计规则。agents 可能无界面地穿梭于 ERP、CRM、HR 和文档系统之间;而只要人还需要检查、协作或批准工作,应用就仍会存在。
Levie 明确改变了看法:过去一年,他越来越确信软件将走向无界面化。两三年前,agents 经常找错文档,也无法稳定打开和解读文件;tool-calling 和跨系统搜索的进步速度超出了他的预期。
对 Box 而言,agents 是其 API 密集型模式的放大器,而 Box 原本处理的机器活动就远多于可见的用户交互。每个 agent 究竟贡献多少收入仍不确定,但当 agents 生成合同、营销素材和报告时,调用量增加100倍或1,000倍,会显著扩大机会;这些内容都需要安全、治理和符合 FINRA 要求的留存。
5. 算力进入运营预算,网络安全风险持续叠加
AI 生成代码带来的风险首先来自数量:当 agents 接近编写90%或95%的代码时,每个上线功能都可能意外暴露端口,或制造新的漏洞。攻击者也能更快进行互联网规模扫描,防御型代码审查 agents 成为唯一的对冲收益。
Levie 并不是最近才开始担忧;自 GitHub Copilot 在大约5至6年前开始生成代码后,他就认为网络安全后果已经被市场计入。但这种攻防不对称仍支持企业大笔投入 agentic security:“Agents 是 agents 制造的问题的解决方案。”
Token 分配将围绕企业价值,而不是平均主义。可能的做法包括以《Shark Tank》式路演争取算力,以及按用户分层:价值最高的5-10%用户无限使用最强模型,下一层用户使用受限的高效模型,普通生产力场景则使用够用的最低价模型。
决定性的预算迁移,是从企业 IT 支出转向日常 OpEx。企业可以在下一轮营销活动和自动化营销引擎之间做取舍;Levie 认为,这种能够调用类似劳动力预算的能力“当然可能让”科技支出翻倍,但明确反对简单套用10倍增长。
6. 企业普及将带来长达10年的服务与责任工作
主持人担心,当前需求拉动可能只是每家公司都需要讲一个 AI 故事所带来的18个月短期脉冲。Levie 押注相反方向:云计算看似早期爆发,却扩张了20年;AI 的普及会比硅谷预期更慢,因为受监管工作流不可能一夜之间移除审核。
如果错误建议可能让银行丢掉牌照,银行就不能让 agent 自主生成每一份客户方案。Levie 亲自使用最新模型时,仍需要修改约15%的产出,这说明企业需要大规模设计人机协同工作流,而不是立即裁员。
他同意,企业销售“归根结底确实需要 FDE 式模式”,但不认为这与产品驱动增长冲突。AI 服务的规模和持续性都将高于市场原先的假设,因为企业需要系统集成、数据整理、工作流梳理和变革管理。
一次合同风险查询可能触及10个系统,包括网络共享盘和遗留存储库;数据割裂会导致 agent 找错文档或合同。Levie 称,这类清理和重构是“Accenture 未来10年的工作”,也可能属于专注特定行业和工作流的新一代服务商。
7. 责任机制会让人、公司和机构继续留在流程中
主持人给出了服务业最直白的逻辑:公司需要“一个可以怪罪的人”,就像客户聘请律师,部分原因也是 NDA 出问题时责任必须落到某个人身上。Levie 同意,数据损坏或发生安全漏洞后,客户不会接受“Anthropic 犯了错”。
一旦存在责任,所有权和汇报结构就会随之形成。人类行为、合同法和监管制度并没有发生根本变化;只是计算机被交付了“一挺机枪”,可以利用我们的全部数据生成更多信息和工作。
谈到中国开源模型,Levie 表示硅谷从中受益“从经验上看必然是真的”。他保留了一个前提:权重或参数可能存在可被触发的后门;但他没有接受主持人的警报式判断,并强调,即使是最强的前沿模型,也仍需要有人承担责任并进行审核。
8. 软件将出现分化,前沿实验室与 agent 基础设施继续扩张
Jason Lemkin 的挑衅是:上市公司做出来的 agents 普遍平庸,Palantir 是例外。Levie 不完全认同,认为 Box 拥有最好的内容 agent,并表示如今的行业领导者必须跟进那些讨论 memory 和 harnesses 的一线实践者,而不是等两周看传统媒体的复盘。
技术迭代速度让 Levie 的工作比过去更难:产品、战略和合作关系一周内可能被改变数次。上市公司 CEO 周末用 cloud code 和 Codex 构建产品,同时还要给行动缓慢的客户“通往未来的桥梁”。对构建者而言,这一年将是“彻底且不间断的执行”。
Box 表示,其融合工作流、自动化、应用开发和 agents 的新套餐,已经在去年带来收入增长拐点。但华尔街仍在等待行业最终落位;Levie 预计,软件股不加区分的定价会在1至2年内分化,对于应对得当的公司,3倍自由现金流“低得激进”。
要判断 OpenAI 和 Anthropic 谁胜出“根本不可能”:2010年 AWS 收入只有5亿美元,Azure 刚刚推出,GCP 还只是 Google App Engine;15年后,云计算已经成为数千亿美元规模的生态。Levie 预计企业会采用多个供应商,仍愿意投资前沿模型融资,同时看好跨实验室基础设施,例如 Braintrust 这类能够发现 agents 突然无法正确处理贷款发放文件的评测系统。
I would still probably be loading up on all of the frontier rounds. These numbers could continue to get much larger.
Now, I think Aaron Levie is one of the luminaries on AI at Paved Enterprise. He did a viral tweet the other night, and I said, “Dude, we’ve got to do a show on this.” This is specifically on how AI will impact the biggest enterprise in the world and how agents will be introduced into the largest enterprises. We couldn’t have anyone better than Aaron, founder and CEO of Box, one of the public companies of the last decade. This is an incredible discussion.
What we are in is a commercial and economic race. We haven’t removed humans from the loop. We’ve just changed where they enter the loop. Everybody is so myopic about this. I want to just shake the industry.
There are going to be more lawyers in the next 5 years than we have today. The workflow needs to be redesigned for agents, not for people. The budget of tokens will have to move out of IT spend and into regular OpEx spend.
Is your job harder than ever?
Yes. If you’re in software or infrastructure or building agents, it’s a year of complete, unrelenting execution.
Aaron, dude, it’s so lovely to have you on the show. You know that we have Rory on every week, and he’s just like, “Aaron is the greatest.” I’m not going to do his accent because I suck at them. He’s like, “The greatest.”
You can’t easily do an Irish accent.
Well, I can’t really do the Irish accent so well. But exactly. You basically, I’m sure, bought Rory one of his houses, so no wonder he’s grateful.
We got more out of Rory than he got out of us.
An exceptional man. But I wanted to start with what we were just chatting about. I was running around the park listening to the Dwarkesh and Jensen episode, and I was like, “I don’t think Jensen came out very well.” Do you agree with me that Jensen didn’t come out very well from that episode?
I think this is the greatest Rorschach test of all time of where somebody is mentally on AI. I happened to see a bunch of the tweets before I watched it, so I was a little bit biased in advance. But if I hadn’t seen any of the commentary and had just watched it, I would have been very confused by the commentary post-interview. To be clear, I kind of jumped to the more salacious part of China and that topic, but I’m probably 80% with Jensen.
My way of thinking through the logic actually works much closer to Jensen’s. The idea that we’re in some kind of existential race where a month or 2 of advantage is going to change the total outcome of AI progress, and whatever everybody does between us and China, I just don’t agree with.
I think what we are in is a commercial and economic race, obviously with safety built into that. There’s no question. I think we actually have a lot more power globally if it’s our technology stack that’s powering AI. So I’m more in Jensen’s camp on his lines of logic, though he oversimplified a few components.
He said, “With mythos, if we get early access to that, then we can go and upgrade all of our systems.” Again, with great respect to Dwarkesh, upgrading software is a multiyear effort. Unless they somehow keep models closed for the next decade, there’s not some magical moment where you can just secure everything.
This is an ongoing, endless, until-the-end-of-time leapfrogging between the defensive side and the offensive side. I just don’t think these things are as binary, so I’m more inclined to Jensen’s view of that.
Jensen had a really key point that didn’t go viral yet. Maybe you could kick it off, but he had this small vignette, about 90 seconds in the whole conversation, where he said, “We’re going to do ourselves a disservice if we scare people out of engineering, if we scare people out of radiology, if we scare people out of health care because they think all these jobs are going to get eliminated with AI. That is not helping us. It’s doing a disservice to the next generation. It’s doing a disservice to society as a whole.”
We don’t yet know any way to use AI in a capacity other than augmenting our work, where we still eventually have to go and review the work in some form. Maybe you don’t have to review the tiny little parts of it anymore; you can review a bigger part of the work product that happens. But we haven’t removed humans from the loop. We’ve just changed where they enter the loop.
I think Jensen has a more pragmatic view of the technology. We should be very thoughtful about how we make these systems safe, but I land much more in Jensen’s camp on the overall contours of the debate.
Oh, Jesus, dude. You didn’t leave me. I was quite a long way away there.
I just had a coffee. Okay, I’m sorry.
Okay, first: if you discourage people from going into categories like radiology or engineering, do you think you will have more engineers in 5 years’ time?
We will, and I think the part that everybody misses is that everybody is so myopic about this. I want to just shake the industry. We are so myopic and self-interested, and we think that the entire industry is the tech industry.
When you go around the country or the world and talk to a tractor company, a bank, and a pharma company, and ask them, “Do you think you have enough engineers to automate what is going to happen in your industry going forward?” they absolutely, unequivocally, universally always say no.
What the breakthroughs of cloud code or Codex or others are doing is making it so those companies can now do the same kind of engineering that Silicon Valley has been able to do. We are myopic because we think tech is the only use of engineers.
Tech is only—I don’t know what the right number is—8%, 10%, 12%, 15% of GDP in the economy. What happens when 85% of the economy now gets access to engineering like tech has always had? That is what will happen.
Maybe if you’re graduating from, name your computer science school, today, you don’t go immediately to Google. You go to literally John Deere or Caterpillar or Eli Lilly, but the skills that you have are going to be just as relevant in a different domain.
You’re not going to be building a little app with little buttons. You’re going to be automating pharmaceutical research. You’re going to be doing AI for the future of farming and industrial equipment. So we’re just too myopic about how this works.
You can already start to see this playing out. There was a really funny FT article about lawyers being inundated by all of these AI responses that they’re now getting from their clients saying, “Hey, can you review this contract? Can you review this memo? Can you look at this case?”
Well, guess what happens when everybody thinks that they’re a lawyer? Do you know what the ultimate constraint is? The ultimate constraint is the actual number of lawyers that are able to review all of this stuff being produced.
So I would take the other side. There are going to be more lawyers in the next 5 years than we have today because we’ve made it easy to generate legal content, but it has not gotten any easier to get any of that approved by a court system, file a patent, or do any of the things that law actually ends up relating to. So, again, this is where I differ from the rest of the industry.
Do you really think so? With the greatest of respect, we’ve all seen the eradication of lower-ranking legal positions.
That is a different issue, which is how you do the next generation of mentorship and apprenticeship when AI automates the traditional tasks that those workers are doing. That’s a big question, a big question facing every bank in the world, every law firm in the world, and anybody who had an apprenticeship model.
I don’t doubt that’s a real issue, but that’s different from the constraints that all of this work ends up resulting in, which you still have not been able to automate. We had a customer conversation 2 weeks ago, and this is just going to sit with me forever. I always have this example.
They’ve automated—or they’re working on automating—patient referrals. When you want to go and see the radiologist or the high-end doctor for whatever issue you have, they’re automating that, which is awesome. Now you don’t have to be on the phone for a week or whatever.
Well, guess what? You can automate anything, but if it’s still 18 months out before an appointment is available, your ultimate constraint is still the health care institution, the number of doctors we have, and actually the amount of real labor we have across those organizations.
So, yes, maybe you don’t want to stake your career on being a frontline customer service rep in health care right now, but first of all, that same person will have a lot of other types of jobs that they’ll have access to.
You will still end up having all of these other constraints that eventually we will need to produce more and more jobs to go and resolve. Automation is going to actually just force us to see the next set of bottlenecks in all of these industries that we didn’t perceive we had before because everything was so slow and manual.
What job title does not exist today that will be incredibly prominent in 5 years' time?
Yeah. I'm workshopping this, and a bunch of people are doing this, so this is not my invention. But I'm workshopping—
Aaron, you’ve got to take attribution. As a venture investor, it’s all about coining a term, okay? This was your original thought, having it in the shower: Aaron Levie’s. Share it with me.
I've been influenced by nothing I've seen online. This is all from me.
There’s some kind of role—and who knows if this sustains as a full-time role or where it gets diffused into—but there is 100% a role right now that there are going to be 500,000 to 1 million jobs created for. It’s basically some kind of agent operator.
This person is going to need to be somewhat technical. They’re going to have to be deep in the AI world. They’re going to have to understand MCPs and CLIs, know how to write skills, and understand AGENTS.md files.
It’s going to be this group of people who know how to go into your marketing team, legal team, operations team, or life sciences research team. This is the person who is basically going to enable that function to get leverage from agents.
The problem that the real world has, which startups and frankly many of your guests don’t understand, is that when you start a company from scratch, the world is your oyster. You can design your workflows however you want. There’s really no risk if something goes wrong because you don’t have much scale to begin with. There’s no real regulator calling on you to say, “Hey, are you doing things the right way?” It’s effectively infinite upside and white space.
When you go into a Fortune 1000 pharma company, bank, or consultancy, that’s just not the case. These companies are regulated, they have data fragmented across their organization, and they have employees who are wired to do workflows a particular way.
There needs to be somebody who can basically say, “Hey, if we actually want to get real leverage from automation, we need to start to redesign the workflow that we’re doing.” The workflow needs to be redesigned for agents, not for people.
What do you do when you reimagine a business process where the agent is now doing much more of the work than the human used to do in that process? That means it’s a very different implementation cycle. There’s real change management. You’ve got to get data organized in the right way, and you’ve got to connect systems in the right way.
Guess what? The second a new model drops, your workflow probably breaks because the way you prompt that agent is now different. There’s a different way that it wants its index to be handled. It just requires care and feeding, as well as a real level of technical and business process acumen.
I think we’re going to create an untold amount of jobs that look like that. Some of those people will come from IT. Some will come from operations. Some will come from engineering.
If you’re in a more technically inclined company, there’s a limit to the number of software products you need to build that look like an app on your phone. There’s an unlimited amount of software you need to build that looks like a background system process connecting different data sources and automating workflows. That’s where the work is going to go.
But this was really going to be one of my main questions. Jensen Huang very clearly said, “AI won’t kill software. It will exploit the amount of software needed.”
When I thought about that, the thesis there is obviously that you have this core AI that crawls over 15 SaaS tools, and they really become databases that agents crawl on top of. Is that what it looks like? Are they not just valueless SaaS tools then?
Yeah, I’m sympathetic to that argument in some categories. I think there’s some software where, because the person was the user of the software and they were clicking all the buttons, the ratio of buttons to underlying APIs was more in favor of buttons. I’m oversimplifying, but there are some tools where you open them up and there are 93 features that you’re clicking around on, and the user has been so accustomed to exactly how to do that that the software’s value proposition was correlated to roughly that mass.
In a world of APIs, and a world of agents being able to do more of the work that you used to do by clicking those buttons, the value goes more to the API layer. The question then becomes: How many APIs do you have? Not that you just need 1,000 APIs, but how robust, useful, and proprietary are they? How much business logic is embedded in those APIs versus them just calling a database and pulling a record?
Does the API surround a set of business logic? Does it secure the data, or know exactly which person each piece of information should be accessible to inside the organization?
At the end of the day, all software has a database behind it. You could oversimplify it and be quite reductive about that, but there’s a lot of business logic in the layer above the database that software players have.
If you’re an ERP system, you’re way more than a database at this point because you’ve written a tremendous amount of business logic about how your supply chain should be automated and work, and how you should do accounting. None of that goes away.
The question is: What changes? The user interface that either the user or the workflow is interacting with changes. The user interface might now be that you’re just chatting with an agent.
I think increasingly the right way to do this is to have some kind of agent in the background connecting multiple systems. The user may not even see half the value that’s happening, but the agent is working across an ERP system, a CRM system, an HR system, a document repository, and doing work across those systems.
That means the value proposition has to be: How good are your APIs? How well designed are they? Are they ready for agents? And then can you monetize that in some way that makes sense?
We’re treating software too much like one gigantic, monolithic industry. It would probably be better to have some kind of 2-by-2: How much business logic is there, and how much human-to-agent collaboration needs to happen?
The reason I bring that up is that the moment you have human-and-agent collaboration, you usually need something that the user can pop into to experience the work that the agent did. That probably doesn’t go away so much.
When more agents are working on the software, which parts of the software do agents need those APIs for even more than humans ever did? I think there are a lot of categories of software where agents using the tools is a massive boon for the technology, as opposed to a dilemma.
Where will agents use the tools more than humans do, and those API calls become much more frequent?
Yeah, an easy one is just unstructured data. Agents are going to be an incredible consumer and creator of your unstructured data. They’re going to read through every one of your contracts and generate all of your contracts. They’re going to generate marketing assets and write reports for you.
When it becomes trivially easy for you to generate all this new information or have agents review it all, guess what? You still need a backbone that manages and coordinates those workflows and creates the guardrails for all the agents doing that work. We’re about to see an explosion of unstructured data, as an example.
With the greatest respect, Aaron, can I actually suggest—
100%.
Does that increase the value of your business? When I think about it, I asked Aaron from monday.com: If you become a data repository that agents crawl on top of, how do you retain value in that? I would ask the same to you.
Yeah, 100%. It’s the question on the mind of every investor on the planet right now. We’re used to it, and it’s not a scary question.
One thing that helps us is that we’ve always had an API—maybe not first, but equal—strategy. If I told you the number of API calls we did last year, and you guessed first, you’d probably be off by an order of magnitude.
The volume of API usage on our system is already enormous and already outsized relative to any of the end-user interactions on the system. That’s just a virtue of the fact that you use content in a variety of applications and workflows that far exceed what people do when they open up their Finder and upload a document.
An ERP system generates files. A wealth management portal has clients uploading documents into the portal, and they never see Box. You have invoice-processing workflows happening behind the scenes.
The headless version of Box has been alive and well for almost as long as we’ve been in business.
And so agents, to me, represent a force multiplier on that. It’s actually an exciting proposition for us. We already know how to monetize it. The question is: will the exact dollars and cents be the same between an agent user and a previous application user? We don’t know.
But we do know that if the number goes up by 100x or 1,000x, that’s actually more opportunity for us in the future. That’s not the same for all software providers. But for where we sit in the workflow—where you generate a document, it needs to go somewhere, you have to secure and protect it, and you have to govern it over the long run—that’s just more data going into our platform. That’s why it’s all upside for us.
You said “secure and protect it.” We mentioned our mutual love for Rory O’Driscoll. I do a show with Rory and Jason every week. Jason has bluntly said that this will be the golden age for cybersecurity because the security threats are going through the roof. Are you concerned with the system vulnerabilities and security threats that are coming with AI? What do we not know about security that we should know?
I am concerned, but not in any kind of new-concern sense. This, to me, was priced in the moment we were generating code with AI. If you can generate code, you have 2 problems. One, you’re going to generate way more code than anybody’s ability to review that code.
Starting with GitHub Copilot 6 years ago—or whatever the date was, 5 years ago—that was just priced in. As soon as AI writes most of the code, and then 90% of the code, and then 95% of the code, by volume we’re going to produce this unbelievable amount of code. Any change in a system gives you a chance of a security vulnerability.
Everybody thinks about security as, “Is there a zero-day where there was an unpatched component of your technology, or somebody found a clever new package that you could slip into?” Every time you ship a new feature, you have a chance of a security vulnerability because the AI could have written in, “Oh, we want to actually open up that port in the system because we need to do something.” Maybe that was the wrong decision for the agent to make.
We are going to be living in this new world of cyber risk in the form of using more agents. On the other side, obviously, if you have the offensive side able to use AI—probably more in the form of open models and whatnot—then they can find more vulnerabilities because they can scan across the internet far faster than before.
You actually have 2 new forms of risk in the development process, and you only have 1 benefit, which is that agents can also review the code and try to keep it secure. It’s going to be a very dynamic period. I think, for better or worse, agents are the solution to the problem that agents have caused, and that’s why there’s going to be a lot of money made in agentic security as well.
You said agents are the solution to the problem that agents have caused. It almost reminded me of when Jensen went on TV and was like, “Every engineer should be spending”—I can’t remember the amount. I think it was either $250,000 or $500,000.
Yeah, or like half the salary, essentially.
It’s like, “Drug dealer, you should buy drugs.” Well, okay. No [__].
Again, I mean, Jensen—anyway, we love Jensen for that level of grandiosity and charisma. Whether he’s off by half or not, directionally the idea is pretty salient, which is that you’re going to be spending more on compute per person in the future than you ever thought, and certainly more than you are today.
What percentage of salary are you going to spend on compute at Box in 5 years?
Great question. I don’t think we’ve modeled that out in 5 years, and obviously the joy of being public is—
—is your chance.
No, totally. I was told not to model long-term financial projections on podcasts, so let me—yeah, it’s a weird SEC financial thing. Don’t ever go public if you don’t want to model on podcasts.
This is why the Collisons don’t. Everything else is great. They just didn’t podcast. Cheeky planning.
I don’t know if you’d be able to pin Patrick or John on the same question for their 5-year view, but it’ll be a larger number for sure than it is today.
I’ll smash them with 4 tequilas and then ask them. You said one of your observations in your very viral tweet was about token maxing and token allocations within enterprises. I’m really intrigued. How do you think about advising CIOs on token allocation and token maxing? What should we know that we don’t know? How do you think about that?
This one’s tough. The general advice will end up sounding generic by definition. Your token allocation will have to correlate to where the most value is generated for your company. It’s the most bland statement of all time, but it obviously has to be true.
In the software industry, we’re into token maxing because generally the value proposition of your company will correlate to how much software you can produce. If you’re trying to drive a lot of change, and you want to make sure everybody’s shipping lots of software and teach the best practices faster, then token maxing and leaderboards are an interesting way to do that.
It’s not obvious that you’re going to see that across every industry. We’ve seen a couple of interesting examples. One company had this sort of Shark Tank pitchathon-type thing, where teams have to show up and pitch for compute and a token budget. Then you allocate it in some central fashion, like a VC would.
I don’t know their exact interval, but I would imagine you review that 3 or 6 months in, saying, “Okay, did you get the upside that you thought you would get from that token usage?” That’s an interesting one.
Another company had a view of natural stratification: 5% of your users are doing the most valuable things, 20% are doing the next tier of most valuable things, and everybody else is doing general productivity. I’m making up the numbers, but the idea would then be: for that 5% or 10%, give them the best models with unlimited capacity.
For the next 20%, have some limits. Maybe it’s a little bit more efficient of a model. For everybody else, we’re going to use the cheapest thing on the market. It’s not going to be the game changer of employee productivity. Everybody’s working their way through this.
The part that, back to Silicon Valley, is sometimes a more positively naive view is that, in the real world, they have budgets and annual budget-planning cycles because they have EPS numbers and they commit to Wall Street. You don’t get to say, “We’re going to token-max across the enterprise, where everybody gets unlimited token budgets,” because that company would just miss its earnings throughout the year.
You have to wait for the earnings, wait for the budget cycle, and figure out which teams are most interested and have the best use cases. That’s a natural learning.
One final bookmark that I think is well understood now is that the budget for tokens will have to move out of IT spend and into regular OPEX spend. This can’t be treated like, “I’m going to trade off between Salesforce licenses and compute tokens.” It’s going to be more like, “I’m going to trade off this next marketing campaign, and instead I’m going to drive more automation in our marketing engine.” It’s going to be that kind of set of trade-offs.
What happens to that token budget when it transitions to a different spend category?
Well, first of all, it goes up, because IT spend as a percentage of revenue of large enterprises is—
This is the same as the classic VC blog post, which every [__] firm has written: “AI: It’s moving from software budgets to labor budgets.” Every partner goes and writes the tweet, and there’s like no [__] [__]. Really?
Yeah. If you do it in that voice, it sounds kind of simple, but that’s a very big deal in technology. We’ve never had—there’s never, or rarely, been a technology that you could sell into an enterprise where you weren’t capped by that company’s corporate IT budget.
Now, for the first time ever, you have a technology where you can go into the line of business and say, “I can now offer you a new tool in the form of an agent that will augment a workflow and make you 50% or 100% more productive.” Maybe I should be able to get 5% of your OPEX budget this year to go and do that.
That is a new budget to tap into, and I don't think it 10×s the size of IT spend or technology spend globally, but it certainly doubles it.
I mean, total enterprise technology spend is estimated at between 10% and 12%. To see that going to 20%, as you said, is relatively feasible. You said that companies are based on earnings per share and actually have budgets they have to adhere to. It's very strange not to have venture-funded companies.
Yeah, they don't have unlimited VC. They want to go and solve this.
Can't we just go to our venture investor and ask for more money?
The one thing that I worry about is that we see this insane demand-side pull. Every company in the world needs an AI story. Everyone wants to kick the tires with something, and I think we project the same demand-side pull and extrapolate it continuously. Do you worry that we are in a momentary 18-month period of demand-side pull and that it may not always last?
It's very possible. I should be more sensitive to that. But I would take the opposite side of that particular wager at the moment, partly because we already saw one diffusion cycle with cloud and how long that ended up taking, as well as the spiky early nature of it. You would have just been like, "Oh my God, this is on fire. How could this last?" Twenty years later, it lasted and got way bigger than we ever realized.
If it works, the market is always larger than you ever think. The only reason why 18 months is not even a relevant window to me is that I think diffusion is going to take longer than Silicon Valley thinks. It goes back to that very first new-role idea. When you go to most companies, they can't yet just deploy an agent to do full financial proposals for all of their clients without a human reviewing them, because the SEC will just show up and be like, "Hey, you just gave this person bad financial advice, and you're going to lose your license." That will just start to happen across the board.
That's why people take time. That's why there are a lot of regulatory controls, and compliance teams and security teams have to figure this out. That just takes time in the economy.
I had, I think, Matt Fitzpatrick from Invisible, which is like a Turing or a McCool competitor. He said, "You cannot sell into enterprise without an FDE model. It is impossible."
I mean, it rounds to being true. So, yeah.
It's super interesting to hear that, because we're seeing the rise of, "Oh, we go PLG and then we seep up into enterprise."
Well, I don't think of those as mutually exclusive, for what it's worth.
I guess what I'm saying is, when you think about adoption within the largest enterprises, are AI services companies the best-positioned companies of the next 5 years?
As in, you're saying traditional professional services?
Yeah, I'm saying Accenture's AI team that comes into Bank of America.
No, 100%. These spaces are going to be both bigger and more sustainable and robust than people realize.
We are always so myopic. Back to the myopic thing, we're like, "AI will replace all of this stuff because it just does it for you." I'm trying to think of my most recent experience with the best models in the world: I probably had to go and change 15% of the thing that was the output. We're nowhere near eliminating the human from the workflow.
In a world where you don't eliminate the human, there is a lot of real change management. Where should the human enter that business process? How would you want to review that work output? How do you wire up your systems to make them effective for agent-and-human collaboration? How do you connect all of these data sources together?
One thing that we see is that if you wanted an agent right now in a Fortune 500 company to give you an answer to where you have the most risk in your upcoming contract renewals, that agent might find 10 different systems that contain contracts. Half of those systems will be legacy technologies that don't work well with the agent. They have low throughput, or maybe you can't even wire them up. They're on network file shares or in legacy document management systems. First of all, half of your data estate is not even ready to work with the agent.
The other half of the data estate is probably fragmented because you have 2 decades of employees bringing their own tools. The agent will find the wrong document, the wrong contract, or the wrong piece of data because you never really cared to have a standardized system for your contracts. People could always go and find what they were looking for.
Agents can't do that. They'll find what they're looking for, but they'll just as often find the wrong thing as the right thing. They have to be targeted. They have to have that information curated. They need to understand the context of the process they're doing.
What I just described is 10 years of work for Accenture and every enterprise on the planet, or for the next-generation Accenture that does this in particular industries or workflows. We have to upgrade your systems. We have to start to understand and organize your data in the right way. We have to start to describe these workflows to the agent itself. We have to figure out where the human is in the process. That is real change management that every enterprise will have to go through.
We also have to have someone to blame.
Exactly.
No, 100%.
This is why a lot of these industries exist. I have lawyers not because I can't necessarily write an NDA; it's because it's your freaking fault if anything goes wrong.
Yes, no, literally. I promise you, you're not going to be able to blame Anthropic when something goes wrong. If you can't blame Anthropic when something goes wrong, then at some point it doesn't really work to tell your customer, "That sort of system that we set up screwed up your data, automated something the wrong way, or created a security vulnerability." The company will just say, "Well, I'm never working with you again."
Then you have to have some accountability in your own organization for who is liable when something goes wrong. The moment you have to have any liability, you have to have some amount of ownership and accountability. People have to roll up to somebody who has more liability, more ownership, and more accountability.
This hasn't really changed the fundamental pattern of human behavior, contract law, and the regulatory regimes that everybody is a part of. We've just given our computers a machine gun to generate way more information and work with all of our data.
You said before, when I've tried the latest model, it's got about 85% of the way there. I speak to many of the best early-stage and more mature West Coast-based companies, and they say, "We use frontier models to set where we can be, and then we use open-source Chinese models to get as close as we can to that frontier benchmark." Is Silicon Valley being funded by a generation of open, CCP-funded models?
That must be empirically true. I don't have the same kind of "Oh, that's so scary" element. Obviously, I'm holding out some element of risk from backdoor weights that can get triggered at some moment, or some parameters. But that's not how I'm perceiving it.
That's also orthogonal to my point that the best frontier models still will do the wrong thing. Thus, I have to be in the workflow loop to make sure that I review their work.
As a venture investor, I specialize in making bold statements with little substantive evidence.
It worked for the greats.
Do you know what? I'm just following their lead. Jason Lemkin, my dear friend, says, "Why has no public company created any good agent product? Everyone creates 60% [bleep] agents." But he says the one company that's done it is Palantir, and no other public company has created a sufficiently good agent product. Why is that?
I don't know that I can fully endorse the point, but I can give you the reason: I would argue that our agent is the best agent for working with content. This is a very fast-moving space, and you have to be wired in at a level that I don't think you've ever had to be wired into in tech.
The information sources aren't the classic ones. It's not the roundup review 2 weeks later from a traditional news publication that's going to give you any kind of alpha. It's the practitioner who's literally the engineer at the agent sandbox company, and their long-form article on how they're handling memory and the harness. If you're not wired into that ecosystem, it's very hard to have your team be at the forefront of everything that's happening.
It’s just a different pattern than what we’ve ever had to do. COVID was pretty crazy. We all had to hunker down and pay attention to daily news cycles on COVID-related stuff. But it wasn’t a tech problem; it wasn’t hard technologically. There hasn’t been a moment before where the speed of change and the responsiveness you have to have is quite literally on a multiple-times-a-week cycle.
Is your job harder than ever?
Yes.
Because of that speed, that transience, and the superiority of technology?
Yes. You basically have this component of, one, there’s a tsunami of change that you can just feel. You’re like, “Okay, we’ve got to run faster than ever before.” Then there are the pure technical underpinnings, some of which have business and strategy implications, some of which have product implications, and some of which have partner ecosystem implications.
Because of that tsunami, you have to very quickly wire up what you’re doing about that shift and where the market is going. At the exact same time, you have to find a way to be a bridge for your customers, who also don’t want to get crashed into by the tsunami. They want to be able to have a bridge into the future. You’re juggling a lot right now.
You said your agent product is the best product. Again, Jason Amroy said this, and Jason might kill me for this because he gets a little bit more sensitive about when I quote him—or misquote him, more appropriately—but he basically says this. This is Jason again: “If you can’t charge way more for your agent product, Wall Street doesn’t give a shit. You have to reaccelerate revenue with agent products.” Can you charge significantly more for an agent product?
The answer is yes, but there’s a little bit of nuance. Our business model is a new plan tier that we introduced last year, which houses our best workflow capabilities, our business automation, and our application development capabilities. The agent is central to that because it’s going to help you automate the work that you’re actually doing with your content. It’ll read a document and extract metadata from it, and it’ll process information inside a workflow.
That is causing a real reacceleration of our revenue growth. Last year, we saw an inflection in our revenue growth, so it’s already happening in our business. We’re doing the thing that I think Jason is probably saying is the new benchmark.
To be fair to what’s happening, though, I think Wall Street is still saying, “We kind of need to step back and see where everybody lands in this,” because of how much change there is. This is very much a year where, if you’re in software or infrastructure or building agents, you’ve got a year of complete, unrelenting execution.
Do you look at the ticker?
Yeah.
Every day?
Yeah, but I was like a day trader.
I’ve never met a public company CEO who hasn’t. The Navan CEO was on the other day, and he said, “Multiple times a day.” Multiple, multiple.
Yeah, no, 100%. Partly, I just have ADHD or something.
When we look back on this period, will we be like, “What the fuck? Companies trading at 3 times cash flow”—way overexaggerated or not?
3 times cash flow is very much overexaggerated. I would say that we’re in a period right now where the market is being treated roughly as an indiscriminately bucketed sector. Over the next year or 2, you’ll start to see some separation and parsing between the companies because, as I noted in the beginning, agents will be really good for some parts of software, and agents will put pressure on other parts of software.
It’ll mean some companies have to fully pivot, and some companies can just ride the wave. If they respond effectively, clearly 3 times free cash flow seems like aggressively low territory. But I also think that, at times in software, things have been aggressively overvalued beyond the realm of what the likely terminal value is of a particular category or company.
I think there’s a pendulum that needs to find its equilibrium right now, and that’ll play out over the next year.
Okay, I’m going for spicy. I interview most of the public company CEOs that you know and I know, and Jason Lemkin said on the show, “If Aaron Levie is the best”—you’re a phenomenal AI-first mind and leader, so just roll with me on this—and it gets worse, sorry: even he is struggling.
Wait, wait. Why am I struggling?
Well, I mean—
I just said I’m tired. Wall Street does its thing. We’re cranking.
Dude, it’s Jason. Blame him. Okay. Do you think the generation of CEOs that you have around you is equipped for the AI transformation that is ahead? Because I don’t. I’m not blaming Smartsheet now—I see you all. You’re so versed in this. You’re so fluid. But someone said to me the other day, “No, we don’t have the AI chops in-house. We might need to bring it in.”
This one’s hard. I think you still have a lot of founder-led or tech-forward people, whether they were engineers or they’re just very technical, who are pretty dialed in. I have Slack channels and WhatsApp groups where people on the weekend are just working with cloud code or Codex, building stuff. They’re public company CEOs.
They are clearly wired in and tapped in. They can feel the technology, and they’re not going to let their company lose, assuming that, as a category, they’re in a spot where there’s a lot of upside. But every technology wave has winners and losers. I don’t think this will be any different. You just have to be super dialed in and work through it.
A hard one before we do a quick fire.
Okay.
Who has the world turned its back on who you think should be much more appreciated?
I don’t know. I’ll give a shout-out to Atlassian as an example. I think that feels like oversold territory.
878% is a bit harsh.
I think possibly. It’s in the category of—I just think they’ve been fighting this narrative, and I’m not going to speak too much for them, but what I perceive is, “Oh no, engineering gets commoditized.” So where in the stack was their engineering revenue generation?
Again, with my mindset, I’m like, “No, there are going to be more engineers.” Does that mean Atlassian’s product set will look exactly as it does today? No, obviously it has to evolve. But if you’re a company selling infrastructure for engineering to be more automated, that seems like a good spot to be in.
You look at what Linear is doing, and it’s fantastic and awesome to watch. But I think there will be multiple plays in that space, given how big the market is. Right now, this is a moment where you need to be deep in the workflow, and you need to have data. You have to have data in your platform, you have to be the best place for that data to go, and you have to be the best place where agents want to work with that data.
That’s the mandate right now. If you are not the best place that an agent would intentionally choose for working with data of that particular category or automating the workflow in that particular area, that’s a tough spot to be in. That’s the job for all of us if we’re building software.
The best place where agents want to work is defined by great APIs?
Great APIs, great pricing models, and the surrounding features to the API. If you were to say, “I want to be able to wire up a workflow where an agent is interacting with FINRA-compliant documents”—a FINRA-compliant document means the things that get generated, seen, or shared with a customer can’t ever be deleted or removed for a certain amount of time—then, on one hand, the API has to be super clean for the agent.
On the other hand, you have to have a bunch of surrounding capabilities to ensure that the company can go to its regulator or auditor and say, “Yeah, we are complying with FINRA.” That combination is what makes it so you would build that kind of agent on something like Box, and that persists across a variety of industries.
I’m going to do a quick-fire round with you. You have to go and be a public company CEO, I know. What have you changed your mind on most significantly in the last 12 months?
I do think that I’ve become more convinced that software is headless in the past year than I was maybe 3 years ago.
It's because of the level of agentic capabilities in tool calling and searching across systems, and the accuracy of that. That has happened faster than I would have perceived. Two to 3 years ago, if you were to wire up an agent and tell it, “Hey, go work inside of Box and find a document to work with and do some process,” it would almost always find the wrong document, and it wouldn't be able to handle cracking open the file and reading through it.
In the past year, those capabilities have absolutely accelerated to the point where I'm fully convinced that you have to be headless-first as a software platform.
What acquisition did you not make that you wish you had made over the Box journey? Jensen Huang said on the show, “Oh, I wish we'd invested in frontier models. That was my big mistake.” What acquisition did you not make that you wish you had done?
Honestly, I don't think I have any M&A regrets. It's the deals that I wanted to do that we ended up not doing that I don't regret. That's probably more of the situation.
Wait, which one is that?
I can't tell you those, but there are some where, left to my own devices, I would have done them. I look back and I'm like, “Oh, thank God there was more rational logic in the process.”
Who is going to win the enterprise race, OpenAI or Anthropic?
Oh God, that's impossible. Back to the cloud piece, I think it's totally fair to think about it as a race. Certainly, if you're in either of those companies, you have to treat it like a race because you obviously want 80% share, not 55% market share. You have to treat it as, “We've got to dominate.” That's exactly how they should be executing; that way, everything is going according to plan.
If you compare it to other areas of compute—and I ran this analysis recently—in 2010, AWS made $500 million in revenue. Azure had just launched, and GCP was called Google App Engine. It had a little turbine logo with wings or something. That was the state of the cloud.
Fast-forward to this year, and it's a couple-hundred-billion-dollar-a-year revenue ecosystem. In 15 years, we went from being in that moment and saying, “Who's going to win, AWS, Azure, or GCP? How's this all going to play out?” It just turns out the market was so large. Obviously, it was due to their execution that they kept it going and kept it large, and the competition kept up, but it just didn't really matter. Everybody kind of won.
I think of AI in a similar fashion. I can't predict if it's going to be OpenAI at 60% and Anthropic at 40%, if it gets flipped, or if I'm off by another 10% here or there. No matter what, these markets are fantastically large. Companies are going to adopt multiple of these systems. They don't want to be single-vendor in this stack. One service goes down, one changes its APIs, or one has a new commercial model. It's going to be a multivendor, multi-AI world, and that's why it's very hard to call it at this stage.
What does everyone think they know about enterprise adoption with AI that they get totally wrong?
What they think is that the outcomes you're seeing in AI coding will quickly come for other areas of knowledge work. That's a slight misread of the other areas of knowledge work. Some of it is the idiosyncrasies of coding, and some of it is the broad elements of the rest of work and how it happens.
If you were a venture investor today, which category would you be most excited to invest in? Obviously, I'm just—
Yeah.
Hypothetically speaking—
Yeah, but I would still probably be loading up on all of the frontier rounds. These numbers could continue to get much larger.
Get—I mean, much larger? I mean, like, this is where, at $850 billion, you've got like a 3x to a $2.1 trillion-style valuation.
I always think it's hard because I've said that on the way up of many companies.
I did it with crypto. How much further can it go?
Yeah, well, that one I'm going to put in a different category because that can just be memed to life.
No, but I actually think, to the point on Atlassian and companies like yours and your whole category, it's the casinoization of the stock markets. If you're a momentum trader today, you still buy Palantir because the market's a casino right now.
To be a little bit more fair, I think you have some one-off companies that have done an amazing job capturing the zeitgeist on that. I do think the broad story right now is the sector-rotation story. It's, “Hey, this AI thing's happening. Right now, I can get a higher return if I get closer to the semiconductor stack, where the workloads are going, and where the data-center build-out is happening. I get less of a return if I'm in software with pure licensing.”
Some of the data-center and infrastructure names may have been memed also, and that's helping the case. It's just a really weird time overall that's hard to think through.
So, you would not buy all bets on AI companies?
I mean, maybe you would because of that exact point. I think new bird AI, or whatever it's called, will be in the one-off category. But I am still making this as a generic statement: there will still be a lot of money to be made in the companies that can take the innovation we're seeing in Silicon Valley and in the labs and apply it to the real-world work that happens inside enterprises.
Whether that looks like vertical AI or the new kinds of tooling that companies will need, there's a new category emerging around agent observability and evaluations. I'll give a shout-out to Braintrust as an example—not an investor of mine—where I can just sit back and be like, “[Expletive], we thought that agent builders were going to need evals.”
That's a Silicon Valley TAM. Then I'm like, “Oh, actually, everybody on the entire planet, if you're putting agents into an enterprise workflow, needs evals, because you need to know if, all of a sudden, your agent just stopped producing loan-origination documents the right way.”
That's a category where it's probably not going to be owned by one of the labs. You want it to work across all the labs. It's a very relevant new form of infrastructure for an agentic enterprise. I think you're going to see a dozen, 2 dozen, 5 dozen things like that start to emerge.
I've known you for a while now, and you've put up with me for multiple different sessions. I want to finish on something a bit off-script. You're a phenomenal CEO, you're a public-company CEO, and the pressure you have on you is intense. You're also married and have a great relationship.
What's your biggest piece of advice on marriage when it's super—I'm being serious—when it's super stressful, it's hard, and you also have to show up and be a great husband? What's the advice on marriage?
It feels dangerous if I actually acknowledge the great-husband piece and the other parts that were embedded in that. That feels like you need a full 360 eval.
I'll just say from my perspective, I'm very lucky to have an amazing wife and family. You're in a grind in one of these roles, and obviously having a strong support base helps a ton. We try to make time for the fun side of life as much as possible, but obviously that gets constrained in the window that we're in.
I've been with my wife for, I don't know, 15 years or so—16 years—and she's seen the whole grind all the way. She has her own set of grind in her business, and so it's just lots of fun.
Dude, you're my hero. I want to be you when I grow up. Thank you for being so great. I really appreciate it. I was 14 in 2010.
Okay, all right, all right. So I almost called it. I almost called it.
Yeah.