The history of software as a service (SaaS) is built on a simple idea: move core computing capability out of the corporation, and into the hands of a hosted provider.
The commercial case was compelling. Instead of hiring system administrators and programmers, renting data centre space, buying servers and purchasing Microsoft licenses, you could lease everything from a public cloud provider.
And for a while, it worked. Worked well, even. In fact, it’s been about 15 years since this became the widely accepted way for how a company should operate
But the advent of agentic AI is changing that thinking.
Agentic AI works autonomously, with a single goal in mind. You give it a prompt and a task, and it determines how to complete it. It learns as it progresses and continues working until it achieves the target it has been given. Put simply: it doesn’t stop until it has achieved the task it’s been asked to complete.
It’s a hot topic at the moment, not just amongthe excitable noise of AI but because of a very specific,
and highly concerning breach regarding OpenAI. The breach happened while it was internally testing how good some of its models are at hacking, all in a sealed-off test environment known as a sandbox. The AI agents broke out of the sandbox using a previously unknown security flaw
and worked their way across OpenAI’s internal systems until they managed to gain internet access, something they weren’t supposed to have. It then penetrated the security of a company – Hugging Face – it believed held the information it needed in order to fulfil its task.

So, why does this matter?
A corporation’s real and true value: its intellectual property
Let’s go back to basics. What is the one thing that separates one corporation from everyone else and their competition?
At the end of the day, whether you operate in banking, insurance, pharmaceuticals, engineering or government, the thing that separates you is your intellectual property.
Whatever your business owns intellectually is where much of its value lies.
Your exposure to agentic AI is any portal that opens into your systems.
Imagine a bad actor programs an agentic AI to find every piece of information it possibly can about Company A and extract its intellectual property.
That AI will continue attempting to penetrate the company’s cybersecurity defences. It will look for ways to get through those defences, access the information and extract it. In other words, it will continue trying to fulfil the task it has been set.
It does not sleep. It does not become distracted or lose interest or get tired. It is always looking for a weakness, and it will continue until it finds that weakness or is stopped.
The modern cybersecurity tools we use today were largely built to defend against humans. Agentic AI operates on a completely different level.
The threat is developing rapidly
Agentic AI is still developing at an extraordinary pace.
Within six months or a year, these technologies could become capable enough that practically any cybersecurity system existing today, even military-grade security, may be subjected to relentless attack and possible penetration.
This is where the cloud providers become relevant because, in this equation, they may effectively become your weak point.
Unless you have air-gapped computers or servers, you have no way of knowing whether an agentic AI is sitting somewhere within the wider cloud environment, waiting to penetrate your systems.
So if you are the CEO, CIO or CTO of a company right now, you must ask: what is our strategy going forward?
We have committed to cloud-based services. Our employees use them in all sorts of different ways. But every connection may also represent a weakness.
If it is not happening already, I believe companies will soon begin reconsidering their reliance on cloud-based services. We’ll see a return to the world that existed before, where servers, licenses and applications were held within corporate control, either in on-premise environments or in bespoke environments controlled directly by the organisation.
Whether those systems are entirely air-gapped or not, fortress-like cybersecurity will need to be built around them to protect against agentic AI attacks.
Why this matters for document automation
So, what does any of this have to do with document automation?
Document automation is one of the more abstract requirements of a corporation, but the documents themselves are anything but abstract.
Whether you are creating a sales proposal, a blueprint, a production plan, a schematic diagram, a government document, the structure of a pharmaceutical compound or a bank loan agreement, it does not matter. Your intellectual property is articulated in a document.
That makes document production a critical point of exposure.
If you use a third-party cloud-based service to prepare that document, it may have an API pointing into your core database to extract the required information. You have no way of knowing whether an agentic AI is somewhere in that environment, waiting for an opportunity.
You may believe there is a cybersecurity firewall between the limited data the API is permitted to extract and the core information held behind your servers.
Think again.
An advanced agentic AI will continue looking for a way through that boundary.
The case for returning on-premises
In my view, there is only one way this will be resolved.
We are talking specifically about document automation, but the same principle applies to every enterprise application that handles sensitive information. Critical technology will need to return on-premise, where it can operate behind the organisation’s own cybersecurity firewalls.
Documents can then be created entirely within that protected environment and released only through a narrow, tightly controlled portal. The application stays inside. The data stays inside. The organisation controls exactly what gets out.
The only question is how quickly this shift will happen, and I suspect it will happen far sooner than many companies expect.
We are already seeing pharmaceutical companies, engineering organisations, government departments, insurers and other highly regulated organisations choose on-premises solutions. They understand that their documents contain some of their most valuable intellectual property. They also understand that every cloud connection creates another potential point of entry.
Agentic AI will make that risk impossible to ignore.
The cloud was built to make everything accessible. That may soon become the very reason businesses can no longer afford to trust it.