SAM Automation with AI and Cloud Tools: What Actually Works

Software asset management has spent two decades catching up to how organizations actually buy and use technology. AI-assisted discovery, cloud-native reconciliation, and anomaly detection are finally closing that gap—but they’re changing what a SAM analyst does, not replacing the need for one. Here’s what’s actually working, what’s still marketing, and where the discipline is headed.

The Problem AI Is Being Asked to Solve

Stat tiles showing IT asset and AI spend visibility gaps
Source: Flexera 2026 State of ITAM Report.

For most of SAM’s history, the job looked like this: pull data from SCCM or a discovery tool, dump it into a spreadsheet, manually match “MSFT OFFICE 365 E3” to “Microsoft 365 E3” to “O365-E3-NEW,” and hope the effective license position was right by the time the vendor showed up for an audit. That process never scaled well, and it’s breaking down faster now because the estate it’s supposed to describe has changed shape entirely.

Flexera’s 2026 State of ITAM Report, based on a survey of more than 500 technology professionals, found that complete IT asset visibility across organizations dropped to just 36%. That’s not because teams got worse at their jobs. It’s because the mix of on-prem licenses, SaaS subscriptions, container-based deployments, and now AI tooling has outpaced what manual reconciliation can track. The same report found only 31% of organizations have accurate visibility into their AI software spend specifically, even though nearly half already treat AI as its own spend category. Fifty-nine percent said wasted AI spend increased year over year. That’s the gap AI-driven SAM tooling is being built to close—somewhat ironically, since AI is also the thing making the estate harder to see.

Audit pressure hasn’t eased either. Flexera’s data shows 48% of organizations were audited in the past year, and 44% spent over a million dollars on audit response across a three-year window—a number that’s stayed stubbornly flat across multiple survey cycles. Oracle audit activity climbed to 38% of respondents (up from 24%), and Adobe audit activity rose to 32% (also up from 24%). Microsoft remains the most frequent auditor at 64%. None of that goes away just because you bolt AI onto your CMDB.

Automated Discovery and Normalization: Where AI Actually Earns Its Keep

The least glamorous part of SAM is also where machine learning has made the most measurable difference. Software recognition—matching raw install data, SaaS API metadata, and cloud marketplace records to a clean, normalized product and edition—used to depend on static signature libraries that vendors updated on their own schedule. Miss an update and your discovery tool would report “unknown” or misclassify a product family, throwing off your entire license position.

Modern SAM platforms now use pattern-matching and machine learning models trained on much larger recognition libraries to auto-classify software with less manual mapping. This matters most for the long tail: internally packaged applications, open-source components bundled inside commercial software, and the constant renaming vendors do during licensing model changes. Instead of a SAM analyst manually building recognition rules for every oddball entry, the system flags likely matches and confidence scores, and a human confirms or corrects the edge cases.

It Still Needs a Human in the Loop

Don’t mistake this for “set it and forget it.” Confidence scoring exists precisely because normalization engines get things wrong, especially with bundled SKUs, OEM licensing, and products that share a vendor name but carry completely different entitlement terms. Teams that turn off manual review because the AI “seems accurate” tend to find out the hard way during an audit that a 90% confidence match was the 10% that mattered. The realistic gain here isn’t zero-touch discovery. It’s cutting the hours a team spends on first-pass classification so people can spend their time on the exceptions that actually carry financial risk.

AI-Assisted License Optimization: Recommendations, Not Autopilot

Bar chart of SaaS waste by organization size
Source: Zylo 2026 SaaS Management Index.

Once inventory is normalized, the next question is always the same one procurement and finance ask every renewal cycle: are we over-licensed, under-licensed, or both at once in different parts of the business? AI-assisted optimization tools now generate recommendations by correlating actual usage telemetry—login frequency, feature usage, API calls—against entitlement data, then suggesting downgrades, reclamation, or tier changes.

Zylo’s 2026 SaaS Management Index puts a number on the opportunity: the average organization uses only 54% of its purchased SaaS licenses, while organizations with mature reclamation practices reach 90% utilization or better. That gap translates into real money. The same report estimates the average organization wastes $19.8 million a year on unused SaaS licenses alone, with waste scaling sharply by company size—from roughly $3.8 million a year at smaller organizations to $80.6 million a year at enterprises with more than 10,000 employees. A separate industry estimate a few years earlier put average waste closer to $18 million, so the trend line isn’t improving as fast as the tooling vendors would like you to believe.

The AI layer here is genuinely useful for triage: it can rank which licenses to review first based on inactivity duration, cost, and renewal date, instead of a human scanning a spreadsheet trying to guess where the money is. What it can’t do reliably yet is make the call on ambiguous cases—someone who logs in rarely but holds a role where that access is a compliance requirement, or a named-user license tied to a contractual minimum. Optimization recommendations are a starting point for a negotiation and a business conversation, not a purchase order.

Shadow IT and SaaS Sprawl: Anomaly Detection Grows Up

Discovery used to mean scanning managed devices. It now has to account for SaaS applications that employees connect to through OAuth, browser extensions, and expense reports, none of which ever touch an agent-based scanner. Torii’s 2026 SaaS Benchmark Report found the average large enterprise now runs 2,191 applications, with individual employees interacting with roughly 40 apps a day. Of the applications discovered through API-based and network-based methods, 61% were not formally approved or overseen by IT—only about 15% of the discovered app portfolio was fully sanctioned.

AI tools are changing the character of this problem, not just the scale. As Torii co-founder Uri Haramati put it, AI didn’t invent shadow IT, but it “dramatically increased its speed and blast radius”—AI agents and copilots connect into other systems quickly, request broad access, and often keep running long after the team that adopted them has moved on. That’s a governance problem as much as a discovery one: an AI coding assistant with a standing OAuth grant into your source control system is a very different risk profile than an unused project management trial.

Anomaly detection models now flag unusual patterns automatically: a spike in SaaS sign-ups from one department, a license that suddenly shows activity from an unfamiliar geography, spend that doesn’t match any known contract. This is where machine learning has a real edge over manual review, because humans are bad at noticing gradual drift across hundreds of low-dollar subscriptions. The catch is tuning: too sensitive, and the alerts get ignored like a smoke detector that goes off every time someone makes toast; too loose, and it misses the slow-building sprawl that eventually shows up as a surprise renewal invoice.

Cloud and SaaS Cost Reconciliation: Where FinOps and ITAM Collide

Cloud-hosted software licensing adds a reconciliation problem that traditional SAM tools weren’t built for: a single workload might carry a cloud infrastructure cost, a bring-your-own-license entitlement, and a marketplace subscription, all billed differently and often owned by different teams. FinOps practices have matured around cost visibility and anomaly detection for cloud spend; ITAM has matured around license compliance and entitlement tracking. Those two disciplines are now being asked to reconcile the same line items, and most organizations haven’t built the operating model to do it.

Vendor cost-optimization platforms are starting to bridge this by pulling in cloud billing data alongside license and SaaS contract data, so a licensing decision (say, moving a database workload to bring-your-own-license) and a cost decision (right-sizing the underlying compute) get evaluated together instead of by two teams that never compare notes. The functional overlap is real, but the organizational overlap usually isn’t there yet—FinOps and ITAM teams reported in Flexera’s 2026 survey that their day-to-day interaction actually declined slightly year over year, even as reporting alignment between the two functions improved. Tooling is ahead of org design here, which is a common pattern in ITSM generally.

What the Platforms Are Actually Shipping

ServiceNow has added generative AI capabilities to its Software Asset Management workflows, aimed at helping analysts summarize license positions, draft optimization recommendations, and speed up the research that used to require digging through vendor contracts and usage reports by hand. Flexera has built out FinOps and cloud cost optimization directly alongside its ITAM platform, reflecting the same convergence pressure described above. Snow Software and other established SAM vendors have been layering machine learning into recognition and reclamation workflows for a few years now, with the newer marketing push being generative AI assistants on top of that existing engine.

Worth saying plainly: most of what’s shipping right now is assistive, not autonomous. These tools summarize, draft, flag, and rank. They don’t yet sign off on a license true-up or negotiate a renewal. Vendors describe roadmaps toward more autonomous remediation—automatically reclaiming an unused license after a grace period, for instance—but most production deployments today still route those actions through human approval, and for good reason given the financial and contractual stakes.

The AEIOU Lens: Where Automation Fits in a Maturity Model

AEIOU maturity ladder diagram for SAM automation
Source: Desqcon AEIOU framework (proprietary).

This is exactly the kind of shift our AEIOU framework is built to evaluate rather than hype. Automation is one letter in that model, not the whole story—it has to connect to Edification (does your team actually understand what the AI is recommending and why), Integration (is the data feeding these tools clean and connected across your CMDB, procurement, and cloud billing systems), Operations (does a recommendation turn into a workflow someone owns, with an ITIL 4-aligned change and approval path), and User experience (do the people affected by license changes, from end users to finance, actually notice an improvement or just more noise).

Organizations that bolt an AI-driven SAM module onto a low-maturity, siloed asset management practice tend to get a faster version of the same bad data, not better decisions. The tools are only as good as the practice underneath them, which is why a vendor-neutral maturity assessment—looking honestly at your discovery coverage, data quality, and governance model before you shop for an AI feature set—tends to save more money than the AI itself does in year one.

Where Human Governance Still Wins

A few things AI-driven SAM tooling still doesn’t do well, worth naming directly. Contract interpretation remains a human skill—license terms are full of exceptions, grandfathered rights, and negotiated carve-outs that a model trained on general usage patterns won’t catch. Vendor relationship management and audit negotiation are still fundamentally about people and leverage, not automation. And accountability for a license decision that turns out wrong has to sit with a person, not a recommendation engine, both for internal governance and for external audit defensibility.

None of that is an argument against the tooling. It’s an argument for treating AI-assisted SAM as a force multiplier for a competent team, not a substitute for one.

Getting Started Without Boiling the Ocean

If you’re evaluating AI capabilities in your SAM tooling, start with the data foundation, not the feature list. Confirm your discovery sources actually cover SaaS, cloud marketplace, and on-prem consistently before trusting any AI-generated recommendation built on top of them. Pilot optimization recommendations on one or two high-spend publishers where you already understand the contract terms well enough to sanity-check what the model suggests. And build the review workflow before you build the automation—decide who signs off on a reclamation, a downgrade, or a flagged anomaly, so the tool produces decisions your organization can actually act on.

If you’re not sure where your SAM practice stands against that kind of foundation, that’s exactly what a maturity assessment is for. Desqcon runs vendor-neutral SAM maturity assessments built around the AEIOU framework, mapped to ITIL 4 practices, to help you see where automation will genuinely pay off and where it would just add noise on top of an already shaky process. If that sounds useful, it’s worth a conversation before your next tool renewal.

Leave Comment

Your email address will not be published. Required fields are marked *

Are you human? Please solve:Captcha