This topic makes a nice change from the ongoing SaaS-pocalypse the tech industry is supposed to be experiencing in the face of the growing capabilities of AI. Despite enthusiastic predictions of the end of SaaS since February this year (alongside the predicted ends for art, literature, design, cinema, and now mathematics), new developments in the game modding and porting communities suggest SaaS might have the best chance as AI eats the world.
All this is very recent, the result of another step change in ability. In September OpenAI released GPT-Astra and Anthropic released Claude Opus 5.5. They both impressed with their ability to one-shot complex interfaces and 3D models.

Early 1900s San Francisco built by Claude driving Blender
What happened next made it clear that the near future of software is going to be messy.
Game modders and the NSA
Out of the abilities of these new frontier models sprang game merging. While game modding is making a change to a game’s code (or working with the game’s tools) to add new features, game merging was taking 2 or more games and mashing them together: Skate 3 and Call of Duty, Minecraft and Elden Ring, Minecraft and Call of Duty and Skate, and so on.

The mashups are not as simple as they appear. They rely on running the merged games at the same time and integrating them via a bridge that passes and encodes/decodes data between them.
Building those bridges requires a deep understanding of each game’s codebase. But these hobbyists don’t have access to IP like that. However, thanks to a combination of the Anthropic-originated Model Context Protocol (MCP) for connecting agent harnesses to external services and tools, and tools like an NSA-originated reverse engineering application, they don’t need the codebase.
Ghidra was developed by the NSA around 1999 for reverse engineering software as part of their cybersecurity and foreign intelligence activities. No-one outside the US intelligence community knew about it until the Wikileaks “Vault 7” CIA data dump in 2017 which referenced it.
For some reason the NSA did a conference presentation on Ghidra in 2019 and released binaries for the software followed by an open source release a month after.
There is also the commercial IDA – Interactive Disassembler – by hex-rays, also available in free versions with limited functionality.
Both Ghidra and IDA have multiple MCP implementations that allow models like Astra and Opus to explore, map and understand binary files to the level where you can use them to bridge games as different as Elden Ring and Minecraft.
These tools also enable the AIs to do a very good job of disassembling binary executables, converting a game or application that has been downloaded as an executable back into source code. Not the original source code, but something very close. Close enough that the game or application can be rebuilt from this derived source code and be indistinguishable in its running from the original.
Once you have the source code for an application you can do something rather more interesting with it than just rebuild the executable. At least in the United States.
Several court cases in the 80s and 90s established that clean room copies of software are legal. A clean room copy is where the original source code for an application is not used directly to make a working copy of it. Instead, one party takes the original and writes out specifications on how the application operates. That specification is handed to a second party who uses it to write a “clean” copy of the application.
AIs are not just specification writing machines, spec-driven development is a standard practice in agentic coding.
Today we have tools that allow an AI to convert any executable into accurate, compilable source code. Those same AIs can translate that source code into specifications with a level of detailed that would take humans years to match. And then those AIs can turn the detailed specifications back into working source code.
And they can do this in hours or days, depending on the size of the application.
The bazaar defeats the cathedral
In the late 90s Eric S Raymond wrote The Cathedral and the Bazaar. He was inspired by the open source movement and the success of Linux. Here was an entire operating system, one of the most complex categories of software, written by volunteers, winning marketshare against Microsoft, against IBM.
Open source software was the bazaar – lots of noise and confusion that both signalled and slightly obscured the quality and amount of activity going on. It was a distributed, loosely organised way to develop software. The “many hands make light work” model.
Everything else was the cathedral – software developed within the hallowed ground of corporate offices following very detailed and professional work practices performed by trained professionals.
Raymond’s premise was that the bazaar would win. Open source would force out the closed source products of the cathedral, which would limp on in the periphery, in niches where a bazaar’s head count might not be sustainable.

And then he discovered StoryTold and their ArtCraft site, featuring clean room implementations of the Adobe Suite built in Rust, available for free download and, thanks to Rust, able to run directly in the browser.

StoryTold used AI clean rooms to re-implement the Adobe Suite – PhotoShop, Illustrator, Premiere, After Effects, Acrobat, LightRoom – and give it away for free so they can make money by adding a margin to AI image and video generation services they’ve integrated into their own versions of the apps.
Talk about commoditising your complements (that’s a deep cut for the players). They have performed the commoditising of software for the labs selling the tokens. And they made all their apps open source as well.
The money, it seems, is in the tokens, not the software.
The new old SaaS moat
If Figma and Canva are reading this they might be feeling pretty smug at the moment. You can’t make clean room clones of software you don’t have the binaries for.
And an SaaS is never a binary. It’s a collection of services and the tooling that keeps it running in the cloud, and the people that management it.
Yes, some vibe-coders could copy a portion of the functionality, but they will always be a tiny minority. And no-one wants to maintain, or even use, someone else’s half-baked vibe-coded codebase. So you don’t need to be concerned about distribution from that end impacting your numbers.
Your competitors, with their own people and their own tooling, will be working just as fast as you to maintain feature parity, but that’s fighting over which portion of the pie the knife is cutting out for you, not watching the entire pie dissolve before your eyes.
This does mean to maximise this moat you need to be thinking about how much functionality you can move behind a network call while maintaining performance. Browsers are notoriously open and AIs see right through Javascript obfuscation.
If you’d like to chat about the direction you would take your SaaS if you had another pod, or another three pods, get in touch with us. Our developers out of Yogyakarta have a wide timezone overlap with your team, which keeps day-to-day operations smooth.