SaaS management tools track what software your organisation owns and what it costs. SaaS governance asks what that software does with your data, how it classifies under the EU AI Act, and what regulatory evidence it must produce. The gap between those two questions shows up the moment you look at a single app through both lenses.
Notion is one app to your SaaS management tool. To your AI governance obligations, it is three: Notion the SaaS, Notion AI the embedded feature, and the data Notion AI processes when employees use it. SaaS management sees the first; AI governance sees all three.
This piece is for the IT Director who has bought Zylo, Torii, BetterCloud, Productiv, or Flexera, and is being asked by the DPO and the CFO about AI governance. The instinct is to ask your existing vendor. The honest answer is that you have found the seam between two adjacent categories, and the case for treating them as the same product is weaker than the marketing implies.
What SaaS Management Tools Do Well
The category exists for good reasons, and a fair piece on the gap has to start with what the tools genuinely solve.
Cost visibility. The SaaS spend sprawl problem has been real since the post-2015 shift to credit-card software adoption. Zylo, Productiv, Sastrify, and Vendr each give the IT and finance functions a unified view of subscriptions, contracts, and renewals that the expense management system did not provide. Most mid-market firms recover meaningful spend in the first year of using a tool in the category, the consistent finding in audits is roughly 15–25% of total SaaS spend, depending on prior rationalisation.
Licence right-sizing. Tools like Productiv and BetterCloud combine usage data with seat counts to show which licences are underutilised, which renewal cycles are misaligned, and which seats can be reclaimed at the next renewal. This is operational work the firm cannot do at scale without a tool.
Discovery and software inventory management at the SaaS level. Most tools in the category combine SSO logs, finance data, and where consented browser telemetry to surface shadow IT the central inventory does not list. They produce, for many firms, the first complete SaaS inventory the firm has ever had.
Vendor risk surface. BetterCloud, Torii, and others overlay vendor risk attributes - SOC 2 status, data residency, breach history - on the inventory. This gives the security team a starting position for vendor risk assessment that the IT inventory alone does not.
These are real capabilities, and SaaS management tools have continued to extend them. The category is moving, most tools have added some AI-specific surface through 2024 and 2025. The depth varies meaningfully by vendor, and the architectural question is not whether they have started covering AI but whether the architecture extends naturally to the regulatory work AI governance requires.
Where SaaS Management Tools Stop
Four gaps show up consistently when the IT Director is asked to produce AI governance outputs from the SaaS management platform.
AI feature detection inside SaaS. The category was designed for app-level discovery: which apps are in use, who uses them, what they cost. The AI features inside those apps are a different unit of analysis. Notion AI is a feature of Notion, not a separate app. Slack AI is a feature of Slack. Microsoft Copilot is a feature inside Microsoft 365. SaaS management tools generally do not natively detect when an AI feature inside an existing app turns on, which sub-feature is enabled, or what data it processes. The detection requires a different layer of telemetry - API behaviour, configuration scanning, or partnership-driven feature flags from the SaaS vendor itself. This is the boundary where SaaS management ends and dedicated AI governance begins.
EU AI Act risk classification. The Act categorises AI systems into four risk tiers - prohibited under Article 5, high-risk under Article 6 and Annex III, limited-risk under Article 50, minimal-risk by default. The classification is fine-grained and per-system, not per-app. The same Notion workspace is minimal-risk for note-taking and limited-risk under Article 50 when Notion AI generates customer-facing content. SaaS management tools were not built for this taxonomy and do not produce the per-system classification output.
GDPR Article 30 RoPA generation. The record of processing activities under Article 30 requires per-processing-activity entries with purposes, data categories, recipients, and international transfers. SaaS management produces an inventory of vendors. The inventory is the starting input for the RoPA, not the RoPA. The conversion - defining each processing activity, mapping it to the controller's purposes, identifying the lawful basis, is judgement work that the SaaS management platform's data model does not support.
Cross-regulation evidence assembly. The DORA Article 8 register, the NIS2 Article 21 supply chain assessment, the EU AI Act Annex III classification, and the GDPR RoPA each draw from the same underlying inventory but produce different documentary outputs in different formats for different supervisors. SaaS management tools produce the inventory. AI governance platforms produce the framework-specific outputs from that inventory. The two layers are different because the consumers of each are different.
Notion Through Two Lenses
The clearest way to see the difference is a single SaaS through both lenses.
SaaS management lens. Notion is one entry on the inventory. Cost: €X per seat per month. Licence count: Y. Active users: Z. Renewal date: November. Vendor risk attributes: SOC 2 Type II, EU data residency available on Enterprise tier, no recent breach disclosures. The category-leading tools enrich this with usage signals - which teams use Notion most, which seats are dormant, which features are hit hardest.
AI governance lens. Notion is three entries. Notion the SaaS - same as above. Notion AI the embedded feature - currently enabled at the workspace level, defaulting on for paid plans, processing the data inside Notion docs through inference calls to a third-party AI provider. The data Notion AI processes when employees use it for summarisation, drafting, and Q&A, distinct processing activities that touch customer data when employees summarise customer-facing documents, that touch personal data when employees draft outreach, and that may touch confidential information depending on which workspaces are connected.
Each of those three has different regulatory implications. Notion the SaaS sits on the GDPR processor list with a standard DPA. Notion AI the embedded feature requires its own assessment - what AI sub-processor does it use, where is the inference run, what data is sent in prompts, what retention applies. The processing activity through Notion AI requires its own RoPA entry, and may attract Article 50 transparency obligations under the EU AI Act when employees use it for customer-facing content.
The IT Director's SaaS management tool sees the first lens. The DPO needs the second.
Replace or Augment?
Augment, in nearly every case. The SaaS management tool is doing real work the firm needs done - cost optimisation, licence management, the SaaS-level software inventory management and vendor risk surface. AI governance is the regulatory and feature-level layer that sits beside it, not on top.
The integration pattern that works in mid-market firms: the SaaS management tool feeds the AI governance platform with the vendor inventory and licensing data it already has. The AI governance platform adds the AI-feature detection, the regulatory classification, and the framework-specific evidence outputs. Each tool does what its architecture was designed for. The IT Director keeps both, the operating model is clean, and the budget conversation is about adding a regulatory layer rather than replacing an operational one.
What Montro Sees in the Field |
In the Discovery Audits that Montro runs for the European Mid Market firms, the patterns we see are the same. The IT director checks the SaaS management platform, and the vendor inventory looks quite satisfactory. But when we ask them about the AI capabilities, they go quiet. They have Notion AI, Copilot, and Slack AI, but they are not visible in the inventory. This is not happening because the tool doesn't work, this is happening because the tool was not designed for SaaS governance at the AI feature level. |
Five Questions To Ask Your SaaS Management Vendor
Before deciding the existing vendor covers AI governance, ask:
- "Show me the AI features detected inside the top ten SaaS apps in our inventory." If the answer is the apps themselves rather than the AI features inside them, the gap is real.
- "Produce an EU AI Act Annex III classification for the high-risk AI tools in our environment." If the answer is a vendor questionnaire to fill in manually, this is documentation, not classification.
- "Generate the Article 30 RoPA entries for our AI processing activities." If the answer is a template to be completed by the DPO, the platform is producing a form, not a record.
- "Map our inventory to DORA Article 8 register format." For firms in scope of DORA, this is the most direct test of regulatory output capability.
- "What sub-processors do the AI features inside our SaaS use, and where are they located?" Fourth-party visibility is where DORA enforcement is moving and where SaaS management tools rarely extend.
If the answers are present, you may not need a separate AI governance layer. If they are absent, you have found the seam, and the seam is wider than the category marketing implies.
Frequently Asked Questions
Does Zylo or Torii detect AI features inside SaaS apps?
Not natively. These tools detect apps, not the AI features running inside them. Notion AI, Slack AI, and Microsoft Copilot activate at the feature level, a different unit of analysis that requires API behaviour monitoring or vendor-level feature flags, not shadow IT discovery methods like SSO log analysis.
Which EU AI Act article covers embedded AI features in SaaS tools?
Article 50 is the relevant provision. Embedded AI features may trigger Article 50 transparency obligations depending on how they generate content or interact with users.
What is fourth-party visibility in the context of DORA?
Fourth-party visibility means knowing which sub-processors your SaaS vendors' AI features use - not just the vendor, but who the vendor's AI runs on. DORA's supply chain and ICT third-party oversight model increasingly pushes firms toward this level of visibility. Most SaaS management tools stop at the direct vendor relationship.
Do I need a separate GDPR DPA for AI features inside tools I already have a DPA for?
Potentially. It depends on whether the AI feature introduces new sub-processors or materially changes the processing activity already covered by the existing DPA.





