Salesforce Brings a New Model and Agent Guardrails to Dreamforce

Salesforce used its Dreamforce stage this week to unveil a new AI model alongside a set of security tools built for AI agents, according to The Information. The two announcements land together for a reason: Salesforce has spent the last two years betting the company on Agentforce, and enterprises keep asking the same question. Who’s watching the agents?

The Information’s report is brief, so I’ll stick to what’s confirmed and add the context you need to read it properly.

What Salesforce announced

  1. A new AI model. Salesforce is putting its own model into the lineup rather than relying only on partner models from OpenAI, Anthropic, or Google. That’s a notable shift for a company that has mostly positioned itself as the orchestration layer, not the model builder. Details on size, benchmarks, and training data weren’t included in the report.
  2. Agent security tools. The second piece targets the messier problem: keeping autonomous agents from doing things they shouldn’t. Think permissions, guardrails, and visibility into what an agent actually did inside a CRM full of customer data. The Information didn’t specify the exact feature list, so treat this as a category announcement until Salesforce publishes documentation.

Why the pairing matters

Here’s my read. A model on its own doesn’t sell to a Fortune 500 CIO anymore. Everyone has a model. What closes the deal is the answer to “what happens when the agent goes off script and touches a customer record it shouldn’t?”

Salesforce knows this. Its entire pitch since Agentforce launched in 2024 has been “agents that work inside your data, with your rules.” Security tooling is the rules part. Shipping it at Dreamforce, the company’s biggest customer event of the year, signals that agent trust is now a headline feature, not a footnote in the admin console.

The bigger pattern across the industry

Salesforce isn’t alone here. Three things are happening at once:

  • Vertical players want their own models. Databricks, Snowflake, and ServiceNow have all moved toward owning at least part of the model stack. Owning a model means better margins and less dependence on a partner who might become a competitor.
  • Agent security is becoming its own product category. Prompt injection, data exfiltration through tool calls, and agents with over-broad permissions are real incidents now, not theoretical ones. Vendors are racing to package controls before customers build their own.
  • Enterprise buyers are slowing down on agent rollouts. The pilots happened in 2025. The production deployments are stalling on governance questions. Whoever answers those questions wins the next budget cycle.

What we don’t know yet

The Information’s report doesn’t cover pricing, availability dates, or whether the new model is exclusive to Agentforce or available through Salesforce’s broader platform. It also doesn’t say whether the security tools work with third-party agents or only Salesforce’s own. Those two answers will determine whether this is a defensive move to lock in existing customers or an offensive push into the broader agent market.

I’d expect Salesforce to fill in those gaps over the course of Dreamforce week. The company usually stages announcements across the event, with technical sessions following the keynote reveals.

What to watch

If you’re running Salesforce in your stack, the security tools are the thing to evaluate first. A new model is interesting, but agent permissions and audit trails are what your compliance team will ask about before you’re allowed to turn anything on.

If you’re a competitor, watch how Salesforce prices the model. If it’s bundled free into Agentforce, that’s a shot at the API-based model vendors who charge per token. If it’s a premium tier, it’s a margin play.

Either way, Salesforce just told the market that owning the agent layer means owning the model and the guardrails, not just the workflow. Full details are at The Information.

Scroll to Top