Summary Bullets:
• New fears of AI breaches and vulnerabilities significantly threaten AI adoption
• Salesforce and rivals launch aggressive control plane portfolios as part of the new layer of the AI stack
On the heels of broad industry doomsday reports of AIs going rogue, Salesforce launched its mega Dreamforce conference in San Francisco, California (US) last week. CEO Marc Benioff used the stage to reposition the company as the industry platform to provide the oversight and governance of both Salesforce and third-party agents under a single view.
The message was apropos following multiple news events that have triggered a new wave of AI mistrust across the industry. In one news report, a high-ranking OpenAI official states there is a greater than 10% chance that AI could kill all humans in the next decade. In others, OpenAI models breached open AI platform Hugging Face, and Anthropic report similar hacks by its popular model Claude Opus as well. During keynotes, Benioff discussed the unfortunate hacks by leading AI models, while strongly urging customers to invest in long-established, proven, and well-funded AI platforms such as Salesforce.
A more open agentic ecosystem via APIs
The company’s latest AI premise is based on Salesforce AIforce, which is built on what the company calls a Headless Toolkit, for exposing all of its services via APIs, MCPs, or CLIs, making it easier for agents to work with Salesforce services. These 60-plus MCPs and 30-plus coding “skills” are a key component for giving coding agents such as Claude Code and Cursor direct access to the Salesforce platform. AIforce consolidates leading frontier models and combines them with Salesforce skills—portable instruction packages on how to complete a task and work with specific Salesforce metadata.
Salesforce’s solution for AI governance
Now that Salesforce is opening its AI ecosystem through MCPs and increased accessibility to its own platform services via APIs, the company has been formulating a strategic approach to multi-agent orchestration coupled with the promise of trusted Salesforce context to ensure security and governance around agentic actions. This is a pivotal step in helping assure its customers of Salesforce’s ability to combat AI threats and vulnerabilities, and it largely hinges on an AI control plane architectural construct initially previewed in 2025. The initiative is branded MuleSoft Agent Fabric, an agent orchestration capability based on a trust and data security layer. This approach is intended to reassure customers that their developer activities are being properly governed and secured, particularly in light of the recent spate of breaches and vulnerabilities associated with leading GenAI products by Anthropic and OpenAI.
More specifically, the company’s control plane maintains a central registry of all agents, MCP servers, and APIs, including the ability to discover agents automatically. It accomplishes this through a single point of control AI Gateway for all LLMs, MCPs, and agent calls. While the AI control plane provides customers with unified management, control, cost control, and visibility of agents, they can pick and choose from newer services available in Salesforce’s Enterprise AI Harness, including context, agency, action, governance, security, and models. GlobalData expects this portfolio of services to eventually include other core capabilities such as policy controls, guardrails, observability, etc.
Salesforce is not the only platform provider to devise an operating system, which sits underneath multiple vendors’ agents in order to ultimately establish a control plane of agent management, governance, security, policy, and guardrails. Salesforce is taking direct aim at key rival offerings, including ServiceNow AI Control Tower and IBM watsonx Orchestrate. The battle will only continue to heat up as vendors in this space continue to build out more comprehensive portfolios of governance services as part of their orchestration strategies.
The emerging architectural approach represents the most promising method yet for addressing what has quickly become a global crisis surrounding a newfound mistrust of AI technology based on a stunning lack of adequate security and guardrails attached to agent activities. AI companies have invested heavily in the GenAI market segment, and they can’t afford to neglect having proper controls in place to ensure ongoing adoption of AI solutions. The heavy emphasis on GenAI’s user interface over the past few years is no longer the conversation starter among enterprise buyers. They’ll be limiting investments in those tech providers with strong AI orchestration messaging squarely in place.

