At Dreamforce, Salesforce introduced AIforce, which changes how users can interact with Salesforce. Instead of navigating through screens, reports and workflows, users can increasingly ask for information or take action conversationally, including from Slack or Claude.
Salesforce still sits underneath that interaction. The data, permissions, business rules and workflows do not disappear. That distinction matters, particularly after the recent unsettling headlines about what increasingly capable AI models can do by going rogue.
In July, OpenAI disclosed that models being tested for advanced cybersecurity capabilities found a way out of a controlled evaluation environment, reaching the open internet and compromising parts of Hugging Face’s production infrastructure. It immediately raises an understandable question: if AI is becoming more capable, what happens when we give it access to systems such as Salesforce?
What actually happened
The OpenAI incident was real and significant. But the conditions matter. The models were being deliberately tested on advanced cyber exploitation. OpenAI ran the evaluation with reduced cyber refusals and without the production classifiers normally used to prevent high-risk cyber activity. The model principally involved was an internal research prototype that OpenAI said was never intended for public release.
In other words, researchers were deliberately testing what highly capable models could do under unusually permissive conditions. That is very different from a Salesforce user asking an AI assistant to summarize an account, update an opportunity or initiate an approved workflow.
But the incident does reinforce something enterprises should take seriously: capability and control are two different things. The model provides capability. The enterprise has to provide the control around it.
Salesforce AI still operates inside Salesforce controls
Salesforce is explicit about this. With AIforce, the interface may change, but when an authorized user accesses Salesforce, the request is still authenticated and authorized. The user must have a valid Salesforce license, and object- and field-level security still determine what information is returned.
The Salesforce Trust and Security foundation applies the org’s permissions, sharing rules and security model across agents and interfaces. That should be reassuring, but it also exposes the more important enterprise issue.
AI inherits the controls you already have
If your Salesforce permissions are well designed, AI inherits well-designed permissions. If they are not, AI inherits those too.
Consider a salesperson who accumulated broader access than necessary over several years. In the traditional interface, extracting everything that access permitted requires manual effort and judgment on the part of the user and the trust placed on that individual by the organization.
The issue is whether that user, and therefore the agent acting for that user, should have the same broad access. AI did not create the permission problem. It reduced the effort required to exercise those permissions, and it can do so at much greater speed and scale.
That is why the next phase of enterprise AI is not simply about better models. It is about a better harness.
The data foundation tells AI what it knows. The harness determines what it can do.
We have written before about the data foundation: the quality, structure, context and governance of the information an AI system relies on. That determines what the AI knows. The harness determines how it is allowed to operate:
This is an important distinction because powerful AI does not have to be unconstrained or uncontrolled AI. The model may be capable of doing many things. The harness determines which of those things it is allowed to do inside your enterprise.
Salesforce is building many of these controls directly into the platform. Its architecture documentation identifies Testing Center, Session Tracing, configurable guardrails, observability and agent lifecycle management as parts of its governance layer.
Testing Center lets organizations evaluate agent behavior, actions and responses before deployment. Session Tracing captures what happened during an agent interaction, including actions, inputs, outputs, errors and responses, so teams can monitor and investigate agent behavior. That is the harness becoming operational.
Four things Salesforce organizations should look at now
As headless access becomes another way for users to work with Salesforce, we should focus on four things.
The interface changed. The responsibility did not.
Better models will continue to expand what is possible. Better harnesses will determine what AI is allowed to do for you. You are still responsible for the actions.
Start by asking: What can this agent see? What can it do? And what controls surround those actions?
Vertex Tower, Plot no-
C-33, 4th Floor, Phase 2, Industrial Area, Sector 62, Noida, Uttar Pradesh, 201309