Salesforce just shipped a product that tells you exactly where it thinks the AI agent war will be won. The Enterprise AI Harness, announced September 10, is not a new model or a flashier chatbot. It is a composable architecture designed to give AI agents the one thing they cannot get from a foundation model alone: the institutional memory of your business.

The timing is deliberate. With Dreamforce days away and competitors like ServiceNow and Microsoft racing to define the governance layer for enterprise AI, Salesforce is making a structural argument: the model you use matters less than the context you feed it. And nobody has more customer context than the company that has spent 25 years accumulating CRM data, metadata, workflows, and business logic across millions of orgs.

The Thesis in One Sentence

Rohan Kumar, Salesforce's president and chief platform and engineering officer, put it plainly in the announcement:

The Agentic Enterprise won't be defined by which model a company chooses. Models will keep changing, and intelligence will increasingly be available everywhere. What will differentiate an enterprise is the trusted, proprietary context it brings to that intelligence.

Rohan Kumar

This is a CFO-friendly framing. It shifts the conversation from "which AI vendor has the best model" to "which vendor can make our existing data and processes actionable for AI." The first question invites a race to the bottom on inference costs. The second question favors incumbents with deep system-of-record positions.

What the Enterprise AI Harness Actually Does

The architecture groups six capabilities: Trusted Context, Trusted Agency, Trusted Action, Trusted Governance, Trusted Security, and Trusted Models. The naming is marketing, but the substance is real.

  • Context means Data 360, Informatica, and the unified customer profiles that let an agent understand who a customer is, what they have bought, and what commitments exist in contracts.
  • Agency means the Atlas Reasoning Engine that plans multi-step workflows.
  • Action means MuleSoft and the integration layer that lets agents execute across systems.
  • Governance and Security mean the Einstein Trust Layer, audit trails, and the controls that let a CISO sign off on production deployment.

The new AI Control Plane is the piece that matters most for multi-vendor environments. It gives enterprises a single place to discover, register, and govern agents, including third-party agents and models. AI Weekly reports that the average enterprise now runs 3.1 agent platforms. Salesforce is positioning itself as the governance layer across all of them.

The Financial Case

Salesforce's Q2 FY27 earnings show the bet is already generating revenue. Agentforce and Data 360 ARR reached nearly $3.9 billion, up over 210% year-over-year. Agentforce alone exceeded $1.5 billion in ARR. The company delivered 7 billion Agentic Work Units to date, with 3.2 billion in Q2 alone, growing 97% quarter-over-quarter.

Those numbers matter because they answer the question every CFO asks about AI investments: is this real revenue or is this a science project? Salesforce is showing that customers are paying for AI capabilities at scale, not just running pilots.

The pricing evolution tells its own story. SaaStr documented how Salesforce shipped three different pricing models in roughly 18 months:

  • $2 per conversation at launch
  • Flex Credits at $0.10 per action in May 2025
  • Per-user licenses at $125/user/month

Running three models simultaneously looks like chaos until you realize the market has not converged on how to buy AI agents. Salesforce is letting customers self-select into the model that matches their usage pattern while it learns which model scales.

The real competitive advantage isn't the AI—it's what the AI remembers.
The real competitive advantage isn't the AI—it's what the AI remembers.

The Competitive Landscape

ServiceNow is making the same governance play from a different angle. At Knowledge 2026, the company introduced AI Control Tower and ServiceNow Otto, positioning itself as "the AI control tower for business reinvention." The partnership with Microsoft extends AI Control Tower governance across Microsoft Agent 365, giving ServiceNow a foothold in the Microsoft 365 ecosystem where Salesforce has less presence.

Microsoft has Copilot Studio and the distribution advantage of being embedded in every enterprise's productivity stack. Google has Vertex AI and the cloud infrastructure play. But neither has the depth of customer relationship data that Salesforce has accumulated. The question is whether that data advantage translates into better agent performance in production.

The Operational Reality

Salesforce's Agentic Enterprise Index shows how deployments are actually playing out. Organizations increased activated agents by nearly 3x over the past fiscal year and reduced average creation time by 53%. Agents are expanding their skill sets by up to 350% during peak demand. Weekly employee usage tripled while customer escalation rates held steady at scale.

The bifurcation in deployment patterns is instructive. Consumer-facing sectors lean into high-volume, task-specific agents that handle immediate customer needs. Operationally complex and regulated industries like manufacturing and public sector build versatile agents capable of multi-step workflows that require cross-functional business logic. Both patterns generate ROI, but they require different architectures and different governance models.

What This Means for Marketing Leaders

The Enterprise AI Harness is not a marketing tool. It is infrastructure. But the implications for marketing are direct.

First, the data unification story becomes a budget conversation. If your AI agents are only as good as the context they can access, then the investment in Data 360 and clean customer data is not a nice-to-have. It is the foundation that determines whether your agents can actually personalize at scale or just generate generic responses.

Second, the governance layer matters for brand risk. An agent that hallucinates a commitment to a customer or exposes PII is a marketing problem before it is a legal problem. The Einstein Trust Layer and the audit capabilities in the AI Control Plane are the controls that let you deploy agents in customer-facing channels without creating reputation risk.

Third, the pricing models create new unit economics to model. If you are paying $2 per conversation or $0.10 per action, you need to know the cost per lead, cost per case resolution, and cost per upsell attempt. That math determines whether AI agents are a margin expansion story or a cost center.

The Pilot Plan

For marketing leaders evaluating Agentforce, the path forward is a scoped pilot with clear metrics. Pick one high-volume, low-complexity use case where you can measure deflection rate, resolution time, and customer satisfaction. Run it for 60 days with a holdout group. Model the unit economics against your current cost structure.

The risks to mitigate: data quality gaps that cause agent failures, escalation paths that create customer friction, and governance gaps that create compliance exposure. The Enterprise AI Harness addresses the third risk. The first two are on you.

Salesforce is betting that the company with the deepest customer context will win the AI agent race. The bet is not crazy. But it only pays off if that context is clean, connected, and governed. For most enterprises, that is still the hard part.