Dreamforce 2026 lands at Moscone Center in San Francisco on September 15 – 17, and the theme Salesforce has put on the marquee – Becoming an Agentic Enterprise – is not subtle about where the platform is going. If you have been building on Salesforce for the last two years, you already feel the pull. The question most of our clients are asking is not “what’s new?” It’s quieter and more honest: have we actually gotten value out of the last thing before the next thing arrives?
That gap! between what Salesforce has shipped and what enterprises have genuinely operationalized – is the single most consistent pattern we see across engagements right now. This piece is our attempt to name it plainly, walk through where the friction actually concentrates, and be specific about the work that pays off in the weeks before Dreamforce.
How fast the ground has moved.
It helps to say out loud how much has changed, because the pace is the root of the problem.
At Dreamforce 2024, Salesforce introduced Agentforce, autonomous agents that take action within the CRM rather than just suggesting actions. It was early, and the demos were polished, and most people left intrigued but unsure what to do on Monday.
Dreamforce 2025 turned that idea into the center of the platform. Agentforce 360 became the orchestration layer tying agents, governance, and observability together. Data Cloud was rebranded as Data 360 and tasked with grounding agents in real, unified data, including unstructured content. Salesforce announced a deep partnership with OpenAI, and Slack was repositioned as the conversational surface where agents and people meet.
Then in April 2026, TDX added Headless 360 – a large set of Model Context Protocol (MCP) tools that let agents operate through APIs and the command line with no browser session at all. Composable, headless Salesforce stopped being a whiteboard concept and became something you could ship.
So, in roughly 18 months, the platform went from “here’s an interesting agent demo” to “here’s an agentic operating model spanning data, orchestration, governance, and headless deployment.” Very few enterprises absorbed all of that. Most are still midway through the previous cycle. Dreamforce 2026 will extend every one of these threads, and the organizations that get the most out of it will be the ones that closed the loop on the last cycle first.
The number worth putting on the wall
Gartner predicted in June 2025 that more than 40% of agentic AI projects would be canceled by the end of 2027, and the reason it gave is the part that matters. Not model quality. The causes were escalating costs, unclear business value, and inadequate risk controls. Coverage through 2026 has kept the forecast resurfacing, as it continues to prove accurate in the field.
Two supporting figures make it concrete. Gartner’s data showed that only around 17% of organizations had actually deployed AI agents, while more than 60% planned to do so within two years, a large intent-to-deployment gap that creates exactly the conditions for stalled projects. And across the industry, data preparation routinely consumes the majority of total project effort on these builds.
The lesson we draw from our own delivery experience matches the analysts: agentic projects rarely fail because the agent can’t reason. They fail because the data underneath was not ready, the use case was never measured, no one owned the outcome, or the guardrails were an afterthought. Every one of those is fixable, and none of them requires waiting for a keynote.
Where the friction actually concentrates
Here is what we see repeatedly, engagement after engagement, and what we do about each.
Data that is not ready to be reasoned over. This is the one under almost every stalled project. Agentforce is only as good as the Data 360 layer beneath it; fragmented records, duplicated profiles, and unstructured content that has never been made retrievable will quietly cap what any agent can do. This is why every Agentforce engagement we take on starts with a data readiness assessment rather than an agent build. Getting fragmented enterprise data into a clean, AI-ready layer is unglamorous work, and it is usually the highest-leverage thing an org can do before September.
Service agents who don’t know the business. Teams switch on Agentforce Service, expecting deflection, and get generic answers because the agent is grounded in stale or thin knowledge rather than the top drivers of actual case volume. Salesforce itself expects AI to handle a large share of service interactions in the near term, but that only holds if the knowledge base is first audited against real-world case patterns. The fast win is boring and effective: map your highest-volume case types, then ground the agent specifically on those.
Forecasting and pipeline that leaders don’t trust. On the sales side, the blocker is rarely the feature – it’s data hygiene and adoption. If reps don’t work the system, the AI has nothing honest to reason over, and forecast confidence never recovers. The near-term move is to clean the inputs and tighten adoption before layering intelligence on top.
Governance is treated as a phase two problem. Risk controls were one of Gartner’s three named causes of cancellation, and it shows. In regulated environments, this is non-negotiable – it’s the reason our published work includes AI-driven document review built to a media regulator’s compliance standards and AI transformation for a leading global financial center, where the Einstein Trust Layer, auditability, and human-in-the-loop review were designed in from day one, not retrofitted. If you operate under a regulator, governance is the first design conversation, not the last.
MCP and headless without a control plane. Headless 360 and MCP tooling are genuinely powerful – we’ve built proof-of-concept work like a React 19 single-page app running against a headless Salesforce backend, and a Sales Pipeline Intelligence Dashboard on the new multi-framework SDK. But opening up API- and CLI-driven agent access without governance over which tools an agent can call and on what data is how costs and risk escalate quietly. The pre-Dreamforce win here is establishing MCP governance before expanding what agents are allowed to touch.
Scale across languages and channels. For global operations, the failure mode is a pilot that works in one language and one channel and never generalizes. Our published work here includes multilingual support scaled for a delivery giant and AI-powered voice agents for a global ultra-luxury resort operator, both of which lived or died on the underlying data and orchestration, not the demo.
The through-line across all of these: the quick wins before Dreamforce are rarely adding a new capability. They are preparing the organization to absorb its existing capabilities.
The risk surface that widens the moment an agent goes public
Governance deserves its own section because it’s the friction point most likely to end a project rather than just slow it, and the one most likely to be waved off until it’s too late. Prompt injection and runaway cost get the headlines, but a customer-facing agent carries a much wider risk surface than an internal one. When an Agentforce agent is answering on your website or in Experience Cloud, the blast radius shifts from your team to your customers, regulators, and your brand.
We think about that surface across seven dimensions. It maps closely to the OWASP Top 10 for LLM Applications (2025), which is the reference framework security teams and buyers now use to talk about these risks in a common vocabulary:
- Exploitation and manipulation – prompt injection (direct and indirect), jailbreaks, and system-prompt leakage. Prompt injection has held OWASP’s number-one spot for two editions in a row, and you can’t fully patch it away; it requires a defense-in-depth approach.
- Runaway usage and cost – “denial of wallet,” looping queries, and bot-driven floods that quietly turn a metered agent into an unbounded bill.
- Data exposure and privacy: oversharing, PII leakage, and data residency or GDPR exposure. Usually, this isn’t a breach; it’s overbroad retrieval that pulls sensitive records into an answer, a transcript, or a log.
- Accuracy and trust – hallucination, misinformation, and model drift that degrade answers gradually enough that nobody notices until a customer does.
- Access and identity – over-permissioned agents, and gaps between what the agent can reach and your actual Salesforce sharing model.
- Governance and operations – agent sprawl with no monitoring and weak human oversight, where nobody owns what the growing fleet of agents is actually doing.
- Compliance and supply chain – EU AI Act obligations, disclosure requirements, and third-party or MCP connector risk that enters through the tools your agent calls.
Here’s how quietly this fails in practice – a pattern we flag constantly. Say a service agent is grounded on your history of resolved cases. Learning from past resolutions is genuinely valuable, but a resolved case is not a sanitized knowledge article: its comments and internal fields routinely hold another customer’s PII, a blunt internal note (“don’t offer the discount”), or a competitor mention from a migration deal. Whether the agent should surface any of that to the current user is a question most rollouts never explicitly ask, and it isn’t answered automatically. Grounded on live records through the standard retriever, with a properly scoped running user, and permissions can be respected. Still, the moment you ground on a vectorized index of case text, run a public agent under an over-permissioned guest user, or never exclude internal comments at ingestion, the agent can hand one person content they could never reach through the normal UI. The Einstein Trust Layer doesn’t fully close this either. Its masking catches recognized PII patterns in the prompt flow, but a competitor name or an internal workaround isn’t “PII,” and masking doesn’t decide what gets indexed in the first place. The upstream fix is unglamorous: ground on curated, scrubbed Knowledge rather than raw case bodies; exclude internal fields and comments at ingestion; scope retrieval to what the requesting identity is entitled to see; and settle the running-user model before the agent goes public.
None of this is an argument against shipping agents. It’s an argument for treating these seven as design inputs rather than incident post-mortems. In practice, that means grounding on the Einstein Trust Layer, scoping agent permissions to your sharing model rather than around it, constraining retrieval so agents only see what a query needs, putting monitoring and human-in-the-loop review on anything sensitive, and governing which connectors an agent is allowed to touch. This is exactly the discipline behind our published work under a media regulator’s compliance standards and for a leading global financial center – environments where “we’ll add governance later” was never an option. If your agent is going public, the safe sequencing is to design against this surface first.
A short pre-Dreamforce checklist
If you want to walk into DF26 in a position actually to use what’s announced, this is roughly the order we’d run it:
- Audit before you add. Inventory what’s already licensed and switched on versus what’s actually delivering measurable value. The gap is your real backlog.
- Fix the Data 360 foundation. Deduplicate, unify, and make unstructured content retrievable. This is where most of the effort goes, and most of the value is won.
- Ground service agents for real case drivers. Audit knowledge against your highest-volume case types, not against all case types.
- Make governance a design input. Trust Layer, auditability, and human-in-the-loop belong in the first architecture conversation – especially under a regulator.
- Put an MCP control plane in place before you widen headless and agent access.
- Map the risk surface before you go public. Run any customer-facing agent against the seven risk dimensions above – especially permissions, retrieval scoping, and connector governance before it touches a real customer.
- Pick one measurable process and instrument it end-to-end so you can prove ROI rather than hope for it.
None of this is theoretical, and none of it needs to wait for a keynote.
Where ABSYZ fits
We are a pure-play Salesforce firm, a Salesforce partner since 2014, and a Summit Partner (the highest tier), a status we held through the partner program’s March 2026 restructuring into the new Select-and-Summit model. Practically, that means a team of 450+ certified professionals, 1,500+ certifications across the clouds, 300+ delivered projects across healthcare, manufacturing, high-tech, BFSI, and financial services, and a 4.9/5 AppExchange rating built on real customer outcomes.
More relevant to this moment: we run a live Agentforce practice with production deployments behind us, not just sandbox pilots. When we fielded eleven teams in the pan-India Agentforce Hackathon, we emerged as one of the twelve finalist teams selected nationwide. Still, that result is downstream of the real delivery work we’ve done with clients across industries, and the problems we’ve had to solve in production rather than in a demo. That’s also why this piece reads the way it does. We would rather give you a realistic picture of what’s actually possible, where the risk sits, and where the value is, than a story that sounds impressive and falls apart on contact with your org.
If you are heading into Dreamforce 2026 and want an honest read on where your Agentforce and Data 360 foundations actually stand, and a prioritized plan for the weeks leading up to September, that’s exactly the conversation we like to have. Reach out before the keynote.
