Dreamforce 2026: From Deploying Agents to Governing Them
Explore why AI agent governance is taking center stage at Dreamforce 2026 and how enterprises can scale Agentforce with trust and control.
For the last two successful Dreamforce Events, the story was speed: how fast could you stand up an agent, how many workflows could it touch, and how quickly could you get from pilot to production?
Walk the halls of Moscone Center this September 15–17, and you'll notice the question has changed. It's no longer just "can we deploy this?" It's "can we control what we've already deployed?"
That shift isn't a vibe—it shows up in the data, and it's the reason governance has become one of the most heavily programmed themes at Dreamforce 2026.
Agent adoption has moved fast:
Salesforce's own numbers tell a similar story. By December 2025, the company reported closing roughly 29,000 Agentforce deals and logging more than a million agent conversations. Agents are no longer a lab experiment. They're doing real work, at real scale, inside real customer data.
Here's the part that should give every operations and IT leader pause: governance hasn't kept up. In that same Deloitte survey, only 21% of organizations describe their agentic AI governance as mature. McKinsey’s research reveals a similar ceiling, with roughly 30% reaching baseline maturity in strategy, controls, and oversight. Writer's research goes further, finding that more than a third of organizations have no formal plan for deploying agents at all.
While these studies evaluate different enterprise cohorts, looking at their primary findings side-by-side reveals a stark industry trend:
Put plainly: most companies are further along in deploying agents than they are in governing them. That's not a gap that closes itself.
It's tempting to file "governance" under compliance busywork—something legal signs off on after the real work is done. The numbers say otherwise. Gartner now expects more than 40% of agentic AI projects to be cancelled by the end of 2027, and the reasons cited aren't model quality. They're escalating costs, unclear business value, and inadequate risk controls—exactly the problems governance exists to catch early, before they show up on a budget review.
The core technical issue is that agents don't fail the way traditional software fails. A broken integration throws an error you can see. An agent that takes a wrong action, escalates a case it shouldn't, or reasons its way to the wrong conclusion often does so silently, and the same prompt can produce different outcomes on different days. Industry researchers point to this non-deterministic behavior as the leading barrier enterprises cite when agent projects stall on their way to production, ahead of cost or integration complexity.
Regulators have noticed, too. The EU AI Act now carries penalties of up to €35 million or 7% of global turnover for prohibited AI practices, and that's before accounting for sector-specific rules in financial services, healthcare, and government. "We'll figure out governance once we scale" is no longer a workable sequence when the fines and the failures both arrive before the governance does.
This is the backdrop Salesforce has been building against. Over the past year, the company has spent real engineering effort hardening Agentforce's control layer—and it's worth understanding before you land in San Francisco, because most of the agentic-enterprise sessions on the schedule will assume you already know this foundation going in.
The Einstein Trust Layer sits between every prompt an agent generates and the underlying model, whether that model is Salesforce-hosted or a third-party provider. It handles data masking so sensitive fields never leave your trust boundary, zero-retention agreements with external model providers, and toxicity scoring on generated responses before they reach a customer or employee. None of that is exposed for show, either. Salesforce backs it with a real audit answer for the question every security team eventually asks: where does the data go, and does the model learn from it?
On top of that sits agent-level access control: the ability to filter which subagents and actions any given agent can invoke, and session tracing that gives admins a real record of what an agent did and why, not just what it was asked. That's the difference between an agent you can explain to an auditor and one you're simply hoping behaves.
The practical implication for anyone building on Agentforce: governance isn't a separate workstream bolted onto your rollout. It's a configuration decision you make at the same time you decide what the agent is allowed to do in the first place.
Strip away the vendor terminology and mature agentic governance tends to share a handful of traits, regardless of which platform it's built on:
None of this slows deployment down as much as leaders fear it will. If anything, it's the opposite: the organizations skipping these steps are the ones showing up in Gartner's cancellation statistics two years from now, not the ones who built the guardrails in from day one.
If last year's Dreamforce was about proving agents could work, this year is about proving they can be trusted to keep working, unsupervised, at scale, inside systems that hold real customer and financial data. The organizations getting the most out of Agentforce 360 aren't the ones that deployed fastest. They're the ones that treated governance as part of the architecture from the first design conversation, not a control they'd add once something went wrong.
That's the lens we're bringing to our own sessions and conversations at Dreamforce this year: not "how many agents can you deploy," but "how many can you actually stand behind." If you're heading to San Francisco and want to compare notes on what a governed agent rollout looks like in practice, find the Accelerize 360 team on the show floor, or reach out ahead of time.
Sources: Deloitte State of AI in the Enterprise 2026; KPMG AI Quarterly Pulse Survey Q2 2026; Google Cloud, The ROI of AI 2025; McKinsey Global AI Survey and AI Trust Maturity research; Gartner Hype Cycle for Agentic AI 2026; Writer enterprise AI planning research; Salesforce Einstein Trust Layer documentation; EU AI Act (EUR-Lex).