
Benioff’s Slight of Hand
Dreamforce 2026 through the 5 Pillars. They ran my playbook one layer up and kept the alpha.
The setup
Marc Benioff spent most of this year fighting a narrative. At its June lows Salesforce was down more than 40% for 2026, with a P/E of 11 against roughly 20 at the start of the year, reflecting a market that had stopped believing an application company had a future in an agent world. The thesis was simple and brutal: if agents do the work, the UI is dead, and a CRM without a UI is a database somebody else queries.
So on September 15 at Moscone he took the stage and called the SaaSpocalypse crazy nonsense, with Jensen Huang beside him agreeing that the end of software is not near. His actual formulation was better than the dismissal: not the end of software, but maybe the end of software that makes humans do all the work.
Then he shipped the answer. AIforce, a live interface layer launching with Claudeforce, Slackforce and Agentforce Coworker. Koa, Salesforce’s first CRM reasoning model. Google Cloud and AWS partnerships announced the same day. Robin Washington put a fiscal 2030 revenue target above $63 billion in front of investors. Stifel, Guggenheim, TD Cowen and Cantor Fitzgerald all came back with $300 price targets.
The market bought it. I want to talk about what they actually bought, and I am going to start with the money, because the money is where this gets interesting.
The claim is real
I run vendors through five pillars: Territorial, Operational, Technological, Legal, Financial. Most vendors fail all five and market as though they passed. Salesforce is more interesting, because two narrow layers pass on the merits and I want them on the record before I take the rest apart.
Koa’s training provenance is clean. Post-trained from NVIDIA’s open-weight Nemotron on a corpus built entirely from synthetic CRM scenarios, with Salesforce controlling the weights and running it in its own infrastructure so no customer data crosses the trust boundary during inference. That answers four questions I normally spend a week extracting from a vendor’s legal team.
Headless 360 is the better one. A single MCP server exposing all of Salesforce through four tools, Discover, Describe, Dispatch and Dispatch Read Only, with existing permission sets, field-level security and sharing rules still applying. Open standard, small stable surface, your permission model intact. Real portability at the interface, and it makes Salesforce more substitutable rather than less. Shipping it took nerve.
Now watch where the credit goes.
Financial: they ran my playbook one layer up
Launch coverage describes Agentforce’s AI gateway routing high-volume, well-scoped work to Koa while judgment-heavy work stays on Claude or GPT.
Read that twice, because it is my own TCO strategy, verbatim. Baseline on open weights, burst to frontier tokens when you actually need the intelligence. I have been telling enterprises to run exactly this for two years.
Salesforce ran it. One layer above you. And kept the spread.
Your rate card did not move. Flex Credits at $500 per 100,000, a standard action at 20 credits, voice at 30, $2 per conversation, $125 per user per month, and now $2 per successful resolution. Four concurrent ways to be billed for the same product, and buyers cannot model their own costs before deployment because nobody knows their actions-per-conversation ratio until months in.
The detail that gives the game away is a 10,000-token threshold per action, beyond which additional credits apply. The action is not a unit of work. It is a token meter wearing a business-outcome costume.
None of this is really an argument about price. A perfect, published, predictable rate card would change nothing here. The point is that the arbitrage between what inference costs and what an action sells for is now a line on someone else’s income statement. That spread is alpha, it was generated by your workload, and you do not own it.
It is worse than a margin grab
Everything above assumes the routing at least saves somebody money. Look harder at who.
Whatever else is true about frontier models, and this newsletter has spent a year cataloguing what is wrong with depending on them, they are better at the job and more efficient at it. A stronger model reaches the same outcome in fewer steps, fewer retries, fewer context re-reads. That efficiency is the thing you are actually buying when you pay frontier prices, and on a per-outcome basis it often makes them the cheaper option rather than the dearer one.
Now cap the work at Koa and watch the arithmetic.
Salesforce’s cost meter is tokens. Your price meter is actions. Those are not the same meter, and routing down improves one while degrading the other. A weaker model that needs six actions where a frontier model needed three has just halved Salesforce’s inference cost and doubled your invoice, at an unchanged $0.10 per action. You pay a premium price for discount intelligence, and the premium widens precisely as the intelligence narrows.
Then ask who decides. The gateway classifies what counts as well-scoped and high-volume versus judgment-heavy. That classifier belongs to the vendor whose gross margin improves every time it routes down. Nobody has published its logic and no customer sees the decision. You cannot audit a routing choice you are billed for and not shown.
And the worst line item never reaches the invoice. When a downgraded model fails and the case escalates to a person, that cost lands in your service org, not in Salesforce’s revenue. Outcome-based pricing hedges this in one narrow place, since a Help Agent resolution is only billable after at least two turns with non-negative feedback and nothing is charged on escalation. Good design, genuinely. It also covers exactly one product while the rest of the estate stays on actions, where every extra retry is revenue.
So the financial pillar does not merely fail. It inverts. The sovereignty argument for open weights has always been that you trade some capability for control and a lower unit cost. Here you surrender the control, keep the capability loss, and pay a higher effective rate for the privilege. That is not a trade. It is a toll.
The fiscal 2030 target is above $63 billion. Ask yourself which side of the spread that number lives on.

Territorial: fail
Hyperforce EU Operating Zone launched in March 2023 and confines records and supporting logs to EU territory with EU-based support. A 2023 answer to a 2023 question, and it concerns data at rest.
The 2026 question is who sits in the request path. Gemini went GA in the Agentforce Reasoning Engine. AWS brought Agentforce model choice through Bedrock. Claude arrives through Claudeforce. My standing rule has not moved: a hosted frontier model anywhere in the request path is an automatic Territorial fail, and no residency certificate for data at rest changes it, because the sensitive thing was never the record. It was the prompt.
Operational: fail, partial credit
EU-based support personnel is a real mitigation and I will not pretend otherwise. But they hold the keys, they run the paging rotation, and the agent decision record lives in their control plane. Shield BYOK covers data at rest. There is no equivalent for the agentic layer, and the agentic layer is the one now making the decisions.
Technological: fail, and this is the sleight of hand
Koa is built on open weights. Salesforce controls those weights. You cannot audit it, fork it, or self-host it.
Open-weight lineage that accrues to the vendor is an ingredient claim, not a sovereignty claim. Nemotron being open is a fact about Salesforce’s supply chain, not about your control. Runs inside Salesforce’s trust boundary means the boundary moved one hop. It did not come home. If the test is can I audit, fork, self-host, Koa scores zero of three and still gets warm coverage, because the word open appeared in the sentence.
Headless 360 passes here, at the protocol layer. But a calling convention has no Territorial or Legal grade of its own. It inherits whatever executes behind it, and behind it is a runtime that fails.
Legal: hard fail, and it got worse this month
Salesforce is US-domiciled, so CLOUD Act reach follows the company rather than the region. Residency is where data physically sits. Sovereignty is which legal authority can reach it, and storing data in Europe does not mean European law exclusively governs it.
This is also why the obvious question about Koa’s roadmap is not worth asking. Koa is in pilot with general availability expected in US regions during Winter 2026, and people will want to know when a European region lands. It would not matter. A Koa region in Frankfurt run by a US company is a US-reachable model with a German postcode. Moving the rack does not move the jurisdiction.
Meanwhile, count who Salesforce added to the path in one week: Anthropic, Google, AWS, NVIDIA. Every one US. The mitigation offered is Zero Data Retention, under which business data routed to external model providers is used only to generate the response and not retained afterwards. That is a contract, and contracts lose to statutes. Microsoft’s own chief legal officer in France told the French Senate the company cannot fully guarantee EU data is beyond CLOUD Act reach, and Microsoft has spent considerably more on this problem than Salesforce has.
FedRAMP High, DoD IL5 and thirteen country authorizations are procurement credentials. They get you on the bid list. They are not jurisdictional insulation, and nobody at Salesforce claims they are. The claim gets made for them, in slide decks, by people who should know better.
For contrast, AWS stood up its European Sovereign Cloud in January 2026 in Brandenburg, operated by German subsidiaries with EU-resident staff, its own root certificate authority, and an independent advisory board. Those subsidiaries remain wholly owned by Amazon. Even that, the most serious structural attempt any hyperscaler has made, does not fully clear the pillar. Salesforce did not attempt it.
The executive TCO
The comparison that matters is not Agentforce versus a competitor’s agent. It is Agentforce versus owning the same routing decision yourself.
Salesforce’s own architecture proves the economics work. A specialized open-weight model handles the bulk of well-scoped agentic work at a fraction of frontier cost, with frontier models reserved for genuine judgment. That pattern is now validated by a company with every incentive to tell you the opposite.
The only question left is who holds the gateway. If Salesforce holds it, you pay a metered price per action with a token threshold inside it, across four pricing models you cannot forecast, on a rate card that does not fall when their costs fall, driven by a routing decision you cannot see. If you hold it, you own that decision, you can re-price it whenever the model market moves, and it moves quarterly. You also get to make the trade in the direction that suits your workload, spending more on intelligence exactly where intelligence pays for itself.
Everything else here is a rounding error against that one architectural choice. The Territorial and Legal failures are real and they will matter to your regulator. The Financial one will matter to your CFO every month for the life of the contract.
Two questions
I would put exactly these to Salesforce, and to any vendor selling you an agentic layer:
Can I export the full agent decision record, which agent acted, on whose authority, through which model, and why, in a schema I can take somewhere else?
Can I pin inference to a model and a region of my choosing, including one I host?
Answer both and Headless 360 becomes a genuine sovereignty story, one of the better ones in enterprise software. Leave them open and it is a more elegant front door to the same dependency, with better engineering than most and a cleaner narrative than anyone.
Salesforce did not sovereign-wash here. They did something harder to spot. They earned credit at two narrow layers, honestly, then let the market apply it to a runtime where nothing changed. That is the card moving. It is not a lie, it is a load-bearing omission, and it works better than a lie because every individual sentence survives fact-checking.
Run your estate before someone runs it for you
Agentcy Labs runs procurement-facing Sovereignty Assessments: your vendor estate, every pillar, named risk factors, no pass/fail theatre. Sovereignty is not binary. It is control with an acceptable risk sidecar, and the worst posture is the ostrich, not the imperfect one. If you are deploying an agentic layer this quarter and cannot answer those two questions about your own stack, that is the assessment.
Amit
Sources
Koa announcement, Salesforce, 15 Sep 2026: https://www.salesforce.com/news/press-releases/2026/09/15/koa-reasoning-model/
Dreamforce 2026 keynote roundup: https://synconai.com/dreamforce-2026-keynote-announcements
Benioff on the SaaSpocalypse, TechRadar Pro: https://www.techradar.com/pro/salesforce-ceo-marc-benioff-says-the-saaspocalypse-is-crazy-nonsense-and-jensen-huang-agrees-with-him
Salesforce stock decline and P/E context, CNBC: https://www.cnbc.com/2026/08/26/were-raising-our-price-target-on-salesforce-after-results-defy-saaspocalypse.html
FY2030 revenue target and analyst price targets: https://finance.biggo.com/news/30d06d3a-acbf-4bf4-b62a-d5d8f4e6023c
Headless 360 architecture, four tools and permission model: https://byteiota.com/dreamforce-2026-what-salesforce-developers-must-do-now/
Koa gateway routing, high-volume to Koa and judgment-heavy to frontier: https://ailearningguides.com/salesforce-koa-crm-reasoning-model-guide/
Agentforce rate card, Flex Credits, conversations, pay-per-resolution: https://ashapurasoftech.com/blog/agentforce-pricing-flex-credits-explained/
Flex Credits token threshold per action: https://www.jitendrazaa.com/blog/salesforce/salesforce-agentforce-credits-cost-model-complete-guide-2026/
Outcome-based pricing conditions for billable resolutions: https://help.salesforce.com/s/articleView?language=en_US&id=ai.usage_flex_credits.htm&type=5
Hyperforce EU Operating Zone launch, March 2023: https://www.salesforce.com/news/press-releases/2023/03/02/hyperforce-eu-operating-zone-news/
Residency versus sovereignty distinction: https://www.grax.com/blog/what-you-should-know-about-salesforce-hyperforce/
FedRAMP High, DoD IL5, thirteen country authorizations, IDC MarketScape: https://www.salesforce.com/news/stories/idc-marketscape-vendor-assessment-2026-announcement/
AWS European Sovereign Cloud, CLOUD Act exposure, Microsoft testimony to the French Senate: https://eualternative.eu/guides/choosing-eu-cloud/
Zero Data Retention description: https://www.techtimes.com/articles/327622/20260916/salesforce-launches-aiforce-crm-data-now-works-claude-slack-amazon.htm
