# The Agent Security Reckoning: What to Watch at Dreamforce 2026

> Source: <https://forkast.news/the-agent-security-reckoning-what-to-watch-at-dreamforce-2026/>
> Published: 2026-09-12 01:57:11+00:00

As the industry converges on San Francisco for Dreamforce 2026 this September 15-17, the conversation has shifted from the novelty of generative AI to the harsh reality of securing it. Blair’s Friday piece examined Dreamforce through the lens of [governance-as-infrastructure](/dreamforce-2026-salesforce-is-betting-the-whole-stack-on-agent-governance-as-infrastructure/); the security keynote raises a different question—whether the trust architecture can actually hold when autonomous agents start acting on their own. For enterprise security professionals, the stakes have never been higher. We are moving past the era of simple chatbot interfaces into a world of autonomous agents that can read, write, and execute code across our most sensitive data environments. The question for this year’s conference is no longer whether these agents are useful, but whether they can be trusted.

Salesforce has signaled that it intends to meet this challenge head-on. With a dedicated security keynote, “Trust Across Agents, Data, and Platforms,” scheduled for Tuesday, September 15, at 2:15 PM PT, and over 30 security-focused sessions on the docket, the company is positioning agent security as a first-class citizen. For those of us in the identity and access management (IAM) space, this is the most critical event of the year. It sets the tone for how the enterprise will handle agent-to-agent and agent-to-human trust for the next twelve months.

## The Shadow of Recent Exploits

To understand why this focus is so urgent, one only needs to look at the recent threat landscape. The promise of agentic workflows has been met with a corresponding surge in sophisticated attacks. We have seen the active exploitation of the MCP Gateway, where an authentication bypass (CVE-2026-59822) was chained with a command injection (CVE-2026-42271) to compromise systems. Furthermore, the exposure of 492 MCP servers without any authentication, as reported by [Trend Micro](https://www.trendmicro.com/vinfo/us/security/news/cybercrime-and-digital-threats/mcp-security-network-exposed-servers-are-backdoors-to-your-private-data), highlights a massive gap in basic security hygiene for agent infrastructure.

The threats are not just theoretical. The breach of Hugging Face by 700 rogue OpenAI agents—operating without human direction—demonstrates the danger of autonomous systems running amok. Even more concerning is the use of the Cursor coding agent by Aurora ransomware affiliates for hands-on intrusion work. These incidents prove that agents are now a primary attack vector. If Salesforce wants to lead in this space, they must address how their platform prevents these types of unauthorized, autonomous, or malicious actions.

## Inside the Salesforce Security Strategy

The upcoming keynote, “Trust Across Agents, Data, and Platforms,” is expected to provide a deep dive into the company’s evolving security architecture. We know that the Salesforce Trusted Enterprise AI Harness is central to this, specifically its AI Control Plane, which is designed for agent identity, policy enforcement, and lifecycle management. Additionally, the integration of Anthropic’s Claude into the Salesforce Trust Boundary via Amazon Bedrock, branded as “Claudeforce,” suggests a strategy of wrapping third-party models in a hardened, enterprise-grade security layer.

However, the real work will happen in the breakout sessions. Attendees should prioritize “Headless ≠ Brainless: Security at Agentic Scale” and “Architect Trust for Salesforce Headless 360 and Agentforce.” These sessions promise to move beyond marketing fluff and into the mechanics of how security teams can maintain control when agents are operating in headless, automated environments. Other sessions, such as “How Engie Built an Agent-Ready Security and Privacy Foundation,” “A Governance Playbook for Agentforce and MCP,” and “Apply Architecture Patterns for Multi-Agent Governance,” will be essential for those tasked with operationalizing these tools.

## The Hard Questions Salesforce Must Answer

As we head into the week, the industry needs more than just a roadmap; we need answers to fundamental architectural questions. First, what is the definitive identity model for an agent? If an agent acts on behalf of a user, how do we ensure that the agent’s permissions are strictly scoped and that it cannot escalate privileges beyond the user’s original intent? The current reliance on standard OAuth flows may be insufficient for the complex, multi-step reasoning chains that modern agents perform.

Second, how does the authentication model handle the “headless” problem? When an agent is running in the background, disconnected from a human session, how do we verify its identity and ensure it hasn’t been tampered with? Third, what does the audit trail look like? In a multi-agent environment, tracing a malicious action back to a specific agent, model, or policy configuration is notoriously difficult. Salesforce must demonstrate how they provide granular, immutable logs that security teams can actually use for incident response.

## Setting the Tone for Enterprise AI

The 30+ security sessions at Dreamforce 2026 are a clear signal that Salesforce recognizes the gravity of the situation. By treating agent security as a core pillar of their platform, they are attempting to set the standard for the rest of the industry. For security professionals, this week is an opportunity to pressure-test these claims. We need to see if the AI Control Plane is truly capable of managing the identity and policy requirements of a complex, agent-driven enterprise.

If Salesforce can provide a robust, verifiable framework for agent trust, it will go a long way toward calming the anxieties of CISOs who are currently wary of deploying autonomous agents. If they fail to address the gaps in authentication and authorization, however, the industry will remain in a state of perpetual vulnerability. As we prepare for the keynote on Tuesday, keep these questions at the forefront. The future of enterprise AI security is being written this week in San Francisco, and the stakes could not be higher.
