Agentforce Agent Inventory: The Governance Gap CIOs Need to Close Now · Enterprise Agentic AI Insights

Agent Fabric is GA but most Salesforce orgs still have no agent inventory or spend controls. EU AI Act enforcement starts Aug 2. Here is what to do before then.

The problem sitting on your desk right now You approved Agentforce. You approved the Bedrock connector. Someone on the service team spun up a Copilot Studio agent that touches your Salesforce data. Three months ago. Without a ticket. That is not a hypothetical. That is the median enterprise Salesforce deployment in Q2 2026. Agentforce annual recurring revenue just crossed $800 million, up 169% year over year. Multi-agent adoption is projected to surge 67% by 2027. The agents are proliferating. The question your board will ask at the next QBR is not whether you have AI. It is whether you know what your AI is doing. Right now, most CIOs cannot answer that question. --- What is actually failing Salesforce shipped Agent Fabric — their multi-vendor agent control plane — to general availability this month. It connects Agentforce agents, Bedrock agents, and Microsoft Foundry agents into a single governed layer with deterministic orchestration, LLM token cost visibility, and Trusted Agent Identity for mobile approval of non-human agent actions. The control plane exists. The problem is that most enterprise teams have not implemented it. The gap between "we have Agentforce" and "we can account for every agent action" is where the risk lives. And it is getting expensive to leave open. --- Why this just became a board conversation The EU AI Act GPAI enforcement clock does not care about your implementation backlog. On August 2, 2026 — 62 days from today — the European Commission's supervision and enforcement powers over GPAI model providers activate. The Commission can access code, model weights, and infrastructure. Paper compliance is explicitly insufficient under the published guidelines. Here is the part most enterprises miss: GPAI provider compliance does not discharge the obligations of the orchestration layer. And orchestration layer compliance does not discharge enterprise deployer obligations. Every layer owns its piece. If your agents are running in Europe — or touching European customer data — and you cannot produce an audit trail of what they did and who approved each action, that is a deployer-level exposure. Not a vendor problem. Yours. Add to that: NIST AI RMF Map/Measure functions require traceable agent actions. SR 11-7 (for financial services) extends model risk management to AI agents. The CRO's question "can we produce evidence of agent behavior?" is no longer a future question. It is a Q3 audit question. --- The move: three things to do before August 2 You do not need to rebuild your Salesforce architecture. Agent Fabric GA gives you the control plane. Here is how to sequence the work: 1. Run your agent inventory before anything else. Pull a list of every active Agentforce agent, every third-party agent with a Salesforce connector, and every Copilot Studio or Bedrock agent touching your Salesforce data. Most orgs have between 3x and 6x more agents in production than their architecture diagram shows. Use Agent Fabric's discovery layer and MuleSoft's Anypoint to surface the full picture. 2. Implement LLM Governance in AI Gateway. Token usage, cost, and data flow visibility for every model call is now available natively in Agent Fabric. This directly answers the "what is this costing and what data is it seeing" question your CDO and CFO are asking. Get this live before the Summer '26 release ships on June 15. 3. Map agent actions to identity. Trusted Agent Identity — Salesforce's mobile approval mechanism for non-human agent actions — is the fastest path to an audit trail. Prioritize the agents that touch customer records, financial data, or any field that feeds your compliance reporting. These are your highest blast-radius agents. A targeted 6-week sprint on these three tracks gets most enterprise Salesforce teams from "we have Agentforce" to "we can account for our agents" before the August deadline. That is the difference between a governance posture and a governance problem. --- What we are seeing in the field Organizations that are ahead of this have one thing in common: they treated agent governance as an infrastructure problem, not a compliance checkbox. They stood up the control plane before they scaled the agent count. The ones who are behind are running fast rollouts with no agent registry, no spend controls, and no audit trail — betting that the enforcement window gives them time to catch up. The enforcement window is 62 days. That is not a comfortable margin if you are starting from zero. If you are a CIO or CDO inside a Salesforce-heavy enterprise and you want a direct read on where your gaps are, the AI Success Pack assessment is structured exactly for this: principal-led, domain-savvy, and built to give you a clear picture in 30 minutes. --- Sources - Salesforce Agent Fabric GA announcement - MuleSoft Agent Fabric launch - Salesforce Summer 2026 release - Futurum: Agent Fabric governance analysis - Salesforce Connectivity Report 2026 — multi-agent adoption - KPMG / CIO: AI ROI disconnect - CIO: Scale or fail 2026 - EU AI Act GPAI enforcement timeline - AI regulation 2026 overview — multistate stacking - Sirocco Group: Agent Fabric the real test

Open the formatted article on Ariana.Digital →