SR 26-2 Left Agentic AI Out of Scope. Dreamforce Calls It Infrastructure Anyway · Enterprise Agentic AI Insights
OCC, Fed, and FDIC guidance (SR 26-2, April 2026) explicitly excludes agentic AI from model risk examination. Five months later, Dreamforce 2026 calls agent governance infrastructure. What regulated buyers should ask before they renew.
Three days on governance as infrastructure. Five months after the regulator opted out. Dreamforce opens Tuesday, September 15, at Moscone Center in San Francisco, and the theme running through the keynotes is governance treated as infrastructure rather than an add-on. Agentforce annual recurring revenue crossed 1.5 billion dollars this quarter, up 240 percent year over year. The Claudeforce partnership with Anthropic, announced August 26, adds 37 prebuilt sales skills running on Claude's reasoning inside Salesforce's existing Trust Boundary permission model. MuleSoft's Agent Fabric gets its own keynote September 16 at 3:30pm Pacific, an orchestration and observability layer built to answer exactly the governance question a bank examiner would ask. Here is the fact sitting underneath all of it. On April 17, 2026, the OCC, the Federal Reserve, and the FDIC jointly issued SR 26-2, revised model risk management guidance that replaced bulletins dating back to 1997. Buried inside: generative AI and agentic AI models are described as "novel and rapidly evolving," and as such, not within the scope of this guidance. No enforceable standard applies to them under this letter. Non-compliance with any AI-specific expectation triggers no supervisory criticism, because there is no AI-specific expectation yet. The guidance itself is aimed mainly at institutions holding more than 30 billion dollars in assets. Regulators said a separate request for information on AI-specific model risk was coming. As of this writing, five months later, it has not landed. So the agencies that would normally examine a bank's model governance looked at agentic AI specifically and said: not yet, not here, not with this letter. 1. The vendor side is not wrong to call it infrastructure Claudeforce's design is a real answer to a real problem. Agents run under the authenticated permissions of the human user who invoked them, inside the same Trust Boundary that already governs Salesforce data access, rather than under a separate, broader service account. Dario Amodei said plainly that the effort enterprises put into managing permissions at scale is substantial. That is a governance primitive, not a marketing line, and it is worth taking seriously regardless of which vendor a given buyer ends up choosing. 2. The ROI numbers are not in the room yet either MarketScale reported on September 6 that Dreamforce's own pre-event materials carry no customer-reported ROI figures, no adoption metrics, and no numbers on what an agent actually costs to run in production. McKinsey survey data cited in Forkast's September 11 Dreamforce preview found 80 percent of respondents reporting individual productivity gains from AI, and only 37 percent seeing that gain show up in organizational EBIT. The same preview cites a specification-gap finding: 79 percent of multi-agent failures trace back to how the task was specified, not to the underlying model. 3. Two true things, read together, are the actual finding A regulator explicitly declined to examine agentic AI under its own model risk letter. A vendor is spending three days calling the resulting gap infrastructure. Neither claim is false. But infrastructure nobody outside the vendor has examined is still exactly that: unexamined. Governed and not yet reviewed by anyone with supervisory authority are not opposites. This week, for regulated buyers, they describe the same three days in the same city. The Monday question If SR 26-2 will not grade your agent program this cycle, and Dreamforce will not hand you customer ROI figures this week, the actual due diligence question does not change: who inside your institution reviewed the permission model your agents inherited, wrote it down, and can produce it on request. Not whether the vendor published a trust boundary. Who looked at yours, specifically, and signed their name to it. If that person does not exist yet, that is not a Dreamforce problem. It is this quarter's project, independent of which platform gets picked this week. Sources - OCC, Federal Reserve, FDIC: Updated Model Risk Management Guidance (SR 26-2), April 17, 2026 - Kevin D. Oden & Associates: New Federal Model Risk Guidance (SR 26-2) Leaves Generative and Agentic AI Outside Scope, June 24, 2026 - Dreamforce 2026: Salesforce Is Betting the Whole Stack on Agent Governance as Infrastructure, Forkast, September 11, 2026 - Dreamforce 2026 Goes All In on AI Agents, But ROI Numbers Are Still Missing, MarketScale, September 6, 2026 - Salesforce and Anthropic Announce Claudeforce, Salesforce Newsroom, August 26, 2026 - Agentforce ARR Hits $1.5B: Can It Boost Salesforce Revenue Growth?, Yahoo Finance, September 2026