Salesforce outlined how AI agents worked across company lines
Salesforce brought specialists from 21 organizations together to discuss trust in AI agents that worked across company boundaries. The talks fed into a new white paper with recommendations.
What happened
The shift from isolated large language models (LLMs), AI systems that processed text, to connected multi-agent systems, groups of AI programs that worked together, promised a revolutionary leap in productivity. It allowed autonomous AI to negotiate, trade and collaborate across company lines. Agents from third-party vendors and partners could access data and execute tasks across a platform, according to the company.
In the agentic world, that perimeter was blurring. Agents built on diverse platforms operated across various ecosystems, integrating data and executing tasks across organizations. That development required a fundamental shift in enterprise architecture, the structure of company software systems, and a rethinking of how to approach security.
Old perimeter security no longer covered how agents operated
Traditionally, enterprise security functioned like a castle with a moat, with a clear perimeter separating the internal from the external. In the agentic world, that perimeter was blurring. The threats they faced were evolving too.
For investors, the point was architectural rather than incidental. When software acted on its own across systems, control could no longer rest only on the outer boundary. Confidence in automation then depended on whether security moved with every interaction.
Hidden instructions inside systems created a different threat
A malicious prompt could lie latent in an agent’s knowledge base or past procedures, ready to be unknowingly executed, automated, amplified and potentially originating from within an organization’s own system. This internal, pervasive nature of agent-based threats made Zero Trust, explicit and continuous verification for every interaction, not just a best practice but the foundation for confident innovation.
The risk differed from a break-in from outside. Because the instruction could already sit inside the system, every interaction needed checking. That explained why the company presented continuous verification as a condition for wider use.