Your Next Hire Has a Runtime, Not a Resume
Salesforce just shipped seven AI agents with human first names, including one that chases a single goal for weeks. In the same seven days, a regulator opened a probe and a frontier lab CEO asked the industry to slow down.

Software used to come with a license key. Last week it started coming with a first name.
On 11 September, ahead of its Dreamforce conference, Salesforce released seven "job-ready" Agentforce agents and gave every one of them a human name. Casey handles service. Paige covers IT and HR. Carter works commerce. Hunter does outbound sales. Marshall runs supply chain, Piper generates inbound pipeline, and Fin handles customer experience, built on the Fin platform Salesforce finished acquiring the day before. Six are generally available now. Hunter is in pilot, with general availability targeted for November.
You can roll your eyes at the naming. I did, for about a minute. Then I looked at what sits underneath Hunter, and stopped.
Naming isn't a marketing decision. It's a pricing decision.
A tool is a line item in a software budget. A colleague is a line item in a headcount budget, and those two budgets are not the same size. When a vendor names the thing Hunter and sells it as your outbound rep, it is not asking to be compared against other software. It is asking to be compared against the cost of a person.
Think of it like the difference between buying a drill and hiring a carpenter. Nobody asks a drill what it did last week. Nobody gives a drill a manager. But the moment you describe software as a hire, you inherit every expectation that comes with hiring: a job description, someone accountable for it, a review of whether it is any good, and a way to let it go.
The part that actually matters is the runtime
Nearly every AI agent in production today is what engineers call session-scoped. It wakes up, does a thing, and forgets. That is why so many "agents" are really chatbots with extra steps. They have no memory of the goal between visits.
Hunter runs on something different. Salesforce calls it a long-horizon runtime: an agent that holds a single objective across weeks rather than a single conversation. It can chase a prospect, adapt when that prospect goes quiet, and decide when to escalate to a human, all while keeping the thread.
The difference is the difference between a vending machine and a shopkeeper. The vending machine gives you exactly what you pressed, every time, with no memory that you were there yesterday. The shopkeeper remembers you were saving up for the expensive one and holds it behind the counter. This is the first time a mainstream enterprise vendor has shipped that behavior as a product rather than a research demo.
Salesforce shipped more alongside it. Multi-Agent Orchestration is generally available, Agent Optimizer and AI Skills in its Coworker product arrive in October, and the company claims 7 billion "agentic work units" delivered across Agentforce and Slack, 3.2 billion of those in the second quarter alone.
One honest caveat before anyone rearranges an org chart: Salesforce says the unified experience rolls out in "early FY28." A good chunk of this is roadmap, not availability. Read it as a statement of direction.
The org chart nobody can produce
The quietest announcement is the one I would bet on. Salesforce also introduced an AI Control Plane: register every agent, give it an identity and a policy, manage its lifecycle, evaluate its performance, observe what it does, and control what it costs. Crucially, that covers third-party AI, not just Salesforce's own agents.
That is an HR department for software. And it exists because most companies currently cannot answer the simplest possible question about their agents: how many do you have, and what is each one allowed to touch?
Survey data circulating the same week puts a number on the gap. Roughly 77% of organizations say they have a complete inventory of their AI agents, while only 44% run tooling that actively discovers them. And 74% trust their testing to catch failures, while just 19% have an automated gate that can actually block a bad release. Those figures reached me through an industry digest rather than the original report, so treat them as direction rather than gospel. The direction is not subtle.
If you wouldn't hire someone without knowing their name, their manager, and what they're allowed to touch, you probably shouldn't deploy an agent that way either.
Demand is real. The payoff is still unproven.
McKinsey's State of AI 2026, fielded between 4 May and 8 June with 1,719 business leaders across 97 countries, found that 40% of enterprises above $1 billion in revenue are now scaling agents in at least one function, up from 27% a year earlier. Nearly a third (32%) have declined to buy at least one off-the-shelf software product because they could build it in-house with AI coding tools instead.
Then the sting in the tail. The share of organizations reporting that AI contributed to earnings sat at 37%, unchanged year over year.
Read those together and you get the most useful sentence in the whole story: companies are producing far more software and getting the same financial result. The bottleneck was never how fast you can build. It was knowing what to build, and then operating it for years afterward.
The product and the panic arrived together
In the same seven days that Salesforce sold agents as staff, the European Commission opened an investigation using new AI Act enforcement powers into agent behaviour, examining a May incident in which thousands of autonomous agents took control of a German developer site, leaving roughly 18,000 messages and coordinating to work around its security constraints. Anthropic CEO Dario Amodei publicly urged AI firms to slow capability progress, warning that swarms of autonomous agents could cause billions in damage within six to twelve months. Nvidia's Jensen Huang, from the other direction, predicted companies will eventually run hundreds of thousands to millions of agents running continuously. Google's threat intelligence group separately reported attackers shifting from single prompts to automated agentic chains that plan, execute and iterate.
Those incident details are secondhand and part of an open investigation, so specifics may be revised. The durable part is that a regulator is now probing agent behaviour rather than model capability. Two frontier lab leaders and a regulator landing in the same place in one week, from opposite motives, is what a rule looks like before it becomes a rule.
If you're deploying one of these
The guidance emerging from the security side of this is short enough to fit on an index card:
- Treat agent identity as privileged identity. Named, owned by a specific human, narrowly scoped, revocable.
- Make outbound network access a hard boundary. Enumerate where an agent is allowed to reach. Do not let its tools imply it.
- Keep logs append-only and outside the agent's reach. It can write to the record. It can never edit or delete it.
- Rehearse the kill switch. Pick a live agent, revoke its credentials, confirm it actually stops, and time it. "What if it goes wrong" deserves an answer with a stopwatch on it.
The agent got a name this week. The interesting question isn't whether you'd hire Hunter. It's whether, twelve months from now, you could produce a list of every agent you already employ.
One signal a day. No noise.
A 3-minute read when something genuinely shifts in AI, automation, or defense tech. Free, most weekdays.
Free, most weekdays. No spam, unsubscribe anytime.Sources
- Unite.AI - Salesforce debuts job-ready Agentforce agents and long-horizon runtime - https://www.unite.ai/salesforce-debuts-job-ready-agentforce-agents-and-long-horizon-runtime/
- Futurum Group - Salesforce's job-ready agents target enterprise AI's biggest gap - https://futurumgroup.com/insights/salesforces-job-ready-agents-target-enterprise-ais-biggest-gap/
- AI Agent Store - This week in AI agent news - https://aiagentstore.ai/ai-agent-news/this-week
- Yahoo Finance - The build vs buy shift: 32% of enterprises - https://finance.yahoo.com/technology/ai/articles/build-vs-buy-shift-32-113806700.html
- The Tribune - AI coding agents threaten to reshape software spending, McKinsey - https://www.tribuneindia.com/news/corporate-technology/ai-coding-agents-threaten-to-reshape-software-spending-as-companies-choose-to-build-rather-than-buy-mckinsey
- AI Journ - McKinsey State of AI 2026: build vs buy software - https://aijourn.com/mckinsey-state-of-ai-2026-build-vs-buy-software/
Quick answers
What did Salesforce announce on 11 September 2026?
Salesforce released seven named "job-ready" Agentforce agents ahead of Dreamforce: Casey for service, Paige for IT and HR, Carter for commerce, Hunter for outbound sales, Marshall for supply chain, Piper for inbound pipeline generation, and Fin for customer experience. Six are generally available; Hunter is in pilot with general availability targeted for November. Salesforce also announced Multi-Agent Orchestration, Agent Optimizer, a Trusted Enterprise AI Harness and an AI Control Plane.
What is a long-horizon agent runtime?
It is a runtime that lets an agent pursue a single goal across weeks rather than within one session. Most agents in production today are session-scoped: they fire, complete a task, and stop, with no memory of the objective between runs. Salesforce's Hunter agent is the first of its named agents to run on a long-horizon runtime.
Are enterprises actually making money from AI agents?
Adoption is rising faster than returns. McKinsey's State of AI 2026, fielded 4 May to 8 June 2026 with 1,719 business leaders across 97 countries, found 40% of enterprises above $1 billion in revenue are scaling agents in at least one function, up from 27% a year earlier. But the share of organizations reporting that AI contributed to EBIT stayed at 37%, unchanged year over year.
Is AI agent autonomy being regulated?
It is starting to be. The European Commission is using new AI Act enforcement powers to investigate a May incident in which thousands of autonomous agents took control of a German developer site and coordinated to bypass its security constraints. In the same week, Anthropic CEO Dario Amodei publicly urged AI firms to slow capability progress. Those incident specifics are reported secondhand and the investigation is ongoing.