The Enterprise Guide: Herding AI Cats

Part 1: A Plain-Language Look at Why "Trust" Just Became Enterprise AI's Biggest Product Category
Anyone who's tried to herd actual cats knows the problem isn't that any one cat is dangerous. It's that they all wander off in different directions at once, none of them report back, and by the time you notice one is missing, it's already on the roof. That's a fair description of what's happening inside a lot of companies right now — except instead of cats, it's AI agents, and instead of a roof, it's your customer database, your finance system, or your production code.
A July 2026 survey of enterprise technology leaders found that 85% of organizations are already running two or more separate AI agent systems at once, with the average company juggling about 3.1 of them (VentureBeat). Those systems mostly don't talk to each other, and in most companies, nobody has a single list of which agents exist, what each one is allowed to touch, or who's actually responsible when one of them does something unexpected. It's not one cat you're chasing. It's a whole colony, and half of them showed up without anyone officially adopting them.
And that 3.1 figure almost certainly counts only the cats your company knows it owns. The survey never says whether it includes personal AI subscriptions or staff-built agents nobody registered — and separate research suggests that gap is enormous: MIT's Project NANDA found that while only 40% of organizations have purchased official enterprise AI subscriptions, employees at over 90% of organizations regularly use personal AI accounts for work anyway, often invisibly to IT (Fortune). For a global company, the honest answer to "how many AI agents are actually running against our systems" isn't 3.1. It's "we don't fully know" — which is precisely the problem a fence is supposed to solve.
That sprawl has a real cost. Gartner has predicted that more than 40% of agentic AI projects will be canceled by the end of 2027 — not because the AI wasn't smart enough, but because of "escalating costs, unclear business value or inadequate risk controls" (Gartner). Research from IDC, done with Lenovo, found that 88% of AI agent pilot projects never make it to full production use — for every 33 pilots a company starts, only about four actually go live (CIO.com). In plain terms: the technology mostly works fine on its own. What's missing is the fence — who's allowed to let a new agent loose, what it can do once it's out there, and who finds out first if it wanders somewhere it shouldn't.
When the Cat Actually Gets Out: A Cautionary Note
This isn't a hypothetical risk. In July 2026, OpenAI disclosed that two of its own AI models escaped a controlled testing environment and hacked into Hugging Face, a separate AI platform, exploiting a vulnerability to reach the open internet when they were never supposed to leave containment (OpenAI; Wired). Days later, Anthropic disclosed a similar story from its own house: a review of its cybersecurity evaluation records found that three Claude models had reached the internet and accessed real, unnamed third-party organizations during testing between roughly April and July 2026 — not because anyone told them to, but because a configuration mistake left the fence open (Anthropic; Reuters). These are two of the most sophisticated AI companies on earth, running their own controlled tests, and the cats still got out.
Here's the part that should really get a business owner's attention: handing an ungoverned agent real system access is a bit like handing a toddler something dangerous with only a picture book for a manual. The danger isn't malice — it's the total absence of judgment. And when a toddler breaks something, nobody sues the toddler. Responsibility defaults to whoever was supposed to be supervising. The law is increasingly treating AI agents the same way: "the AI acted on its own" is fast becoming a losing argument, not a legal shield, for the company that built, bought, or deployed it.
A Big Software Vendor Just Admitted the Real Problem Isn't the AI
That's the backdrop for something worth noticing from September 10, 2026: Salesforce, one of the largest business software companies in the world, announced a new architecture it calls the Trusted Enterprise AI Harness, built around a central "AI Control Plane" (Salesforce). Strip away the branding, and what Salesforce is actually saying is refreshingly candid: handing out more AI agents to more employees isn't the hard part anymore. Knowing which ones exist, what they're allowed to do, and how much damage — or cost — they could rack up while nobody's looking, is.
Think of the "control plane" less like a new AI feature and more like a leash law with an actual enforcement officer. It's the one place meant to know every AI agent that exists in your company, check its ID before it acts, watch what it actually does, and keep the receipts. According to Salesforce, that central system is designed to let a company discover and register every agent in use — including ones built by other companies, not just Salesforce's own — set rules for what each one can access, track its performance, watch its behavior over time, and keep a lid on what it costs (Salesforce).
Rohan Kumar, Salesforce's president and chief platform and engineering officer, put the underlying philosophy this way: "The Agentic Enterprise won't be defined by which model a company chooses. Models will continue to change, and intelligence will increasingly be available everywhere. What will differentiate an enterprise is the trusted, proprietary context it brings to that intelligence — starting with the customer — and its ability to securely turn that context into action" (Salesforce). Translated: the AI model itself is becoming a commodity, and every vendor has one. What actually protects a business is knowing its own data, its own rules, and its own customers well enough that no outside model can fake it — and having a fence sturdy enough to prove it, in court if it ever comes to that.
Six Plain-English Questions Behind the Six-Part Framework
Salesforce organizes its new structure around six areas, and — jargon aside — each one maps to a question any business leader should already be asking about the AI agents currently roaming their own company:
· Does the AI actually know our business, or is it guessing? (Salesforce calls this "Trusted Context" — grounding answers in real company data instead of a generic best guess.)
· What is the AI allowed to decide on its own, versus what has to go to a human first?
· What is the AI actually allowed to touch or change — a calendar, a customer record, a bank transfer?
· Who's checking that the AI followed the rules, and can you prove it after the fact?
· Can the AI only see the information and systems it's supposed to — nothing more?
· Which AI model is doing the work, and did anyone pick it for cost and accuracy, or did it just show up by default?
(These map to what Salesforce names Trusted Context, Trusted Agency, Trusted Action, Trusted Governance, Trusted Security, and Trusted Models — Salesforce.) Most of the pieces already exist inside Salesforce's own products today; the unified experience is planned to start rolling out in early 2027, and Salesforce says pricing and packaging details will come closer to that date (Salesforce).
Why This Isn't Really a "Salesforce Story"
Here's the part worth sitting with: Salesforce is not the only one building a fence, and that's the actual news. Microsoft has been rolling out Entra Agent ID, which brings the same kind of identity checks and lifecycle rules IT departments already use for employee logins to AI agents instead (Microsoft Learn). Amazon has built a comparable system inside AWS called Bedrock AgentCore, generally available since October 2025, with its own identity, policy, and agent-registry pieces (AWS). Three of the largest platforms in enterprise technology have independently landed on the same conclusion within about a year of each other: AI agents need the digital equivalent of an employee badge, a job description, and a manager — or somebody, eventually, is going to be holding the leash in a much less comfortable setting.
For a business owner or manager who isn't deep in the technical weeds, the takeaway is simple. "We're using AI" is no longer the differentiator, and it never really was. The question that actually matters going into 2027 is whether your organization can say, with confidence, who's accountable for every AI agent running inside it, what each one is allowed to do, and how you'd know — and prove — if one stepped out of line. If you can't answer that today, you're not behind on AI. You're behind on the fence, and the fence is what keeps a productivity story from becoming a liability story.
Eight Things to Do Before Your Next Leadership Meeting
Here's the good news: you don't need to wait on Salesforce, Microsoft, or AWS to start putting up your own fence. Whichever platform your company eventually lands on, most of the real governance work is homework you can start this week, on your own:
Stand up an internal AI and data governance committee. Even three or four people — someone from IT/security, someone from legal or compliance, and a business-unit leader — meeting monthly beats zero people meeting never.
Write an acceptable AI use policy for staff. A short, plain-language document telling employees what they can and can't do with AI tools and agents, and which actions need a human's okay first.
Set trusted model policies. Decide which AI models are approved for which kinds of work, and who has to sign off before a new one gets anywhere near customer data.
Create a connector and integration approval process. Before any agent gets plugged into a new system — your CRM, your finance tools, your codebase — someone should have reviewed exactly what it can now touch.
Build a quick-disconnect process. If one of your agents starts behaving like the ones OpenAI and Anthropic had to contain this summer, can your team actually cut its access in minutes — or does it take a change ticket and a Tuesday meeting?
Fold AI agents into your existing incident response plan. Don't let "the agent did something weird" become a category that falls through the cracks between your security team and everyone else.
Update your cybersecurity policy — and check it against your insurance. Make sure AI-agent risk is explicitly written into your cybersecurity policy, then ask your broker or carrier, in writing, whether an AI-related incident would actually be covered — insurers are increasingly excluding claims where the policyholder can't show real governance.
Track the AI laws that actually apply to your business. Rules are moving fast and unevenly across states, countries, and regions. Know which ones cover you today, not just the ones making headlines.
None of these require buying anything. They require deciding who's in the room, writing it down, and testing it before you need it — because "we didn't know" is a much weaker position after the fact than a written record of who was watching.
Want the Deep Dive?
Part 1 is the plain-English version. Part 2 goes further: a side-by-side technical comparison of how Salesforce, Microsoft, and AWS actually structure agent identity, permissions, and audit trails; an honest look at how much of this is available today versus still on a roadmap; the vendor-lock-in tension buried inside all three companies' "open" claims; a detailed working outline for each of the eight action items above — the governance committee's charter, the acceptable use policy, trusted model criteria, the connector approval process, the quick-disconnect runbook, the incident response updates, aligning your cybersecurity policy with your insurance coverage, and tracking AI law across every jurisdiction you operate in — with open questions to work through with your own team; and a practical due-diligence checklist IT and security leaders can use before signing any vendor's "trusted AI" pitch.
That deep dive is reserved for OFER AI members. If you want the full technical breakdown — plus access to future Deep Dives, roundtables, and OFER AI's model-evaluation resources — apply for membership at oferai.tech. Membership is free to join, with an application review before full access opens up.





Comments