News thumbnail
Technology / Wed, 07 Oct 2026 LinkedIn

Claude Now Runs Inside Salesforce, Slack, and Microsoft 365. Your Security Review Never Saw It Arrive.

Each announcement promised the agents would "inherit" the host platform's security model from day one. AI security assumed a moment: a committee, a license, a review, a surface to instrument. The toolkit built for that moment (model scanning, prompt inspection, gateway enforcement) only works when someone in the company chose the thing being secured. The bottom lineAgent security is not a feature of AI security. Nothing for AI security to instrument, because nobody in your company adopted anything.

In one week in August 2026, Salesforce launched Slack Code, which lets anyone tag a coding agent into a conversation and ship a pull request, and then announced Claudeforce, which wires Claude directly into live Salesforce data and workflows. It was Anthropic's third native embed of the year, after Slack and Microsoft 365. Each announcement promised the agents would "inherit" the host platform's security model from day one. Not one of them passed through a procurement review, because nothing was procured.

Agents are the first attack surface that grows without an adoption decision.

AI security assumed a moment: a committee, a license, a review, a surface to instrument. The toolkit built for that moment (model scanning, prompt inspection, gateway enforcement) only works when someone in the company chose the thing being secured. Agents skip the moment. The CRM ships an agent platform. The ticketing system ships one. The meeting notetaker, the HR suite, the data warehouse all become launchpads, for vendors and employees alike, in product updates nobody reads. Every governance process an enterprise owns fires at adoption. Agents never trigger it.

Offensive AI went from impossible to $20 in four months.

While the attack surface expands at the pace of vendor release calendars, the attackers' curve is steeper. In February, frontier models could not solve a deliberately hard offensive challenge: reverse-engineer unfamiliar software, find a subtle race condition, weaponize it. By April, the best model solved it occasionally at roughly $2,000 in inference cost. By June, several solved it reliably for about $20. Offensive AI costs are falling roughly tenfold a year. The two curves cross in the third-party application layer, which is exactly where the agents live.

The board is asking three questions the policy document cannot answer.

How many agents do we have?

What can they reach?

Who is accountable if one is compromised?

Workday reports AI now drives more than a quarter of its new annual contract value, with over 5,500 customers running its agents, so the pressure to adopt is not going away. Security leaders are being asked to say yes faster and to be accountable for the result, in the same meeting. A one-time inventory does not resolve that. What resolves it is a live, continuously updated answer to what is operating, what each agent inherited, what it can reach, and what changed since yesterday.

The bottom line

Agent security is not a feature of AI security. It is a different category for a different kind of problem: third-party, continuous, and growing at machine speed. First-party problems get solved at the decision point. Third-party problems have no decision point.

Nothing for AI security to instrument, because nobody in your company adopted anything. The ecosystem simply grew.

The full series runs six chapters, from why the era changed to a sequenced ninety-day plan, a four-level self-assessment, and the fifteen questions that separate vendors who built for this problem from vendors who renamed a product. None of that is in this article.

About Reco

© All Rights Reserved.