The AI agent market stopped selling assistants this week and started selling employees. Salesforce announced seven named, job-ready Agentforce AI agents on September 11, 2026, each purpose-built for a specific business function, then followed at Dreamforce in San Francisco with Claudeforce, Slackforce, and Agentforce Coworker. For law firm owners and practice managers, the product details matter less than the shift they represent. Vendors are now packaging AI as named workers with job descriptions, months of memory, and their own identities inside your systems. That changes what you need to ask before any of this touches client files or patient records.
What Salesforce Announced on September 11
Salesforce released seven named Agentforce agents: Casey for help, Paige for IT and HR, Carter for shoppers, Hunter for outbound sales, Marshall for supply chain, Piper for inbound pipeline, and Fin for customers. Six are generally available now, while Hunter remains in pilot. The announcement was timed ahead of Dreamforce 2026, which ran September 15 to 17 in San Francisco.
These are not blank chatbots you have to train from scratch. The agents integrate with Customer 360, giving them access to customer context and existing business processes within Salesforce, which the company says lets them work purposefully from the start without extensive configuration. Salesforce is also framing this as proven at scale: the company reported that Agentforce and Slack have collectively delivered 7 billion Agentic Work Units, with 3.2 billion in Q2 alone.
The Dreamforce Follow-Up
At the conference itself, the interface story took center stage. Salesforce released Claudeforce, Slackforce and Agentforce Coworker, each bringing skills, dashboards, triggered workflows and packaged interfaces to where users already work. The keynote highlighted the Claudeforce announcement, which will be charged on a per-user, per-month basis, and Salesforce wants Slack to be where agent-based coding happens. On the platform side, Salesforce detailed Multi-Agent Orchestration, now generally available, plus AI Skills in Coworker and Agent Optimizer, both reaching general availability in October.
Hunter and the Shift to Long-Horizon Agents
The most important technical detail is buried in the one agent that is not yet generally available. Hunter is the first agent to use a new long-horizon runtime that pursues goals over weeks instead of a single chat session, and it is currently in pilot with general availability planned for November 2026.
An agent that works toward a goal for weeks is a different animal from a chatbot that answers a question and forgets. For a law firm, persistent agent memory raises concrete operational questions. What does the agent retain about client matters, for how long, and who can review it? How does that memory interact with your retention schedule, and could it become discoverable in litigation? For a medical practice, the same questions apply to anything adjacent to patient information. I am not offering legal advice here. These are the questions to put to your vendor and your own counsel before deployment, and the point is that long-running memory makes them unavoidable.
There is also a new access path to think about. The Agentforce REST API lets external systems invoke agent sessions and receive structured responses without a logged-in Salesforce user in the loop. Agents that act without a human at the keyboard need their own identity, permissions, and audit trail.
Agent Fabric and the Trusted Enterprise AI Harness
Salesforce clearly knows governance is the buying objection, because it shipped governance as a product. Alongside the agent portfolio, the company introduced the Trusted Enterprise AI Harness, a six-part governance framework for enterprises already running agents from multiple vendors, with pillars covering Trusted Context, Trusted Agency, Trusted Action, Trusted Governance, Trusted Security, and Trusted Models. It includes a new AI Control Plane for managing agents and AI systems across an entire organization, effectively a management layer above any single platform, though it was previewed rather than fully available.
The piece that already shipped is the one I would watch. Agent Fabric is the governance answer, and MuleSoft's control plane discovers agents across Agentforce, Amazon Bedrock, Google Vertex AI and Microsoft Copilot Studio, while its Trusted Agent Identity "enables agents to execute actions using specific user permissions". Cross-vendor discovery matters because if you run agents from more than one vendor, this is the layer that stops that becoming an inventory problem nobody owns. Your practice may already be running agents from more than one vendor without realizing it: a chatbot on the website, an AI feature in the practice management system, a Copilot in Microsoft 365.
The Governance Gap the Industry Just Admitted
The same week, independent research showed why this tooling exists. Harness published a survey-backed report showing a wide confidence gap: 77% of large organizations say they have a complete inventory of agents while only 44% run active discovery tooling, and 74% trust testing to catch failures but just 19% have an automated gate to block bad releases. As the report's coverage put it, many deployments are operating on faith rather than verifiable controls, and undetected agents, weak rollout gates, and slow shutdowns create real production, security, and budget risk.
For regulated businesses, faith is not a control. A firm that cannot list its agents will struggle to answer a client security questionnaire, a malpractice carrier, or a regulator. The gap between saying you have an inventory and actually running discovery is exactly where confidentiality incidents can happen.
What Law Firms and Medical Practices Should Do Now
You do not need to buy anything announced this week to act on it. The pattern is set, and the same questions apply to every vendor pitching you an agent this quarter.
- Build a real inventory of every AI agent and assistant running in your practice, including features embedded in tools you already license, and verify it with discovery rather than memory.
- Name one person who owns agent governance, including approval of new agents, permission reviews, and the authority to shut an agent off.
- Ask every vendor how their agents authenticate, whether each agent acts under a specific user's permissions, and what audit logs you can export.
- Treat persistent agent memory as a records question: ask what is retained, where it lives, how long it is kept, and how it is deleted, then review the answers with counsel against your confidentiality and privacy obligations.
- Require human approval on any agent action that leaves the building, such as outbound messages to clients, patients, or opposing parties, at least through an initial pilot.
- Pilot one narrowly scoped agent in a low-risk internal function, measure output against current hours, and expand only after the audit trail proves out.
The Bottom Line
September 2026 is the month the agent market matured into job titles. The agents being released now are the step from generic AI assistants toward AI workers with names, defined roles, and measurable output, and the governance tooling to manage them across vendors shipped in the same news cycle. Practices that build the inventory, ownership, and permission discipline now put themselves in a strong position to evaluate useful agents quickly and adopt them with clear controls. Practices that skip that work risk finding out what is running in their systems the hard way.

