The defense sector is done experimenting with agentic AI. On August 5, the Department of Defense granted Impact Level 5 authorization to Salesforce’s Agentforce 360 platform — a production-grade clearance that lets the system handle Controlled Unclassified Information and certain unclassified National Security Systems data. This is not a sandbox. It is the security clearance that lets autonomous AI agents operate inside real military workflows.
IL5 is a serious bar. It requires a FedRAMP High baseline plus a DoD-specific overlay of more than 450 security controls, physical tenant separation from non-federal systems, and U.S.-persons-only access. The platform runs on AWS GovCloud, a physically and logically isolated region operated exclusively by U.S. personnel. By clearing it, Salesforce became, in the words of Kendall Collins, CEO of Missionforce and Government Cloud, “the first ones, as a commercial software company, bringing an agentic platform that’s been productive in the commercial side into the national security environment.”
The money angle is hard to miss. The U.S. AI defense market sits at roughly $4 billion this year, with forecasts projecting it to reach $10.9 billion by 2031 — a compound annual growth rate of 22.1%. The DOD’s own AI budget request for fiscal year 2026 is $14.2 billion. Salesforce is positioning itself to capture a meaningful share of that spend, and it already has the contract to prove it: an Army IDIQ vehicle worth up to $5.6 billion over 10 years, announced in January.
Army Human Resources Command is the first component contracted to deploy Agentforce 360 in the new IL5 environment. At full scale, the deployment is projected to handle more than 55 million agent conversations per month, serving soldiers, veterans, spouses, and military families. Collins described the U.S. government as Salesforce’s “single biggest customer, globally” and national security as one of the company’s “best and fastest growing areas.” The company is also pursuing prime-contractor status with DOD rather than working solely through systems integrators — a shift that could reshape how commercial software companies compete for defense work.
The competitive landscape is crowded. Palantir’s Maven Smart System was designated an official program of record in March, and Anthropic held a $200 million DOD contract ceiling before being blacklisted as a supply-chain risk in February 2026. That last detail matters here: to achieve IL5, Salesforce had to attest to the Pentagon that Anthropic’s generative AI models were disabled within the platform. The platform remains model-agnostic, with a policy-driven toggle that could re-enable Anthropic if DOD changes its stance. But the current configuration highlights a tension between commercial AI innovation and defense supply-chain security that will not resolve quickly.
This authorization arrives as the private sector scrambles to build the trust infrastructure for autonomous agents. Visa just completed a $2.4 billion acquisition of BioCatch to secure behavioral biometrics as the authentication layer for agent commerce. A 9th Circuit ruling on August 4 held that users — not agent makers — are liable for their AI agents’ actions under the Computer Fraud and Abuse Act, creating a liability vacuum that payment networks and infrastructure providers are rushing to fill. And vulnerabilities like the ChatMate Remote Prompt Execution attack, disclosed at Black Hat, showed that agent infrastructure itself has become the attack surface.
The government side of that trust sprint just got its first production deployment. “Trust is the foundation of every successful mission,” Collins said. “Agentforce 360 IL5 authorization means national security agencies can harness the power of AI — autonomous agents, real-time data, decision intelligence — without compromising the security their missions demand.”
The defense sector has moved from studying whether agents can work to deploying them under the most demanding constraints in the enterprise. That changes who pays, who competes, and how fast the trust infrastructure sprint accelerates. The question is no longer whether agentic AI has a government market. It is how fast that market materializes — and who controls the security standards that govern it.
