As the industry converges on San Francisco for Dreamforce 2026, the narrative is predictably polished. Salesforce is positioning its Trust Boundary as the definitive architecture for the agentic enterprise, promising a seamless vision of unity. Yet, for those tasked with building the actual infrastructure, the reality is far more fragmented. The trust stack has not coalesced into a single platform; instead, it has fractured into three distinct, often incompatible domains: governance specification, runtime authority, and runtime enforcement.
Governance specification is currently a crowded, nascent field where organizations attempt to define agent behavior before execution. The OWASP Top 10 for Agentic Applications now highlights critical risks like Agent Goal Hijack and Identity and Privilege Abuse, while the NIST AI Agent Standards Initiative continues to work toward federal benchmarks. In practice, enterprises are cobbling together a governance stack from vendors like Okta, IBM, Broadcom, and Dataiku. This focus is well-placed; the UC Berkeley MAST taxonomy indicates that 79% of multi-agent failures are traced to specification problems rather than model limitations.
Once specifications are set, the challenge shifts to runtime authority — the mechanism that validates an agent’s identity and intent in real-time. The industry is moving away from static permissions toward more dynamic models. Akeyless has introduced intent-based access control, while CrowdStrike is pushing SPIFFE-based identities to ensure agents are cryptographically verifiable. As CrowdStrike CTO Elia Zaitsev noted, “Authorize once and trust indefinitely is not a security model; it’s a liability.” Akeyless CEO Oded Hareven echoes this skepticism, asking, “Is there one place issuing, governing, and revoking that authority?” Currently, the answer is no, leaving teams to manage runtime authority as infrastructure manually.
The final hurdle is runtime enforcement, where security policies meet live traffic. This is the domain of bidirectional API security and agent fabrics, recently exemplified by the expanded integration between Akamai and MuleSoft. With 87% of organizations reporting an API security incident in 2025, this layer is critical for preventing the kind of escalation seen in the July 2026 Hugging Face incident. Despite the marketing at Dreamforce, no single vendor covers all three layers. The “unified solution” is, in practice, a multi-vendor assembly project.
This fragmentation creates a significant friction point for agentic commerce. We are witnessing a merchant readiness paradox: 42% of merchants are testing agentic systems, yet only 3% of transactions actually involve agents. Consumer trust remains fragile, dropping off sharply for purchases above £50, and 81% of shoppers will not return to a brand after a single bad agent experience. While Mastercard projects over 300 million shoppers using AI agents by 2030, the current reality is that only 14% of users trust AI recommendations without manual verification.
For enterprise decision-makers, the cost of this multi-layered trust stack is becoming a structural margin factor. Gartner warns that 40% of autonomous AI efforts will be partially derailed by governance gaps discovered only after production incidents. Between Nvidia’s $12.9 billion acquisition of Hugging Face and Stripe’s $7.5 billion acquisition of OpenRouter, the industry’s largest acquirers are buying routing infrastructure at premium valuations — signaling that the orchestration layer’s fragmentation is itself the margin risk. As companies scale, the overhead of managing these disparate layers will determine whether agentic commerce becomes a viable revenue stream or a costly liability. The industry is moving toward a future of autonomous agents, but the infrastructure to support them is not being built; it is being improvised.
