Salesforce has reported record second-quarter results for fiscal 2027, with the company crediting AI adoption across its platform for accelerating growth.

Revenue reached $11.3 billion for the quarter ended 31 July 2026, up 11 per cent year-on-year, while current remaining performance obligation, a measure of contracted future revenue, climbed 14 per cent to $33.5 billion. GAAP operating margin stood at 20.5 per cent and non-GAAP operating margin at 34.1 per cent, while GAAP diluted earnings per share more than doubled to $4.29.

Agentforce, the company's AI agent platform, was central to the results. Combined with Data 360, annual recurring revenue from the two products approached $3.9 billion, up more than 210 per cent year-on-year, with Agentforce ARR alone surpassing $1.5 billion. Salesforce said 3.2 billion "agentic work units", its measure of discrete tasks completed by AI agents, were delivered in the quarter, nearly doubling from the previous three months. Slack also had its strongest quarter of net new order value growth since Salesforce acquired it, with Slackbot users up more than 150 per cent quarter-on-quarter.

Execution Level Governance- What audit-ready agent governance actually looks like
David Girvin, founder and CEO of Assury argues that model-in-the-loop review, AI governing AI, is fundamentally unreliable for regulated environments: even the best-performing models miss a meaningful share of violations, the reviewing model is typically provided by the same vendor being reviewed, and prompt injection or context poisoning can compromise both the acting agent and its supposed overseer simultaneously. He makes the case for deterministic, architecturally enforced controls instead, walking through Assury’s approach of autonomy zones, session risk accumulation, and credential starvation, which lets a compromised agent be cut off from its tools instantly rather than relying on time-boxed access. The conversation touches on why David is sceptical of just-in-time credentialing as a solution for agent security more broadly, since agent sessions don’t run on predictable human timescales, along with the current gap between how identity and security vendors are pitching agent protection and what he sees happening at the execution layer in practice. He also discusses the compliance and audit implications of probabilistic decision-making, arguing that regulated industries will increasingly need tamper-evident, hash-chained audit trails that can withstand scrutiny from auditors and regulators who are only beginning to understand agentic risk, and reflects on a named frontier lab’s own published framework as an example of the gap between research and practitioner reality. Elsewhere, David reflects candidly on building a bootstrapped security company in an increasingly crowded market, why he turned down aggressive VC funding to stay in control of the product, and what a credible third-party assessment of his own gateway would need to look like given that Assury sits directly in the execution path for every customer’s agents.

The company returned $364 million to shareholders in dividends and continued executing its $25 billion accelerated share buyback. It also confirmed its pending acquisitions of Contentful and Fin, announced in June, are expected to close independently during the third quarter.

On the back of the results, Salesforce raised its full-year revenue guidance by $200 million to between $46.1 billion and $46.4 billion, while flagging a reduced currency tailwind following dollar strength during the quarter.

Chief executive Marc Benioff said the company was "seeing incredible demand for our AI and data products, with ARR about to cross $4 billion," adding that its AIforce platform was "unlocking the data, workflows, business logic, actions, and governance inside Salesforce" for use by outside AI agents and models.


Agentic Exploits- Deterministic gates for a probabilistic problem
David Girvin, CEO and co-founder of Assury, joins Stewart Tinson to dig into what’s actually happening when agentic AI goes wrong, and why he thinks most of the industry is solving the wrong layer of the problem. David explains the difference between prompt-level exploits and execution-level ones, arguing that the real danger starts the moment an agent moves from generating text to calling tools: deleting databases, reading files, sending emails. He walks through real-world incidents, including a Mexican government breach chain that escalated from just over a thousand prompts to over five thousand AI-executed actions across multiple agencies before detection, and the UK AI Security Institute’s recent cyber evaluation, in which agents took unsanctioned action including fabricating identities to socially engineer a real GitHub maintainer. The conversation covers why David is sceptical of “guardrails” language and AI-governing-AI approaches, arguing that only deterministic, architectural controls can reliably constrain agent behaviour, alongside human review reserved for genuinely high-stakes actions rather than blanket approval fatigue. He breaks down credential starvation, session risk accumulation, and why classifier-based tools keep failing inconsistently on identical actions, pointing to a named frontier lab’s own zero trust paper as an example of the industry misjudging what actually works. Elsewhere, David discusses the exposed MCP server problem, the widening trust gap between small specialist security vendors and platform incumbents, and why he believes regulation, not product quality alone, is what finally drives enterprise security spend. He closes with the exploit that concerns him most for the year ahead: session-level, goal-directed deception with no attacker involved at all.
Share this post
The link has been copied!