Agentforce ARR up 205% and Gartner says 40% of enterprises will pull their agents back by 2027
The hype meets the reality. The state of the Agentic Enterprise in May 2026
May 2026 was a month of contradictory signals in the world of Agentic AI. Adoption metrics are breaking records, yet analysts now predict that 40% of the enterprises which deployed agents to production will demote or decommission them by 20271. Both are true at once, and the gap between them is an interesting story.
On May 26, Gartner predicted that by 2027, 40% of enterprises will demote or decommission autonomous AI agents - not because the agents don’t work, but because of governance gaps discovered after a production incident. On May 27, Salesforce reported a genuinely strong quarter: Agentforce ARR is up 205% year over year. Despite this, its stock is down 30% year to date.
That is the agentic enterprise in May 2026, in one frame.
The money is real now, and so is the doubt about pricing models
For most of the last eighteen months, the agentic market ran on projections. May was the month the numbers got large enough that the debate stopped being abstract. Salesforce closed Q1 FY27 with Agentforce ARR at $1.2 billion, up 205% year over year. Combined AI and Data ARR reached nearly $3.4 billion (worth noting: that figure includes roughly $1.1 billion of Informatica Cloud ARR, so it is not all “agentic”). The company reported 3.8 billion Agentic Work Units delivered to date, up 111% quarter over quarter, and more than 28.6 trillion tokens processed, up 152% quarter over quarter. More than half of Agentforce and Data 360 bookings came from existing customers. It means expansion inside the installed base, not new logos.
And yet, just before the earnings, Bank of America reinstated coverage at Underperform with a $160 target, well below the ~$268 Street consensus, and named the structural fear out loud, calling it an “AI-driven structural reset.“ Salesforce built a $30-billion-plus business selling one seat per human. If agents do some of that human work, the seat model shrinks.\
This is the central tension of the agentic enterprise in 2026, and it is no longer theoretical. The companies selling agents are watching their own pricing model get questioned in real time. Salesforce’s response is to run three pricing models simultaneously:
per conversation
per action via Flex Credits
per-user under the Agentic Enterprise License, plus the new Agentic Work Unit metric.
That’s a similar story to what I described in my previous article (“Microsoft’s 35.8% problem with Copilot is a category problem”) and what happens at Microsoft - trying to monetize the right model for work being done by agents.
Apparently, the market has not yet settled on how to procure agentic outcomes. Vendors are forcing customers to self-select, allowing us to watch the transition from deterministic software seats to probabilistic compute consumption play out live. (important note: a meaningful share of what vendors now report as “agentic” usage was running under different product names before the agentic relabeling. Gartner’s own term for the broader pattern is “agent washing.” The Salesforce numbers are real ARR, but the year-over-year comparisons sit on top of a category that has been redefined while it grew).
Governance stopped being a slide and became an operating problem
The most important number in May wasn’t financial. It was the above mentioned Gartner’s number about 40% of enterprises projected to demote or decommission autonomous agents by 2027, because of governance gaps found after an incident.
What makes the framing sharp is why Gartner says agents fail. Not because governance is absent, but because it’s applied uniformly. Treating every agent as either locked down or fully trusted produces two failure modes: over-restrict the simple agents and you slow delivery and push teams into shadow deployments. Under-restrict the autonomous ones and you discover the access scope was wrong only after the agent has already acted. Gartner’s distinction is between an agent’s ability to act and the scope of access it was granted. Most enterprises aren’t separating the two.
The supporting data from this year is bracing.
A Cloud Security Alliance study (published April 21) found 65% of organizations had at least one cybersecurity incident in the past year caused by an AI agent2.
A separate CSA study with Zenity found 53% had agents exceed their intended permissions and 47% experienced an agent-related security incident. Across these surveys the recurring theme is identical: the risk is not the model hallucinating.
The risk is the agent being too good at executing something it should never have been permitted to do, gaining write access it was never scoped for, taking actions nobody authorized.
If you’ve read my previous articles, you know this is the argument I keep returning to: in production, governance is not a legal document, it’s a permission model expressed in code. May was the month the analyst forecasts and the breach data caught up to it.
Microsoft moved the architecture ceiling just before Build
While the market focused on the June 2 Build keynote, the most consequential news for enterprise agent builders actually shipped in May. On May 13, computer-using agents reached general availability in Copilot Studio, rolled out across all commercial Power Platform geographies (sovereign clouds excluded). These are agents that operate websites and desktop software through the UI rather than through APIs. That matters more than it sounds, because most enterprise software does not expose a documented API for the operations employees actually do all day. The GA build added secure credential management (Azure Key Vault), model choice across OpenAI and Anthropic, Purview audit logging, configurable human-in-the-loop review, and the ability to embed these agents directly into multi-step workflows.
When combined with April’s Work IQ intelligence layer, which provides organizational memory and enables Agent-to-Agent (A2A) communication, Microsoft’s direction is clear. The company is packaging the grounding, Dataverse integration, and coordination plumbing into a managed surface. Context reasoning and agent delegation are becoming native Microsoft-operated layers, eliminating the need for teams to stitch together custom cognitive architectures.
Salesforce pushed agents into the back office
The other notable platform move came at the end of April and shaped the May conversation: Agentforce Operations went generally available on April 29, built on the platform built by Regrello acquired by Salesforce and aimed at back-office bottlenecks, ie. process coordination, data verification, compliance clearing, approval chasing, rather than the front-office customer interactions where agentic CRM started.
This aligns with the migration path we have tracked for months. The first wave of agentic CRM focused on sales and service copilots. The second wave is everything behind them: the unglamorous operational tasks where work actually stalls. By framing this as the “agentic enterprise,” Salesforce is acknowledging a core truth: the durable ROI of AI is not a smarter chatbot, but the total redesign of the underlying business processes.
What it adds up to
May 2026 was the month the agentic enterprise stopped being a forecast and became a balance sheet, with all the scrutiny that brings.
The revenue is becoming real. The pricing model is genuinely unsettled, and the market is pricing in that uncertainty. The platforms keep raising the architectural ceiling: computer use at GA, managed grounding and agent-to-agent coordination, back-office process automation. Simultaneously, the governance reckoning is here. Unexamined access scopes are leading to real-world breaches, guaranteeing that a significant percentage of today’s agents will be pulled offline by 2027.
The dividing line between the AI agents that survive their first security incident and those that are quietly decommissioned remains exactly what it has always been: whether the engineering team defined the boundaries in code before the agent went live, or waited to discover them after something broke.
“Gartner Says Applying Uniform Governance Across AI Agents Will Lead to Enterprise AI Agent Failure”, Gartner, May 2026, https://www.gartner.com/en/newsroom/press-releases/2026-05-26-gartner-says-applying-uniform-governance-across-ai-agents-will-lead-to-enterprise-ai-agent-failure
“New Cloud Security Alliance Survey Reveals 82% of Enterprises Have Unknown AI Agents in Their Environments”, Cloud Security Alliance, April 2026, https://cloudsecurityalliance.org/press-releases/2026/04/21/new-cloud-security-alliance-survey-reveals-82-of-enterprises-have-unknown-ai-agents-in-their-environments

