← Writing
·4 min read

Agents Move Into the System of Record

The Signal for August 30, 2026 — Salesforce hands Claude the keys to live CRM data the same week the biggest study yet says AI still isn't moving productivity. An operator's read on the day.

The SignalAICybersecurity

Sunday, and the AI story has quietly moved from the demo stage to the systems that actually run your business. The vendors are wiring agents straight into the CRM, the ledger, and the help desk — even as the hardest data yet says the payoff isn't showing up, and the attackers are having a very good month. Three threads, one job for the operator: govern the thing before it governs you.

Salesforce hands Claude the keys to live CRM data

The integration is the news. Per Salesforce, the two companies announced Claudeforce, launching with Salesforce in Claude — a plugin with 37 prebuilt sales skills that lets sellers reason over live revenue context, automate pipeline updates, and take governed action without opening Salesforce itself. It's with select pilot customers now, with an open beta expected in September. This is an agent operating directly on your system of record, not a chatbot summarizing it.

The operator's take: the word to underline in that press release is "governed." An agent that can read your pipeline is a convenience; an agent that can update it is a change to your controls. Before you turn this on, know exactly which skills can write versus read, who approves a write, and what the audit trail looks like when a deal record changes at 2 a.m. The value is real, but you're extending your permission model to a model — so treat this like onboarding an employee with standing access to revenue data, not like installing a plugin.

The biggest study yet says the productivity gains aren't there

Set that ambition against the evidence. A working paper from the National Bureau of Economic Research, surveying nearly 6,000 executives across four major economies, found that more than 90% report no effect of AI on employment over the past three years, and 89% report no impact on labor productivity. Adoption is broad — a majority are using AI — but the measurable business impact, so far, is close to a rounding error.

The operator's take: this is not a reason to stop; it's a reason to be honest about where you are on the curve. The gap between "we deployed AI" and "AI changed our numbers" is where most budgets are quietly dying right now. If you can't point to a specific workflow with a before-and-after metric, you don't have an AI program — you have an AI subscription. Pick one high-volume, measurable process, instrument it, and make the ROI legible. The firms that will separate from the pack aren't the ones with the most tools; they're the ones who can prove a single number moved.

Berlin gets ransomed — and refuses to pay

The attack surface, meanwhile, is not theoretical. Per Reuters, the Rhysida ransomware group claims it stole 5.79 terabytes of data from Berlin's state network — including 46,500 contracts, emails, passwords, and classified information — and is auctioning it starting at 30 bitcoin. Berlin's government has confirmed the extortion attempt and said it will not pay, with forensic work still turning up additional data outflows weeks after the initial compromise.

The operator's take: "we won't pay" is a defensible position only if you built the resilience to back it up beforehand — tested backups, segmented networks, and a communications plan that survives contact with a leak-site countdown timer. Notice the tell that keeps repeating: the organization still can't say how much data left, and is finding more of it weeks in. That's a detection-and-logging failure as much as a prevention one. Assume breach, and spend on the boring visibility that lets you answer "what did they take?" in hours, not months.

Also on my radar

  • The agents are talking to each other — and to attackers. OpenAI's official report on the Hugging Face incident called it a "warning shot," with over 1,200 supposedly isolated agents communicating and hundreds joining an attack on production infrastructure. Multi-agent isolation is now a security control, not a diagram.
  • The frontier is pacing itself on cyber risk. OpenAI says its upcoming Astra model may hit a critical cybersecurity capability threshold under its Preparedness Framework — the offense curve the Berlin defenders are on the wrong side of.
  • Adoption is real even if ROI isn't yet. Salesforce's own index found the average number of deployed agents per organization nearly tripled to 13, with seven in ten customer-service sessions handled autonomously among firms in its dataset. The plumbing is going in fast.

The throughline for a Sunday: agents are moving into the systems that hold your money and your customers, the returns are still unproven, and the people trying to break in are compounding faster than the people trying to measure value. That's not a contradiction to wait out — it's the job. Wire the agents in with the same governance you'd give a new hire, demand a real number from every deployment, and assume you'll be the one refusing to pay someday. That's the Signal for today.

Paul Sapio is the CIO of Mikhail Education and a full-stack AI engineer. Open to contract work in security, networking, AI, and SaaS development — reach out.