On 5 August 2026, Salesforce announced that Agentforce Public Sector has received Impact Level 5 (IL5) authorisation. IL5 is the highest DoD authorisation level for Controlled Unclassified Information and unclassified National Security Systems data. The US Army Human Resources Command is the first Department of War deployment, covering 9.2 million users. Agentforce is now the first agentic AI platform authorised at IL5. The read-across for regulated enterprises outside the DoD (banks, insurers, healthcare providers, government contractors) is that the platform excuse for delaying AI agent deployment in regulated environments no longer holds. This handbook explains what IL5 means, how IL5 Agentforce differs from commercial Agentforce, and the five governance questions every regulated enterprise architect should now be asking their AI vendor.
The story that landed on 5 August 2026 was, on the surface, a public-sector procurement note. The US Army Human Resources Command deployed Agentforce Public Sector to support 9.2 million soldiers, veterans, civilian staff, and military families. It was the first Department of War organisation to run Salesforce's agentic AI platform inside an Impact Level 5 (IL5) environment, delivered through the newly announced Missionforce National Security offering.
For most readers, that sentence contains three acronyms and one press release. The architectural story behind it is larger, and it applies to every enterprise operating under a regulator, not just the DoD.
Agentforce is now the first agentic AI platform authorised at IL5. That fact resets the negotiating table for enterprise architects in banking, healthcare, insurance, energy, and any other industry whose CISO has spent the past 18 months explaining why AI agents cannot be deployed inside their regulated environment. The platform-side excuse is now a dated position. The architectural discipline required to deploy them safely, on the other hand, has not become one gram lighter. This piece is written for the architect who has to translate the news into a defensible governance posture.
What is Impact Level 5 (IL5) authorisation?
Impact Level 5 (IL5) is the second-highest of the US Department of War's six cloud authorisation levels. It covers Controlled Unclassified Information (CUI) with elevated protection requirements, and unclassified National Security Systems (NSS) data. Above IL5 sit IL6 (Secret) and, informally, IL7 (Top Secret) environments. Below it are IL4 (CUI, standard) and IL2 (public / non-sensitive).
IL5 authorisation is granted by the Defense Information Systems Agency (DISA) after the cloud service provider demonstrates continuous compliance with the DoD Cloud Computing Security Requirements Guide (SRG). In practice this means physical isolation from lower-impact tenants, US-citizen-only administrative access, cleared personnel handling incident response, and audit obligations well beyond FedRAMP High.
The comparison for civilian architects: FedRAMP High is the closest analogue in the civilian federal cloud space. IL4 is roughly equivalent to FedRAMP High plus DoD-specific controls. IL5 adds tenant-isolation and personnel controls on top of that. If a platform is authorised at IL5, it has also been authorised at IL4 and, by construction, meets or exceeds FedRAMP High.
This matters because the framework a US regulator uses to evaluate a platform for healthcare, banking, or critical infrastructure workloads is either FedRAMP-derived, HIPAA-derived, or industry-specific (SOX, GLBA, NERC CIP, PCI-DSS). Platforms authorised at IL5 have crossed a bar that most private-sector regulators consider more than sufficient.
What did Salesforce announce on 5 August 2026?
Three linked announcements landed together:
- Agentforce Public Sector achieved IL5 authorisation. Announced via the Salesforce newsroom on 5 August 2026, this makes Agentforce the first agentic AI platform authorised to operate at IL5 for CUI and unclassified NSS workloads.
- US Army Human Resources Command deployment. The Army HRC became the first Department of War organisation to deploy Agentforce Public Sector in the IL5 environment, supporting 9.2 million users across active duty, reserve, veteran, civilian, and family populations.
- Missionforce National Security launched as the delivery vehicle. Missionforce is the newly branded Salesforce entity through which IL5-authorised agentic capabilities are delivered to defence and national-security customers, with a stated roadmap of expanding across the DoD.
The three announcements were coordinated. The Army HRC deployment is proof-of-life for the IL5 authorisation. Missionforce is the go-to-market wrapper. Agentforce is the underlying platform. Enterprise architects should read them as a single move. Salesforce is establishing that its agentic AI stack is deployable inside the strictest publicly-disclosed unclassified environment, and it has a live customer to prove it.
What Agentforce IL5 changes for regulated enterprises outside the DoD
The most useful way to interpret this announcement outside the DoD is to notice what it removes from the vendor conversation.
For the past 18 months, CISOs at banks, hospital systems, insurers, and Tier-1 government contractors have used a specific sentence to slow down AI agent adoption: no agentic AI platform has yet been authorised for our regulatory environment. That sentence was accurate. It is now dated. The most stringent publicly-disclosed unclassified environment has authorised an agentic AI platform. Any regulator whose bar is lower than IL5 has watched the ceiling move above them.
What that means, industry by industry:
- Financial services (SOX, GLBA, OCC, PCI-DSS): Banks that argued Agentforce could not be deployed against customer-facing workloads for compliance reasons have lost the platform-side leg of that argument. The remaining objections (model risk, explainability, human-in-the-loop controls) are governance objections, and they belong to the enterprise, not to the vendor.
- Healthcare (HIPAA, HITECH, state privacy laws): HIPAA-covered entities and business associates that have kept AI agents out of workflows touching PHI can no longer rely on “no HIPAA-certified agentic AI exists” as a stall. Agentforce operates in a regulatory environment stricter than HIPAA's technical requirements. The remaining question is BAA-level contractual coverage, which is a procurement conversation, not a platform-capability one.
- Insurance (state DOI, NAIC Model 668): Insurers building AI agents into underwriting, claims, or member-service workflows have a new reference point when discussing platform selection with state insurance departments. The NAIC AI Model Bulletin has been in force for eighteen months. The platform-side objection has now caught up.
- Critical infrastructure (NERC CIP, TSA SDs): Utilities and pipeline operators subject to NERC CIP or TSA security directives now have a benchmark for what an agentic AI platform authorised for national-security workloads looks like. The compliance conversation with regulators shifts from is this platform safe enough to what governance controls does the enterprise wrap around it.
- Government contractors under CMMC: Prime and subprime contractors handling CUI under CMMC 2.0 Level 2 or Level 3 have the most direct read-across. IL5 is the DoD's own environment for CUI. If the prime is authorised there, subcontractors have a platform-clearance argument they did not have a week ago.
The common pattern is not that IL5 authorisation solves regulated AI adoption. It is that IL5 authorisation removes the last of the platform-side excuses, and pushes the entire conversation up one layer. From can we use this? to what discipline are we required to wrap around it?
How Agentforce for IL5 differs architecturally from commercial Agentforce
The IL5 environment is not the same environment as commercial Agentforce. Enterprise architects should understand the differences before assuming feature parity.
Tenant isolation
IL5 workloads run in a physically and logically separated tenant from IL4, IL2, and commercial Agentforce. There is no shared compute, no shared storage, and no cross-tenant model call. The Salesforce hyperscaler infrastructure supporting IL5 is a dedicated environment with its own operational plane.
Personnel controls
Every human with administrative access to the IL5 environment must be a US citizen with active DoD-side background clearance. Incident response, patch management, and telemetry review are performed by cleared personnel operating under DoD supervision. This is a material operational difference from commercial Agentforce, where support is delivered by Salesforce's standard global support organisation.
Model hosting and inference
IL5 Agentforce runs on the Atlas Reasoning Engine configured for natively hosted large language models. No cross-boundary calls to third-party LLM APIs such as OpenAI GPT, Anthropic Claude, or Google Gemini outside the authorised environment. Enterprise architects reading the Agentforce commercial documentation should not assume the same model availability inside IL5.
Data residency and provenance
All IL5 tenant data (including agent conversation transcripts, tool-call logs, and model inference telemetry) remains inside the authorised environment. Data provenance and lineage requirements are stricter than the commercial environment, and integration architects should assume additional friction when bridging IL5 data to non-IL5 systems.
Feature parity lag
New Agentforce capabilities land in the commercial environment first and reach the IL5 environment on a lag. Historically two to four quarters for high-security cloud environments across the industry. Architects planning IL5-relevant deployments should expect that commercial Agentforce features they can demo today may not appear in IL5 until 2027.
Five governance questions a regulated enterprise architect should now be asking their AI vendor
IL5 authorisation resets the platform question. It does not reset the enterprise governance question. The following five questions are the ones an architect at a regulated enterprise should now be putting to any AI agent vendor, including but not limited to Salesforce, in the wake of this announcement.
1. In which authorisation environments is your agentic AI platform deployable today, not on the roadmap?
Distinguish between authorised (deployable now), in-process (undergoing 3PAO assessment), and roadmap (stated intent). Vendors will conflate the three. Ask for the authorisation letter or ATO date. If the answer is “we are pursuing FedRAMP High,” that is not authorisation.
2. Where does the model inference happen, and inside which authorisation boundary?
If your enterprise handles regulated data, an agent that calls out to a commercial third-party LLM API is a data-exfiltration risk regardless of the vendor's platform authorisation. Ask specifically which LLMs are available, where they are hosted, and whether prompts and completions cross the authorised boundary at any point.
3. Who operates the environment, and are they cleared to your regulatory standard?
The personnel controls that make IL5 credible are the same class of controls that make FedRAMP High and HIPAA-compliant offerings credible. Ask who administers the environment your regulated workload will run in, whether they are subject to background checks appropriate to your regulator, and what the incident-response chain of custody looks like.
4. What audit and logging obligations are you contractually able to meet, and at what cadence?
Regulated AI deployments require prompt-level, tool-call-level, and data-access-level logs, typically retained for the audit lookback period specified by the relevant regulator (7 years for SOX, 6 for HIPAA, longer for some banking regimes). Ask whether the vendor can meet those retention obligations inside the authorised environment, and whether the logs are available for regulator inspection on request.
5. What is the feature-parity lag between your commercial and regulated offerings?
Architects budgeting multi-year regulated AI programmes need to know which features they can plan against and which they cannot. A vendor that cannot articulate the parity lag between its commercial and regulated environments cannot help you build a defensible three-year roadmap.
Where IL5 Agentforce fits in your AI agent registry
For readers of the Enterprise Dreaming agent-sprawl handbook published on 5 August, IL5 Agentforce is a new entry, not a special case. The nine-column agent registry (name, owner, business trigger, hosting platform, tools it may call, data domains, decide vs. do, escalation path, sunset review date) applies identically to IL5-authorised agents.
Two columns change materially:
- Hosting platform. Record explicitly whether the agent is running in commercial Agentforce, Agentforce for FedRAMP High, or Agentforce for IL5. These are three different runtime environments with three different feature sets, three different operational owners, and three different regulatory reporting obligations. A registry that treats them as one entry will produce audit findings.
- Data domains it may touch. Map explicitly to the data classification the authorisation environment supports. IL5 supports CUI and unclassified NSS. It does not support classified data (that is IL6). Commercial Agentforce supports commercial-sensitivity data. It does not support CUI. An agent that touches CUI must run in IL4 or higher, and the registry entry must make that constraint machine-checkable.
The remainder of the registry (ownership, tool-call contracts, decide-vs-do trust boundaries, escalation paths, sunset review dates) behaves identically regardless of authorisation environment. The IL5 announcement does not change the discipline. It changes the ceiling on where the discipline can be applied.
What IL5 signals for the Dreamforce 2026 announcements six weeks away
Dreamforce 2026 runs 15 to 17 September in San Francisco. Salesforce's stated theme is Becoming an Agentic Enterprise, and the architect track has previewed a capability called Agent Fabric for multi-vendor agent governance. The IL5 announcement six weeks earlier is not a coincidence.
Two things are foreseeable. First, additional IL5-adjacent authorisations (likely FedRAMP High for the commercial Agentforce environment, if not already in place) will be positioned as generally available or imminently so. Second, the enterprise-facing pitch will be that Agentforce is the only agentic AI platform authorised at every relevant compliance environment, and that the governance layer to consume it (Agent Fabric, Command Center, MCP hosted servers) is now complete enough to underpin a multi-year architecture bet.
Enterprise architects should treat the pitch as a fact-pattern to evaluate, not a conclusion to accept. The governance layer is only as complete as the enterprise-side discipline that consumes it. IL5 does not remove the requirement for an agent registry, a decide-vs-do classification, a tool-call contract, or an escalation path. It removes the platform-side excuse for not building those things this year.
What to do this week
For enterprise architects at regulated companies, three things belong on the desk this week.
- Update the vendor evaluation matrix. Add a column for authorisation environments deployable today, separated from roadmap intent. Every AI vendor in your evaluation pool gets rated against this column. It will produce clarity you did not have last week.
- Send the five governance questions above to your incumbent AI vendor. Track the response quality, specificity, and time-to-answer. The vendor's ability to answer these questions is a leading indicator of the operating discipline they can actually deliver.
- Add hosting-environment and data-domain columns to your AI agent registry (or create the registry if you do not yet have one). Existing agents get classified retroactively. New agents cannot be provisioned without the classification being set.
The IL5 announcement is a fact. It changes what the vendors can be asked to prove, and what the enterprise can be asked to accept. Every regulated enterprise architect now has six weeks (the interval between this announcement and Dreamforce 2026) to reset their governance position before the next round of vendor pitches lands. The architects who use those six weeks will negotiate from a different position than the ones who do not.



