Enterprise Dreamin'
Data Security← All Articles

Agentforce Just Got IL5 Authorisation. That Reframes the AI Governance Conversation for Every Regulated Enterprise.

The first Department of War Agentforce deployment authorised for Impact Level 5 arrived on 5 August 2026. It is a small operational story with a large architectural one behind it. The platform-side excuse for delaying AI agent deployment in regulated environments no longer holds.

By Enterprise Dreamin' Editorial Team

10 min read
Agentforce Just Got IL5 Authorisation. That Reframes the AI Governance Conversation for Every Regulated Enterprise.
Agentforce Just Got IL5 Authorisation. That Reframes the AI Governance Conversation for Every Regulated Enterprise.
On 5 August 2026, Salesforce announced that Agentforce Public Sector has received Impact Level 5 (IL5) authorisation. IL5 is the highest DoD authorisation level for Controlled Unclassified Information and unclassified National Security Systems data. The US Army Human Resources Command is the first Department of War deployment, covering 9.2 million users. Agentforce is now the first agentic AI platform authorised at IL5. The read-across for regulated enterprises outside the DoD (banks, insurers, healthcare providers, government contractors) is that the platform excuse for delaying AI agent deployment in regulated environments no longer holds. This handbook explains what IL5 means, how IL5 Agentforce differs from commercial Agentforce, and the five governance questions every regulated enterprise architect should now be asking their AI vendor.

The story that landed on 5 August 2026 was, on the surface, a public-sector procurement note. The US Army Human Resources Command deployed Agentforce Public Sector to support 9.2 million soldiers, veterans, civilian staff, and military families. It was the first Department of War organisation to run Salesforce's agentic AI platform inside an Impact Level 5 (IL5) environment, delivered through the newly announced Missionforce National Security offering.

For most readers, that sentence contains three acronyms and one press release. The architectural story behind it is larger, and it applies to every enterprise operating under a regulator, not just the DoD.

Agentforce is now the first agentic AI platform authorised at IL5. That fact resets the negotiating table for enterprise architects in banking, healthcare, insurance, energy, and any other industry whose CISO has spent the past 18 months explaining why AI agents cannot be deployed inside their regulated environment. The platform-side excuse is now a dated position. The architectural discipline required to deploy them safely, on the other hand, has not become one gram lighter. This piece is written for the architect who has to translate the news into a defensible governance posture.

What is Impact Level 5 (IL5) authorisation?

Impact Level 5 (IL5) is the second-highest of the US Department of War's six cloud authorisation levels. It covers Controlled Unclassified Information (CUI) with elevated protection requirements, and unclassified National Security Systems (NSS) data. Above IL5 sit IL6 (Secret) and, informally, IL7 (Top Secret) environments. Below it are IL4 (CUI, standard) and IL2 (public / non-sensitive).

IL5 authorisation is granted by the Defense Information Systems Agency (DISA) after the cloud service provider demonstrates continuous compliance with the DoD Cloud Computing Security Requirements Guide (SRG). In practice this means physical isolation from lower-impact tenants, US-citizen-only administrative access, cleared personnel handling incident response, and audit obligations well beyond FedRAMP High.

The comparison for civilian architects: FedRAMP High is the closest analogue in the civilian federal cloud space. IL4 is roughly equivalent to FedRAMP High plus DoD-specific controls. IL5 adds tenant-isolation and personnel controls on top of that. If a platform is authorised at IL5, it has also been authorised at IL4 and, by construction, meets or exceeds FedRAMP High.

This matters because the framework a US regulator uses to evaluate a platform for healthcare, banking, or critical infrastructure workloads is either FedRAMP-derived, HIPAA-derived, or industry-specific (SOX, GLBA, NERC CIP, PCI-DSS). Platforms authorised at IL5 have crossed a bar that most private-sector regulators consider more than sufficient.

What did Salesforce announce on 5 August 2026?

Three linked announcements landed together:

  • Agentforce Public Sector achieved IL5 authorisation. Announced via the Salesforce newsroom on 5 August 2026, this makes Agentforce the first agentic AI platform authorised to operate at IL5 for CUI and unclassified NSS workloads.
  • US Army Human Resources Command deployment. The Army HRC became the first Department of War organisation to deploy Agentforce Public Sector in the IL5 environment, supporting 9.2 million users across active duty, reserve, veteran, civilian, and family populations.
  • Missionforce National Security launched as the delivery vehicle. Missionforce is the newly branded Salesforce entity through which IL5-authorised agentic capabilities are delivered to defence and national-security customers, with a stated roadmap of expanding across the DoD.

The three announcements were coordinated. The Army HRC deployment is proof-of-life for the IL5 authorisation. Missionforce is the go-to-market wrapper. Agentforce is the underlying platform. Enterprise architects should read them as a single move. Salesforce is establishing that its agentic AI stack is deployable inside the strictest publicly-disclosed unclassified environment, and it has a live customer to prove it.

What Agentforce IL5 changes for regulated enterprises outside the DoD

The most useful way to interpret this announcement outside the DoD is to notice what it removes from the vendor conversation.

For the past 18 months, CISOs at banks, hospital systems, insurers, and Tier-1 government contractors have used a specific sentence to slow down AI agent adoption: no agentic AI platform has yet been authorised for our regulatory environment. That sentence was accurate. It is now dated. The most stringent publicly-disclosed unclassified environment has authorised an agentic AI platform. Any regulator whose bar is lower than IL5 has watched the ceiling move above them.

What that means, industry by industry:

  • Financial services (SOX, GLBA, OCC, PCI-DSS): Banks that argued Agentforce could not be deployed against customer-facing workloads for compliance reasons have lost the platform-side leg of that argument. The remaining objections (model risk, explainability, human-in-the-loop controls) are governance objections, and they belong to the enterprise, not to the vendor.
  • Healthcare (HIPAA, HITECH, state privacy laws): HIPAA-covered entities and business associates that have kept AI agents out of workflows touching PHI can no longer rely on “no HIPAA-certified agentic AI exists” as a stall. Agentforce operates in a regulatory environment stricter than HIPAA's technical requirements. The remaining question is BAA-level contractual coverage, which is a procurement conversation, not a platform-capability one.
  • Insurance (state DOI, NAIC Model 668): Insurers building AI agents into underwriting, claims, or member-service workflows have a new reference point when discussing platform selection with state insurance departments. The NAIC AI Model Bulletin has been in force for eighteen months. The platform-side objection has now caught up.
  • Critical infrastructure (NERC CIP, TSA SDs): Utilities and pipeline operators subject to NERC CIP or TSA security directives now have a benchmark for what an agentic AI platform authorised for national-security workloads looks like. The compliance conversation with regulators shifts from is this platform safe enough to what governance controls does the enterprise wrap around it.
  • Government contractors under CMMC: Prime and subprime contractors handling CUI under CMMC 2.0 Level 2 or Level 3 have the most direct read-across. IL5 is the DoD's own environment for CUI. If the prime is authorised there, subcontractors have a platform-clearance argument they did not have a week ago.

The common pattern is not that IL5 authorisation solves regulated AI adoption. It is that IL5 authorisation removes the last of the platform-side excuses, and pushes the entire conversation up one layer. From can we use this? to what discipline are we required to wrap around it?

How Agentforce for IL5 differs architecturally from commercial Agentforce

The IL5 environment is not the same environment as commercial Agentforce. Enterprise architects should understand the differences before assuming feature parity.

Tenant isolation

IL5 workloads run in a physically and logically separated tenant from IL4, IL2, and commercial Agentforce. There is no shared compute, no shared storage, and no cross-tenant model call. The Salesforce hyperscaler infrastructure supporting IL5 is a dedicated environment with its own operational plane.

Personnel controls

Every human with administrative access to the IL5 environment must be a US citizen with active DoD-side background clearance. Incident response, patch management, and telemetry review are performed by cleared personnel operating under DoD supervision. This is a material operational difference from commercial Agentforce, where support is delivered by Salesforce's standard global support organisation.

Model hosting and inference

IL5 Agentforce runs on the Atlas Reasoning Engine configured for natively hosted large language models. No cross-boundary calls to third-party LLM APIs such as OpenAI GPT, Anthropic Claude, or Google Gemini outside the authorised environment. Enterprise architects reading the Agentforce commercial documentation should not assume the same model availability inside IL5.

Data residency and provenance

All IL5 tenant data (including agent conversation transcripts, tool-call logs, and model inference telemetry) remains inside the authorised environment. Data provenance and lineage requirements are stricter than the commercial environment, and integration architects should assume additional friction when bridging IL5 data to non-IL5 systems.

Feature parity lag

New Agentforce capabilities land in the commercial environment first and reach the IL5 environment on a lag. Historically two to four quarters for high-security cloud environments across the industry. Architects planning IL5-relevant deployments should expect that commercial Agentforce features they can demo today may not appear in IL5 until 2027.

Five governance questions a regulated enterprise architect should now be asking their AI vendor

IL5 authorisation resets the platform question. It does not reset the enterprise governance question. The following five questions are the ones an architect at a regulated enterprise should now be putting to any AI agent vendor, including but not limited to Salesforce, in the wake of this announcement.

1. In which authorisation environments is your agentic AI platform deployable today, not on the roadmap?

Distinguish between authorised (deployable now), in-process (undergoing 3PAO assessment), and roadmap (stated intent). Vendors will conflate the three. Ask for the authorisation letter or ATO date. If the answer is “we are pursuing FedRAMP High,” that is not authorisation.

2. Where does the model inference happen, and inside which authorisation boundary?

If your enterprise handles regulated data, an agent that calls out to a commercial third-party LLM API is a data-exfiltration risk regardless of the vendor's platform authorisation. Ask specifically which LLMs are available, where they are hosted, and whether prompts and completions cross the authorised boundary at any point.

3. Who operates the environment, and are they cleared to your regulatory standard?

The personnel controls that make IL5 credible are the same class of controls that make FedRAMP High and HIPAA-compliant offerings credible. Ask who administers the environment your regulated workload will run in, whether they are subject to background checks appropriate to your regulator, and what the incident-response chain of custody looks like.

4. What audit and logging obligations are you contractually able to meet, and at what cadence?

Regulated AI deployments require prompt-level, tool-call-level, and data-access-level logs, typically retained for the audit lookback period specified by the relevant regulator (7 years for SOX, 6 for HIPAA, longer for some banking regimes). Ask whether the vendor can meet those retention obligations inside the authorised environment, and whether the logs are available for regulator inspection on request.

5. What is the feature-parity lag between your commercial and regulated offerings?

Architects budgeting multi-year regulated AI programmes need to know which features they can plan against and which they cannot. A vendor that cannot articulate the parity lag between its commercial and regulated environments cannot help you build a defensible three-year roadmap.

Where IL5 Agentforce fits in your AI agent registry

For readers of the Enterprise Dreaming agent-sprawl handbook published on 5 August, IL5 Agentforce is a new entry, not a special case. The nine-column agent registry (name, owner, business trigger, hosting platform, tools it may call, data domains, decide vs. do, escalation path, sunset review date) applies identically to IL5-authorised agents.

Two columns change materially:

  • Hosting platform. Record explicitly whether the agent is running in commercial Agentforce, Agentforce for FedRAMP High, or Agentforce for IL5. These are three different runtime environments with three different feature sets, three different operational owners, and three different regulatory reporting obligations. A registry that treats them as one entry will produce audit findings.
  • Data domains it may touch. Map explicitly to the data classification the authorisation environment supports. IL5 supports CUI and unclassified NSS. It does not support classified data (that is IL6). Commercial Agentforce supports commercial-sensitivity data. It does not support CUI. An agent that touches CUI must run in IL4 or higher, and the registry entry must make that constraint machine-checkable.

The remainder of the registry (ownership, tool-call contracts, decide-vs-do trust boundaries, escalation paths, sunset review dates) behaves identically regardless of authorisation environment. The IL5 announcement does not change the discipline. It changes the ceiling on where the discipline can be applied.

What IL5 signals for the Dreamforce 2026 announcements six weeks away

Dreamforce 2026 runs 15 to 17 September in San Francisco. Salesforce's stated theme is Becoming an Agentic Enterprise, and the architect track has previewed a capability called Agent Fabric for multi-vendor agent governance. The IL5 announcement six weeks earlier is not a coincidence.

Two things are foreseeable. First, additional IL5-adjacent authorisations (likely FedRAMP High for the commercial Agentforce environment, if not already in place) will be positioned as generally available or imminently so. Second, the enterprise-facing pitch will be that Agentforce is the only agentic AI platform authorised at every relevant compliance environment, and that the governance layer to consume it (Agent Fabric, Command Center, MCP hosted servers) is now complete enough to underpin a multi-year architecture bet.

Enterprise architects should treat the pitch as a fact-pattern to evaluate, not a conclusion to accept. The governance layer is only as complete as the enterprise-side discipline that consumes it. IL5 does not remove the requirement for an agent registry, a decide-vs-do classification, a tool-call contract, or an escalation path. It removes the platform-side excuse for not building those things this year.

What to do this week

For enterprise architects at regulated companies, three things belong on the desk this week.

  • Update the vendor evaluation matrix. Add a column for authorisation environments deployable today, separated from roadmap intent. Every AI vendor in your evaluation pool gets rated against this column. It will produce clarity you did not have last week.
  • Send the five governance questions above to your incumbent AI vendor. Track the response quality, specificity, and time-to-answer. The vendor's ability to answer these questions is a leading indicator of the operating discipline they can actually deliver.
  • Add hosting-environment and data-domain columns to your AI agent registry (or create the registry if you do not yet have one). Existing agents get classified retroactively. New agents cannot be provisioned without the classification being set.

The IL5 announcement is a fact. It changes what the vendors can be asked to prove, and what the enterprise can be asked to accept. Every regulated enterprise architect now has six weeks (the interval between this announcement and Dreamforce 2026) to reset their governance position before the next round of vendor pitches lands. The architects who use those six weeks will negotiate from a different position than the ones who do not.

Key Takeaways
  • 1

    Agentforce Public Sector received IL5 authorisation on 5 August 2026 (the highest DoD unclassified impact level), making it the first agentic AI platform cleared for CUI and unclassified NSS workloads.

  • 2

    The read-across for banks, insurers, healthcare providers, and government contractors is that the platform-side objection to deploying AI agents in regulated environments no longer holds. The remaining objections are governance objections, which belong to the enterprise.

  • 3

    IL5 Agentforce is a different environment from commercial Agentforce: separate tenant, cleared personnel, natively hosted models only, and a feature-parity lag of two to four quarters.

  • 4

    Every regulated enterprise architect should now be pressing their AI vendor on five questions: authorisation environments deployable today, where model inference happens, who operates the environment, contractual audit obligations, and feature-parity lag.

  • 5

    IL5 Agentforce fits inside the existing nine-column AI agent registry as a new hosting-platform entry. The discipline does not change, only the ceiling on where it can be applied.

Frequently Asked Questions

Impact Level 5 (IL5) is the second-highest of the US Department of War's six cloud authorisation levels, covering Controlled Unclassified Information (CUI) with elevated protection requirements and unclassified National Security Systems (NSS) data. It is granted by the Defense Information Systems Agency (DISA) after continuous demonstration of compliance with the DoD Cloud Computing Security Requirements Guide. It is stricter than FedRAMP High and adds tenant-isolation and cleared-personnel requirements on top of IL4.

Salesforce announced three linked items. Agentforce Public Sector achieved IL5 authorisation, the first agentic AI platform to do so. The US Army Human Resources Command became the first Department of War organisation to deploy it, supporting 9.2 million users. And Missionforce National Security launched as the delivery vehicle for IL5-authorised agentic AI to defence and national-security customers.

IL5 is a DoD-specific authorisation, but its practical implication reaches every regulator whose compliance bar is lower than IL5, which is effectively every US civilian regulator, including HIPAA, SOX, GLBA, PCI-DSS, NERC CIP, and state insurance departments. A platform authorised at IL5 has crossed a security and operational bar that most private-sector regulators consider more than sufficient.

IL5 Agentforce runs in a physically and logically separated tenant with US-citizen cleared personnel, natively hosted large language models only (no cross-boundary calls to commercial LLM APIs), stricter data residency and provenance requirements, and a feature-parity lag of two to four quarters behind commercial Agentforce releases. Enterprise architects should not assume feature parity between the two environments.

Most do not need IL5 itself, because HIPAA, SOX, GLBA, and PCI-DSS have lower technical bars than IL5. The relevance is comparative. If the strictest publicly-disclosed unclassified environment has authorised an agentic AI platform, the argument that no agentic AI platform is safe enough for banking or healthcare workloads is no longer supported by the platform-availability facts. The remaining governance work still belongs to the enterprise.

Missionforce National Security is the Salesforce entity announced on 5 August 2026 that delivers IL5-authorised agentic AI capabilities, including Agentforce Public Sector, to Department of War and national-security customers. It is the go-to-market wrapper around the IL5-authorised Salesforce cloud environment.

Add an explicit column to the vendor evaluation matrix for authorisation environments deployable today (not roadmap intent). Rate every AI vendor against it. Then send the five governance questions to your incumbent AI vendor: authorisation environments available now, where model inference happens, who operates the environment and to what clearance, contractual audit and logging obligations, and feature-parity lag between commercial and regulated offerings. The quality and specificity of the vendor's answers is a leading indicator of operating discipline.

Subscribe

One email a week. Practitioner analysis, no vendor spin.

The Weekly Brief. Sessions and essays from senior Salesforce practitioners working through AI, security, and architecture in production.

The Weekly Brief

One email each Friday. The sharpest analysis on Salesforce, AI, and enterprise architecture, written for senior practitioners.

No spam. Unsubscribe anytime.