Salesforce completed its acquisition of Informatica in November 2025. The deal cost approximately $8 billion. That is not a product acquisition. That is an admission.

Marc Benioff explained it plainly when the deal closed: "Data and context is the true fuel of Agentforce, and without clean, connected, trusted data there is no intelligence — only hallucination."

The CEO of the company selling you AI agents just told you, in public, that the agents are only as good as the data they run on. Most organizations deploying Agentforce are not taking that seriously enough.

The Hallucination Problem Is a Data Problem

When AI outputs are wrong, the instinct is to blame the model. Sometimes that is accurate. More often, especially in enterprise CRM environments, the problem is upstream: the data the model is acting on is incomplete, inconsistent, duplicated, or simply wrong.

Salesforce CRM data quality degrades over time in predictable ways. Contacts accumulate duplicate records. Account data goes stale as companies are acquired or restructured. Opportunity fields get filled in inconsistently depending on who owns the record. Custom objects that made sense two implementations ago carry residual junk. None of this is catastrophic when a human is navigating the system — experienced users know which fields to trust and which to ignore. An AI agent does not have that institutional knowledge. It reads what is there and acts on it.

Garbage in, automated garbage out — at scale and at speed.

The Risk Is Larger Than Wrong Answers

The hallucination problem is embarrassing when a customer-facing agent gives incorrect information. It becomes operationally damaging when the agent takes actions based on that incorrect information.

77%

Of employees have pasted company information into AI tools — and 82% of that activity came from personal, unmanaged accounts that bypass enterprise security controls.

Source: LayerX Security, Enterprise AI and SaaS Data Security Report, 2025

Agentforce agents, depending on how they are configured, can create records, update records, trigger workflows, and initiate downstream automations. An agent with over-permissioned access and low-quality input data is not just a source of wrong answers — it is a source of wrong actions. Cascading automation loops. Thousands of records modified incorrectly. API calls that rack up platform costs before anyone notices.

One of the most common complaints from early Agentforce deployments was not that the agents were slow or limited — it was that there was no easy way to manage them once they were running. Lifecycle management: who owns this agent, what can it do, what is it actually doing, and how do you shut it down cleanly when requirements change?

The Einstein Trust Layer Does Not Do What People Think It Does

Salesforce's answer to the governance concern is the Einstein Trust Layer — a set of controls, data masking capabilities, and audit logging that applies policy enforcement to every Agentforce interaction. It is real technology and it is genuinely useful.

It also requires setup. It does not operate out of the box as a complete shield against poorly governed deployments. Organizations that provision Agentforce without deliberately configuring the Trust Layer's access controls and data permissions are not protected by it — they have simply skipped the step that would make it protective.

The compliance dimension compounds this. Organizations operating under GDPR, CCPA, HIPAA, or the EU AI Act have specific obligations around how AI processes personal data. An Agentforce deployment that has not been mapped against those regulatory frameworks is not just a business risk — it is a compliance exposure that a standard Salesforce contract does not indemnify against.

What Data Readiness Actually Looks Like

Before deploying Agentforce in any customer-facing or record-modifying capacity, there are four questions worth answering honestly:

1. What is your duplicate rate? If you do not know, run a deduplication analysis before you proceed. AI agents that encounter duplicate contact or account records do not gracefully handle the ambiguity — they pick one or create a third.

2. Which fields in your CRM are consistently populated and trusted? The fields Agentforce draws from need to be the ones your team actually fills in reliably. A field that is 60 percent populated with accurate data and 40 percent blank or wrong is a liability when an AI agent uses it as a decision input.

3. What access permissions have you granted the agent? Least-privilege applies to AI agents exactly as it applies to human users. An agent that only needs to read opportunity records and create follow-up tasks should not have write access to account records. Work backward from what the agent needs to do, not forward from what it could technically access.

4. How are you auditing what the agent has done? Salesforce's audit logging through the Trust Layer captures agent actions — but someone needs to be watching those logs, especially in the first months of deployment. Anomalies in agent behavior surface early if you are looking for them. They compound undetected if you are not.

The question is not whether to deploy Agentforce. It is whether your data is clean enough that you would trust an AI to act on it without supervision. For most orgs, the honest answer is: not yet.

The Informatica Acquisition as a Signal

Return to the $8 billion Informatica acquisition for a moment. Salesforce did not buy Informatica because data governance is a nice-to-have for Agentforce. They bought it because without it, Agentforce deployments at scale produce unreliable results — and unreliable results at scale are an existential threat to the product's enterprise credibility.

The acquisition is essentially Salesforce admitting that the data quality problem is real, significant, and not solvable through the platform alone without dedicated tooling. That is a meaningful signal about the state of most Salesforce orgs going into AI deployment.

The organizations that will get the most value from Agentforce are not the ones that deploy it first. They are the ones that get their data house in order first, configure governance deliberately, define agent permissions narrowly, and monitor outputs systematically before trusting agents to act autonomously.

The technology is ready. The data, in most orgs, is not. That gap is fixable — but only if you acknowledge it exists.

Sources

Salesforce Completes Acquisition of Informatica (~$8B, November 18, 2025) — salesforce.com/news/press-releases/2025/11/18/salesforce-completes-acquisition-of-informatica/

Marc Benioff on data and Agentforce ("...no intelligence — only hallucination") — Salesforce press release, November 2025

LayerX Security, Enterprise AI and SaaS Data Security Report, 2025 (77% of employees paste company data into AI tools; 82% from personal accounts)

4 Ways Salesforce Customers Risk Losing Millions Because of AI Agents — salesforceben.com

Salesforce AI Governance: A Guide to GDPR, CCPA & EU AI Act — cirra.ai

Einstein Trust Layer documentation — Salesforce Help