og.rsts.dev
← writing

AI Replaces the UI. What an Architect Actually Takes Home

Dreamforce 2026's headline was AIforce: AI replacing the interface itself. Underneath it sits an old argument with two right answers. The customer and the banker want the friction gone. The architect has to keep control of identity, data, and cost. Here is the honest case for each side, grounded in what the keynotes actually said, and how the control plane lets you say yes to both.

AI Replaces the UI. What an Architect Actually Takes Home
Contents

Dreamforce is over, and the sentence everyone will repeat on the flight home is that AI replaces the UI. That was the headline, and Salesforce earned it. I want to close this series the way I opened it, by refusing to buy or sell on a headline. I flew in with a set of boundaries drawn on paper. I gave my own answers on stage. Now the keynotes have spoken, and I have spent the days since going back through them instead of the press recaps, because the honest question is not what sounded impressive in the room. It is what actually holds up once you have to wire it into a real estate and run it.

The honest question is that the week set up an argument with two right answers, and the mistake is picking one. Salesforce knew it, too. In the main keynote they put Dario Amodei and Jensen Huang on stage back to back with opposite views of AI governance, Amodei arguing the industry has to organize itself around shared safety standards and Huang answering that safety is an engineering problem and we do not need new laws. That was not an accident. It is the same tension every architect now lives inside. On one side is the person who has to use this software: the customer who wants a resolution and the banker who wants an answer without hunting through five screens. On the other side is the person who has to keep the institution intact: the architect, and behind the architect the examiner, who needs to know where the data went, who acted, and what it cost. Both of those people are right. Any read of Dreamforce that only listens to one of them is marketing or it is fear, and neither one ships anything.

A balance scale holds two glowing pans level. The left pan, The Experience, carries work where you are, faster service, and agents everywhere. The right pan, The Control, carries identity, egress, determinism, and cost. The fulcrum and beam are labeled The Control Plane. Caption: you don't pick a side, the control plane is how you say yes to both.

The headline: AI replaces the UI

The umbrella announcement was AIforce, and it is a genuine shift, so let me state it at full strength. Marc Benioff framed it in the main keynote not as the end of software but as the end of software that makes humans do all the work. Instead of opening the app, finding the screen, and navigating the menu, you ask, and the answer comes to you in Claude, in Slack, in Lightning. Parker Harris had asked months earlier why you should ever log into Salesforce again, and the keynote’s answer was that the product was never the interface in the first place. The logic always lived in metadata: objects, fields, permissions, business rules. It used to recompose into a browser. Now it recomposes into a chat surface. One analyst called it the end of the interface, and the framing is not wrong.

The case for the experience

Start with the side architects are too quick to wave off, because waving it off is how we end up defending software nobody wants to use.

The strongest argument for the experience is that your customers are not waiting for you. In the financial services keynote, Salesforce put a number on it: the share of Americans using AI for financial advice went from about one in ten to about five in ten in a single year, most of Gen Z already run money decisions through AI, and more than half of web traffic is no longer human. The customer knocking on your digital front door is increasingly an agent acting on their behalf. In the demo, a customer asks Claude to consolidate accounts and a bank wins the business precisely because its own agent can join that conversation over a secure MCP connection. The line that framed it stuck with me: an AI model cannot walk into a bank on its own, you need the model and the system of record together.

For the person doing the work, the interface was never a feature, it was a tax. The same keynote showed Bank of America’s “journey of a meeting” running across tens of thousands of bankers and saving hours on each of roughly a million meetings a year, and the quote from a user was not about the model, it was that the tool took the toil out of the job so they could have the high-touch conversation instead of prepping for it. The recurring rule was to stop shipping standalone tools and put the AI where the work already happens. That is the whole appeal of agents showing up in Slack and the contact center: not novelty, just the task getting done where you already are.

And this is not only efficiency. In the main keynote, ADECO’s story was the most human moment of the day, told as AI with people, not to people. Their recruiters got back a third to nearly half of their time and spent it on actual conversations, and the result was tens of thousands more people placed. Dario Amodei’s line from the same stage is the one I would put in front of any architect who thinks they can slow-walk this: even if you froze the technology today, we are using maybe five to ten percent of its value, and the bottleneck now is diffusion, not capability. A perfectly governed system that people route around is not safe, it is unused, and shadow tools fill the gap. The experience case is not the soft side of the argument. It is half of whether any of this was worth building.

The case for control

Now the side I have spent this whole series defending, and it is every bit as real.

The sharpest version of it also came from the financial services keynote, and it is one line: “It can’t be probably right. It has to be right.” A composed view in a chat window is probabilistic by nature, and that is fine until it becomes the way something changes in the system of record. Then the ephemeral thing has to leave behind a write that is deterministic, attributable, and replayable: which row changed, by whom, under which model version, and why. This was the intellectual spine of the whole conference. Benioff kept returning to probabilistic meets deterministic, Siemens put it more bluntly that hallucination has no place on the shop floor, and the standout demo made it concrete: an agent named Marshall learned a supplier-onboarding process in a sandbox, then packaged what it learned into trusted actions it executes the same way every time. The keynote’s own phrase was that AI reasoning becomes deterministic execution, and they admitted this is exactly where most AI projects hit a wall.

The security keynote was where the control case got teeth. The opening question was the one every architect should be able to answer and mostly cannot: how many agents were onboarded into your systems this week, and can you even see them. Agents are the insiders nobody ran a background check on. They never log in, never log off, and swarm in parallel, so the human-era perimeter is done, and with IDC forecasting a tenfold rise in agents by 2027 the attack surface is not growing linearly, it is compounding. Give an agent raw, unfiltered data, the session warned, and you have handed over the keys to the kingdom. The answer they proposed is the exact shape I argued from the stage in The Model Decides, the Code Controls: a real scoped identity per agent instead of a shared key, full observability, and a kill switch that works at the session, the agent, or the whole tenant.

The control plane to run all of that stopped being a slide and became a product line. Agent Fabric is a single registry to govern agents across Azure, AWS, Google, and Agentforce, and it now carries spend wallets that budget what an agent can cost and suggest how to cut its token bill, which is the first time I have seen cost governance treated as a first-class control. Underneath it, the Omni Gateway is one enforcement point in front of API, MCP, LLM, and agent traffic, federated across gateways it does not even own. Salesforce Guardian, the evolution of Shield, extends data classification and adds agent identity, and the dedicated Agent Fabric keynote made that concrete. Give every agent its own governed identity, where effective access is the intersection of what the user and the agent are each allowed, so a person with full rights can pair with an agent granted read and edit but never delete. The admin on stage said the quiet part out loud, that he does not let agents delete data because he does not trust them yet, and an observability center traced two agents making eighteen hundred requests a minute down the full call chain, from an MCP request to an API call to a flow. And model choice moved inside the perimeter: Claudeforce runs Claude inside the Salesforce trust boundary, and Koa, the new CRM reasoning model, was trained on synthetic data with, in the keynote’s words, not a single byte of customer data. That same Agent Fabric keynote framed the design cleanly: the model alone is not enough, so you feed a frontier model your business foundation through a trusted harness and swap the model later without rebuilding the foundation. The most important line for the control side, though, was the reframe from the financial services keynote: your existing operational risk frameworks are the accelerant for AI, not the thing holding you back. That is the argument I have been making all series, said by someone selling to the same room.

Where they collide

The tension is not rhetorical, it is a design decision you make over and over, and the conference kept showing it colliding in real cases. The cleanest example was zero data retention. It has been the gold standard for AI privacy, deleting prompts the moment they are processed. The security keynote’s uncomfortable admission was that the slowest, most dangerous attacks only reveal themselves across weeks of behavior, so deleting everything blinds the defender. The resolution they hammered out, Enterprise Frontier Safeguards, keeps that history in the customer’s own cloud under the customer’s own keys. Two goods, privacy and detection, in direct conflict, reconciled by engineering rather than by picking one.

The human side of the collision came from The Human Veto, where Salesforce’s Paula Goldman started from the premise that just because AI can do something doesn’t mean it always should. Her research had a pattern I have not stopped thinking about: when people are angry they want a human, and when they are embarrassed they often prefer the AI, because it will not judge them. Push all the way to the experience and you automate the moment a person needed a person. Push all the way to control and you build something defensible that nobody uses. The deepest worry she raised was accountability, that a human professional holds an accreditation that can be revoked and nothing like it exists for AI yet, which is not an abstract concern when the agent is acting on a customer’s account.

How I resolve it: the control plane is the yes

So I do not pick a side. I use the control plane to make the experience safe to say yes to, and that reframes the whole week. The reason a bank can let a banker work inside Claude is that the gateway in front of that surface enforces what the agent can reach, meters what it spends, and writes the trail the examiner will want. The control plane is not the tax on the experience. It is the permission slip for it. The proof was on the floor: a London operator running more than four hundred production agents said that putting agent governance in place did not slow them down, it sped their API innovation by more than twenty percent. Governance is what ships the experience, not what blocks it, which is the same throughline I have been pulling on all series. The financial services keynote said the quiet part out loud: the leading firms are not choosing between AI and human connection, they use AI to decide when to spend human talent.

Which is exactly the boundary I told you to draw before any of this shipped. In Draw the Boundary Before You Buy Deeper I said every platform opens one layer so it can quietly own the layer above it. Dreamforce was the vendor drawing that line, and the control plane that governs your APIs, your models, and your agents from one seat is both a genuinely good capability and the most valuable place to own you from. Both are true at once. So adopt the control-plane thinking, because it is what lets you say yes, but keep the plane of record yours. That the same Agent Fabric registry spans Azure, AWS, and Google is the tell that no single vendor owns the whole picture yet. The moment you let one of them become the only place your agents can be governed, you have handed away the seat that decides both your experience and your exposure. Whoever owns the control plane owns the yes. And the semantic layer underneath it is still the part that decides whether the answers are grounded at all, which is the whole argument of Data 360 Is a Reference System, Not a Database.

What I’m still figuring out

The honest close, for this post and for the series. The metering problem I flagged the day I flew out is still open. Agent Fabric’s spend wallets are the first real attempt I have seen to price agent behavior, but nobody can yet tell you what an agent workforce will cost per business line before you run it, so both sides of the argument are still negotiating with a number no one has. The trust story is also splitting across a registry, an identity layer, and a gateway, and the zero-data-retention reversal shows that even a norm everyone treated as settled is being renegotiated in real time, which is more surface to keep coherent than a single pane implies. And most of the headline, AIforce itself, ships as beta and roadmap across its surfaces, so the gap between the experience in the demo and the experience you can defend is measured in quarters, not days.

I came into this week having drawn boundaries, given answers, and learned that Data 360 is a reference system. I am leaving it holding both sides at once on purpose. The experience is not the soft part of the job and control is not the brake on it. They are two constraints that both have to hold, and the architecture that wins is the one that treats saying yes to the customer and keeping faith with the examiner as the same problem. Draw that boundary yourself, in your own hand, or the vendor will draw it for you. This week, they drew a very good one. Just make sure it is yours, and make sure it says yes.


This closes the Dreamforce 2026 series. If you are starting from here, read it in order: Draw the Boundary Before You Buy Deeper on the questions I refused to leave without answering, Data 360 Is a Reference System, Not a Database on the semantic layer, and The Model Decides, the Code Controls on the governance that actually ships agents.

Find me on X @orestesgarcia or LinkedIn /in/setsero.