Your CRM changed its model, and your contract has no clause for it
On August 26, 2026, Salesforce and Anthropic announced Claudeforce. One sentence in the official release deserves a second reading: Claude becomes the default model for Slack AI, Slackbot, Salesforce in Claude, Headless 360, and Agentforce Coworker. The same text is more careful about the rest of the perimeter, where Claude serves as a reasoning model for the Atlas Reasoning Engine and is "available in Agent Builder". The distinction is real and worth holding onto: default is not exclusive, and available is not imposed. What happened on August 26 was not the closing of an architectural choice. It was a default setting moving on surfaces that tens of thousands of teams open every morning.
The instinct when reading an announcement like this is to ask whether you are locking yourself into one model provider. The more useful question sits elsewhere, and Anthropic's own documentation asks it better than any commentary. When Claude is served through Amazon Bedrock, which is precisely the arrangement Salesforce describes for bringing Claude inside its Trust Boundary, Anthropic states plainly that the cloud provider is the data processor, not Anthropic. The name in the headline of the announcement is therefore not the one whose retention policy governs your data. The model independence debate has been running for two years against the wrong name.
The September 1 article covered deprecation notice as a vendor clause, meaning what breaks when the provider you chose removes what you call. The subject here is the reverse, and nobody owns it inside the organization: the model you did not choose, embedded in a business application, replaceable by a third party, with no contractual event on your side. The VentureBeat Pulse Research survey of August 12, 2026, covering 107 companies, ranked flexibility across models as the top purchasing criterion for an orchestration platform at 29%, well ahead of native alignment on a frontier model at 10%. The market claims agnosticism on the layer it operates at the very moment it gives it up on the layer it buys.

What the announcement says exactly, and what it does not
The announced perimeter is broad but bounded. Salesforce in Claude arrives with 37 prebuilt sales skills, restricted today to selected pilot customers, with an open beta announced for September 2026 and additional skills promised for late in the year. In other words, as you read this, the most visible part of Claudeforce is not yet generally available, while the default model switch on Slack and Agentforce Coworker is described in the present tense.
One passage describing the customer-side setup says considerably more than it appears to. An administrator connects Salesforce in Claude once, authentication and permissions are managed centrally, and the entire sales team has access from day one, with no per-user setup, no new permissions model to build, and no account-by-account re-audit. That is an excellent deployment argument. It is also an exact description of an exposure surface that opens through a single administrative action, for an entire population, over live revenue data.
Three terms not to conflate
Embedded model: a language model you neither chose nor contracted for directly, which produces the reasoning behind a feature of business software you buy. You pay for the software, not the model.
Default: an initial setting, changeable by whoever controls it. The opposite of exclusive. A default can move without anything moving in your contract, because the contract covers a service, not a component.
Harness: the layer of tooling, rules, and context around the model that determines most of its behavior. Salesforce calls its own AIforce and presents it as the way to expose its data and workflows to any agent.
That last notion decides everything that follows. If most of the behavior comes from the harness rather than the model, a vendor can sincerely regard a model change as an implementation detail. That position is defensible in engineering terms. It becomes untenable the moment the model's output triggers an action on your data, which is exactly what Salesforce claims it does.
The name in the announcement is not the one processing your data
Anthropic's retention page is a reference document on this subject, and it opens by drawing its own boundary. It covers the Claude API, Claude Platform on AWS, and Claude in Microsoft Foundry, cases where Anthropic is the data processor. On Amazon Bedrock and Google Cloud's Agent Platform, the cloud provider holds that role, and the documentation explicitly redirects the reader to those platforms' policies. The Salesforce release states that Claude enters the Trust Boundary through Amazon Bedrock.
Follow the path to the end. Your contract binds you to a business software vendor. That vendor runs inference in a cloud environment where it is the customer. The model provider, whose name carries the headline, is not the data processor in this arrangement. Three entities, three retention regimes, and a single contractual relationship on your side.
Who is who in the chain
Controller: the entity that determines the purposes and means of processing. Its policy is the one that applies, and the obligations fall on it.
Processor: the entity that processes data on the controller's behalf, within the limits of its instructions.
Subprocessor: the processor's processor. This is where the cloud provider and the model provider sit in an embedded AI arrangement, and it is the level most pre-2024 SaaS contracts do not describe.
The second thing to check is retention imposed upstream, a subject already covered on August 26 through the angle of derived signal and Zero Data Retention. Anthropic's documentation designates Claude Fable 5 and Claude Mythos 5 as Covered Models, requires 30-day retention on them, and excludes Zero Data Retention for both. The wording that matters to a software buyer is the scope: the requirement applies wherever those models are offered. On Bedrock and Google Cloud, the retained data stays inside the cloud provider's environment, which changes the location but not the principle. A business software vendor cannot negotiate that constraint away on your behalf, and nothing in a CRM contract today tells you which model generation serves its AI features.
One more element is worth knowing, because it cuts across every regime: Anthropic states that content flagged by its automated safety systems may be retained for up to two years, regardless of the arrangement in place.

What an embedded AI contract actually contains
The supplementary terms vendors publish for their generative AI features are more instructive than the announcements. Litera's, a legal software vendor, are public and dated April 2026. They provide a readable specimen of what thousands of companies sign today.
On model hosting, the vendor commits to using models hosted in the same jurisdiction as the software "where commercially and technically feasible", and failing that in a jurisdiction with comparable standards. The following sentence shifts the burden: it is the customer's responsibility to consult the product documentation and subprocessor disclosures to determine where the model is hosted. Location is therefore not a quantified contractual obligation. It is information to go and find, in a document the vendor updates alone.
On upstream dependency, the text provides that if the customer's use contradicts third-party terms the vendor must abide by, naming Azure OpenAI's explicitly, the vendor may immediately cut access to the AI features after notifying the customer. The model provider's terms therefore travel through the contract and reach you, in one direction only.
On price, the vendor reserves the right, at its sole discretion, to throttle access, require migration to a higher-cost plan, or add usage-based charges, subject to reasonable prior notice. On agents, a clause prohibits deploying autonomous agents, recursive prompt chains, or any automation that materially increases token consumption outside intended user flows. Many teams building an orchestrator on top of their business software today have not read that clause.
What is missing from the document says more than what it contains. Four clauses cover jurisdiction, termination, price, and usage. None requires the vendor to warn you before changing the model underneath your workflows.
Five clauses to run against every contract with an embedded model
The grid below runs contract by contract, with a test question for each. The first pass requires neither immediate renegotiation nor specific legal expertise.
The first covers substitution and its notice period. Does the contract state what the vendor may change in the reasoning chain, and how long before you find out? Michael Kimball, who tracks these negotiations as The Innovation Attorney, describes the clause now settling into enterprise agreements: advance notice before any material change to the underlying model, materiality defined by a measurable accuracy or output shift, and above all a window to test the replacement against your own test set before the swap becomes mandatory. He puts the notice period under discussion at thirty to sixty days. Test question: ask two vendors for that number in writing this week and compare the answers.
The second walks up the subprocessing chain. Do not ask which model is used, ask who the data processor is. Name the three entities in order, software vendor, cloud provider, model provider, and identify which one publishes the retention policy that actually governs your data. Test question: if nobody on the team can name all three in under a minute, the clause is not audited.
The third deals with retention imposed upstream. Check whether the vendor's AI features rest on a model generation subject to mandatory retention, and where that data lives. Test question: ask whether a change of model generation at the provider can alter your retention regime without an amendment to your contract.
The fourth concerns price pass-through, because model prices move in both directions. Does the contract say who absorbs an increase, and with what notice? The Litera clause shows the shape asymmetry takes when nothing is negotiated: migration to a higher-cost plan, at the vendor's sole discretion. Test question: find the sentence in your contract that protects you from an upstream inference cost increase. If you cannot find it, it does not exist.
The fifth covers reversibility and permitted usage. What do you take with you on exit, in what timeframe, and in what form? And in the other direction, does your contract allow you to put an agent in front of the vendor's AI feature? Test question: search for the word "agent" in the supplementary terms of your three main business applications.
Two regulatory deadlines tighten the schedule for this review. The European Product Liability Directive must be transposed by member states by December 9, 2026, and it treats a software update or a machine learning change as a defect capable of triggering manufacturer liability, a status it extends to any party that substantially modifies a product after it reaches the market. Chapter V of the EU AI Act, applicable since August 2, 2026, separately requires general-purpose model providers to give downstream integrators what they need to meet their own obligations. A vendor receiving that information from its model provider should be passing it to you through the contract, not through a public model card your legal team will never see.
What to set in motion this week
Inventory the business applications where a model produces reasoning, not the ones where you call a model yourself. In the field, model exposure inventories almost always capture the calls the company makes itself and never the embedded models, for a simple reason: nobody in the organization bought a model, they bought a CRM module, a support tool, a document suite. The line appears in no AI budget.
Write to two vendors, not ten, and ask three questions: which model serves your AI features today, with what notice can it change, and who is the data processor in the arrangement you use. The quality of the answers, and how long they take to arrive, will tell you as much as their content.
Revisit your agent usage data before concluding the subject is marginal. The index Salesforce published on August 7, 2026, reports that the average agent now acts on six skills against two in early 2025, up to nine during seasonal retail peaks, and that the share of actions taken outside its core domain rose from roughly 1% to 5.9% between February 2025 and April 2026. These figures come from usage data the vendor aggregated across its own customers; they describe a trend, not a market. The trend is enough: the surface exposed to substitution is widening faster than the governance around it.
Finally, decide who owns the subject. Model substitution belongs neither wholly to procurement, which does not read supplementary AI terms, nor wholly to architecture, which does not see contracts. Until someone is named, the clause stays unaudited by construction.
Conclusion
A tribunal decision captures what is at stake better than any analysis. In Moffatt v. Air Canada, decided in British Columbia on February 14, 2024, the airline was held liable for incorrect information given by its chatbot, with the tribunal refusing to treat the bot as an entity separate from the company or to let a webpage stating the correct rule prevail. You answer for the output of a model you did not choose, served by infrastructure you did not contract for, under a retention regime you did not negotiate. The five-clause grid will not give you that choice back. It will simply tell you, contract by contract, what you have already given up.
Sources: As of August 2026
- [Primary] β Salesforce and Anthropic Announce Claudeforce: The #1 AI Meets the #1 AI CRM β Salesforce β 2026-08-26 β https://www.salesforce.com/news/press-releases/2026/08/26/salesforce-and-anthropic-announce-claudeforce/
- [Primary] β API and data retention β Anthropic, Claude Platform Docs β August 2026 β https://platform.claude.com/docs/en/manage-claude/api-and-data-retention
- [Primary] β Additional Terms for Software with Generative AI Features, April 2026 version β Litera β April 2026 β https://www.litera.com/sites/default/files/file/2025-03/GenAI%20Terms_v.Mar2025.pdf
- [Primary] β Salesforce Agentic Enterprise Index: Agent Deployments More Than Double Year over Year β Salesforce β 2026-08-07 β https://www.salesforce.com/news/stories/agentic-enterprise-index-insights-2026/
- [Secondary] β Rewriting the SaaS Agreement for the Age of Agentic AI β Michael Kimball, The Innovation Attorney β 2026-07-28 β https://theinnovationattorney.substack.com/p/rewriting-the-saas-agreement-for
- [Secondary] β Agentic orchestration: enterprise AI organizations know how to govern agents but still can't meter what they cost β VentureBeat Pulse Research β 2026-08-12 β https://venturebeat.com/resources/agentic-orchestration-enterprise-ai-organizations-know-how-to-govern-agents-but-still-cant-meter-what-they-cost
Comments ()