Salesforce and SAP Clash Over AI Agent Integration Compliance

Salesforce and SAP Clash Over AI Agent Integration Compliance

Maryanne Baines is a preeminent authority in the intersection of enterprise software strategy and corporate technology law, possessing a rare ability to decode the complex licensing frameworks that govern the world’s largest tech ecosystems. With an extensive background in evaluating cloud tech stacks and their multi-industry applications, she has become a go-to strategist for firms navigating the increasingly blurred lines between interoperability and intellectual property. In this conversation, we explore the high-stakes friction between AI autonomy and proprietary governance, specifically examining how recent demonstrations of AI agents are testing the limits of long-standing vendor policies. We delve into the strategic maneuvers of industry giants, the historical weight of “indirect access” disputes, and the growing divide between vendor-endorsed architectures and the practical, day-to-day needs of global enterprises.

How do you interpret the technical and legal friction created by the recent demonstration where a Salesforce AI agent was seen navigating an SAP environment to onboard suppliers?

When you witness a demonstration like the one featuring the AI agent Marshall, you aren’t just looking at a clever piece of automation; you are seeing a direct challenge to the traditional “walled garden” philosophy of enterprise software. The agent wasn’t merely pulling data through a standard pipe; it was using large language model reasoning to actually learn the business rules, identifying field requirements and clicking through the interface just as a human operator would. This “wow-effect” created at the San Francisco keynote was designed to show that the user experience can be entirely detached from the backend system. However, from a legal and strategic perspective, this is where the “dragons” reside—a term we’ve used in the industry since the indirect access battles began nearly two decades ago. SAP’s position is that any autonomous AI must operate within their specifically endorsed architectures, and seeing their logic captured and replicated by a rival’s agent is likely viewed as a significant breach of their territorial integrity. It’s a bold assertion by Salesforce that the center of the enterprise universe is the collaboration platform, like Slack, rather than the ERP system where the data officially lives.

Salesforce has argued that because they used service accounts to interact with the user interface rather than calling APIs directly, the new restrictive policies shouldn’t apply—is this a legitimate loophole or a dangerous gamble for customers?

This is the multi-million dollar question that currently has every corporate counsel in the sector on edge. By claiming that they interacted through the user interface using service accounts, Salesforce is essentially trying to bypass the specific constraints of the API policy launched this past April. They are betting on the idea that if a human can log in and do it, a service account acting on behalf of an agent should be treated with the same permissions. However, critics and independent consultants are already pointing out that the policy specifically forbids “impersonation techniques.” If the AI is planning and executing sequences of calls to mimic a human, SAP can easily argue that this is an unauthorized bypass of their governed access paths. For a massive customer like Siemens, the risk is real; while Salesforce surely vetted this for compliance before “name-dropping” such a prestigious client, other enterprises might find themselves in a grey area where they are technically non-compliant the moment their agent starts “reasoning” its way through an SAP sandbox. It feels less like a stable loophole and more like a tactical provocation in a much larger war over who owns the metadata of business processes.

The term “endorsed architectures” appears frequently in recent policy updates; what does this mean for the 93 percent of large customers who are reportedly feeling locked out of modern AI capabilities?

The term “endorsed architectures” is essentially a code for “our way or the highway.” It’s a protectionist strategy that links the most advanced AI capabilities to specific partnership agreements, like the RISE with SAP program. When you look at the numbers, it’s staggering to realize that almost all large customers—that 93 percent figure—are essentially denied access to these streamlined AI integrations because they aren’t moving to the cloud on the vendor’s specific timeline. These customers are sitting on legacy systems or on-premise environments, and they are increasingly frustrated by the prospect of “wasting money” just to talk to their own ERP through an approved, and often more expensive, architecture. We saw a bit of a U-turn this past May when AI services were finally offered to on-premise customers, but the friction remains. Most organizations that have already deployed generative AI using standard APIs might now find themselves non-compliant under the April policy. This creates a massive disconnect between how customers actually work today and the rigid, siloed environment the vendor is trying to enforce.

How does the emergence of tools like the Joule Agent Builder, which arrived this past December, change the competitive landscape for companies trying to build their own cross-platform agents?

The release of the Joule Agent Builder and the subsequent 2.0 update this May were clearly designed to keep developers within the proprietary ecosystem. The executive board is now preaching “extensibility” as a core principle, promising that their agents can reach out to non-SAP applications. It’s a classic defensive move: if you can’t stop people from building agents, make sure they build them in your backyard first. However, the industry is skeptical because, despite the launch in late 2025, we haven’t seen a significant volume of successful, large-scale case studies yet. While SAP wants their agents to be the ones “reaching out,” Salesforce and Microsoft are already deeply embedded in the daily workflow of the end user. The real battle isn’t just about who has the best LLM; it’s about who has the “natural fit” with the person sitting at the desk. If a user is already spending eight hours a day in Slack or Teams, they are going to want their AI assistant to live there, not in a separate ERP portal that they only visit for backend tasks.

Given the aggressive posture of these vendors, what is your forecast for how enterprise licensing will evolve as AI agents become more autonomous and less dependent on traditional API calls?

We are heading toward a period of significant litigation and “licensing audits” that will likely feel quite painful for the end-user. My forecast is that we will see a fundamental shift from “per-seat” or “per-user” licensing toward “value-based” or “outcome-based” models, simply because the traditional metrics fall apart when an AI agent can do the work of fifty people through a single service account. Vendors will continue to tighten their API policies to prevent what they call “systematic data extraction,” but the sheer utility of autonomous agents will eventually force a more open standard. We’ll likely see a “Great Convergence” where the major players are forced to create a common interoperability layer, similar to how the industry eventually settled on SQL or HTML, because the alternative—a fragmented enterprise world where nothing talks to anything else—is a productivity nightmare that even the largest customers won’t tolerate. Expect more “edgy” demos in the coming months as companies test the legal boundaries of what it means to “access” a system in 2026.

WordsCharactersReading time

Subscribe to our weekly news digest.

Join now and become a part of our fast-growing community.

Invalid Email Address
Thanks for Subscribing!
We'll be sending you our best soon!
Something went wrong, please try again later