Every writeup of Salesforce’s blowout quarter led with Agentforce and the Claude partnership, and not one of them set the $2.6 billion gain on its Anthropic stake next to the $3.53 billion of net income that gain sits inside. Anthropic is in three of today’s four stories, which is worth noticing in the weeks before it becomes a public company.
Salesforce Put Its CRM Inside Claude, and Claude Inside Slack
Matters. Salesforce and Anthropic announced Claudeforce on Wednesday, and the joint announcement is more specific than the branding suggests. The launch product is a plugin called Salesforce in Claude carrying 37 prebuilt sales skills, including meeting prep, deal health review and pipeline review. It runs on AIforce, the harness Salesforce describes as exposing its data and workflows to any agent through MCP servers, APIs and CLI tools. It is available to select pilot customers now, with open beta set for September 2026 and more skills arriving late in the year.
The line I keep rereading is the setup model. An admin connects Salesforce in Claude one time, permissions are managed centrally, and every seller on the team has access from day one with no per-user setup and no re-auditing account by account. That is genuinely the right design, and it is also the entire risk surface in one sentence. One admin action now determines what a reasoning model can read and write across your revenue system. If you pilot this in September, the work is not the plugin. The work is deciding what that service account can touch before somebody clicks connect.
Going the other direction, Claude is now the default model for Slack AI, Slackbot, Headless 360 and Agentforce Coworker, and Salesforce is putting Claude Code in front of its own engineers. Anthropic’s Dario Amodei told CNBC the companies built what he called Enterprise Frontier Safeguards around permissions. Take the specifics seriously and the marketing loosely: the “the UI is the AI” framing is a pitch, while the MCP harness underneath it is a real piece of plumbing you can reason about.
The $2.6 Billion Line Nobody Put in the Headline
Marketing. Salesforce stock rose 22% on Thursday, which CNBC noted was its second-best day ever, behind only a roughly 26% move in August 2020. The operating business did fine. Revenue came in at $11.35 billion against the $11.32 billion analysts modeled, up 11% year over year, and current remaining performance obligation reached $33.5 billion, up 14%.
Then there is the bottom line. CNBC’s report on the quarter puts net income at $3.53 billion, up from $1.89 billion a year ago, and notes in the same paragraph that the company booked a $2.6 billion gain on its strategic investment in Anthropic, whose valuation has climbed to $965 billion. Do that arithmetic. Roughly three-quarters of the profit in Salesforce’s record quarter came from owning equity in the company it shared a stage with that afternoon. That is not fraud and it is not even unusual accounting. It is just not operating performance, and every headline that ran “record quarter” without it left readers with the wrong picture.
The Agentforce number deserves the same treatment. Salesforce reported Agentforce annual recurring revenue above $1.5 billion, up more than 240% year over year, and then defined the metric in the earnings release like this:
Effective Q2 FY27, Agentforce ARR includes our AI offerings, Slackbot and Headless 360.
They widened what counts inside the metric during the same quarter the metric grew 240%. Slackbot is bundled into Slack, which Salesforce already owned. I am not saying the growth is fake, and 3.2 billion agentic work units in the quarter is real usage of something. I am saying a growth rate is uninterpretable when the denominator changed silently in the same period, and that “agentic work unit” is a unit Salesforce invented and defines. If you are building a business case on Agentforce adoption, price the seats, not the press release.
A Hundred Companies Signed a Cyber Warning. An Uncensored Model Shipped in 37 Hours.
Breaks your stack. On Thursday more than 100 organizations including OpenAI, Anthropic, Google, Microsoft, AWS, CrowdStrike, Palo Alto Networks, Visa and Mastercard signed an open letter calling for a global surge in cyber defense. It argues for a narrow “defenders’ window” of two to three years, asks AI companies to provide model access and funding to defenders, and asks governments to coordinate across borders. We covered a similar joint letter at the end of July, and the pattern holds: the labs sign the warning and none of the asks bind the labs.
Here is the part the coverage of that letter missed, and it happened this week. Z.ai shipped GLM-5.3 on August 14 and held back the open weights, saying cyber capability had developed faster than expected during post-training. The model scored 84.5% on CyberGym vulnerability discovery, ahead of Anthropic’s Claude Mythos 5 at 83.8% and OpenAI’s GPT-5.6 Sol at 83.6%, and surfaced 2,436 findings across 269 open-source projects, of which 107 were critical and 990 high. Z.ai targeted today, August 28, for the weights.
So I checked the Hugging Face API instead of taking anyone’s word for it. As of this morning, Z.ai’s account carries GLM-5.3-Flash and GLM-5.3-Flash-BF16, both published August 25, and no full GLM-5.3 repository at all. That breaks a run: GLM-5.2, GLM-5.1, GLM-5 and GLM-4.7 each shipped a base model and an FP8 version on the same day. The withholding is real.
The withholding is also doing less than it looks. The Flash weights went up at 06:43 UTC on August 25. By 19:37 UTC on August 26, roughly 37 hours later, an account had published a full-weight derivative of it labeled uncensored, 120 weight files, followed by a second one and an abliterated quantization the next morning. I want to be precise about what I verified: those repositories contain real weight files, and I have not run them to confirm what safety training was actually stripped. One honest counterpoint in the other direction, since I went looking for the scariest thing I could find: a repository named for offensive cyber work, created the day GLM-5.3 launched, turns out to contain two files and no weights at all. It is a squatted name, not a weapon.
The operator read is that a two-week safety hold buys you two weeks, and only on the checkpoint you actually withhold. Everything downstream of a public release belongs to whoever downloads it first. If your threat model assumed model providers are the control point, this week is the correction. We flagged the same gap when MiniMax promised open weights and slipped earlier this month.
Anthropic Is About to File Into a Country That Does Not Want Its Data Centers
Matters. Anthropic confidentially filed to go public in June and the prospectus is expected within weeks. CNBC reports that negative public sentiment toward AI and data centers will be named as a risk factor in that filing, with CFO Krishna Rao fielding questions in test-the-water meetings about competition, margin pressure from open-source models, and what happens if data center construction slows. Investors project a float around $2 trillion against a private valuation near $1 trillion, on a revenue run rate that hit $65 billion at the end of July.
The risk factor is not boilerplate. A Gallup survey published in May found seven in ten Americans opposed data center construction in their area, with close to half of those strongly opposed and only about a quarter in favor. That is already showing up in politics: Pennsylvania Governor Josh Shapiro signed an executive order tightening data center standards, and data centers were an issue in the Florida Republican gubernatorial primary.
My position: this is the most honest disclosure any AI company has made this year, and it is honest because the lawyers required it. Compute capacity converts more or less directly into revenue for a frontier lab, so local siting fights are not a public relations problem for Anthropic, they are a supply constraint on the growth curve the $2 trillion number assumes. Anyone building a business on a single frontier vendor should read that risk factor as a dependency disclosure about their own stack, not just about Anthropic’s.
What I Would Actually Do Monday
Three things came out of this week with different shelf lives. Claudeforce is real and you can plan around it, so spend September deciding permissions rather than evaluating features. The Salesforce quarter is strong and oversold, so use the operating numbers and ignore the profit line. The weights story is the one that changes behavior: assume any capability that ships in open weights is uncontrolled within two days, and build like the provider is not your safety boundary, because this week it demonstrably was not.