Reference  ·  Updated August 2026  ·  Aethyr Research

Independent analyses put the real cost of deploying Agentforce for a mid-market company well beyond $150,000 and $600,000 in Year 1. The headline price is $2 per conversation. The gap between those two numbers is Data Cloud licensing, implementation services, and a consumption billing model that is hard to forecast before deployment.

This page sources its key numbers. It is the reference for any technical or security buyer evaluating enterprise AI agent platforms across pricing, data sovereignty, and cryptographic identity: five major platforms measured on the same basis.

§1

The market moment

Adoption is no longer the question. Control is. The platform decision being made now locks in for three to five years.

72%
of enterprises are using or testing AI agents
Zapier · Dec 2025 [1]
40%
of enterprise applications will include task-specific agents by end of 2026
Gartner [2]
95% / 29%
say sovereign AI is important / are actually acting on it
NTT DATA · May 2026 [3]
38%
of organizations cite security and privacy as their top barrier to AI adoption
NTT DATA · May 2026 [3]

The organizations that choose wrong will spend years unwinding ecosystem dependencies. Security and data privacy are widely reported as the top barriers to adoption, and the architecture chosen today is the one that determines whether those barriers can ever be cleared.

§2

Platform comparison

Five platforms, seven dimensions, one basis. Sort by Year-1 TCO or by name; filter to platforms with hardware-bound sovereignty.

Sort
Platform
Pricing
Year-1 TCO
Deployment
Sovereignty
PQC identity
Agents
AiOS Console
Aethyr Research
Seat-based
$160K–$200K
On-prem / sovereign
Yes
FIPS 203/204
Unlimited
Copilot Studio
Microsoft
Consumption + M365
$120K–$480K
Azure cloud
No
Not platform-native
Metered
Agentforce
Salesforce
Per-conversation
$150K–$600K
Cloud only
No
Not platform-native
Metered
ServiceNow
ServiceNow
Quote required
Quote-gated
ServiceNow cloud
No
Not platform-native
Tiered
watsonx
IBM
Enterprise license
Enterprise-only
Hybrid
Partial
Not platform-native
Tiered
TCO ranges are Year-1, modeled on a 100-seat mid-market deployment. Sources [3][4].
§3

The total cost of ownership

The per-conversation headline price excludes the stack typically required beneath it. Model your own deployment below. Every input maps to a documented Agentforce cost line.

Deployment inputs
Users / seats100
Cases per user / day3
Working days / month20
Engagement scope
Agentforce · Year-1 TCO
$299,600
per user / year
$2,996
Data Cloud (typically required)$108,000
Implementation$50,000
Consulting / yr$120,000
Flex Credits / yr$21,600
AiOS Console · seat-basedfrom $2,400 / seat / yr
Seat-based annual contracts, unlimited agents. No per-action billing, no consumption credits, no prerequisite platform, so cost does not scale with agent activity the way the metered stack above does. Volume pricing beyond a starter team: contact us.

Salesforce Agentforce: headline vs. real

The $2/conversation rate is real and incomplete. Data Cloud is a prerequisite commonly at six figures per year before a single agent runs. Implementation typically runs well into six figures, with ongoing monthly maintenance retainers. Salesforce's own worked example (100 users, 3 cases/day, 20 days) consumes 360,000 Flex Credits at $1,800/month in credits alone. [4]

Microsoft Copilot Studio: the stack math

Copilot Studio is consumption-priced and assumes the M365 estate beneath it. The agent line looks modest until you account for the per-message metering and the E3/E5 licensing the experience is designed around. The forecastable number is the floor; the realized number tracks usage, which is the variable few can hold flat across a 12-month rollout.

ServiceNow: the quote-required wall

ServiceNow's agent pricing is quote-gated. The published list does not carry the number; it carries a contact form. For a buyer building a decision memo, a price that cannot be retrieved without a sales motion is itself a data point: TCO is unknowable at the evaluation stage, and tiering is negotiated against an installed Now Platform footprint.

IBM watsonx: built for the largest enterprises

watsonx supports hybrid deployment, which is the closest any incumbent comes to data locality. The cost of that flexibility is an enterprise-license and services posture that in practice suits large enterprises and front-loads integration. It is a platform for organizations that already run IBM, sized accordingly.

§4

The sovereignty gap

Data sovereignty is not a feature you toggle. It is a property of where computation happens. When a cloud-native agent processes a record, that record moves through the vendor's cloud. Masking is not residency, and the distinction is the entire question for a regulated buyer.

Where your data goes
AgentforceSalesforce cloud
Copilot StudioAzure
ServiceNowServiceNow cloud
watsonxHybrid
AiOS ConsoleStays on your hardware
The three buyers this affects
Defense & government suppliers
CMMC, FedRAMP, and data-residency mandates that are hard to satisfy with a third-party cloud contract alone.
Healthcare & life sciences
HIPAA and patient-adjacent data where the processing boundary is the liability boundary.
Financial services & energy
Contractual residency and sector regulation that turn an architecture choice into a compliance posture.
Scenario · a defense contractor running Agentforce

An agent handling a controlled-unclassified support ticket sends that record through Salesforce infrastructure. The Einstein Trust Layer masks fields. It does not keep the record inside the contractor's environment. Where does the data sit at rest? Who holds the keys? What is the legal exposure under the contract?

Hardware-bound identity changes the answer at the cryptographic layer, not the network layer. The agent's identity is anchored in physical hardware: iOS Secure Enclave, a TPM2 PCR-policy seal on server nodes, eFuse OTP on edge devices. Agent impersonation is designed to be cryptographically infeasible, and the data does not cross the hardware boundary. That is what on-premises sovereignty means when it is real. Only 38% of enterprise leaders report high confidence in their cloud security posture [3], and the architecture decision is the security-posture decision.

§5

Post-quantum cryptographic identity

Harvest-now-decrypt-later is an operational assumption, not a theoretical threat. A nation-state storing today's encrypted agent traffic for decryption when quantum computers mature is the exact model CNSA 2.0 was written for. NSA's Commercial National Security Algorithm Suite 2.0 mandates migration off classical cryptography for national-security systems: ML-KEM for key encapsulation (FIPS 203), ML-DSA for signatures (FIPS 204), SLH-DSA for stateless hash-based signatures (FIPS 205).

A vendor claiming PQC support should be able to show test evidence. NIST's ACVP (Automated Cryptographic Validation Protocol) supplies the algorithm test vectors: passing every parameter set means the implementation computes each FIPS-standard algorithm correctly, not merely that a library was linked. Module-level CAVP/CMVP certification is a separate, later step, still rare among AI agent platform has completed either.

NIST ACVP: algorithm test-vector results
All 9 parameter sets implemented: FIPS 203 / 204 / 205
Tested internally
against NIST ACVP test vectors [5]
ML-KEM
FIPS 203 · key encapsulation
512PASS
768PASS
1024PASS
ML-DSA
FIPS 204 · digital signatures
44PASS
65PASS
87PASS
SLH-DSA
FIPS 205 · hash-based sigs
SHA2-192sPASS
SHA2-192fPASS
SHA2-256sPASS
1,493
SPARK Gold proofs
GNATprove discharged
7 / 7
Tamarin protocol
properties proved
6 / 7
ProVerif
properties proved
8,430
TLA+ states
no deadlock

Why retrofitting this is hard for incumbents. TLS and OAuth identity sit at the core of every incumbent platform, beneath every integration and API. Replacing that layer breaks everything above it. At Salesforce, Microsoft, or ServiceNow scale the migration surface is too large and the backward-compatibility risk too high. Post-quantum identity is not a product decision but a structural constraint of the current generation. This is not a criticism. It is the reason a clean-slate trust layer exists at all.

§6

The AiOS Console position

Not a pitch. A factual statement of what AiOS Console is, what has been independently verified, and what remains on the compliance roadmap. Transparent platform pricing, mesh-scale agents, hardware-bound sovereign deployment, and post-quantum cryptographic identity whose algorithm implementations are tested against NIST's ACVP vectors.

Starter
from $2,400/seat/yr
10 seats included, $24,000/yr
Unlimited agents. No per-action billing. Full PQC identity stack.
Professional
$2,000/seat/yr
40 seats included, $80,000/yr
Unlimited agents. Hardware-bound DID across nodes. Priority onboarding.
Enterprise
$1,600/seat/yr
150 seats included, $240,000/yr
Unlimited agents. Dedicated infra, air-gap option. Sovereign on-prem deployment.
Architecture facts
AWPClean-slate wire protocol built from first principles.
KEMML-KEM-768 for key encapsulation.
SIGNML-DSA-65 signs every agent action; verified against the hardware-bound public key.
ENCXChaCha20-Poly1305 for encryption.
DIDHardware-bound identity: Secure Enclave, TPM2 PCR-policy, eFuse OTP.
Verified: reproducible today
VERIFIEDML-KEM-768 / ML-DSA-65 implemented to FIPS 203 / FIPS 204 across all parameter sets.
VERIFIED1,493 SPARK Gold proofs discharged on the AWP codec.
VERIFIEDDelivered three paid milestone engagements for a commercial customer.
On the roadmap: not yet attained
PLANNEDSOC 2 Type 1: audit underway.
PLANNEDCMMC Level 2: planned.
PLANNEDCAVP / CMVP module validation: on the roadmap.

The sovereign AI infrastructure decision is architectural, not commercial. Once made, it compounds. The technical buyer reading this already knows which way the data points.

Sources
[1] Zapier: AI agent adoption, December 2025.
[2] Gartner: enterprise application forecast, 2026.
[3] NTT DATA: Global AI Report 2026, May 14 2026.
[4] Salesforce: Agentforce pricing worked example, 2026.
[5] NIST ACVP: public algorithm test vectors, used in internal testing. Formal NIST certification not yet obtained.
AETHYR RESEARCH LLC  ·  SOVEREIGN AI INFRASTRUCTURE  ·  AUGUST 2026