Salesforce has introduced Koa, its first reasoning model built specifically for CRM work, built on Nvidia’s open-weight Nemotron-3-Super-120 B. Salesforce is positioning the model for multi-step sales, marketing, and customer-support tasks inside Agentforce, and says it used no customer data to train it.
The important part for enterprise buyers is not simply that Salesforce now has another model. Koa changes where part of the Agentforce intelligence can run, who controls the model weights, and how dependent complex CRM workflows are on proprietary frontier providers such as OpenAI and Anthropic.
There is also an important availability caveat. Koa is currently being offered to selected pilot customers. Salesforce’s Koa product page says general availability in U.S. regions is expected in Winter 2026. This isn’t a model every Salesforce customer can switch on today.
Koa is built on Nemotron-3-Super-120B, not trained from scratch
Salesforce’s technical paper identifies the foundation model as Nvidia Nemotron-3-Super-120B, a roughly 120-billion-parameter reasoning model. Salesforce then post-trained it using reinforcement learning, specifically Group Relative Policy Optimisation, to improve tool calling and multi-turn enterprise workflows.
The training approach is more interesting than a generic CRM fine-tune. Salesforce generates simulated users, workflows, tools and business states from specifications describing how an Agentforce agent should behave. The model receives rewards when it resolves the task successfully through the correct tools, rather than merely producing a convincing answer.
That pushes Koa towards a problem enterprise agents repeatedly struggle with: deciding which action to take, selecting the correct function and maintaining enough context to finish a workflow that may span several turns.
Open-weight Nemotron does not automatically make Koa an open model
The wording around “open-weight” needs some care.
Nvidia’s Nemotron Open Model License permits commercial use and the creation and distribution of derivative works. That gave Salesforce considerably more control over the base model than it would have had when adapting a closed API-only model.
Salesforce, however, says it controls Koa’s weights and runs the model inside its own infrastructure. The launch material does not announce downloadable Koa weights, customer self-hosting or a standalone public Koa inference API.
So there are two separate facts. The foundation is open-weight. The Salesforce product built from it is currently a managed Salesforce model.
This creates an unusual form of portability. Salesforce becomes less dependent on a closed frontier-model company, but Agentforce customers do not necessarily become less dependent on Salesforce. That is worth remembering as Nvidia expands further into the open-model stack.
Koa plugs directly into Agentforce rather than becoming another separate AI app
Salesforce is integrating Koa as a model choice inside its existing AI stack. Customers can select it as a managed LLM in the Data Cloud generative models catalogue, choose it as an organisation-wide model provider, or assign it to individual agents, sub-agents, and agent routers in Agentforce.
This model-routing layer may prove more useful than the headline benchmark scores. A business does not need Koa to replace every other model. A straightforward writing task could still go elsewhere, while a multi-step CRM workflow involving records, policies and tool calls could be routed to Koa.
Developers also get a tighter relationship between agent configuration and model behaviour. Salesforce’s Agent Script describes routers, sub-agents, actions, tool scopes and workflow instructions. Similar specifications were used during Koa’s training process, meaning the model has been optimised around the kind of structured tool environment in which it will actually operate.
The benchmark story is more nuanced than Salesforce beating frontier AI
Koa’s technical paper reports meaningful improvements over the Nemotron base model, particularly on multi-turn tool use, but it does not show Koa dominating the strongest general-purpose models.
On Tau2Bench, Koa reached a task-weighted score of 69.41 compared with 68.64 for its Nemotron base. On the Berkeley Function Calling Leaderboard, it scored 66.63% against 64.73% for the base. Its overall CRM Bench score reached 0.86, compared with 0.84 for Nemotron-3-Super-120B.
Koa beat GPT-4.1 in the evaluations published by the Salesforce researchers, but stronger frontier models remained ahead on several measures. The practical case for Koa is therefore specialisation and deployment control, not a claim that Salesforce has built the world’s most capable reasoning model.
That is probably the right engineering target. An enterprise agent gains little from exceptional abstract reasoning if it repeatedly chooses the wrong CRM action, loses context or calls a tool with incorrect parameters.
No customer training data solves only one part of the privacy problem
Salesforce says Koa was trained using public and synthetically generated data, with no customer information included in its training corpus. Its synthetic scenarios cover CRM workflows across more than 14 industries and are based on the company’s experience building CRM systems, not copies of customer records.
This helps provenance reviews because an enterprise can separate the model’s training history from its own confidential CRM records.
It does not remove runtime risk. Once an Agentforce deployment is operating, Koa may still receive customer records, instructions and tool results as context. It can trigger actions that affect sales opportunities, service cases, and other business systems.
Security reviews should therefore concentrate on what each agent can read and change, which identity its tools use, how prompts and retrieved records are logged, and what happens after an incorrect tool call. Our guide to AI agent security covers the permission and tool-call risks that remain even when the underlying model itself is trusted.
Salesforce still has to prove Koa’s economics in production
Salesforce and Nvidia are also pitching the model around inference efficiency and reduced token usage. That could be significant because long-running agents can consume far more inference than a conventional chatbot interaction.
There isn’t enough public pricing information yet to conclude that Koa will be cheaper for customers in practice. A lower token count helps only if model pricing, Agentforce consumption charges and workflow success rates produce a lower total cost.
For buyers, cost per resolved workflow is a better metric than cost per million tokens. An inexpensive model that takes three attempts to update the correct opportunity can cost more than a higher-priced model that completes the task in one attempt.
Koa will not fix a badly designed Salesforce estate
A recurring concern from Salesforce practitioners discussing enterprise AI is that the model is often not the hardest problem. Years of custom fields, inconsistent records, brittle automations, overlapping permissions and poorly documented processes can leave an agent operating on foundations humans already struggle to understand.
Koa may make the reasoning layer better at navigating those workflows, but it cannot decide that a company’s underlying CRM design is wrong and safely rebuild it.
Before expanding a Koa pilot, teams should measure failed tool calls, permission errors, ambiguous records, unnecessary agent hand-offs and tasks that repeatedly require human correction. Those operational failures will say more about readiness than a model benchmark alone.
What enterprise buyers should check before adopting Koa
- Availability: Koa is still in selected customer pilots, with U.S. general availability expected in Winter 2026.
- Deployment control: confirm whether Salesforce’s managed deployment satisfies internal data residency and infrastructure requirements.
- Model provenance: record the Nemotron base model version, Koa version and applicable licences alongside other production AI dependencies.
- Permissions: audit what each Koa-powered agent can read, modify and send before judging model quality.
- Portability: do not assume an open-weight foundation means the finished Salesforce model can be exported or self-hosted.
- Economics: compare cost per successfully completed workflow against the existing Agentforce model route, not token pricing in isolation.
DIY AI view: Koa is a bigger deal for model control than model rankings
Koa gives Salesforce something it previously relied on frontier providers to supply: an enterprise reasoning model it can control, specialise and operate inside its own platform.
The open-weight Nemotron foundation gives Salesforce a credible route to reducing dependency on third-party model APIs while tuning behaviour around CRM tools and Agentforce workflows. For customers, however, the immediate benefit is not equivalent openness. Koa remains a Salesforce-managed product, and Salesforce has not announced a route to download its weights or move the same model into another stack.
The first pilots should therefore be judged on mundane but valuable measures: fewer incorrect CRM actions, fewer failed multi-step workflows, lower inference cost per completed task and predictable behaviour around sensitive business data. If Koa improves those figures, Salesforce does not need it to beat every frontier model on general intelligence. It needs it to be better at Salesforce work.