Cisco has unveiled Cloud Control, a unified management platform designed to let human operators and AI agents run, monitor and defend critical IT infrastructure from the same environment. The announcement, made at Cisco Live US on June 2, 2026, frames agentic operations as a security challenge as much as an automation opportunity.
According to Cisco's announcement, Cloud Control combines networking, security, compute, observability and collaboration capabilities behind one login. The platform is intended to give people and agents access to the same operational context, while keeping human teams responsible for oversight and decision-making.
One operating view for humans and agents
Cisco says Cloud Control brings together cross-domain telemetry so that operators and automated systems can act on shared information. The company is also combining purpose-built models with frontier models, including its Deep Network Model, which Cisco describes as being grounded in decades of operational networking data.
The practical objective is an agentic loop that can move from signal to action: an agent identifies a problem, investigates likely causes, proposes or carries out a fix, tests the change and confirms whether service has recovered. Cisco presents this as a way to automate complex infrastructure work without hiding the actions taken by the system.
That distinction is important. A conventional assistant can summarize an alert or suggest a command. An agentic operations platform can potentially invoke tools, change configurations and trigger workflows. Cloud Control therefore places visibility and governance alongside automation rather than treating them as separate security functions.
Runtime protection becomes part of the platform
The security portion of the announcement focuses on reducing the time between vulnerability discovery and exploitation. Cisco says it is expanding Live Protect, a runtime capability designed to shield supported Cisco products from newly discovered and prioritized vulnerabilities without requiring reboots, upgrades or maintenance windows.
At the time of the announcement, Live Protect was available for N9000 series switches and included with the Nexus One product entitlement. Cisco said the protection would expand to additional products, beginning with campus and branch smart switches and later secure routers. These statements describe Cisco's announced roadmap; organizations should verify current coverage and eligibility before relying on the capability for incident response or vulnerability mitigation.
Cisco also highlighted Hybrid Mesh Firewall, which is intended to coordinate protection across networks, applications, and Cisco and third-party firewalls. The stated goal is to limit the blast radius when an application, endpoint or automated workflow behaves unexpectedly.
Agents, tools and policy boundaries
Cloud Control Studio includes an Agent Builder for creating agents around customer policies and workflows. Cisco says the platform can connect to more than 50 third-party platforms and tools through native connectors or the open Model Context Protocol. An App Builder is intended to let teams create applications and workflows from natural-language prompts.
These integrations could make agentic automation useful across existing IT environments, but they also create a larger control surface. Every connector can expose data, permissions or actions that require explicit governance. The announcement says actions remain visible and governed, but it does not provide a complete control matrix for every connector or deployment model.
For security teams, the meaningful questions are therefore operational: which identities agents use, what permissions they receive, whether sensitive actions require approval, how tool calls are logged, and how quickly access can be revoked. Those controls should be tested against real workflows before an agent is allowed to make changes to production infrastructure.
Longer-term resilience and quantum risk
Cisco's release also covers risks that extend beyond immediate agent behavior. New Quantum Ready Assessments in Cisco IQ are intended to identify infrastructure exposed to harvest-now-decrypt-later attacks and help organizations prioritize migration work. Cisco said global availability was planned for July 2026.
The company further announced quantum-safe secure boot for newly introduced campus, branch and data-center routers, switches and firewall series, alongside a commitment to expand quantum-safe communications across most of its core portfolio by December 2026. These measures address a different time horizon from agent security, but both are part of the same resilience question: whether infrastructure can remain trustworthy as capabilities and attack methods evolve.
What the announcement means
Cloud Control represents Cisco's attempt to make the infrastructure control plane an operating environment for both people and AI agents. Its central proposition is not simply that agents can work faster, but that their actions should be connected to telemetry, policy, testing and recovery processes.
At launch, Cisco placed Cloud Control in Controlled Availability in the United States and said global availability would follow. That makes the June announcement a product and roadmap statement rather than an independent performance test. Organizations evaluating it should confirm present availability, supported products, data-handling terms and approval controls in current Cisco documentation.
The broader lesson is already relevant beyond Cisco's portfolio: as agents gain the ability to operate infrastructure, security cannot stop at model evaluation. Identity, least privilege, tool governance, runtime protection and human escalation paths need to be designed into the operating workflow from the start.
By Clara Reed
