Cisco is expanding its cybersecurity portfolio around a simple premise: AI agents need to be treated as operational identities, not just software features. In a March 23, 2026 announcement from RSA Conference, the company introduced a set of controls covering agent identity, access permissions, adversarial testing, runtime protection and security operations.
The announcement reflects a shift in the security problem created by agentic AI. Traditional assistants generally respond to a person, while agents can interpret intent, call tools and act across business systems. That makes authorization, traceability and containment more important than a model’s ability to generate a useful answer. Cisco framed its release around three goals: protecting organizations from agents that act beyond their mandate, protecting agents from manipulation, and helping security teams investigate incidents at machine speed.
Identity becomes the first control layer
Cisco says its Zero Trust Access capabilities are being extended to AI agents through Cisco Identity Intelligence, Duo identity and access management, and policy enforcement in Secure Access. The proposed model gives each agent a verified identity and maps it to an accountable human owner. That association is intended to make agent actions traceable and give security teams a clearer answer when an automated workflow behaves unexpectedly.
The company also described visibility features for agentic and other non-human identities. This matters because organizations can deploy AI tools through multiple teams, cloud services and development platforms without maintaining a single inventory. Cisco says its tooling is designed to discover those identities and the tools they use. Access can then be restricted to the resources required for a specific task and for a limited period. Tool traffic routed through an MCP gateway is intended to reduce blind spots between the agent and the systems it can reach.
Cisco cited a survey of major enterprise customers in which 85 percent reported experimenting with AI agents, while 5 percent had moved agentic technology into production. Those figures are Cisco’s own survey results rather than an independent industry census, but they illustrate the adoption gap the company is targeting: organizations are testing agents faster than they are establishing governance around them.
Red teaming before deployment
The company’s AI Defense: Explorer Edition is presented as a self-service environment for testing models and applications before they are connected to production workflows. Cisco says it uses the same core AI Defense Validation engine used by its enterprise customers, but the announcement does not provide independent test data demonstrating how the service performs against a representative set of attacks.
At launch, the feature set included dynamic, multi-turn adversarial testing for agentic workflows; checks for prompt injection, jailbreaks and unsafe outputs; exportable security reports; API access for CI/CD systems including GitHub Actions, GitLab and Jenkins; and team collaboration features. Cisco also announced an Agent Runtime SDK that embeds policy enforcement into agent workflows during development. The SDK supports frameworks and platforms including AWS Bedrock AgentCore, Google Vertex AI Agent Builder, Azure AI Foundry and LangChain.
This pre-deployment emphasis is significant because agent security cannot be assessed only by sending isolated prompts to a model. An agent may interpret a sequence of messages, retrieve sensitive context, call a tool and then pass the result to another system. Testing must therefore examine the complete workflow, including tool permissions and the consequences of an apparently successful action.
DefenseClaw and the runtime question
Cisco also introduced DefenseClaw, an open-source secure agent framework that brings together several security components. The company lists a Skills Scanner, MCP Scanner, AI Bill of Materials and CodeGuard among the integrated tools. Cisco says the framework is designed to scan skills, verify MCP servers, sandbox components and maintain an inventory of AI assets.
The announcement says DefenseClaw features will hook into NVIDIA’s OpenShell to provide runtime-level protection. That integration is described as an ongoing collaboration, so organizations should distinguish the announced direction from a fully documented, generally available deployment path. The practical value of the approach will depend on how consistently the framework can enforce policies across different agent runtimes and cloud environments.
From alert triage to agentic SOC workflows
On the operations side, Cisco said Splunk is adding specialized AI agents to security workflows. The named capabilities include Detection Builder, Standard Operating Procedures, Triage, Malware Threat Reversing, Guided Response and Automation Builder agents. Cisco describes these systems as moving beyond data retrieval toward evaluation and execution, with the goal of reducing repetitive work for analysts.
The release also announced Exposure Analytics, Detection Studio and Federated Search updates. Detection Studio and the Malware Threat Reversing Agent were described as generally available at the time of the announcement, while other capabilities were assigned future launch or prerelease targets. Cisco explicitly noted that those timelines could change.
The broader message is that agent security is becoming an end-to-end discipline. Identity controls determine who an agent is and what it may access. Red teaming tests whether the workflow can be manipulated. Runtime safeguards limit the damage if a component is compromised. SOC automation then helps defenders investigate and respond when something still goes wrong.
Cisco’s announcement is best understood as a portfolio and roadmap statement, not an independent validation of security effectiveness. For organizations evaluating agent deployments, the useful takeaway is the control sequence it highlights: inventory every agent, assign human accountability, apply least-privilege permissions, test multi-step behavior before launch, and keep runtime activity visible to the security team.
Source: Cisco Newsroom, March 23, 2026.
