Skip to news

Cisco Pushes Agentic Security Into the Enterprise Core

Cisco and Splunk are moving AI security agents closer to production, pairing on-premises infrastructure with spending controls and human oversight.

By THE COLDAI TIMES deskPublished 3 min read503 words

Cisco and Splunk unveiled a broader package of agentic-security tools on September 15, positioning the security operations center as one of the first enterprise environments where AI agents may move from assistants to semi-autonomous operators.

The announcement, made at Splunk’s .conf26 event in Denver, combines several pieces. Cisco said Splunk AI capabilities will run on-premises through its AI POD for Splunk, built with NVIDIA. Splunk also introduced new agentic-SOC skills spanning detection, investigation, response and governance. A new Tokenomics capability is designed to track AI spending and coding-agent usage in real time, giving technology leaders a way to connect model activity with operating costs.

The companies also formalized a multi-year agreement with AWS to develop security products aimed at AI-driven attacks. Cisco framed the overall strategy around a simple premise: enterprises will not deploy agents broadly unless they can observe what the systems are doing, restrict their permissions and explain the financial value.

What changed

The significance is less about a single model release than about where Cisco is placing the control layer. Instead of treating AI as a separate cloud application, the company is integrating agentic functions with telemetry, identity data, exposure analytics and existing security workflows. That architecture lets organizations keep sensitive operational data near the systems already collecting it, while using automation to triage alerts, investigate incidents and recommend or execute responses.

Splunk’s new capabilities are intended to make that workflow more repeatable. Cisco says customers can run, defend and observe AI where their machine data already lives. The approach also extends Cisco’s existing relationship with NVIDIA, suggesting that the company sees enterprise AI infrastructure and cybersecurity infrastructure increasingly converging.

Why it matters

Security operations are a natural proving ground for enterprise agents because the work is repetitive, data-heavy and time-sensitive. Analysts must correlate logs, identities, vulnerabilities and network events faster than attackers can move. If agents can handle the first layers of that process, companies may reduce alert fatigue and allow specialists to focus on higher-value decisions.

But the same setting exposes the central risk of agentic software: an automated system that can investigate can also misclassify, overreach or trigger an expensive response. Keeping the tools on-premises may help with data residency and control, but it does not by itself solve authorization, auditability or model reliability. Cisco and Splunk are therefore selling governance as part of the product, not as a later compliance exercise.

What remains uncertain

The announcement does not establish how independently these agents can operate, how customers will measure accuracy or what safeguards are mandatory before an agent can take action. Cisco also provided no customer deployment data showing reduced incident response times or lower total security costs.

The commercial test will be whether enterprises accept the additional infrastructure and integration work. If they do, agentic SOC tools could become a major route for AI adoption in regulated industries. If they do not, the package may remain another layer of automation around conventional security software rather than a genuine shift toward autonomous defense.

Related stories