Cisco added its strongest guardrails yet concerning the hottest – and perhaps most insecure – tool of the moment: AI agents.
As part of Cisco Secure Access, the networking giant is extending its Zero Trust Access solution to AI agents, with users able to register agents for identity and access management (IAM) safeguarding. In a press briefing ahead of this week's RSA 2026 event, Tom Gillis, SVP and GM for Cisco's Infrastructure and Security Group, compared agents to the humble computer printer while revealing Cisco believes agents offer the “worst of both worlds" when it comes to security.
“Human access is still pretty broad. … I can get to over 1,000 applications, and it's still pretty long-lived, like it's months or sometimes years,” Gillis said. “At the other end of the spectrum, we have machine access, and here you want a printer to be able to access the print manager and nothing else. So this is extremely narrow access and extremely rigid. As we start to move into a world of AI agents, these two lines begin to blur. Because the agent has the power of the human but the common sense of the printer.”
Gillis argued Cisco’s updates move agentic access control to action control, giving the example of preventing an agent that typically processes expense reports from making any big-ticket item purchases, either due to its intrinsic lack of judgment or the control of a nefarious actor.
“We need to think not just about whether the agent can access the expense report or the credit card, we have to think about what is it doing inside of that? … These little agents need the ability to solve a problem, and so it is what we call 'task-driven behavior.' And what's particularly challenging is that those tasks may change [spurring] a different set of functions that I need to allow. So identity becomes a critical part of this.
“This is a really, really hard problem, and it is moving at warp speed because people are downloading, using tools like OpenClaw, and they're creating these agents with or without its approval,” Gillis added, noting concern over the exponential increase in scope, speed, and scale.
Accordingly, Cisco’s new tools help understand the difference between humans and agents, adding intelligent security controls for human access alongside minimum privilege for machine access. This ability, which is built on Cisco's Duo capability, is what was described as a non-human identity that can keep track of agents while judging what access is granted on a sessional basis only.
Specifically, Duo IAM is integrated with model context protocol (MCP) policy enforcement to route tool traffic through an MCP gateway,while assigning short-term, fine-grained permissions to agents only for specific tasks or essential resources they need for a short duration. Tool traffic is routed through an MCP gateway to remove blind spots, while Cisco Identity Intelligence helps monitor agentic and non-human identities on the network.
Claw-in-claw with Nvidia
Regarding agentic ecosystems like OpenClaw, Cisco is also releasing its DefenseClaw secure agent framework, which is compatible with Nvidia's recently released OpenShell open-source runtime that enforces policy-based security, network, and privacy guardrails for AI agents.
DefenseClaw integrates tools such as Skills Scanner, MCP Scanner, and CodeGuard to keep skills scanned and sandboxed, MCP servers verified, and system-wide AI assets automatically inventoried.
Other additions include AI Defense: Explorer Edition, which is a self-service, shift-left platform to help users promptly red-team AI models and applications intended for agentic workflows. This allows for multiturn adversarial testing, and model and application security validation to detect prompt injections or jailbreaks. The tool provides API-first integration with continuous-integraton, continuous deployment (CI/CD) pipelines such as GitHub Actions, GitLab, and Jenkins.
This comes alongside an Agent Runtime Software Development Kit (SDK) to help embed policy enforcement directly into agent workflows, supporting mainstream frameworks like Amazon Web Services' (AWS) Bedrock AgentCore, Google's Vertex Agent Builder, Microsoft Azure AI Foundry, and LangChain. Cisco also unveiled an LLM Security Leaderboard, offering transparent assessments of large language model (LLM) risk in response to adversarial attacks and jailbreak attempts.
Splunk aids SOCs
Splunk is also offering agentic care, with the Cisco subsidiary now touting specialized AI agents covering detection, standard operating procedures, triage, malware threat reversion, guided response, and automation building.
These come with what were described as new AI-driven features: exposure analytics in Splunk Enterprise Security for a continuously updated inventory of all assets and users; automated detection engineering as mapped against the MITRE ATT&CK framework; and a unified search function for security operations centers (SOCs) to analyze data across multiple environments.
Commenting on the raft of releases was Jeetu Patel, president and chief product officer at Cisco, who said:
“AI agents aren't just making existing work faster; they're a new workforce of coworkers that dramatically expand what organizations can accomplish," Cisco Chief Product Officer Jeetu Patel explained. "Projects shelved for lack of resources are now within reach. The only limit is imagination, and security teams are the key to unlocking this opportunity by making the agentic workforce safe enough to trust."
Patel recently promised to SDxCentral that Cisco is doubling down on agentic security, while helping telecom companies to become inference providers as the rise of AI agents continues unabated.
Comments