AI agent concept
– Getty Images

Cisco deployed its Foundation-sec-1.1-8B-Instruct model inside of its Identity Intelligence, taking another step toward AI-native security.

The integration is the result of collaboration between the Cisco Identity Intelligence and the Cisco Foundation AI teams, with a focus on to improve how enterprises detect, analyze, and respond to security threats.

The company said the model is designed specifically for enterprise security use cases, rather than general-purpose AI, enabling more accurate and contextual insights across critical security workflows.

IYaron Singer, VP of AI and engineering, and Didi Dotan, senior director of engineering, outlined in a blog post that, “Cisco Identity Intelligence helps organizations understand and respond to identity-related risk across their entire environment. It continuously monitors identity behavior, giving administrators clear insight into who is logging in, from where access is taking place, and which device is being used.”

The team also outlined that by examining post-authentication signals, the system can identify patterns that traditional access controls often miss, including unusual geographic activity, abnormal privilege usage, and indications of multifactor authentication (MFA) fatigue attempts or session hijacking. This expanded visibility can help security teams take proactive action before attackers advance within the environment.

Cisco also expects the technology to strengthen a broad range of security functions, including endpoint protection, network analytics, cloud defense, and policy analysis. By embedding AI more deeply into these areas, Cisco is seeking to automate complex security decisions and reduce the burden on security teams facing increasingly sophisticated attacks.

The launch comes hot off the heels of a demo of its agentic AI in which another of its security-optimized AI models – Foundation-Sec-8B – was used to power an autonomous agent for security operations center (SOC) use cases.

The firm indicated that this latest deployment will support deeper use of AI in future security services, particularly in identity-centric security, which has become a key focus as hybrid work and cloud adoption expand.