AI agent security innovations were announced by Cisco on May 12, 2026, designed to address risks in the agentic AI ecosystem where software takes autonomous actions rather than simply answering questions. The company introduced solutions at RSA Conference 2026 focused on establishing trusted identities, enforcing Zero Trust Access controls, hardening agents before deployment, and enabling security operations center teams to detect threats at machine speed.

A recent Cisco survey found that 85% of major enterprise customers reported experimenting with AI agents, but only 5% had moved agentic technology into production. The gap reflects security concerns as a top barrier to wider adoption. Cisco is addressing three key pillars: protecting the world from agents by ensuring they act as intended, protecting agents from the world by preventing manipulation or corruption, and detecting incidents at machine speed.

Establishing Agent Identity and Access Control

Cisco is extending Zero Trust Access to AI agent security by holding agents accountable to human employees and securing agentic actions. New Duo Identity and Access Management capabilities integrate with novel Model Context Protocol policy enforcement and intent-aware monitoring in Cisco Secure Access. The solution enables organizations to gain visibility and governance over their agentic workforce through three capabilities: Agent Identity Management registers agents in Duo IAM and maps them to accountable human owners, ensuring every agent has a verified identity and enabling traceability of actions.

Agent and Tool Visibility uses Cisco Identity Intelligence to discover agentic and non-human identities, helping organizations understand existing AI usage. Strict Access Control assigns agents fine-grained permissions for specific tasks or resources for short durations, with all tool traffic routed through an MCP gateway to eliminate blind spots. This approach differs from existing Secure Service Edge tools, which were not built to enforce time-bound access for agentic workload identities or understand context behind agent requests.

Testing and Hardening Agents Before Deployment

Cisco is expanding AI Defense with new tools to help organizations test, trust, and secure their AI agents and interactions between them. The company launched Cisco AI Defense: Explorer Edition, a self-service solution built on the same core AI Defense Validation engine trusted by Global 2000 customers. Users can begin red teaming AI models and applications that will be deployed into agentic workflows to uncover susceptibility to attacks and measure risk posture before deployment.

Cisco also introduced DefenseClaw, a secure agent framework designed to reduce friction between development and security teams. DefenseClaw integrates essential open source tools including Skills Scanner, MCP Scanner, AI Bill of Materials, and CodeGuard. These capabilities help ensure every skill is scanned and sandboxed, every MCP server is verified, and every AI asset is automatically inventoried, enabling developers to deploy secure agents with greater speed.

Detecting and Responding to AI Incidents

Splunk, part of Cisco’s security portfolio, has embedded AI capabilities into key security operations center workflows to move from reactive to proactive threat detection. The same AI agents that pose new security challenges can also serve as powerful tools for defenders. Current SOC analysts face alert fatigue and fragmented data, spending more time on research than response. Splunk’s enhanced capabilities address these operational challenges by automating analysis and prioritizing threats.

Industry Context and Adoption Barriers

According to Cisco’s 2025 Talos Year in Review, attackers overwhelmingly targeted components that directly authenticate users, enforce access decisions, or broker trust between systems. Adversaries’ focus on identity is expected to accelerate with the rise of agentic workloads. Most enterprises currently lack visibility into which agents are running or who is responsible if something goes wrong, creating governance gaps that security innovations must address.