All posts

Cisco's five strategies to close the AI trust gap

Manaal KhanJuly 24, 2026 at 12:02 PM5 min read
Cisco's five strategies to close the AI trust gap

Key Takeaways

Closing the Trust Gap: Securing the Agentic Workforce | Cisco Live 2026

Cisco's five strategies to close the AI trust gap
Source: TahawulTech.com
  • Cisco identifies five critical areas to secure agentic AI: fundamentals, infrastructure, machine-speed defense, embedded protection, and AI-powered security
  • Trust must be built into AI infrastructure from the start, not added as an afterthought
  • Organizations need AI-powered defenses to counter AI-enabled attacks at machine speed

Cisco has published a framework of five strategies to address the growing trust gap in agentic AI deployments, warning that organizations unable to secure their AI systems risk being left behind. The guidance comes as enterprises race to deploy autonomous AI agents while struggling to manage the security implications of systems that can act independently.

"The ability to delegate a task in a trusted form is going to be the difference between being a market leader versus being bankrupt," said Jeetu Patel, Cisco's President and Chief Product Officer. The statement reflects a broader industry concern: agentic AI promises productivity gains, but only if employees and customers actually trust these systems enough to use them.

Advertisements

What are Cisco's five agentic AI security strategies?

The framework targets security, privacy, and infrastructure. Cisco's point is simple: trust cannot be a feature layered on at the end. It must be woven into the fabric of an organization's infrastructure from day one.

First, establish the fundamentals. Attackers target low-hanging fruit. Organizations must deploy phishing-resistant multifactor authentication, strong identity verification, and least-privilege access controls that extend to AI agents, not just human users. Zero Trust architectures, patching discipline, asset visibility, and configuration management form the baseline.

Second, upgrade infrastructure. End-of-life systems that cannot be patched or upgraded must be replaced. Modern platforms should include memory safety mechanisms and exploit mitigations designed for future threats. Structural vulnerabilities are not acceptable when autonomous agents operate across your network.

Third, defend at machine speed. Human analysts cannot match the scale, adaptability, and speed of modern threats. Organizations need machine-speed detection, automated triage and containment, and continuous monitoring of identity and data activity. Manual incident response is too slow when attackers move in milliseconds.

Fourth, embed defenses directly within workloads. Post-incident analysis is insufficient. In-line enforcement mechanisms, runtime protections, and updateable exploit shields must act in real time at the device, workload, and traffic path level.

Fifth, deploy AI for defense. The best counter to AI-powered attackers is AI-powered security. Use AI for threat hunting, conformance testing, digital twins, and validation. Cisco claims agentic AI can compress deployment cycles from months to days when used as a virtual security team member.

Also Read
Telli raises $15M to build AI voice agents for call centers

Another example of agentic AI deployment in enterprise settings

How do these five pillars compare in implementation complexity?

StrategyPrimary FocusImplementation TimelineKey Technologies
Establish FundamentalsAccess control, identityWeeks to monthsMFA, Zero Trust, IAM
Upgrade InfrastructurePlatform modernizationMonths to yearsMemory-safe platforms, cloud migration
Defend at Machine SpeedAutomated responseMonthsSOAR, SIEM, ML detection
Embed DefensesRuntime protectionWeeks to monthsIn-line enforcement, EDR
Unleash AIAI-powered securityMonthsThreat hunting AI, digital twins

Why does the AI trust gap matter now?

Agentic AI differs fundamentally from the chatbots and copilots that preceded it. These systems don't just answer questions. They execute multi-step tasks, make decisions, and interact with external services autonomously. A traditional AI assistant might draft an email; an agentic AI sends it, schedules the follow-up meeting, and updates your CRM.

That autonomy creates security exposure. An AI agent with write access to customer data, API credentials, and the authority to take actions without human approval is a target. If compromised, it operates at the same machine speed that makes it useful. The attacker inherits its permissions and its speed.

Without foundational trust, employees and customers hesitate to use AI to its full potential. Organizations invest in capabilities their people avoid. The productivity gains never materialize. Meanwhile, competitors who solve the trust problem pull ahead.

Also Read
UAE trains 32 experts on AI stack in new talent program

Regional context on enterprise AI readiness

Advertisements

What does least-privilege access mean for AI agents?

Traditional least-privilege access limits human users to the minimum permissions required for their job. Cisco's framework extends this principle to AI agents, a distinction that matters because agents often request broad access to be maximally helpful.

An AI scheduling agent doesn't need access to payroll systems. An AI code assistant doesn't need production database credentials. Defining tight permission boundaries for each agent, then monitoring for scope creep, is foundational work most organizations haven't done.

The challenge: agents are often deployed by business units without security review. Shadow AI is the new shadow IT, but with autonomous capabilities and API access.

What's missing from Cisco's framework?

The five strategies focus on defense and infrastructure. They don't address supply chain risks in AI models themselves, such as poisoned training data, backdoored weights, or malicious prompt injection attacks that manipulate agent behavior.

Model provenance and integrity verification are emerging concerns. If you deploy an open-weight model from a community repository, how do you know it hasn't been tampered with? Cisco's framework assumes you're running trustworthy models, then securing the infrastructure around them. That assumption may not hold.

ℹ️

Logicity's Take

Cisco's framework is infrastructure-focused, which makes sense given their product portfolio. But for AI builders and product teams, the harder problem is often agent behavior governance: what happens when an agent does something technically permitted but contextually wrong? Tools like LangChain and LlamaIndex offer some guardrails, but enterprise-grade agent orchestration remains immature. Teams should treat Cisco's five pillars as necessary but not sufficient. You also need runtime observability into agent decisions, not just network traffic and access logs.

Where to go deeper

Cisco's white paper, titled "Shields Up: Guidance for defending in the age of AI-enabled attacks," provides additional implementation detail. The company positions its networking, security, and observability portfolio as covering all five categories, though the framework itself is vendor-agnostic.

For organizations already running agentic workloads, the immediate action is access auditing. Map which agents have which permissions. Identify the agents deployed outside IT governance. That visibility is prerequisite to everything else.

Frequently Asked Questions

What is agentic AI in enterprise security?

Agentic AI refers to autonomous AI systems that can execute multi-step tasks, make decisions, and interact with external services without human approval for each action. In enterprise security, this creates both opportunity (AI-powered defense) and risk (AI agents as attack targets).

How does Zero Trust apply to AI agents?

Zero Trust for AI agents means treating each agent as an untrusted entity that must continuously prove its identity and authorization. Agents should receive least-privilege access limited to their specific function, with continuous monitoring for scope creep or anomalous behavior.

Why can't humans defend against AI-enabled attacks?

AI-enabled attacks operate at machine speed, adapting and executing faster than human analysts can detect, triage, and respond. Automated detection and containment are required to match the pace of modern threats.

What is embedded defense in AI security?

Embedded defense means building security controls directly into workloads, devices, and traffic paths rather than analyzing attacks after they occur. This includes in-line enforcement, runtime protections, and updateable exploit shields that act in real time.

What does Cisco's Shields Up white paper cover?

The white paper provides detailed guidance on defending enterprise systems in the age of AI-enabled attacks, expanding on the five strategies Cisco has outlined for securing agentic AI deployments.

ℹ️

Need Help Implementing This?

Logicity covers enterprise AI security weekly. Subscribe to our newsletter for implementation guides, tool comparisons, and interviews with security teams deploying agentic AI at scale.

Source: TahawulTech.com / Daniel Shepherd

M

Manaal Khan

Tech & Innovation Writer

Produced with AI assistance and reviewed by the Logicity editorial team. Learn more in our Editorial Policy.