Cisco is enhancing the deployment of trusted AI in the enterprise by introducing new advancements in Splunk, which are designed to bolster confidence and efficiency in AI adoption.
The barrier to widespread AI implementation often lies not in capability, but in trust.
Through innovations, Cisco aims to make AI scalable and secure across environments, notably extending its partnership with NVIDIA for on-premises AI deployment.
Expanding AI Accessibility with NVIDIA
The introduction of Cisco's AI developments addresses the difficulty of deploying AI due to data sensitivity concerns in the cloud. Through collaboration with NVIDIA, Cisco enables the deployment of self-managed AI within Splunk Enterprise, ensuring clients can utilize AI functionalities on their own premises, private clouds, or air-gapped environments.
Jeetu Patel, Cisco's President and Chief Product Officer, states, “One of the biggest roadblocks to enterprise AI today is that it’s too hard to deploy. Customers want to know: Can I trust it to do the job? Can I afford it? And, most importantly, can I secure it?” The new Cisco AI POD for Splunk package, optimized for on-premises customers, provides necessary infrastructure and software, with pre-validated capabilities ensuring efficiency and ease of use.
Harnessing AI for Security and Performance
New AI tools enable custom agent creation and deployment across use casesThe rollout introduces advanced features such as the Splunk AI Assistant and the upcoming Agent Launchpad, which facilitate custom AI agent creation and deployment for diverse use cases. Organizations can also adopt various AI models to suit their specific enterprise needs, thereby maintaining data integrity and security.
NVIDIA's Vice President of Enterprise AI, Justin Boitano, emphasizes the importance of localized data handling: “Enterprises need to bring AI where their data lives, especially when security and sovereignty requirements require critical workloads to stay on-premises.” This partnership ensures that Splunk AI operates effectively on NVIDIA computing resources, offering robust performance and security capabilities.
Enhanced Observability and Cost Management
Cisco customers can also take advantage of new observability solutions that offer comprehensive insights into AI agent performance and expenditures. To address potentially hidden costs, Splunk Agent Observability introduces Tokenomics, which provides visibility into AI token usage and costs.
Initially announced for on-premises use, the solution now extends to Splunk Observability Cloud and Cisco Cloud Control, offering comprehensive monitoring and guiding organizations in managing AI-related expenses. It ensures that AI operations are both economically sustainable and fully observable.
Elevating Security Through Agentic SOC
Splunk Enterprise Security Essentials expands security coverage and team autonomyThe introduction of an agentic Security Operations Center (SOC) is aligned with combating AI-driven threats. By integrating enterprise-wide telemetry with specialized AI agents, Cisco and Splunk enhance capabilities to meet the speed of modern threats. New enhancements in Splunk Enterprise Security Essentials are enabling broader security coverage and autonomy across various security teams.
These improvements allow security operations to effectively use data across networks, applications, and identities, offering deep analytical and responsive capabilities in counteracting cyber threats.
Collaborative Efforts with AWS
Furthermore, Cisco's strategic collaboration with AWS aims at joint product development to combat rapidly advancing AI-driven threats. The collaboration signifies a robust partnership where AWS's global cloud capabilities complement Cisco and Splunk's data platforms, providing expansive detection and response mechanisms.
Collectively, these advancements represent a progressive step for enterprises to maintain oversight, secure AI implementations, and ensure their security practices evolve in line with emerging threats.
As AI agents take on more of the work inside the enterprise, the biggest barrier to adoption isn’t capability – it's confidence.
Customers need to trust that AI is secure, governed, and worth the cost before they let it run at scale. Today, Cisco closes that gap through new Splunk innovations, giving
customers the ability to safely and cost-efficiently scale AI wherever their data already lives. This includes an expanded partnership with NVIDIA to bring Splunk AI to on-premises customers.
“One of the biggest roadblocks to enterprise AI today is that it’s too hard to deploy,” said Jeetu Patel, President and Chief Product Officer, Cisco. “Customers want to know: Can I trust it to do the job? Can I afford it? And, most importantly, can I secure it? By running Splunk AI on the infrastructure customers already trust, they can move faster to put AI to work in their business with confidence and control.”
Self-managed Splunk AI, accelerated by NVIDIA
For customers who can’t move sensitive data to the cloud, Splunk AI has remained out of reach – until now. Cisco and NVIDIA are expanding their partnership to bring self-managed AI directly to Splunk Enterprise customers, across their own on-premises, private cloud, and air-gapped environments.
- Cisco Secure AI Factory with NVIDIA is the reference architecture that brings the full AI stack together, built from Cisco AI PODs. The newest of these configurations, Cisco AI POD for Splunk, brings Splunk AI to on-premises customers with new AI runtime software, Cisco infrastructure, NVIDIA accelerated computing, and Kubernetes-based architecture – pre-validated and optimized for Splunk AI workloads. Cisco AI POD for Splunk is available today. For customers who have their own infrastructure, partners like bitsIO, Wipro, and World Wide Technology are ready on day one to help customers stand it up.
- Splunk AI Assistant (available now) and Agent Launchpad (coming later this year) run on this layer. Together, they bring ad-hoc agentic investigations and custom agent building for a broad variety of use cases including the agentic SOC to teams that run Splunk in their own data centers.
- Customers can also self-host a selection of open and proprietary generative AI models for their Splunk Enterprise workloads, including the Cisco Deep Time Series Model, Google Gemma 4, and OpenAI GPT-OSS 20B, with NVIDIA Nemotron open models in the coming months. Teams can use the model best suited for the job without sending data outside their environment.
“Enterprises need to bring AI where their data lives, especially when security and sovereignty requirements require critical workloads to stay on-premises,” said Justin
Boitano, Vice President of Enterprise AI at NVIDIA. “By enabling Splunk AI workloads to run with NVIDIA Nemotron open models on NVIDIA accelerated computing, Cisco and NVIDIA are working together to bring AI agents directly to Splunk and giving organizations a high-performance, full-stack foundation for agentic security operations wherever they run their infrastructure.”
Observe agent performance and track token spend in one view
New observability innovations give Cisco customers one full-stack view into how their AI agents are actually performing.
AI agents behave in ways that the people running them can’t always predict, running up costs that stay invisible until the invoice lands. Splunk Agent Observability, with its new Tokenomics capabilities, is closing that visibility gap and giving organizations a real-time view into agent performance and AI token spend. This enables teams to see exactly where and why AI costs accumulate before they become a budget problem.
Splunk Agent Observability, announced initially as an on-premises offering, is now available in Splunk Observability Cloud and in Cisco Cloud Control, extending visibility to customers working across the Cisco portfolio. It evaluates agent and model behavior, observes performance across the AI stack, and applies runtime guardrails that block inaccurate or unsafe actions, like hallucinations or leaking sensitive data.
As part of Splunk Agent Observability, the new Tokenomics solution extends that visibility to spend – tracking and attributing token expenditure across AI agents and employees’ use of coding agents like Claude Code, Codex, and Cursor. It will also forecast consumption patterns to project where spend is headed before a billing period ends, using the Cisco Deep Time Series Model. These insights help organizations to operationalize a tokenomics framework and tie AI spend to business outcomes.
Cisco is also helping organizations strengthen their infrastructure resilience by minimizing visibility gaps and cost barriers that hinder autonomous troubleshooting. The Observability Studio enables teams to ensure new applications are “born observable,” measurable and production-ready from the start. The new Network Intelligence App brings Cisco network topology, device health, and events into Splunk, so network teams can trace an alert straight to the device behind it and the network around it. Also, the new editions for Observability Cloud – Essentials and Premier – simplify how customers buy and expand observability across their business, with cost-effective log analytics to debug application and infrastructure problems.
Trusted autonomy for the agentic SOC
The AI threat landscape is on track to outpace the human-led defense model. Never has it been more critical for organizations to be able to understand and address potential exposure and vulnerabilities across their entire IT landscape – from the infrastructure to the applications. Stopping these AI-era threats requires an agentic SOC capable of reasoning and defending at machine speed, without compromising the data sovereignty and human governance enterprise leaders demand.
Splunk is advancing the agentic SOC by combining enterprise-wide telemetry with specialized AI agents powered by leading frontier and domain-specific models. New purpose-built agent capabilities expand the Splunk Agentic SOC Workforce and mirror how elite security operations teams work across detection engineering, proactive threat hunting, autonomous investigation, coordinated response, and policy governance. By correlating rich, full-stack machine data across network, cloud, application, and identity environments, these agents deliver deep reasoning and transparent, explainable verdicts that cut alert noise and accelerate mean time to remediate.
Attackers are now using AI to hunt for vulnerabilities at scale, probing infrastructure, applications, and identity systems continuously and indiscriminately. Recent exploitation campaigns have made complete exposure visibility a board-level requirement. New Exposure Analytics enhancements deliver on that with broader asset coverage, historical change tracking, and business-specific risk insights. Connecting exposure context to live security activity across Splunk, Cisco, and an extensive third-party ecosystem, so teams see their entire estate rather than one vendor’s slice of it. Agents use that context to pinpoint what matters most and where risk is active.
New capabilities in Splunk Enterprise Security Essentials bring agentic security operations and greater autonomy to far more security teams. Splunk Enterprise Security Premier adds deeper agentic autonomy and the full power of Splunk Enterprise Security.
Building the agentic enterprise together: Cisco’s Splunk and AWS
The same urgency is driving Splunk’s next chapter with AWS. Splunk and AWS are expanding their long-standing relationship into joint product development through a multi-year agreement. The work advances the agentic SOC to match the speed of AI-driven attacks.
Those attacks now move faster than human-led response processes can answer. Matching that speed takes deep security intelligence and the scale to act on it instantly. Splunk brings the data platform and detection depth security teams already run on. AWS brings global cloud scale. Together they will put agentic support in the hands of analysts across detection, investigation, and response.
Security teams won’t give up oversight to move faster. What’s ahead is agentic action at scale, with the governance and analyst control enterprises require.