The management issue is not whether AI can help security teams, but who is accountable when it acts. Agentic tools only become useful when leaders can define the boundary between assistance and delegation. That means clear decision rights for what an AI agent may observe, recommend, block or execute, plus explicit escalation paths when confidence is low or behaviour is unusual.
Observability is therefore a governance requirement, not just a technical feature. If leaders cannot trace model behaviour, runtime context and downstream actions, they cannot prove control, tune risk appetite or satisfy audit and legal scrutiny. The practical question for CIOs and CISOs is which signals must be monitored centrally, which can remain in domain tools, and how exceptions will be reviewed without creating a manual bottleneck.
The operating model also changes. Moving toward machine-speed detection and response can reduce dwell time, but it may also compress the time humans have to validate alerts and approve containment. That creates a trade-off between automation and oversight: faster response versus a higher need for guardrails, testing and role redesign for SecOps, architecture and risk teams. Leaders should ask where human approval remains mandatory and where pre-authorised playbooks are acceptable.
Finally, platform consolidation is a portfolio decision, not merely a procurement one. Integrated controls may improve visibility and reduce integration burden, but they can also deepen vendor dependence and delay best-of-breed choices. The next questions for governance boards are whether the current toolset can support policy consistency across AI agents, how third-party integrations will be risk-assessed, and which metrics will prove that AI is reducing exposure rather than simply increasing activity.
Three-pronged approach to agentic security
Patel discussed how Cisco is working with enterprises in securing their agentic workforce via three main goals: by protecting AI agents from external threats, preventing AI agents from creating cybersecurity threats, and detecting and responding to threats “at machine speed.” Cisco’s AI threat strategy includes the launch ofย Cisco Cloud Controlย this week, available on a limited basis in the US. It’s currently being used by about 60 organizations including semiconductor company AMD. Cisco Cloud Control expands on last year’s launch ofย Security Cloud Control. The new product is a cloud-based network infrastructure management platform that embeds security services with a number of other IT and networking infrastructure applications โ both Cisco applications and 50 third-party vendors’ applications โ on a single platform. Enterprise customers don’t want to be system integrators anymore, but are looking to vendors to provide these types of integrated platforms, Robbins said during a press and analyst conference after the keynotes. Patel said he believes that โ with AI โ the ability to analyze every security signal/alert is within reach, predicting the emergence of agentic SOCs that can quickly identify and prevent network anomalies. But for SecOps teams to operate at “machine speed and scale,” they will need to invest in network visibility, threat validation, and security guardrails for AI agents, he said.Enjoyed this article? Sign up for our newsletter to receive regular insights and stay connected.

