Cisco Unveils Agentic Platform for Operating and Defending Critical IT Infrastructure

Cisco on Tuesday unveiled Cisco Cloud Control, a unified operating platform designed to manage, monitor and defend enterprise infrastructure through a combination of human operators and AI agents. Announced at Cisco Live U.S. in Las Vegas, the platform is the foundation of Cisco’s AgenticOps strategy, which aims to bring networking, security, compute, observability and collaboration operations into a common control plane.[1]

The launch matters because enterprises are being asked to operate more dynamic infrastructure as AI agents generate sustained traffic, interact with applications and APIs, and trigger a growing volume of operational changes. Cisco’s answer is not to hand unrestricted control to autonomous software, but to create a shared environment where agents can investigate, recommend, validate and, where authorized, execute changes with human oversight. Cloud Control entered controlled availability in the United States on June 2; it is not yet generally available.[1]

Cisco Cloud Control: key platform milestones5 stagesAgenticOps workflow>40 yearsnetworking operationaldata grounding>50third-party platformsand tools supporDec. 2026target forquantum-safe
Data: Article text

A common operating layer, not a wholesale replacement

Cisco Cloud Control is intended to reduce the fragmentation that has long characterized enterprise IT operations. Cisco describes it as a single login, shared data layer and common system of action spanning its major infrastructure domains. Rather than immediately replacing every specialized management controller, the service is designed to expose and coordinate capabilities from existing Cisco products.

The platform builds on Cisco’s former Security Cloud Control and expands the concept into network operations and observability. Its cross-domain view is supported by Cisco’s Splunk-powered Data Fabric, bringing together data that would otherwise sit in separate networking, security and operations tools.[1][2]

That consolidation is central to Cisco’s pitch. A connectivity incident may also involve an identity policy, a security event, an application dependency and a poor employee or customer experience. By correlating those signals in one environment, Cisco is attempting to shorten the path from alert to remediation.

Cisco AI Canvas is the collaborative workspace for that process. It is designed to let operators and AI agents investigate incidents using the same live evidence, rather than requiring teams to pass findings across disconnected dashboards.[1]

Cisco Nexus switch
Photo: Patrick Finnegan, CC BY 2.0, via Wikimedia Commons

The AgenticOps loop adds controls around automation

Cloud Control operationalizes Cisco’s five-stage AgenticOps workflow: sense, diagnose, remediate, validate and deploy. The sequence starts by identifying degradation, anomalies or security signals; correlates telemetry, topology, configuration and experience data to determine probable causes; then recommends or performs a corrective action. Before deployment, the platform is meant to test the proposed change and estimate its impact or blast radius. It then applies approved changes and verifies whether the user experience recovered.[1]

Cisco says the workflow combines its Deep Network Model, grounded in more than 40 years of Cisco networking operational data, with “Deep Reasoning” to assess competing explanations and the evidence supporting them. Other inputs include ThousandEyes network intelligence, Splunk observability data and experience metrics intended to translate large volumes of infrastructure telemetry into user-centered operational indicators.[1]

A digital-twin capability is intended to test changes before they reach production, while Cisco Agentic Workflows provide deterministic and governed execution. That distinction is important: Cisco is positioning the system as an automation platform with explicit controls, rather than an opaque agent allowed to make broad production changes on its own.

Operators can inspect what an agent observed, its inference, the evidence behind its recommendation, the proposed action, required approvals and the verified result, Cisco said. Customers will be able to set autonomy levels according to action type, network domain and change window.[5] Cisco President and Chief Product Officer Jeetu Patel has described this visibility as necessary to address an enterprise “AI trust deficit,” arguing that organizations will not delegate consequential work without insight into agent behavior, runtime activity and results.[4]

network operations center
Photo: Azaleos, CC BY-SA 3.0, via Wikimedia Commons

Studio and integrations broaden the platform’s scope

Cisco also announced Cloud Control Studio, the customization layer intended to let customers build agents, applications and workflows around their own policies and processes. Its Agent Builder supports agent creation through natural-language instructions, while App Builder is designed for building applications and workflows from prompts. Cisco said OpenAI Codex is embedded in the App Builder experience.

Studio is also expected to include a marketplace for internally developed and ecosystem-provided agents and applications. Cisco says Agent Builder supports more than 50 third-party platforms and tools through native connectors or the open Model Context Protocol, or MCP.[1]

Listed integrations include AWS, Microsoft, Google Cloud, Wiz, ServiceNow, PagerDuty, Slack and Linear. The approach reflects a practical constraint in enterprise operations: even Cisco-heavy environments rely on a mix of cloud providers, SaaS tools, ticketing systems and security products.

However, the June launch does not mean every Studio capability is ready for broad production use. TechTarget reported that Cisco plans to add Cloud Control Studio later in 2026, making the current release a controlled-availability foundation rather than a fully developed agent marketplace.[2] Questions around pricing, metering and data access will also matter, particularly when external agents consume Cisco data or invoke platform services. Mike Leone of Moor Insights & Strategy said the launch was Cisco’s most coherent platform argument in years, while cautioning that commercial details could determine adoption.[2]

Security and quantum resilience are part of the broader push

Cisco paired Cloud Control with a wider set of infrastructure-security announcements. Live Protect, described as a runtime “digital immune system,” is intended to protect supported Cisco products from newly discovered and prioritized vulnerabilities without requiring a reboot, software upgrade or maintenance window. It is available initially on N9000-series switches through the Nexus One entitlement, with Cisco planning expansion to campus and branch smart switches and then secure routers.[1]

The company also introduced Hybrid Mesh Firewall, which is intended to provide unified protection across networks, applications, and Cisco and third-party firewalls to limit attack blast radius. Cisco said it is extending agentic security capabilities across AI Defense, Zero Trust for agents and an Agentic SOC.[1]

On AI security, Cisco said it is a charter member of Anthropic’s Project Glasswing and OpenAI’s Daybreak, initiatives focused on testing AI-enabled cyber threats and defenses. It also open-sourced its Foundry Security Spec for evaluating AI-driven security systems.[1]

Post-quantum security was another major component. Cisco committed to support quantum-safe communications across the majority of its core portfolio by December 2026. The company announced quantum-safe secure boot for newly introduced campus, branch and data-center routers, switches and firewall series, plus a Quantum Resilience Framework. Quantum Ready Assessments delivered through Cisco IQ are planned for global availability in July and are designed to identify systems exposed to “harvest now, decrypt later” risks.[1]

Ambition meets a cautious enterprise market

Cisco is entering a crowded field. HPE Aruba, Juniper Mist, Extreme Networks, Arista, Forward Networks, HPE Apstra, Itential and Gluware all offer varying combinations of network automation, AI-assisted operations or orchestration. Hyperscalers and enterprise software vendors including Microsoft, Google, AWS, Dell and IBM/Red Hat are also building agent frameworks and management layers.

Cisco’s differentiator is breadth: a large installed base across networking, security and observability, combined with a platform designed to use information from all three. TechTarget noted that near-term demand will likely come primarily from existing Cisco customers, and Omdia analyst Jim Frey said Cisco is joining an active third-party agent ecosystem rather than inventing a new category.[2]

The near-term adoption model is also likely to be supervised automation, not full autonomy. Faisal Bhutto, chief executive of Cisco partner Alykas, said customers may accept agents that prepare a change while a human approves its production deployment, but are unlikely to permit unrestricted autonomous changes at the outset.[3]

Cloud Control’s broader claims will need validation. It remains in controlled availability, some capabilities are planned for later in the year, and Cisco has not yet provided broad independent evidence that the platform reduces mean time to resolution, outages or staffing costs. Its value will also depend on how much Cisco infrastructure a customer already operates and whether that customer is willing to centralize operational data and policy enforcement within Cisco’s ecosystem.

Still, the announcement shows how Cisco sees the next phase of infrastructure management: less as a collection of domain-specific consoles and more as a governed system in which people and agents share context, make decisions and act across the enterprise stack.

Editor’s Take

Cisco’s strongest idea here is not the agent—it is the control plane around the agent. Enterprise teams do not need another chatbot that summarizes alerts; they need a way to join topology, configuration, security, application and experience data, then safely move from diagnosis to a tested change. The proposed sense-to-validate loop and explicit approval boundaries are much closer to how consequential operations should work than the industry’s louder promises of fully autonomous infrastructure.

The practical question is whether Cloud Control can correlate data across real mixed estates, not just a polished Cisco reference environment. Cisco’s installed base, Splunk data assets and ThousandEyes visibility give it a credible starting advantage, but integrations, data-access rules, metering and pricing will determine whether customers treat it as a daily operating layer or another premium console. I would watch for evidence that the digital-twin testing catches bad changes, that recommendations are explainable, and that operators can reliably roll back actions.

Controlled availability is the right posture. The hype outruns the facts whenever vendors imply that agents can safely own broad production changes today. Near-term value will come from supervised automation: agents gathering evidence, narrowing root causes, drafting changes and validating outcomes while experienced people retain authority. If Cisco can make that workflow materially faster without weakening governance, it has a meaningful platform opportunity.

References

  1. Cisco Newsroom – https://newsroom.cisco.com/c/r/newsroom/en/us/a/y2026/m06/cisco-unveils-agentic-platform-for-operating-and-defending-critical-it-infrastructure.html
  2. TechTarget – https://www.techtarget.com/searchitoperations/news/366643670/Cisco-Cloud-Control-unites-AgenticOps-for-IT-infrastructure
  3. CRN – https://www.crn.com/news/ai/2026/cisco-unveils-cloud-control-ai-canvas-quantum-security-push-at-cisco-live
  4. InformationWeek – https://www.informationweek.com/cybersecurity/cisco-s-jeetu-patel-cisco-cloud-control-
  5. Cisco Blog – https://blogs.cisco.com/networking/from-signal-to-action-the-next-step-in-cisco-agenticops

Leave a Reply

Your email address will not be published. Required fields are marked *