SourceStalecollected in 27m

Securing AI agents with AWS and Cisco AI Defense

Read original on AWS Machine Learning Blog
#ai-security#governance#compliance

Discover how to secure enterprise AI agent deployments with Cisco and AWS.

30-Second TL;DR

What Changed

Addresses security challenges in scaling AI agents

Why It Matters

Provides enterprises with a robust framework to deploy AI agents securely, ensuring that agent-to-agent communication remains compliant and monitored.

What To Do Next

Evaluate your current AI agent governance policy against the Cisco and AWS security framework for A2A deployments.

Who should care:Enterprise & Security Teams

Key Points

  • Addresses security challenges in scaling AI agents
  • Implements automated scanning for unified governance
  • Focuses on securing MCP and A2A (Agent-to-Agent) architectures
  • Mitigates compliance risks for enterprise AI deployments

Deep Insight

Background and context from public sources — not the original article. 19 sources cited.

Enhanced Key Takeaways

  • The joint solution provides end-to-end security across the entire AI application lifecycle, encompassing development, deployment, and runtime phases, with a focus on continuous validation and protection.
  • Cisco AI Defense integrates with core AWS AI services, including Amazon Bedrock and SageMaker, to offer automated vulnerability detection and real-time guardrails against AI-specific threats.
  • The partnership directly addresses emerging AI threats such as prompt injection, data poisoning, model manipulation, adversarial attacks, and the risks associated with 'shadow AI' applications.
  • Cisco has introduced an 'Explorer Edition' of its AI Defense solution, enabling enterprises to perform self-service red teaming and assess the risk posture of AI models and applications before they are deployed into agentic workflows.
  • AWS contributes a comprehensive security fabric for autonomous systems, utilizing services like Amazon Bedrock Guardrails, AWS Step Functions, Amazon Bedrock AgentCore, AWS IAM, and Amazon GuardDuty to build auditable and trustworthy AI agents.

Competitor Analysis

Core Focus
AWS & Cisco AI Defense
End-to-end AI agent security, lifecycle protection, hybrid cloud integration, MCP/A2A.
Palo Alto Networks
AI-driven threat detection, identity security, cloud security, security orchestration.
Microsoft
AI-driven threat detection, identity security, cloud security, security orchestration.
SentinelOne
AI-driven threat detection, identity security, cloud security, security orchestration.
CyberArk
Identity-first approach to securing autonomous AI agents, privilege control, lifecycle management.
Key Capabilities
AWS & Cisco AI Defense
Automated vulnerability testing, runtime guardrails, network-layer visibility, compliance with NIST, OWASP, MITRE ATLAS.
Palo Alto Networks
AI-driven SOC platform (Cortex XSIAM) with SIEM, SOAR, XDR, NDR.
Microsoft
AI-driven threat detection, identity security, cloud security.
SentinelOne
AI-driven threat detection, real-time monitoring, automated response.
CyberArk
AI agent discovery, context enrichment, privilege control, threat detection.
AI Threat Mitigation
AWS & Cisco AI Defense
Prompt injection, data poisoning, model manipulation, adversarial attacks, shadow AI.
Palo Alto Networks
Thousands of analytics models and detections, alert noise reduction.
Microsoft
Capabilities in AI-driven threat detection.
SentinelOne
Real-time monitoring, automated response, protection of agent-driven environments.
CyberArk
Reduces risks from over-permissioned or unmanaged agents.
Deployment Model
AWS & Cisco AI Defense
Integrated with AWS cloud services, Cisco Security Cloud.
Palo Alto Networks
Unified SOC platform.
Microsoft
Cloud-based, integrates with Microsoft ecosystem.
SentinelOne
Cloud-based.
CyberArk
SaaS, cloud, developer environments.
Compliance/Standards
AWS & Cisco AI Defense
Aligns with NIST, MITRE ATLAS, OWASP LLM Top 10.
Palo Alto Networks
Microsoft
SentinelOne
CyberArk
Unique Offerings
AWS & Cisco AI Defense
Cisco AI Defense: Explorer Edition for self-service red teaming; AWS AgentCore Identity for secure agent access.
Palo Alto Networks
Cortex XSIAM consolidates multiple security capabilities.
Microsoft
Strong position in the agentic AI security market.
SentinelOne
Strong position in the agentic AI security market.
CyberArk
Focus on AI agents as a new class of privileged identities.

Technical Deep Dive

  • **Cisco AI Defense Architecture**: Provides a contiguous layer of AI security, privacy, and safety for real-time, organization-wide AI risk management. It combines proprietary machine learning models, real-time threat intelligence, and automated guardrails. The solution integrates into existing development workflows for automated vulnerability testing and implements runtime guardrails for production applications. It leverages network-layer visibility across the Cisco Security Cloud and aligns with AI security standards such as NIST, MITRE ATLAS, and OWASP LLM Top 10.
  • **AWS AgentCore Identity**: A standalone service designed to secure how AI agents access external services across various compute platforms (Amazon ECS, Amazon EKS, AWS Lambda, on-premises). It utilizes OAuth access tokens and a token vault, ensuring that each token is bound to a specific user identity with explicit consent, thereby maintaining an auditable chain from user authentication to agent action. The Authorization Code Grant flow is used for agentic workloads acting on behalf of users, providing user consent, session binding, and scoped delegation.
  • **AWS Security Fabric for Autonomous Systems**: This ecosystem provides primitives for secure autonomy. Key strategies include preprocessing and classifying all context inputs before inference, explicitly encoding reasoning-to-action sequences, limiting the scope of permissions per tool, per agent, and per invocation, correlating LLM and system-level anomalies, verifying every document to prevent silent poisoning, and tracing reasoning and tool activity end-to-end. Services like Amazon Bedrock Guardrails, AWS Step Functions, Amazon Bedrock AgentCore, AWS IAM, and Amazon GuardDuty are leveraged to achieve these controls.
  • **Model Context Protocol (MCP) and Agent-to-Agent (A2A) Security**: MCP is a standardized JSON-RPC 2.0 communication interface that decouples AI models from data sources and tools, allowing any AI model to connect to any MCP-speaking data source. A2A is Google's protocol for inter-agent collaboration. Security concerns in these protocols include information asymmetry (AI models processing hidden content), prompt injection, API key/credential theft, token replay attacks (where a token for one service is reused for another), Distributed Denial of Service (DDoS) risks from unthrottled agent requests, and context poisoning in A2A systems where a misbehaving agent sends malicious instructions to a peer.

Future ImplicationsAI analysis grounded in cited sources

The agentic AI security market will experience substantial growth in the coming years.
The market is projected to grow from USD 1.65 billion in 2026 to USD 13.52 billion by 2032, at a CAGR of 42.0%, driven by the increasing adoption and complexity of multi-agent AI systems across enterprises.
Enterprises will increasingly adopt a 'security-by-design' approach for AI agents, integrating security measures from the initial development stages.
Solutions like Cisco AI Defense and AWS's security fabric emphasize testing and hardening AI agents before deployment and throughout their operational lifecycle, shifting away from security as an afterthought.
The partnership will accelerate the secure adoption of AI in complex hybrid and multi-cloud environments.
Cisco and AWS aim to bridge networking and cloud security, providing unified protection and consistent security policies across diverse hybrid and multi-cloud setups, which is critical for enterprise AI deployments.

Timeline

2024-08
Cisco's Webex AI team leverages AWS SageMaker and Bedrock for generative AI.
2025-09
Cisco and AWS highlight their partnership for secure AI adoption and digital transformation.
2025-12
AWS releases its Agentic AI frontier model, AWS Security Agent, for security reviews and pentesting.
2026-01
AWS publishes prescriptive guidance for securing agentic AI systems on AWS.
2026-03
Cisco introduces AI security solutions, including AI Defense: Explorer Edition and DefenseClaw framework.
2026-05
AWS announces Amazon Bedrock AgentCore Identity to secure AI agent access to external services.

Weekly AI Recap

Read this week's curated digest of top AI events →

AI-curated news aggregator. All content rights belong to original publishers.
Original source: AWS Machine Learning Blog

This is a summary, not the original. Read the source, or get the weekly briefing.

The weekly digest

One email a week. Unsubscribe anytime.