Cisco AI Defense License provides organizations with purpose-built security for AI models, applications, agents, and the infrastructure used to develop and operate them. Unlike conventional security controls that primarily protect networks, endpoints, and applications, Cisco AI Defense is designed to identify risks specific to generative AI, including prompt injection, sensitive-data leakage, unsafe model behavior, malicious model files, AI supply-chain threats, and agentic AI attacks.
Cisco AI Defense Benefits
- Discovery of AI models, applications, and agents
- AI application and model security testing
- Automated AI red teaming
- Prompt injection protection
- Sensitive-data leakage prevention
- AI runtime security guardrails
- AI supply-chain risk analysis
- MCP server and tool security
- Agentic AI threat detection
- AI asset risk scoring
- Integration with cloud and security infrastructure
- Alignment with AI security frameworks

At a Glance
- Product: Cisco AI Defense
- Category: Cisco Security
- Primary Use: Protect AI models, applications, and agents
- License Packages: Validation Essentials, Runtime Essentials, and Advantage
- License Metric: Number of AI applications
- Core Functions: Discover, validate, and protect
- Runtime Security: Prompt and response inspection
- AI Validation: Algorithmic red teaming
- Supply Chain: Model, repository, and MCP scanning
- Agent Security: Agent behavior and tool-use protection
Cisco AI Defense License Overview
Cisco AI Defense licensing is structured according to the AI security capabilities an organization requires and the number of AI applications being protected.
Validation Essentials is intended for organizations that primarily need to discover AI assets and assess AI models or applications before production deployment. It includes AI Cloud Visibility and AI Model and Application Validation.
Runtime Essentials focuses on protecting active AI applications. It includes AI Cloud Visibility and AI Runtime Protection, allowing organizations to inspect prompts and responses and enforce security, privacy, and safety policies while applications are being used.
Cisco AI Defense Advantage provides the broadest coverage. It combines AI Cloud Visibility, AI Model and Application Validation, AI Runtime Protection, and AI Supply Chain Risk Management. This makes Advantage suitable for organizations that need security throughout the AI lifecycle, from identifying and testing assets to protecting production workloads.
Licensing is based on the quantity of AI applications included in the subscription rather than a traditional per-user or per-device model.
Cisco AI Defense Product Overview
Cisco AI Defense creates a dedicated security layer around enterprise AI development and production environments.
AI Cloud Visibility helps security teams identify models, applications, agents, and related AI assets deployed across supported cloud environments. This is particularly important as organizations adopt multiple AI services and development teams introduce new models without always involving security teams.
AI Model and Application Validation evaluates AI systems using automated algorithmic red teaming. Instead of relying only on manual testing, AI Defense can test applications against large numbers of AI-specific threat scenarios and identify weaknesses before deployment.
Once applications move into production, AI Runtime Protection monitors interactions between users, applications, models, agents, and tools. Policies can block unsafe prompts, malicious responses, sensitive-data exposure, and other prohibited AI activity in real time.
Advantage licensing further extends protection into the AI supply chain by examining model files, repositories, MCP servers, and related components for hidden risks before they reach production.
Core Technical Flow
Cisco AI Defense can begin by discovering AI assets across supported cloud environments. Models, applications, agents, and MCP-related components can be identified and presented to security teams for assessment.
Before an AI application is released, AI Defense can perform automated validation. Algorithmic red teaming tests the model or application against AI-specific threats such as prompt injection, jailbreak techniques, privacy violations, unsafe responses, and security weaknesses.
The resulting findings allow security teams to understand the application’s risk profile and develop appropriate guardrails.
During production use, AI Runtime Protection inspects prompts, responses, and supported agent interactions. Security policies evaluate this activity and determine whether requests should be allowed, monitored, or blocked.
For agentic AI environments, runtime controls can also evaluate MCP requests, tool calls, agent behavior, privilege use, and potentially unsafe action chains.
Security events and policy violations remain visible for investigation and can be integrated into broader security operations.
Options & Licensing Models
| Cisco AI Defense Package | Included Capabilities | Typical Use |
|---|---|---|
| Validation Essentials | AI Cloud Visibility and AI Model & Application Validation | Organizations testing AI applications before deployment |
| Runtime Essentials | AI Cloud Visibility and AI Runtime Protection | Protecting AI applications operating in production |
| Advantage | Visibility, Validation, Runtime Protection, and AI Supply Chain Risk Management | End-to-end enterprise AI security |
| AI Runtime Protection | Prompt, response, privacy, security, and safety controls | Production GenAI applications and agents |
| AI Supply Chain Security | Model, repository, and MCP asset scanning | Securing AI development pipelines and third-party components |
The correct package depends on whether the primary requirement is pre-production validation, runtime protection, or complete lifecycle security. Organizations operating business-critical AI applications should also estimate the number of distinct AI applications that require protection because this is a primary licensing metric.
Features & Benefits
AI Discovery, Validation, and Automated Red Teaming
Cisco AI Defense gives security teams visibility into AI models, applications, agents, and related infrastructure while providing automated tools to evaluate security before deployment. Algorithmic red teaming tests AI systems against hundreds of threat categories and subcategories, helping identify prompt-injection weaknesses, privacy exposures, unsafe responses, and other vulnerabilities faster than traditional manual testing. This allows development and security teams to integrate AI risk assessment earlier into development and CI/CD workflows.
Runtime Security, Privacy, and Safety Guardrails
AI Runtime Protection monitors prompts and responses while AI applications are operating and can enforce security, privacy, and safety policies in real time. Organizations can block prompt injection, malicious URLs, denial-of-service techniques, inappropriate content, and sensitive information such as PII, payment-card data, healthcare information, source code, and internal model data. These controls help organizations adopt generative AI while maintaining more consistent governance over what information enters and leaves AI applications.
AI Supply Chain, MCP, and Agentic AI Protection
Cisco AI Defense extends security beyond conventional chat-based LLM applications into AI supply chains and agentic systems. Advantage licensing can scan model files, repositories, and MCP servers for malicious code, unsafe components, or compromised assets before they are introduced into development. Runtime policies can also inspect agent tool calls and MCP communications to detect behaviors such as unauthorized tool use, privilege escalation, memory poisoning, intent hijacking, and harmful action chains.
Compatibility & Requirements
Before ordering a Cisco AI Defense License, organizations should assess:
- Number of AI applications requiring protection
- AI models and model providers in use
- Cloud platforms hosting AI workloads
- AI development and CI/CD architecture
- Production GenAI applications
- AI agents and agentic workflows
- Model Context Protocol usage
- Required pre-production validation
- Runtime prompt and response protection requirements
- Sensitive-data and privacy requirements
- AI supply-chain security requirements
Activation and Deployment
Cisco AI Defense deployment begins by determining which AI applications require visibility, validation, runtime protection, or full lifecycle security.
Administrators provision the AI Defense subscription and connect the required cloud or application environments. AI assets can then be discovered and organized within the management platform.
For applications still in development, validation workflows can be integrated into development or CI/CD processes so models and AI applications are tested before production release.
Runtime protection is deployed at appropriate enforcement points where AI application traffic can be inspected. Cisco supports architectures that allow AI prompts, responses, MCP interactions, and agent workflows to remain within the customer’s cloud or on-premises environment while required management metadata is communicated to Cisco.
Policies are then defined for security, privacy, safety, agent behavior, and tool usage according to organizational requirements.
Cisco AI Defense License Pricing and Quote
Cisco AI Defense License pricing is based primarily on the number of AI applications and the selected subscription package.
Validation Essentials is suited to organizations primarily focused on security testing and model validation, while Runtime Essentials focuses on production protection. Advantage provides the most complete licensing option by combining visibility, validation, runtime enforcement, and supply-chain risk management.
Cisco’s current licensing terms also define usage entitlements associated with AI Runtime and supporting cloud-security infrastructure. Organizations expecting high AI query volumes or large distributed deployments should therefore include expected application utilization when designing the final licensing architecture.
Before requesting a quote, prepare the number of AI applications, required license package, cloud platforms, model providers, production and development environments, agent and MCP usage, runtime traffic requirements, and required security integrations.
Cisco Secure Access pricing depends on your license type, deployment model and support requirements.
