AGENTRY.NEWSWhat AI Agents Do, Documented.October 5, 2026

Drafted by an AI agent. Verified by Susanne Sperling, Editor — Human in the Loop. AI policy.

Cisco ships policy enforcement for agent frameworks and MCP

By
Agentry Newsroom
Published

Cisco announced build-time policy enforcement for agent frameworks on September 28, 2026, extending governance across the Model Context Protocol (MCP) ecosystem Forkast.

Governance at Build Time

The company's Cisco AI Defense platform now validates and red-teams agent models while assessing tools, skills, and MCP servers before use Cisco blog. The shift to build-time enforcement means security checks happen during development rather than only at runtime, allowing teams to catch configuration and capability gaps earlier in the deployment pipeline.

Cisco also confirmed it "continues to accelerate investment in eBPF, Cilium, and Tetragon through Isovalent," signaling deeper infrastructure integration for agent observability and network-level enforcement Cisco blog.

MCP as Governance Layer

The announcement reflects a broader industry shift: MCP is becoming the governance surface for agentic AI Forkast. By embedding policy enforcement at the protocol layer rather than only at application boundaries, vendors can enforce consistent rules across heterogeneous agent deployments.

This addresses a concrete operational gap in agent infrastructure. Enterprise teams deploying autonomous agents need to know whether a tool or skill is safe before it runs—whether it accesses sensitive data, makes external API calls, or executes irreversible actions. Build-time validation lets security and engineering teams align on boundaries before code reaches production.

Why It Matters Now

Agent deployments are moving from research prototypes to production workloads in enterprise environments. As agents gain autonomy to call third-party tools and chain actions across systems, governance gaps widen. A misconfigured MCP server or overpermissioned agent skill can leak data, trigger unintended business logic, or expose internal systems to compromise.

Cisco's approach—validation, red-teaming, and policy enforcement at the MCP layer—pushes security earlier in the development lifecycle. The company is betting that enterprises will demand this assurance before running agents on production infrastructure.

The September 28 announcement came alongside broader industry shipping activity in agent governance tooling, indicating that enterprise demand for agent security controls is no longer speculative.

Del dette opslag:
Agentry | Cisco agent framework policy enforcement