Cisco has introduced new updates to Splunk AI to help enterprise customers deploy, secure, and monitor artificial intelligence workloads directly within their private infrastructure. Announced in Riyadh, the release expands on-premises options for organizations that handle regulated data and cannot transfer sensitive information to public cloud environments.

The announcement includes an extended collaboration with NVIDIA to deliver self-managed capabilities for enterprise customers. Organizations can now run models locally across private cloud and air-gapped systems using pre-validated hardware architectures.

On-Premises Deployments with Splunk AI

The newly released Cisco AI POD delivers Splunk AI to organizations requiring local control over their infrastructure. This configuration combines runtime software, Kubernetes architecture, and NVIDIA accelerated computing to handle demanding workloads.

Enterprises can self-host proprietary and open models such as Google Gemma 4, OpenAI GPT-OSS 20B, and the Cisco Deep Time Series Model. In addition, support for NVIDIA Nemotron models will arrive in the coming months, allowing teams to keep sensitive data within their own network perimeter.

“One of the biggest roadblocks to enterprise AI today is that it’s too hard to deploy. Customers want to know: Can I trust it to do the job? Can I afford it? And, most importantly, can I secure it?”

Jeetu Patel, President and Chief Product Officer at Cisco

Monitoring Agent Behavior and Token Costs

Cisco also introduced Splunk Agent Observability to give technical teams centralized visibility into agent actions across their technology stack. The software monitors model performance and applies runtime guardrails to prevent unsafe behavior or data leaks.

Furthermore, a dedicated Tokenomics feature tracks spending across AI agents and coding tools like Claude Code, Cursor, and Codex. The system uses time-series forecasting to project expenses before billing cycles conclude, helping managers control infrastructure budgets.

Automating Security Operations Center Defenses

To combat automated digital threats, Cisco is updating its cybersecurity defenses with agentic SOC workflows. These software agents analyze full-stack telemetry from cloud, identity, and network systems to investigate incidents autonomously.

Security teams can also use Exposure Analytics to identify vulnerabilities across their entire digital footprint. Consequently, these tools accelerate remediation times by filtering out background noise and highlighting active security risks.

Expanding Cloud Integrations with AWS

Alongside on-premises options, Cisco and AWS signed a multi-year agreement for joint engineering initiatives. The collaboration connects Splunk telemetry with AWS cloud scale to support automated threat detection and response.

System implementation partners including Accenture, bitsIO, Wipro, and World Wide Technology are currently deploying the on-premises architecture for enterprise clients globally.