Cisco has launched new advancements to its Splunk AI platform aimed at helping enterprises securely adopt, observe, and scale AI alongside their machine data wherever it resides.

These developments follow an extended collaboration with Nvidia, enabling on-premises Splunk AI deployment via the newly introduced Cisco AI POD for Splunk.

Through the Cisco AI POD for Splunk, enterprise customers can now deploy Splunk AI features directly in their own data centres, private clouds, or air-gapped environments.

The solution combines Cisco infrastructure, Nvidia accelerated computing, a new AI runtime, and Kubernetes-based architecture, all pre-validated for Splunk AI workloads.

The AI POD for Splunk is available immediately, with day-one support from partner firms including Accenture, bitsIO, Wipro and World Wide Technology for customers with existing infrastructure.

Cisco president and chief product officer Jeetu Patel said: “One of the biggest roadblocks to enterprise AI today is that it’s too hard to deploy. Customers want to know: Can I trust it to do the job? Can I afford it?

“And, most importantly, can I secure it? By running Splunk AI on the infrastructure customers already trust, they can move faster to put AI to work in their business with confidence and control.”

Customers can self-host a broad selection of open and proprietary generative AI models within their Splunk Enterprise environments.

Supported models include the Cisco Deep Time Series Model, Google Gemma 4, and OpenAI GPT-OSS 20B, with Nvidia Nemotron open models expected soon. This enables organisations to deploy AI agents and models best suited to their needs while maintaining full control and data sovereignty.

The Splunk AI Assistant, already available, along with the upcoming Agent Launchpad, are designed to enable ad-hoc agentic investigations and development of custom AI agents for diverse use cases, including security operations centres.

To improve oversight of AI agent behaviour and expenditure, Cisco has enhanced Splunk Agent Observability with new Tokenomics features. This provides real-time visibility into AI agent performance and tracks token spending by agents and coding tools.

The Tokenomics capability, now available across Splunk Observability Cloud, Cisco Cloud Control, and on-premises deployments, offers forecasting of future consumption and ties AI costs directly to business value.

Cisco says runtime guardrails are also implemented to automatically block inaccurate or unsafe AI actions, such as hallucinations or accidental data leakage.

Additional observability improvements include the Observability Studio, which allows development teams to ensure new applications are “born observable”, measurable and production-ready from launch.

The new Network Intelligence App integrates Cisco network topology, device health and event data into Splunk, providing contextual alerts and real-time network tracing capabilities. Cisco has also rolled out new Essentials and Premier editions for Observability Cloud, intended to streamline purchasing and support wider, cost-effective adoption.

On the security front, Cisco is advancing agentic operations by expanding the Splunk Agentic SOC Workforce. This workforce uses enterprise-wide telemetry and specialised AI agents to mirror elite security team functions, including detection engineering, proactive threat hunting, investigation, response and policy governance.

By correlating data across network, cloud, application and identity environments, these agents deliver deep reasoning and explainable verdicts to cut alert noise and accelerate response times.

To further strengthen this ecosystem, Exposure Analytics has been enhanced to offer broader asset coverage, historical change tracking, and business-specific risk insights, connecting live exposure data across Splunk, Cisco, and third-party ecosystems. These updates aim to equip security operations centres with the autonomy and context needed to respond to AI-driven attacks quickly.

In parallel, Cisco’s Splunk division has formed a multi-year agreement with Amazon Web Services (AWS) to jointly develop new security solutions intended to mitigate the rapidly evolving threat landscape posed by AI-enabled attacks.

The partnership will concentrate on delivering agentic support for detection, investigation and response, maintaining analyst oversight and governance. Splunk, which is engaged in cybersecurity and observability, was acquired by Cisco for approximately $28bn, in an all-cash deal that closed in 2024.