{"id":17211,"date":"2026-07-19T16:15:40","date_gmt":"2026-07-19T16:15:40","guid":{"rendered":"https:\/\/dmsretail.com\/RetailNews\/cisco-ai-defense-built-for-the-way-ai-is-actually-used\/"},"modified":"2026-07-19T16:15:40","modified_gmt":"2026-07-19T16:15:40","slug":"cisco-ai-defense-built-for-the-way-ai-is-actually-used","status":"publish","type":"post","link":"https:\/\/dmsretail.com\/RetailNews\/cisco-ai-defense-built-for-the-way-ai-is-actually-used\/","title":{"rendered":"Cisco AI Defense: Built for the Way AI Is Actually Used"},"content":{"rendered":"<p> <p><a href=\"https:\/\/dmsretail.com\/online-workshops-list\/\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-496\" src=\"https:\/\/dmsretail.com\/RetailNews\/wp-content\/uploads\/2022\/05\/RETAIL-ONLINE-TRAINING-728-X-90.png\" alt=\"Retail Online Training\" width=\"729\" height=\"91\" srcset=\"https:\/\/dmsretail.com\/RetailNews\/wp-content\/uploads\/2022\/05\/RETAIL-ONLINE-TRAINING-728-X-90.png 729w, https:\/\/dmsretail.com\/RetailNews\/wp-content\/uploads\/2022\/05\/RETAIL-ONLINE-TRAINING-728-X-90-300x37.png 300w\" sizes=\"auto, (max-width: 729px) 100vw, 729px\" \/><\/a><\/p><br \/>\n<\/p>\n<div>\n<p><span class=\"TextRun SCXW206957216 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"none\"><span class=\"NormalTextRun SCXW206957216 BCX0\" data-ccp-parastyle=\"Normal (Web)\">Enterprise AI\u00a0<\/span><span class=\"NormalTextRun SCXW206957216 BCX0\" data-ccp-parastyle=\"Normal (Web)\">operates<\/span><span class=\"NormalTextRun SCXW206957216 BCX0\" data-ccp-parastyle=\"Normal (Web)\">\u00a0in conversations \u2014 multilingual, multi-turn, and context-dependent. A guardrail that performs only on English single-turn prompts cannot protect what enterprises are\u00a0<\/span><span class=\"NormalTextRun AdvancedProofingIssueV2Themed SCXW206957216 BCX0\" data-ccp-parastyle=\"Normal (Web)\">actually building<\/span><span class=\"NormalTextRun SCXW206957216 BCX0\" data-ccp-parastyle=\"Normal (Web)\">. In a recent\u202f<\/span><\/span><span class=\"TextRun SCXW206957216 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"none\"><span class=\"NormalTextRun SCXW206957216 BCX0\" data-ccp-charstyle=\"Hyperlink\">independent benchmark by ML6<\/span><\/span><span class=\"TextRun SCXW206957216 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"none\"><span class=\"NormalTextRun SCXW206957216 BCX0\" data-ccp-parastyle=\"Normal (Web)\">\u202fon 80,000 Dutch-language prompts, Cisco AI Defense led the cohort\u00a0<\/span><span class=\"NormalTextRun SCXW206957216 BCX0\" data-ccp-parastyle=\"Normal (Web)\">of providers<\/span><span class=\"NormalTextRun SCXW206957216 BCX0\" data-ccp-parastyle=\"Normal (Web)\">\u00a0<\/span><span class=\"NormalTextRun SCXW206957216 BCX0\" data-ccp-parastyle=\"Normal (Web)\">with the highest F1 score<\/span><\/span><span class=\"TextRun SCXW206957216 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"none\"><span class=\"NormalTextRun SCXW206957216 BCX0\" data-ccp-parastyle=\"Normal (Web)\">.\u00a0<\/span><\/span><span class=\"EOP Selected TrackedChange SCXW206957216 BCX0\" data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;201341983&quot;:0,&quot;335557856&quot;:16777215,&quot;335559738&quot;:0,&quot;335559739&quot;:270,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p>\n<h2><span style=\"color: #ff0000;\">01<\/span> A Note on Semantics<\/h2>\n<p><span data-contrast=\"none\">AI safety labels only work when everyone agrees on what they mean.\u00a0<\/span>Language is inherently semantically diffuse; intent, context, and linguistic nuance shape interpretation, and, consequently, the true label.<\/p>\n<p><span data-contrast=\"none\">Cisco addresses this through\u202f<\/span><b><span data-contrast=\"none\">constitutional definitions<\/span><\/b><span data-contrast=\"none\">: precise, per-technique operational specifications that serve as the\u00a0single source\u00a0of truth for classification, model training, and customer-facing explanations. This approach\u202f<\/span><span data-contrast=\"none\">reduces inter-model disagreement by up to 57\u00d7<\/span><span data-contrast=\"none\">\u202fcompared to paragraph-level definitions. Because the spec is machine-enforced, it applies with equal precision in French, Japanese, or Arabic.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;201341983&quot;:0,&quot;335557856&quot;:16777215,&quot;335559738&quot;:0,&quot;335559739&quot;:270,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"none\">The taxonomy distinguishes\u202f<\/span><i><span data-contrast=\"none\">intent<\/span><\/i><span data-contrast=\"none\">\u202ffrom\u202f<\/span><i><span data-contrast=\"none\">content<\/span><\/i><span data-contrast=\"none\">: a conversation can carry harmful intent without harmful output (a probed-and-refused attack), or harmful content without adversarial intent (model misbehavior on a benign request). That distinction is essential in production, where the same surface language can mean\u00a0very different\u00a0things depending on conversational context.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;201341983&quot;:0,&quot;335557856&quot;:16777215,&quot;335559738&quot;:0,&quot;335559739&quot;:270,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p>\n<h2><span style=\"color: #ff0000;\">02<\/span> Security Has Moved Into the Conversation<\/h2>\n<p><span data-contrast=\"none\">In AI systems, ordinary language is the control plane. A malicious instruction can look identical to a\u00a0user\u00a0request; a benign phrase can look suspicious out of context. Attacks rarely arrive in a single prompt \u2014 real adversaries\u00a0iterate, reframe refusals, and escalate gradually across turns.\u202f<\/span><span data-contrast=\"none\">Cisco research across 15 frontier models<\/span><span data-contrast=\"none\">\u202ffound that every model tested\u00a0shows\u00a0meaningful multi-turn vulnerability, with attack success rates that bear no consistent relationship to single-turn benchmarks.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;201341983&quot;:0,&quot;335557856&quot;:16777215,&quot;335559738&quot;:0,&quot;335559739&quot;:270,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"none\">This means the security perimeter must move outside the model. Cisco AI Defense\u00a0validates\u00a0inputs and outputs in production, classifying the\u202f<\/span><i><span data-contrast=\"none\">intent and active direction<\/span><\/i><span data-contrast=\"none\">\u202fof each conversation \u2014 not just the surface content of each message. Guardrails are tailored to the specific vulnerabilities of each model and\u00a0application, and\u00a0applied at the point where AI behavior is actually shaped: the live exchange between user, model, data, and tools.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;201341983&quot;:0,&quot;335557856&quot;:16777215,&quot;335559738&quot;:0,&quot;335559739&quot;:270,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p>\n<h2><span style=\"color: #ff0000;\">03<\/span> The Multilingual Reality Check<\/h2>\n<p><span class=\"TextRun SCXW105157925 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"none\"><span class=\"NormalTextRun SCXW105157925 BCX0\" data-ccp-parastyle=\"Normal (Web)\">The ML6 benchmark put multilingual performance into sharp relief. Testing on 80,000 Dutch-language prompts \u2014 including prompt injection, policy bypass, ambiguous instructions, and realistic enterprise interactions \u2014 Cisco AI Defense achieved the highest F1 score in the cohort:\u202f<\/span><\/span><span class=\"TextRun MacChromeBold SCXW105157925 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"none\"><span class=\"NormalTextRun SCXW105157925 BCX0\" data-ccp-charstyle=\"Strong\">0.845<\/span><\/span><span class=\"TextRun SCXW105157925 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"none\"><span class=\"NormalTextRun SCXW105157925 BCX0\" data-ccp-parastyle=\"Normal (Web)\">.<\/span><\/span><span class=\"EOP Selected SCXW105157925 BCX0\" data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;201341983&quot;:0,&quot;335557856&quot;:16777215,&quot;335559738&quot;:0,&quot;335559739&quot;:270,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p>\n<p><img fetchpriority=\"high\" decoding=\"async\" class=\"lazy lazy-hidden aligncenter wp-image-494912\" data-lazy-type=\"image\" src=\"https:\/\/blogs.cisco.com\/gcs\/ciscoblogs\/1\/2026\/07\/ml6_f1_stat.png\" alt=\"\" width=\"738\" height=\"164\"\/><noscript><img fetchpriority=\"high\" decoding=\"async\" class=\"aligncenter wp-image-494912\" src=\"https:\/\/blogs.cisco.com\/gcs\/ciscoblogs\/1\/2026\/07\/ml6_f1_stat.png\" alt=\"\" width=\"738\" height=\"164\"\/><\/noscript><\/p>\n<p><span class=\"TextRun SCXW126920243 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"none\"><span class=\"NormalTextRun SCXW126920243 BCX0\" data-ccp-parastyle=\"Normal (Web)\">To\u00a0<\/span><span class=\"NormalTextRun SCXW126920243 BCX0\" data-ccp-parastyle=\"Normal (Web)\">highlight<\/span><span class=\"NormalTextRun SCXW126920243 BCX0\" data-ccp-parastyle=\"Normal (Web)\">\u00a0Cisco\u2019s\u00a0<\/span><span class=\"NormalTextRun SCXW126920243 BCX0\" data-ccp-parastyle=\"Normal (Web)\">multilingual\u00a0<\/span><span class=\"NormalTextRun SCXW126920243 BCX0\" data-ccp-parastyle=\"Normal (Web)\">capabilities \u2013<\/span><span class=\"NormalTextRun SCXW126920243 BCX0\" data-ccp-parastyle=\"Normal (Web)\"> in this post we sample and share results on\u00a0<\/span><\/span>an augmented version of <span class=\"TextRun SCXW126920243 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"none\"><span class=\"NormalTextRun SCXW126920243 BCX0\" data-ccp-parastyle=\"Normal (Web)\">LMSYS Chat-1M and\u00a0<\/span><span class=\"NormalTextRun SpellingErrorV2Themed SCXW126920243 BCX0\" data-ccp-parastyle=\"Normal (Web)\">WildChat<\/span><span class=\"NormalTextRun SCXW126920243 BCX0\" data-ccp-parastyle=\"Normal (Web)\">\u00a0\u2014 two widely used open-source conversational datasets\u00a0<\/span><span class=\"NormalTextRun SCXW126920243 BCX0\" data-ccp-parastyle=\"Normal (Web)\">representing<\/span><span class=\"NormalTextRun SCXW126920243 BCX0\" data-ccp-parastyle=\"Normal (Web)\">\u00a0realistic enterprise chat traffic<\/span><span class=\"NormalTextRun SCXW126920243 BCX0\" data-ccp-parastyle=\"Normal (Web)\">. The data was\u00a0<\/span><span class=\"NormalTextRun SCXW126920243 BCX0\" data-ccp-parastyle=\"Normal (Web)\">augmented\u00a0<\/span><span class=\"NormalTextRun SCXW126920243 BCX0\" data-ccp-parastyle=\"Normal (Web)\">with conversations from e<\/span><span class=\"NormalTextRun SCXW126920243 BCX0\" data-ccp-parastyle=\"Normal (Web)\">ight\u00a0<\/span><span class=\"NormalTextRun SCXW126920243 BCX0\" data-ccp-parastyle=\"Normal (Web)\">additional<\/span><span class=\"NormalTextRun SCXW126920243 BCX0\" data-ccp-parastyle=\"Normal (Web)\">\u00a0<\/span><span class=\"NormalTextRun SCXW126920243 BCX0\" data-ccp-parastyle=\"Normal (Web)\">languages<\/span><span class=\"NormalTextRun SCXW126920243 BCX0\" data-ccp-parastyle=\"Normal (Web)\">\u00a0with a similar distribution as LMSYS and\u00a0<\/span><span class=\"NormalTextRun SpellingErrorV2Themed SCXW126920243 BCX0\" data-ccp-parastyle=\"Normal (Web)\">WildChat<\/span><span class=\"NormalTextRun SCXW126920243 BCX0\" data-ccp-parastyle=\"Normal (Web)\">.\u00a0<\/span><span class=\"NormalTextRun SCXW126920243 BCX0\" data-ccp-parastyle=\"Normal (Web)\">The ground truth labels for this dataset were generated\u00a0<\/span><span class=\"NormalTextRun SCXW126920243 BCX0\" data-ccp-parastyle=\"Normal (Web)\">using Cisco<\/span><span class=\"NormalTextRun SCXW126920243 BCX0\" data-ccp-parastyle=\"Normal (Web)\">\u00a0AI\u2019s<\/span><span class=\"NormalTextRun SCXW126920243 BCX0\" data-ccp-parastyle=\"Normal (Web)\">\u00a0security and safety taxonomy. The ML6 benchmark used a separate Dutch-specific dataset assembled independently; the two evaluations are complementary, not directly comparable.<\/span><\/span><span class=\"EOP SCXW126920243 BCX0\" data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;201341983&quot;:0,&quot;335557856&quot;:16777215,&quot;335559738&quot;:0,&quot;335559739&quot;:270,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"lazy lazy-hidden aligncenter wp-image-494913\" data-lazy-type=\"image\" src=\"https:\/\/blogs.cisco.com\/gcs\/ciscoblogs\/1\/2026\/07\/Screenshot-2026-07-16-at-11.02.39\u202fAM.png\" alt=\"\" width=\"856\" height=\"445\"\/><noscript><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-494913\" src=\"https:\/\/blogs.cisco.com\/gcs\/ciscoblogs\/1\/2026\/07\/Screenshot-2026-07-16-at-11.02.39\u202fAM.png\" alt=\"\" width=\"856\" height=\"445\"\/><\/noscript><\/p>\n<p class=\"p1\">Cisco AI Defense was evaluated on a multilingual, augmented conversational dataset derived primarily from the LMSYS Chat-1M and WildChat corpora. The evaluation set consists predominantly of benign, general-purpose conversations, along with an adversarial subset representing approximately 14% of the labeled examples. The dataset had approximately 5,800-5,900 conversations per language. FPR is measured on this specific adversarial evaluation mix; on a real-world distribution it would be much lower. Results are presented with English first, Dutch second, followed by the remaining languages ordered by F1 score.<\/p>\n<p><span class=\"TextRun SCXW153660152 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"none\"><span class=\"NormalTextRun SCXW153660152 BCX0\" data-ccp-parastyle=\"Normal (Web)\">F1 ranges from 0.796 (Arabic) to 0.860 (Portuguese) \u2014 a tight spread across nine typologically diverse languages, from Latin-script European languages to Arabic and Japanese. That consistency reflects the constitutional taxonomy at work: when a definition is precise and machine-enforced, the signal transfers across languages reliably. The same operational specification governs whether a prompt injection is written in French, Japanese, or Arabic.<\/span><\/span><span class=\"EOP Selected SCXW153660152 BCX0\" data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;201341983&quot;:0,&quot;335557856&quot;:16777215,&quot;335559738&quot;:0,&quot;335559739&quot;:270,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p>\n<p style=\"text-align: left;\"><img loading=\"lazy\" decoding=\"async\" class=\"lazy lazy-hidden aligncenter wp-image-494914\" data-lazy-type=\"image\" src=\"https:\/\/blogs.cisco.com\/gcs\/ciscoblogs\/1\/2026\/07\/roc_aidefense_sidebyside.png\" alt=\"\" width=\"890\" height=\"386\"\/><noscript><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-494914\" src=\"https:\/\/blogs.cisco.com\/gcs\/ciscoblogs\/1\/2026\/07\/roc_aidefense_sidebyside.png\" alt=\"\" width=\"890\" height=\"386\"\/><\/noscript><span class=\"TextRun SCXW139147005 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"none\"><span class=\"NormalTextRun SCXW139147005 BCX0\" data-ccp-parastyle=\"roc-note\" data-ccp-parastyle-defn=\"{&quot;ObjectId&quot;:&quot;d60cbee9-9776-5b93-a7af-2ca05b166c73|1&quot;,&quot;ClassId&quot;:1073872969,&quot;Properties&quot;:[469777841,&quot;Times New Roman&quot;,469777842,&quot;Times New Roman&quot;,469777843,&quot;Times New Roman&quot;,469777844,&quot;Times New Roman&quot;,469769226,&quot;Times New Roman&quot;,335559705,&quot;1033&quot;,335559740,&quot;240&quot;,201341983,&quot;0&quot;,335559739,&quot;0&quot;,201342446,&quot;1&quot;,201342447,&quot;5&quot;,201342448,&quot;3&quot;,201342449,&quot;1&quot;,201341986,&quot;1&quot;,268442635,&quot;24&quot;,469775450,&quot;roc-note&quot;,201340122,&quot;2&quot;,134233614,&quot;true&quot;,469778129,&quot;roc-note&quot;,335572020,&quot;1&quot;,134233118,&quot;true&quot;,134233117,&quot;true&quot;,469778324,&quot;Normal&quot;]}\">Each curve is the achievable recall-vs-FPR frontier for Cisco AI Defense per language, across all threshold combinations. Higher and further left <\/span><span class=\"NormalTextRun ContextualSpellingAndGrammarErrorV2Themed SCXW139147005 BCX0\" data-ccp-parastyle=\"roc-note\">is<\/span><span class=\"NormalTextRun SCXW139147005 BCX0\" data-ccp-parastyle=\"roc-note\">\u00a0stronger. Legend shows AUC per language.<\/span><\/span><span class=\"EOP Selected SCXW139147005 BCX0\" data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;201341983&quot;:0,&quot;335557856&quot;:16777215,&quot;335559738&quot;:180,&quot;335559739&quot;:270,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p>\n<h2><span style=\"color: #ff0000;\">04<\/span> Protection Without Friction<\/h2>\n<p><span class=\"TextRun SCXW152874596 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"none\"><span class=\"NormalTextRun SCXW152874596 BCX0\" data-ccp-parastyle=\"Normal (Web)\">A guardrail with\u00a0<\/span><span class=\"NormalTextRun SCXW152874596 BCX0\" data-ccp-parastyle=\"Normal (Web)\">high\u00a0<\/span><span class=\"NormalTextRun ContextualSpellingAndGrammarErrorV2Themed SCXW152874596 BCX0\" data-ccp-parastyle=\"Normal (Web)\">recall<\/span><span class=\"NormalTextRun SCXW152874596 BCX0\" data-ccp-parastyle=\"Normal (Web)\">\u00a0but\u00a0<\/span><span class=\"NormalTextRun SCXW152874596 BCX0\" data-ccp-parastyle=\"Normal (Web)\">poor precision is not a security product \u2014 it is an availability problem. In the ML6 benchmark,\u00a0<\/span><span class=\"NormalTextRun SCXW152874596 BCX0\" data-ccp-parastyle=\"Normal (Web)\">anot<\/span><span class=\"NormalTextRun SCXW152874596 BCX0\" data-ccp-parastyle=\"Normal (Web)\">her guardrail solution<\/span><span class=\"NormalTextRun SCXW152874596 BCX0\" data-ccp-parastyle=\"Normal (Web)\">\u00a0under test<\/span><span class=\"NormalTextRun SCXW152874596 BCX0\" data-ccp-parastyle=\"Normal (Web)\">\u00a0<\/span><span class=\"NormalTextRun SCXW152874596 BCX0\" data-ccp-parastyle=\"Normal (Web)\">reached 0.327 recall but only 0.453 F1, as false alarms collapsed precision to 0.737. Cisco achieved 0.843 recall and 0.847 precision simultaneously \u2014 the highest F1 in the cohort. That balance requires a threat model precise enough to distinguish an adversarial instruction from a legitimate but emphatic user request.<\/span><\/span><span class=\"EOP Selected SCXW152874596 BCX0\" data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;201341983&quot;:0,&quot;335557856&quot;:16777215,&quot;335559738&quot;:0,&quot;335559739&quot;:270,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p>\n<p style=\"text-align: left;\"><img loading=\"lazy\" decoding=\"async\" class=\"lazy lazy-hidden aligncenter wp-image-494915\" data-lazy-type=\"image\" src=\"https:\/\/blogs.cisco.com\/gcs\/ciscoblogs\/1\/2026\/07\/cisco_aidefense_idealzone.png\" alt=\"\" width=\"843\" height=\"668\"\/><noscript><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-494915\" src=\"https:\/\/blogs.cisco.com\/gcs\/ciscoblogs\/1\/2026\/07\/cisco_aidefense_idealzone.png\" alt=\"\" width=\"843\" height=\"668\"\/><\/noscript><span class=\"textrun\">Each marker is one language, positioned by its recall and false-positive rate. F1 scores shown in the legend. The shaded region marks the ideal operating zone \u2014 high recall with low false positives.<\/span><span class=\"eop\">\u00a0<\/span><\/p>\n<p>The FPR figures in the table \u2014 2.3\u20135.8% across languages \u2014 are measured on an evaluation mix that is roughly 14% adversarial. On a predominantly benign production population, the effective FPR would be much lower. More meaningful than the absolute values is their cross-language stability: the narrow range across nine languages indicates the constitutional taxonomy produces consistent signal rather than silently trading precision for recall as users switch languages. Operating thresholds are configurable without retraining, allowing organizations to tune the precision-recall tradeoff to their specific risk profile.<\/p>\n<h2><span style=\"color: #ff0000;\">05<\/span> Real-Time Protection<\/h2>\n<p>A guardrail that cannot keep pace with production traffic will not stay in the critical path. Enterprise AI applications have response-time SLAs; users notice latency; and in agentic pipelines, per-hop overhead compounds. Security that adds seconds per request gets disabled or bypassed.<\/p>\n<p>Cisco AI Defense is built to sit in the live interaction without becoming the bottleneck. At p90 = 40 ms and p99 = 250 ms per request, the security check adds overhead that is imperceptible to end users and compatible with real-time conversational SLAs across chatbots, copilots, and agentic pipelines.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"lazy lazy-hidden aligncenter wp-image-494916\" data-lazy-type=\"image\" src=\"https:\/\/blogs.cisco.com\/gcs\/ciscoblogs\/1\/2026\/07\/viz_latency.png\" alt=\"\" width=\"944\" height=\"424\"\/><noscript><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-494916\" src=\"https:\/\/blogs.cisco.com\/gcs\/ciscoblogs\/1\/2026\/07\/viz_latency.png\" alt=\"\" width=\"944\" height=\"424\"\/><\/noscript><\/p>\n<p style=\"background: white; margin: 0in 0in 13.5pt 0in;\">Runtime protection is not a point-in-time test. AI applications evolve continuously: models are updated, RAG sources shift, agents acquire new tools, and attack techniques adapt. Pre-deployment evaluation establishes a baseline; runtime guardrails maintain it under live production conditions, for every user, in every language, across every model and application the enterprise runs \u2014 regardless of vendor or deployment framework.<\/p>\n<h2>What Enterprises Should Take Away<\/h2>\n<p>Enterprise AI is multilingual and multi-turn by design. Security must match that reality. Cisco AI Defense addresses this from first principles:<\/p>\n<ul>\n<li>A constitutional taxonomy that produces consistent, explainable signal across languages and attack types.<\/li>\n<li>Conversational-native detection that classifies the intent and active direction of an exchange, not just its surface content.<\/li>\n<li>Multilingual by design \u2014 consistent detection across languages and scripts, because the taxonomy that drives the guardrail is language-agnostic.<\/li>\n<li>A precision-recall balance that protects the enterprise without punishing legitimate users.<\/li>\n<li>Runtime performance designed for production \u2014 p90 latency of 40 ms per request, compatible with real-time conversational SLAs.<\/li>\n<\/ul>\n<p>For organizations scaling AI, the goal is not simply to block more. It is to preserve trust \u2014 protecting users, data, models, and business processes while keeping the conversation open for everyone who deserves to have it.<\/p>\n<p><strong>Related reading:<\/strong>\u00a0Improving Labeling Consistency with Detailed Constitutional Definitions and AI-Driven Evaluation\u00a0\u00a0\u00b7\u00a0\u00a0Proprietary Problems: No Frontier Model Is Multi-Turn Immune\u00a0\u00a0\u00b7\u00a0\u00a0ML6 Enterprise Guardrail Benchmark<\/p>\n<\/p><\/div>\n<p><p><a href=\"https:\/\/dmsretail.com\/online-workshops-list\/\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-496\" src=\"https:\/\/dmsretail.com\/RetailNews\/wp-content\/uploads\/2022\/05\/RETAIL-ONLINE-TRAINING-728-X-90.png\" alt=\"Retail Online Training\" width=\"729\" height=\"91\" srcset=\"https:\/\/dmsretail.com\/RetailNews\/wp-content\/uploads\/2022\/05\/RETAIL-ONLINE-TRAINING-728-X-90.png 729w, https:\/\/dmsretail.com\/RetailNews\/wp-content\/uploads\/2022\/05\/RETAIL-ONLINE-TRAINING-728-X-90-300x37.png 300w\" sizes=\"auto, (max-width: 729px) 100vw, 729px\" \/><\/a><\/p><br \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Enterprise AI\u00a0operates\u00a0in conversations \u2014 multilingual, multi-turn, and context-dependent. A guardrail that performs only on English single-turn prompts cannot protect what enterprises are\u00a0actually building. In a [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":17212,"comment_status":"","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5],"tags":[],"class_list":["post-17211","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technology"],"_links":{"self":[{"href":"https:\/\/dmsretail.com\/RetailNews\/wp-json\/wp\/v2\/posts\/17211","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dmsretail.com\/RetailNews\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dmsretail.com\/RetailNews\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dmsretail.com\/RetailNews\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/dmsretail.com\/RetailNews\/wp-json\/wp\/v2\/comments?post=17211"}],"version-history":[{"count":0,"href":"https:\/\/dmsretail.com\/RetailNews\/wp-json\/wp\/v2\/posts\/17211\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/dmsretail.com\/RetailNews\/wp-json\/wp\/v2\/media\/17212"}],"wp:attachment":[{"href":"https:\/\/dmsretail.com\/RetailNews\/wp-json\/wp\/v2\/media?parent=17211"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dmsretail.com\/RetailNews\/wp-json\/wp\/v2\/categories?post=17211"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dmsretail.com\/RetailNews\/wp-json\/wp\/v2\/tags?post=17211"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}