More in
AI at Work News
OpenAI Opened ChatGPT Advertising to Small Businesses at Any Budget
Jun 6, 2026
AI Is Everywhere at Work. Only 1 in 10 Say It Transformed the Job
Jun 6, 2026
Vibe Coding's $10.5B Moment: AI Now Starts Most New Software Builds
Jun 6, 2026
AI Agents Now Have More System Access Than Your Employees. Few Are Secured
Jun 5, 2026
Should You Build Your AI or Buy It? Watch What the Giants Bought.
Jun 5, 2026
Uber Caps Employee AI Spending at $1,500 Per Seat After a Budget Blowout
Jun 5, 2026
Trump's AI Executive Order Is Deregulatory. Your Compliance Risk Didn't Move
Jun 4, 2026
AI Pushed 220 Unicorns Below $1B. Pre-ChatGPT Companies Face a Reckoning
Jun 4, 2026
Token Prices Fell 67% This Year. Your AI Bill Is Going Up Anyway
Jun 3, 2026
Small Businesses Using AI Report Higher Revenue and Shorter Workdays
Jun 3, 2026
Cisco Live 2026 Added a Fifth Agent Control Plane to the Enterprise Stack Map

Turn this article into takeaways for your work.
Each assistant summarizes the article only for you and suggests best practices for your work.
Most CTO agent-platform maps in 2026 have four rows: Microsoft for productivity, Salesforce for customer-facing work, SAP for finance and procurement, ServiceNow for IT and employee services. Cisco Live 2026 just added a fifth row, and most enterprise architecture documents don't have a slot for it yet.
That gap matters more than it might look on a Tuesday keynote slide. The five agent control planes don't compete with each other. They each own a different surface where software agents operate. But where those surfaces touch, governance, audit trails, and incident response all start to fracture, and right now almost no enterprise team has drawn those boundary lines.
What Cisco Actually Shipped at Cisco Live 2026
Cisco Live 2026 runs May 31 through June 4 at Mandalay Bay in Las Vegas, drawing roughly 20,000 attendees from 75 countries. CEO Chuck Robbins took the stage for the Tuesday June 2 keynote, and the headline wasn't a new switch or router. It was a revised AI infrastructure order target.
According to investor disclosures referenced in Channel Insider and Network World reporting, Cisco raised its full-year AI infrastructure order forecast to $9 billion, up from a prior estimate of $5 billion. A near-doubling in a single earnings cycle is a strong signal about where Cisco thinks enterprise infrastructure spend is heading.
The product story behind that number is AgenticOps. Cisco first announced AgenticOps at Cisco Live EMEA in February 2026, then expanded it across the portfolio in a Cisco Newsroom announcement on February 10, 2026. By the time Las Vegas opened, the roadmap had moved from announcement to production.
The May 2026 general availability milestones covered firewall operations and compliance inside Cisco Security Cloud Control. Agentic compliance now runs continuously, evaluating firewall configurations against PCI-DSS requirements and surfacing remediations without waiting for a scheduled audit cycle. That shifts the network security posture from periodic review to persistent monitoring.
The June 2026 controlled-availability releases include the Automation Builder Agent, the Triage Agent, and data center capabilities. The Detection Builder Agent and Guided Response Agent are in pre-release testing. Cisco is also using Model Context Protocol (MCP) servers inside agents that retrieve and prioritize network insights from Meraki and Cisco Catalyst Center through a mobile app, letting network engineers query their infrastructure the same way they'd ask a question in a chat thread.
Key Facts
- Cisco raised its full-year AI infrastructure order forecast to $9 billion, up from $5 billion (Cisco investor disclosures via Channel Insider and Network World, June 2026)
- AgenticOps GA milestones in May 2026 include firewall operations and PCI-DSS agentic compliance inside Cisco Security Cloud Control (Cisco Newsroom, February and May 2026)
- Cisco AI Defense added agent-specific security capabilities in March 2026, targeting agentic workforce environments (Cisco Newsroom, March 2026)
Why the Network and Security Layer Counts as a Separate Control Plane
The default instinct in enterprise architecture is to treat Cisco as infrastructure: the network is a pipe, and agents run on top of the pipe. That model held when agents meant people clicking through software. It breaks when agents are software processes autonomously making network changes and triggering security remediations.
Three things changed at Cisco Live 2026 that upgrade Cisco from infrastructure vendor to agent platform.
First, AgenticOps ships agents that take action, not just surface insights. An Automation Builder Agent that assembles and executes a configuration workflow is a different category from a dashboard that shows alerts. Agents that execute network changes own a distinct action surface, and that surface needs its own governance layer.
Second, Cisco AI Defense now has agent-specific security controls. The March 2026 release added capabilities designed for environments where software agents are making authenticated calls, not humans. That recognizes that the threat model for an agentic environment is structurally different from one built around human operators.
Third, the Model Context Protocol (MCP) integration makes Cisco's network layer directly callable by agents on other planes. An agent inside Microsoft 365 can retrieve network context from Meraki via an MCP server. That's not Cisco acting as a pipe. It's Cisco acting as an API surface that agents on other platforms will query. Once another platform's agents are calling Cisco's MCP endpoints, the boundary between planes gets complicated fast.
The Five Control Planes Audit
The audit reframes agent governance as a control-plane problem rather than a single platform selection question.

Most enterprise architecture maps in early 2026 were drawn around four control planes. The frame below adds the fifth and names the Q3 decision that each one forces on a CTO.
| Control Plane | Domain Owned | Primary Agent Use Case | Audit Surface | Q3 Decision |
|---|---|---|---|---|
| Microsoft Agent 365 | Productivity, Office, identity (Entra) | Email triage, document workflows, Teams transcripts | Microsoft Purview | Where to draw the agent action boundary inside Microsoft 365 |
| Salesforce Agentforce | CRM, customer engagement, Slack | Customer-facing agents, sales follow-up, support routing | Salesforce Shield, AppExchange | Whether agentic activity in Slack becomes a CRM write-back surface |
| SAP Joule | ERP, finance, procurement | Procurement workflows, vendor onboarding, financial close | SAP Cloud ALM | Whether to let SAP own agentic depth in financial close processes |
| ServiceNow | Workflow, IT services, HR services | Ticketing, incident routing, employee requests | ServiceNow AI Control Tower | Where ServiceNow workflow agents hand off to other planes |
| Cisco AgenticOps | Network, security, observability | Firewall remediation, threat triage, network change | Cisco AI Defense, Splunk, AgenticOps Triage Agent | Whether network agents trigger automated change in production |
The table shows something that isn't obvious when you look at each platform in isolation: these five planes are not redundant. They each own distinct ground. But they will intersect constantly in real enterprise environments, and the question of who owns the action at each intersection is unanswered in most architecture documents.
Consider a Salesforce Agentforce agent handling a customer escalation that determines a VPN policy change is required to restore access. The Agentforce agent owns the customer interaction. The Cisco AgenticOps layer owns the network configuration. There's no defined handoff protocol between those two planes for that scenario. Someone will encounter it in production in 2026, and if the answer isn't worked out in advance, the incident response will be improvised.
The same dynamic plays out between ServiceNow and SAP. A ServiceNow procurement agent completing a vendor onboarding workflow may need to trigger a purchase order in SAP Joule. Both planes have agents. Neither plane's governance framework explicitly covers what happens when their agents interact at the process boundary, which is where audit trails break and where "which system was responsible?" becomes unanswerable.
Where the Boundaries Will Actually Break
The first failure mode is the firewall rule collision. A Microsoft 365 agent working inside an approved workflow needs to allow a new SaaS tool for the sales team. The agent can update Microsoft tenant settings. But the network-level firewall rule that permits the traffic is owned by Cisco Security Cloud Control. If the Cisco agentic compliance layer is evaluating configurations against PCI-DSS, the Microsoft agent's change may conflict with an active compliance rule. Neither agent has visibility into the other's constraint set. The result is a change that completes on one plane and fails silently on another. The fix is a shared constraint registry each plane can query before acting.
The second failure mode is the audit gap at SAP and ServiceNow handoffs. When a ServiceNow incident ticket triggers a financial adjustment that routes through SAP Joule, the action log in ServiceNow records the ticket closure and the SAP log records the financial event. But the causal chain connecting them may not appear in either system's audit trail in a form a compliance reviewer can follow. For any organization subject to SOX or similar controls, that's a documentation problem a manual audit will surface at the worst possible time.
The third failure mode is the Salesforce webhook to Cisco network policy path. Salesforce Agentforce agents can trigger outbound webhooks as part of customer workflows. If a customer account status change needs to update access rules in a partner network managed through Cisco, the webhook fires from Salesforce and the receiving endpoint sits inside Cisco's network policy layer. If the Cisco AgenticOps Triage Agent flags the inbound webhook as anomalous, the Salesforce agent's action halts without a clear error either platform's operator can diagnose quickly.
All three failure modes share the same prerequisite fix: someone needs to own the cross-plane action mapping before the agents start firing in production.
What to Do This Week
Action 1: Add a "Network and Security" row to your current agent-platform map. If your architecture document has four rows for agent control planes and no row for Cisco, update it this week. The row doesn't need to be complete. It needs to exist so the team treats the network layer as an agentic surface, not just infrastructure. Start with the Cisco AgenticOps capabilities that are already in general availability: firewall agentic compliance and Security Cloud Control.
Action 2: Identify the two or three highest-frequency cross-plane actions in your environment and assign a single owner per action. Pull the list of workflows where two platforms exchange data or trigger each other's processes today (before agents). Those are your highest-risk intersection points when agents come in. Pick one person who is accountable for the handoff governance on each. That person doesn't have to solve the full cross-plane protocol problem in week one. They need to know the problem is theirs before an incident forces the answer.
Action 3: Brief your security team on Cisco AI Defense agent capabilities from the March 2026 release before any AgenticOps general availability rollout begins. The March release added controls specifically designed for environments where agents are authenticating and taking action, not humans. Your security team's threat models were probably written for human operators. They need a briefing on what changes when the actor is an agent with persistent credentials, not a person typing a password. Do that briefing before the Cisco Automation Builder Agent or Triage Agent goes into any production environment, not after.
Related Reading
- The autonomous agent pattern and how it applies to network-layer agents: the architectural pattern behind agents like Cisco's Triage Agent and Automation Builder Agent.
- What "Execute" means in the AI capability stack: the distinction between agents that surface insights and agents that take actions, which is the line Cisco AgenticOps is crossing with its firewall remediation capabilities.
- Microsoft Build 2026 Windows Agent Platform and Store: the CTO architecture decision: the first control plane that most enterprise teams are mapping, and why it intersects with Cisco's network layer.
- SAP Sapphire 2026 and the autonomous enterprise: the CTO integration decision: SAP Joule's position as the ERP control plane and where it shares boundary with ServiceNow and Cisco.
- AI governance and audit trails for sales operations: practical audit trail architecture that applies directly to cross-plane action logging.
FAQ
What is Cisco AgenticOps and when did it reach general availability?
Cisco AgenticOps is Cisco's framework for AI agents that manage network operations, security compliance, and infrastructure workflows. Cisco first announced it at Cisco Live EMEA in February 2026. The first general availability milestones, covering firewall operations and PCI-DSS agentic compliance inside Cisco Security Cloud Control, shipped in May 2026. The Automation Builder Agent and Triage Agent reached controlled availability in June 2026.
Why does the network and security layer count as a separate agent control plane?
Cisco AgenticOps agents now take action rather than just surfacing insights. Cisco AI Defense added agent-specific security controls in March 2026 because the threat model for an agentic environment is structurally different from a human-operator model. And the Model Context Protocol (MCP) integration makes Cisco's network layer directly callable by agents on other platforms, meaning Microsoft or Salesforce agents can query Cisco's network surface as an API. That's infrastructure behaving like a platform.
How should a CTO handle overlap between Cisco AgenticOps and other agent platforms?
Map the cross-plane intersections before agents start executing in production. Identify two or three workflows where two platforms already exchange data or trigger each other's processes. Those become high-risk when agents take over the action steps. Assign a single named owner per intersection and document the constraint set each platform's agents must respect. The groundwork doesn't require a unified orchestration platform. It requires a shared constraint registry each plane's agents can consult before acting.
