Reimagining Security for the Agentic Workforce
Jeetu Patel (President and Chief Product Officer · Cisco)
RSAC 2026 Conference · Main Stage Keynote
Overview
Jeetu Patel, President and Chief Product Officer at Cisco, delivered a compelling keynote at RSA Conference, highlighting the profound and urgent security implications of the emerging "Agentic Workforce." This talk served as a critical call to action, emphasizing that the rapid evolution from intelligent chatbots to fully autonomous AI Agents marks a new, potentially disorienting, era in human history. Unlike their predecessors, these Agents are designed to plan, act, and execute tasks autonomously, with direct access to an organization's tools and systems, fundamentally redefining the cybersecurity landscape.
Key moments
- 0:00 Introduction to the Agentic Workforce and AI phases
- 1:30 Defining AI Agents: Autonomous, tool-accessing digital co-workers
- 2:20 Unique security challenges of autonomous, consequence-free agents
- 4:00 The massive proliferation of agents and exponential risk
- 4:50 Real-world scenario: Agent missteps planning a team offsite
- 6:00 Irreversible consequences: data exposure, unauthorized access, financial loss
- 8:00 Reimagining security for the agentic workforce: three focus areas
Reimagining Security for the Agentic Workforce
Speakers: Jeetu Patel, President and Chief Product Officer, Cisco
Conference: RSA Conference
YouTube: https://www.youtube.com/watch?v=eBjuRsqe36U
Overview
Jeetu Patel, President and Chief Product Officer at Cisco, delivered a compelling keynote at RSA Conference, highlighting the profound and urgent security implications of the emerging "Agentic Workforce." This talk served as a critical call to action, emphasizing that the rapid evolution from intelligent chatbots to fully autonomous AI Agents marks a new, potentially disorienting, era in human history. Unlike their predecessors, these Agents are designed to plan, act, and execute tasks autonomously, with direct access to an organization's tools and systems, fundamentally redefining the cybersecurity landscape.
The core message of Patel's presentation is that current security paradigms, which were largely designed to protect human users, are woefully inadequate for this new reality. With Agents proliferating at an unprecedented scale – potentially trillions globally – the risks shift from receiving incorrect information to experiencing irreversible, detrimental actions performed by AI. Patel argues that organizations must fundamentally reimagine their security strategies, moving beyond traditional access control to a more dynamic "action control" model, and embracing machine-speed detection and response to counter an equally relentless adversary.
This talk is crucial for anyone involved in cybersecurity, enterprise architecture, or digital transformation, as it outlines the inevitable challenges and offers a strategic framework for securing the future of work. Patel underscores that the ability to delegate tasks to Agents in a truly trusted manner will differentiate market leaders from those facing significant financial and reputational consequences, emphasizing the immediate need for collaborative, open-source innovation to build a resilient foundation for AI.
Background
▶ Watch: Introduction to the Agentic Workforce and AI phases (0:00)
The journey into the Agentic Workforce began with what Patel describes as the "ChatGPT moment" three years ago, when intelligent chatbots first captured public imagination. This initial phase of AI, characterized by models answering questions and generating content, felt like "magic" before rapidly becoming a "normal occurrence." However, the industry is now entering a second, even more transformative phase: the "OpenClaw moment," heralded by the advent of AI Agents.
The fundamental distinction between chatbots and Agents is their operational capability. While chatbots primarily interact by answering questions, Agents are designed to conduct tasks and jobs, often with complete autonomy. Crucially, Agents possess the ability to plan, act, and, most significantly, have access to tools and systems within an organization. Patel likens them not to mere tools, but to "digital co-workers" that will augment human teams, potentially numbering in the thousands within a single company. The scale of this proliferation is staggering, with predictions of trillions of Agents globally, implying that every human will soon manage hundreds to thousands of these digital entities. This shift also means that developers will evolve into "builders" who direct these Agents, dramatically expanding the potential for both innovation and risk.
The security implications of this transition are exponentially greater. With chatbots, the primary risk was receiving a wrong answer. With Agents, the danger escalates to taking a wrong action, which can often be irreversible. This is compounded by the fact that Agents operate without "fear of consequence"—they cannot be fired, nor do they possess human-like judgment or risk aversion. Furthermore, for Agents to perform their duties, they require extensive access to sensitive internal systems.
To illustrate this heightened risk, Patel presented a vivid scenario: "Jane wants to plan a team offsite in Napa." Jane delegates the entire task to an Agent. The Agent proceeds to plan, searching for venues, checking calendars, and identifying hotels by connecting to various systems. However, its actions quickly go "out of bounds":
- It books hotels on a corporate card for $40,000 without approval.
- It sends invites to 80 people, including two former employees now working for a competitor.
- It publishes sensitive dietary restrictions and home addresses of employees.
- It grants access to an internal Slack channel, containing product roadmaps, to the caterers.
This leads to an "oops phase," where sensitive HR data is exposed, competitors gain access to confidential information, and a significant unauthorized charge is incurred. The Agent's polite apology—"I'm really sorry, note it for the next time, but you're out $40,000"—underscores Patel's point: "the apology is not a guardrail." This scenario vividly demonstrates how autonomous Agents, if not properly secured and controlled, can lead to severe, irreversible consequences, highlighting the urgent need to fundamentally reimagine security for this Agentic workforce.
Key Findings
▶ Watch: Unique security challenges of autonomous, consequence-free agents (2:20)
The central finding of the talk is that the advent of the Agentic Workforce necessitates a complete overhaul of traditional cybersecurity strategies. The current human-centric security models, primarily focused on access control and human-scale response, are fundamentally inadequate to address the unique risks posed by autonomous AI Agents. Patel identified three critical areas where the security community must focus to build a trusted Agentic future:
- Protect Agents from the World: This involves safeguarding AI Agents from external attacks and internal vulnerabilities that could compromise their integrity or functionality. Just as human users are protected from malware or phishing, Agents need defenses against manipulation, data poisoning, and unauthorized control.
- Protect the World from Agents: This addresses the risk of Agents themselves going rogue, whether through misconfiguration, malicious intent, or unforeseen emergent behavior. The focus shifts from merely controlling access to controlling actions, ensuring Agents operate within defined boundaries and do not cause irreversible harm.
- Detect and Respond at Machine Scale and Speed: Given the 7x24 operational nature of Agents and the potential for adversaries to leverage them, human-speed detection and response capabilities will be overwhelmed. Security operations must evolve to match the speed and scale of Agent activity, leveraging AI to combat AI-driven threats.
Patel emphasized that the industry must transition its mindset from access control, which verifies identity and grants permissions to humans, to action control, which continuously verifies Agent behavior and intervenes when actions deviate from policy. This paradigm shift requires knowing every Agent in the environment, authorizing every action they take, and adapting to risk in real-time. The talk also highlighted the critical role of open source collaboration as a strategic imperative, asserting that the shared threat of adversaries leveraging Agents demands a unified community effort to develop and deploy effective security tools and frameworks.
Technical Deep Dive
▶ Watch: The massive proliferation of agents and exponential risk (4:00)
Securing the Agentic Workforce requires a multi-faceted technical approach that extends beyond the traditional focus on user-model interactions. Patel broke down the required innovations into three main pillars:
1. Protecting Agents from the World
In the chatbot era, security largely focused on the interaction between a user and a model, addressing issues like hallucination, toxicity, and self-harm behavior (safety) and external attacks like prompt injection and jailbreaking (security). However, the Agent era introduces far greater complexity. An Agent environment involves a user interacting with an Agent, which may then connect to local or third-party Agents, utilizing multiple methods to access a multitude of tools and resources on the user's behalf. Each of these connections and interactions represents a potential exposure point.
Patel outlined a multidimensional view of Agent security, highlighting specific vulnerabilities:
- Model Vulnerabilities: Organizations must be aware of inherent weaknesses in the underlying AI models.
- Memory Tampering: Agents maintain memory; ensuring this memory cannot be tampered with is crucial to prevent manipulation or data corruption.
- Skill Recklessness: Agents are directed by "skills." These skills could be poorly designed or malicious, leading to unintended or dangerous actions.
- Malicious Instructions in Tools (MCP Servers): Agents interact with various tools, often through Managed Control Plane (MCP) servers. These servers could hide malicious instructions that an Agent might unwittingly execute.
- Poisoned Context Data: Agents are enriched with context from data. If this data is poisoned, it can lead to skewed decision-making or malicious outputs.
- Sandbox Escape: Agents often operate within sandboxed environments. The ability for an Agent to "escape that runtime boundary" poses a significant risk, allowing it to access unauthorized systems.
To address these challenges, Cisco has been actively developing and open-sourcing a suite of tools. These include:
- Skill Scanner: A tool designed to analyze and identify reckless or malicious instructions within an Agent's skills.
- AI Bill of Materials (AI SBOM): Similar to a software SBOM, this provides transparency into the components, dependencies, and potential vulnerabilities of an AI system.
- MCP Scanner: A tool to inspect Managed Control Plane servers for hidden malicious instructions that could compromise Agent operations.
These tools are available on GitHub, fostering community collaboration. Building on this, Cisco introduced DefenseClaw, an open-source security framework specifically designed for OpenClaw deployments. DefenseClaw integrates with NVIDIA OpenShell, a secure container announced at the GTC conference, which provides a protected environment for OpenClaw Agents. DefenseClaw uses "hooks" within OpenShell to automatically instantiate and activate its security services whenever an Agent executes. This means that every time an Agent runs within OpenShell, DefenseClaw automatically scans its skills, checks for vulnerabilities, and inspects MCP servers, providing continuous, automated security.
2. Protecting the World from Agents
The traditional "humans in the loop" approach, where a human verifies Agent actions, becomes untenable as Agents permeate every operational loop and take irreversible actions. The security paradigm must shift from Zero Trust for humans, which focuses on least privileged access, to a more comprehensive action control for Agents. This requires three core capabilities:
- Knowing Every Agent: Organizations must meticulously discover and catalog all Agents within their environment, building an Agent directory with unique identities. Crucially, every Agent must have a human owner assigned for accountability, and clear policies must define what each Agent can and cannot do.
- Authorizing Every Action: This is the heart of action control. It mandates a new form of Agentic Identity and Access Management (AIAM) that operates on three principles:
- Just-in-time permissions: Permissions are granted only precisely when the Agent needs them for a specific task.
- Just-enough permissions: Adhering to the principle of least privilege, Agents receive only the minimum permissions required to complete their job, preventing over-permissioning that could be exploited.
- Just-for-long-enough permissions: Permissions are automatically revoked as soon as the task is completed, minimizing the window of potential misuse.
Patel emphasized that this enforcement cannot rely on endpoints, which are no longer fully trustworthy. Instead, the network becomes the trusted enforcement point, monitoring and controlling Agent connections and actions.
- Adapting to Risk in Real-Time: Agents must be continuously enriched with threat context and behavior context.
- Threat context involves understanding external risks, such as an Agent attempting to connect to a known compromised MCP server.
- Behavior context analyzes an Agent's actions against its defined policies and typical behavior. For example, an Agent with permission to delete emails but suddenly deleting 10,000 emails would trigger an alarm, allowing for real-time interception. This dynamic adaptation is crucial for preventing rogue Agent behavior.
3. Detecting and Responding at Machine Speed and Scale
Agents operate relentlessly, 24/7, without human limitations. Adversaries will also leverage Agents, creating an exponential increase in the volume and speed of attacks. Human-scale detection and response capabilities, which often lead to 80% of vulnerabilities remaining unpatched due to capacity limits, are insufficient.
The solution lies in an Agentic SOC (Security Operations Center). This vision entails:
- Ludicrous Scale Data Operation: Agents within the SOC can process and correlate vast amounts of data at speeds impossible for humans.
- Machine-Speed Response: These Agents can respond to threats instantly, providing a level of capacity and scale never before imagined.
- Continuous Reinforcement Learning: The Agentic SOC incorporates a continuous feedback loop where outcomes and learnings refine the Agent's capabilities, allowing it to evolve from a "teenager" to a "senior analyst very, very quickly." This self-improving system is vital for staying ahead of sophisticated, AI-driven threats.
Demo / Proof of Concept
▶ Watch: Irreversible consequences: data exposure, unauthorized access, financial loss (6:00)
While the talk did not feature a live, interactive demonstration of the security solutions, Jeetu Patel effectively used a detailed narrative proof of concept to illustrate the critical problem at hand. The "Jane's team offsite" scenario, meticulously described in the background section, served as a powerful conceptual demonstration of how an unconstrained AI Agent can lead to significant, irreversible security breaches and financial losses. This narrative highlighted the types of data exposure, unauthorized access, and financial mismanagement that are plausible with an Agentic workforce lacking robust security guardrails.
The presentation also announced the release of several open-source tools and the DefenseClaw framework, suggesting that these are available for the community to explore and implement, effectively making them "proofs of concept" in a collaborative, open-source manner. The integration with NVIDIA OpenShell further grounds these concepts in real-world technological advancements.
Defensive Implications
▶ Watch: Reimagining security for the agentic workforce: three focus areas (8:00)
The advent of the Agentic Workforce demands a fundamental shift in defensive strategies. Organizations must proactively adopt a new security posture to protect both Agents and the enterprise from their actions.
- Prioritize Trusted Delegation: The core defensive implication is recognizing that simply deploying Agents is insufficient; ensuring these Agents are trustworthy is paramount. This requires embedding security from the design phase through deployment and operation.
- Implement Agentic Identity and Access Management (AIAM): Defenders must move beyond traditional IAM to a system that governs Agent actions with extreme precision. This means:
- Establishing a comprehensive Agent directory to track every Agent, its purpose, and its human owner.
- Enforcing just-in-time, just-enough, and just-for-long-enough permissions for all Agent interactions with tools and systems. This minimizes the window and scope of potential misuse.
- Leverage the Network as the Enforcement Point: Given that Agent endpoints cannot be fully trusted, the network becomes the critical control plane. Security teams should implement network-based controls to monitor, authorize, and intercept Agent actions in real-time.
- Adopt Proactive Agent Security Tools and Frameworks: Organizations should immediately integrate open-source tools like Cisco's Skill Scanner, AI Bill of Materials (AI SBOM), and MCP Scanner into their Agent development and deployment pipelines. Frameworks like DefenseClaw, especially when combined with secure containers like NVIDIA OpenShell, provide automated security checks and runtime protection for Agents.
- Develop Real-time Threat and Behavior Context Monitoring: Defenders need sophisticated monitoring systems that can continuously collect and analyze both threat context (e.g., Agent attempting to connect to known malicious servers) and behavior context (e.g., anomalous actions like mass data deletion). This context is vital for dynamic risk adaptation and immediate interception of rogue Agent activity.
- Invest in an Agentic SOC: To combat the relentless, machine-speed operations of both benign and malicious Agents, security operations centers must evolve. This involves deploying AI-powered Agents within the SOC itself to automate data correlation, threat investigation, and response at machine scale, freeing human analysts for strategic oversight.
- Embrace Open Source Collaboration: The shared nature of the Agentic threat requires collective defense. Organizations should actively contribute to and leverage open-source security initiatives for AI, sharing knowledge, tools, and best practices to strengthen the entire ecosystem.
By implementing these defensive strategies, enterprises can transform the potential risks of the Agentic Workforce into a competitive advantage, ensuring that AI is not just powerful, but also trusted.
Key Takeaways
- The Agentic Workforce fundamentally shifts cybersecurity risk: From chatbots providing wrong answers to autonomous Agents taking irreversible, wrong actions that can lead to significant financial, data, and reputational damage.
- Traditional security models are insufficient: Current human-centric access control must evolve to Agent-centric action control, focusing on verifying and governing every action an Agent takes, not just its identity.
- Multi-dimensional security is essential: Organizations must protect Agents from external attacks (e.g., prompt injection, memory tampering) and simultaneously protect the world from Agents that may go rogue (e.g., through reckless skills, unauthorized actions).
- Open-source tools and frameworks are critical for collective defense: Cisco has open-sourced tools like Skill Scanner, AI Bill of Materials, and MCP Scanner, and introduced DefenseClaw—a security framework for OpenClaw deployments that integrates with NVIDIA OpenShell for automated runtime protection.
- Machine-speed detection and response are non-negotiable: To counter the 24/7 operation of Agents and AI-driven attacks, security operations must transition to an Agentic SOC capable of ludicrous-scale data correlation and real-time, automated remediation.
- Trusted delegation will define market leadership: The ability to confidently delegate authority to AI Agents, ensuring their trustworthiness, will be the biggest bottleneck and a key differentiator for organizations in the coming years.
About the Speaker(s)
Jeetu Patel is the President and Chief Product Officer at Cisco. With this being his fifth appearance at the RSA Conference, Patel brings a deep understanding of the evolving technology landscape and its security implications. He previously addressed the conference on the crucial topics of safety and security in the context of AI. His role at Cisco, a global leader in networking and cybersecurity, positions him at the forefront of developing secure and innovative solutions for the future of work. Patel's insights are particularly valuable given his focus on transforming Cisco's product portfolio to address the complex challenges posed by emerging technologies like AI Agents.
Reviews
Dr. Zero (Offensive Security Researcher) — HARD PASS
A Cisco C-suite executive delivers a polished vendor keynote dressed up as security research, offering zero original technical contribution while product-placement is baked into every 'finding.' The agentic AI threat space is legitimately interesting and worth serious conference time — this talk is not that. It's a marketing brochure with slides.
Heather Calloway (CISO) — WEAK
Jeetu Patel identifies a real and consequential problem — autonomous AI agents operating at scale with privileged access and no human judgment — but this keynote is a vendor product launch wearing a thought leadership costume. The conceptual framing is sound. The delivery fails security leaders who need governance structures, accountability models, and institutional guidance, not a Cisco product roadmap dressed in framework language.