The News
At Cisco’s .conf26 event, Cisco announced a set of Splunk platform advancements designed to bring trusted, governed AI to enterprise scale. The headline capabilities include Cisco AI POD for Splunk, which extends Splunk AI features to on-premises customers as part of the Cisco Secure AI Factory with NVIDIA; a new Splunk Agent Observability product that tracks AI agent spending and coding agent usage in real time; and a formalized multi-year co-development agreement with AWS focused on security solutions built to counter AI-driven threats. Cisco framed the announcements around three customer questions its leadership says block enterprise AI adoption: Can I trust it? Can I afford it? Can I secure it?
Analyst Take
The trust gap is the real market opportunity
Cisco isn’t positioning Splunk AI primarily as a speed play or a cost-reduction tool. It’s positioning it as the answer to enterprise hesitation. That’s a sharper value proposition than most AI platform vendors are currently offering, and it targets a real and documented problem. According to ECI Research’s Google GovTech Survey, 31.8% of respondents identified “FedRAMP/compliance approval friction for AI vendors” as the single largest blocker preventing widespread AI adoption in developer workflows. Compliance friction, not capability gaps, is what stalls deployment at scale. Cisco’s decision to extend Splunk AI to on-premises infrastructure via the AI POD offering attacks that friction by letting regulated customers run AI inference on hardware they already own, control, and trust.
On-premises AI is a serious architectural bet
Running Splunk AI locally, on validated Cisco hardware alongside NVIDIA accelerators, means customers in regulated environments don’t have to route sensitive telemetry through public cloud endpoints to get AI-powered detection and analysis. That’s not a minor convenience. For organizations operating in air-gapped or hybrid environments, it’s often the only viable path. ECI Research’s GovTech data shows that 46.9% of respondents describe their software development environments as “a mix of connected and disconnected (air-gapped) environments,” with another 24.9% operating primarily in disconnected settings. A vendor that can deliver production-grade AI capabilities inside that constraint is competing in a market segment that most SaaS-first AI vendors simply cannot reach.
Tokenomics and the ROI accountability problem
The Splunk Agent Observability product, which Cisco is branding under a “Tokenomics” framework, targets something the market has been slow to tackle directly: the cost accountability gap in agentic AI deployments. Enterprises are beginning to deploy AI coding agents, security agents, and operations agents, but few have reliable tooling to answer the basic question of what those agents are actually spending and what they’re producing in return. Real-time tracking of AI agent usage tied to business value metrics is a meaningful differentiator, particularly as AI inference costs become a line item that CFOs are starting to scrutinize. The AWS co-development agreement adds a distribution and integration dimension to this, signaling that Cisco intends to compete not just on its own installed base but across multi-cloud deployments where Splunk already has significant penetration.
The agentic SOC capabilities round out a coherent platform story. Cisco is threading a single narrative from infrastructure (AI POD, on-prem compute) through observability (Agent Observability, cost tracking) to security operations (agentic SOC, AWS partnership). That kind of stack coherence is harder to achieve than any individual feature, and it’s what enterprise buyers actually need to make a durable platform commitment rather than a point-solution purchase.
Looking Ahead
Cisco’s near-term competitive challenge is execution speed. The AWS agreement is framed as a multi-year co-development effort, which signals ambition but also means the most differentiated joint capabilities are likely 12–18 months from meaningful customer availability. Competitors are not standing still on agentic security, and the window for Cisco to convert announcement momentum into pipeline is narrower than the multi-year framing might suggest. The on-premises AI POD, by contrast, is a near-term differentiator that Cisco should be actively placing in front of regulated-industry customers today, since the competitive set for compliant on-prem AI in security operations is thin.
Over the next two to three years, the Tokenomics framing could prove to be the most strategically important piece of this announcement, provided Cisco executes on it. If AI agent spending becomes as visible and manageable in Splunk as cloud infrastructure spending became in cloud cost management tools, Cisco will have built a durable reason for enterprises to keep Splunk as the control plane for their agentic operations rather than allowing point solutions to fragment the data layer. That’s the bet embedded in this announcement, and it’s a reasonable one.
Stay Ahead of Application Development Trends
Get weekly analyst insights, research notes, event coverage, and AppDevANGLE updates delivered directly to your inbox.
Subscribe for Weekly Insights
Join technology leaders, practitioners, and GTM teams following the trends shaping modern software delivery.
Looking for deeper research access?
Explore ECI Research reports, survey insights, and market analysis through the ECI Research Portal.
