Trust has always been a hot-button issue when it comes to the use of AI in business environments (and beyond). Recently, however, this topic has come to the forefront even more prominently. Cisco aims to help organizations build this trust, in part with the help of Splunk. At Splunk .conf26, we’ll see how it plans to do that. Is it possible to offer“trusted AI at scale” without giving up control? Splunk thinks so. Here’s why.
We’re starting to get a little tired of the big AI companies. Anthropic and OpenAI, in particular, seem to be primarily concerned with their own relevance. In recent months, we’ve witnessed the hype surrounding Mythos , which was supposedly so dangerous that Anthropic didn’t want to release it (but was all too happy to tell everyone about it). Then , Anthropic, OpenAI, and Meta all scrambled to proudly announce that their AI agents are so powerful and smart that they can hack into other organizations on their own (which is a crime in itself). And now the CEOs of Anthropic, OpenAI, and SpaceXAI are once again calling for a halt to the development of AI models.
Whatever else you may think of the developments mentioned above, they’re unlikely to inspire much confidence in organizations that want to start using AI or are already doing so. That in itself is something that can cause quite a bit of stress, particularly in areas such as sovereignty, data security, and transparency. If organizations then also have to use technology from companies that seem more concerned with themselves than anything else, that stress isn’t necessarily going to go away.
Know what you’re getting into and what’s required
In our view, the best option for most organizations right now is not to ignore AI. AI is here to stay. However, it is time to take control of AI. Use the models as a tool and manage the rest yourself as much as possible. This includes ensuring sovereignty, as well as security and compliance. Finally, especially when it comes to deploying AI agents, it’s crucial to keep a close eye on costs.
If you have all of this well organized, that is, setting aside the unpredictable words and actions of the major AI companies, then you can get started with AI with a certain degree of confidence, even as the number of AI agents increases. At .conf26, Cisco and Splunk made it clear that they want to play a key role in this. They’re doing so in several areas: the platform, observability, and security.
Starting with the basics…
When we look at the Splunk platform, the main focus is on making it available in environments where organizations can have and maintain control. We’ve already covered this part of the Splunk and Cisco story quite extensively in a previous article, so we won’t repeat it here. In short, it will be possible to run Splunk in on-premises and air-gapped environments, on a Cisco AI POD (with Nvidia compute), or on an organization’s own infrastructure (also with Nvidia compute). Combined with a choice of multiple AI models, this should enable organizations to maintain control over AI.
…through observability…
To maintain that control, insight is needed first and foremost, especially as more and more AI agents are eventually deployed within organizational environments. That’s where observability comes into play. Specifically, Splunk offers Splunk Agent Observability, which is available not only in the Splunk Observability Cloud but also in Cisco Cloud Control. The latter is also the case for customers who do not hold Splunk licenses. In our view, this is a smart move, as it allows Cisco to make Cloud Control more attractive while also gathering more telemetry itself, which, ideally, improves the platform as a whole.
A new development in the field of observability is Splunk Observability Studio. This is potentially a very interesting addition. This new component is designed to ensure that applications are no longer deployed into production without being observable. OpenTelemetry plays a key role in this. It makes it possible to make components of virtually any application measurable, thereby making them suitable for observability.
Another addition in the area of observability is the Network Intelligence App. With this, Cisco makes network data available in Splunk Observability. This should make it easier to resolve issues related to the underlying network. Employees can now see immediately where the problems lie right from within the Splunk environment.
…to security
The third piece of the puzzle that organizations must put in place to maintain control over, and thus trust in, AI is, of course, security. At Splunk, this has meant focusing on the Agentic SOC for several years now. Specifically, it refers to what the company calls The Agentic SOC Workforce. This is essentially a collection of AI agents that assist security teams and intervene partially autonomously when possible and permitted.
The AI agents within “The Agentic SOC Workforce” are divided into four categories: Detection & Security, Threat Hunting, Investigation & Response, and Governance & Policy. Within these categories, Splunk regularly rolls out new capabilities for the agents. The goal is to have these agents function more and more like a well-functioning security team.
Below is a look at what’s new:

Security and observability are converging
It’s also clear that observability and security are converging more and more. This has become evident at Cisco as well following the merger of its security and Splunk divisions. This makes perfect sense to us. Without continuous observability of all components within an environment, it’s impossible for AI agents (whether autonomous or not) to operate. That’s difficult to assess if you don’t have up-to-date information on how everything else is running and performing.
We wouldn’t be surprised if we see more integration of observability and security in the near future. At Cisco, this also fits very well within the overall Cloud Control strategy. This brings all parts of the company together into a single environment.
The fact that Cisco is already adding components from Splunk to this new platform, regardless of whether users have Splunk licenses, is also telling in this regard. The boundaries between components are blurring, which is also the case in practice. Everything is interconnected and integrated. In that sense, Cisco Cloud Control is a digital mirror image of reality.
Whether it’s actually desirable to present everything on a single platform, however, remains an open question as far as we’re concerned. The theory sounds great, but we’ve also learned by now that reality is often more challenging. Everything hinges on the execution of Cisco’s plans for it.
Read also: Cisco Cloud Control brings networking and security together in a single platform
Splunk isn’t Splunk anymore, it’s going to help cut costs
Splunk has actually always been known as a platform that racked up hefty bills for organizations. When Cisco bought Splunk for $28 billion, a joke made the rounds online that Cisco had done the math and concluded it was cheaper to buy the company than to keep paying their bills for Splunk Enterprise.
The integration of what Hathi calls a freemium version of Observability Cloud into Cisco Cloud Control suggests that the image described above is no longer entirely accurate. Splunk is undoubtedly still a pricey platform, but customers using Cloud Control can now use part of it for free. In addition, a free version of Observability Cloud has recently been introduced. Splunk also made its observability offering available in two flavors: Essentials and Premier. This also provides opportunities to keep spending on the Splunk platform within reasonable limits.

Finally, Splunk Agent Observability is introducing a new feature designed to ensure that the budget organizations have for tokens is spent wisely. This “Tokenomics” addition is intended to give organizations greater control over their spending. This, in turn, should lead to greater insight into the relationship between token spending and the business outcomes of those investments.
Trust in AI starts with control
The message from Cisco and Splunk at .conf26 is clear: organizations must ensure they take and maintain control and always have insight into and control over AI. Only then can you ensure that everything happens on your terms and that you can always intervene if that changes. You define the guardrails within which AI (agents) are allowed to operate and set policies and permissions.
Of course, this is all fairly simple in theory. In practice, it’s not quite so straightforward. Control isn’t all good news for organizations; it also places a significant additional burden on their shoulders. This isn’t something you set up once and then sit back and relax. If you want to be able to make continuous adjustments, you must also stay vigilant. While much of this can be done virtually autonomously, staying vigilant remains important.
For companies like Cisco and Splunk, it’s important to keep pace with developments. At the moment, there aren’t that many AI agents active yet. That number will undoubtedly grow significantly. During a keynote we attended, we saw that AI agents are already using 14 times more tokens than humans. If the number of AI agents increases by a factor of 100, 1,000, 100,000, and so on, environments will be faced with an enormous amount of traffic. On top of this, there will vast amounts of data and telemetry too. These types of environments must be able to continue handling this.
Trust will only become more important
Such numbers of AI agents, and everything that comes with them, will require a fairly high degree of autonomy on the part of the AI agents tasked with keeping customer environments transparent and secure. This makes it even more important to trust the AI running in your environment. That makes it all the more important to get started on this as soon as possible.