Cisco releases open-source security specification for AI agents

Share

Key Points

  • Windows Server 2022 integration
  • Foundry Security Spec open-source
  • CodeGuard AI coding support

What is changing

Cisco released its internal Agentic AI spec on GitHub, built with the spec-kit framework. The spec lists eight core agent roles such as orchestrator, indexer, cartographer and detector. It is model agnostic, so it works with any frontier LLM. GitHub’s spec-kit provides standardized workflows that can be used with any AI agent. Developers can integrate the spec into existing CI pipelines. This makes the process repeatable.

The spec defines roughly 130 functional requirements each with an inline rationale. It adds validation steps so findings become bounded, prioritized and auditable. It includes safety guardrails that assume the model may act maliciously and constrain it at the substrate. The guardrails limit the model’s ability to cause unintended actions. Teams can verify findings without writing custom scripts. This makes the process repeatable.

Why it matters

IT security teams will use a common framework to evaluate AI agents, cutting reliance on ad-hoc chat queries. It also lets auditors trace each step from detection to publication. It can reduce manual effort for large enterprises.

The new system provides clear validation output and an Auditable provenance chain, easing audit work. The auditable provenance chain simplifies compliance reporting for enterprise regulators. Enterprises can now schedule regular AI security audits without hiring extra staff. This makes the process repeatable.

Share your deployment experience in the comments.

Read the original source.


Discover more from Windows Mode

Subscribe to get the latest posts sent to your email.