Head-to-head · updated 13 September 2026
DataShield vs Cisco AI Defense: who proves what the agent was allowed to do?
Cisco AI Defense is the real thing, and we'd rather say that up front. It red-teams your models before launch, inspects prompts and responses in production, and enforces where Cisco already terminates traffic. Their own phrase is "guardrails embedded in the network." If you run Duo and Secure Access, a lot of this is a switch you flip.
DataShield sits under that. Datasets are tokenized at ingest; agents query tokenized data over MCP; detokenization is a privileged, audited operation. Every governed tool call is checked against the agent's authority right now. Each decision is sealed into a hash chain you can verify without trusting us. Most buyers here should run both. Below is the honest split, including the rows Cisco wins.
The short version
Pick DataShield when
- Someone will one day ask you to prove an agent's access log wasn't edited. Guardrail logs are logs. Ours is a hash chain with signed checkpoints, and the verifier names the failure. Run it yourself.
- You want the model to see tokens, not the raw record. Guardrails read content and decide. Tokenization changes what there is to read.
- You need the control plane to run inside your own account, self-hosted, with your keys, and not tied to a network vendor's stack. How we deploy.
- You want GDPR erasure and agent break-glass to be mechanisms with a demo, not roadmap items.
Pick Cisco AI Defense when
- Your problem is prompt injection and unsafe output at production traffic volume. Their published guardrail numbers are good: 0.843 recall and 0.847 precision on the ML6 benchmark, p90 latency of 40 ms.
- You need model validation before launch. Algorithmic red teaming came in with their 2024 AI-security buy, and nothing we ship competes with it.
- You're already a Duo and Secure Access shop. The MCP policy gateway and agent discovery land inside tooling your team already runs.
- You want the Splunk tie-in so agent activity feeds an SOC that already has your other detections.
Bottom line: Cisco watches what the agent says. We decide what the agent may touch, and keep proof of the decision. Those are different layers, and the honest answer for most regulated teams is both. If your next audit is closer than your next network refresh, start here.
Feature by feature
Competitor cells describe what Cisco's public site, newsroom and Duo blog say as of the date above. If we've mischaracterised something, email support@myorg.ai and we'll correct it, credited.
| What matters | DataShield | Cisco AI Defense | Edge |
|---|---|---|---|
| Audit evidence | SHA-256 hash chain with Ed25519-signed checkpoints that are themselves chained. Verification names the failure: tampering, insertion, deletion, or truncation. Public verifier. | "Every tool call produces an identity-correlated audit log: human → agent → tool → action," plus Splunk export. We found no published tamper-evidence or chain verification. | ◆ |
| Agent authorization | Every governed tool call passes a scope ceiling, an authority tier, and a revocation re-check before dispatch. Revocation lands mid-session, on the next call. | Duo answers "can this user's agent invoke this specific tool on this specific server, right now," on OAuth 2.1 and OIDC, with short-lived just-in-time tokens. A real per-call claim. Mid-session revocation behaviour isn't described. | ◈ |
| Break-glass | Scoped, time-boxed emergency access for agents that auto-revokes and can't be quietly deleted from the log. | Not found in their public docs. Worth asking. | ◆ |
| GDPR erasure | Crypto-shred of per-subject key material plus ISO 27560 consent receipts. The chain still verifies after the subject is gone. | Not found in their public docs. Their material is about traffic and models, not subject records. | ◆ |
| Tokenization and data handling | Datasets are tokenized at ingest; agents query tokenized data over MCP; detokenization is a privileged, audited operation. Tokens are deterministic, join-preserving and vault-reversible, with quasi-identifier generalization (dates to year, decade or age band; ZIPs to 3 or 4 digits; partial phones, SSNs and emails) with a measured cardinality-reduction score per column for quasi-identifiers. | No tokenization of PII or PHI found. AI Access applies policy to limit sensitive data exposure to third-party AI apps, and guardrails inspect content in flight. | ◆ |
| Runtime guardrails | None. We don't sit inline and don't claim to. Our control is what the agent may reach, not what it may say. | Runtime protection with multi-turn intent classification, 9+ languages at F1 0.796 to 0.860, guardrails enforced in the network fabric. | ◇ |
| Model validation and red teaming | Not offered. | Algorithmic red teaming inherited from their 2024 AI-security acquisition, plus an LLM Security Leaderboard and a free Explorer Edition for testing. | ◇ |
| MCP and agents | Native MCP endpoints on Auth, Ontology and Lighthouse. MCP tool tokens with scope ceilings, per-call metering attributed to the agent. | MCP policy gateway plus agent discovery in Cisco Identity Intelligence. Works with VS Code, Cursor, Claude Code and other MCP clients. | ◈ |
| Deployment and independence | Self-hosted in your own cloud or data center, or on a dedicated single-tenant server we operate. Your keys. No IdP or network vendor to displace; we federate over SAML and OIDC. | Delivered through Cisco's security cloud and best value inside the Cisco identity and access stack. Self-hosting for AI Defense isn't described in public material. | ◆ |
| Portfolio and roadmap risk | One team, one roadmap. Design-partner terms include source escrow, because a small vendor shouldn't be a single point of failure. | Two acquisitions in this space in under two years: an AI-security vendor in 2024, then Astrix Security, closed 29 June 2026. Astrix stopped selling standalone licences a day later. Distribution is huge, but the capability map keeps moving. | ◆ |
| Maturity signals | Auth, Guardian and Lighthouse are live in production (Guardian and Lighthouse since April 2026). SOC 2 not yet certified, and we say so. | Cisco Systems. Public company, global channel, Splunk in the portfolio. Nobody gets fired for this one. | ◇ |
| Pricing | Published model, scoped instant quote, no sales wall. | Quote-only. The primary CTA is "Talk to an expert." Explorer Edition is free but scoped to testing, not production enforcement. | ◆ |
◆ DataShield leads◇ Cisco AI Defense leads◈ comparable
Cisco claims are drawn from cisco.com, newsroom.cisco.com, blogs.cisco.com and duo.com, last checked 13 September 2026. We link them below rather than paraphrase from memory.
Three things you get here that you won't get from a network security platform
Proof, not just a log
A guardrail log tells you what the filter saw. It doesn't tell an examiner that the March entries are the same March entries. Ours is a hash chain with signed checkpoints, and the verifier says what broke, not just that something did. That's the property EU AI Act Article 12 and HIPAA §164.312(b) reviewers care about. Try it in your browser, no signup.
Tokens where the raw record used to be
Guardrails inspect content and make a call. Tokenization removes the question. Datasets are tokenized at ingest, the agent queries tokens over MCP, and getting a real value back is a privileged vault operation that leaves a record. How the data layer works.
Authority that changes mid-flight
An analyst resigns at 2pm. Their agent is 20 minutes into a 40-minute job. Our next governed tool call is re-checked against current authority and fails closed. A short-lived token is better than a long one, but it still rides until it expires. How Auth does it.
Where Cisco AI Defense is genuinely stronger
We're not going to pretend this is a small vendor with a thin product. Cisco paid a reported $1.5 billion for an AI-security vendor in 2024. It turned that into a runtime layer with published numbers: multi-turn intent classification, 0.843 recall and 0.847 precision on the ML6 benchmark, p90 latency of 40 ms. Algorithmic red teaming before launch is a capability we simply don't have. The March 2026 launch added agent discovery, a Duo-backed MCP policy gateway and the DefenseClaw open-source project. The Duo team also makes a per-call authorization claim. It is closer to ours than anything else in this market. If you already run Duo and Secure Access, the cheapest correct answer may be to turn Cisco on first.
The push-back is narrow and it matters. Detection answers "was that output safe." It doesn't answer "was that agent allowed to read that row," and it doesn't make the record of the answer hard to edit. Gartner expects most unauthorized agent transactions through 2028 to be internal policy violations, not attacks. That is the category guardrails are worst at. There's also a plain commercial point: a control plane that ships with your network vendor is a control plane your network vendor owns. That is fine until the renewal. Or until the thing you bought gets folded into a different SKU, which is what Astrix customers found out on 30 June.
Questions worth asking both of us
These are the questions we'd want answered if we were buying. Ask them on every vendor call, including ours.
Can you cryptographically prove an audit log entry wasn't deleted?
DataShield: yes. Each record commits to the one before it, checkpoints are signed and chained, and verification tells deletion apart from truncation and tampering. Run it on a sample chain at /verify. Cisco: the Duo blog describes an identity-correlated audit log of human, agent, tool and action, and Splunk export. We found no published tamper-evidence. Ask them to show you a verification step.
What happens to a revoked agent mid-session?
DataShield re-checks authority on every governed tool call, so revocation takes effect on the next call. Cisco issues short-lived just-in-time tokens for MCP servers. That shortens the window but doesn't close it, and we found no description of mid-session revocation. Ask both of us the same question: after I click revoke, how many more tool calls succeed?
How does GDPR erasure interact with the audit trail?
DataShield crypto-shreds per-subject key material and issues an ISO 27560 consent receipt. Actor identities in the chain are HMAC-committed, so the evidence stays verifiable after the subject is erased. We found nothing on erasure in Cisco's AI Defense material, which is fair since it's a traffic and model product, not a record store. Ask where subject erasure lands in their stack.
Do I have to adopt Duo and Secure Access to get the MCP gateway?
Ask them directly. The public material positions Duo as the identity engine behind agent authorization and Secure Access as the enforcement point, and Astrix capabilities are being folded into Identity Intelligence, Secure Access, Duo and Splunk. DataShield federates to whatever IdP you already run over SAML or OIDC and never asks you to replace it.
Do guardrails cover PII and PHI reaching the model?
Cisco's AI Access applies policy to limit sensitive data going to third-party AI apps, and runtime guardrails inspect content in flight. That's detection on the wire. DataShield works upstream: datasets are tokenized at ingest, agents query tokenized data over MCP, and detokenization is a privileged, audited operation. Different mechanism, different failure mode. Running both is reasonable.
Does DataShield have SOC 2?
Not yet, and we won't imply otherwise. Auth is live a public threat model and a verifier anyone can run. Guardian and Lighthouse have been in production since April 2026. Design-partner terms include source escrow so a small vendor isn't a single point of failure. Details on the security page.
- Cisco's agentic hero: "Zero trust for the agentic AI workforce." Primary CTA is "Talk to an expert." — cisco.com, 13 Sep 2026
- March 2026 launch adds Duo Agentic Identity, MCP policy enforcement, DefenseClaw and AI Defense Explorer Edition. Cites 85% of large enterprises experimenting with agents, 5% in production. — Cisco newsroom, 23 Mar 2026
- Duo: authorization for "can this user's agent invoke this specific tool on this specific server, right now," and "every tool call produces an identity-correlated audit log." — duo.com blog, 13 Sep 2026
- AI Defense guardrail benchmarks: 0.843 recall, 0.847 precision on ML6; F1 0.796 to 0.860 across 9+ languages; p90 40 ms, p99 250 ms. — blogs.cisco.com, 17 Jul 2026
- Cisco acquires Astrix Security, completed 29 June 2026, citing that only 24% of organizations can control agent actions with guardrails. — blogs.cisco.com, 4 May 2026
- ≥80% of unauthorized agent transactions through 2028 will be internal policy violations rather than attacks. — Gartner, 2026
Other head-to-heads
DataShield vs Astrix Security
The NHI discovery product Cisco bought, and what happened to standalone sales.
RuntimeDataShield vs HiddenLayer
Model-layer detection on top, authorization and evidence underneath.
GuardrailsDataShield vs Lakera
Prompt defence is a real layer. It isn't the authorization layer.
AllEvery comparison
One honest scorecard per vendor, sources at the bottom.
Bring your Cisco architect. Break a live audit chain in the browser, revoke an agent mid-session, then decide which layer you're still missing. Demo Center access is free with a work email.
Get free Demo Center accessYou've seen the proof
Ready for a number? Scope your deployment and we'll price it against your own economics.
Get your quote →