Cisco and Splunk Put Trust at the Center of the Agentic Enterprise at .conf26
At Splunk .conf26 in Denver, Cisco and Splunk argued that trust, not compute, is the scarcest resource in the agentic enterprise, and that security and observability are merging.
Cisco President and Chief Product Officer Jeetu Patel told the audience that the industry "has squarely moved now from the era of chatbots to the world of agents, conducting tasks for us almost fully autonomously," and urged customers to treat agents "not as tools but as teammates." He framed the shift around four claims: inference is the new workload, agents are the new workforce, tokens are the new currency, and trust is the new currency of adoption. Splunk Senior Vice President and General Manager Kamal Hathi appeared alongside Patel in the welcome keynote, according to SiliconANGLE's account of the sessions.
Patel offered figures to back the argument. In February, tokens consumed by agents passed the number consumed by humans for the first time, and seven months later agents were consuming five times as many, he said. He also cited projections that roughly 60% of global AI compute capacity this year would go to inference rather than training. Because agents run continuously, spawn other agents and use more network bandwidth than the people working beside them, the consumption curve is no longer limited by human attention span. Patel also described agents as being "like teenagers" — intelligent, fearless and known for poor judgment.
The keynotes also argued that observability and security can no longer be treated as separate disciplines. A live demonstration had an AI engineer and a security operations center analyst work the same incident from two consoles. Patel said it is "actually very hard to distinguish between whether there's a breach, or some agent was poisoned because of an external prompt, or the agent just exercised poor judgment because it was very literally following your instructions." Splunk's answer is to place agent traces, evaluator scores, application telemetry, network data and security signals on a single correlated fabric so that both teams work from the same evidence trail.
John Morgan, Splunk's senior vice president and general manager of security, previewed an integration shipping at the end of the year that will let any customer holding both Splunk Observability and Enterprise Security join those datasets. "We want to respect that the observability and the security teams are different. We know they often have different budgets, but at the same time they have the same business goal," he said.
On the product side, Splunk announced the general availability of Splunk Agent Observability, offered in the cloud, on premises and as a native Cisco Cloud Control application, with a new capability called Tokenomics for tracking and forecasting token spend across agents and coding tools. A demonstration showed a retailer's shopping agent, told to increase customer satisfaction, honoring an expired $300 promotion that the engineers who granted it backend access had not anticipated; the presenter estimated the behavior could cost about $500,000 an hour at scale. The correction was not to pull the agent from production but to convert a custom evaluator into a small language model guardrail running inline with sub-350-millisecond latency, cutting evaluation costs.
The across-the-board message was that enterprises are moving from software that answers questions to software that acts, and that the second category cannot be scaled without a system of record and a way to authorize what an agent may do.