Artificial intelligence doesn’t just bring new tools into companies — it’s fundamentally changing how applications are built and how data is accessed and secured. As AI moves deeper into production processes, with autonomous agents that can use other applications and services on their own, the attack surface grows exponentially. That’s why AI security can’t be solved with a simple “firewall for ChatGPT” — that’s a superficial approach that overlooks how complex these threats really are.
Cisco AI Defense is exactly the tool that helps organizations answer a few essential questions: what AI applications actually exist in the organization, which models they use, what sensitive data they access, who uses them and with what permissions, what AI-specific vulnerabilities have been found, what happens to the prompts and responses generated, and above all, what actions an AI agent can take on a user’s behalf.

AI Security, a strategic direction at Datanet Systems
This isn’t a theoretical risk, and the numbers back that up. According to a 2025 Gartner study, 29% of cybersecurity leaders surveyed said their organization had been directly targeted by an attack on GenAI application infrastructure in the past 12 months, and 32% reported serious incidents exploiting prompt vulnerabilities.
The trend is even more concerning when you look at how vulnerabilities are evolving. The HackerOne 2025 report shows a 210% increase in AI vulnerabilities reported overall, while prompt injection — one of the most insidious types of attack — has grown by 540%, quickly becoming one of the most critical risk areas across the entire AI security landscape.
In other words, AI creates an entirely new category of risk, one that calls for different tools, processes and expertise. That’s also why Datanet Systems set up a dedicated cybersecurity division.
Read the Datanet Systems article: “AI Security — Responsibility or Necessity”
Cisco AI Defense: security for the entire AI lifecycle
Cisco AI Defense starts from a simple but decisive fact: no matter how sophisticated they are, traditional cybersecurity tools weren’t designed for — and can’t easily be adapted to — the particularities of AI applications and models.
A modern organization can be running several categories of AI at once: internal applications built on proprietary LLMs, open-source models with variable risk, third-party cloud AI services, GenAI applications employees use ad hoc, databases connected directly to AI models, RAG architectures (Retrieval Augmented Generation) that combine external data sources, and, increasingly, autonomous AI agents that can use external tools and take actions with real impact on systems.
Cisco AI Defense is built precisely for this fragmented, complex new reality, and it secures AI across three complementary layers: Discover, Detect, Protect.
1. Discover – IT teams find out exactly what AI exists in the organization
The first problem, and one that’s often underestimated, is visibility. You can’t effectively secure or protect what you don’t know exists in your organization — it’s a basic security principle, but in the world of AI it’s easy to overlook, given how fast these technologies are being adopted.
Cisco AI Defense systematically identifies and catalogs AI workloads, applications, specific models, the data they interact with, and the users behind them, across distributed cloud environments and on-premise infrastructure. This level of visibility matters most in a context where AI is often introduced by different teams within the organization, through different infrastructures and services, without any central coordination.
That’s how you get a real, up-to-date picture of the company’s AI footprint: what’s actually being used, by whom, for what purpose, and with what level of risk. For the first time, an organization can answer precisely questions like: “How many instances of ChatGPT, Copilot or Gemini are in use?” or “How many databases are connected to AI models?”
2. Detect – testing and evaluating AI before vulnerabilities turn into crises
An AI model isn’t secure just because it comes from a well-known vendor or has built-in guardrails. AI models and applications need to be rigorously tested for domain-specific vulnerabilities: prompt injection attacks, jailbreaking, data leakage and privacy issues, unsafe behavior under pressure, or other sophisticated forms of adversarial manipulation.
Cisco AI Defense introduces automated, scalable AI red teaming, which allows models and applications to be evaluated at enterprise scale. Cisco states that the tool tests against more than 200 documented and emerging attack techniques and subcategories.
The difference from a traditional security assessment is easy to underestimate: it’s not just the IT infrastructure around the AI application, the network security or system configuration that gets analyzed, but also how the model actually behaves when exposed to malicious, manipulative or adversarial inputs. This kind of testing becomes even more critical for AI agents with greater autonomy.
3. Protect – controlling AI in real time, in production
An AI application can pass every rigorous test in the development phase and still be successfully attacked once it’s in production, under real-world pressure. Cisco AI Defense provides continuous, adaptive runtime protection against real, specific threats such as prompt injection attacks, data leakage and denial-of-service, applying granular policies to the interactions between users, AI applications and models.
This is where one of the fundamental differences from a classic security approach comes in: protection has to understand not just network traffic and traditional protocols, but also the context and intent behind AI prompts and responses.
Why the combination of Networking, Security, Observability and Threat Intelligence matters
This is, in fact, one of the major, differentiating advantages of Cisco’s approach. Cisco AI Defense isn’t built as a product isolated from an organization’s existing security infrastructure — Cisco draws on its networking and enterprise cybersecurity expertise, combined with the extended visibility offered by its security, observability and telemetry ecosystem.
The result is an integrated approach in which:
- Networking provides complete visibility and granular control over traffic flows, including AI communications, and enables fast identification of unusual behavior.
- Security identifies and blocks threats in real time, applies granular protection policies, and responds quickly to incidents.
- Observability supports a deep understanding of context, infrastructure behavior, and how AI applications are actually used, giving a clear picture of system health.
- Threat intelligence brings up-to-date information on evolving threats, emerging tactics, and supports better-grounded, more anticipatory detection and prevention.
Cisco builds this approach in part on broad telemetry sources from networking, security and observability, collected across thousands of organizations, while threat intelligence from Cisco Talos labs continuously feeds the portfolio with data on emerging threats and evolving attacks.
For customers, this is an important strategic difference: AI Security is no longer a separate topic — it becomes an organic part of the overall security and infrastructure architecture, integrated with the rest of their technology investments.
Cisco AI Defense through Datanet
As Cisco’s principal partner in Romania, Datanet Systems has quickly aligned itself with this emerging direction and is actively working on integrating Cisco AI Defense into its product and services portfolio. Cisco also offers AI Defense Explorer Edition, an accessible version that lets security teams test and run systematic red teaming for their own applications and AI agents, and get a detailed evaluation report that can serve as the basis for an audit and a medium-term action plan.
Interest in AI Security is growing exponentially in the local market precisely because it addresses a real and urgent problem: companies have already started using AI and GenAI, often without centralized planning, while security processes and governance haven’t always kept pace with the speed of adoption.
As more and more organizations use GenAI tools without management or IT even knowing, the conversation shouldn’t start with the usual question, “Which AI solution should we adopt?” — it should start with a more fundamental, riskier one: “What AI do we already have, and how exposed are we?” This is exactly where Datanet Systems can start: with a comprehensive analysis of the organization’s AI application and usage exposure, to identify the real, priority risks and then build a protection strategy suited to the existing infrastructure.
For more information, contact the Datanet Systems Security Division by email at sales@datanets.ro.
Access is the new security perimeter....