Secure AI Assistants with Cisco's Advanced Defense System

·

Teams are rapidly integrating Claude Enterprise, an artificial intelligence (AI) assistant, into their workflows. However, this integration also creates a new attack surface for potential security threats. The prompt used to interact with the AI assistant is now exposed and vulnerable to manipulation by malicious actors.

The traditional approach to data loss prevention focuses on identifying sensitive data leaving the organization’s systems. However, this method does not account for the manipulation of the model itself or its tools. A jailbreak can attempt to bypass the assistant’s guardrails, while a prompt injection hidden in a shared file can hijack an agent and turn it against the user.

Anthropic recently introduced inference hooks, which enable organizations to send each governed prompt to an AI security service before inference begins. When configured, this hook allows Cisco AI Defense to inspect the prompt for artificial intelligence threats and return a verdict of allow or deny. This integration is crucial in protecting against potential attacks on the model and its tools.

The focus on AI-first defense by Cisco sets it apart from traditional data loss prevention methods. While these methods are designed to identify sensitive data, Cisco’s approach reads intent and catches prompt injection and jailbreaks that target the model, its tools, and agents acting on its behalf. This evaluation also includes agent activity in the conversation transcript.

When Claude Code or Cowork calls a tool, including those connected over the Model Context Protocol (MCP), the transcript can include the tool call and its result. Cisco AI Defense runs both privacy and manipulation guardrails on this transcript: it flags sensitive data as traditional data loss prevention would, plus identifies injection and jailbreak attempts that data loss prevention was never designed to detect.

This reflects how we think about the entire problem of securing AI assistants in business environments. The Claude Enterprise integration is one runtime enforcement point within a broader platform. Cisco AI Defense secures the full AI lifecycle by discovering and inventorying AI assets, assessing their risk through validation, red-teaming, and supply chain and model scanning, and protecting them at runtime with guardrails like this one.

The result of this integration is real-time protection delivered through the hook, an additional layer for comprehensive AI coverage that adds enforcement without requiring infrastructure changes to the user’s workflow. This gives security leaders a direct enforcement point for AI policy across governed Claude Enterprise requests. Enterprise users can maintain their fast and native experience while using Claude.

For teams relying on data analysis tools like Claude Enterprise, this integration provides an essential layer of protection against potential threats. By leveraging Cisco AI Defense, organizations can ensure the secure use of these powerful AI assistants in their business environments.

Cisco AI Defense plugs into Anthropic’s inference hooks to provide inline protection for every governed prompt: The prompt is sent for inspection; Claude Enterprise sends each governed prompt across Claude, Code, and Cowork to Cisco AI Defense through the hook before model execution. This ensures that potential threats are caught early in the process.

The request is cryptographically verified using a one-time signing secret. Cisco AI Defense checks this signature and confirms the request’s authenticity before inspecting it for potential threats. The conversation transcript, including tool calls and their results, is then evaluated against the organization’s runtime policy for prompt injection, jailbreaks, tool exploitation, and sensitive data.

A verdict returns before inference begins: allow or deny. Safe prompts continue through to model execution; a malicious prompt is blocked, preventing potential harm.

Cisco AI Defense inspects both prompts and responses in this integration. This uses Anthropic’s inference hook, which currently fires on each governed prompt before the model runs. As Anthropic extends the hook to responses, response-side enforcement can use the same integration path. Over time, we expect this enforcement to become a native part of the Cisco AI Defense Inspect API.

This integration is available today with Claude Enterprise and inference hooks in beta. Users can try it out by visiting our developer portal’s playground; enter a prompt and watch the live inspection and verdict. Schedule time with our team to see how Cisco AI Defense stands up against AI threats.