Cisco has revealed its AI Security and Safety Framework to support and manage risks in modern systems.
This unified structure combines both security and safety into a single model to reduce gaps and misalignment in activities.
This will enforce protection on AI tools utilized in customer interactions, reducing the risk of unsafe customer outputs.
The threat of AI is still recognized as a real risk, despite the pace of adoption being at its highest level.
This has likely been a result of knowledge gaps in AI security, with the technology evolving at a rapid pace, many organizations have not yet understood how to control its behavior within an unpredictable ecosystem.
According to Cisco’s 2025 AI Readiness Index, many companies are still unprepared to face this danger, with only 29% of those surveyed believing they’re adequately prepared to defend themselves against these threats.
In attempting to keep up with the rising demand for AI products, these results suggest that CX leaders are willing to encounter this risk rather than fall behind in AI deployment.
This could result in unwanted exposure and failure of customer and brand data without a management plan in place, elevating risk likelihood due to low responsible adoption and a reactive-first solution.
Furthermore, only a third of these companies admitted to having a formal change-management plan, with the remaining respondents likely relying on incomplete risk reviews and immature organizational adoption.
With many companies not having yet adopted a framework, they can expose themselves to risks in agentic, supply chain, and multimodal vulnerabilities.
This can lead to inconsistencies in service teams, with customer impact likely not being assessed in advance, potentially resulting in incorrect information, sensitive data exposure, or reduced overall quality of customer interactions.
To tackle this issue, Cisco’s AI Security Framework offers a unified, end-to-end solution that covers both safety and security, as well as educating organizations on their AI risks.
It also acts as a vendor-agnostic framework, allowing organizations to continue using their tools with the solution without modifying its architecture, supporting vendors across multiple environments for durable and flexible capabilities.
This strategy is designed to improve a company’s readiness and AI risk understanding by defining threat types and failure modes so organizations can identify what risks they are prepared to handle and the ones they can’t.
Furthermore, it also supports formal change management by providing a common risk taxonomy to ensure risks are explained and organized into priorities for the company, as well as identifying recurring or unresolved ones.
This allows individual teams to understand the current threat landscape using shared language and mental model, working to support established infrastructure, complex supply chains, company policies, and human-in-the-loop interactions to determine a likely security outcome.
This ensures a company’s AI accountability, protection, and assurance for a system’s ethical and reliable attitude in alignment with its values and organizational policies.
To ensure the framework adopts these expectations, Cisco has included five built-in design elements to explain how AI is used today and that older frameworks are no longer sufficient for current adoption.
1. Threat and Harm Integration
Cisco framework combines both security and safety to allow organizations to understand an attack and witness a fuller impact on a customer.
During an attack, the framework will allow companies to build better defenses against technical exploits by having security and safety teams collaborate to address AI risks.
In the case of traditional frameworks, teams will attempt to solve these two problems separately, retaining only the security or safety information, likely leading to context gaps in necessary information.
For CX teams, this means that with security issues and customer harm being so intertwined, an attack on an AI system by a cybercriminal could result in poor customer experience with unsafe or incorrect answers, or possibly expose sensitive information during an interaction.
2. AI Lifecycle Awareness
The AI Security Framework is also designed to determine risks by examining an AI system’s entire lifecycle, rather than simply reviewing development and deployment periods.
By collecting all its recorded data, this will allow teams to identify various security and safety concerns outside of model or AI deployments and assess data collection risks to ensure the whole system is behaving properly.
And by mapping risk appearance at each stage, teams can understand how threats have evolved within the system.
This ensures AI system risks are caught early so CX teams can offer consistent customer experiences during updates and feature rollouts.
3. Multi-Agent Orchestration
This orchestration capability allows the framework to acknowledge emerging or likely risks during high AI system interaction periods, considering all systems involved rather than looking at each in isolation.
During AI collaboration, risks and exploits are more likely to occur with data and communication sharing. However, the framework ensures that these tools behave safely and consistently with each other to avoid external impact.
This means that CX teams can prevent customers from receiving harmful outputs during multi-agent collaboration by utilizing tools such as chatbots and customer support agents simultaneously.
4. Multimodality Considerations
The security framework can recognize that AI systems are becoming more multimodal, being more willing to accept and produce many inputs.
However, this can increase threat levels through possible corruptions in capabilities such as voice command, image uploads, and video sharing, unintentionally causing problems that may bypass traditional text-based safeguards.




