BotBeat
...
← Back

> ▌

CiscoCisco
OPEN SOURCECisco2026-05-23

Cisco Open-Sources Foundry Security Spec for Agentic AI Evaluation

Key Takeaways

  • ▸Cisco released Foundry as an open specification (not code) for agentic AI security evaluation, based on internal production experience across multiple iterations and deployment models
  • ▸The specification is deliberately underspecified at organization-specific decision points, enabling implementation on any cloud provider, issue tracker, or development stack
  • ▸Foundry's detection-to-prevention flywheel combines rule-based scanning with exploratory agents, turning detection gaps into corpus improvements that prevent bugs at the keystroke level
Source:
Hacker Newshttps://github.com/CiscoDevNet/foundry-security-spec↗

Summary

Cisco's Advanced Security Initiatives Group has released Foundry, an open specification for evaluating agentic AI security. Rather than open-sourcing proprietary code tightly coupled to Cisco's infrastructure, the company distilled years of production experience into a portable, organization-neutral specification designed for any deployment stack. The specification includes eight core agent roles, five extension roles, 11 inviolable principles, and approximately 130 functional requirements—each with inline rationale explaining why it exists. The approach emphasizes flexibility, leaving infrastructure-specific decisions as explicit open questions for organizations to answer based on their own environment. At the core of Foundry's design is a 'detection-to-prevention flywheel' that combines systematic rule-based detection with exploratory agent-driven hunting. When exploration identifies gaps in detection, those findings are generalized into new or revised rules that feed into the CodeGuard corpus—which Cisco previously open-sourced to the Coalition for Secure AI (CoSAI). This creates a continuous improvement loop: the same bugs detected during evaluation become prevention rules in developers' coding assistants, embedding knowledge from each evaluation into the entire organization before the next assessment cycle begins.

  • The release integrates with CodeGuard, an OASIS open standard Cisco previously donated to the Coalition for Secure AI, creating a unified ecosystem for detection and prevention
AI AgentsCybersecurityAI Safety & AlignmentOpen Source

More from Cisco

CiscoCisco
RESEARCH

Cisco Tests AI for Security Reports, Finds 50% Time Savings But Significant Reliability Gaps

2026-05-22
CiscoCisco
OPEN SOURCE

Cisco Open Sources Model Provenance Kit to Secure AI Supply Chains

2026-05-06
CiscoCisco
INDUSTRY REPORT

AI-Driven Talent Exodus Deepens Wireless Networking Skills Crisis, Cisco Report Shows

2026-04-20

Comments

Suggested

GitHubGitHub
PRODUCT LAUNCH

GitHub Launches Copilot Desktop App for Agent-Driven Development

2026-05-23
Verytis (Community/Independent)Verytis (Community/Independent)
PRODUCT LAUNCH

Verytis Brings Shared Error Memory to AI Coding Agents via MCP

2026-05-23
Google / AlphabetGoogle / Alphabet
PRODUCT LAUNCH

Google is pitching an AI agent ecosystem to consumers who may not buy it

2026-05-23
← Back to news
© 2026 BotBeat
AboutPrivacy PolicyTerms of ServiceContact Us