Robust Intelligence

Security for AI acquired

Market readinessHow well the company can compete in its security market, scored across eight dimensions against public evidence. Emerging: Market readiness of 24 or below. Below the typical band, where few analyzed companies sit.
DefensibilityHow well the company holds its position if competitors catch up on features, scored across seven dimensions against public evidence. Contested: Defensibility of 13 to 14, the typical band, where a moat exists but is under pressure.
Last updated 2026-07-17

All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.

Executive Summary

Robust Intelligence no longer sells separately in the record. Cisco bought it in 2024, calls it foundational to Cisco AI Defense and Foundation AI (s1), and enforces the guardrails inside the network without agents or libraries. The capability is hard to build, and s2 shows an assessment initiated with a simple API call when a model enters a registry. Its detections map to OWASP and MITRE ATLAS, a shared vocabulary that does not force a buyer to stay. Cisco places the capability inside products its install base already runs, conversion into sales undocumented, so it is easy to reach for a Cisco customer and hard to price against a standalone rival. It stays defensible while a buyer standardizes on Cisco and becomes exposed the moment that buyer evaluates the capability on its own.

Sourced Details

Description Robust Intelligence, now part of Cisco AI Defense, tests AI models for safety and security vulnerabilities using algorithmic red teaming and protects running AI applications with runtime guardrails that block adversarial attacks. [f1]
Acquisition Cisco, announced 2024-08-26 , now Cisco AI Defense [f2]
Deployment SaaS, Self-hosted [f3]

Products

Product What it does
Robust Intelligence Algorithmic red teaming and runtime guardrails for AI models and apps: tests models against attacks and screens prompts, responses, and agent workflows. Now part of Cisco AI Defense.

Matrix Coverage

AI Defense Matrix

GovernIdentifyProtectDetectRespondRecover
AI-Workload Platforms Inference servers, training platforms, vector DB platforms, and the model-loading supply chain.
AI Orchestration Tools Agentic orchestration tools, plus their plugins, skills, hooks, system prompts, scaffolding, harnesses, configuration settings, and MCP clients on user devices.
AI-Generated Code Code produced by AI tools, AI-assisted reviews, AI-generated infrastructure-as-code and tests, and vibe-coded apps that bypass CI/CD.
AI Gateways & Routers MCP proxies and gateways, LLM routers, outbound AI-service traffic, shadow AI egress, and model-registry traffic.
AI Model Model weights, fine-tuning checkpoints, model cards, registries, AIBOM, and the third-party LLMs your enterprise consumes.
Training Data Datasets used for training, fine-tuning, and continued learning.
Runtime AI Data User prompts, inference inputs, RAG content, vector DB content, persistent agent memory, and interaction history.
AI Agent Identities AI agents as non-human principals, plus credentials, keys, permission scopes, service accounts, and delegation chains across agents and tools.

Robust Intelligence tests AI models against attacks and screens prompts, responses, and agent workflows with algorithmic red teaming and runtime guardrails, and is now part of Cisco AI Defense. It is mapped to the AI Defense Matrix. [f4]

Market Readiness

How well the company can compete in its security market, scored across eight dimensions against public evidence.

Emerging 22 /40 Emerging: Market readiness of 24 or below. Below the typical band, where few analyzed companies sit.
Dimension Score Rationale
Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. 3/5 The line names the enterprise AI buyer and maps detections to OWASP and MITRE ATLAS, but the pain stays qualitative with no independent quantification, so it reads as present and credible rather than quantified across non-vendor sources. [s2, s4, s5]
Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. 3/5 Cisco pages document algorithmic validation, runtime guardrails, and supply chain scanning in detail. The team's Tree of Attacks paper shows research depth in algorithmic red teaming, but the cited pages do not tie that published method to the productized validation engine, so it reads as team research rather than an external evidence point for the product, holding depth at the vendor-detail level. [s2, s7, s9]
Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. 3/5 Enterprises moving models into production is a credible enabler, but the demand cited is the 2024 Cisco acquisition (an acquirer entering the category) rather than buyer-side RFP, budget, or analyst signals, so timing holds at the credible-enabler level. [s5, s1, s4]
Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. 3/5 Press identifies founder Yaron Singer as a mathematician and professor, and the team's Tree of Attacks paper at NeurIPS 2024 is a concrete publication signal. That single flagship paper and the post-acquisition move under Cisco fall short of the sustained, multiply-evidenced publication record or in-domain exit the next level needs. [s5, s8, s9, s10]
GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. 3/5 A public-company acquisition by Cisco, recorded in Cisco's own quarterly filing, is a real validation signal, but the line shows no named reference customers, no disclosed revenue, and distribution now runs through the parent, which the product-line read excludes, so traction sits present rather than corroborated at scale. [s1, s5, s6, s11]
Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. 2/5 Funding totals conflict across sources and the Cisco acquisition closed on undisclosed terms, so capital efficiency cannot be verified, leaving it at the unverifiable-funding level rather than a confirmed efficient exit. [s5, s1]
Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. 3/5 AI security is still a forming and contested category that competing vendors crowd, and the line's placement leaned on the Cisco AI Defense framing, so it fits an emerging slot rather than an established one buyers place unaided. [s1, s3, s5]
Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. 2/5 The capability was not just absorbable, it was absorbed and dissolved. Where the acquired peer folded into a suite that still names its products, Robust Intelligence was rebuilt into Cisco AI Defense and Foundation AI with no standalone product surviving, the outcome this dimension warns against, placing it one below the cluster. [s1, s3]
Business Risks The validation and guardrail capability is substitutable at the interface, so a Cisco buyer could choose Lakera, Protect AI inside Palo Alto, or Google Model Armor and port dependent workflows with limited reabsorption…
  • The validation and guardrail capability is substitutable at the interface, so a Cisco buyer could choose Lakera, Protect AI inside Palo Alto, or Google Model Armor and port dependent workflows with limited reabsorption.
  • Because the line was dissolved into Cisco AI Defense and Foundation AI, its roadmap now depends on Cisco priorities, and a capability that does not fit the network-fabric model could be deprioritized.
  • The timing window can close within three to five years if frontier model vendors ship native validation and guardrails, commoditizing the enabling gap that made the line necessary.
  • Detections aligned to OWASP and MITRE ATLAS are shared reference points rather than a proprietary lock, so the alignment does not by itself keep a buyer from switching.
  • Revenue and funding figures conflict across public sources, so any claim about the line's pre-acquisition scale depends on press estimates rather than confirmed numbers.
Problem & Market Robust Intelligence targets the enterprise that moves AI models and applications into production and needs to know they will not fail under attack. Cisco describes the line validating a model's safety and security vulnerabilities and protecting against emerging threats, and press describes protection across the model lifecycle from development to production. The pain is concrete and ties to recognized industry frameworks. Detections and tests map to OWASP and MITRE ATLAS, the shared reference points enterprises use to reason about AI risk, and the supply chain scanning blocks malicious model files that can run arbitrary code. This is a problem buyers can state in their own budget terms rather than one the vendor has to teach…

Robust Intelligence targets the enterprise that moves AI models and applications into production and needs to know they will not fail under attack. Cisco describes the line validating a model's safety and security vulnerabilities and protecting against emerging threats, and press describes protection across the model lifecycle from development to production.

The pain is concrete and ties to recognized industry frameworks. Detections and tests map to OWASP and MITRE ATLAS, the shared reference points enterprises use to reason about AI risk, and the supply chain scanning blocks malicious model files that can run arbitrary code. This is a problem buyers can state in their own budget terms rather than one the vendor has to teach. [s2, s4, s7]

Product Capabilities The line does three things that the public record documents in detail…

The line does three things that the public record documents in detail. It runs an automated, algorithmic assessment of a model's vulnerabilities, kept current by AI Threat Research teams. It enforces runtime guardrails on AI applications. It scans open-source models, data, and files to block supply chain threats, with an assessment initiated by a simple API call.

Cisco frames the validation output as trust that models are safe and secure, which is judgment about model behavior delivered through automation rather than software sold for its own sake. The capability is deep and specific, but the same validate-and-guardrail shape is what competing vendors offer, so depth here is table stakes for the category rather than a differentiator on its own.

The team also published the method behind its red teaming. Tree of Attacks, accepted at NeurIPS 2024, automatically generates jailbreaks against state-of-the-art models and gets past guardrails such as LlamaGuard, which shows the research depth behind the line even though the public record does not tie that specific method to the productized validation engine. [s2, s7, s3, s9, s10]

Competitive Positioning Inside Cisco the line competes on distribution rather than on a feature gap. Cisco enforces AI security at the network level without agents or libraries, and press says Cisco embeds the technology into its security and networking products, which reaches buyers that a standalone vendor would have to sell one at a time. The capability itself stays contested. Lakera, Protect AI inside Palo Alto Networks, TrojAI, HiddenLayer, and Google Model Armor all screen prompts and validate or defend models on overlapping assets. Cisco the company owns the distribution advantage, not the validation technology, so a buyer who is not already standardizing on Cisco can reach the same capability elsewhere…

Inside Cisco the line competes on distribution rather than on a feature gap. Cisco enforces AI security at the network level without agents or libraries, and press says Cisco embeds the technology into its security and networking products, which reaches buyers that a standalone vendor would have to sell one at a time.

The capability itself stays contested. Lakera, Protect AI inside Palo Alto Networks, TrojAI, HiddenLayer, and Google Model Armor all screen prompts and validate or defend models on overlapping assets. Cisco the company owns the distribution advantage, not the validation technology, so a buyer who is not already standardizing on Cisco can reach the same capability elsewhere. [s3, s6]

Go-to-Market & Traction The acquisition is the traction story…

The acquisition is the traction story. Cisco, a public company, bought the line in 2024 to enter AI security, the strongest demand signal a young AI-security capability can produce, and press positioned the platform for enterprise AI security across the model lifecycle ahead of the deal. Robust Intelligence also appears by name in Cisco's SEC filings, including its fiscal 2025 Form 10-K and an 8-K.

Distribution now runs through Cisco. The line reaches buyers through the Cisco Security Cloud and the installed base of Cisco networking and security products rather than a direct sales motion the line built on its own. That reach is real, but it measures Cisco's market position, so it should be read as an indirect signal for the line rather than independent proof the technology wins head to head. [s1, s5, s6, s11]

Team & Credibility Press names founder Yaron Singer, an Israeli mathematician and professor, and Cisco describes the line pioneering AI-security research that includes algorithmic red teaming. That is verifiable domain pedigree and a real research record, and the team's Tree of Attacks paper at NeurIPS 2024 puts a concrete publication behind it. The public record here does not establish the sustained, category-defining publication record that would lift this above the peer cluster, and after the acquisition the team and roadmap fall under Cisco. So the credibility is real and sits level with the AI-security peers rather than above them…

Press names founder Yaron Singer, an Israeli mathematician and professor, and Cisco describes the line pioneering AI-security research that includes algorithmic red teaming. That is verifiable domain pedigree and a real research record, and the team's Tree of Attacks paper at NeurIPS 2024 puts a concrete publication behind it.

The public record here does not establish the sustained, category-defining publication record that would lift this above the peer cluster, and after the acquisition the team and roadmap fall under Cisco. So the credibility is real and sits level with the AI-security peers rather than above them. [s5, s8, s9, s10]

Trust Readiness The line aligns its work to recognized external frameworks, mapping detections and tests to OWASP and MITRE ATLAS, which gives enterprise buyers a shared vocabulary for evaluating coverage. Supply chain scanning that blocks malicious model files capable of arbitrary code execution speaks directly to a security buyer's procurement checklist. Operating inside Cisco adds the trust an enterprise vendor carries into regulated environments. The framework alignment is reference-point compatibility rather than a certification that locks a buyer in, so it supports adoption without by itself raising the cost of leaving…

The line aligns its work to recognized external frameworks, mapping detections and tests to OWASP and MITRE ATLAS, which gives enterprise buyers a shared vocabulary for evaluating coverage. Supply chain scanning that blocks malicious model files capable of arbitrary code execution speaks directly to a security buyer's procurement checklist.

Operating inside Cisco adds the trust an enterprise vendor carries into regulated environments. The framework alignment is reference-point compatibility rather than a certification that locks a buyer in, so it supports adoption without by itself raising the cost of leaving. [s4, s7, s3]

Competitors Lakera, Protect AI, TrojAI, HiddenLayer, Google Model Armor…
Company Relationship Note Compare
Lakera competes with AI runtime guardrails and prompt screening for the same enterprise AI buyer.
Protect AI competes with Model scanning, AI red teaming, and runtime defense, now inside Palo Alto Networks. N/AWe scored these companies at different scopes, so the totals measure different things.
TrojAI competes with AI model and application validation plus runtime protection on overlapping assets. N/AWe scored these companies at different scopes, so the totals measure different things.
HiddenLayer competes with Model scanning and detection across model, runtime, and orchestration assets. N/AWe scored these companies at different scopes, so the totals measure different things.
Google Model Armor competes with Cloud-platform AI firewall screening prompts, responses, and agent interactions.

Add analyzed competitors to compare them side by side with Robust Intelligence.

Strategy Deep Dive

A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.

Defensibility

Contested 14 /21 Contested: Defensibility of 13 to 14, the typical band, where a moat exists but is under pressure. reinforce or reposition

The line is structurally durable for a Cisco customer and exposed for anyone else. Its strength is a hard problem and a strong enterprise buyer, and inside Cisco it gained a network-fabric position, the acquirer's architecture lent to the line. Its weakness is that the capability carries no compliance lock and the record shows no singular line-owned dataset, though s2 describes continuously updated validation. The durability the line now has is Cisco's distribution, real but the acquirer's. Latent and not yet evidenced is that the line's algorithmic red teaming spans many customers' models, so the AI Threat Research function could aggregate cross-customer model-vulnerability findings a rival could not assemble.

Dimension Score Rationale
Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. 1/3 Cisco AI Defense is screening and validation software the customer configures and operates, a product rather than a judgment or accountability service. The trust framing is the software's own output, not a human-validated delivery layer.
Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. 2/3 Replacing the line means re-integrating and re-tuning the guardrail and validation policies configured across a customer's AI estate, meaningful line-level friction short of lock-in, while the deeper network-fabric insertion belongs to Cisco's architecture rather than the line.
Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. 1/3 Mapping detections and tests to OWASP and MITRE ATLAS is alignment to shared reference points, not a regulatory or certification gate that forces a buyer to stay, so the line earns no compliance lock.
Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. 3/3 Continuous algorithmic red teaming and adversarial validation of models is a genuinely hard problem that few teams can solve, backed by a dedicated AI Threat Research function and a published method, Tree of Attacks at NeurIPS 2024, matching the cluster's top score on complexity.
Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. 3/3 The buyer the line addresses is the enterprise running AI in production with the security budget and the regulatory exposure to fund model safety, a strong buyer identity that holds on the line's own evidence. Cisco's enterprise install base is distribution context that widens reach, not what earns the score.
Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. 3/3 The line's validation and guardrail capability runs inline in the path AI traffic passes through, infrastructure other applications route model calls through, the basis on which the corpus scores inline AI-security lines.
Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. 1/3 The continuously updated threat research is a maintained operational asset, not a named non-public cross-customer corpus a new entrant could not assemble. It is less singular than an independent leader's large interaction dataset, so the data position is replicable rather than a proprietary moat.
Strategic Market Segmentation The line targets the enterprise running AI models and applications in production, the buyer with the budget and the regulatory exposure to care about model safety. Cisco describes automated assessment of a model's vulnerabilities and protection against emerging threats, and the acquisition coverage names the same segment when it reports that the platform protected AI models throughout their lifecycle, from development to production, which names a clear segment rather than a broad market. Inside Cisco the segment is defined by reach more than by selection. The documented buyer path runs through Cisco networking and security products, where the technology is inserted rather than sold as a separate evaluation (s4, s6), with conversion undocumented. That places the capability where a standalone vendor could cover, but it also ties the segment to Cisco's existing accounts rather than to buyers choosing the validation capability on its own…

The line targets the enterprise running AI models and applications in production, the buyer with the budget and the regulatory exposure to care about model safety. Cisco describes automated assessment of a model's vulnerabilities and protection against emerging threats, and the acquisition coverage names the same segment when it reports that the platform protected AI models throughout their lifecycle, from development to production, which names a clear segment rather than a broad market.

Inside Cisco the segment is defined by reach more than by selection. The documented buyer path runs through Cisco networking and security products, where the technology is inserted rather than sold as a separate evaluation (s4, s6), with conversion undocumented. That places the capability where a standalone vendor could cover, but it also ties the segment to Cisco's existing accounts rather than to buyers choosing the validation capability on its own.

Product Capabilities & AI Advantages The capability is specific and hard to build…

The capability is specific and hard to build. The line runs an automated, algorithmic assessment of a model's safety and security vulnerabilities, kept current by AI Threat Research teams, and enforces runtime guardrails on AI applications. It also scans open-source models, data, and files to block supply chain threats such as malicious model files that allow arbitrary code execution.

The AI advantage is the continuously updated threat research that feeds the validation, an accumulating asset rather than a static ruleset. The limit is that no cited source sizes how distinctive the validate-and-guardrail shape is, and s2 shows a registry-triggered API entry point, with output portability undocumented. The durable part is the continuously updated threat research and the network-level enforcement, with no named corpus in the record, rather than the assessment interface.

The team's red-teaming method is also public research. Tree of Attacks, accepted at NeurIPS 2024, automatically jailbreaks state-of-the-art models and gets past guardrails such as LlamaGuard, which shows the research depth behind the line and confirms the core technique is published rather than held as a secret.

Sales Engagement & Go-to-Market Go-to-market now runs entirely through Cisco…

Go-to-market now runs entirely through Cisco. Before the deal the company positioned a standalone lifecycle-protection platform for enterprise AI security, but the defining motion today is distribution through the Cisco Security Cloud and the installed base of Cisco networking and security products. Robust Intelligence also appears by name in Cisco's SEC filings, including its fiscal 2025 Form 10-K and an 8-K, even as the product folded into AI Defense.

The record shows the integration, not installed-base conversion into sales. Cisco inserts the technology into existing data flows and products (s3, s4, s6), and what that placement converts into won deals the record does not document. The tradeoff is that the motion measures Cisco's market position rather than the line's independent ability to win head-to-head evaluations, so the strength here is the acquirer's, lent to the line.

Pricing Model The public record does not expose a standalone price for the line, which is consistent with a capability now sold inside Cisco AI Defense rather than as a separate product. Cisco does not publish AI Defense pricing on the pages reviewed, the pattern of a negotiated enterprise motion. The strategic consequence is that no line-specific charging unit is visible in the record. Its value ships inside AI Defense and, further upstream, the Cisco platform relationship, with packaging details undocumented. That makes the capability easier to adopt for an existing Cisco customer and harder to evaluate on price against any standalone alternative, since no line price is published…

The public record does not expose a standalone price for the line, which is consistent with a capability now sold inside Cisco AI Defense rather than as a separate product. Cisco does not publish AI Defense pricing on the pages reviewed, the pattern of a negotiated enterprise motion.

The strategic consequence is that no line-specific charging unit is visible in the record. Its value ships inside AI Defense and, further upstream, the Cisco platform relationship, with packaging details undocumented. That makes the capability easier to adopt for an existing Cisco customer and harder to evaluate on price against any standalone alternative, since no line price is published.

Product Delivery & Operations Delivery is the line's clearest structural change…

Delivery is the line's clearest structural change. Cisco enforces AI security at the network level without the need for agents or libraries, which decouples AI development from security and removes the integration burden a per-application tool imposes. Validation can be initiated with a simple API call when a new model enters a registry.

Operating inside Cisco also means the threat research that drives validation is maintained by AI Threat Research teams as a continuous service rather than a customer-run process. That operational model rides Cisco's network enforcement and research organization, with no competitor comparison in the record.

Earning Customers' Trust The line earns trust through external framework alignment and the weight of its acquirer. Detections and tests map to OWASP and MITRE ATLAS, the reference points enterprise buyers use to reason about AI risk, and the supply chain scanning addresses a concrete procurement concern by blocking malicious model files that can execute code. Sitting inside Cisco adds the assurance an established enterprise vendor carries into regulated environments. The alignment is shared-vocabulary compatibility rather than a certification that forces a buyer to stay, so it lowers the barrier to adoption without by itself raising the cost of leaving for the capability on its own…

The line earns trust through external framework alignment and the weight of its acquirer. Detections and tests map to OWASP and MITRE ATLAS, the reference points enterprise buyers use to reason about AI risk, and the supply chain scanning addresses a concrete procurement concern by blocking malicious model files that can execute code.

Sitting inside Cisco adds the assurance an established enterprise vendor carries into regulated environments. The alignment is shared-vocabulary compatibility rather than a certification that forces a buyer to stay, so it lowers the barrier to adoption without by itself raising the cost of leaving for the capability on its own.

Platform Strategy & Ecosystem Positioning The line is now a component of a platform rather than a platform itself…

The line is now a component of a platform rather than a platform itself. Cisco positions the technology as part of the Security Cloud, inserted into networking and security products so that telemetry and enforcement share the network fabric. Gillis said the technology will accelerate existing Cisco bets such as adaptive policy enforcement and attack prediction, which is platform reinforcement language.

This is where the absorbed-pioneer pattern is sharpest. The capability rides Cisco's network visibility, product integration, and threat-intelligence updates, with no shared proprietary corpus evidenced in the record. Its fate is tied to whether it keeps earning a place in the Cisco architecture rather than to its own ecosystem of integrations.

Team & Execution Capability The founding team carried credible domain pedigree…

The founding team carried credible domain pedigree. Press names founder Yaron Singer, an Israeli mathematician and professor, and Cisco describes the line pioneering AI-security research that includes algorithmic red teaming. That pedigree and the research output behind it are real assets the acquisition valued, and the team's Tree of Attacks paper at NeurIPS 2024 puts a concrete publication behind the claim.

After the acquisition the team and roadmap fall under Cisco, and the line is described as foundational to Cisco AI Defense and Foundation AI. The strategic question shifts from whether the team can build to whether the capability retains dedicated investment inside a much larger organization, where competing priorities decide which bets get accelerated.

Sources

Company Detail Sources (4)
Id Source Tier Accessed
f1 Cisco: AI Defense product page official 2026-07-09
f2 Cisco announces intent to acquire Robust Intelligence (with completion update) official 2026-06-07
f3 AI Defense Matrix Catalog entry other 2026-06-07
f4 AI Defense Matrix Catalog mapping other 2026-06-23
Profile Analysis Sources (11)
Id Source Tier Accessed
s1 Robust Intelligence is now part of Cisco
“The company was acquired by Cisco in October 2024 and has been foundational to the development of Cisco AI Defense and Cisco Foundation AI.”
official 2026-06-18
s2 AI Model and Application Validation
“AI model and application validation performs an automated, algorithmic assessment of a model's safety and security vulnerabilities, continuously updated through AI Threat Research teams.”
official 2026-06-14
s3 Cisco AI Defense
“Cisco enforces AI security at the network-level without the need for agents or libraries, decoupling AI development from security.”
official 2026-06-14
s4 Cisco announces intent to acquire Robust Intelligence (with completion update)
“All detections and tests are mapped to industry and regulatory standards like OWASP and MITRE ATLAS.”
official 2026-06-18
s5 Cisco to acquire Yaron Singer's Robust Intelligence to enhance AI security
“Robust Intelligence's platform offers protection for AI models throughout their lifecycle, from development to production. Through advanced automation and risk mitigation, Robust Intelligence helps organizations to securely deploy AI applications while adhering to industry and regulatory standards.”
press 2026-06-18
s6 Cisco Bolsters AI Security by Buying Robust Intelligence
“The acquisition of Robust Intelligence will help Cisco integrate advanced AI defense features into its existing security and networking products, giving customers better control and visibility over AI traffic.”
press 2026-06-18
s7 Protect against AI supply chain attacks
“AI Validation automatically scans open-source models, data, and files to block supply chain threats, such as malicious model files that can allow for arbitrary code execution in your environment.”
official 2026-06-14
s8 Robust Intelligence is at the core of Cisco Foundation AI and Cisco AI Defense
“Robust Intelligence is widely recognized for pioneering the AI security category with cutting-edge research and product innovation, including algorithmic red teaming and the industry's first AI Firewall.”
official 2026-06-18
s9 Robust Intelligence and Yale, Tree of Attacks: jailbreaking black-box LLMs automatically
“In this work, we present Tree of Attacks with Pruning (TAP), an automated method for generating jailbreaks that only requires black-box access to the target LLM.”
research 2026-06-30
s10 Tree of Attacks accepted at NeurIPS 2024 (arXiv listing)
“Accepted for presentation at NeurIPS 2024.”
research 2026-06-30
s11 SEC EDGAR full-text search: Robust Intelligence named in Cisco Systems filings (forms 10-K, 8-K, DEF 14A, S-8)
“"match_phrase":{"doc_text":"Robust Intelligence"} ... "display_names":["CISCO SYSTEMS, INC. (CSCO) (CIK 0000858877)"] ... "form":"10-K" ... "file_date":"2025-09-03" ... "form":"8-K"”
regulatory 2026-06-30
Deep-Dive Sources (12)
Id Source Tier Accessed
s1 Robust Intelligence is now part of Cisco
“The company was acquired by Cisco in October 2024 and has been foundational to the development of Cisco AI Defense and Cisco Foundation AI.”
official 2026-06-14
s2 AI Model and Application Validation
“AI model and application validation performs an automated, algorithmic assessment of a model's safety and security vulnerabilities, continuously updated through AI Threat Research teams.”
official 2026-06-18
s3 Cisco AI Defense
“Cisco enforces AI security at the network-level without the need for agents or libraries, decoupling AI development from security.”
official 2026-06-14
s4 Cisco announces intent to acquire Robust Intelligence (with completion update)
“All detections and tests are mapped to industry and regulatory standards like OWASP and MITRE ATLAS.”
official 2026-06-14
s5 Cisco to acquire Yaron Singer's Robust Intelligence to enhance AI security
“Robust Intelligence's platform offers protection for AI models throughout their lifecycle, from development to production. Cisco has announced its intention to acquire Robust Intelligence, a company founded by Israeli mathematician Professor Yaron Singer. The purchase amount was not disclosed.”
press 2026-06-18
s6 Cisco Bolsters AI Security by Buying Robust Intelligence
“The acquisition of Robust Intelligence will help Cisco integrate advanced AI defense features into its existing security and networking products, giving customers better control and visibility over AI traffic.”
press 2026-06-18
s7 Protect against AI supply chain attacks
“AI Validation automatically scans open-source models, data, and files to block supply chain threats, such as malicious model files that can allow for arbitrary code execution in your environment.”
official 2026-06-14
s8 Robust Intelligence is at the core of Cisco Foundation AI and Cisco AI Defense
“Robust Intelligence is widely recognized for pioneering the AI security category with cutting-edge research and product innovation, including algorithmic red teaming and the industry's first AI Firewall.”
official 2026-06-14
s9 Acquisition will accelerate existing Cisco bets
“Gillis said Robust Intelligence's technology and expertise will accelerate existing Cisco bets in areas such as simplified configuration, attack prediction, adaptive policy enforcement and user experience.”
press 2026-06-14
s10 Robust Intelligence and Yale, Tree of Attacks: jailbreaking black-box LLMs automatically
“In this work, we present Tree of Attacks with Pruning (TAP), an automated method for generating jailbreaks that only requires black-box access to the target LLM.”
research 2026-06-30
s11 Tree of Attacks accepted at NeurIPS 2024 (arXiv listing)
“Accepted for presentation at NeurIPS 2024.”
research 2026-06-30
s12 SEC EDGAR full-text search: Robust Intelligence named in Cisco Systems filings (forms 10-K, 8-K, DEF 14A, S-8)
“"match_phrase":{"doc_text":"Robust Intelligence"} ... "display_names":["CISCO SYSTEMS, INC. (CSCO) (CIK 0000858877)"] ... "form":"10-K" ... "file_date":"2025-09-03" ... "form":"8-K"”
regulatory 2026-06-30

Disclaimer

This content is provided "as is" with no warranties.

This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.

The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.

Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.

The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.

To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.

Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.

Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.