Analyst(s): Fernando Montenegro
Publication Date: September 18, 2026
Cisco and NVIDIA expanded their partnership to bring Splunk AI into customer-controlled environments. Local deployment addresses sovereignty requirements, while the broader security and cost-management announcements leave operational results to be demonstrated.
What Is Covered in This Article:
- The Cisco–NVIDIA relationship and local Splunk AI deployment.
- Sovereignty requirements and the need for hybrid data access.
- Token spending visibility and changes to platform pricing.
- Agentic security operations and Splunk’s development agreement with AWS.
The News: Cisco introduced Cisco AI POD for Splunk at Splunk .conf in Denver on September 15, 2026, extending its NVIDIA partnership to support self-managed Splunk AI. The AI POD and AI Assistant are available now; Agent Launchpad is due later this year, with NVIDIA Nemotron models following in the coming months.
The company also announced Tokenomics capabilities, expanded Agent Observability into its cloud offerings, and added agentic security and Exposure Analytics capabilities. Splunk and AWS agreed to multi-year joint security development, while Activity-Based Pricing is scheduled for this fall.
Cisco and NVIDIA Bring Splunk AI to Enterprises
Analyst Take: Cisco’s most consequential move here is bringing Splunk AI to customers who need to keep sensitive data in their own environments. The NVIDIA partnership provides the infrastructure for that step, while support for local and cloud environments reflects the different restrictions customers place on their data. Customers now have more options for deploying AI, although allowing agents to take on more security work still requires evidence of their effectiveness.
NVIDIA Gives Splunk AI a Way Into the Data Center
The Cisco–NVIDIA partnership extends Splunk AI to customers that previously could not use it because their sensitive data had to remain outside the cloud. Cisco AI POD for Splunk brings together Cisco infrastructure, NVIDIA accelerated computing, and Splunk’s Kubernetes-native runtime in a configuration validated for Splunk workloads.
Customers can also deploy the software on their own infrastructure, with implementation support available from partners. The rollout remains incomplete: AI Assistant is available now, while Agent Launchpad is due later this year, and NVIDIA Nemotron models will follow in the coming months. For buyers, the immediate benefit is access to local Splunk AI, and deployment decisions should reflect what the companies can deliver today.
Hybrid Support Reflects How Customers Must Handle Data
Some organizations have no option but to move sensitive data to the cloud, regardless of the AI capabilities available there. Splunk AI now supports on-premises, private cloud, and air-gapped environments, while Agent Observability also extends into Splunk Observability Cloud and Cisco Cloud Control. These deployment options are particularly relevant to the healthcare, finance, and government organizations whose data must remain within their own environments.
Federated Search extensions to AWS CloudWatch Lake and Databricks, together with MCP-enabled Catalog Discovery, address another part of the problem by helping teams find and analyze distributed data without first migrating it. Customers should assess deployment and data access together, since keeping AI within an approved environment is useful only if it can reach the information needed for its work.
Customers Need to Know What Their Agents Cost
Tokenomics tackles a familiar budgeting problem: spending that becomes apparent only when the invoice arrives. It tracks token expenditure across agents and employee use of Claude Code, Codex, and Cursor, with consumption forecasting through Cisco Deep Time Series Model still to come.
Agent Observability brings spending information together with performance evaluation and runtime guardrails intended to block unsafe or inaccurate actions. Activity-Based Pricing adds a further consideration this fall, when Splunk plans to give search and ingest equal weight in its pricing. Buyers should use these capabilities to assess the cost of individual workloads before deciding whether wider agent adoption makes financial sense.
AWS and Splunk Still Have Details to Provide
The AWS agreement sets a direction for joint security development, although customers still need to know which products it will produce and when. Splunk’s expanded Agentic SOC Workforce covers detection engineering, threat hunting, investigation, response, and governance, with more than 1,300 security integrations.
Exposure Analytics adds asset coverage and historical context, but the announcement gives buyers no quantified measure of the resulting improvement in security operations. The Futurum Group’s 1H 2026 Cybersecurity Market Sizing & Five-Year Forecast projects $77 billion in incremental annual spending by CY2031 across Cloud Security, Security Operations & GRC, Data Security, and Application Security. Cisco is pursuing a substantial opportunity, and earning more responsibility inside the SOC will require evidence that these capabilities improve investigations while keeping analysts in control.
What to Watch:
- Will Agent Launchpad and NVIDIA Nemotron models arrive within the announced windows, and which local workflows will each support at release?
- How effectively will Federated Search and MCP-enabled Catalog Discovery provide relevant context across data sources that customers keep in separate environments?
- When will Tokenomics forecasting become available, and how accurately will it project consumption before a billing period ends?
- What will Activity-Based Pricing mean for customers with different search and ingest patterns?
- Can the Essentials and Premier security editions demonstrate reduced alert noise and faster remediation while preserving analyst control?
- Which products will emerge from the AWS agreement, and when will customers be able to evaluate them?
See the complete announcement on Splunk AI and its expanded security capabilities on Cisco’s website.
Declaration of generative AI and AI-assisted technologies in the writing process: This content has been generated with the support of artificial intelligence technologies. Due to the fast pace of content creation and the continuous evolution of data and information, The Futurum Group and its analysts strive to ensure the accuracy and factual integrity of the information presented. However, the opinions and interpretations expressed in this content reflect those of the individual author/analyst. The Futurum Group makes no guarantees regarding the completeness, accuracy, or reliability of any information contained herein. Readers are encouraged to verify facts independently and consult relevant sources for further clarification.
Disclosure: Futurum is a research and advisory firm that engages or has engaged in research, analysis, and advisory services with many technology companies, including those mentioned in this article. The author does not hold any equity positions with any company mentioned in this article.
Analysis and opinions expressed herein are specific to the analyst individually and data and other information that might have been provided for validation, not those of Futurum as a whole.
Read the full Futurum Group Disclosure.
Other Insights From Futurum:
Cisco Q4 FY 2026 Earnings Point to Broader AI Infrastructure Demand
Cisco Live 2026: Platform, Silicon, and Security for the Agentic Era
Can Cisco Widen Splunk’s Agentic SOC Capabilities With WideField?
Author Information
Fernando Montenegro serves as the Vice President & Practice Lead for Cybersecurity & Resilience at The Futurum Group. In this role, he leads the development and execution of the Cybersecurity research agenda, working closely with the team to drive the practice's growth. His research focuses on addressing critical topics in modern cybersecurity. These include the multifaceted role of AI in cybersecurity, strategies for managing an ever-expanding attack surface, and the evolution of cybersecurity architectures toward more platform-oriented solutions.
Before joining The Futurum Group, Fernando held senior industry analyst roles at Omdia, S&P Global, and 451 Research. His career also includes diverse roles in customer support, security, IT operations, professional services, and sales engineering. He has worked with pioneering Internet Service Providers, established security vendors, and startups across North and South America.
Fernando holds a Bachelor’s degree in Computer Science from Universidade Federal do Rio Grande do Sul in Brazil and various industry certifications. Although he is originally from Brazil, he has been based in Toronto, Canada, for many years.

