Groups are placing Claude Enterprise to work quick, and never only for chat. Claude, Claude Code, and Claude Cowork act on behalf of customers. They learn paperwork, name instruments, and run duties. That makes the immediate an assault floor. A jailbreak can attempt to bypass the assistant’s guardrails. A immediate injection hidden in a shared file can hijack an agent and switch its personal instruments towards you. Conventional knowledge loss prevention instruments had been constructed to look at for delicate knowledge leaving the constructing. They weren’t constructed to see the mannequin being manipulated, and that’s the publicity that issues most right here.
Anthropic not too long ago launched inference hooks, which let a corporation ship every ruled immediate to an AI safety service earlier than inference begins. When configured, an inference hook is ready to name Cisco AI Protection, which inspects the immediate for synthetic intelligence (AI) threats and returns a verdict, permit or deny. When a person submits a immediate, Claude Enterprise passes it to Cisco AI Protection, which inspects it for AI threats and returns a verdict. Protected prompts undergo. A immediate carrying an injection or a jailbreak is blocked, and the mannequin by no means runs.
That is the place the AI-first focus of Cisco reveals. Right here is the distinction in plain phrases. Conventional knowledge loss prevention is designed to determine delicate knowledge. Cisco AI Protection reads intent. It catches immediate injection and jailbreaks that focus on the mannequin, its instruments, and the brokers performing on its behalf, and it evaluates agent exercise within the dialog transcript. When Claude Code or Cowork calls a software, together with instruments related over the Mannequin Context Protocol (MCP), the transcript can embrace the software name and its outcome, so poisoned content material could be caught earlier than the following inference continues. Cisco AI Protection runs each privateness and manipulation guardrails on that transcript: it flags delicate knowledge the best way knowledge loss prevention would, plus the injection and jailbreak makes an attempt knowledge loss prevention was by no means constructed to see. Put merely: knowledge loss prevention watches for knowledge leaving; Cisco AI Protection watches the dialog itself, catching each knowledge leaving and the mannequin being turned towards you.
That displays how we take into consideration the entire downside. This Claude Enterprise integration is one runtime enforcement level in a much wider platform. Cisco AI Protection secures the total AI lifecycle: it discovers and inventories your AI property like brokers, expertise, MCP servers and instruments, and fashions; assesses their threat by means of validation, red-teaming, and provide chain and mannequin scanning; and protects them at runtime with guardrails like this one. It’s a part of Cisco Cloud Management, Cisco’s unified platform and safe harness for the agentic period. You possibly can learn extra about our full-lifecycle strategy to agent safety in Cisco AI Protection Will get Private with Agent Safety.

The result’s real-time safety delivered by means of the hook, a further integration layer for complete AI protection that provides enforcement with out including infrastructure to the person’s workflow. It provides safety leaders a direct enforcement level for AI coverage throughout ruled Claude Enterprise requests. Enterprise customers of Claude maintain the quick, native expertise they signed up for. For safety leaders, this turns Claude Enterprise from one thing you both belief or block into one thing you possibly can govern towards actual AI threats. For the groups utilizing it, that safety arrives with no single change to how they work.
The way it works
Cisco AI Protection plugs into Anthropic’s inference hooks, so safety runs inline on each ruled immediate:
- Immediate is shipped for inspection. Claude Enterprise sends every ruled immediate, throughout Claude, Claude Code, and Cowork, to Cisco AI Protection by means of the inference hook, earlier than the mannequin runs.
- Request is cryptographically verified. Each name is signed with a one-time signing secret. Cisco AI Protection checks that signature and confirms the request is genuine earlier than it inspects something.
- Dialog is inspected towards your coverage. Cisco AI Protection reads the total dialog, together with software calls and their outcomes, and evaluates it towards your runtime coverage for immediate injection, jailbreaks, software exploitation, and delicate knowledge.
- A verdict returns earlier than inference. Cisco AI Protection returns permit or deny. Protected prompts proceed; a malicious immediate is blocked, and the mannequin by no means runs.


Availability
Cisco AI Protection inspects each prompts and responses. This integration makes use of Anthropic’s inference hook, which at present fires on every ruled immediate earlier than the mannequin runs, so that’s the place we implement proper now. As Anthropic extends the hook to responses, response-side enforcement can use the identical integration path. Over time, we count on this enforcement to develop into a local a part of the Cisco AI Protection Examine API, so turning it on can be a number of steps in your Claude Enterprise settings. It really works with Claude Enterprise right this moment, and inference hooks are in beta.
Need to see it? Attempt the playground in our developer portal; enter a immediate and watch the reside inspection and the actual verdict. See how Cisco AI Protection stands as much as AI threats. Schedule time with our workforce.
