Cisco's AI Defense product topped an independent ML6 benchmark for enterprise LLM guardrails, achieving the highest F1 score in a cohort test on 80,000 Dutch-language adversarial prompts. Cisco attributes the result to an approach it calls constitutional definitions.
According to Cisco's benchmark analysis, the product achieved an F1 of 0.845 with 0.843 recall and 0.847 precision. A competing guardrail solution in the same ML6 cohort reached 0.327 recall, with false alarms cutting its F1 to 0.453. Scores across nine tested languages stayed within a tight band, from 0.796 F1 in Arabic to 0.860 in Portuguese. Cisco also reports p90 latency of 40 milliseconds and p99 of 250 milliseconds per request. The company's multi-turn vulnerability research, covering 15 frontier models, found that every model tested carries meaningful exposure to multi-turn attacks, with success rates that show no consistent correlation to single-turn benchmark scores. Constitutional definitions reduced inter-model disagreement by up to 57 times compared to paragraph-level natural-language definitions, Cisco says.
Constitutional definitions are precise per-technique operational specifications that serve as the machine-enforced ground truth for both classification and model training. Because the specification describes intent and content in language-agnostic terms rather than natural-language prose, the same taxonomy governs whether a prompt injection is written in French, Arabic, or Japanese without retraining per language. Cisco contrasts this with broader paragraph-level definitions, which it says introduce inconsistency that compounds across models and deployment frameworks.
The core security argument is structural. In production, adversaries rarely embed an attack in a single prompt; they iterate across a conversation, reframe refusals, and escalate gradually across turns. An AI system's security perimeter, in that environment, needs to sit outside the model and track the intent and active direction of the exchange rather than classify each message in isolation. Standard English, single-turn benchmarks do not test that scenario, which means guardrails calibrated on such evaluations may substantially overstate protection for organizations running multilingual deployments.
For organizations evaluating LLM guardrails for non-English or multi-turn workloads, the ML6 benchmark provides independent cross-language performance data. The narrow F1 band across nine typologically diverse languages is a concrete claim that enterprise buyers can probe in their own evaluation environments before committing to a production deployment.













