Well, already knew Windows RT supported basic VPN functionality (IPSec etc) out of the box with 8.0. What it didn't, and in Cisco's case still doesn't, support is SSL VPN client functionality because the vendors all implement it differently from my understanding (correct me if I'm wrong). It sounds to me that additional capabilities have been added to the built-in Microsoft VPN client in 8.1 for Juniper etc, as opposed to a third party VPN client. Cisco may not be able to do the same with their client due to whatever may differ, or they may not be interested in exposing how their AnyConnect VPN works (the competitor drama you describe) to add that functionality to the built-in VPN client, but at the same time may still not be able to write a client using just the WinRT API. If this is the case it still may very well still be about the APIs on Windows RT. Once again I wish Microsoft would reconsider their insistence on blocking third party use of any API other than WinRT in Windows RT.
You highlight my contradiction - Cisco could write an SSL connection for Cisco to sit within RT but they didn't. Checkpoint, F5, Juniper, etc did take that initiative.
MS could open up their APIs for a Cisco client, but they haven't, and no other vendor is really complaining.
SSL is a standard: http://tools.ietf.org/html/rfc6101 and has been for a while.
That said, it is possible that Cisco wrote proprietary code they claim will make it better - they are notorious for that, and have done it with discovery protocols, routing protocols, and SIP just to name three. This doesn't really make it MS's obligation to support it.
I hope whatever the block is, the Cisco community out there get an acceptable answer for their connectivity. We will see...