Telesoft | AI Agents Are Becoming Network Citizens. Security Needs to Follow Them.
Telesoft | AI Agents Are Becoming Network Citizens. Security Needs to Follow Them.
05.10.2026

Why agentic AI is pushing network identity, network observability and NDR into the security conversation and why the shift matters at 400G and 800G.

ai agents

IntSOC agent / investigation interface.

AI agents are moving beyond chat interfaces and becoming active participants in enterprise environments. They can browse the web, access applications, call APIs, communicate with other systems and take actions on behalf of users. Increasingly, they are being given their own identities, permissions and access to enterprise infrastructure.

A recent development pushes that evolution directly into the network. In October 2026, networking company doxx.net announced the open beta of what it calls Agentic Defined Networking (ADN), alongside a $38 million Series A funding round led by Andreessen Horowitz.

The terminology is new, and it remains to be seen whether Agentic Defined Networking becomes an established category. The architectural direction behind it is more significant. The platform is designed around giving AI agents their own network identities and private networking capabilities, with agents able to interact programmatically with network infrastructure while controls restrict where they can communicate.

This reflects a wider change already taking place. AI agents are becoming capable of accessing applications, communicating with services, interacting with infrastructure and completing tasks without continuous human involvement. They are becoming network actors. For cybersecurity teams, that means the behaviour of AI agents is increasingly becoming network behaviour too.

AI Agents Create Observable Network Behaviour

An AI agent may have its own identity, application logs, permissions, policies and guardrails. Those controls are important, but they do not remove the value of understanding what actually happened across the network. Every interaction leaves a network footprint. An agent communicates with systems and services. It establishes connections, accesses destinations, transfers data and creates patterns of machine-to-machine activity.

Those patterns can provide security teams with another perspective on the agent’s behaviour. Changes in destinations, unexpected communications, abnormal data volumes, new relationships between systems and unusual long-lived sessions can all provide useful investigative context.

These are already familiar concepts within Network Detection and Response. What changes in an agentic environment is the entity generating the activity. Increasingly, that entity may be autonomous software rather than a person sitting behind a keyboard. Network-level visibility can therefore provide an independent source of security evidence alongside identity, application and agent-level controls.

Behaviour Matters When Individual Actions Look Legitimate

The security challenge becomes particularly interesting when an AI agent is not behaving like conventional malware. An agent performing an unwanted action may still be using legitimate credentials, accessing legitimate applications and communicating across legitimate infrastructure.

Viewed individually, those actions may appear valid. Viewed as behaviour, they may tell a different story. An agent that normally communicates with a defined group of internal services could suddenly establish connections with an unfamiliar external destination. A new pattern of lateral communication might appear. Data volumes could change significantly, or a system could begin communicating with services outside its normal role.

This is where behavioural network intelligence becomes increasingly relevant. The objective is not simply to determine whether a connection matches a known malicious indicator. It is to understand whether the behaviour makes sense in the context of what that system or agent normally does.

As autonomous systems become more common, establishing normal network behaviour for machines and AI agents could become as important as understanding normal behaviour for human users.

Network Intelligence Also Supports the Defensive Agent

There is another side to this development. AI agents are not only becoming systems that security teams need to monitor. They are also becoming part of security operations themselves.

Agentic security systems are increasingly being designed to evaluate alerts, gather evidence, correlate events, investigate hypotheses and determine which incidents require human attention. This makes the quality of the information available to the agent critical.

For NDR, that information begins with network activity: communications between systems, behavioural changes, traffic patterns, relationships and the context surrounding them. An individual alert rarely provides enough information to understand an incident. An investigation needs context around what is normal for a system, which relationships have changed, how traffic patterns have evolved and what other evidence supports or contradicts the initial detection.

This is the foundation of the wider IntSOC Agentic AI story. Agentic AI doesn’t start with the agent. It starts with the network intelligence the agent receives.  The stronger the underlying evidence, the more useful an AI-assisted or agentic investigation can become.

Agentic AI Is Arriving as Networks Get Faster

The development of Agentic AI is happening alongside another major infrastructure change. AI training, inference, distributed computing and other data-intensive workloads are contributing to the transition from 100G networking towards 400G and 800G architectures.

This creates an important security requirement. Network performance is increasing rapidly, but security visibility has to keep pace. At 400Gbps, enormous quantities of traffic can cross infrastructure in seconds. Moving towards 800G increases that challenge again. The answer cannot simply be to collect ever-larger quantities of data. Security platforms need to turn high-speed network activity into useful intelligence that can support detection and investigation.

That means extracting the metadata, behavioural patterns, relationships, anomalies and context that analysts and AI-driven security systems can use. For IntSOC 400, this starts with unsampled network processing and enriching every session to Layer 7, providing context for the detection and investigation layers above it.  As network speeds increase and autonomous machine-to-machine communication becomes more common, maintaining that visibility becomes more important.

AI-Driven SOCs Need Reliable Evidence

Agentic AI is also changing how security teams use the intelligence generated by the network. AI-driven SOC platforms can help investigate alerts, correlate events, gather threat intelligence, prioritise incidents and reduce repetitive investigative work.

Their effectiveness still depends on the evidence available to them. Incomplete telemetry produces an incomplete view of an incident, regardless of how capable the AI analysing it may be. Rich network intelligence provides another source of evidence that an AI system can use to establish context, test hypotheses and support its conclusions.

This creates an important relationship between Agentic AI and NDR. Network intelligence can help AI agents investigate threats while also helping security teams understand the network behaviour of AI agents themselves.

The same network can therefore provide intelligence about both the threat being investigated and the autonomous systems increasingly involved in the investigation.

What This Means for IntSOC

Telesoft’s IntSOC platform is built around turning network activity into security intelligence. IntSOC’s documented Agentic AI capabilities include continuously evaluating and prioritising alerts, autonomous triage, evidence correlation, threat-intelligence gathering and hypothesis-based threat hunting.  Those capabilities depend on the intelligence available underneath them.

The emergence of AI agents as network actors adds another dimension to that requirement. Future enterprise environments are likely to contain increasing numbers of autonomous processes interacting with applications, APIs, cloud services, AI models, infrastructure and other agents. Identity controls, application security and agent guardrails will remain essential. Network visibility adds another layer by showing how those systems actually communicate and behave.

At 400G and, increasingly, 800G, delivering that visibility becomes a significant engineering challenge. For NDR, the opportunity is to provide useful network intelligence at those speeds without overwhelming the security team with raw data. That intelligence can support human analysts and AI-driven investigations while also providing an independent view of increasingly autonomous machine behaviour.

The Network Is Becoming Part of the Agentic Security Model

It is too early to know whether Agentic Defined Networking will become an established industry category. What matters today is the direction of travel.

AI agents are acquiring identities, permissions, communications channels and the ability to interact directly with infrastructure. As their autonomy increases, they become a more significant part of the network environment organisations need to understand and protect. Security architecture will evolve with them.

At the same time, organisations are moving towards higher-speed infrastructure capable of carrying ever-greater volumes of machine-to-machine traffic. Together, these trends strengthen the case for maintaining independent, high-performance network visibility. The agent may explain what it intended to do. The application may record the actions it processed. Identity systems may show which credentials were used.

The network provides another part of the evidence: what actually communicated, where it went and how that behaviour changed. For the agentic enterprise, that evidence could become increasingly valuable.

 

agentic ai

IntSOC 400 Network Overview: network activity provides the evidence layer for detection and investigation.

Talk to Telesoft About Network Visibility for the Agentic Era

Agentic AI is changing both the systems organisations need to protect and the tools security teams can use to investigate threats. For organisations operating high-speed networks, greater automation and greater network performance should not come at the expense of security visibility.

Telesoft IntSOC combines high-speed network intelligence, Network Detection and Response and AI-driven security operations to help organisations understand activity across demanding network environments.

Contact Telesoft to discuss Agentic AI, NDR, IntSOC 400 and how your security architecture can prepare for the transition towards 800G.

Go Back