Preparing for agentic infrastructure requires making changes to how the network is operated, not just what it carries. At the AI Networking Summit Dallas 2026, Cisco’s Tom Gillis described an important convergence. AI awareness built into network security, security built into the fabric of the network, and the network built into the GPU compute complex.
His message was that AI creates a wave of new problems for infrastructure teams, and also the tools to solve them. Here are five questions every enterprise leader should be able to answer as agents and AI applications move onto the network.
The operating model has to change because AI can now find software vulnerabilities faster than infrastructure teams can patch them. Gillis pointed to Anthropic’s Project Glasswing, which gave critical vendors early access to its Mythos model. Frontier models can now comprehend code bases of tens of millions of lines and find long chains of exploitable flaws, including ones that lived in Linux and OpenSSH for decades.
Gillis’s answer is to bring CI/CD, cloud-like operating principles to infrastructure. Cisco’s Live Protect applies targeted compensating controls to a switch or router without a reboot or a traditional change control window. It does not replace a patch, he stressed, but it buys time to patch in an orderly way.
AI applications need a back-end network that GPUs use to talk to each other, alongside the traditional front-end network. Many enterprises want to run AI in their own environment, both to protect their data and for economic reasons, and that puts this new network in their data center.
Cisco ships 800 Gbps per port today, has announced 1.6 Tbps, and is working on 3.2 Tbps. Gillis described the Ethernet network as the backplane of composable systems, stitching CPU, GPU, memory, and storage into what looks like one giant computer. As he put it, networking is back.
You teach network security to understand AI. Traditional applications are deterministic: a click triggers a known set of actions. AI applications are not. Ask the same question twice, and you may get two different answers, and that non-determinism carries into agent-to-API interactions.
Cisco is putting that capability into its proxies and secure access, and into the east-west, API-to-API traffic inside the data center. The goal is to apply reasoning and spot behavior that falls outside normal bounds.
The firewall should be spread across the network fabric, not sitting at the edge in a box. Gillis called this a hybrid mesh firewall.
With a firewall on every port, a team buried in vulnerabilities can protect just the Postgres database without touching the Kubernetes cluster or the Apache server next to it. The same view lets security catch an AI application that starts acting outside its normal pattern. Smart switches are what make this workable. The networking chip and the security chip sit in the same box but get updated on their own schedules, so adding a firewall between two workloads becomes a button push instead of a hairpin routing project.
You watch every east-west transaction at the process level, without trying to ingest it all. In a post-Mythos world, Gillis said, teams should assume attackers are already inside, and lateral movement happens on the network. Process-level east-west data is roughly a thousand times more than what goes into a SIEM today.
Instead of one giant data lake, Gillis described a federated architecture of local “data ponds” that push analytics closer to where the data is created. Firewall logs, for example, can be indexed locally and made searchable from Splunk with no ingestion at all. He said this capability is coming this calendar year.
His closing ask tied it all together.
The questions raised in Dallas, from AI-scale vulnerabilities to securing agent traffic, are what enterprise practitioners will take on next.
The conversation continues at the AI Networking Summit NYC. Join the enterprise leaders, architects, and security teams building the agentic infrastructure ahead. Get your ticket today.