Qubicweb reading view
Black Hat Fireside Chat: As AI agents spread, the network shifts from traffic mover to policy enforcer
Internal Read means the full piece stays on Qubicweb, with its source path and context still visible.
Brief points
- The network’s job has always been simple: watch the traffic.
- Related: AI agents have a Lord Of The Flies problem For decades, network traffic came from something physical: a server, a laptop, a badge reader, a printer, each with a fixed a...
- An AI agent isn’t physical, and it has no fixed home on the network.
The network’s job has always been simple: watch the traffic. Authority stopped there.
Related: AI agents have a Lord Of The Flies problem
For decades, network traffic came from something physical: a server, a laptop, a badge reader, a printer, each with a fixed address. An AI agent isn’t physical, and it has no fixed home on the network. It appears, acts and disappears, with no device to hang a policy on. Watching isn’t enough anymore.
Across the networking industry, vendors are moving to meet that shift. HPE Networking, Palo Alto Networks, Cisco and others are folding security enforcement directly into the network itself, and integrating their own governed AI agents into that work.
David Hughes leads HPE’s piece of that work as senior vice president for SASE and security. We talked at Black Hat USA in Las Vegas about what folding AI into network enforcement actually looks like in practice. The full conversation is available on the accompanying Last Watchdog podcast.
The tell
It all starts with visibility. Hughes points to two things a network can see: what a device normally does, and how fast it does it.
The first is fleet learning. The network doesn’t watch a single customer’s device in isolation — it watches the same kind of devices, like electronic door locks, installed across thousands of different customer networks at once. That gives the network a baseline: what this kind of lock normally does, everywhere it’s installed. When one customer’s lock breaks from that pattern, the network can identify that lock as the outlier.
The second is pace. A person works at a human rate. An agent doing the same job doesn’t share that limit — it moves faster and keeps that pace without stopping. The network can see all of that. “A great place to have as a sensor and detector,” Hughes calls it. The advantage was never a secret. What’s changed is how much rides on it now.
Holding the line
Fleet learning and pace don’t catch everything. The cloud and IoT era already pushed more traffic through networks than detection could fully cover. AI agents add to that volume and move faster than networks were built to track. Something always gets through.
The network’s answer is containment — limiting what a compromised device can reach once it’s inside. Hughes uses a zero-trust example to show how that works: someone compromises a video camera on the network. Without internal segmentation, that camera is a launchpad — a way in that lets an attacker reach everything else on the same network. Segment first, and the same camera can only talk to the one server it was assigned to. The compromise still happens. The lateral movement doesn’t.
Segmentation means fixing exactly where a device is allowed to go, and cutting it off from everything else.
That same logic now extends to AI agents. An unscoped agent can reach anything the network exposes to it — and unlike a compromised device, it can act on that access immediately, at machine speed. Hughes described the safeguard: restrict what a company’s own agent can reach before it’s turned loose. Build it for one employee, and scope it to exactly three systems, nothing else. Point it at the open internet and it sees nothing beyond those three destinations. Something could still go wrong inside that boundary. What can’t happen is the agent reaching systems nobody scoped it for.
The proof
The Hugging Face incident, raised at Black Hat two days before this interview, shows what that boundary is for. OpenAI researchers recounted how a set of its own evaluation agents, over roughly two months beginning in May, worked past the edges of a testing environment, used a previously unknown software flaw, and reached systems at Hugging Face that were never part of the original assignment — exactly the kind of reach Hughes’ scoping example is meant to prevent.
The cybersecurity industry has leaned on machine learning, then language models. Now it’s shifting into another gear: governed, scoped agents, brought on by what Hugging Face just proved about what an ungoverned one can do. HPE is building toward that shape — an agentic mesh of its own governed agents, aimed at what it calls a self-driving network. “The self-driving network is absolutely North Star,” Hughes said.
First the network moved traffic. Then it watched. Now it’s starting to act on its own.
I’ll keep watch and keep reporting.
Acohido
Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.
(Editor’s note: This journalist-led report was produced with underwriting support from some of the featured companies, while Last Watchdog retained full editorial control. I used Claude and ChatGPT to assist with research compilation, source discovery, and early draft structuring. All interviews, analysis, fact-checking, and final writing are my own. I remain responsible for every claim and conclusion.)
The post Black Hat Fireside Chat: As AI agents spread, the network shifts from traffic mover to policy enforcer first appeared on The Last Watchdog.