Legacy networks cannot support AI-driven workloads
AI is changing the basic assumptions behind enterprise infrastructure. Most corporate networks were designed around people using applications, sending emails, joining video calls, and accessing business systems throughout the day. AI agents operate very differently. They exchange information continuously, make decisions in real time, and interact with multiple systems simultaneously. That changes the scale and speed of network traffic.
Tay Bee Kheng, President of Cisco ASEAN, said that today’s infrastructure was built for human interactions. She explained that while chatbots create intermittent demand, AI agents generate sustained and persistent demand on enterprise infrastructure. This distinction matters because organizations moving from AI assistants to autonomous AI agents will experience a significant increase in network utilization.
The challenge extends beyond bandwidth. AI agents depend on low latency, meaning information must move quickly between applications, databases, cloud platforms, and edge devices. Small delays can reduce the effectiveness of AI systems that need to reason, plan, and execute actions in near real time. Legacy networks often struggle to provide this level of performance consistently across an enterprise.
Cisco also expects organizations to manage as many as 10 AI agents for every employee. That represents a dramatic increase in the number of active digital workers operating inside the business. These agents will require identity management, network access, security controls, monitoring, and governance. Most enterprise operating models were never designed for that scale.
For business leaders, this is no longer an IT upgrade discussion. Network infrastructure is becoming a strategic business capability. Companies that modernize early will be better positioned to deploy AI across customer service, supply chain management, software development, manufacturing, finance, and operations. Those that continue relying on legacy infrastructure may find that AI projects perform well during pilot stages but become difficult to scale across the organization.
The conversation should also move beyond supporting today’s AI models. AI capabilities continue to improve rapidly, and infrastructure decisions made today should support increasing workloads over the coming years. Building networks that can adapt to future AI demands will reduce costly redesigns and provide greater flexibility as new AI applications emerge.
AI agents demand a zero-trust security approach
The arrival of AI agents changes enterprise security in a fundamental way. Traditional cybersecurity was built around people. Employees log in, authenticate themselves, perform work, and eventually log out. AI agents can operate continuously, interact with multiple systems automatically, and execute tasks without direct human involvement. Security models must evolve accordingly.
Koo Juan Huat, Director of Cyber Security at Cisco ASEAN, argued that organizations should apply the same zero-trust architecture to AI agents that they already use for employees. Zero trust assumes that no user or system should be trusted automatically. Every request must be verified, every permission should be limited to what is necessary, and every action should remain observable.
This approach begins with visibility. Organizations need to know every AI agent operating on their networks, understand its purpose, identify which systems it can access, and monitor how it behaves over time. Without that visibility, security teams cannot distinguish between authorized activity and unexpected behavior that could indicate misuse or compromise.
Authorization becomes equally important. Koo explained that enterprises should grant permissions only when required and only for the specific task an AI agent needs to perform. This “just-in-time” and “just enough” access reduces unnecessary privileges and limits the potential impact if an AI agent behaves unexpectedly or is exploited by an attacker. He also emphasized that sensitive actions should still require a human to authenticate and authorize the decision before execution.
The timing of this shift is important. The Government Technology Agency of Singapore has already announced plans to build an AI agent registry for public officers. That reflects a broader industry trend toward treating AI agents as managed digital identities rather than software running quietly in the background. Enterprises are likely to adopt similar governance models as AI deployment expands.
For executives, the implication is straightforward. AI governance cannot be separated from cybersecurity. Identity management, access control, continuous monitoring, and human oversight should become standard components of every AI deployment strategy. Organizations that build these capabilities early will be better prepared to scale AI confidently while reducing operational and regulatory risk.
A project in mind?
Schedule a 30-minute meeting with us.
Senior experts helping you move faster across product, engineering, cloud & AI.
Shadow AI presents significant security risks
AI adoption is accelerating faster than governance in many organizations. That creates a growing gap between what employees can do with AI and what security teams can see. Shadow AI is emerging as one of the biggest risks because it often develops outside formal approval processes.
Robert Pizzari, Group Vice-President of Asia at Splunk, now a Cisco company, warned that employees are increasingly using unsanctioned foundation models or giving AI agents permissions they should not have. In many cases, these actions are intended to improve productivity. The problem is that they can expose sensitive business data, create compliance issues, or allow AI systems to perform actions beyond their intended scope.
This is different from traditional shadow IT. Modern AI systems can access large amounts of enterprise information, connect to multiple applications, generate code, and make recommendations that influence business decisions. If these systems are deployed without oversight, organizations lose visibility into how information is being used and whether AI outputs remain reliable.
Cisco is addressing this challenge by expanding its AI observability capabilities following its acquisition of Galileo. AI observability gives organizations the ability to monitor AI systems throughout their lifecycle. This includes tracking model drift, where an AI model’s performance changes over time as business conditions or data evolve, and monitoring agent behavior to detect unexpected actions before they become operational or security problems.
Pizzari acknowledged that shadow AI is likely to become a permanent feature of enterprise environments rather than a temporary issue. He emphasized that organizations need the ability to “hit the handbrake” when AI systems begin behaving in unsafe or unintended ways. That means governance should include rapid intervention capabilities.
For executives, this changes the governance conversation. The objective is not to prevent employees from using AI. The objective is to create approved pathways that allow innovation while maintaining visibility, security, and accountability. Organizations that combine clear AI policies with strong observability tools will be better positioned to benefit from AI without introducing unnecessary business risk.
Frontier AI models enhance cyber defense capabilities
AI is changing both sides of cybersecurity. Attackers are using increasingly capable AI systems to automate their activities, improve phishing campaigns, identify vulnerabilities, and accelerate malicious software development. Defenders must respond with equally advanced technologies that can operate at comparable speed and scale.
Cisco is applying frontier AI models to strengthen its own security capabilities. Through Anthropic’s Project Glasswing, the company used frontier AI models, including Claude Mythos, to scan 1.8 billion lines of code across more than 25 programming languages in just eight weeks. According to Cisco, the process achieved a false positive rate of under 3%, helping security teams identify genuine issues while reducing unnecessary investigation work.
This demonstrates how AI can improve software security at enterprise scale. Modern organizations manage millions or even billions of lines of code across internal applications, cloud environments, and third-party software. Manual review alone cannot keep pace with this level of complexity. AI allows security teams to identify vulnerabilities earlier, prioritize risks more effectively, and accelerate remediation without significantly increasing staffing requirements.
Cisco also recognizes that enterprise security remains highly fragmented. Many organizations rely on multiple security products that do not always share information efficiently. To encourage broader collaboration, Cisco is open-sourcing several AI security and safety frameworks designed to help organizations build more secure agentic AI systems.
One of these frameworks is DefenseClaw, which scans, sandboxes, and inventories AI agents before they are allowed to operate. It also reviews their skills and Model Context Protocol (MCP) connections to understand how they interact with other systems. Another component, CodeGuard, performs static analysis on AI-generated code to identify potential vulnerabilities before deployment. Together, these tools strengthen governance while allowing organizations to continue expanding AI adoption.
Robert Pizzari, Group Vice-President of Asia at Splunk, now a Cisco company, acknowledged that the industry’s fragmented security landscape remains a challenge. Cisco’s decision to make these frameworks open source reflects the view that AI security cannot be solved by individual vendors alone. Stronger collaboration across the technology ecosystem will be necessary as AI agents become a standard part of enterprise operations.
For business leaders, the broader lesson is clear. AI should not be viewed only as a source of new cyber risk. It is also becoming one of the most effective tools available to improve cyber resilience. Organizations that invest in AI-enabled security today will be better prepared for the increasingly automated threat landscape that is already emerging.
Proactive preparation is required for AI-enabled cyber threats
AI is no longer limited to generating text, images, or answering questions. Modern AI systems can reason, plan, and take action with increasing levels of autonomy. This creates significant opportunities for businesses, but it also changes the nature of cyber risk. Threat actors now have access to many of the same AI capabilities that organizations are adopting to improve productivity and efficiency.
Rahayu Mahzam, Singapore’s Minister of State for Digital Development and Information, emphasized that AI-powered attacks are already a reality. She pointed to voice phishing attacks in 2025 that used AI to clone the voices of chief executives, demonstrating that sophisticated impersonation is no longer a theoretical concern. As AI models continue to improve, these attacks are expected to become more convincing, scalable, and difficult to detect.
The growing use of agentic AI introduces additional risks. AI agents can make decisions, access business systems, and execute tasks with limited human involvement. If these systems are not governed properly, errors can spread quickly across business processes, while compromised agents could be exploited to gain access to sensitive information or disrupt operations. The speed and autonomy of these systems require organizations to rethink traditional governance models.
This is becoming both a technology and a leadership issue. Executives should ensure that AI governance extends beyond cybersecurity teams. Legal, compliance, risk management, operations, and business leaders all have a role in establishing policies that define where AI can be deployed, what decisions require human approval, and how AI activities should be monitored and audited. Governance should evolve alongside AI capabilities rather than react after problems emerge.
Organizations should also prepare for increasing regulatory attention. Governments around the world are introducing AI governance frameworks that emphasize transparency, accountability, and responsible deployment. Businesses that establish strong governance early will be better positioned to meet future regulatory requirements while maintaining customer and stakeholder confidence.
As Rahayu Mahzam noted, “Agentic AI is here – AI that doesn’t just respond, but reasons, plans and acts.” She also warned that “with accelerating capabilities and automation come new digital and cyber risks. AI agents that act without sufficient oversight can cause real harm.” For business leaders, the priority is not slowing AI adoption. It is ensuring that innovation is supported by governance, security, and trust from the beginning.
Workforce development is essential for secure AI adoption
Technology can accelerate business transformation, but people remain responsible for how that technology is deployed, governed, and improved. AI adoption will succeed only if organizations develop the skills needed to manage increasingly advanced systems responsibly. This makes workforce development a strategic priority rather than simply a human resources initiative.
Recognizing this need, Cisco and the Digital Defence Alliance Singapore (DDAS) signed a three-year memorandum of understanding to develop joint training programs focused on AI and cybersecurity. The initiative is designed to create practical learning opportunities for both young talent and working professionals, helping them build the technical and operational capabilities needed in an AI-driven economy.
The program emphasizes hands-on experience rather than theory alone. Polytechnic students from the DDAS community are scheduled to visit Cisco’s Tokyo office in October to learn about network security within Japan’s commercial IT industry, following a similar educational visit to Seoul in April 2026. These experiences expose participants to real-world security practices and international perspectives that can strengthen future workforce capabilities.
For executives, this highlights an important shift. AI investment should include infrastructure, governance, and talent development as equally important priorities. Organizations often focus on acquiring AI platforms while underestimating the skills required to operate, secure, and govern them effectively. Without continuous learning, businesses may struggle to realize the full value of their AI investments or maintain appropriate oversight as AI systems become more capable.
Upskilling also extends beyond technical specialists. Senior leaders, business managers, legal teams, and frontline employees all need a practical understanding of AI’s capabilities, limitations, and associated risks. Cross-functional knowledge improves decision-making, supports responsible AI adoption, and helps organizations respond more effectively as technologies and regulations continue to evolve.
Rahayu Mahzam, Minister of State for Digital Development and Information, Government of Singapore, announced the partnership between Cisco and DDAS and concluded, “The question is no longer whether AI will transform the way we work. It already has. The question is whether we are ready to lead that transformation – with skill, with security and with trust at the centre.” That message reflects the broader challenge facing every enterprise. The organizations that combine advanced technology with a highly capable workforce will be in the strongest position to capture AI’s long-term value while managing its risks responsibly.
Key takeaways for decision-makers
- Modernize network infrastructure for AI: Legacy networks designed for human activity cannot efficiently support always-on AI agents. Leaders should treat network modernization as a strategic investment that enables AI to scale reliably across the business.
- Extend zero trust to AI agents: AI agents need the same identity, access, and governance controls as human users. Build visibility into every agent, enforce least-privilege access, and keep humans involved in high-risk decisions.
- Make AI observability a core capability: Shadow AI will continue to grow as employees adopt new AI tools. Organizations should invest in AI observability to monitor model behavior, detect drift, manage unauthorized AI use, and quickly stop unsafe activity.
- Use AI to strengthen cybersecurity: As attackers adopt AI, defenders must do the same. AI-powered security tools can identify vulnerabilities at enterprise scale, while open standards and shared security frameworks help improve resilience across the broader ecosystem.
- Build AI governance before risks escalate: Autonomous AI creates new operational and cyber risks that require proactive oversight. Leaders should establish governance frameworks that combine security, compliance, human approval, and continuous monitoring from the start.
- Invest in AI skills alongside technology: Successful AI adoption depends on people as much as platforms. Organizations should continuously develop AI and cybersecurity skills across technical and business teams to ensure AI is deployed securely, responsibly, and at scale.
A project in mind?
Schedule a 30-minute meeting with us.
Senior experts helping you move faster across product, engineering, cloud & AI.


