80% of network pros are OK with giving AI an autonomous role in network operations

News Analysis
Sep 23, 20268 mins

Cisco survey of 1,000 IT pros shows unsustainable growth in network complexity and alerts, leading to a willingness to let agentic AI tools take actions on their own.

Artificial Intelligence Internet of Things Network Protection Global Business Robots Touch Key Protection Icons Digital technology concepts online marketing, data analysis, e-commerce connectivity
Credit: Apichatn / Shutterstock

Network professionals are pinning their hopes on artificial intelligence to deliver them relief from an uptick in network complexity that is only getting worse, in no small part due to the increased use of artificial intelligence.

A new report from Cisco and the research and advisory firm Omdia paints a picture of enterprise networks that have literally become too complex for humans to manage. The situation is so dire that 51% of respondents use agentic AI tools in production to take corrective action in real time, rather than simply taking advice from them. Eighty-four percent expect to reach a fully AI-led operating model within twelve months.

Three-quarters of the 1,000 IT and network operations leaders surveyed say they use AI in some fashion for network operations, and 80% are comfortable granting AI a “high or fully autonomous role” in network operations. More than half of respondents (56%) will do so only with a human approving those actions, but 24% are comfortable with AI taking network actions with no human oversight. The vast majority (82%) are comfortable allowing AI to make some production network changes on its own for some categories.

Cisco calls it a move from AIOps to agent-powered operations, or AgenticOps. Longtime industry watchers such as Zeus Kerravala, founder and principal analyst at ZK Research, are on board with the idea.

“You have to have agentic operations. Networking pros will embrace it,” he says. It may take some time to fully develop trust in the new tools, but that will come, too—similar to the curve for autonomous vehicles, which he notes get in far fewer accidents than cars with human drivers. By the same token, agentic AI tools are “going to make mistakes, but a lot fewer than people will. And it’s going to let people focus on things that are higher value,” Kerravala says.

Jim Frey, principal analyst, networking, at Omdia, who helped develop the Cisco survey, likewise sees the move to AgenticOps as inevitable.

“To me it’s a combination of the increasing network complexity and decreasing number of humans who have the right skills to solve networking problems, including cross domain issues,” Frey says.

AgenticOps must include effective guardrails

The Cisco survey, titled “The Impact of Agentic AI on Network Operations,” is being released amid calls to slow AI use, partly in response to events such as the Hugging Face hack caused by agentic AI agents running amok. Yet the survey shows hundreds of network professionals are happy to cede at least some control of their networks to AI agents.

They will do so, however, only if strict guardrails are in place, which the Hugging Face incident lacked. Nearly every respondent (99%) said they would not trust AI to act without such guardrails, including:

  • Explainable AI actions
  • Human approval for actions
  • Policy-based operational limits
  • Emergency override mechanisms
  • Role-based access control
  • Immutable audit trails

Guardrails build trust in AI by letting users see the reasoning that leads an agent to a conclusion, says Joe Vacarro, senior vice president and general manager for network platforms and ThousandEyes at Cisco. What’s more, while AI agents can draw conclusions from the intelligence they examine, any actions they take map to predefined workflows based on the network team’s standard operating procedures for how to respond in different situations, he says.

From his conversations with Cisco, Frey says another key constraint is that agentic agents don’t talk to other agents. “That helps a lot because when they’re constrained to only figuring things out themselves, they’re a lot less dangerous,” he says.

Another constraint is that agents are built around specific skills or knowledge and a defined scope of responsibility. “That can be controlled when you’re doing this on a product basis like Cisco and Splunk are doing. That’s the way to do this.”

“When you put that all together, it gives enterprise network operations teams the confidence to leverage agentic AI to help them manage this increasing level of complexity,” Vacarro says.

Driving the need: complexity, rapid change, and AI itself

Complexity is indeed increasing, as 59% of survey respondents report making changes to their production network environments at least daily. “Half of those organizations are making multiple changes per day, and for a meaningful share, change happens multiple times per hour,” the report says. As a result, 57% say their change processes can’t keep up.

Ninety-two percent of respondents say performance issues tend to cross multiple domains, including cloud, security, applications, and endpoints. Similarly, 95% say their existing, non-agentic tools (AIOps) fall short in significant ways, mostly by requiring too much human interpretation and lack of cross-domain visibility.

Two-thirds of respondents say the generative AI boom has also increased network complexity. From its own traffic analysis of direct-to-AI traffic, Cisco found average daily AI traffic is on a trajectory to double every six months. “This acceleration is likely fueled by the growing complexity of AI tasks which demand more data exchange than a simple query,” the report says.

Perhaps not surprisingly, then, the survey found the average organization generates around 4,100 monitoring alerts and events per day, with 51% being network-related. Omdia estimates a typical practitioner can review, investigate, and resolve about 21 network alerts a day, meaning it would take a team of about 100 specialists to handle that daily volume.

Since few organizations have that much staff, nearly half of alerts (46%) are closed without investigation. Alert fatigue is a “meaningful source of employee dissatisfaction” for 65% of respondents, while 67% say alert volumes prevent teams from doing other, critical work.

Kerravala says those numbers ring true based on his own research around security alerts, which found well under 50% of alerts are investigated.

Too many tools, too much time to resolve issues

Organizations rely on an average of 10 tools to try to maintain end-to-end visibility, but they tend to be siloed, making it difficult to diagnose problems that cross domains, as many do. That is reflected in the time it takes respondents to resolve issues.

The mean (average) time to resolve a network incident is 88 hours, while the median is 12.5 hours. Frey says the mean is skewed by some organizations that take a week or longer to resolve issues, reflecting the degree of complexity. “It’s a real opportunity to start doing a better job by having AI help with the analysis and automate the root cause process,” he says.

One example is where the organization tends to take the same corrective action every time a situation occurs. “If I’ve done it 14 times, go ahead and automate it, but tell me you did it,” Frey says.

Network professionals may also take a page from their security counterparts. With a similar problem of too many issues to tend to, security pros are increasingly taking the tack of automating the response, even if that means shutting down a resource, Frey says. The thinking is, the potential losses are greater than the potential impact to the business. “I think network folks are moving their way toward being more comfortable with that approach.”

The solution: another single pane of glass

For its part, Cisco is proposing its new Cloud Control platform as a solution. It is intended to provide a unified view and management plane for networking, security, compute, observability, and collaboration solutions. Cloud Control also applies agentic AI to diagnose and resolve issues, including those that cross domains. It is, yet again, the proverbial “single pane of glass,” this time with an AI twist.

It may seem somewhat ironic that a vendor that sells the networking gear that has become too complex to manage is now also selling the solution intended to address that complexity.

“Have the network vendors been complicit in this? Sure. But it’s good to see them simplify things now,” Kerravala says. “And the network is just being used in so many more ways than it ever has before. It’s more complex for a number of reasons,” including that networks support orders of magnitude more devices and connect to pretty much everything.

Frye agrees. “I’ve been watching networks evolve, and attempts to automate operations, and it’s just been very difficult to achieve,” he says. “I think we’re finally potentially getting there with AI.”

Paul Desmond

Paul Desmond has been involved in the IT trade press since 1988. He is principal with PDEdit (www.pdedit.com), an IT publishing firm he founded in 2002 that produces content for the IT trade press and vendor communities, including white papers, blog posts, case studies and Web content. Prior to founding PDEdit, Paul spent 11 years at Network World, serving as a reporter as well as news editor and features editor. Paul has also served as editor of Redmond magazine and was the founding editor-in-chief of Redmond Channel Partner magazine. He was also founding editor of eComSecurity.com, now known as eSecurityPlanet.com. Reach him at paul@pdedit.com.

More from this author