Source of truth first. Deterministic guardrails. The agent reasons, executes inside your boundaries. The winners of the next two years know which config the agent should never touch.
What is the one task you would never hand an agent?
John Capobianco of Itential said it cleanest: LLMs are probabilistic and infrastructure is not. A probabilistic model improvising on a network with no source of truth is not automation. It is a faster outage.
AgenticOps has a $9B order book behind it. The question is no longer whether AI runs your network, but what you let it run unattended.
What is the first change you would trust an agent to make, and the first you never will?
Cisco raised its AI infrastructure order target to $9B, up from $5B. And cut under 4,000 roles. Record demand for AI networking, fewer people to run it. That is the trade.
GreyNoise: across 104 scanning surges, 68 preceded a vendor CVE. Median lead 11 days. A surge is a weather forecast, not noise.
Are scanning surges in your patch-prioritization signal yet?
May 12: roughly 597,000 scanning sessions against SonicWall management interfaces in one day, about 46x normal. SonicWall was 72% of enterprise VPN-targeted activity that week.
AIOps was a dashboard. Agentic NetOps is an actor in your control plane. The value moved from writing the change to building the guardrails the agent runs inside. I build audit-grade tools around exactly this. In my profile.
Every MCP-connected agent is a new identity making privileged calls, most authenticating weakly or not at all.
NSA fix: filtering proxy, signed messages with replay protection, just-in-time credentials.
Patch: PAN-OS 12.1.4-h6, 12.1.7, 11.2.12, 11.1.15, 10.2.18-h6. Prisma Access vulnerable to 11.2.7-h13. Then hunt identity logs for forged cookies.
When did you last audit which features share a certificate?
Rapid7 saw exploitation start May 17, second wave May 21. CISA KEV May 29, federal deadline June 1.
Root cause CWE-565: cookies without integrity checking.