Enterprises are rapidly integrating artificial intelligence agents and physical AI into daily operations, but many are doing so on legacy networks that were never designed for machine-speed decision-making. The result is a growing mismatch between infrastructure built for human-driven workflows and the always-on, high-frequency demands of AI workloads.
At Cisco Connect 2026 Singapore, Tay Bee Kheng, president of Cisco ASEAN, framed the challenge bluntly: "The infrastructure we built for today is like a road network that is built for bicycles." Her opening address set the tone for a conference focused on the operational, security, and workforce implications of agentic AI.
The network bottleneck
Tay explained that chatbots place only intermittent pressure on networks. A user asks a question, the system responds, and the connection returns to idle. AI agents, by contrast, generate sustained and persistent demand. They are continuously observing, reasoning, planning, and acting across applications, often in parallel. "Infrastructure that is made for a human click on the network is not applicable for AI agents anymore," she said.
This distinction matters for capacity planning. Legacy architectures were built around bursty human interactions. Network teams could predict peak usage and size links accordingly. AI agents do not follow those patterns. They query databases, invoke APIs, move data between services, and coordinate with other agents at machine speed. The same network that handles thousands of employees may suddenly need to support millions of machine-to-machine transactions per minute.
Beyond bandwidth, latency becomes a harder constraint. An AI agent managing a supply chain cannot wait for a round trip to a distant data center when a disruption occurs. Edge locations, low-latency fabrics, and local processing become essential. Yet many enterprises still rely on VPNs, hub-and-spoke WANs, and legacy switching that were never optimized for this kind of traffic.
Tay added a daunting perspective on the scale of the challenge: organisations may need to onboard as many as ten agents for every employee. "There's no HR system for that at this moment," she said. Managing identities, permissions, lifecycles, and cost for agent fleets is an operational problem that has not yet been solved.
Security blind spots and shadow AI
Agentic AI's ability to reason, plan, and act across supply chains and operations creates new security exposures. Unlike human employees, AI agents do not authenticate with passwords or behave like users following a predictable routine. They can move laterally through systems, invoke tools, and make decisions in response to changing data. Traditional IT operations, built around human behavior, have a blind spot when it comes to these non-human identities.
During a media briefing, Robert Pizzari, group vice-president of Asia at Splunk, now a Cisco company, warned of the risks of shadow AI. Employees may deploy unsanctioned foundation models, connect personal AI assistants to corporate data, or grant AI agents privileges they should never have. The speed of generative AI adoption has outpaced governance in many organizations.
"Inevitably, shadow AI will be a feature and a function, so we also need to ensure that organisations have the ability to hit the handbrake," Pizzari said. Cisco is tackling the problem with its AI observability stack, bolstered by the recent acquisition of Galileo. The stack is designed to monitor model drift, track agent behavior, and detect when an AI system is doing something outside its intended scope. Observability becomes the foundation for stopping a rogue agent before it causes damage.
Zero trust for non-human identities
Koo Juan Huat, Cisco ASEAN's director of cyber security, stressed that treating AI agents with the same zero-trust architecture used for human employees is the only way forward. "You need to be able to look at what the agent is doing and give it permission just in time and just enough to do what it needs to do," he explained. "A human needs to come into the loop and authenticate and authorise the action."
Koo outlined three priorities for securing AI agents: know the agents on your network, know what they are authorised to do, and implement strict guardrails. This aligns with the Government Technology Agency of Singapore's recent move to build an AI agent registry for public officers. A registry gives security teams a complete inventory of every agent, its capabilities, its data access, and its communication paths.
The zero-trust model must also extend to the tools agents use. Agents connect through model context protocol, or MCP, to external services. Each connection is an attack surface. Organisations need to inventory every MCP connection, verify the identity of each agent, and continuously validate that the agent's behavior matches its assigned role. Privileges should be granted in the smallest dose required for a specific task, and they should expire once the task is complete.
Fighting frontier AI with frontier AI
As organisations deploy AI, so do threat actors. Rahayu Mahzam, Singapore's minister of state for digital development and information, reminded the industry that AI-powered voice phishing attacks that cloned CEO voices in 2025 are no longer hypothetical risks. Those attacks were early warning signs of what agentic AI can do in the hands of malicious actors.
"Agentic AI is here – AI that doesn't just respond, but reasons, plans and acts," Rahayu said. "But with accelerating capabilities and automation come new digital and cyber risks. AI agents that act without sufficient oversight can cause real harm.\
Source: ComputerWeekly.com News