AgenticOps Arrives in the Network: 51% Already Let Agents Act in Production

·11 min read·Evergreen Tools Team

On September 23, 2026 Cisco released The Impact of Agentic AI on Network Operations, research conducted independently by Omdia. The study surveyed 1,000 IT and network operations leaders at organisations with 500 or more employees across North America, Western Europe, and Asia-Pacific. The conclusion is direct: organisations have crossed from AI in an advisory role into AgenticOps, a model where operators set direction and guardrails and AI agents sense, reason, and act across domains. More than four in five respondents expect to reach an AI-led operating model within 12 months, three quarters are willing to grant agentic AI significant autonomy in NetOps, and nearly a quarter are comfortable with fully autonomous operation and no human oversight.

1. The Alert Math No Longer Works

The report opens with arithmetic that explains why autonomy stopped being a novelty. The average organisation generates about 4,100 monitoring alerts and events each day, more than half of them network related, and at that volume clearing the daily network-alert backlog by hand would require roughly 100 IT specialists. Efficiency is worse than the raw count suggests. Nearly half of network alerts are closed without investigation, and an almost identical share of respondents say investigation time goes to false positives. Complexity compounds it: 92% report that performance issues commonly span multiple domains requiring correlation across ten or more tools, and 57% say current change processes cannot match the speed required. Put together, the numbers do not argue that AI is exciting; they argue that the old alerting model has already failed.

# Intent, not scripts. AgenticOps means operators declare the outcome and
# the guardrail, and agents choose the path inside it. Everything that
# follows is a constraint the runtime enforces, not advice for the agent.

intent:
  name: keep-payments-latency
  target: "p95_latency_ms <= 40 for service=payments"
  scope: [region:ap-northeast, tier:edge]
  allowed_actions:
    - shift_traffic_weight      # within declared bounds only
    - scale_edge_pool
    - rollback_last_change
  forbidden:
    - modify_firewall_policy
    - change_dns_ttl            # blast radius too wide for autonomy
  approval_required:
    - anything_touching: [region:us-east, tier:core]
  observe_only_hours: 72        # shadow mode before the agent may act
A network operations centre

The average organisation generates about 4,100 alerts and events a day

2. Agentic Is Deployed, Not Discussed

What makes the report notable is that autonomy is already in the present tense. 75% of organisations have deployed AI for NetOps and 51% run agentic AI that acts in production today. That includes rerouting traffic, adjusting wireless parameters, isolating suspicious endpoints, and resolving incidents end to end without prior human approval. Appetite matches the deployment. 80% are comfortable granting AI a high or fully autonomous role in NetOps, including 24% who are comfortable with no human oversight at all. 82% are comfortable allowing AI to make at least some production network changes without prior approval, and 84% expect an AI-led operating model within twelve months. If your organisation is still debating whether agents should be permitted to act, the report's answer is that you are behind most of your peers.

// Blast radius is the whole argument. 82% are comfortable letting AI make
// some production changes without prior approval, which is only reasonable
// if the change cannot exceed a bound you chose in advance.

export function admit(change, intent) {
  const checks = [
    { name: "scope",    ok: within(change.targets, intent.scope) },
    { name: "action",   ok: intent.allowed_actions.includes(change.kind) },
    { name: "forbidden", ok: !intent.forbidden.some((f) => matches(change, f)) },
    { name: "budget",   ok: change.affectedPct <= 5 },          // <= 5% of traffic
    { name: "window",   ok: !inFreeze(change.now) },
  ];
  const failed = checks.filter((c) => !c.ok).map((c) => c.name);
  if (failed.length) {
    // Pause for a human rather than guessing. 24% would skip this step;
    // for anything in scope [tier:core] that is a bad trade.
    return { decision: "escalate", reasons: failed, reviewer: intent.owner };
  }
  return { decision: "allow", rollout: { canaryPct: 5, watch: "p95_latency_ms" } };
}

3. Writing Intent as an Enforceable Guardrail

Autonomy is not abandonment, and Cisco frames the shift as moving from running operations to orchestrating intent. Code sample 1 turns that sentence into an executable file: the objective is stated precisely, payments p95 latency at or below 40 milliseconds; the scope is bounded, the ap-northeast edge tier; permitted actions are enumerated, shifting traffic weight within declared bounds, scaling the edge pool, rolling back the last change; and forbidden actions are named, modifying firewall policy or changing DNS TTL, because the blast radius is too wide for autonomy. One field is easy to overlook and matters a great deal: the shadow period during which the agent may observe but not act. Writing intent down this way pays off three times, as instructions to the agent, as review material for humans, and as the basis for a runtime admission decision.

# The alert math is what makes autonomy attractive: ~4,100 events a day,
# more than half of them network related, and roughly 100 specialists
# needed to clear the backlog by hand. Correlation is not optional.

def dedupe(events: list[dict]) -> list[dict]:
    # 92% of organisations say performance issues span multiple domains and
    # need 10+ tools to resolve. Collapse them into one incident instead.
    groups: dict[str, dict] = {}
    for e in events:
        key = (e["service"], e["region"], e["failure_mode"])   # not the timestamp
        g = groups.setdefault(key, {"key": key, "count": 0, "domains": set(),
                                    "first": e["ts"], "last": e["ts"]})
        g["count"] += 1
        g["domains"].add(e["domain"])
        g["last"] = e["ts"]
    return sorted(groups.values(), key=lambda g: (-len(g["domains"]), -g["count"]))

# Roughly half of network alerts are closed without investigation today.
# Ranking by domain spread tells you which half was actually safe to skip.
Autonomy and trust

80% accept high autonomy, but 69% demand detailed explainability

4. Blast Radius Is the Whole Argument

The finding that 82% are comfortable with production changes going out without prior approval is only reasonable if a change cannot exceed a boundary you chose in advance. Code sample 2 lays out five admission checks: whether the targets fall inside the authorised scope, whether the action kind is on the allowed list, whether it trips a forbidden pattern, whether affected traffic stays at or below 5%, and whether a freeze window is in effect. If any check fails the change escalates to a human rather than letting the agent guess, which matters because 24% of organisations would skip that step and the downside of skipping it on a core-tier target is asymmetric. Code sample 5 handles the other half, progressive rollout: let the agent act on a 5% slice, watch the exact metric the intent promised for fifteen minutes, and roll back automatically on regression. Together these samples define the trust the report describes as visibility, explainable context, and guardrails that produce deterministic outcomes.

// The report is unambiguous about the price of autonomy: full observability,
// with tracing, a summarised rationale, and post-action audits, is the
// minimum acceptable standard for 36% of organisations, and 69% require
// detailed explainability for agent-driven actions. So record all of it.

type AgentAction = {
  traceId: string;
  agent: string;
  intent: string;              // which declared objective authorised this
  tool: string;                // e.g. shift_traffic_weight
  args: Record<string, unknown>;
  rationale: string[];         // the agent's reasoning, in its own words
  evidence: string[];          // telemetry ids it read before deciding
  predicted: Record<string, number>;   // expected p95, error rate, cost
  observed?: Record<string, number>;   // filled in after the window closes
  rollback?: { at: string; by: string; verified: boolean };
};

// "It shows its work, so I can follow the logic" is the difference between
// a force multiplier and a queue of tickets nobody trusts.

5. The Network Itself Is Changing

One finding in the report is easy for engineering teams to miss and impossible for operations teams to ignore, which is traffic. According to Cisco's analysis of aggregated direct-to-AI network telemetry, AI traffic is on a trajectory to double every six months, and when agent-generated traffic is included, Cisco testing found that tasks performed by agents can generate up to 450% more total network traffic. An agent optimising a service-level objective can therefore be loading the network underneath it. Code sample 5 watches both the service and the network when it decides whether to roll back. Code sample 3 addresses the alert stream itself, collapsing thousands of events into one incident keyed on service, region, and failure mode, and ranking by how many domains are involved. Since roughly half of network alerts are closed without investigation today, the quality of that ranking decides which closures are actually safe.

#!/usr/bin/env bash
# Progressive rollout beats a big-bang switch. Let the agent act on a small
# slice, watch the same metric the intent promised, and lose the argument
# automatically if the slice degrades.

set -euo pipefail
intent="$1"; slice="5"; window="15m"

agent-apply --intent "$intent" --slice "$slice"
if ! agent-watch --intent "$intent" --window "$window" --max-regression 2pct; then
  echo "regression detected in slice; rolling back"
  agent-apply --intent "$intent" --rollback
fi

# Cisco testing found agent-performed tasks can generate up to 450% more
# total network traffic, and AI traffic is on a trajectory to double every
# six months. Watch the network too, not just the service. 
New traffic generated by agents

Cisco testing found agent tasks can add up to 450% more traffic

6. Explainability Is the Price of Admission

The report is explicit about what autonomy costs. 69% require detailed explainability for agent-driven actions, 36% say full observability, meaning detailed tracing, a summarised rationale, and post-action audits, is the minimum acceptable standard, and 86% say a single integrated platform rather than another point tool is the most effective path forward. Code sample 4 lists what should be recorded: a trace ID, which declared intent authorised the action, the tool invoked, its arguments, the agent's own reasoning, the telemetry it read before deciding, the predicted metrics, and the observed metrics once the window closes. Joe Vaccaro, SVP and GM of Network Platform and Assurance at Cisco, frames it as trust built on visibility into every decision, explainable context behind every recommendation, and guardrails that ensure deterministic outcomes. Mark Rodrigue, a senior network engineer at Room & Board, puts it more plainly: the system shows its work, so he can follow the logic and see the evidence chain behind every recommendation, and that is the trust it takes to deploy agents at scale.

📌 Frequently Asked Questions

Who conducted the Cisco research?

The Impact of Agentic AI on Network Operations was conducted independently by Omdia and surveyed 1,000 IT and network operations leaders at organisations with 500 or more employees across North America, Western Europe, and Asia-Pacific.

How many organisations already let agents act in production?

51% run agentic AI that acts in production today, 75% have deployed AI for NetOps, and 84% expect an AI-led operating model within twelve months.

Why are organisations willing to grant autonomy?

Alert volume has outgrown human capacity: the average organisation generates about 4,100 alerts and events a day, more than half network related, and clearing the backlog by hand would take roughly 100 IT specialists. Nearly half of network alerts are already closed without investigation.

What does the report say about network traffic from agents?

Cisco's analysis of aggregated direct-to-AI telemetry puts AI traffic on a trajectory to double every six months, and Cisco testing found that agent-performed tasks can generate up to 450% more total network traffic.

What does the report require before autonomy scales?

Explainability and observability. 69% require detailed explainability for agent-driven actions, 36% consider full observability with tracing, summarised rationale, and post-action audits the minimum standard, and 86% want a single integrated platform.