When Anthropic CEO Dario Amodei published “We Must Pace the Frontier”, the AI industry took notice. He is basically saying the industry must pace the rate of model capabilities. It was not a call to stop progress, but an urgent plea to align AI’s trajectory with humanity’s ability to govern it. Amodei prompted the reality of recursive self-improvement and autonomous agent swarms, by laying out a pragmatic vision for improving the pace at which capabilities are delivered.
To manage these risks, the current playbook relies on two main pillars: model governance (embedded evaluators, safety alignment, regulatory checkpoints) and endpoint control (device-level restrictions, API throttling, local sandboxing).
Yet, this debate overlooks a fundamental reality: AI agents do not exist in a vacuum.
Whether executing multi-step business workflows, orchestrating infrastructure, or talking to other autonomous models, AI agents rely on the network. By focusing almost exclusively on how models think (governance) and where they sit (endpoints and infrastructure), we are ignoring the fabric through which agentic behavior actually manifests.
If we’re to “pace the frontier”, as Dario puts it, we must enhance the Zero Trust footprint and control of the network. The following outlines my initial thoughts.
1. Governance Stops Malice; the Network Stops Velocity
Governance measures like the proposal by Anthropic to embed independent third-party evaluators into labs are essential for assessing intent and structural alignment. But governance operates at human speed: through policy, audits, and static evaluations.
AI agents, conversely, operate at machine speed.
When autonomous agents engage in complex, multi-agent orchestrations, emergent behaviors happen in milliseconds. A governance framework cannot issue an emergency intercept mid-handshake when a rogue swarm attempts horizontal privilege escalation. Endpoints can log the activity, but by the time a local process terminates, data exfiltration or lateral movement across enterprise systems has already occurred.
The network is the only layer equipped to monitor, analyze, and policy-enforce agent communications in real time.
2. Agent Swarms are Network-Native Threats
Consider Amodei’s warning regarding rogue agent swarms. When hundreds of autonomous agents communicate, coordinate, and dynamically route around technical guardrails, their primary attack surface is not the prompt, it is the transport layer.
Agents coordinate via API requests, WebSocket streams, and distributed message queues. They move laterally across the network and cloud environments, spin up compute nodes, and dynamic-proxy through benign network routes.
Endpoint controls only see what happens on a single node. Model guardrails only see the prompt-and-completion pair. Neither can detect the macro-pattern of a thousand agents quietly orchestrating a distributed denial-of-service attack or establishing a persistent botnet across thousands of cloud instances.
Without network-level visibility, an organization running a legacy network architecture based on outdated VLAN technology is blind to the machine-to-machine traffic that forms the connective tissue of agentic systems.
3. The Shift to “Zero Trust for AI”
For decades, cybersecurity evolved from perimeters to Zero Trust and the philosophy of never trust, always verify. Yet, we still treat AI agents with implicit network trust. Once an agent receives an API key or token, it is frequently granted broad network access to query the web, make API calls, and interact with internal databases.
Innovation requires extending Zero Trust down to the packet level for non-human identities. We need an Agent-aware Network Architecture that treats an agent just like any other endpoint:
- Intent-Aware Microsegmentation: Isolating agentic traffic so a model tasked with customer support cannot physically reach operational technology, production databases, or critical infrastructure pipelines on the network layer.
- Deterministic Filtering: Preventing autonomous agents from making unverified outbound connections, constraining their capability to exfiltrate data or communicate with unauthorized external command-and-control servers.
- Semantic Network Visibility: Inspecting payload traffic moving between models, validating that machine-to-machine API calls adhere to safe, pre-defined behavioral parameters.
Conclusion: Securing the Foundation, Not Just the Windows
Dario Amodei is right: we must set a pace for the frontier of AI before agentic capabilities outpace human oversight. But slowing down the engine (model capability) and inspecting the framework (governance) is only part of the equation.
If an agentic system breaks through its layers, the network is the final, unbreakable choke point. You cannot exfiltrate data, compromise cloud environments, or build persistent botnets without passing through network infrastructure, gateways, and firewalls. A new and modern network architecture that is based on a built-in Zero Trust fabric, microsegmentation and per-endpoint isolation is now a must within the industry.
If we want true control over the frontier of AI, we must stop treating the network as passive infrastructure. It is time to treat the network as the primary control plane for AI safety.