For most of my career in networking, the operating model hasn't fundamentally changed.
A switch switches.
A firewall filters.
A monitoring platform monitors.
A SIEM collects events.
And somewhere in the middle of all of that sits a network engineer trying to figure out what actually happened.
We have become incredibly good at generating data.
Logs. Alerts. Flows. Metrics. Traps. Configuration changes. Authentication events. DHCP records. DNS queries. Endpoint telemetry.
The problem isn't lack of information anymore.
The problem is understanding it fast enough to matter.
And I think we're approaching a significant change in how that happens.
AI is moving into the network
We've mostly experienced AI as something that lives somewhere else.
You open a browser.
Send a request to a cloud service.
Get an answer back.
But a new generation of hardware is making another architecture increasingly practical: powerful AI models running locally, inside the business itself.
Machines like NVIDIA's DGX Spark and the NVIDIA-powered systems being built by ASUS and other manufacturers can put serious AI compute into a box small enough to sit on a desk.
That may sound like a hardware story.
I don't think it is.
I think it's a network operations story.
Because once AI can live next to the infrastructure, the question changes from:
"What can I ask AI?"
to:
"What can AI continuously understand about my environment?"
Think about a normal network incident
Imagine it's 8:15 Monday morning.
Users report that "the network is slow."
What happens?
Someone opens the firewall.
Someone checks WAN utilization.
Someone looks at the switches.
Someone checks wireless.
Maybe they look at DNS.
Maybe authentication logs.
Maybe an ISP dashboard.
Maybe yesterday's configuration changes.
Eventually an experienced engineer starts connecting the dots.
Now imagine an intelligence layer that has already been watching those systems.
You ask:
"Why is the network slow this morning?"
Instead of another graph, it responds:
"WAN latency began increasing at 7:42 AM. No corresponding increase in total bandwidth utilization occurred. At 7:39 AM, traffic for two internal networks shifted to the secondary VPN path following three tunnel interruptions. Switch interfaces and wireless utilization remain normal. The issue is likely upstream of the LAN."
That doesn't replace the engineer.
It gives the engineer something we've never really had before:
a system capable of reasoning across multiple sources of network information at the same time.
That's different from monitoring
Traditional monitoring is very good at answering:
Is interface utilization above 80%?
Did this device stop responding?
Did CPU cross a threshold?
Did this tunnel go down?
Those are valuable questions.
But network engineers usually have to answer something much harder:
What does all of this mean together?
A firewall alert by itself may mean nothing.
A DHCP event by itself may mean nothing.
A spike in DNS traffic may mean nothing.
A new device appearing may mean nothing.
An authentication failure may mean nothing.
But put them together in the right sequence and suddenly they tell a story.
That correlation layer is where AI becomes interesting.
The NOC could become conversational
Today, network operations often looks something like:
Network → Telemetry → Dashboard → Engineer → Investigation → Action
The next generation may look more like:
Network → Telemetry → AI → Engineer → Action
And eventually, for carefully defined and controlled operations:
Network → Telemetry → AI → Approved Automation → Network
That last step needs guardrails.
Lots of them.
I am not interested in letting an LLM randomly rewrite production firewall policies because it thinks it found a better configuration.
But consider smaller, controlled workflows.
Detect an anomaly.
Correlate the surrounding events.
Compare the current configuration with yesterday's.
Identify the likely cause.
Recommend a change.
Show the engineer the evidence.
Wait for approval.
Implement the change through a controlled automation.
Validate whether the problem improved.
Roll back if it didn't.
That isn't science fiction anymore.
The networking industry is actively building toward exactly this kind of agentic operational model.
And there's another part of this that businesses should pay attention to
The AI doesn't necessarily have to live in the cloud.
Imagine a small manufacturer, healthcare office, engineering firm or government contractor.
Their network infrastructure generates extremely sensitive operational information:
Internal IP addresses.
Device inventories.
Firewall configurations.
User identities.
Authentication events.
Security alerts.
DNS activity.
Network topology.
Configuration history.
Potentially even information about where sensitive systems and data live.
There are good reasons an organization may not want all of that continuously shipped into a public AI platform.
Local AI introduces another option.
Put the compute inside the environment.
The business owns the hardware.
The monitoring data stays inside.
The network configurations stay inside.
The security telemetry stays inside.
The AI operates where the data already lives.
That changes the privacy conversation significantly.
Cloud AI will absolutely continue to have a major role.
But I suspect many organizations will eventually operate a hybrid model:
Cloud AI for general intelligence.
Private AI for operational intelligence.
Now imagine this for an SMB
This is where I think things get particularly interesting.
Large enterprises have had sophisticated NOCs, SIEM teams, automation engineers and expensive analytics platforms for years.
A 40-person manufacturer doesn't.
A 75-person professional services company doesn't.
A small government contractor probably doesn't.
But they still have:
A firewall.
Switches.
Wi-Fi.
VPNs.
Microsoft 365 or Google Workspace.
Servers.
Endpoints.
Security tools.
Logs.
And problems.
What if a relatively small on-premises AI system could become an intelligence layer over that environment?
Instead of an SMB owner receiving 46 alerts they don't understand:
"Tell me what happened on my network today."
Instead of asking whether their firewall is secure:
"What changed in my firewall configuration this month?"
Instead of staring at a monitoring dashboard:
"Which three network issues should I actually care about right now?"
Instead of waiting for an annual security review:
"Has anything changed that materially affects our security posture?"
Now we're getting somewhere.
Network engineers aren't disappearing
Whenever AI enters an engineering conversation, someone eventually asks whether it replaces engineers.
I think that's the wrong question.
Networks are full of context.
Why does this firewall rule exist?
Why is that VLAN allowed to communicate with another VLAN?
Why is that old server still online?
Why does this application require that port?
Why does this branch route traffic differently?
AI can see configuration.
It doesn't automatically understand intent.
That's where engineering judgment becomes even more important.
The role starts shifting.
Less time:
manually searching through thousands of log entries.
More time:
designing what data should be collected.
Less time:
jumping between dashboards.
More time:
building the context that allows systems to correlate them.
Less time:
performing repetitive configuration checks.
More time:
defining what AI is allowed to recommend, automate — and absolutely not touch.
The network engineer increasingly becomes the person designing the guardrails around intelligence.
The network stack may be getting a new layer
We've traditionally thought about infrastructure in layers.
Physical infrastructure.
Network.
Security.
Applications.
Monitoring.
Cloud.
I think another layer is forming:
Operational Intelligence.
A layer capable of consuming information from everything underneath it and answering:
What changed?
What is abnormal?
What is related?
What is likely causing this?
What should we investigate?
What should we fix first?
And eventually:
What can safely be fixed automatically?
That could fundamentally change how networks are operated.
Especially for organizations that have infrastructure but don't have a 24/7 NOC watching it.
We're still early
There are plenty of challenges.
AI models hallucinate.
Telemetry needs normalization.
Vendor APIs vary wildly.
Network context matters.
Permissions matter.
Security matters enormously.
Automation needs rollback.
And AI recommendations must never be confused with deterministic network state.
So no — I don't think we're plugging an AI box into a network tomorrow and firing the NOC.
But I do think something important is happening.
For decades, we built tools that allowed humans to see networks.
Then we built APIs that allowed software to control networks.
Now we're beginning to build systems that can reason about networks.
That's a very different capability.
And when the compute required to do that can sit quietly on a desk inside the customer's environment, the economics — and the architecture — start changing too.
We spent years making networks software-defined.
The next chapter may be making them intelligence-driven.
And for network engineers, I think that's going to be one of the most interesting shifts we've seen in a long time.