AI is shifting enterprise traffic from human-initiated to machine-generated workflows. Discover why Cisco SD-WAN must evolve to provide the visibility, policy enforcement, and performance assurance needed to support AI operations at scale.

The increasing adoption of artificial intelligence (AI) is fundamentally altering enterprise network traffic patterns, posing new challenges for existing network infrastructures, particularly in the realm of Software-Defined Wide Area Networks (SD-WAN). A 2026 survey conducted by Cisco and Foundry research involving 3,472 IT and networking leaders revealed that organizations experienced an average 34% increase in campus and branch traffic related to AI over the preceding year. Despite this surge, only 15% of respondents considered their networks sufficiently flexible and adaptable to support AI at the required scale, and a significant 73% anticipated facing capacity limitations within the next 24 months.
Traditionally, enterprise networks and SD-WAN solutions were designed with the assumption that traffic was primarily human-generated, following predictable patterns from applications, meetings, and data access. However, the rise of AI, especially autonomous agents and copilots, means machines are increasingly generating network traffic independently. This includes retrieving data, invoking APIs, coordinating actions, and making decisions across various environments, often without direct human initiation. A single AI agent request can trigger dozens of machine-to-machine exchanges, creating a new class of traffic with distinct characteristics.
AI workloads introduce four key changes to network traffic models. First, traffic becomes burstier, as a single AI prompt can initiate multiple downstream transactions. Second, performance becomes more time-sensitive, particularly for voice AI, edge AI, and physical AI applications where latency directly impacts live operations. Third, communication becomes more distributed, with traffic spanning branches, cloud services, data centers, and specialized AI infrastructure. Finally, policy enforcement becomes more consequential as interactions cross regions, environments, and data domains.
Different AI workloads exhibit varying network requirements. For instance, AI voice assistants are highly sensitive to latency, while retrieval-augmented generation (RAG) distributes queries across multiple models and data sources. Video analytics and data ingestion demand sustained throughput, and edge AI and autonomous robots require predictable performance close to operational sites. Agentic AI further amplifies traffic, as one request can lead an agent to retrieve information, invoke APIs, consult other agents, and execute complex workflows, generating numerous machine-to-machine exchanges. This necessitates not only increased capacity but also enhanced visibility and policy management.
The shift from human-generated to machine-generated traffic elevates the strategic importance of SD-WAN. SD-WAN, which already connects diverse locations and applies policy across various transport methods, is uniquely positioned to evolve from optimizing human-initiated application traffic to assuring dynamic, distributed, and business-critical machine-generated workflows. This evolution requires stronger capabilities in four areas: AI workload awareness to identify relevant traffic and understand its performance and policy needs; experience assurance to continuously measure network conditions and steer latency-sensitive AI flows onto optimal paths in real time; integrated security and governance to apply consistent inspection, segmentation, and data-handling policies across all locations; and operational visibility to provide insights into how AI interactions traverse the enterprise for effective troubleshooting, governance, and planning.
The implications for CIOs extend beyond mere bandwidth consumption. The challenge lies in ensuring that the network can recognize, prioritize, secure, and guarantee a new class of traffic whose business importance may be high even when no human is directly involved. For example, in fulfillment centers, autonomous robots, such as the more than one million deployed by Amazon by 2025, rely on reliable connectivity for fleet coordination, telemetry, inventory systems, and cloud services. SD-WAN can maintain operations by prioritizing critical traffic, steering it across the best available path, and applying consistent policy. Similarly, for digital agents approving transactions or coordinating supply chains, the network must differentiate critical interactions from background activity and adapt to changing conditions.
The integration of AI into enterprise operations marks a significant transformation, akin to the impact of cloud computing and mobility on network architectures. These previous shifts changed where applications resided and how users accessed them; AI now changes who or what generates traffic, the speed at which network conditions fluctuate, and the direct impact of network behavior on business outcomes. For CIOs, the opportunity lies in leveraging SD-WAN as the critical policy, assurance, and visibility layer to ensure enterprise AI performs reliably, securely, and at scale.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed