The perimeter just officially lost. Here's what replaces it.
Agents connect on their own schedule, MCP servers hold standing credentials to your systems of record, and none of it was built with a person at the keyboard in mind. This guide lays out the identity-based Zero Trust architecture that secures LLM and MCP access — mTLS, dark-by-default services, and just-in-time policy — without an upfront inventory project.
Every control you inherited — the VPN, the firewall rule base, the IP allowlist — encodes a person at the keyboard. AI workloads discard that assumption entirely.
An agent initiates connections on its own schedule, holds sessions open for hours, and fans out across dozens of tools in a single task. An MCP server sits between an agent and your system of record, holding credentials that no person ever types. Security teams write the AI usage policy — platform engineering makes it true at the packet level.
API keys, VPNs, and IP allowlists were built to identify a person. AI traffic has no person to identify.
Five different controls, one shared failure: each one authenticates a secret or a network location instead of a workload. The guide walks through exactly why each one breaks — and what replaces it.
Twelve sections. One reference architecture you can start building this afternoon.
From naming the three new AI traffic patterns to a full implementation roadmap that requires no upfront inventory.
Written for the people who make AI usage policy true at the packet level.
Security teams write the policy. This guide is for whoever has to ship the connectivity that enforces it.
You own the connective tissue every agent and MCP server depends on.
Get the reference architecture for identity-based access, without a certificate authority to run yourself.
Prompt injection means you can't fully prevent agent compromise.
See how least-privilege connectivity becomes the containment layer your application controls can't provide.
Agents scale faster than any change ticket can keep up with.
Learn the just-in-time model: grant a connection the moment a workload needs it, revoke it just as fast.
Every MCP server you stand up is a new credentialed pathway.
Understand what makes an MCP server "dark by default" — and why that's the single most effective control.
VPNs grant a network position when a workload needs one service.
Walk through why that mismatch — and IP-based rules generally — fail for ephemeral AI workloads.
An auditor will eventually ask which agent touched what, and when.
See how policy-as-code turns your audit trail into a byproduct of how connectivity works, not a bolt-on project.
Six ideas the guide builds toward.
The 2026 DBIR found vulnerability exploitation, not stolen credentials, is now the #1 way attackers get in — and VPNs/edge devices are the most attacked infrastructure in most environments.
AI introduces three new traffic patterns your network was never built for: LLM access, MCP access, and agent-to-agent east-west traffic.
API keys, VPNs, and IP allowlists all fail for AI workloads, because they identify locations and secrets, not workloads.
Zero Trust principles — cryptographic identity, least privilege, deny-by-default, just-in-time access — map onto AI infrastructure with unusual precision.
Prompt injection means you can't fully prevent agent compromise — so least-privilege connectivity becomes your real containment layer.
A dark-by-default architecture needs no upfront inventory — onboard your first agent-to-MCP connection in an afternoon and build from there.
Get The Platform Engineer's Guide to AI Network Architecture
The full reference architecture, implementation roadmap, and platform evaluation checklist — ready to apply to your first agent-to-MCP connection.
