Technical Guide · Platform Engineering

The perimeter just officially lost. Here's what replaces it.

Agents connect on their own schedule, MCP servers hold standing credentials to your systems of record, and none of it was built with a person at the keyboard in mind. This guide lays out the identity-based Zero Trust architecture that secures LLM and MCP access — mTLS, dark-by-default services, and just-in-time policy — without an upfront inventory project.

Download the free guide 26 pages · No inventory required to start
60%
jump in third-party involvement in breaches
45%
of employees now using unapproved "shadow AI"
21%
month-over-month growth in AI bot traffic
guide to ai network architecture
The problem
Every control you inherited — the VPN, the firewall rule base, the IP allowlist — encodes a person at the keyboard. AI workloads discard that assumption entirely.

An agent initiates connections on its own schedule, holds sessions open for hours, and fans out across dozens of tools in a single task. An MCP server sits between an agent and your system of record, holding credentials that no person ever types. Security teams write the AI usage policy — platform engineering makes it true at the packet level.

31%
of breaches now start with vulnerability exploitation — overtaking stolen credentials for the first time in the DBIR's 19-year history.
increase in attacks on edge devices and VPNs — the appliances meant to guard the perimeter are now the leading way in.
109:1
average ratio of machine identities to human identities across today's organizations.
Why old controls fail

API keys, VPNs, and IP allowlists were built to identify a person. AI traffic has no person to identify.

Five different controls, one shared failure: each one authenticates a secret or a network location instead of a workload. The guide walks through exactly why each one breaks — and what replaces it.

 
73%
of ransomware victims had an infostealer infection or credential leak in the year before their attack.
 
81%
year-over-year rise in leaked AI service credentials — the fastest-growing category of exposed secrets.
 
85%
projected growth in AI agent populations over the next twelve months.
 
68%
of security teams say they lack identity security controls for AI workloads altogether.
 What's inside

Twelve sections. One reference architecture you can start building this afternoon.

From naming the three new AI traffic patterns to a full implementation roadmap that requires no upfront inventory.

01The Perimeter Just Officially LostP.2
02The New AI Traffic Patterns You Must SecureP.4
03Why Perimeter and VPN Models Fail for AIP.6
04Zero Trust Principles Applied to AI InfrastructureP.9
05mTLS: The Foundation of Machine-to-Machine TrustP.12
06Access Control for LLM EndpointsP.13
07Access Control for MCP ServersP.15
08Governance and Observability for AI ConnectivityP.17
09What to Look for in an AI Networking PlatformP.19
10Reference Architecture: Putting It TogetherP.21
11Implementation Roadmap: Just-in-Time Zero TrustP.23
12Your Next StepsP.25
Who it's for

Written for the people who make AI usage policy true at the packet level.

Security teams write the policy. This guide is for whoever has to ship the connectivity that enforces it.

Platform Engineer

You own the connective tissue every agent and MCP server depends on.

Get the reference architecture for identity-based access, without a certificate authority to run yourself.

Security Architect

Prompt injection means you can't fully prevent agent compromise.

See how least-privilege connectivity becomes the containment layer your application controls can't provide.

DevOps / Platform Lead

Agents scale faster than any change ticket can keep up with.

Learn the just-in-time model: grant a connection the moment a workload needs it, revoke it just as fast.

AI / ML Engineer

Every MCP server you stand up is a new credentialed pathway.

Understand what makes an MCP server "dark by default" — and why that's the single most effective control.

Network Architect

VPNs grant a network position when a workload needs one service.

Walk through why that mismatch — and IP-based rules generally — fail for ephemeral AI workloads.

CISO / Security Leader

An auditor will eventually ask which agent touched what, and when.

See how policy-as-code turns your audit trail into a byproduct of how connectivity works, not a bolt-on project.

Key takeaways

Six ideas the guide builds toward.

01

The 2026 DBIR found vulnerability exploitation, not stolen credentials, is now the #1 way attackers get in — and VPNs/edge devices are the most attacked infrastructure in most environments.

02

AI introduces three new traffic patterns your network was never built for: LLM access, MCP access, and agent-to-agent east-west traffic.

03

API keys, VPNs, and IP allowlists all fail for AI workloads, because they identify locations and secrets, not workloads.

04

Zero Trust principles — cryptographic identity, least privilege, deny-by-default, just-in-time access — map onto AI infrastructure with unusual precision.

05

Prompt injection means you can't fully prevent agent compromise — so least-privilege connectivity becomes your real containment layer.

06

A dark-by-default architecture needs no upfront inventory — onboard your first agent-to-MCP connection in an afternoon and build from there.

Free Technical Guide · 26 Pages

Get The Platform Engineer's Guide to AI Network Architecture

The full reference architecture, implementation roadmap, and platform evaluation checklist — ready to apply to your first agent-to-MCP connection.

A reference architecture diagram covering LLM, MCP, and agent-to-agent traffic
The 5-point checklist for evaluating an AI networking platform
A no-inventory-required implementation roadmap
Download the Guide