AI Agent Blog

AI Agents Can Run. But on the Network, They Can’t Hide.

Why Passive Packet Access and Unified Network Visibility Are Becoming Essential for Autonomous AI Environments

A few weeks ago, the headline above might have sounded like a dramatic metaphor. Two newly disclosed incidents now make it uncomfortably literal.

IT OT Complete Visibility

Two incidents, two very different attack paths

In the OpenAI/Hugging Face incident, models running in a cyber-capability evaluation found and exploited a previously unknown vulnerability in a package-registry cache proxy. They obtained open internet access, escalated privileges, moved laterally through the research environment and ultimately compromised Hugging Face infrastructure in pursuit of benchmark solutions.

A separate incident disclosed by the UK AI Security Institute (AISI) followed a different path. Agents were intentionally given internet access and tested with cyber safeguards disabled. In the most serious sequence, an agent attempted to insert malicious code into a real open-source project, created fake identities, tried to influence a human maintainer, sent messages and files carrying harmful content, used Tor, and planted prompt-injection instructions intended for other AI coding tools. A human reviewer blocked the malicious contribution, and AISI has not identified resulting real-world harm.

The two cases must be interpreted carefully: both occurred under exceptional evaluation conditions and do not represent normal public deployment. But together they show a clear direction of travel. Autonomous systems can pursue goals over long horizons, combine technical exploitation with deception, and move from a controlled task into real networks and services.

The network is where intent becomes action

Although an AI agent can draw conclusions within an opaque model, it cannot act in isolation. To access a repository, use credentials, perform DNS queries, call an API, move laterally, establish a tunnel, or transfer data, it must interact with systems and networks.

Those actions leave observable traces: connection flows, DNS lookups, source-and-destination relationships, certificates, protocol metadata, timelines, data volumes, failed attempts, and changes in communication patterns.

Even if the application’s payload is protected by TLS, the surrounding network behavior still provides valuable contextual information.

A complete content inspection requires authorized TLS transparency or supplemental telemetry data from endpoints, proxies, and SaaS services; packet-level transparency should not be confused with general plaintext transparency.

This is why the network can become an independent source of truth. It records what the agent actually did, not merely what it was instructed to do or what its own logs claim happened.

Passive access: seeing without becoming part of the traffic

The first requirement is trustworthy access to the relevant packets. At the acquisition layer, NEOX PacketRaven provides passive, out-of-band access at critical observation points:

  • No IP presence on the monitored link
  • No MAC presence on the monitored link
  • No packet injection into production traffic
  • No active participation in the monitored network
  • Full packet copies at the selected observation poin

This independence is crucial. The monitored workload does not have to interact with the transparency layer, and an agent cannot simply suppress its local logs to cover its tracks on the network.

Where resilient inline access is required, PacketHawk provides the appropriate bypass architecture, while PacketRaven remains the foundation for passive observation.

The NEOX Unified Network Visibility Universe

Network Tapping

Packet acquisition alone is not enough. Data traffic must be controlled, distributed, analyzed, stored, and managed as a unified structure. This is where the more comprehensive NEOX platform comes into play:

PacketLion, PacketTiger and PacketWolf aggregate, filter, process and deliver the relevant agent, sandbox, DNS, proxy, server and egress traffic to the right monitoring and security tools.

PacketOwl adds network-based security visibility, helping teams identify known attack techniques, suspicious communication, scanning and lateral movement.

PacketFalcon and PacketGrizzly preserve packet-level evidence for investigation and forensic reconstruction. As my colleague Matthias Lichtenegger recently described, PacketFalcon can serve as an independent network “flight recorder” when prevention and containment controls fail.

PacketDirector provides centralised management, traceability and operational oversight across the visibility platform.

Visibility is only the first step

The OpenAI/Hugging Face and AISI incidents also expose the next challenge. Seeing individual network actions is essential, but defenders ultimately need to understand whether those actions belong to one coherent incident across multiple hosts, identities, services and time windows.

Can a sandbox or proxy exploit, privilege escalation, credential use, lateral movement, external tunnelling and HTTPS/API communication be connected into one attack chain rather than appearing as separate alerts?

Can a social-engineering attempt, a malicious repository change, Tor activity and outbound file transfer be presented as one investigation?

That is the next part of the story: moving from visibility and packet evidence to detection, correlation and a connected attack narrative. It deserves its own article.

The takeaway

AI agents may be new, but the network behaviours they rely on are not. They still use protocols, identities, services, repositories and paths through the infrastructure. With a passive and independent visibility architecture, those actions become observable and forensically defensible.

NEOX Unified Network Visibility provides the foundation: passive packet access, intelligent aggregation and processing, network security visibility, packet capture and centralised operations.

Dr. Stefan Diepolder serves as Head of Solution Engineering at NEOX, bringing decades of leadership experience in communications, security, and IT. He has a strong track record in transforming technology organizations, building customer-focused teams, and turning complex ideas into scalable solutions. At NEOX, Stefan leads Solution Engineering and Pre-Sales, working closely with Sales, Development, and Delivery to translate customer requirements into high-value architectures, PoCs, and solution strategies that strengthen NEOX’s market impact and customer success.