AI Networking Intelligence
Daily Briefing · Jul 25, 2026
ServiceNow reported Q2 FY 2026 total revenue of $3.99 billion, up 24% year-over-year, with AI Control Tower adoption and agentic AI moving further into production environments. The company's AI platform strategy validation shows enterprises moving past pilot fatigue into governed, production AI workflows with integrated observability.
ServiceNow's Q2 results validate its AI platform strategy by tying AI adoption to governed action rather than assistant-only use cases. AI Control Tower, built on the Traceloop acquisition completed in March 2026, provides deep runtime observability into how AI agents reason, where they make decisions, and when course-correction is needed. This replaces periodic manual audits with continuous live monitoring. The platform now discovers AI assets across 30 third-party systems including AWS, Google Cloud, Microsoft Azure, SAP, Oracle, and Workday—extending governance, observability, and security well beyond ServiceNow's own ecosystem. For network and AIOps practitioners, this signals a fundamental shift: observability platforms must now monitor not just infrastructure and applications, but the behavior and decision-making of autonomous AI agents. The practical implication is that traditional alert-and-dashboard models are giving way to runtime governance and tracing, requiring new instrumentation and decision-tracking capabilities at the agent execution layer.
Read full article ↗MCP's maintainers plan to finalize the protocol's 2026-07-28 revision with substantial non-backward-compatible changes reflecting hard lessons learned. The move to statelessness enables enterprises to use MCP as middleware for controlling AI agent access to production systems, giving cyber teams a unified control point.
On July 28, MCP's maintainers will finalize the protocol's 2026-07-28 revision with the most substantial changes since adding authorization, including removal of the initialization handshake. The protocol version, client info, and client capabilities now travel in _meta on every request. The 10-week window between the release candidate and final spec allows SDK maintainers and server implementers to validate changes against real workloads—critical for teams already running MCP servers in production. For infrastructure practitioners, the shift to statelessness means MCP servers can now be horizontally scaled behind load balancers and API gateways without session affinity concerns, enabling MCP as enterprise middleware rather than point solutions. Stacklok CEO Craig McLuckie noted that MCP's original stateful design emerged from supporting developers using coding tools locally, but the broader AI community now embraces MCP as a mechanism for enterprises to intermediate access to production systems with consistent governance and operational controls.
Read full article ↗On July 28, 2026, the Model Context Protocol publishes its largest revision since launch—a foundation change for every production MCP deployment. The spec delivers stateless core scaling on ordinary HTTP infrastructure, first-class extensions (MCP Apps, Tasks), OAuth/OIDC hardening, and formal deprecation policy.
The MCP 2026-07-28 specification is not a marginal update but a fundamental architectural shift enabling MCP as critical infrastructure behind load balancers, API gateways, and enterprise identity providers. Release candidate locked May 21, 2026; final spec ships July 28, 2026. This follows April 2026 analysis of how MCP stabilization and A2A protocol reshaped agent interoperability. The move to stateless design is operationally critical: MCP servers can now be deployed as stateless microservices on Kubernetes, scaled horizontally with standard load-balancing, and integrated into existing service mesh ecosystems without session affinity. Authentication and session state move to the HTTP layer (OAuth/OIDC), enabling enterprises to apply existing identity and access management infrastructure. For companies already connecting Claude, Cursor, n8n, or custom agents to remote MCP servers, this clarifies migration paths: what breaks, what improves, and how to upgrade without interrupting workflows. The stateless design also reduces operational complexity—MCP becomes just another HTTP service in your infrastructure, governed by standard observability, scaling, and resilience patterns.
Read full article ↗AMD partnered with Cisco at the Advancing AI event to support observability and governance controls for its $4,000 compact, high-performance developer PCs, with Cisco's Splunk observability and monitoring offerings applying to Ryzen AI Halo hardware. The collaboration extends network governance to edge-deployed AI inference workloads.
Cisco's Secure Network will underpin the PCs, which are designed for powering intense AI and agentic workloads from the desktop. For companies deploying Halo PC en masse for their developers, Cisco will support fleet-wide observability, tracking agent behavior, token usage, and compute utilization. DefenseClaw, the vendor's open source agent security tool, adds guardrails directly on-device, ensuring policy enforcement is maintained. For infrastructure teams scaling agentic AI at the edge, this represents a practitioner-relevant convergence: observability tools built for cloud-native environments now extend governance, policy enforcement, and telemetry collection to distributed AI developer endpoints. The partnership surfaces the operational reality that autonomous AI agents deployed across infrastructure require centralized visibility and control—whether running in data centers or developer workstations—and shows Cisco positioning observability as the foundation for managing agentic systems at scale.
Read full article ↗CrowdStrike and Cerebras announced a strategic partnership to integrate Cerebras' high-speed AI inference technology with CrowdStrike's Falcon AI Detection and Response platform. CrowdStrike will run its AIDR models on Cerebras infrastructure, while Cerebras will adopt the Falcon platform to secure its own operations. The deal aims to slash response times against cyberattacks that now unfold in seconds.
CrowdStrike and Cerebras announced a partnership to integrate Cerebras' AI inference infrastructure with CrowdStrike's Falcon AIDR models, with Cerebras also adopting Falcon to secure its own operations. The timing addresses a critical shift in the threat landscape where every millisecond determines whether AI prevents an attack or merely explains it afterward. For SecOps and AIOps practitioners, this partnership has direct operational implications. CrowdStrike will leverage Cerebras's industry-leading inference speed to run Falcon AIDR models at machine speed, pairing AI-native security with the world's fastest inference. The pairing of Falcon's lightweight agent architecture with Cerebras' inference capability targets the detection-to-response latency gap that manual SOAR playbooks cannot close. Shares of Cerebras surged 7.05% while CrowdStrike slipped 1.90% on the announcement. For organizations standardized on Falcon, this partnership signals deeper investment in AI-native detection. For those evaluating AI-augmented incident response, the inference-speed component becomes a measurable procurement factor when comparing XDR and AIDR platforms.
Read full article ↗AMD's Advancing AI 2026 opened with the commercial debut of EPYC "Venice," the first x86 server processor to enter volume production on TSMC's 2-nanometer process node, alongside the Instinct MI450-series GPU accelerators and the Helios rack-scale AI system. The EPYC 9006 "Venice" family offers CPU core counts of up to 96-core/192-thread on chips with "Zen 6" cores, and up to 256-core/512-thread on chips with compacted "Zen 6c" cores. For infrastructure teams evaluating multi-socket fabric deployments, AMD now has a complete current-generation AI stack on the market backed by commitments from Meta, Microsoft, Oracle, and OpenAI.
AMD formally launched its 6th generation EPYC server CPUs at its flagship Advancing AI conference July 22-23, 2026. Venice represents a major generational leap: it's the first x86 HPC CPU to achieve volume production on TSMC's 2nm node, with up to 256 cores (using compact Zen 6c) and up to 96 full-speed Zen 6 cores depending on SKU. The processor features 5th generation Infinity Fabric, PCIe Gen 6 with 128 lanes per socket, 16-channel DDR5 memory support (up to DDR5-12800 on MRDIMMs), and CXL 3.1 support. For networking practitioners, the CPU includes significantly increased I/O die capacity to support four MI450-series GPUs, DPUs, and 800G NICs per node in Helios racks. The Helios rack-scale system bundles 72 MI455X GPUs with Venice CPUs and Pensando networking into a single integrated platform priced around $5.25M, with H2 2026 availability. This creates a real procurement window for enterprises: with Intel Xeon's next competitive response not arriving until mid-2027, AMD's integrated stack (CPUs, GPUs, networking, orchestration) now represents the only current-generation alternative to hyperscaler-optimized systems.
Read full article ↗After overtaking Cisco as the largest data center Ethernet switch vendor in 2024, Arista continues riding the AI wave as hyperscalers race to wire ever-larger GPU clusters with high-speed Ethernet. Arista reported first-quarter 2026 revenue of $2.71 billion, up 35.1% year over year, and raised its full-year AI networking target to $3.5 billion—roughly double its AI-related sales from a year earlier. Customers want the newest silicon at the fastest pace, moving from 400-gig to 800-gig and now to 1.6-terabit platforms, with power now as much a constraint as bandwidth.
Arista Networks continues to dominate the data center Ethernet switch market with strong momentum from AI infrastructure buildouts. The company reported Q1 2026 revenue of $2.71B (35% YoY growth), with deferred revenue reaching $6.2B—driven by longer customer acceptance cycles on new AI leaf-spine products rather than demand weakness. The company raised its full-year AI networking revenue target to $3.5B, effectively doubling YoY AI sales. Two customers (Microsoft and Meta) each represent 10%+ of total revenue, underscoring concentration among hyperscalers. The technical transition reflects: shift from 400G→800G→1.6T port speeds; power density as a primary constraint alongside bandwidth; adoption of liquid cooling and linear-drive pluggable optics (LPO) to reduce power in dense AI fabrics; and rapid adoption of Broadcom Tomahawk 6 silicon in next-generation platforms. Arista's 7060XE7 series (announced June 9, 2026) targets rack-scale AI with 1.6T ports, shipping Q4 2026. Meanwhile, Nvidia has captured 21.5% market share in data center Ethernet switches (Q1 2026), creating competitive pressure on all incumbent vendors.
Read full article ↗Claude Opus 5 reaches roughly Claude Fable 5–level intelligence at half the price ($5 per million input tokens, $25 output), adds a low/medium/high effort toggle to trade cost for capability per request, and sets new state-of-the-art scores on agentic-coding and knowledge-work benchmarks. Anthropic compared Fable 5 to Opus 5 across 13 benchmarks, with the latter scoring higher on eight of the tests despite costing about 50% less, and performing 9.7% better than Fable 5 on GPQA Diamond.
Claude Opus 5 first surfaced as "Honeycomb EAP" inside Cursor on July 9 and was pulled within hours, then rolled out across providers on July 23, 2026, with the rollout extending into July 24. Standard mode is $5 per million input tokens and $25 per million output tokens — the same rate as Opus 4.8 and half of Fable 5's input price, while fast mode doubles the rate ($10/$50) and runs about 2.5× faster. The spec profile includes a 1 million token context window, an "xhigh" reasoning effort setting, per-turn controls, and a safety fallback that routes to Claude Opus 4.8 on trigger. The model outperformed Opus 4.8 across all internal life sciences benchmarks and proved particularly adept at automated protein research, an important field that was the focus of the 2024 Nobel Prize in chemistry. On Anthropic's own table it more than doubles Opus 4.8 on agentic terminal coding and posts the lowest misalignment score the company has measured. Anthropic discloses that its Frontier-Bench v0.1 figures come from an internal run on the mini-SWE-agent harness with a GKE backend, taking mean reward over five attempts per task — and that Opus 4.8 served as the fallback on safety-classifier refusals.
Read full article ↗Google shipped Gemini 3.6 Flash on July 21, 2026, with 17 percent fewer output tokens than Gemini 3.5 Flash on the Artificial Analysis Index, and on individual evals like DeepSWE the reduction reaches 65 percent. Google cut the output price from 9 dollars to 7.50 dollars per million tokens, and combined with the efficiency gain, the effective cost per completed task drops roughly 31 percent, and up to about 71 percent on agentic coding workloads.
Building on Gemini 3.5 Flash, Google describes 3.6 Flash as its workhorse model, reducing output token usage by 17% according to the Artificial Analysis Index, and released three new Gemini models on July 21: Gemini 3.6 Flash, Gemini 3.5 Flash-Lite, and Gemini 3.5 Flash Cyber. Output dropped from $9.00 to $7.50 per million tokens with input held steady at $1.50, and on the DeepSWE coding benchmark the model scores 49 percent, up from 37 percent for 3.5 Flash. Gemini 3.6 Flash scores 49% on the DeepSWE benchmark and pushes machine learning engineering performance higher, scoring 63.9% on MLE-Bench compared to 49.7% previously. The model takes fewer reasoning steps and tool calls to accomplish multi-step workflows and exhibits reduced verbosity. Both 3.6 Flash and 3.5 Flash-Lite feature a one-million-token input context window and a maximum output limit of 64,000 tokens, with native multimodal input, thinking controls, and built-in Computer Use as a client-side tool via the Gemini API.
Read full article ↗OpenAI introduced Presence, a product designed to help enterprises deploy trusted AI agents that can answer questions, resolve issues, use company systems, take approved actions, and escalate to people when needed. Presence bundles company policies and standard operating procedures, permission controls, escalation rules, and pre-deployment simulations; after launch, a Codex agent reviews interactions, identifies weaknesses, and proposes behavioral improvements that staff must test and approve before going live.
The challenge for enterprises is making AI agents reliable enough to do high-value work in production, which requires more than a model: it requires systems, evaluations, and deployment expertise to improve agents without giving up control. Deployments are led by OpenAI Forward Deployed Engineers and select global systems integrators, drawing from the OpenAI Deployment Company subsidiary formed in May with $4 billion in backing and a $10 billion valuation. Target use cases span customer support, outbound sales development, procurement, IT services, and HR functions, with agents able to verify identity, access account data, apply company policies, and execute approved actions including billing resolution and refunds. OpenAI says Presence already handles its own English-language phone support line and resolves 75% of inbound calls without human intervention, with a Codex-driven improvement process reducing human handoffs by 15 percentage points within 10 days of launch. Presence is not available as a self-service product, so interested companies must work through their OpenAI account team.
Read full article ↗Dassault Systèmes announced acquisition of ArisGlobal, an AI-native regulatory-compliance platform, for $1.8 billion in cash plus up to $200 million in milestone payments. ArisGlobal processes over 12 million patient-safety reports annually and is used by roughly half the top 50 global biopharma companies, folding vertical AI domain expertise into an enterprise software giant's stack.
The acquisition consolidates a critical vertical AI platform into Dassault's life-sciences product suite. ArisGlobal specializes in FDA and regulatory-compliance workflows for pharmaceutical and medical device manufacturers, processing 12+ million patient-safety reports annually and serving approximately 50% of the world's top 50 biopharma companies. The deal structure—$1.8B upfront plus $200M in multi-year AI revenue milestones—reflects strategic intent to embed AI-native regulatory capabilities across Dassault's installed base rather than treat it as a standalone acquisition. Expected close is H2 2026 pending regulatory approval. For enterprise technology leaders, this acquisition exemplifies the 2026 M&A pattern: buyers with broad installed bases acquiring deep vertical AI specialists to accelerate time-to-value and avoid building domain-specific AI capabilities from scratch. The milestone structure also signals that acquirers now value demonstrated revenue traction in AI-augmented workflows, not just technical capability. Organizations evaluating AI compliance tools should anticipate consolidation among standalone vendors and rapid integration into larger enterprise stacks, which may accelerate feature deployment but increase switching costs.
Read full article ↗No articles match your filter. Clear filter
Podcasts & Talks · Jul 25, 2026
Cloudflare's 2026 Threat Report identifies eight key trends reshaping the threat landscape, with AI automating high-velocity attacker operations, state-sponsored actors pre-positioning in critical infrastructure, and the necessity for autonomous defense capabilities at machine speed. The report shifts the focus from incident response to autonomous observability and real-time automated response.
The report details how generative AI is being weaponized for real-time network mapping, exploit development, and deepfakes, enabling low-skill actors to conduct high-impact operations. This is not theoretical: the report includes case studies of autonomous post-exploitation attacks driven by LLM agents. State-sponsored actors (Chinese threat groups Salt Typhoon and Linen Typhoon) are targeting North American telecom, commercial, and government infrastructure, anchoring persistent presence for geopolitical leverage. A critical theme: over-privileged SaaS integrations are expanding attack blast radius, particularly where API tokens grant excessive permissions. For network and SRE practitioners, the report argues that traditional manual checklists and fragmented alerting are obsolete—organizations must shift to real-time visibility and automated response. The report details Cloudflare's methodology, including using AI coding agents to perform self-vulnerability analysis on their own systems, a practical approach to understanding agent-driven attack surfaces. The broader insight: in 2026, the goal is no longer building a better wall but ensuring your system acts faster than the attacker, even unmonitored.