SHARE
Security / September 28, 2026

Strengthening AI Governance and Security Outcomes With Deeper Network-Derived Intelligence

Summary

Modern AI, including generative applications and agentic frameworks, represents a double-edged sword. Defenders are using AI to automate security operations, improve observability and runtime protection, accelerate threat detection, and speed investigations and remediation. At the same time, frontier cybersecurity models such as Anthropic’s Mythos early preview demonstrate how AI can scan codebases at machine speed and discover vulnerabilities that may have gone undetected for years, changing the economics and operational dynamics for both attackers and defenders.

AI is quickly reshaping enterprise IT and OT architectures to accommodate new network traffic patterns and growing volumes of data for training and inferencing. As organizations adopt a mix of frontier and specialized models, AI services, autonomous agents, and private deployments, applications will increasingly span models, clouds, SaaS services, and enterprise systems, creating new dependencies and making the resulting activity more difficult to understand and govern.

The discovery and exploitation of vulnerabilities, sophistication of attacks, and scale of cyber activity are likely to accelerate as frontier AI becomes more capable. The growth of distributed AI architectures is also making it more difficult for organizations to understand activity across their environments. No individual security control or telemetry source provides a complete picture. Consequently, deep observability can help organizations uncover critical evidence of network activity, validate whether existing controls are working, and investigate when controls fail.

LoneStar Advisory & Research believes Gigamon has built a strong foundation in network visibility for addressing these challenges. The Gigamon Deep Observability Pipeline and Application Metadata Intelligence (AMI) can supercharge existing security, observability, operations, and AI platforms with independent network-derived evidence and application-aware context, improving the quality of intelligence available to those platforms to strengthen AI governance and security outcomes.

Why Deep Observability Matters

Modern AI deployments are driving significant growth in network traffic across increasingly distributed infrastructure. Organizations are deploying AI applications and running models across private data centers, public clouds, and edge environments. These distributed architectures can create visibility gaps that traditional observability approaches relying primarily on metrics, events, logs, and traces may not capture. Although these MELT sources remain valuable, they do not always capture a complete picture of data moving through a network.

To complement MELT data, Gigamon offers an additional layer of network-derived intelligence. The Gigamon Deep Observability Pipeline provides granular visibility into data in motion, delivering packets, flows, and application-aware metadata to existing security and observability platforms. Gigamon also enables the flexibility to filter, De-duplication, decrypt, mask, and enrich traffic before downstream tool ingestion.

This architectural approach is particularly relevant for AI deployments because it can surface network activity and application context other telemetry sources may miss. It also helps reduce the financial implications of telemetry costs by avoiding unnecessary processing and storage. Filtering and enriching traffic before ingestion can also improve signal quality while reducing the amount of data downstream tools need to process.

The value of deeper observability becomes especially relevant as enterprises deploy agentic frameworks. With proper identity, access, and provisioning, agents can communicate with applications, make API and other tool calls, and access databases and cloud services. You cannot protect what you cannot see, and the Gigamon Deep Observability Pipeline has the potential to improve threat detection, accelerate investigations, strengthen automation, and enable better operational decisions without the rip-and-replace of existing infrastructure.

How Frontier AI Is Changing Cybersecurity Economics

Frontier AI has great promise to facilitate scanning large codebases quickly to prioritize critical vulnerabilities and apply both compensating controls and virtual dynamic patching. However, threat actors can leverage the same infrastructure to move from AI-assisted to increasingly automated attack campaigns, dramatically compressing the time required to identify and exploit vulnerabilities. Simply stated, AI is changing the economics of cyberattacks. Network-derived telemetry can empower defenders with an independent source of evidence to identify security exposures and prioritize response. This additional context can help defenders identify suspicious application traffic and attack sequences that could lead to lateral movement across networks and cloud services beyond endpoint visibility and control.

The recent integration with CrowdStrike Falcon Next-Gen SIEM illustrates the inherent value in this approach. Gigamon AMI supplies network-derived telemetry that complements CrowdStrike’s proven endpoint, identity, and data logging expertise. The integration provides security analysts with additional context around anomalous application activity, access, and network behavior.

Why AI Application Traffic Visibility Matters

As generative AI applications and agents proliferate, visibility into AI application traffic is becoming increasingly important to security and governance. Gigamon AMI analyzes network traffic to extract contextual information about applications and protocols. This can improve AI governance by identifying sanctioned and unsanctioned AI applications and services while providing granular visibility into AI application traffic, data flows, and interactions across hybrid cloud environments.

Gigamon AMI can also enrich existing tools with application-level context about the impact of growing generative and agentic traffic on applications and data services.

A second integration combines Zscaler Private Access identity and access controls with Gigamon AMI, adding application-level context that can help organizations validate policy and gain deeper visibility into application activity across hybrid cloud infrastructure.

Final Thoughts

Modern AI is improving defensive posture and ongoing runtime protection, but threat actors will inevitably use the same capabilities to their advantage. Deep observability and application metadata intelligence have the potential to counter increasing attacker speed and address visibility and security gaps across increasingly distributed hybrid cloud infrastructure. Enriching existing security, observability, operations, and AI platforms with network-derived telemetry will improve intelligence quality without requiring organizations to replace established tools. As AI applications and agents proliferate across hybrid environments, application-level visibility will become increasingly important for security, governance, and operational performance.

LoneStar Advisory & Research believes that the Gigamon Deep Observability Pipeline and AMI platform can accomplish these tasks, improving the quality of intelligence available to existing platforms to strengthen AI governance and security outcomes — ultimately fortifying data intelligence for modern AI deployments.

CONTINUE THE DISCUSSION

People are talking about this in the Gigamon Community’s AI Exchange group.

Share your thoughts today


Back to top