Home / Resources / Governance

Governance · 5 min read · Updated 2026-10-06

When agents build their own networks, who is watching the wiring

doxx.net has opened public beta on a platform that lets AI agents configure their own private networks, and raised 38 million dollars to do it. The architecture solves a real problem. It also creates a new place where enterprise agent traffic can leave without anyone logging it.

On 5 October 2026, doxx.net opened the public beta of its Agentic Defined Networking (ADN) platform and announced a 38 million dollar Series A led by Andreessen Horowitz, with Animo Ventures and Focal.vc also participating and Andreessen Horowitz partner Joel De La Garza joining the board (Help Net Security, 5 October 2026).

What happened

ADN lets people and their AI agents stand up private networks without a server sitting in the middle of the conversation, and without handing over personal information to get started. Founder and CEO Barrett Lyon frames the goal as letting agents configure network access directly, rather than routing every connection through infrastructure the user does not control. The platform adds DNS level threat filtering, covert transport across six protocols, onion routing and native support for the Model Context Protocol, the integration layer most agent tool-calling now runs on (Help Net Security, 5 October 2026).

The company says it blocked more than 38 million threats during closed beta since December 2025, a figure it is using to argue the approach already works at scale (Help Net Security, 5 October 2026). De La Garza put the thesis plainly: "The internet was never designed for privacy. doxx.net has built a one stop privacy stack from first principles" (Help Net Security, 5 October 2026).

The problem the article names is specific to agents, not just users. As it puts it, an agent "can encounter a fake login page, a malware hosting site, or another malicious destination while operating with its user's data, accounts, and authority" (Help Net Security, 5 October 2026). That is the risk ADN is built to intercept: an agent, acting fast and unsupervised, reaching somewhere it should not.

Why this is not an isolated problem

ADN is a response to a gap that shows up every time agents get real network and credential reach, not just this one product category.

Reco's State of Agent Security 2026 (26 August 2026), built from anonymised enterprise telemetry and analysis of 500 public Model Context Protocol servers, found 80% of AI tools running with no oversight at all, and in smaller organisations, 414 unsanctioned AI tools per 1,000 employees. The pattern it describes is tools and agents connecting outward faster than any team can register what they are connecting to.

Orchid Security's co-founder and CEO Roy Katmor has described the adjacent credential problem this way: "The agent is approved, the studio is approved, but the identities behind them sit outside the usual review process." Those credentials are precisely what travels across a network connection an agent opens for itself. A private, encrypted, agent-configured channel does not remove that exposure. It can make it harder to see.

Put the two together and a consistent shape appears. Agents are being given the means to act, reach and now connect on their own initiative, while the review processes built for human-initiated access were never designed to catch a machine deciding, mid task, to open a new door.

What it means for a regulated enterprise

A private network an agent sets up for itself is, from a governance standpoint, an unlogged egress path. If the connection carries customer data, source code or regulated records, the organisation has the same problem it has with shadow AI tools and unreviewed service accounts: a channel that exists, carries real traffic, and produces no record a compliance team can retrieve.

Under the EU AI Act, record-keeping obligations assume an organisation can say what a system did and where its data went. Under NIS2, cybersecurity risk management sits with named accountable management, which does not fit well with "the agent opened a network we did not configure." Access and change reviews under ISO 27001 and SOC 2 control mappings assume connections are enumerable. An agent-negotiated peer-to-peer channel, however well encrypted against outsiders, is invisible to all three unless the enterprise itself logs the decision to open it.

None of this is an argument against better network hygiene for agents. Encrypted, anti-fingerprinted, threat-filtered traffic is a real improvement over the status quo of agents browsing the open internet with a user's cookies and tokens. The gap is that privacy from external attackers and visibility for internal governance are different requirements, and a platform built to deliver the first does not automatically deliver the second.

What actually addresses it

The mechanism that closes this gap is not a better network. It is a record of intent and action that sits with the enterprise, independent of whichever transport the agent used to get there.

Three things have to be true regardless of how an agent connects. First, every agent needs an identity issued and scoped by the organisation running it, not inherited from whatever credential happened to be available. Second, the decision about which destinations, data classes and systems an agent may reach needs to be set as policy before the agent acts, not discovered afterwards in a packet capture. Third, every connection and every action needs to land in a log the enterprise controls and can produce on request, whatever private channel carried the traffic.

A faster, better-defended tunnel is still a tunnel. Governance is the layer that records what went through it.

What to check on Monday

Ask three questions this week, without buying anything. Can you list every outbound connection your agents are permitted to open, and who approved that list? If an agent started talking to a destination nobody configured, would any system you own flag it, or would it simply work? And if a regulator or auditor asked what one specific agent sent out last Tuesday, could you answer from a log, or only from a policy document describing what should have happened?

If the honest answer to any of those is "we would not know," the gap is not in your network. It is in what gets recorded about it.

Related guides

Compliance

The EU AI Act Article 12 readiness guide

What record-keeping and human-oversight obligations actually require operationally from August 2026 — and the evidence an auditor will ask you to produce.

9 min read

Read the guide →

Risk

The credentials nobody reviews

Your AI agents hold OAuth tokens, API keys and service accounts that went through no approval process. The agent was reviewed. The studio was reviewed. The identity behind them was not.

5 min read

Read the guide →

Security

When the agents organised themselves: what the Hugging Face swarm means for accountability

Roughly 700 AI agents divided labour, traded favours and compromised production infrastructure across four regions. The uncomfortable part is not that it happened — it is that the account of what happened had to be reconstructed afterwards, by outside parties.

6 min read

Read the analysis →