Artificial intelligence is gradually establishing itself as the most transformative technology in network management since the invention of the TCP/IP protocol. For decades, networks have been configured, monitored and troubleshot manually by specialist engineers. This approach is now reaching its limits in the face of increasingly complex infrastructures: a modern enterprise network can comprise hundreds of devices, thousands of links, dozens of critical applications with different SLAs, and millions of log events per day. No human being can monitor and optimise such a system in real time. AI provides the capability to process these volumes of data to detect anomalies, predict failures and automate corrective actions with a speed and accuracy beyond the reach of a human operator.

1. AIOps — Artificial intelligence for operations

AIOps (Artificial Intelligence for IT Operations) refers to the application of AI and machine learning techniques to the operation of IT systems and networks. The central objective is to shift network management from a reactive approach, where faults are addressed after they have occurred and impacted users, to a predictive and autonomous approach, where issues are detected and resolved before users are even affected.

Predictive fault detection is one of the most highly valued applications of AIOps. It relies on the continuous analysis of time series metrics (device CPU usage, memory utilisation, link latency, packet loss rate, component temperature) using machine learning algorithms such as LSTM (Long Short-Term Memory) recurrent neural networks, Prophet time series forecasting models, or anomaly detection methods using isolation forests. These algorithms learn the normal behaviour of the infrastructure and flag any significant deviations, enabling preventive action to be taken.

Event correlation addresses a different but equally critical issue: alert overload. A complex network can generate thousands of alerts per hour, the vast majority of which are symptoms of the same underlying problem. A failing core network device, for example, can simultaneously trigger hundreds of alerts on the devices that depend on it. AIOps automatically links these correlated alerts, identifies the root cause (Root Cause Analysis, RCA) and presents the operator with a single, structured incident along with its diagnosis. This reduction in alert noise (alert fatigue) is essential for maintaining the efficiency of operational teams.

Beyond detection, autonomous remediation represents the most advanced stage of AIOps. The system no longer merely issues alerts; it takes action: automatically restarting a failing service, switching to a backup link, dynamically modifying a quality of service rule, and automatically isolating a device whose network behaviour indicates it has been compromised. These actions are governed by runbooks (automated procedures) that have been pre-approved by the teams, thereby minimising the risk of error.

Among the leading AIOps platforms on the market, Cisco ThousandEyes stands out for its ability to monitor the end-to-end network experience—from the user’s device through the carrier network and the internet to the cloud application—enabling precise identification of where in the chain a problem occurs. Juniper Mist AI brings AIOps specifically to Juniper Wi-Fi and Ethernet networks, with anomaly detection and automatic root cause analysis (RCA) that are highly valued by administrators. Aruba Central (HPE) offers cloud management with AIOps for campus networks. More generic observability platforms such as Datadog, Dynatrace and New Relic cover the entire infrastructure, from the network to the applications.

⚡ Capacity planning Predictive

AIOps also enables predictive capacity planning: by analysing historical traffic growth trends, calendar events (marketing campaigns, public holidays, the start of the school year) and company projects, the system predicts when links or equipment will reach their limits and recommends the necessary upgrades before performance deteriorates. This approach replaces half-yearly capacity audits with continuous, proactive monitoring.

2. Intent-Based Networking (IBN)

Intent-Based Networking (IBN) represents a fundamental shift in the philosophy of network configuration and management. For decades, configuring a network meant manually connecting to each piece of equipment, command line by command line, to define VLANs, routing rules, ACLs and quality of service policies. This approach is laborious, prone to human error, and, above all, disconnected from actual business objectives. IBN turns this logic on its head: the administrator expresses what they want to achieve in functional terms, and the system takes care of determining how to achieve it and deploying it automatically across the entire network.

The IBN’s operational cycle consists of four complementary stages.

The first step is capturing the intent: the administrator describes their objective in business terms, for example, “all users in the Finance department must be able to access the ERP server with a maximum latency of 50 ms and a guaranteed bandwidth of 10 Mbps, and no other department must have access to this server”. This intent can be entered via a graphical interface, structured forms, or increasingly via natural language interpreted by an LLM.

The second step is the translation: the IBN system automatically translates this declarative intent into concrete network configurations, creating the appropriate VLANs, defining filtering ACLs, configuring QoS rules on each relevant device, and setting up segmentation policies.

The third step is activation: these configurations are automatically deployed across all network devices via standardised automation protocols such as NETCONF, RESTCONF or OPENCONFIG, without the need for manual intervention on each device.

The fourth stage, assurance, is perhaps the most innovative: the system continuously checks that the actual network matches the declared intent. If an event—such as equipment failure, unauthorised modification or link saturation—creates a discrepancy between the desired state and the actual state, the system immediately issues an alert and can apply automatic corrective actions to restore compliance.

There are two leading IBN implementations on the market. Cisco DNA Center (renamed Catalyst Center) is the leading IBN platform for enterprise networks. It incorporates segmentation based on user groups (SGT, Scalable Group Tags), enabling access policies to be defined independently of the physical network topology. Juniper Apstra is a data centre-oriented IBN solution, built around a unified data model called a "blueprint" which describes the desired state of the data centre and validates, in real time, the network’s compliance with this declared state.

⚡ LLMs and network configuration using natural language

Large language models (LLMs) are beginning to be integrated into IBN interfaces to enable network configuration using natural language. Cisco AI Assistant, Juniper Marvis and Aruba Copilot use LLMs to interpret requests such as ‘block the surveillance camera’s access to the internet but allow it to send its images to the local storage server’ and translate them into precise network configurations. This approach significantly lowers the technical expertise required to manage a complex network.

3. AI-driven 5G network slicing

Network slicing is one of the most innovative features of 5G Standalone (SA). It enables the creation of multiple independent virtual networks, known as slices, on the same physical 5G infrastructure, each optimised for a specific use case with guaranteed performance characteristics. Without AI, resource allocation between these slices would be static and inefficient. AI drives dynamic allocation in real time, redistributing radio, transport and core network resources according to the instantaneous load and contractual SLAs of each slice.

There are three main categories of 5G slices that correspond to the use cases defined by the 3GPP standard.

The eMBB (enhanced Mobile Broadband) slice is optimised for high-speed data: 8K video streaming, large file downloads and virtual reality. AI maximises the aggregate data rate by dynamically allocating available radio resources.

The URLLC (Ultra-Reliable Low-Latency Communications) slice is optimised for ultra-low latency—less than 1 ms—and is designed for mission-critical applications such as remote robotic surgery, connected autonomous vehicles and real-time industrial robotics. AI ensures SLAs by systematically prioritising this slice over others in the event of congestion.

The mMTC (Massive Machine-Type Communications) slice is designed to connect a very large number of low-power IoT devices: agricultural sensors, smart meters and logistics tracking devices. AI manages the wake-up and sleep cycles of millions of sensors to optimise the radio network’s power consumption.

ℹ Network slicing 5G SA en France

Standalone 5G network slicing is being rolled out gradually by French operators for industrial businesses. Orange Business Services, SFR Business and Bouygues Telecom Entreprises offer private network slicing solutions for factories and industrial sites seeking service quality guarantees that the shared public 5G network cannot provide.

 

4. Large language models and network support

Beyond AIOps and IBN, LLMs (Large Language Models) are transforming the way network engineers interact with equipment and diagnose issues on a broader scale. These models, trained on vast corpora of technical documentation, knowledge bases and network logs, can now answer complex questions in natural language, analyse configuration files, detect configuration errors and automatically generate automation scripts.

The Cisco AI Assistant for Security, integrated into the Cisco XDR and SecureX platforms, analyses security incidents, explains alerts in natural language that non-specialists can understand, and suggests concrete remedial actions. The Juniper Marvis Virtual Network Assistant takes diagnostics a step further: it answers specific operational questions such as “Why are users in conference room A experiencing poor Wi-Fi this morning?” and automatically identifies the causes: a congested radio channel, a neighbouring access point restarting, or a spike in bandwidth usage by a backup application.

The automatic generation of automation code is another major benefit that LLMs offer network teams. An engineer who describes in French what they wish to automate—for example, “check every night that all switches on the network have port 80 disabled and send a report by email”—can obtain a working Ansible or Python script in a matter of seconds, which the LLM generates, documents and explains. This capability makes network automation accessible to teams that lack advanced development skills.

The analysis of security logs using LLMs also opens up significant possibilities. A single firewall log file can contain millions of lines in a single day. A specialised LLM can analyse this volume in a matter of minutes, identify subtle attack patterns (slow brute-force attempts, stealthy lateral movement, data exfiltration in small packets), and produce a structured report with incidents classified by severity, drastically reducing the investigation time for SOC (Security Operations Centre) teams.

Modifié le: vendredi 9 octobre 2026, 10:01