The current technological landscape is defined by a structural divergence between the speed of hybrid infrastructure evolution and the capacity of traditional operating models to govern it. Historically, the industry has operated on the principle of testing, validating, and deploying infrastructure with the goal of minimizing subsequent changes, relying on annual or semi-annual update plans that were once considered adequate. However, the mass adoption of Artificial Intelligence and the increasing complexity of multi-domain ecosystems have revealed a critical phenomenon: operational obsolescence. This condition manifests when Operation and Maintenance processes, originally designed for static and manual-control environments, prove inadequate to support the pace, scale, and risk profile of modern architectures, rendering legacy management models a systemic risk to operational continuity and organizational innovation.
The Shifting Threat Landscape
Two fundamental factors have accelerated this crisis, radically transforming the threat landscape. First, the infrastructure itself – computers, storage, switches, routers, firewalls, and load balancers—has become the new primary attack surface, as evidenced by sophisticated campaigns such as Salt Typhoon and Volt Typhoon[1], which have put the industry on notice that critical infrastructure is now a direct target. Second, a new generation of frontier AI models has made a significant leap in the ability to identify vulnerabilities in complex software systems. Unlike previous generations of AI coding tools limited to smaller, greenfield contexts, current models are capable of analyzing massive, highly complex legacy code bases developed over many years, drastically reducing the time required for attackers to discover and exploit security flaws.
Evolving ITIL for a Modern Paradigm
This new reality renders traditional manual intervention and static documentation unsustainable. Overcoming this challenge requires an evolution of established reference frameworks such as ITIL. While ITIL remains valid in terms of governance, traceability, and change management discipline, it requires profound re-elaboration. The new operational paradigm, currently being defined, does not aim to replace ITIL’s core principles, but rather to evolve them through the systematic introduction of process automation. This approach allows for the digitalization of intent, the automation of execution, and continuous validation, ensuring consistent infrastructure management in real-time.
The Three Technical Pillars of Modern Operations
The proposed modernization strategy is built on three complementary technical pillars that define the modern operational lifecycle. The first pillar, Services as Code, transforms the desired state of the infrastructure into versionable data, managed according to Software Development Lifecycle best practices.
The second pillar is machine-speed automation enabled by AI in IT Operations (AIOps – Artificial Intelligence for IT Operations), which allows for the execution and remediation of configurations with a level of consistency unattainable through direct human intervention.
The third pillar is the adoption of the DevOps method powered by AI, which integrates governance, approval, and change traceability directly into the code lifecycle, ensuring that every modification is verified and compliant with the security and operational standards defined by the organization.

Establishing a Foundation for Operational Resilience
Translating these strategic pillars into trusted, scalable operations requires a solid foundation. Deploying autonomous AI agents in fragmented or poorly documented environments risks creating cascading operational errors. To achieve true operational resilience and scale safely toward autonomous operations, organizations must establish four core operational foundations:
- Standardization (The Baseline): Aligning a single Source of Truth (SoT), version-controlled data models, golden configurations, design baselines, and standardized procedures (MOPs – Method of Procedures). Standardization ensures that infrastructure intent is machine-readable and eliminates configuration drift across multi-domain environments.
- Automation & Guardrails (The Boundaries): Establishing clean, programmable workflows that provide deterministic boundaries for autonomous execution. By implementing pre-change simulations, policy-as-code guardrails, and Human-in-the-Loop (HITL) gates for high-consequence actions, organizations ensure that AI operates at machine speed without risking unvalidated system disruptions.
- Unified Observability (The Context): Capturing actionable, high-quality telemetry and cross-domain correlation rather than raw noise. Unified observability eliminates operational blind spots across campus, data center, and multi-cloud environments, turning weak signals of performance degradation into actionable intelligence before service failure occurs.
- Agentic Enablement (The Execution): Deploying specialized autonomous AI agents capable of closed-loop triage, deep root-cause analysis (RCA), and guided operational remediation. Working within shared workspaces (such as AI Canvas), these agents assist operators by correlating complex telemetry and executing validated fixes with deterministic precision.
The Metamorphosis of the IT Operator
The transformation toward this new operating model marks the definitive shift from manual-control infrastructures to automated infrastructures with human supervision. In this scenario, the role of the operator undergoes a significant metamorphosis: shifting from repetitive task execution to functions of governance, strategic validation, and intent definition. This evolution is comparable to the manufacturing industry’s transition to Computer Numerical Control (CNC), rendering IT infrastructure inherently programmable, observable, and continuously validated at every step.
The Journey to Autonomous Architecture

Through Cisco’s support, organizations can implement this model, benefiting from an architecture that not only drastically reduces operational risk but also enables the speed and resilience essential for competing in today’s market.
- [1] Salt Typhoon: State-sponsored espionage group targeting U.S. telecom infrastructure using living off the land tactics.
- Volt Typhoon: State-sponsored group targeting U.S. critical operational technology infrastructure, using botnets and stealth techniques.
References
BRKSEC-2499 – Salt Typhoon – Cisco Live 2025
PSOCX-2092 – Cisco Live 2026 EMEA
Infrastructure as Code: https://developer.cisco.com/iac/
Explore the future of infrastructure operations at IBM TechXchange: https://www.ibm.com/think/perspectives/from-infrastructure-as-code-to-autonomous-infrastructure-operations
Outshift by Cisco: Introducing innovation, full speed ahead
Explore the innovative world of Outshift, Cisco’s incubation engine for emerging technologies. We’re building what’s next for tomorrow’s customer needs.
Visit the Outshift by Cisco Blog
