Analyst Whitepaper

Intent Is the New Perimeter

Analyst Jack Poller of Paradigm Technica explains why thirty years of network security asked the wrong question about AI traffic. Proxies were built to check where a connection was going. AI made that the wrong thing to control. This paper traces the shift to intent-aware execution control and what an AI-native security layer has to do to keep up.

Your proxy was built for a protocol AI no longer speaks

Legacy proxies were built for HTTP: discrete requests, short sessions, predictable timeouts. AI traffic behaves nothing like that. Streaming sessions stay open long enough to defeat proxy timeouts, so engineers route around inspection to get work done. A WebSocket stream carries the whole interaction, prompts, responses, and tool calls, inside a channel destination-based tools treat as opaque. MCP arrives as an application-layer protocol the stack has no parser for. At the domain level, Google Search and Google AI Mode look identical, while the data leaving your network through each one does not.

The paper traces the shift: from where a connection is allowed to go to what is actually being attempted.

Poller calls it intent-aware execution control, policy that follows the work across the full execution graph, from the person who starts a task to the agents and tools that carry it out.

Intent

What is the user or agent trying to do?

Behavior

How are they doing it, and in what context?

Identity & Location

Still necessary, but no longer sufficient

Read the Paper

Download PDF

The paper’s six-question readiness test shows exactly where your current stack goes blind to AI traffic.

Get the full analysis, then see how your own environment measures up.

Aurascape Solutions