BackBox's Kilter AI Keeps Humans in the Loop While Automating Network Fixes

BackBox's Kilter AI Keeps Humans in the Loop While Automating Network Fixes

BackerLeader 44 263 463
calendar_today agoschedule5 min read

As network vulnerabilities pile up faster than teams can patch them, most of the AI conversation in NetOps has centered on autonomy: letting AI agents make and execute changes on their own. BackBox is making a different bet. With the launch of its Kilter Platform — and Kilter AI, its new intelligence layer — the company is betting that NetSecOps teams want acceleration, not abdication.

We asked Irfahn Khimji, CISSP, Field CTO at BackBox, to walk through how that actually works in practice: what a human reviews before anything runs, where the hard limits are, and what claims about AI-driven network automation deserve some skepticism.

Walk me through the actual flow: a vulnerability shows up in the Enriched Data Aggregation layer, and a "CVE Workaround Chain" gets generated. What does that chain actually look like, and what specifically does a human review before anything executes?

When a vendor issues an advisory, it includes remediation or mitigation guidance — upgrade to a specific version, or change a configuration — and every vendor presents it differently. Kilter AI parses that advisory, normalizes it, and identifies what needs to happen to the device.

From there, the human-in-the-loop model requires a person to click a button before Kilter AI takes the next step: building the automation chain. Once built, that chain is tagged as AI-generated and still requires a human to review, verify, and approve it before it's scheduled to run.

Chains also enforce best practices by default. A common pattern wraps AI-generated automations in a Backup–Run Automation–Backup cycle, so the network can always be restored if something goes wrong. As Khimji put it, "The AI takes the coding out of the equation, but lets the human engineer decide whether to use it as-is or tweak it, and when to run it."

You describe Kilter AI as a "trusted advisor" rather than autonomous. Concretely, what decision has Kilter AI never been allowed to make on its own, even as trust builds over time? Where's the hard line?

Kilter AI is not allowed to take actions on customer networks, full stop. Its job is to aggregate data, generate recommendations, and surface insights — the research and development phase, not execution.

Why hold that line while competitors race toward full autonomy?

BackBox made a deliberate choice not to go fully autonomous, based directly on customer and prospect feedback. The sticking point is accountability: if an AI makes a mistake, the AI can't be held responsible for it — the person deploying it can. And accountability only works if the person carrying it has a very high level of confidence in the AI's output. "As an industry and society, we're not yet at the point where AI models are 100% or even 99% trustworthy," Khimji said. "Given that networks need more than 99% uptime, I'm not sure it's a risk worth taking just yet."

How much has the threat landscape actually accelerated?

Khimji pointed to a stack of external data supporting the urgency behind Kilter AI's design: over 49,000 CVEs published last year (a 20% increase over 2024, per NIST), with CVE.org projecting more than 60,000 by the end of 2026. The Global Incident Response Report 2026 found the fastest 25% of intrusions now reach exfiltration in 72 minutes, down from 285 minutes the year before. CrowdStrike's 2026 Global Threat Report logged an 89% year-over-year increase in attacks from AI-enabled adversaries, and IBM's X-Force Threat Intelligence Index flagged a 44% year-over-year increase in exploitation of public-facing applications, with 56% of disclosed vulnerabilities exploitable without authentication. IBM's Cost of a Data Breach Report also found that 97% of AI-related breaches trace back to inadequate guardrails.

Mythos, the AI-driven exploit generation approach Khimji referenced, is part of what's compressed attacker timelines from months or years down to days — one of the pressures BackBox says is driving demand for guardrails rather than full autonomy.

"Automation Creation Assistance" turns CLI input into production-ready automations without requiring scripting expertise. What happens when it gets that translation wrong? Is there a review step before it's saved or executed?

Every AI-created automation is tagged as such, and none of them can run without human approval. The underlying connect, authenticate, and disconnect commands are the same ones already used in BackBox's onboarding and inventory process — meaning they're proven, or the device wouldn't be in inventory in the first place.

The final required step is verifying the commands entered into the automation. If they came from the vulnerability intelligence service, they're pulled directly from the manufacturer's site. If they came from the automation creation assistant, the user typed them. Kilter AI's target users are network professionals — engineers, architects — who are assumed to know the CLI for their own devices, though a more junior analyst can cross-reference against vendor documentation.

You support 180+ vendors with 3,000+ pre-built automations. How much of that breadth is genuinely uniform versus vendor-specific quirks that still need manual tuning?

Not much of it is uniform. Every vendor has its own CLI dialect — a Cisco device takes "show run," while the equivalent on Fortinet is "show full-configuration." BackBox has spent more than 15 years building out that automation library manually, vendor command by vendor command.

For a NetSecOps team already drowning in tooling, what's the real integration lift? Does Kilter replace existing tools, or become one more thing to maintain?

It depends on where a team is starting from. Most prospects are either scripting manually with something like Python, using a vendor tool like Cisco's Catalyst Center, or handling the work by hand with no automation at all — and a smaller number do nothing and wait for the next hardware refresh.

For teams doing it manually, Kilter is new tooling, but the ROI has been steep: one customer cut its upgrade cycle for an entire switching infrastructure from six months to six days. For teams on vendor tools, Kilter typically replaces them — BackBox has displaced as many as five other tools in a single deployment, though one or two is more typical. Teams that have built their own scripting stack with staff who know both networking and coding are the toughest fit; if that describes an organization, Kilter probably isn't the upgrade.

What's a claim about AI-driven network automation — yours or a competitor's — that teams should be skeptical of right now?

Khimji singled out vendor platforms that push users to build AI agents natively on their own systems: "Users must learn to code on those platforms instead of in Python, etc., and those agents aren't portable outside those platforms." That lock-in, he argued, is worth questioning regardless of which vendor is offering it.

The bigger picture

Kilter AI is the intelligence layer inside BackBox's broader Kilter Platform, which also includes Kilter ALM (lifecycle management — onboarding, backup, recovery, upgrades, and patching across 180+ vendors) and Kilter Enterprise (compliance, policy, and configuration integrity). BackBox frames Kilter AI as the foundation for what it calls "agentic NetSecOps" — networks that reason, adapt, and act with increasing independence — but insists that autonomy will be earned one deliberate capability at a time, not declared on day one.

Irfahn Khimji is Field CTO at BackBox. Connect with him on LinkedIn.

🔥 Join developers growing publicly
Share your knowledge, build in public, and grow your developer presence with a global community.

More Posts

The Interface of Uncertainty: Designing Human-in-the-Loop

Pocket Portfolio - Mar 10

The Zero-Net-Loss Fleet & The Mercenary Squad: A Live AI Economy

DEVPlank - Aug 4

The Sovereign Vault — A Comprehensive Guide to Protocol-Driven AI

Ken W. Algerverified - Jun 4

Breaking the AI Data Bottleneck: How Hammerspace's AI Data Platform Eliminates Migration Nightmares

Tom Smithverified - Mar 16

From Subjective Narratives to Objective Data: Re-engineering the Elderly Care Communication Loop

Huifer - Jan 28
chevron_left
18.1k Points770 Badges
242Posts
140Comments
103Connections
LLM Training & Evaluation Specialist with hands-on experience building major AI models. As one of th... Show more

Related Jobs

View all jobs →

Commenters (This Week)

1 comment
1 comment
1 comment

Contribute meaningful comments to climb the leaderboard and earn badges!