Introducing Forward AI, chat with your network, with Forward Networks
Forward Networks’ foundational technology is a “digital twin of the network,” which serves as a behavioral source of truth. This software platform connects to all network devices, collecting configuration and state data to build a behaviorally accurate model. It transforms raw, vendor-specific data into a queryable, vendor-independent model, analyzes all possible network behaviors, and proactively traces every conceivable packet path to determine delivery, drops, and the underlying causes. This capability goes beyond mere monitoring by enabling the network’s properties to be provably validated, such as connectivity readiness or security isolation between regions. The platform collects extensive multi-vendor, multi-protocol data at scale, including tens of thousands of devices, and organizes it into a hierarchical stack of raw, normalized, behavioral, and contextual data to enable deep insights.
The company identified an “operational gap” in which network and security teams struggle to translate their goals into actionable information from disparate sources and to manage complex, multi-step workflows. Envisioning “agentic operations” where AI assists with routine tasks, Forward Networks emphasizes the critical need for robust data and trustworthy AI outputs. To address this, they introduce Forward AI, a conversational agentic system powered by the network digital twin. Forward AI provides a plain English interface, allowing operators to ask questions about devices, hosts, subnets, packet paths, and vulnerabilities, effectively bridging the gap between human intent and the complex underlying network data. While designed with agentic capabilities, the initial focus is on enabling users to gain trusted insights necessary for informed actions.
Presented by Nikhil Handigol, Chief AI Officer, Forward Networks. Recorded live at AI Infrastructure Field Day in Santa Clara on January 29th, 2026. Watch the entire presentation at https://techfieldday.com/appearance/forward-networks-presents-at-ai-infrastructure-field-day/ or visit https://techfieldday.com/event/aiifd4/ or https://www.forwardnetworks.com/ for more information.
Transcript
My name is Hago. I'm a co-founder and chief AI officer at Forward Networks, and I'm happy to, uh, I'm excited to tell you everything about Forward AI today. A quick recap of the foundational technology.
In terms of technology, uh, we've, what we've built, uh, it's the technology is called a digital twin of the network. It presents a behavioral source of truth of the network in terms of technology. It's a software platform that connects to all the devices in the network and collects all of the configuration and state and builds a behaviorally accurate model of the network.
And in terms of technology, what do we mean by this behaviorally accurate model? In terms of technology, it comes down to three different, uh, three key things. First, it takes all of the raw configuration and state, and it turns it into a queryable vendor independent model.
Second, it analyzes every possible behavior that the network can exhibit as a result of that configuration. And state, what do I mean by that? Imagine an arbitrary packet showing up at the network.
What is going to happen to this packet? What is the exact path that this packet is going to take through the network? Will it be delivered out of a certain location or will it be dropped by the network?
And more importantly, why is that the case? And third, it proactively traces where every possible packet can go through the network. Imagine the universe of every possible packet that can ever be crafted forward proactively traces that universal set of every possible packet through the network, and it creates this proactive database.
This is very different from monitoring or observability, where you're watching what the traffic that's actually flowing through the network. This is reasoning about every possible package. So that's, that's a very different kind of capability because now you can start proving properties about your network.
You can prove that the network is ready to deliver certain kind of connectivity, or from a security angle, you can prove that two regions in the network are provably isolated from each other regardless of what traffic goes from A to B. Here's a view into the sheer breadth and depth and scale of the data that the forward platform collects. Forward supports most common vendor devices that we encounter in modern enterprise networks.
And, uh, the data that it collects spans pretty much every protocol and technology that we see in modern networks, uh, is expanding layer two, layer three, nas, acls, uh, tunneling technologies, uh, cloud environments, and so on and so forth. And all of this is collected at scale, and we are talking about tens of thousands of devices. And some of our production deployments, uh, are actually north of 50,000 devices in a single view.
It takes all of that raw data, analyzes it, and turns it into a hierarchical data stack. Let me walk you through this hierarchical data stack a little bit. At the bottom here is just the raw data that it directly collects from the, from the network devices.
It's, uh, your configurations and state information. The tier about that is normalized data. It turns all of this vendor specific raw textual data into a normalized unified data model that you can easily query across the entire estate.
So the normalized data tells you what is there in the network and how it's configured, easily consumable, but the tier about that is more interesting. It's behavioral data. How is the network behaving as a result of what is there in the network?
We are talking about all possible parts that any traffic can take through the network or understanding which assets in my network are exposed to the outside world, or if any of these assets were to get compromised, then what is the blast rate is from it? How, where else can the attacker reach based on the connectivity that is provided by the network? And the tier about that is when you take its contextual data, when you take all of this behavioral and normalized data and enrich it with business data from other sources, you're talking about your CMDB systems, your ticketing systems, Nikhil, Lucchese, Silverton Consulting.
Are you, um, in order to understand every possible packet path, are you actually injecting packets into the network to discover where they go? Or are you theorizing based on your model, what the potential packet Yeah. Path might be?
Great question. This is math. I mean, it's, it's inconceivable to inject every possible packet through the network, right?
So this is math and even math, again, this is, this needs to be done in, in a, in a, in a pretty advanced way. You cannot enumerate every single packet and even, like, even mathematically, theoretically, trace every single packet. What we deal with is, is, uh, is a collection of packets.
We call them header spaces. These are packets. These are classes of packets that are treated similarly equivalently by the network.
That is how we make this computation scale. That's the hierarchical stack that we built. And, uh, we've been closely working with operations teams, uh, of some of the largest and most mission critical environments for over a decade now.
And as we've collaborated with these teams, we've observed two main challenges, uh, that these teams regularly have to deal with. We call them the operational gap. First is these network teams and security teams often have to translate their goals and their tasks into sources of information.
These sources of information could be like old school CLI outputs, or these could be from monitoring or, uh, observability tools, or even the digital twin that matter. The second challenge is that these operational tasks are usually complex. They often need to, uh, translate to multi-step workflows, but it, it requires accessing multiple of these sources in a certain sequence, querying, extracting the data, passing the data between these systems and integrating across multiple systems.
Now, a natural question to ask is, can AI help bridge this gap? The industry as a whole is envisioning a world where AI agents perform most of their routine network operations and security operations task with appropriate human supervision. When we are calling this agent operations, Our position is that if we are to succeed with this vision of agent corporations, we need to have the right foundation in place.
And more specifically, it comes down to two key factors, data and trust. AI agents are only as good as the data that they have access to. And if you want to have AI agents operating on critical infrastructure like networks, their outputs and actions must be trustworthy.
And today we are announcing forward AI to help bridge that gap forward. AI is a conversational agent system to simplify operations that's powered by the network. Digital twin forward AI provides a conversational interface.
So the user, uh, be it a network operator or a security operator or a cloud operator can come in, simply come in and express their goals or questions in plain English, can ask questions about devices, posts, subnets, whether they're located on-prem or in the cloud. You can understand what parts packet can take through the network. You can understand what vulnerabilities are present in the environment and how they're exposed to the outside world.
You can talk in networking language. You can use constructs like VRF VLANs interfaces and their relationship. So one thing to have, I'll call it an oracle, about what the network looks like and what it's doing and performance and security auditing.
It's another to actually take action on network configurations. Are your agents able to take action to make changes to the network or, Yeah. Uh, excellent question.
So it's an agentic architecture, so theoretically it's capable. It's, it's, it's capable of taking actions as well. What I will show you today is how do you get to the step where you can, you're ready to take action?
Yeah.