Dual-Resilient DIA: Why AI Workflows Need Two Separate Paths Into the Network

The Bottleneck Is the Network

Dual-Resilient DIA for AI-Ready Sites

Anyone investing in AI today thinks in compute. Practice tells a different story. Between a user’s prompt and the finished result sit four to eight tool calls, and each of them is its own trip across the network. That makes the internet connectivity of the site the factor that decides how fast an AI workflow completes, not the GPU in the provider’s data center. If the line goes down, what stops is the share of value creation that now runs through AI.

Key takeaways:

  • An agentic AI workflow generates 30 to 80 network packets per request. Every fluctuation along the way accumulates across that chain.
  • Bandwidth is not what decides the outcome, predictability is. Jitter above ten milliseconds makes real-time AI degrade.
  • Two lines from the same provider are not redundancy if they share the same main distribution frame and the same duct route.
  • Redundancy does not stop at the building wall. The private direct path to the AI platform belongs in the same chain.

The solution: Dual-Resilient DIA. Two dedicated internet connections from two carriers, across two media, two building entries and two duct routes, with separate hardware and automatic failover. Extended by private direct connections to the AI platforms.

What this article covers: Why AI workflows stress the network differently than classic software, where a seemingly redundant connection fails in practice, which six layers genuinely have to stay separate and how the effort weighs up against the cost of an outage.

Why the Network Decides How Fast AI Runs

For enterprise AI applications the network is the bottleneck, not the compute you buy in. Between a user’s prompt and the finished result sits a chain of stations: the application, the gateway with authentication and routing, the context of the language model, the compute phase at the provider and the return path of the token stream. Each of these stations is its own trip across the network.

Compute is purchased and, as a rule, available. The path to it is the variable a company actually controls. Nikolaus von Johnston, CEO of SAVECALL, put it this way at the VATM Business X-Change in June 2026: in the AI era the token is the raw material. And a raw material needs a reliable supply chain.

If that chain breaks, it is no longer just email that stops. What stops is the share of value creation that now runs through AI. That is the real difference compared to three years ago.

What Makes an AI Workflow So Fragile

An agentic workflow triggers four to eight tool calls per user request. The language model queries the CRM, a pricing database, stored knowledge, a vector database and finally the mail interface. Between each call the model thinks again. In total that produces 30 to 80 network packets per operation, with an end-to-end runtime of five to fifteen seconds.

Each of these hops has its own transit time and its own variance, and the variances accumulate along the chain. This is why the average value of a line is the wrong metric. What matters is the worst percentile of the measurements, known as the P99 value. It describes exactly the minutes in which a workflow breaks.

Three metrics decide the outcome in practice. Jitter, the variation in packet transit time, should stay below ten milliseconds. Above that, real-time AI loses sequence and speech recognition degrades. Time to first token should stay below 500 milliseconds. Above that, users abort and start again, which doubles the load. And P99 latency has to stay stable, because with eight tool calls it hits every single operation at least once.

How Much Bandwidth an AI Workplace Really Needs

Bandwidth demand per workplace rises sharply with the usage profile. Office work with an AI assistant needs 10 to 25 Mbit/s. As soon as voice and video are processed with AI, demand moves to 25 to 50 Mbit/s. Agentic workflows running continuously in the background need 50 to 100 Mbit/s per workplace.

Compared with a plain office workplace today, that is three to fifteen times the demand depending on profile. Anyone sizing a site now should plan for that range rather than extrapolating current consumption. More important than the absolute figure, however, is whether the line holds that figure at peak. Why bandwidth alone is the wrong metric is covered in detail in our article on AI-enabled networks.

What Dual-Resilient DIA Actually Means

Dual-Resilient DIA means two dedicated internet connections are kept separate at every layer. DIA stands for Dedicated Internet Access, a line with guaranteed bandwidth and no shared usage. The duplication applies not just to the contract, but to every physical component along the path.

Separated are the carrier, the transmission medium, the building entry, the main distribution frame and the backbone route. On the customer side this adds two end devices, two routers, an uninterruptible power supply and automatic failover. The switchover has to happen without manual intervention, otherwise the second line is of little use on a Saturday morning.

Different media are not a detail here, they are the core of the matter. A second fiber in the same trench shares the risk of the first. A combination of fiber and microwave radio, or fiber and mobile, genuinely separates it. Which media are available at a given site becomes clear when you look at the underlay, the physical layer beneath all network services.

Where Apparent Redundancy Fails in Practice

The most common gap is the second line from the same provider. On paper it looks like redundancy. In practice it runs through the same main distribution frame, the same cable bundle and the same backbone route. The company pays twice and still gets one path.

Microsoft describes exactly this trap for Azure ExpressRoute in plain terms. If the primary and secondary connections terminate on the same customer device, high availability inside your own network is given up. If both run through the same port, the partner is forced to give up the separation in its network as well. The same logic applies to internet access.

The second gap is the operating mode. A passive standby line that never carries traffic is never tested either. Microsoft therefore recommends running both paths in active mode. If one path then fails, only about half the flows are affected and recovery is faster. With BFD failure detection, detection time drops from around three minutes to under one second.

The third gap is the duct route. The most common cause of fixed-line outages remains construction work. Anyone procuring redundancy should have the separate duct routing confirmed in writing and check the building entry on site. Two fibers arriving through the same conduit are one line with two invoices.

How AI Hyperscalers Enter the Redundancy Chain

Redundancy does not stop at the building wall, it stops at the AI platform. Anyone using language models in Azure, at AWS or with a specialist provider otherwise sends that traffic across the public internet, with all the variance that is normal there. Private direct connections avoid this.

Azure ExpressRoute and AWS Direct Connect each provide a dedicated path into the cloud. AWS ties its highest resiliency model explicitly to separate connections terminating on separate devices in more than one location. That is the same logic as the building entry, just one layer further up.

The market is catching up here. In April 2026 Equinix launched Fabric Intelligence, a private marketplace for AI services through which companies reach inference, training and storage without sending sensitive data across the public internet. Microsoft introduced Multicloud Interconnect, a managed private path between Azure and AWS built on ExpressRoute and Direct Connect with a quad-redundant design. Anyone procuring now should factor these building blocks in from the start.

What an Outage Costs and What It Is Really Worth

For most companies the cost of an outage sits far above the cost of the second line. The Uptime Institute reports in its outage analysis for 2026 that 57 percent of major outages cost more than 100,000 US dollars. In one in five cases the damage exceeded one million US dollars, for the second year running.

On top of that comes the share nobody books as an incident. If thirty managers each wait half an hour a day for AI responses, that adds up to a five-figure sum per month. This waiting time appears in no outage statistic, because technically nothing failed. It is paid for all the same.

Nikolaus von Johnston describes the mismatch with an everyday comparison. A single internet line, he argues, is an inappropriate operational risk for a company. On the leased car of one individual employee, that same company spends more than on protecting the infrastructure the entire business depends on.

How SAVECALL Supports You

SAVECALL sources vendor-neutrally across more than 80 carrier relationships worldwide. For a dual-resilient connection that means we check site by site which two providers genuinely deliver separate paths, have the duct routing confirmed and negotiate both lines through our framework agreements. You get one team member as the point of contact for both carriers, ONE contract set and ONE invoice. The fundamentals of dedicated connectivity are covered in our article Why companies should rely on Dedicated Internet Access. The regulatory side is covered in NIS2, KRITIS and highly available internet. For the selection itself we have compiled the four key criteria for worldwide DIA provider selection. Our work does not end once procurement is done. Sourcing simplified. Lifecycle managed. That means we run contracts, incidents and expansions for you across the entire term.

Conclusion: Redundancy Is a Procurement Decision, Not a Technical One

The technology for a dual-resilient connection exists and has been proven for years. What is usually missing is the procurement logic behind it. Ordering both lines from the same provider because it is the easier buying route means buying convenience, not availability. With AI the calculation has shifted. The network now carries a share of value creation that used to run offline. Check your critical sites against the six layers above. Wherever a layer is shared, that is precisely where your single point of failure sits.

Frank Frommknecht, Key Account Consultant at SAVECALL

Written by

Frank Frommknecht

Key Account Consultant, SAVECALL

Has supported companies for over 20 years in selecting and optimizing their connectivity solutions. His focus: making complex telecommunications understandable from the customer’s perspective and finding the right solution strategically.

Sources

Frequently Asked Questions About Dual-Resilient DIA

What is Dual-Resilient DIA?

Dual-Resilient DIA is a dedicated internet connection that is duplicated at every layer. Two carriers deliver two separate lines. The two lines use different media, for example fiber and microwave radio or mobile. They enter the building through two separate building entries and follow separate duct routes. Inside the building they terminate on separate hardware with its own power supply. The goal is simple: no single component and no single excavator should be able to cut both paths at once.

Is a second line from the same provider not enough?

In most cases it is not. Two connections from the same provider often run through the same main distribution frame, the same cable bundle and the same backbone route. The company pays twice for a single path. Microsoft states explicitly for ExpressRoute that the secondary connection must not terminate on the same customer device, because that gives up high availability inside your own network. The same logic applies to internet access. Real redundancy only starts once the two paths share no component.

What does separate duct routing mean in practice?

Separate duct routing means the two lines reach the building along physically different paths. They do not share a trench, they do not share a conduit, and they enter on two different sides of the building. The most common cause of fixed-line outages is construction work that cuts a cable bundle. If both fibers lie side by side, one excavator hits both at the same time. Anyone buying redundancy should have the duct routing confirmed in writing rather than settling for a second contract number.

Why does AI need different connectivity than classic software?

AI applications are sensitive to variance, not to a lack of bandwidth. An agentic workflow triggers four to eight tool calls per request, and each call is its own trip across the network. That adds up to 30 to 80 network packets per operation. Every fluctuation accumulates along that chain. Once jitter climbs above ten milliseconds, response times degrade noticeably. What matters is the worst percentile of your measurements, not the daily average on the reporting sheet.

What does a direct connect to an AI hyperscaler achieve?

A direct connect is a private path to the cloud provider that bypasses the public internet. Azure ExpressRoute and AWS Direct Connect therefore deliver predictable transit times instead of fluctuating internet paths. For AI workloads that means a shorter time to first token and fewer aborted workflows. AWS ties its highest resiliency model explicitly to separate connections terminating on separate devices in more than one location. Redundancy does not stop at the building wall, it reaches into the cloud.

Does the second line actually pay for itself?

The second line costs a fraction of what an outage costs, depending on site and bandwidth. The Uptime Institute reports for 2026 that 57 percent of major outages cost more than 100,000 US dollars, and that one in five exceeded one million US dollars. Nikolaus von Johnston, CEO of SAVECALL, sums up the mismatch like this: a company spends more on the leased car of a single employee than on protecting the infrastructure the entire business depends on.

Articles You Might Also Like

Delighted customers

Why

Selection & operation of worldwide connectivity & cloud infrastructure. Without vendor risk & unnecessary costs.

What drives you forward – & what drives

Book a free expert consultation