{
  "source": "Cooked Index — occupational AI risk register",
  "page": "https://cookedindex.com/jobs/computer-network-architects/",
  "methodology": "https://cookedindex.com/methodology",
  "notice": "Verdicts are re-examined as evidence accumulates. Re-fetch before relying on this; the page above always carries the current score.",
  "scored_at": "2026-08-11",
  "model": "claude-opus-5",
  "occupation": {
    "title": "Computer Network Architects",
    "soc_code": "15-1241",
    "category": "Tech",
    "us_employment": 179740,
    "median_annual_wage": 134050
  },
  "verdict": "EXPOSED",
  "risk_resistance": 38,
  "contested": false,
  "near_boundary": false,
  "dimensions": {
    "task_resistance": 9,
    "embodiment": 7,
    "liability_shield": 2,
    "trust_premium": 7,
    "judgment_accountability": 13
  },
  "reasoning": {
    "task_resistance": "Subnet plans, VLAN maps, BGP/OSPF config templates, capacity spreadsheets and RFP spec matrices are text artifacts a model drafts in seconds, and Terraform/Ansible/NetBox pipelines already generate device configs from intent — what keeps this at 9 rather than 4 is the multi-year refresh design where you reconcile a 15-year-old wiring closet, an MPLS contract, and a QoS requirement no one wrote down.",
    "embodiment": "You are on the raised floor for cutovers, tracing an undocumented fiber run, checking rack power and cooling headroom before signing off on a spine-and-leaf build, and doing campus walk-throughs for wireless heat maps — but that is weeks a year, not daily, and the design work itself happens in Visio and a terminal, which puts it at 7 and not in the field-tech range.",
    "liability_shield": "There is no PE stamp, no state board, and no statute that requires a licensed human to approve a network design; CCIE, CCDE and CISSP get you shortlisted and get your employer partner status, but nothing prevents an unlicensed person — or a vendor's automated design tool — from producing the same topology and having it deployed.",
    "trust_premium": "Enterprise clients and internal stakeholders keep calling the architect who knows why the DMZ was carved up that way in 2019 and who they trust during a 2 a.m. maintenance window, but the deliverable is a design document evaluated on throughput, cost and RTO — you get replaced on the next contract cycle if a competitor's numbers are better, which caps this at 7.",
    "judgment_accountability": "Choosing flat-versus-segmented for a hospital network, deciding whether to accept a single point of failure to hit a budget, and signing off on a firewall policy that will be read in a breach post-mortem are calls with no clean answer and consequences measured in outage minutes and HIPAA/PCI findings — 13 rather than higher because you usually recommend into a change-approval board or CIO who formally owns the acceptance."
  },
  "rationale": "A large share of the day is documentation, diagramming, config generation, IP addressing schemes, and vendor spec comparison — all of which LLMs already produce at usable quality, and network-as-code tooling is compressing the rest. What persists is owning the topology decision when a hospital or bank cannot tolerate downtime, walking a data center or campus to see what the drawings got wrong, and being the person accountable when a segmentation choice becomes a breach. No licensure protects this role; certifications like CCIE/CCDE are market signals, not legal gates.",
  "outlook": "Headcount thins as one architect plus automation covers what three did, and the remaining roles concentrate in regulated, high-availability, and physical-infrastructure work.",
  "what_would_raise_it": {
    "levers": [
      {
        "dimension": "liability_shield",
        "change": "Critical-infrastructure cyber rules that name an accountable individual: CISA's CIRCIA reporting regime, NERC CIP-005/CIP-007 evidence requiring a named responsible engineer to attest to electronic security perimeter design, and SEC cyber disclosure practice pushing firms to designate a signing network/security architect. If a sector regulator (FERC/NERC, HHS HIPAA Security Rule update, or EU NIS2 as implemented in national law with personal management liability) requires a named human to sign off segmentation and perimeter architecture, this rises materially.",
        "plausibility": "plausible",
        "would_add": 6
      },
      {
        "dimension": "liability_shield",
        "change": "Cyber insurers conditioning coverage on an attested human-reviewed network segmentation and backup-isolation design — already visible in ransomware underwriting questionnaires from Coalition, Beazley, Chubb — hardened into a named-architect sign-off clause rather than a checkbox.",
        "plausibility": "already happening",
        "would_add": 3
      },
      {
        "dimension": "task_resistance",
        "change": "Task-mix shift: this role genuinely has two tiers. As diagramming, IPAM planning, config generation and vendor spec comparison get absorbed by network-as-code and LLM tooling, the residual job is failure-domain reasoning, migration cutover sequencing under a no-downtime constraint, and adjudicating vendor claims against observed behavior — work that is scarce, ambiguous, and consequence-heavy. The score rises because the denominator shrinks, not because AI got worse.",
        "plausibility": "already happening",
        "would_add": 4
      },
      {
        "dimension": "judgment_accountability",
        "change": "Post-incident regulatory practice (e.g. state AG or OCR settlements naming architecture decisions as root cause, or Change Healthcare-style congressional inquiry) making the topology/segmentation owner an identified party in breach findings, which formalizes what is currently informal ownership.",
        "plausibility": "plausible",
        "would_add": 3
      },
      {
        "dimension": "embodiment",
        "change": "Growth of edge/industrial and OT network work — plant floors, hospital wings, substations — where as-built drawings are wrong and commissioning requires physically tracing fiber, verifying cabinet grounding, and validating airgap claims. Rises only if the occupation's center of gravity shifts from cloud/campus toward OT convergence.",
        "plausibility": "plausible",
        "would_add": 3
      },
      {
        "dimension": "trust_premium",
        "change": "Limited route. Buyers pay for the vendor's or integrator's name and accountability, not for a human per se. The closest real mechanism is customer contracts demanding a named CCDE/CCIE-holding individual as design authority on the engagement — visible in some federal and defense integrator SOWs — which is a credential premium more than a human premium.",
        "plausibility": "unlikely",
        "would_add": 2
      }
    ],
    "ceiling_note": "Realistic ceiling is mid-50s. Even with sector cyber rules, accountability attaches to the firm and to CISO-level officers, not to a licensed individual network architect — there is no board, no exam-to-practice gate, and no plausible movement toward one. The task_resistance gain is real but self-limiting: it comes from the job shrinking, so headcount pressure continues even as the residual role gets harder to automate."
  },
  "adjudication": null,
  "employment_history": {
    "points": [
      {
        "y": 2019,
        "emp": 152420,
        "wage": 112690
      },
      {
        "y": 2020,
        "emp": 159350,
        "wage": 116780
      },
      {
        "y": 2021,
        "emp": 168830,
        "wage": 120520
      },
      {
        "y": 2022,
        "emp": 173920,
        "wage": 126900
      },
      {
        "y": 2023,
        "emp": 174100,
        "wage": 129840
      },
      {
        "y": 2024,
        "emp": 177010,
        "wage": 130390
      },
      {
        "y": 2025,
        "emp": 179740,
        "wage": 134050
      }
    ],
    "from": 2019,
    "to": 2025,
    "change_pct": 17.9,
    "comparable_from": 2019,
    "spans_soc_revision": false
  },
  "pivots": [],
  "license": "https://cookedindex.com/terms"
}