No request is trusted because of where it comes from, such as the internal network. Every call is authenticated and authorised on its own.
You have done this if
Your internal tools still checked the user's token even though they were only reachable from inside the VNet.
Say it in a review
Being on the private network doesn't grant anything; every service validates the caller's token.
On the AI Application map API Gateway, Enterprise APIs, Identity