Agentic AI Challenges Progress in Confidential Computing

Agentic AI Agents Pose New Security Challenges in Confidential Computing

Confidential computing, a technology designed to protect sensitive data from being stolen when in storage, transit, or use, has been gaining momentum in recent years. However, as artificial intelligence (AI) agents become increasingly prevalent, they are introducing new security challenges that current confidential computing systems aren’t equipped to handle. Experts say this is pushing the industry back to the drawing board.

At last month’s Linux Foundation’s Confidential Computing Summit in San Francisco, proponents of the technology acknowledged that AI agents are creating a whole new paradigm for system design and security. These agents, which can retain sensitive information and perform tasks autonomously, are raising concerns about their potential to leak confidential data or retain it long after its intended use.

One of the key issues is that agentic AI models don’t forget, and as they train and execute prompts, they may retain enterprises’ most sensitive secrets. For instance, an AI agent evaluating a company for a potential acquisition might absorb sensitive financial and business details. If the deal falls apart, the agent may not automatically forget those details or remove them from memory.

Google’s director of product management for confidential computing and encryption, Nelly Porter, emphasized that this is a critical issue that requires immediate attention. “We have work to do,” she said. “Please don’t stop.” Porter proposed using dedicated encryption keys for each agent to protect their short-term and long-term memory and the data they retain or distill.

Nvidia’s senior director of high-performance and AI factory solutions, Dion Harris, assured that his company’s hardware is ready for agentic AI confidential computing. Meanwhile, Microsoft’s chief technology officer and deputy chief information security officer, Mark Russinovich, acknowledged that confidential computing has advanced enough to provide enterprises and nations with guarantees that no one can see their models, data, or agents.

The agent challenges aside, Russinovich noted that confidential computing has introduced new opportunities but also new risks. Apple’s recent deployment of the technology in its Private Compute Cloud (PCC) infrastructure is a notable example. The tech giant implemented confidential computing to secure AI access across billions of its devices and provide guarantees that no one can see their models or data.

As companies continue to adopt AI, it’s essential for them to understand the new security challenges posed by agentic agents. To mitigate these risks, organizations should consider implementing dedicated encryption keys for each agent and prioritizing regular data deletion through “crypto-shredding.” By doing so, they can ensure that their sensitive information remains protected, even in the face of increasingly sophisticated AI agents.

Ultimately, the industry’s ability to address these new security challenges will determine the success of confidential computing. As Porter noted, “We have all the Lego blocks and all the capability to make it happen.” It’s time for companies to take action and ensure that their sensitive data remains secure in a world where agentic AI agents are increasingly prevalent.


Source: Dark Reading — 2026-07-23