As Confidential Computing Hits Mainstream, Agentic AI Presents New Security Challenges
The adoption of confidential computing has been gaining momentum in recent years, thanks to significant advancements in technology. However, a new threat model is emerging as artificial intelligence (AI) becomes increasingly prevalent in enterprises. Agentic AI, which refers to AI agents that can think and act independently, poses a challenge to the security guarantees provided by confidential computing.
The concept of confidential computing establishes a secure boundary around sensitive data, protecting it from being stolen when in storage, transit, or use. This is achieved through encrypted data stored in secure vaults and protected by mutual attestations and specialized hardware. However, as AI models train and execute prompts, they can retain enterprises’ most sensitive secrets, creating a new threat model that confidential computing isn’t designed to protect.
Google’s Director of Product Management for Confidential Computing and Encryption, Nelly Porter, emphasized the need for a whole new paradigm to address these challenges. “We have work to do. Please don’t stop,” she said at last month’s Linux Foundation’s Confidential Computing Summit in San Francisco. Porter highlighted that AI agents can retain sensitive information, even after their tasks are completed, and that this creates a risk of data exposure.
Porter proposed a dedicated encryption key for each agent to protect short-term and long-term memory and the data it retains or distills. This approach would involve “crypto-shredding”, which involves killing the encryption key as opposed to the data itself. This solution aims to mitigate the risks associated with agentic AI, but it also underscores the need for a fundamental rethinking of how we approach AI security.
Microsoft’s Chief Technology Officer and Deputy Chief Information Security Officer, Mark Russinovich, acknowledged that confidential computing has made significant progress in resolving previous challenges such as speed, cost, and workload complexity. However, he also noted that “with the adoption of AI, now it has introduced a new area in terms of opportunity but also a new area in terms of risk.” Russinovich emphasized that enterprises and nations need guarantees that no one can see their models, data, or agents.
The challenges posed by agentic AI are not limited to theoretical discussions. Apple’s recent implementation of confidential computing in its Private Compute Cloud (PCC) infrastructure is a prime example. While the technology has been touted as a major breakthrough, it also underscores the need for careful consideration of AI security risks. According to Sanchit Vir Gogia, CEO of Greyhound Research, Apple had to break tradition and adapt internal tools to implement confidential computing.
In light of these developments, enterprises must take proactive steps to address the new security challenges posed by agentic AI. This includes implementing dedicated encryption keys for each agent, regularly updating and patching software, and conducting thorough risk assessments. By taking a proactive approach, organizations can mitigate the risks associated with agentic AI and ensure that their sensitive data remains secure.
Source: Dark Reading — 2026-07-23