Security Must Be the Foundation of Enterprise AI Infrastructure, Not an Afterthought
As companies build AI factories to produce intelligence at scale, security leaders warn that traditional cybersecurity approaches are inadequate for protecting autonomous agents, models and data in distributed environments.

Organizations are transforming into intelligence production systems powered by artificial intelligence, but this shift has introduced fresh vulnerabilities that conventional security frameworks were never designed to address. The infrastructure enterprises are deploying to generate knowledge at massive scale was built without security as a foundational principle.
Dave Vellante, chief analyst at theCUBE Research, explained the fundamental challenge: "AI factories introduce a new class of risks that extend beyond traditional cybersecurity models. In this world, data is not static, bounded or easily classified. Rather it is continuously generated, transformed and consumed across distributed environments."
The systems supporting these models operate differently from traditional enterprise infrastructure. While they rely on deterministic processes that function predictably, they are simultaneously probabilistic systems that learn and adapt continuously. Vellante noted that "Agents increasingly act autonomously, interacting with enterprise systems, executing workflows and making decisions with limited – or sometimes no – human intervention."
Autonomous agents create unprecedented security challenges
Dell Technologies Inc. and Intel Corp. are embedding security directly into infrastructure rather than applying it after systems are deployed. Both companies are prioritizing data protection and AI infrastructure security from the earliest design stages.
Steve Kenniston, senior cybersecurity evangelist for portfolio marketing at Dell, emphasized the scope of the problem: "AI changes the whole game. There's the model inferencing; there's the training model, training data. There are the systems where people can do things like prompt injection; there's identity management that needs to be thought about. Every new application has a new attack surface."
The challenge extends beyond simply expanding the threat landscape. Mukund Khatri, fellow and vice president of systems architecture at Dell, highlighted a critical distinction: "The model … the LLMs look like code. They need to be protected like code, but they are essentially data. The model integrity is of paramount importance."
Autonomous agents operating across enterprise systems present distinct risks compared to traditional software. While language models might produce inaccurate responses, agents can execute incorrect actions with real consequences. When systems operate without human oversight, the potential for harmful errors or malicious activity intensifies, particularly because actions occur in real time without review opportunities.
Identity governance emerges as the critical control layer
Organizations are deploying AI rapidly, yet visibility into agent behavior and access permissions remains limited. Managing agent identity has become essential because inadequately controlled agents create openings for attackers. According to the Darktrace 2026 "State of AI Cybersecurity" report, which surveyed 1,540 cybersecurity leaders and practitioners across 14 countries, 92% expressed concern about security implications of AI agents in their organizations, while 46% reported feeling unprepared to defend against AI-powered threats. The same report found that 87% believe AI is significantly increasing malware sophistication and success rates.
Conventional security approaches centered on perimeter defense, static policies and human-speed response are becoming obsolete. Threats including model inversion, prompt injection and data poisoning exploit weaknesses in models and data rather than traditional software flaws. Beyond identifying these dangers, organizations face a speed problem: AI accelerates both vulnerability discovery and exploitation timelines that traditional security frameworks cannot match. AI models can analyze code, locate weaknesses and expedite attack development faster than security teams can respond.
Implementing least-privilege access for agents is essential for safer deployments. Krista Case, principal analyst and practice lead for cyber resilience and security at theCUBE Research, noted that extending governance practices from human identities to agents does not require building new frameworks from scratch. "As AI agents gain autonomy, identity becomes a critical control point. Enterprises need to know which agents are operating, what they can access, what actions they can take and when those permissions should expire. Least privilege and lifecycle governance have to extend to agents as they become a growing class of enterprise identities."
Security teams must participate early in agentic system deployment. Identity controls and governance should be established before these systems begin accessing sensitive data and business processes. Kenniston revealed a striking pattern: "I'm hearing more and more from our services organization that when they start to go into a customer environment and they start talking about AI and implementing AI, about 85% or 90% of those get stopped because the security team hadn't been involved up until that point."
Dell integrates security across its entire operation, from supply chain through chip design to final device delivery. The company builds AI infrastructure with embedded roots of trust in components, incorporating cyber resilience into hardware and firmware rather than adding it afterward. Dell Enterprise Hub employs cryptographic image signing and SHA-384 hash verification to enable organizations to confirm the integrity and provenance of AI model containers before they are deployed.
Security requirements extend to networking and operations layers. Dell's rack-scale infrastructure combines compute, networking and storage into unified systems with consistent telemetry, allowing security teams to monitor entire environments rather than individual components separately. This visibility proves critical because AI workloads generate continuous data movement across nodes, systems and models. This same visibility becomes important after agents execute actions, particularly when organizations must determine what occurred and restore operations to a trusted state.
Case emphasized the importance of operational recovery: "As agents take on more responsibility for business processes, cyber resilience has to account for the state of the business. Recovery will then require understanding what an agent did, what decisions led to that action and how to restore operations to a known good state."
Trustworthy hardware provides the security foundation
Many organizations are choosing to keep sensitive AI workloads on-premises, bringing intelligence to data rather than moving data to cloud environments. This strategy provides greater control over sensitive information, infrastructure access and where processing occurs, while placing greater emphasis on securing the hardware supporting models, data and inference operations.
Mike Ferron-Jones, go-to-market lead for platform security and integrity at Intel, explained the fundamental importance of hardware: "Security software and security measures running up the stack can't be trusted unless the hardware underneath them is trustworthy. The CPU is kind of the fundamental hardware root of trust in the entire security stack. Your choice of a CPU is your very first security decision that you are making."
Intel organizes its data center security capabilities into four categories: platform protection, confidential computing through SGX and TDX, software behavior enforcement through control flow technologies and encryption acceleration. These elements together establish a hardware foundation supporting the entire software stack.
Confidential AI environments place AI workloads inside trusted execution environments featuring hardware-enforced isolation, cryptographic attestation and encryption keys controlled by the organization. Intel has developed reference architecture work with Nvidia Corp. that merges CPU trusted execution environments, including Intel TDX, with Nvidia's confidential-computing capabilities for GPUs, extending confidential AI protection to GPU-accelerated workloads.
Post-quantum cryptography becomes part of the AI security roadmap
Quantum computing advances are raising concerns about the future viability of widely deployed public-key cryptography, though the timeline for cryptographically relevant quantum computers remains unclear. A particular threat is the "harvest now, decrypt later" scenario, where attackers collect encrypted data today for decryption once quantum computers become sufficiently powerful. Both Dell and Intel are preparing for this possibility.
Ferron-Jones stated Intel's timeline: "By 2029, we expect that all cryptographic operations inside Intel platforms will be using quantum safe technology." Intel's public roadmap separately specifies full post-quantum cryptography compliance across all new platforms by 2030. Dell is also advancing toward quantum-resistant protections and post-quantum cryptography across portions of its portfolio.
In an era where knowledge becomes tokens, security must underpin every technology layer. Vellante concluded: "It must become the control plane that governs how intelligence is produced. If you cannot secure the AI factory, you do not control the outcome."


