📣

Advertisement

Google Ad - 970×90 Leaderboard  TOP_LEADERBOARD_4

The Trust Gap Opens Under Enterprise AI
Article

The Trust Gap Opens Under Enterprise AI

Four stories from one news cycle point to the same problem: AI capability now outruns the visibility and control enterprises have over it.

JaysuryaSeptember 22, 20264 min read

Photo: SiliconANGLE

📣

Advertisement

Google Ad - 970×90 Leaderboard  TOP_LEADERBOARD_4

The thread

Four unrelated announcements this week share one assumption: AI systems are being deployed faster than the organisations using them can observe, contain or secure them. The response, across cybersecurity vendors, data platform vendors and even the AI labs themselves, is a new layer of control wrapped around models that were not built with that control in mind. That layer is where much of the enterprise AI business is now being fought.

Control as the product

Darktrace's general availability of SECURE AI, reported by SiliconANGLE, is the clearest statement of the thesis. The company is applying behavioural detection, the discipline it built for network traffic, to how employees and agents use AI tools. The detail that matters is scale: telemetry from roughly 8,200 customers feeds the system. That is not a point product bolted onto a console. It is an attempt to make AI usage legible to security teams that lost visibility the moment staff began pasting work into external models and wiring agents into internal systems.

Vast Data's DataEnclave, also reported by SiliconANGLE, attacks the same problem from the infrastructure side. It is a confidential computing environment inside the Vast DataEngine and AI Operating System, built on Nvidia confidential computing technology, designed to run advanced models against sensitive data without exposing either the data or the model's intellectual property. Where Darktrace watches behaviour, Vast constrains the environment. Both exist because the default deployment pattern, a model reading whatever it can reach, is no longer acceptable for regulated or competitive workloads.

The commercial logic is straightforward. If a bank cannot prove that a model never saw raw customer records, or that a proprietary model was not exfiltrated through its own inference path, the project stalls. Confidential computing and behavioural monitoring are the two practical answers available today, and vendors are now racing to make them standard rather than bespoke.

The agent is the weak point

The Meta story, reported by Ars Technica, shows what happens when that control layer is missing. Ars describes Muse, Meta's AI assistant, as extraordinarily privileged, and reports a serious zero-day in it, with a simple ClickFix attack cited as only one route to completely hijack the agent. The specifics are less important than the structure of the failure. An assistant with broad permissions across a user's accounts and data is, functionally, an insider with excellent credentials and no judgement. A single successful prompt or click can convert that privilege into full compromise.

This is the pattern the enterprise vendors are selling against. The agent is not a chatbot that occasionally says something wrong. It is a principal with rights, and the security industry has spent decades learning that privileged principals need monitoring, least privilege and containment. None of that was designed into the first generation of assistants. Muse is a consumer-facing product, but the same architecture is being copied into enterprise agents, which is precisely why Darktrace's telemetry and Vast's enclaves exist.

Advertisement

📣

728x90

MID_CONTENT_2

Biology enters the compute stack

The Wired story on AI models built from rat brains, and The Biological Computing Company's move to bring its tools to Amazon Web Services, looks like an outlier. It is not. It is the same story told from the supply side. Biological computing is being positioned as an alternative substrate for AI at a moment when the cost, power draw and concentration of conventional accelerator capacity are live concerns for every large buyer.

Bringing that work to AWS is significant because it puts a once-fringe approach inside the same procurement and security perimeter as ordinary cloud workloads. If biological or hybrid compute becomes a real option, it will arrive through the hyperscalers, with the same expectations around isolation, auditability and data handling that Vast and Darktrace are building for today. The field's credibility now depends less on laboratory results than on whether it can be governed like any other production system.

Why this matters in the United States

For US technology companies, the thread points to a maturing market in which the model is no longer the differentiator. Every large vendor has access to capable models. What buyers cannot easily assemble is evidence: proof of what the model touched, proof of who or what invoked it, proof that a privileged agent cannot be turned against its owner. That is why Darktrace is selling visibility, Vast is selling isolation, and Meta is now on the defensive about privilege.

For US enterprises, the practical consequence is procurement pressure. Security review is becoming the gating function for AI projects, and vendors that cannot answer questions about agent permissions, data exposure and inference isolation will lose deals to those that can. The 8,200-customer telemetry base Darktrace cites is a competitive asset precisely because it encodes patterns of misuse that a smaller vendor cannot see.

For US consumers, the Meta zero-day is the relevant data point. Consumer assistants hold mail, calendars, files and payment credentials, and they are being given more authority, not less. The same design choices that make an agent useful make it a high-value target. The security industry's answer, monitoring and containment, will reach consumer products later than enterprise ones, because consumers do not run security operations centres.

What to watch

Three things follow directly from these stories. First, whether confidential computing becomes a default expectation for AI workloads rather than a premium feature; Vast's use of Nvidia technology suggests the hardware groundwork is already there. Second, whether agent privilege is treated as a first-class security problem across the industry the way Ars Technica's reporting frames it at Meta, which would push permission models and audit trails into assistant design rather than bolting them on afterwards.

Third, whether biological computing's arrival on AWS turns into a governed cloud service or remains a research curiosity. The pattern across all four stories is that capability is arriving faster than control, and the vendors now winning attention are the ones selling control. That is unlikely to change while agents keep accumulating privileges.

More on this beat: AI on TechManNews.

Advertisement

📣

728x90

IN_ARTICLE_5

#enterprise AI#AI security#confidential computing#AI agents#biological computing#cloud infrastructure

Newsletter

Get Tech News in Your Inbox

The latest AI, gadgets, software and startup stories from TechManNews, delivered every morning - free.